212-89: EC-Council Certified Incident Handler (E|CIH)

Associate EC-Council EC-Council
Browse certifications

Exam Resources

Official learning paths, exam details, skills measured, and community resources to supplement your study.

About the E|CIH (212-89) Exam

Respond to a breach the right way — detect and triage the incident, contain it without destroying evidence, gather forensically sound proof, eradicate the threat, recover cleanly, and turn lessons learned into a stronger defence.

The EC-Council Certified Incident Handler (E|CIH v3, exam 212-89) validates the structured, hands-on skills a working incident responder needs across the full incident handling and response (IH&R) lifecycle. It is vendor-neutral and process-driven, aligned to NIST SP 800-61, ISO/IEC 27035, the SANS PICERL model, and MITRE ATT&CK. The v3 update covers ten modules: Introduction to Incident Handling and Response (threats, frameworks, IR team roles, and SOAR fundamentals), the nine-step Incident Handling and Response Process (preparation through post-incident review), Forensic Readiness and First Response (securing the scene, the order of volatility, write-blockers, and chain of custody), and dedicated modules for handling Malware, Email, Network, Web Application, Cloud (AWS, Azure, and GCP), Insider Threat, and — new in v3 — Endpoint (mobile, IoT, and OT/ICS) incidents. Every practice question is an original incident-responder scenario with detailed explanations, why-wrong analysis, and exam tips.

Who Should Take This Exam?

The E|CIH is an intermediate specialist certification for incident handlers, SOC analysts and tier-2/3 responders, CSIRT and IR team members, security engineers and administrators on call, digital-forensics practitioners, and threat and vulnerability analysts moving into hands-on incident response. There is no mandatory prerequisite when you take official EC-Council training; without training, you can apply for exam eligibility with at least one year of information-security experience. A working knowledge of networking, operating systems, and core security concepts makes the material far easier. It is DoD 8140/8570 approved (IAT-II, CSSP-IR).

Typical study time: 6-10 weeks of focused study

Exam Quick Facts

DetailValue
Exam Code212-89
TitleEC-Council Certified Incident Handler (E|CIH v3)
Duration180 minutes
Questions100
Pass Score70% (form-dependent)
Cost$450 USD
ProviderECC Exam Portal (EC-Council)
Validity3 years (ECE required)
Question TypesMultiple choice
Official PageView on EC-Council →

Exam Domains & Weights

The E|CIH exam covers 10 modules. EC-Council does not publish per-module percentages publicly, so the weights below are inferred from module breadth and mapped to our 250-question practice bank — use them to prioritise, not as official figures.

DomainWeightPractice Qs
Introduction to Incident Handling and Response9%24
Incident Handling and Response Process12%28
Forensic Readiness and First Response9%24
Handling and Responding to Malware Incidents12%28
Handling and Responding to Email Security Incidents9%24
Handling and Responding to Network Security Incidents11%26
Handling and Responding to Web Application Security Incidents9%24
Handling and Responding to Cloud Security Incidents10%24
Handling and Responding to Insider Threats9%24
Handling and Responding to Endpoint Security Incidents10%24
Total100%250

💡 Study tip: The two heaviest modules — the Incident Handling and Response Process and Malware Incidents (12% each) — are the backbone of the exam, so master them first. Above all, learn the order of the IH&R workflow (Preparation → Detection and Recording → Triage and Notification → Containment → Evidence Gathering → Forensic Analysis → Eradication → Recovery → Post-Incident Activities) and never let an answer eradicate a threat before evidence is preserved. The incident-type modules (network, malware, and the new endpoint module together carry the most questions) reward knowing the right containment and recovery move for each attack; the cloud module tests AWS, Azure, and GCP incident response side by side.

Practice Exam — 250 Questions

Prepare for the E|CIH exam with our 250-question practice exam covering all 10 modules. Every question includes detailed explanations, why-wrong analysis, and exam tips, and maps to the official E|CIH v3 module blueprint.

What you get:

  • ✅ Exam simulation mode with timer
  • ✅ Spaced repetition for weak areas
  • ✅ Detailed explanations for every question
  • ✅ Progress tracking across domains
  • ✅ 20 free questions — no account needed

EC-Council Certification Path

E|CIH is EC-Council’s dedicated incident-handling credential. It builds naturally on the defensive CND (network defense) and pairs with CTIA (threat intelligence) for detection, CHFI (forensics) for deep investigation, and CEH (ethical hacking) for understanding the attacker’s playbook. There is no strict hierarchy — pick the credential that matches your role. E|CIH is the natural choice if you lead or support incident response and want a structured, framework-aligned IH&R process.

If you’re studying for the E|CIH exam, you might also be interested in these EC-Council certifications:

Study Tips

  1. Memorise the IH&R workflow order — most process questions hinge on knowing which phase comes next and never eradicating or recovering before evidence is gathered and the threat is contained
  2. Master the order of volatility and chain of custody — collect RAM and volatile data before disk, image with a write-blocker, verify with hashes (MD5/SHA-256), and keep an unbroken custody record so evidence is admissible
  3. Know the right response per incident type — containment for ransomware vs a DDoS vs a compromised mailbox vs an insider is different; the incident-type modules reward matching the action to the attack
  4. Learn cloud incident response across AWS, Azure, and GCP — map CloudTrail/GuardDuty ↔ Microsoft Sentinel/Defender for Cloud ↔ Security Command Center/Cloud Audit Logs, and know how to snapshot evidence and revoke credentials on each
  5. Contain insider threats quietly — preserve evidence and coordinate with HR and legal without tipping off the insider
  6. Use our practice exam — try the 20 free questions first to gauge your readiness, then use timed exam mode to practise under pressure
20 Free Questions Practice Exam $9 →