You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The EC-Council Certified Incident Handler (ECIH) certification validates your ability to prepare for, detect, and respond to cybersecurity incidents using a structured, method-driven approach. Designed for incident responders, SOC analysts, and security professionals, the program covers the full incident handling and response lifecycle—from preparation and triage to containment, eradication, and recovery. Earning ECIH demonstrates that you can protect your organization from evolving threats and minimize the impact of security breaches.
Content last reviewed 30 July 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The EC-Council Certified Incident Handler (ECIH) program equips cybersecurity professionals with the knowledge, skills, and abilities to effectively prepare for, deal with, and eradicate threats and threat actors in an incident. This ANAB-accredited and US DoD 8140-approved program provides the entire process of Incident Handling and Response, with hands-on labs that teach the tactical procedures and techniques required to effectively Plan, Record, Triage, Notify, and Contain.
Students learn to handle various types of incidents, including malware, email security, network security, web application security, cloud security, and insider threat-related incidents. The curriculum also covers post-incident activities such as containment, eradication, evidence gathering, and forensic analysis, leading to prosecution or countermeasures to ensure the incident is not repeated. The ECIH is a method-driven course that provides a holistic approach covering vast concepts related to organizational IH&R, from preparing and planning the incident handling response process to recovering organizational assets from the impact of security incidents.
The ECIH certification is designed for incident handlers, incident responders, SOC analysts, security operations center personnel, and other cybersecurity professionals who are responsible for detecting, responding to, and mitigating security incidents. It is also valuable for IT professionals seeking to specialize in incident response and for organizations looking to build a structured incident handling capability. The program is ideal for those who want to master the entire incident handling and response process, from preparation and triage to evidence gathering and recovery, and who need to handle a wide range of security incidents systematically.
While EC-Council does not publish formal experience prerequisites for the ECIH exam, a solid understanding of information security fundamentals and familiarity with network and system administration concepts is strongly recommended. Knowledge of networking concepts and common network protocols; Familiarity with operating systems, especially Windows and Linux; Understanding of basic information security principles, such as the CIA triad and risk management; Experience with security tools such as firewalls, IDS/IPS, and SIEM is beneficial
Every domain and objective EC-Council measures, with the weight they carry on the exam.
The official EC-Council exam outline · checked 30 July 2026 · See the source
Everything EC-Council publishes about sitting it, and nothing we inferred.
No mandatory prerequisites — this certification has no required predecessor exam or credential.
The path EC-Council lays out, how the credential is kept, and where to book.
Step-by-step path to EC-Council Certified Incident Handler
This certification is currently active and available. EC-Council maintains this certification to validate current skills and industry relevance.
Register for the exam through Pearson VUE, EC-Council’s authorized testing partner.
Schedule your examVisit the official EC-Council certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksYes, the ECIH program is ANAB-accredited and approved by the US Department of Defense (DoD) under directive 8140. It is also 100% compliant with the NICE 2.0 Framework and with CREST CCIM.
The ECIH training program includes 95 labs that simulate a real-time environment, covered in 22 scenario-based labs. The exam itself is knowledge-based, but the hands-on labs prepare you for real-world incident handling scenarios.
The ECIH certification is designed for incident handlers, incident responders, SOC analysts, and other cybersecurity professionals responsible for detecting, responding to, and mitigating security incidents.
EC-Council typically requires candidates to attend authorized training before taking the exam, but there may be alternative eligibility paths. Check the official EC-Council website for the most current exam eligibility requirements.
ECIH focuses specifically on incident handling and response, while CEH covers ethical hacking and penetration testing, and CND focuses on network defense. They are complementary certifications that cover different aspects of cybersecurity.
EC-Council certifications are available in over 170 countries. The ECIH exam can be taken online or at Pearson VUE test centers, subject to regional availability.
Every domain, every objective, and every concept EC-Council measures — each one written out.





Every objective below is a page you can open and practise now, without an account.
The official EC-Council exam outline · checked 30 July 2026 · See the source
In front of every objective the practice pages are already there, free and without an account. This is one objective, opened.
49 questions on this objective, five to a page. Every range above is a real page, open now, with no account.
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The whole bank is open. 5 questions to a page, every answer explained, and a discussion thread on each one.
Every objective, and every page range, is a link — so you can pick up exactly where you left off.
Short enough to finish, long enough to matter.
Not only which one is right — why the others are wrong.
Ask, answer, and vote. Every question has its own thread.
These are not trivia. Each one is written against a concept in the book, so when you get one wrong there is somewhere to go and find out why.

The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
We build from the official skills outline, not from a summary of it — 10 objectives, 71 concepts written under them, and free questions against every one. When EC-Council changes the outline, this page changes with it.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.