
EC-Council Certified Incident Handler
The EC-Council Certified Incident Handler (ECIH) certification validates your ability to prepare for, detect, and respond to cybersecurity incidents using a structured, method-driven approach. Designed for incident responders, SOC analysts, and security professionals, the program covers the full incident handling and response lifecycle—from preparation and triage to containment, eradication, and recovery. Earning ECIH demonstrates that you can protect your organization from evolving threats and minimize the impact of security breaches.
473 practice questions · Updated 2026-07-30
ECIH Curriculum
Every domain, objective, and concept the ECIH exam measures.
- Incident Handling Overview
- Incident Handling Phases
- Incident Response Team Roles
- Incident Classification and Prioritization
- Incident Handling Policies and Procedures
- Legal and Ethical Considerations
- Communication and Coordination
- Post-Incident Activities
- Incident Handling and Response Process Overview
- Preparation Phase
- Detection and Analysis Phase
- Containment, Eradication, and Recovery Phase
- Post-Incident Activity Phase
- First Response Overview
- Incident Identification
- Initial Assessment and Triage
- Preservation of Evidence
- System Isolation and Containment
- Documentation and Chain of Custody
- Communication and Escalation
- Malware Incident Definition
- Malware Incident Response Phases
- Malware Classification
- Malware Infection Vectors
- Initial Detection and Triage
- Containment Strategies
- Eradication and Remediation
- Recovery and System Restoration
- Forensic Evidence Collection
- Malware Analysis Basics
- Post-Incident Review
- Email Security Incident Identification
- Email Header Analysis
- Malicious Content Detection
- Email Security Incident Containment
- Email Security Incident Eradication
- Email Security Incident Recovery
- Email Security Incident Reporting and Documentation
- Network Incident Identification
- Network Incident Triage
- Network Incident Containment
- Network Incident Eradication
- Network Incident Recovery
- Network Incident Documentation
- Network Incident Communication
- Network Incident Post-Mortem
- Web Application Incident Identification
- Incident Triage and Prioritization
- Evidence Collection and Preservation
- Containment Strategies for Web Incidents
- Eradication and Recovery
- Post-Incident Analysis and Reporting
- Cloud Incident Response Fundamentals
- Cloud Service Models and Shared Responsibility
- Cloud Incident Detection and Monitoring
- Cloud Forensic Acquisition
- Cloud Incident Containment and Eradication
- Cloud Incident Recovery and Post-Incident Activities
- Insider Threat Definition and Types
- Insider Threat Indicators
- Insider Threat Detection Techniques
- Insider Threat Response Procedures
- Insider Threat Investigation and Evidence Handling
- Insider Threat Mitigation and Prevention
- Insider Threat Communication and Reporting
- Endpoint Incident Identification
- Endpoint Containment Strategies
- Endpoint Eradication and Recovery
- Endpoint Evidence Collection and Preservation
- Endpoint Incident Documentation and Reporting
- Endpoint Post-Incident Activities
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for ECIH, so none is invented.