HanuxLearning
Loading…
Have a voucher code? Redeem it and reserve your seat
Grab your voucher →HanuxLearning
Loading…
EC-Council Certified Incident Handler (ECIH v3) training and exam prep - a specialist certification in incident response: detect, contain, eradicate and recover from security incidents.
Group Enrollment with Friends or Colleagues | Get a quote

EC-Council's Certified Incident Handler (ECIH v3) is a specialist certification focused entirely on incident response. It prepares you to detect, contain, eradicate and recover from security incidents using a structured, industry-aligned process. The program covers the full lifecycle - preparation and readiness, detection and first response, containment, eradication, recovery and lessons learned - and then applies it to specific incident types: malware, email/phishing, network, web application, cloud and insider threats. The certification is earned by one exam (code 212-89): 100 multiple-choice questions in a 3-hour window, taken online through the EC-Council exam portal (remote proctoring available) or at an authorised centre. Note: EC-Council does not publish a single fixed passing percentage for ECIH - it uses a form-dependent cut score (70% is commonly cited).
Incident response is now a board-level priority: every organisation needs people who can act calmly and correctly when a breach happens. ECIH is built entirely for that role. It teaches a structured, repeatable incident-response process and then applies it to the incidents teams actually face - malware, phishing, network and web attacks, cloud incidents and insider threats. It is the "respond" specialist in the blue-team path, complementing detection (CSA) and forensics (CHFI).
Source: Glassdoor
Source: Indeed
Annual Salary
Source: Glassdoor
Hiring Companies
Source: Indeed
Batch starting from:
ECIH is ideal for people who respond to security incidents: - Incident handlers and incident responders - SOC analysts (Tier 2) with response duties - Cyber defence / CSIRT team members - IT and security operations staff - Security consultants who manage incident response It is a specialist, intermediate-to-advanced certification - some foundational cybersecurity knowledge and incident-response or security experience is recommended.
How to earn it:
1. Prepare with an ECIH exam-prep course with hands-on incident-response labs - that is what we provide.
2. Register for the exam through EC-Council. (Training routes include self-paced iLearn and live iWeek; confirm current eligibility.)
3. Sit the exam: 100 m...
The EC-Council Certified Incident Handler (ECIH v3) certification validates your ability to identify, analyze, contain, and respond to cybersecurity incidents effectively. The exam assesses your knowledge of incident handling frameworks, threat identification, incident analysis, containment strategies, eradication and recovery processes, evidence handling, and post-incident activities. Understanding the exam structure and certification requirements can help you plan your preparation effectively and build confidence before the assessment. This section explains the exam pattern, question format, duration, certification requirements, incident response areas, and other important details you should know before taking the EC-Council Certified Incident Handler v3 (212-89) exam.
Exam details verified on 16 August 2026. The ECIH exam (212-89, v3) is 100 multiple-choice questions in a 3-hour window. EC-Council does not publish a single fixed passing percentage (it uses a form-dependent cut score, 70% commonly cited). It is valid 3 years and maintained with 120 ECE credits plus an annual membership fee. The voucher is commonly cited at US$450 but pricing varies. Confirm current details and pricing at eccouncil.org, and confirm ECIH's DoD status at the DoD Cyber Exchange.
ECIH is aimed at people who respond to security incidents: - Incident handlers and incident responders - SOC analysts (Tier 2) with response duties - Cyber defence / CSIRT team members - IT and security operations staff - Security consultants who manage incident response It is specialist / intermediate-to-advanced - some incident-response or security background is recommended. If you are earlier in your journey, our Certified SOC Analyst (CSA) course is a strong companion; for forensics, see CHFI.