Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Certified Incident Handler v2
Highest Rated
Rating: 4.6 out of 5(942 ratings)
5,987 students

Certified Incident Handler v2

Certified Incident Handler Certificate Exam Preparatory course
Last updated 3/2025
English
Arabic [Auto],English

What you'll learn

  • Understanding the fundamentals of incident handling and response, including the incident handling process and procedures.
  • Developing an incident response plan and establishing communication channels to ensure a prompt and effective response to incidents.
  • Identifying and classifying incidents, analyzing their impact, and responding appropriately.
  • Implementing containment strategies to limit the impact of incidents and eradicating the cause of incidents.
  • Restoring systems and data affected by incidents and conducting post-incident activities, including forensic analysis and lessons learned sessions.
  • Understanding legal and ethical considerations in incident handling and response.
  • Applying incident handling and response techniques to various types of incidents, including network security incidents, malicious code incidents, insider attack
  • Developing incident handling policies and procedures to ensure consistent and effective incident response across the organization.

Course content

10 sections55 lectures19h 28m total length
  • Overview4:48

    Learn incident handling and response methodologies, from identification to recovery, across networks, cloud, email, and forensics. Build hands-on skills with tools, reporting, and exam-focused guidance for the ECIH.

  • Information Security and Incident Management23:57

    Explore the five core information security elements: confidentiality, integrity, availability, authenticity, and non repudiation, and see how defense in depth, policies, and incident handling address threats and attacks.

  • What is Vulnerability Management24:55

    Explore what constitutes a vulnerability, how to conduct vulnerability assessments, and the six phases of the vulnerability management lifecycle, from baseline and risk assessment to remediation and ongoing monitoring.

  • What are Threat Assessments19:22

    Threat assessments identify and model potential actions by bad actors, using internal and external threat data, threat intelligence, contextualization, and correlation to prioritize defense and incident handling.

  • Risk Management - Vocabulary17:33

    Explore risk management vocabulary, defining threat, vulnerability, likelihood, and impact, and learn how risk equals threat times vulnerability, with countermeasures and residual risk.

  • Risk Management - The Process27:35

    Learn the nine-step risk assessment process within a three-phase risk management framework that identifies systems, threats, and vulnerabilities, then analyzes controls, likelihood, and impact to guide risk decisions.

  • Risk Management - The NIST RMF22:26

    Explore the NIST RMF and its six phases—categorize, select, implement, assess, authorize, monitor—for ongoing risk management.

  • Incident Handling best practices, std., frameworks21:22

    Learn to master incident handling best practices, standards, and frameworks; implement auditing, due diligence, an incident response plan, and a CSIRT, guided by ISO 27001/27002, NIST, PCI DSS, and COBIT.

  • Incident Handling and Legal Compliance22:13

    Assess the role of law in incident handling, including jurisdiction, law enforcement, GDPR, and US acts like SOX, HIPAA, FISMA, GLBA, DMCA, with 72-hour breach notification to supervisory authorities.

Requirements

  • There are no formal prerequisites to take this Course. However, it is recommended that participants have some basic knowledge of computer networking, cybersecurity, and incident handling before taking the course.

Description

The Certified Incident Handler v2 Exam Preparatory Course is designed to provide participants with the knowledge and skills required to handle and respond to various cybersecurity incidents. The course covers the fundamental principles of incident handling and response, including preparation, detection, containment, eradication, and recovery.

The course is intended for security officers, auditors, security professionals, site administrators, and anyone involved in incident handling and response. Participants will learn how to handle various types of incidents, including network security incidents, malicious code incidents, insider attacks, and physical security incidents.

  • Understanding the fundamentals of incident handling and response, including the incident handling process and procedures.

  • Developing an incident response plan and establishing communication channels to ensure a prompt and effective response to incidents.

  • Identifying and classifying incidents, analyzing their impact, and responding appropriately.

  • Implementing containment strategies to limit the impact of incidents and eradicating the cause of incidents.

The Certified Incident Handler v2 Exam Preparatory Course is designed for individuals who are looking to develop their skills and knowledge in incident handling and response. The course is particularly suitable for those who are responsible for maintaining the security of computer systems and networks, as well as those who are interested in pursuing a career in cybersecurity.

Overall, the Certified Incident Handler v2 Exam Preparatory Course aims to provide participants with the knowledge and skills needed to handle and respond to various cybersecurity incidents effectively. Upon completion of the course, participants will have the necessary knowledge to take the Certified Incident Handler certification exam and earn the Certified Incident Handler credential.

This course is NOT affiliated with EC-Council International Limited in any way, and content from this course is not approved by the organization.

Who this course is for:

  • Security officers: Security officers responsible for monitoring and responding to security incidents within an organization.
  • Site administrators: Site administrators responsible for managing and securing computer systems and networks.
  • Auditors: Auditors responsible for assessing the security posture of an organization and identifying vulnerabilities.
  • Security professionals: Security professionals responsible for designing and implementing security solutions within an organization.
  • Network administrators: Network administrators responsible for managing and securing computer networks.
  • Incident responders: Incident responders responsible for investigating and responding to security incidents.
  • Anyone interested in cybersecurity: Anyone interested in learning about incident handling and response in the context of cybersecurity.