
Download files here
Assess threats, vulnerabilities, and exploits, including malware such as viruses, worms, Trojans, spyware, adware, rootkits, and botnets. Learn defenses like anti-malware tools, ARP spoofing countermeasures, and intrusion detection.
Explore wireless threats from wardriving and flawed WEP encryption to SQL injection and cross-site scripting, and learn vulnerability assessments, pen testing, and exploitation using tools like Nessus, Nmap, and Metasploit.
Develop incident handling with strong senior management support, a clear communication and reporting plan, per-incident type procedures, trained teams, and ongoing metrics.
Identify unusual log events, processes, and network usage to guide incident response. Assemble a responder toolkit and use netcat to pipe evidence to a separate system, preserving volatile data.
Explore Linux log analysis for preliminary incident response, identify promiscuous mode, logon failures, and suspicious processes using netstat, ps, top, lsof, arp, and crontab, and review Tripwire and hardening tools.
Identify whether an incident occurred, assess severity and nature, and apply a six-step process: categorize, receive, analyze, document, prioritize, and notify, using sensors, logs, and intrusion detection system and Wireshark.
Explore Sysinternals tool sets—free diagnostic and troubleshooting utilities for Windows, including Process Explorer, Process Monitor, AutoRuns, PS Tools, and Sigcheck, ideal for incident handling and digital forensics.
The Certified Incident Handling Engineer (CIHE) course is designed to enable the candidates to efficiently and effectively handle incidents which arise during their jobs as system administrators, system security engineers and network and cloud security experts. The course helps the candidates to plan, create and utilize their resources properly for the prevention, detection and mitigation of attacks on the data or infrastructure.
The Certified Incident Handling Engineer (CIHE) is a certification exam offered by Mile2. The course is covers the entire curriculum of the said certification and prepares the candidates to appear in the certification exam. Mile2 certifications are vendor neutral and are designed to be applied at real-world scenarios. The course also approaches the concepts in the same manner enabling the students of this course to comprehend, plan, create and implement effective responses to attacks on data and infrastructure. Additionally, the course also teaches about the common exploits and techniques used by hackers globally so that the students of this course are aware and could prevent most of the attacks on their IT infrastructure.
Exam Information
The Certified Incident Handling Engineer exam is taken online through Mile2’s Assessment and Certification System (“MACS”), which is accessible on your mile2 account. The exam will take 2 hours and consist of 100 multiple-choice questions.