Free Practice Questions for ECIH
Exam-style questions and explanations by OpenExamPrep.
Loading practice questions...
Explore More EC-Council Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.
Key Facts: ECIH Exam
100
Exam Questions
EC-Council
70%
Passing Score
EC-Council
3 hours
Exam Duration
EC-Council
$450
Exam Fee
EC-Council
5
Content Domains
ECIH v3
3 years
Certification Validity
ECE required
The ECIH exam has 100 multiple-choice questions in 3 hours with a 70% passing score. It covers incident response lifecycle (25%), malware analysis (20%), digital forensics (25%), threat intelligence (15%), and cloud IR (15%). ECIH v3 includes expanded coverage of cloud incident response, threat hunting, and SOAR automation.
Sample ECIH Practice Questions
Try these sample questions to review concepts for the ECIH exam. Each question includes a detailed explanation. Start the interactive quiz above for the full 174+ question experience with AI tutoring.
1What is the first phase of the incident response lifecycle as defined by NIST SP 800-61?
2Which type of malware replicates itself across networks without requiring user interaction?
3What is the primary purpose of a SIEM (Security Information and Event Management) system in incident response?
4During incident triage, what is the primary goal?
5Which email header field is most useful for tracing the origin of a phishing email?
6What is the chain of custody in digital forensics?
7Which containment strategy involves isolating an affected system while keeping it powered on to preserve volatile evidence?
8What type of malware analysis examines the binary without executing it?
9What is the purpose of a threat intelligence platform (TIP) in incident response?
10Which network forensics tool captures and analyzes full packet data on a network segment?
About the ECIH Exam
The Certified Incident Handler (ECIH v3) validates skills in incident response lifecycle management, malware analysis, digital forensics, cloud incident response, threat intelligence, and SIEM/SOAR operations. ECIH prepares professionals to detect, contain, eradicate, and recover from security incidents across on-premises and cloud environments.
Exam sponsor: EC-Council / Pearson VUE. The requirements and fees below concern the certification or admission exam, separate from our free practice resources.
Questions
100 questions
Time Limit
3 hours
Passing Score
70%
Reported exam pass rate: Not published. EC-Council does not release official pass-rate data Exam sponsor website
Fees, eligibility, and exam policies can change. Confirm them with the exam sponsor before applying or paying.
Our practice resources: topics covered
We aim to reflect publicly available exam outlines and topic information in our study resources. Coverage, format, and difficulty may differ from the actual exam, and we cannot guarantee that every detail is accurate or current. Confirm exam requirements, fees, and policies with the official exam sponsor.
Incident Response Lifecycle
NIST IR phases, preparation, detection, containment, eradication, recovery, lessons learned, playbooks, and CSIRT operations
Malware Analysis
Static and dynamic analysis, sandboxing, persistence mechanisms, fileless malware, ransomware, packing, and YARA rules
Digital Forensics
Evidence handling, chain of custody, memory forensics, email forensics, Windows artifacts, log analysis, and insider threats
Threat Intelligence
STIX/TAXII, MITRE ATT&CK, Cyber Kill Chain, Diamond Model, Sigma rules, SIEM, SOAR, and threat hunting
Cloud Incident Response
AWS CloudTrail, Azure Activity Logs, GCP Audit Logs, shared responsibility model, cloud forensics, and container IR
Preparing for the ECIH Exam
What You Need to Know
- Passing score: 70%
- Exam length: 100 questions
- Time limit: 3 hours
- Exam / certification fees: $450 (exam voucher) Official sources
Using Our Practice Resources
- Work through all 174 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
ECIH: Suggested Study Strategy
Frequently Asked Questions
What is the ECIH exam format?
The ECIH exam consists of 100 multiple-choice questions to be completed in 3 hours. The passing score is 70%. Questions cover the complete incident response lifecycle including preparation, detection, containment, eradication, recovery, and post-incident activities.
How much does the ECIH certification cost?
The ECIH exam voucher costs approximately $450. Training packages are available from EC-Council at various price points. Self-study candidates may need to submit an eligibility application with an application fee.
What is the difference between ECIH and CEH?
CEH focuses on offensive security (ethical hacking, penetration testing) while ECIH focuses on defensive security (incident response, forensics, threat intelligence). They are complementary certifications — CEH helps understand how attacks work, and ECIH teaches how to detect and respond to them.
Does ECIH cover cloud incident response?
Yes, ECIH v3 includes significant coverage of cloud incident response, including AWS CloudTrail analysis, Azure Activity Logs, GCP Audit Logs, the shared responsibility model, cloud forensics techniques, and container security incident handling.
What jobs can I get with an ECIH certification?
ECIH certification prepares you for roles including Incident Response Analyst, SOC Analyst, Threat Hunter, Digital Forensics Analyst, CSIRT Member, Security Operations Engineer, and Cybersecurity Incident Manager.