Exam Domains
1.0 Computer Forensics in Today’s World
Weight not published
2.0 Computer Forensics Investigation Process
Weight not published
- 2.1Forensic Investigation Process and its Importance
Understand the phases involved in the computer forensics investigation process; Understand first response procedures; Understand the roles of first responders; Understand first response in different situations; Understand how to set up a computer forensics lab; Understand hardware and software requirements for a forensics lab; Understand how to build security content, scripts, tools, or methods to enhance forensic processes; Understand how to document the electronic crime scene; Understand search and seizure procedures; Understand evidence preservation techniques; Understand data acquisition methods; Understand case analysis procedures; Understand reporting procedures; Understand how to testify as an expert witness
3.0 Understanding Hard Disks and File Systems
Weight not published
- 3.1Disk Drives and their Characteristics
Understand hard disk drive characteristics; Understand solid-state drive (SSD) characteristics; Understand disk interfaces; Understand the logical structure of disks; Understand the boot process of Windows, Linux, and macOS operating systems; Understand the file systems of Windows, Linux, and macOS operating systems; Understand file system analysis techniques; Understand storage systems; Understand encoding standards and hex editors; Analyze popular file formats
4.0 Data Acquisition and Duplication
Weight not published
5.0 Defeating Anti-Forensics Techniques
Weight not published
- 5.1Anti-Forensics Techniques
Understand the challenges posed by anti-forensics techniques; Understand data/file deletion techniques; Understand recycle bin forensics; Understand file carving techniques; Understand ways to recover evidence from deleted partitions; Understand password cracking/bypassing techniques; Understand steganography, hidden data in file system structures, trail obfuscation, and file extension mismatch; Understand artifact wiping techniques; Understand overwritten data/metadata detection techniques; Understand encryption techniques; Understand program packers and footprint minimizing techniques
6.0 Windows Forensics
Weight not published
- 6.1Windows Forensics
Understand the methodology for Windows forensics; Understand how to collect volatile information; Understand how to collect non-volatile information; Understand how to collect Windows domain information; Understand how to examine compressed files; Understand Windows memory analysis techniques; Understand Windows registry analysis techniques; Understand Electron application analysis techniques; Understand web browser forensics techniques; Understand how to examine Windows files and metadata; Understand ShellBags, LNK files, and Jump Lists; Understand text-based logs and Windows event logs; Understand Windows forensics tools
7.0 Linux and Mac Forensics
Weight not published
8.0 Network Forensics
Weight not published
9.0 Malware Forensics
Weight not published
10.0 Investigating Web Attacks
Weight not published
11.0 Dark Web Forensics
Weight not published
12.0 Cloud Forensics
Weight not published
13.0 Email and Social Media Forensics
Weight not published
14.0 Mobile Forensics
Weight not published
15.0 IoT Forensics
Weight not published