Computer Hacking Forensic Investigator (CHFI) (312-49) Exam Blueprint

312-49

150Questions
240 minDuration
70/60-85%Passing Score
$500Price
3 yearsValid For
1Languages
Practice Computer Hacking Forensic Investigator (CHFI) on QuizForge

Exam Domains

1.0 Computer Forensics in Today’s World Weight not published
  • 1.1Fundamentals of Computer Forensics
    Understand the scope of computer forensics; Identify types of cybercrimes; Understand cyber attribution; Understand cybercrime investigation procedures; Understand the role of digital evidence; Understand sources of potential evidence; Understand federal rules of evidence; Understand forensic readiness and business continuity; Understand the incident response process flow; Understand the role of artificial intelligence in computer forensics; Understand forensic automation and orchestration; Understand the roles and responsibilities of a forensic investigator; Understand the code of ethics; Understand the challenges posed by cybercrimes to investigators; Understand ISO standards; Understand computer forensics and legal compliance
2.0 Computer Forensics Investigation Process Weight not published
  • 2.1Forensic Investigation Process and its Importance
    Understand the phases involved in the computer forensics investigation process; Understand first response procedures; Understand the roles of first responders; Understand first response in different situations; Understand how to set up a computer forensics lab; Understand hardware and software requirements for a forensics lab; Understand how to build security content, scripts, tools, or methods to enhance forensic processes; Understand how to document the electronic crime scene; Understand search and seizure procedures; Understand evidence preservation techniques; Understand data acquisition methods; Understand case analysis procedures; Understand reporting procedures; Understand how to testify as an expert witness
3.0 Understanding Hard Disks and File Systems Weight not published
  • 3.1Disk Drives and their Characteristics
    Understand hard disk drive characteristics; Understand solid-state drive (SSD) characteristics; Understand disk interfaces; Understand the logical structure of disks; Understand the boot process of Windows, Linux, and macOS operating systems; Understand the file systems of Windows, Linux, and macOS operating systems; Understand file system analysis techniques; Understand storage systems; Understand encoding standards and hex editors; Analyze popular file formats
4.0 Data Acquisition and Duplication Weight not published
  • 4.1Data Acquisition
    Understand live acquisition techniques; Understand dead acquisition techniques; Understand data acquisition formats; Understand eDiscovery collection methodologies; Understand eDiscovery tools; Understand how to determine the data acquisition method; Understand how to select data acquisition tools; Understand how to sanitize target media; Understand how to acquire volatile data; Understand how to enable write protection on evidence media; Understand how to acquire non-volatile data; Understand contingency planning; Understand how to validate data acquisition; Understand how to prepare an image for examination; Understand digital forensic imaging tools
5.0 Defeating Anti-Forensics Techniques Weight not published
  • 5.1Anti-Forensics Techniques
    Understand the challenges posed by anti-forensics techniques; Understand data/file deletion techniques; Understand recycle bin forensics; Understand file carving techniques; Understand ways to recover evidence from deleted partitions; Understand password cracking/bypassing techniques; Understand steganography, hidden data in file system structures, trail obfuscation, and file extension mismatch; Understand artifact wiping techniques; Understand overwritten data/metadata detection techniques; Understand encryption techniques; Understand program packers and footprint minimizing techniques
6.0 Windows Forensics Weight not published
  • 6.1Windows Forensics
    Understand the methodology for Windows forensics; Understand how to collect volatile information; Understand how to collect non-volatile information; Understand how to collect Windows domain information; Understand how to examine compressed files; Understand Windows memory analysis techniques; Understand Windows registry analysis techniques; Understand Electron application analysis techniques; Understand web browser forensics techniques; Understand how to examine Windows files and metadata; Understand ShellBags, LNK files, and Jump Lists; Understand text-based logs and Windows event logs; Understand Windows forensics tools
7.0 Linux and Mac Forensics Weight not published
  • 7.1Linux and Mac Forensics
    Understand how to collect volatile information in Linux; Understand how to collect non-volatile information in Linux; Understand Linux memory forensics techniques; Understand Mac forensics data; Understand Mac log files; Understand Mac directories; Understand Mac memory forensics techniques; Understand APFS analysis techniques; Understand how to parse metadata on Spotlight; Understand Mac forensics tools
8.0 Network Forensics Weight not published
  • 8.1Network Forensics
    Understand postmortem and real-time analysis techniques; Understand types of network-based evidence; Understand types of event correlation; Understand event correlation approaches; Understand how to analyze firewall logs; Understand how to analyze IDS logs; Understand how to analyze honeypot logs; Understand how to analyze router logs; Understand how to analyze DHCP logs; Understand how to analyze Cisco switch logs; Understand how to analyze VPN logs; Understand how to analyze DNS server logs; Understand network log analysis tools; Understand how to analyze traffic for network attacks; Understand tools for investigating network traffic; Understand SIEM solutions; Understand how to examine network attacks; Understand types of wireless evidence; Understand wireless network forensics processes; Understand how to detect rogue access points; Understand how to analyze wireless packet captures; Understand how to analyze Wi-Fi spectrum; Understand tools for investigating wireless network traffic
9.0 Malware Forensics Weight not published
  • 9.1Malware Forensics
    Understand different ways for malware to enter a system; Understand components of malware; Understand malware forensic artifacts; Understand how to set up a controlled malware analysis lab; Understand malware analysis tools; Understand types of malware analysis; Understand static malware analysis techniques; Understand system behavior analysis techniques; Understand network behavior analysis techniques; Understand ransomware analysis techniques
10.0 Investigating Web Attacks Weight not published
  • 10.1Web Application Forensics
    Understand indicators of a web attack; Understand OWASP Top 10 Application Security Risks (2021); Understand web attack investigation methodology; Understand IIS Web Server Architecture; Understand how to analyze IIS logs; Understand IIS log analysis tools; Understand Apache Web Server Logs; Understand Apache access logs; Understand Apache error logs; Understand Apache log analysis tools; Understand how to investigate cross-site scripting (XSS) attacks; Understand how to investigate SQL injection attacks; Understand how to investigate path/directory traversal attacks; Understand how to investigate command injection attacks; Understand how to investigate XML external entity (XXE) attacks; Understand how to investigate brute-force attacks
11.0 Dark Web Forensics Weight not published
  • 11.1Dark Web and Dark Web Forensics
    Understand how to work with the Tor Browser; Understand dark web forensics; Understand how to identify Tor Browser artifacts; Understand Tor Browser forensics; Understand memory dump analysis techniques; Understand how to perform forensic analysis of memory dumps to examine email artifacts
12.0 Cloud Forensics Weight not published
  • 12.1Cloud Forensics
    Understand types of cloud computing services; Understand separation of responsibilities in the cloud; Understand OWASP Top 10 Cloud Security Risks; Understand uses of cloud forensics; Understand data storage in AWS; Understand logs in AWS; Understand forensic acquisition of Amazon EC2 instances; Understand data storage in Azure; Understand logs in Azure; Understand forensic acquisition of VMs in Azure; Understand data storage in Google Cloud; Understand logs in Google Cloud; Understand forensic acquisition of persistent disk volumes in GCP; Understand how to investigate Google Cloud security incidents; Understand how to investigate Google Cloud container security incidents; Understand how to investigate Google Cloud VM-based security incidents
13.0 Email and Social Media Forensics Weight not published
  • 13.1Email Basics
    Understand components involved in email communication; Understand parts of an email message; Understand steps to investigate email crimes; Understand U.S. laws against email crime; Understand social media crimes; Understand how to extract footage from social media platforms; Understand how to track social media user activities; Understand how to construct and analyze social network graphs; Understand social media forensics tools
14.0 Mobile Forensics Weight not published
  • 14.1Mobile Device Forensics
    Understand mobile device forensics; Understand OWASP Top 10 Mobile Risks; Understand Android OS architecture; Understand iOS architecture; Understand the mobile forensics process; Understand the Android forensics process; Understand the iOS forensics process; Understand cell site analysis; Understand Android file systems; Understand iOS file systems; Understand how to bypass locked Android devices; Understand how to access root files in Android; Understand how to jailbreak iOS devices; Understand logical acquisition techniques; Understand cloud data acquisition on Android and iOS devices; Understand physical acquisition techniques; Understand JTAG forensics; Understand flasher boxes; Understand static analysis and dynamic analysis of Android package kits (APK); Understand Android log analysis tools; Understand how to collect WhatsApp artifacts from Android devices; Understand how to analyze iOS Safari artifacts; Understand how to analyze iOS keychains; Understand iOS forensic analysis
15.0 IoT Forensics Weight not published
  • 15.1IoT Concepts
    Understand IoT architecture; Understand IoT security problems; Understand OWASP Top 10 IoT Threats; Understand IoT forensics process; Understand IoT forensics challenges; Understand wearable IoT devices: smartwatches; Understand IoT device forensics: smart speakers—Amazon Echo; Understand hardware-level analysis: JTAG and chip-off forensics; Understand how to extract and analyze data from drones/UAVs; Understand IoT forensics tools

Exam Details

Question TypesMultiple Choice
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, government-issued photo ID with full name and photo. ID must match the name used during registration.
RenewalRequired -- Earn 120 ECE (EC-Council Continuing Education) credits over 3-year cycle. ECE credits earned through courses, conferences, publications, or EC-Council activities.
Retake PolicyNo official waiting period specified between retakes. Full exam fee required for each retake.
LanguagesEnglish

Official Study Resources