This guide covers the official exam objectives for the CHFI certification, focusing on computer forensics investigation, evidence handling, and analysis techniques.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
15 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery 312-49term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guideOverview of Computer Forensics and Investigation Process
Objective 1.1 · Understand the fundamental concepts of computer forensics and the investigation process.
Legal and Ethical Issues in Digital Forensics
Objective 1.2 · Identify legal principles, ethics, and regulatory compliance in digital forensics.
Evidence Handling and Chain of Custody
Objective 2.1 · Explain proper evidence collection, preservation, and chain of custody procedures.
Forensic Investigation Process and Methodology
Objective 2.2 · Describe the systematic approach to conducting a forensic investigation.
Data Acquisition and Duplication Techniques
Objective 3.1 · Understand data acquisition methods, tools, and best practices for creating forensic images.
Forensic Tools and Laboratory Setup
Objective 4.1 · Describe common forensic tools and the requirements for a forensic laboratory.
Windows Forensics: File Systems and Artifacts
Objective 5.1 · Analyze the Windows operating system for forensic evidence including file systems, registry, and logs.
Linux and Mac Forensics
Objective 5.2 · Apply forensic analysis techniques to Linux and Mac OS environments.
Network Forensics: Logs, Traffic, and Attacks
Objective 6.1 · Investigate network-related incidents by analyzing logs, traffic captures, and intrusion patterns.
Investigating Web Attacks and Email Crimes
Objective 6.2 · Conduct investigations of web application attacks and email-related crimes.
Database Forensics: Investigating Data Breaches
Objective 7.1 · Perform forensic analysis of databases to identify unauthorized access and data tampering.
Mobile Device Forensics: iOS and Android
Objective 7.2 · Extract and analyze forensic evidence from mobile devices including iOS and Android platforms.
Cloud Forensics: Challenges and Techniques
Objective 8.1 · Identify the unique challenges and forensic techniques for investigating cloud environments.
Malware Forensics: Reverse Engineering and Analysis
Objective 8.2 · Apply forensics to malware incidents using reverse engineering and static/dynamic analysis.
Reporting, Documentation, and Expert Testimony
Objective 9.1 · Create professional forensic reports and prepare for presenting findings in court.
Free 312-49 practice questions with full explanations. Test what you learn chapter by chapter.
312-49 Practice Questions