Courseiva
312-49Free Study Guide

EC-Council Computer Hacking Forensic Investigator (CHFI)The Complete Beginner's Guide

This guide covers the official exam objectives for the CHFI certification, focusing on computer forensics investigation, evidence handling, and analysis techniques.

15 chapters
~3 hours total read
Free — no signup required
By Johnson Ajibi · Senior Network & Security Engineer · MSc IT Security

How to use this guide

This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.

① Read a chapter② Answer practice questions③ Review missed answers④ Repeat
Study Chapters

15 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.

Start Chapter 1
Practice Questions

Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.

Go to practice test
Glossary

Every 312-49term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.

Browse glossary
Exam Overview

Exam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.

View exam guide

Chapters — 312-49

1

Overview of Computer Forensics and Investigation Process

Objective 1.1 · Understand the fundamental concepts of computer forensics and the investigation process.

12m
2

Legal and Ethical Issues in Digital Forensics

Objective 1.2 · Identify legal principles, ethics, and regulatory compliance in digital forensics.

12m
3

Evidence Handling and Chain of Custody

Objective 2.1 · Explain proper evidence collection, preservation, and chain of custody procedures.

12m
4

Forensic Investigation Process and Methodology

Objective 2.2 · Describe the systematic approach to conducting a forensic investigation.

12m
5

Data Acquisition and Duplication Techniques

Objective 3.1 · Understand data acquisition methods, tools, and best practices for creating forensic images.

12m
6

Forensic Tools and Laboratory Setup

Objective 4.1 · Describe common forensic tools and the requirements for a forensic laboratory.

12m
7

Windows Forensics: File Systems and Artifacts

Objective 5.1 · Analyze the Windows operating system for forensic evidence including file systems, registry, and logs.

12m
8

Linux and Mac Forensics

Objective 5.2 · Apply forensic analysis techniques to Linux and Mac OS environments.

12m
9

Network Forensics: Logs, Traffic, and Attacks

Objective 6.1 · Investigate network-related incidents by analyzing logs, traffic captures, and intrusion patterns.

12m
10

Investigating Web Attacks and Email Crimes

Objective 6.2 · Conduct investigations of web application attacks and email-related crimes.

12m
11

Database Forensics: Investigating Data Breaches

Objective 7.1 · Perform forensic analysis of databases to identify unauthorized access and data tampering.

12m
12

Mobile Device Forensics: iOS and Android

Objective 7.2 · Extract and analyze forensic evidence from mobile devices including iOS and Android platforms.

12m
13

Cloud Forensics: Challenges and Techniques

Objective 8.1 · Identify the unique challenges and forensic techniques for investigating cloud environments.

12m
14

Malware Forensics: Reverse Engineering and Analysis

Objective 8.2 · Apply forensics to malware incidents using reverse engineering and static/dynamic analysis.

12m
15

Reporting, Documentation, and Expert Testimony

Objective 9.1 · Create professional forensic reports and prepare for presenting findings in court.

12m

Ready to test your knowledge?

Free 312-49 practice questions with full explanations. Test what you learn chapter by chapter.

312-49 Practice Questions