Courseiva
Free · No account needed · No credit card

Computer Hacking Forensic Investigator CHFI Practice Test

745 questions with instant explanations, domain breakdown, and wrong-answer analysis. Built for the real exam.

Instant feedback after each answer
Full explanations included
Domain score breakdown
Real exam: 240 min
Pass mark: 700/1000

Sample questions with explanations

This is exactly what you see during practice — question, options, and a full explanation after you answer.

Q1Computer Forensics Fundamentals and Processeasy
Full explanation →

What is the primary goal of the chain of custody in a digital forensic investigation?

To maintain the integrity and admissibility of evidenceCorrect
BTo encrypt the evidence during transport
CTo speed up the forensic analysis process
DTo ensure that the forensic tools used are properly licensed

The chain of custody is a documented chronological record that tracks the seizure, custody, control, transfer, analysis, and disposition of digital evidence. Its primary goal is to maintain the integrity and admissibility of evidence by proving that the evidence has not been tamp…Read full explanation

Q2OS and File System Forensicshard
Full explanation →

A forensic analyst is examining a Windows 10 system and needs to determine the last boot time of the system. Which registry hive and key should the analyst query to find this information?

ANTUSER.DAT hive, key 'Control Panel\Desktop\'
SYSTEM hive, key 'CurrentControlSet\Control\Windows\', value 'ShutdownTime'Correct
CSOFTWARE hive, key 'Microsoft\Windows NT\CurrentVersion\'
DSAM hive, key 'SAM\Domains\Account\Users\'

The SYSTEM hive stores system-wide configuration data, and the key 'CurrentControlSet\Control\Windows\' contains the 'ShutdownTime' value, which records the last system shutdown time. Since the last boot time is effectively the time after the last shutdown, querying this value pr…Read full explanation

Q3Application, Email and Cloud Forensicsmedium
Full explanation →

Which of the following email headers is used to verify the domain of the sending server and is commonly used for authentication to prevent spoofing?

AContent-Type
BReceived
CX-Mailer
DKIM-SignatureCorrect

DKIM-Signature is the correct answer because it is an email authentication method that uses a digital signature to verify the domain of the sending server. It allows the receiver to check that the email was not forged or altered during transit, directly preventing domain spoofing…Read full explanation

Untimed Practice

Answer at your own pace. Explanation and domain tag shown immediately after each answer.

Timed Practice

Countdown timer starts immediately. Results and domain scores shown at the end — just like the real exam.

Why practice here?

Full explanations on every question

Not just the right answer — you get exactly why each wrong option is wrong, so you learn the concept, not the answer.

Domain score breakdown

After each session see your score by exam domain so you know exactly where to focus study time.

100% free, forever

No subscription, no trial, no email wall. Start a session in under 10 seconds.

Exam-style questions

Scenario-based, precise wording, realistic distractors — written to match what you actually see on exam day.

← All CHFI questionsCHFI exam guideStudy guidePractice by domain