- What the 17 Content Areas Actually Are
- Format, Fees and Delivery
- Foundations: Incidents, Theory, Prerequisites and Process (Domains 1-5)
- Tools, Storage and Live Acquisition (Domains 6-8)
- Operating System Forensics and Artifact Recovery (Domains 9-13)
- Mobile Forensics and eDiscovery (Domains 14-15)
- Laboratory Protocols and Evidence Presentation (Domains 16-17)
- Sequencing the 17 Areas Across Your Prep
- After You Pass: Validity and Renewal
- Frequently Asked Questions
- The C)DFE from Mile2 maps to 17 course modules; these are unweighted preparation categories, not an official weighted blueprint.
- The exam is 100 multiple-choice questions in about two hours, with a 70% minimum passing score.
- Mile2 publishes no highest-weighted domain, so spread study time rather than betting on one area.
- Coverage spans Windows, Linux, macOS, live acquisition, cloud, mobile, IoT, eDiscovery, lab protocols and courtroom reporting.
What the 17 Content Areas Actually Are
The Certified Digital Forensics Examiner (C)DFE) credential is issued by Mile2 Cybersecurity Institute. Its current official six-page course outline lists 17 modules, and this guide treats each one as a content area. One point of precision up front: Mile2's materials do not publish a numbered exam version or weighted exam domains. The 17 headings below are the course modules that prepare you for the exam. They are a sensible, unweighted map of preparation scope, not a guaranteed list of what appears on test day or in what proportion.
That distinction shapes how you should study. Since no domain is officially identified as the heaviest, a candidate who over-invests in a favorite area, say Windows event logs, and neglects lab protocols or legal admissibility is taking an unnecessary risk. For a broader orientation to the credential itself, see What Is C)DFE Certification? and the companion C)DFE Study Guide 2026.
Format, Fees and Delivery
Before diving into the domains, it helps to know the container they arrive in. The facts below come from Mile2's current course outline and sponsor materials.
| Item | What Mile2 Publishes |
|---|---|
| Question format | 100 multiple-choice questions |
| Time limit | About 2 hours, no pause |
| Minimum passing score | 70% |
| Delivery | Online through your Mile2 Learning Management System account; standard exams generally do not require a live-proctor appointment |
| Technical needs | Current Chrome browser and a stable Internet connection |
| Exam fee | Mile2's sponsor-authored Udemy description (updated January 2026) states USD 400; the current direct checkout price is unconfirmed |
| Exam Combo | Per Mile2's FAQ, includes the guide, a practice simulator and two attempts |
| Voucher validity | One year |
| Suggested background | One year of computer experience, the C)SP course and Foundational Course Pack; exam purchase without training is allowed |
Several details are not publicly verified: the split between scored and unscored questions, whether the exam is open-book, calculator policy, and whether it is adaptive. Do not assume any of these. The candidate pass rate is also not publicly disclosed, so be skeptical of any figure you see quoted; our C)DFE pass rate analysis explains what can and cannot be known. For the money side, the C)DFE certification cost breakdown covers fee mechanics in more detail, and C)DFE requirements addresses eligibility.
Foundations: Incidents, Theory, Prerequisites and Process (Domains 1-5)
The first five modules build the vocabulary and legal-procedural frame that every later technical topic depends on. Candidates with strong hands-on skills sometimes treat these as "soft" material and skim them. That is a mistake, because exam questions on process and admissibility reward precise terminology.
Domain 1: Computer Forensics Incidents
Establishes what digital forensics is for and where it came from.
- Origins of digital forensic science
- The legal system in which examinations operate
- Types of cybercrime incidents
- Internal versus external threats
Domain 2: Computer Forensic Investigative Theory
The conceptual layer behind how examiners reason about evidence.
- Investigative theory and investigative concepts
- Behavioral evidence analysis (BEA)
- Equivocal Forensic Analysis (EFA)
BEA and EFA are the distinctive items here. Be able to explain what each is for and how it differs from simply running a tool and reading its output.
Domain 3: Computer Forensic Prerequisites and Standards
What must be in place before and during an investigation.
- Investigative prerequisites
- Scene management
- Industry standards
Mile2 training references NIST 800-101 and ISO/IEC 27037 as published context. Know what kinds of guidance these represent rather than memorizing revision details, which should not be assumed.
Domain 4: Computer Forensic Investigative Process
The longest process module, and one worth knowing in sequence.
- Foundations of the digital forensics process
- Identification and scope
- Collection and preservation
- Examination
- Analysis and interpretation
- Documentation and interim reporting
- Quality control and review
Domain 5: Forensic Examination/Evidence Protocols
How science and law meet at the evidence itself.
- Science applied to forensics
- Digital evidence categories
- Evidence admissibility
Tools, Storage and Live Acquisition (Domains 6-8)
This block is where the exam moves from "what and why" to "how." Expect scenario-style questions that ask which acquisition approach or storage consideration fits a situation.
Domain 6: Digital Acquisition and Analysis Tools
- Acquisition procedures
- The Computer Forensics Field Triage Process Model (CFFTPM)
- Evidence authentication
- Forensic tools
- AI and forensics
Commercial tools appear as training context. Learn what categories of tools do and why authentication (verifying that an acquired image matches its source) matters, rather than memorizing feature lists that change between releases.
Domain 7: Disks and Storages
- Disk, operating system and filesystem fundamentals
- Spinning disk forensics
- SSD forensics (with an IoT mention)
- Cloud storage
- Handling damaged drives
Pay attention to the contrast between spinning disks and SSDs. The two behave differently for recovery and preservation, and exam questions commonly probe that difference.
Domain 8: Live Acquisitions
- Live acquisition concepts
- Windows acquisition
- macOS acquisition
- Linux/UNIX acquisition
- Cloud and virtualization acquisition
The central judgment call is when a live acquisition is appropriate versus powering a system down. Know what volatile evidence you gain and what you risk altering.
Operating System Forensics and Artifact Recovery (Domains 9-13)
These five modules form the technical core. Windows, Linux and macOS each get a dedicated module, followed by cross-platform artifact recovery and search techniques.
Domain 9: Windows Forensics
- Windows Event Viewer overview
- EVTX and EVT log formats
- Log analysis to identify breaches and attacks
The outline's emphasis is on event logs. Practice reading logs with a question in mind ("what would indicate unauthorized access?") instead of just recognizing the file formats.
Domain 10: Linux Forensics
- Linux artifacts: file system structure
- Basic identifiers
- Common log files
Domain 11: MAC Forensics
- OSX artifacts: file system structure
- Default apps
- Other artifacts
Domain 12: Specialized Artifact Recovery
- Windows components with investigative interest
- Files containing historical information
- Web forensics
- Memory forensics
Domain 13: Advanced Search Strings and File Signatures
- Search strings
- Regular expressions (REGEX)
- File signatures: formats, headers and hex analysis
This is among the most concrete topics in the outline. Being able to recognize a file type from its header bytes, and to read a basic regular expression, are skills you can drill directly.
Key Takeaway
If you work mostly in one operating system, deliberately budget extra time for the other two. Domains 9, 10 and 11 are separate modules, and a Windows specialist who skips Linux and macOS artifacts leaves two full content areas thin. The C)DFE difficulty guide discusses where candidates tend to feel the gaps.
Mobile Forensics and eDiscovery (Domains 14-15)
Domain 14: Mobile Forensics
- The mobile forensic process
- Tools
- IoT and wearables
- Legal considerations
Note the legal-considerations item. Mobile devices raise distinct questions about authorization and scope, so expect crossover with the admissibility themes from Domains 1 and 5.
Domain 15: eDiscovery
- eDiscovery fundamentals
- Laws and regulations
- The eDiscovery process
eDiscovery is the most litigation-oriented module. It is the natural bridge between technical examination and legal workflow, and it matters for candidates targeting corporate legal, compliance or consulting roles. See C)DFE jobs for how these skills show up in hiring.
Laboratory Protocols and Evidence Presentation (Domains 16-17)
The final two modules cover the operational and courtroom ends of the work, and they are easy to underestimate because they involve fewer tools.
Domain 16: Computer Forensic Laboratory Protocols
- Forensics workstation preparation
- Laboratory standard operating procedures
- Quality assurance and quality control
- Peer review and annual review
- Deviations
- Lab intake
Learn the distinction between quality assurance and quality control, and what a documented deviation is for. These are the sort of definitional distinctions multiple-choice questions favor.
Domain 17: Digital Evidence Presentation and Reporting
- The best evidence rule
- Hearsay
- Authenticity and alteration
- Report sections and content
This module ties the whole course together: everything you acquired, preserved and analyzed must survive challenges to authenticity and alteration, and be communicated in a structured report.
Sequencing the 17 Areas Across Your Prep
Because no weighting is published, an even-coverage plan is the defensible choice. One reasonable ordering follows the logic of the investigation itself, which is also the order the course follows. Adjust the pace to your background.
Frame and process (Domains 1-5)
- Learn the Domain 4 phases in order
- Define BEA, EFA, admissibility and evidence categories
Acquisition and storage (Domains 6-8)
- Compare spinning disk and SSD behavior
- Decide live versus dead acquisition for sample scenarios
Platforms and artifacts (Domains 9-13)
- Read Windows event logs against a question
- Practice file signatures and basic REGEX
Mobile, legal and lab (Domains 14-17)
- Review eDiscovery process and laws
- Practice best evidence and hearsay distinctions
Then use timed practice questions to find weak modules and loop back. The 2-hour, 100-question format rewards pacing, so rehearse under the same time pressure. The C)DFE cheat sheet is useful for last-pass review of the terminology-heavy modules.
After You Pass: Validity and Renewal
The certification is valid for 3 years. Mile2's published renewal fee is USD 200 for the U.S. region, potentially USD 100 for eligible developing regions. Renewal options described in Mile2's renewal policy include 60 documented CEUs over the cycle with an ethics and policies acknowledgment and fee, or a qualifying examination-based route.
The course PDF words this differently, listing a three-year expiration with passing the current exam and submitting 20 CEUs per year as requirements. These sources are worded differently, so check Mile2's current renewal policy directly. The optional five-day course earns 40 CEUs, but that alone should not be assumed to renew the credential. For return on investment, see Is the C)DFE worth it? and the C)DFE salary guide.
Frequently Asked Questions
Mile2 does not publish weights. The 17 headings are course modules used as unweighted preparation categories, and the highest-weighted area is unknown. Plan to cover all of them.
The exam is 100 multiple-choice questions in about two hours, with a minimum 70% passing score. The scored versus unscored split is not disclosed. See the C)DFE passing score guide.
No. Mile2 allows the exam to be purchased without training, though it suggests one year of computer experience, the C)SP course and the Foundational Course Pack as background.
The course includes seventeen labs, but they support learning and do not establish a separately scored practical exam. The certification exam is described as multiple choice.
It is delivered online through your Mile2 account, and standard exams generally do not require a live-proctor appointment. Check the C)DFE exam dates guide for scheduling context, and remember the voucher is valid for one year.