C)DFE logo
Focused certification exam prep
Start practice

C)DFE Exam Domains 2026: Complete Guide to All 17 Content Areas

TL;DR
  • The C)DFE from Mile2 maps to 17 course modules; these are unweighted preparation categories, not an official weighted blueprint.
  • The exam is 100 multiple-choice questions in about two hours, with a 70% minimum passing score.
  • Mile2 publishes no highest-weighted domain, so spread study time rather than betting on one area.
  • Coverage spans Windows, Linux, macOS, live acquisition, cloud, mobile, IoT, eDiscovery, lab protocols and courtroom reporting.

What the 17 Content Areas Actually Are

The Certified Digital Forensics Examiner (C)DFE) credential is issued by Mile2 Cybersecurity Institute. Its current official six-page course outline lists 17 modules, and this guide treats each one as a content area. One point of precision up front: Mile2's materials do not publish a numbered exam version or weighted exam domains. The 17 headings below are the course modules that prepare you for the exam. They are a sensible, unweighted map of preparation scope, not a guaranteed list of what appears on test day or in what proportion.

That distinction shapes how you should study. Since no domain is officially identified as the heaviest, a candidate who over-invests in a favorite area, say Windows event logs, and neglects lab protocols or legal admissibility is taking an unnecessary risk. For a broader orientation to the credential itself, see What Is C)DFE Certification? and the companion C)DFE Study Guide 2026.

Scope note: The seventeen labs in the Mile2 course support learning. They do not establish a separately scored practical examination. The certification exam itself is described as multiple choice.

Format, Fees and Delivery

Before diving into the domains, it helps to know the container they arrive in. The facts below come from Mile2's current course outline and sponsor materials.

ItemWhat Mile2 Publishes
Question format100 multiple-choice questions
Time limitAbout 2 hours, no pause
Minimum passing score70%
DeliveryOnline through your Mile2 Learning Management System account; standard exams generally do not require a live-proctor appointment
Technical needsCurrent Chrome browser and a stable Internet connection
Exam feeMile2's sponsor-authored Udemy description (updated January 2026) states USD 400; the current direct checkout price is unconfirmed
Exam ComboPer Mile2's FAQ, includes the guide, a practice simulator and two attempts
Voucher validityOne year
Suggested backgroundOne year of computer experience, the C)SP course and Foundational Course Pack; exam purchase without training is allowed

Several details are not publicly verified: the split between scored and unscored questions, whether the exam is open-book, calculator policy, and whether it is adaptive. Do not assume any of these. The candidate pass rate is also not publicly disclosed, so be skeptical of any figure you see quoted; our C)DFE pass rate analysis explains what can and cannot be known. For the money side, the C)DFE certification cost breakdown covers fee mechanics in more detail, and C)DFE requirements addresses eligibility.

Foundations: Incidents, Theory, Prerequisites and Process (Domains 1-5)

The first five modules build the vocabulary and legal-procedural frame that every later technical topic depends on. Candidates with strong hands-on skills sometimes treat these as "soft" material and skim them. That is a mistake, because exam questions on process and admissibility reward precise terminology.

Domain 1: Computer Forensics Incidents

Establishes what digital forensics is for and where it came from.

  • Origins of digital forensic science
  • The legal system in which examinations operate
  • Types of cybercrime incidents
  • Internal versus external threats

Domain 2: Computer Forensic Investigative Theory

The conceptual layer behind how examiners reason about evidence.

  • Investigative theory and investigative concepts
  • Behavioral evidence analysis (BEA)
  • Equivocal Forensic Analysis (EFA)

BEA and EFA are the distinctive items here. Be able to explain what each is for and how it differs from simply running a tool and reading its output.

Domain 3: Computer Forensic Prerequisites and Standards

What must be in place before and during an investigation.

  • Investigative prerequisites
  • Scene management
  • Industry standards

Mile2 training references NIST 800-101 and ISO/IEC 27037 as published context. Know what kinds of guidance these represent rather than memorizing revision details, which should not be assumed.

Domain 4: Computer Forensic Investigative Process

The longest process module, and one worth knowing in sequence.

  • Foundations of the digital forensics process
  • Identification and scope
  • Collection and preservation
  • Examination
  • Analysis and interpretation
  • Documentation and interim reporting
  • Quality control and review

Domain 5: Forensic Examination/Evidence Protocols

How science and law meet at the evidence itself.

  • Science applied to forensics
  • Digital evidence categories
  • Evidence admissibility
Why the process domain pays off: The seven phases in Domain 4 recur everywhere. Live acquisition (Domain 8), lab protocols (Domain 16) and reporting (Domain 17) all assume you already think in terms of preservation, documentation and review. Master the sequence once and later modules feel like applications of it.

Tools, Storage and Live Acquisition (Domains 6-8)

This block is where the exam moves from "what and why" to "how." Expect scenario-style questions that ask which acquisition approach or storage consideration fits a situation.

Domain 6: Digital Acquisition and Analysis Tools

  • Acquisition procedures
  • The Computer Forensics Field Triage Process Model (CFFTPM)
  • Evidence authentication
  • Forensic tools
  • AI and forensics

Commercial tools appear as training context. Learn what categories of tools do and why authentication (verifying that an acquired image matches its source) matters, rather than memorizing feature lists that change between releases.

Domain 7: Disks and Storages

  • Disk, operating system and filesystem fundamentals
  • Spinning disk forensics
  • SSD forensics (with an IoT mention)
  • Cloud storage
  • Handling damaged drives

Pay attention to the contrast between spinning disks and SSDs. The two behave differently for recovery and preservation, and exam questions commonly probe that difference.

Domain 8: Live Acquisitions

  • Live acquisition concepts
  • Windows acquisition
  • macOS acquisition
  • Linux/UNIX acquisition
  • Cloud and virtualization acquisition

The central judgment call is when a live acquisition is appropriate versus powering a system down. Know what volatile evidence you gain and what you risk altering.

Operating System Forensics and Artifact Recovery (Domains 9-13)

These five modules form the technical core. Windows, Linux and macOS each get a dedicated module, followed by cross-platform artifact recovery and search techniques.

Domain 9: Windows Forensics

  • Windows Event Viewer overview
  • EVTX and EVT log formats
  • Log analysis to identify breaches and attacks

The outline's emphasis is on event logs. Practice reading logs with a question in mind ("what would indicate unauthorized access?") instead of just recognizing the file formats.

Domain 10: Linux Forensics

  • Linux artifacts: file system structure
  • Basic identifiers
  • Common log files

Domain 11: MAC Forensics

  • OSX artifacts: file system structure
  • Default apps
  • Other artifacts

Domain 12: Specialized Artifact Recovery

  • Windows components with investigative interest
  • Files containing historical information
  • Web forensics
  • Memory forensics

Domain 13: Advanced Search Strings and File Signatures

  • Search strings
  • Regular expressions (REGEX)
  • File signatures: formats, headers and hex analysis

This is among the most concrete topics in the outline. Being able to recognize a file type from its header bytes, and to read a basic regular expression, are skills you can drill directly.

Key Takeaway

If you work mostly in one operating system, deliberately budget extra time for the other two. Domains 9, 10 and 11 are separate modules, and a Windows specialist who skips Linux and macOS artifacts leaves two full content areas thin. The C)DFE difficulty guide discusses where candidates tend to feel the gaps.

Mobile Forensics and eDiscovery (Domains 14-15)

Domain 14: Mobile Forensics

  • The mobile forensic process
  • Tools
  • IoT and wearables
  • Legal considerations

Note the legal-considerations item. Mobile devices raise distinct questions about authorization and scope, so expect crossover with the admissibility themes from Domains 1 and 5.

Domain 15: eDiscovery

  • eDiscovery fundamentals
  • Laws and regulations
  • The eDiscovery process

eDiscovery is the most litigation-oriented module. It is the natural bridge between technical examination and legal workflow, and it matters for candidates targeting corporate legal, compliance or consulting roles. See C)DFE jobs for how these skills show up in hiring.

Laboratory Protocols and Evidence Presentation (Domains 16-17)

The final two modules cover the operational and courtroom ends of the work, and they are easy to underestimate because they involve fewer tools.

Domain 16: Computer Forensic Laboratory Protocols

  • Forensics workstation preparation
  • Laboratory standard operating procedures
  • Quality assurance and quality control
  • Peer review and annual review
  • Deviations
  • Lab intake

Learn the distinction between quality assurance and quality control, and what a documented deviation is for. These are the sort of definitional distinctions multiple-choice questions favor.

Domain 17: Digital Evidence Presentation and Reporting

  • The best evidence rule
  • Hearsay
  • Authenticity and alteration
  • Report sections and content

This module ties the whole course together: everything you acquired, preserved and analyzed must survive challenges to authenticity and alteration, and be communicated in a structured report.

Evidence integrity as a thread: Authentication in Domain 6, preservation in Domain 4, admissibility in Domain 5 and authenticity in Domain 17 are the same concern viewed from different angles. When a question seems to span modules, ask what it implies about proving the evidence has not changed.

Sequencing the 17 Areas Across Your Prep

Because no weighting is published, an even-coverage plan is the defensible choice. One reasonable ordering follows the logic of the investigation itself, which is also the order the course follows. Adjust the pace to your background.

Week 1

Frame and process (Domains 1-5)

  • Learn the Domain 4 phases in order
  • Define BEA, EFA, admissibility and evidence categories
Week 2

Acquisition and storage (Domains 6-8)

  • Compare spinning disk and SSD behavior
  • Decide live versus dead acquisition for sample scenarios
Week 3

Platforms and artifacts (Domains 9-13)

  • Read Windows event logs against a question
  • Practice file signatures and basic REGEX
Week 4

Mobile, legal and lab (Domains 14-17)

  • Review eDiscovery process and laws
  • Practice best evidence and hearsay distinctions

Then use timed practice questions to find weak modules and loop back. The 2-hour, 100-question format rewards pacing, so rehearse under the same time pressure. The C)DFE cheat sheet is useful for last-pass review of the terminology-heavy modules.

After You Pass: Validity and Renewal

The certification is valid for 3 years. Mile2's published renewal fee is USD 200 for the U.S. region, potentially USD 100 for eligible developing regions. Renewal options described in Mile2's renewal policy include 60 documented CEUs over the cycle with an ethics and policies acknowledgment and fee, or a qualifying examination-based route.

The course PDF words this differently, listing a three-year expiration with passing the current exam and submitting 20 CEUs per year as requirements. These sources are worded differently, so check Mile2's current renewal policy directly. The optional five-day course earns 40 CEUs, but that alone should not be assumed to renew the credential. For return on investment, see Is the C)DFE worth it? and the C)DFE salary guide.

Frequently Asked Questions

Are the 17 domains weighted on the C)DFE exam?

Mile2 does not publish weights. The 17 headings are course modules used as unweighted preparation categories, and the highest-weighted area is unknown. Plan to cover all of them.

How many questions and what score do I need?

The exam is 100 multiple-choice questions in about two hours, with a minimum 70% passing score. The scored versus unscored split is not disclosed. See the C)DFE passing score guide.

Do I need the course before taking the exam?

No. Mile2 allows the exam to be purchased without training, though it suggests one year of computer experience, the C)SP course and the Foundational Course Pack as background.

Is there a hands-on practical portion?

The course includes seventeen labs, but they support learning and do not establish a separately scored practical exam. The certification exam is described as multiple choice.

Where do I take the exam and how is it scheduled?

It is delivered online through your Mile2 account, and standard exams generally do not require a live-proctor appointment. Check the C)DFE exam dates guide for scheduling context, and remember the voucher is valid for one year.

Ready to pass your C)DFE exam?

Put this into practice with free C)DFE questions across every exam domain.