Study Guide

How to Prepare for the EC-Council CHFI (312-49) Exam

Prepare for the EC-Council CHFI (312-49) exam with verified format facts, official blueprint domain weights, and a focused, source-backed study plan.

Updated September 202611 min readStudy GuideCEH Exam
Gabrielle Wallace

Gabrielle Wallace

CEH Exam Editorial Team

Prepare for CHFI by studying the six official blueprint domains in proportion to their weights, learning the investigation process and data acquisition methodology as the course teaches them, and attaching every tool you meet to the forensic task it performs. The exam is 150 multiple-choice questions over four hours, scored against a per-form cut score between 60% and 85%. This guide gives you the verified logistics, the domain map, two complete practice exercises, and the career and credential context, with all official requirements cited to EC-Council's own pages.

Exam format, scoring, and how you take it

CHFI exam 312-49 has 150 multiple-choice questions with a four-hour limit, delivered through EC-Council's ECC EXAM portal, with a cut score that can range from 60% to 85% depending on the exam form.

EC-Council lists the exam title as Computer Hacking Forensic Investigator, code 312-49, with 150 questions over four hours, available through the ECC EXAM portal. The certification is awarded after you pass this exam.

The passing standard is not one fixed number. EC-Council builds each exam form from a different question bank and sets a cut score per form, and those cut scores can range from 60% to 85%. Prudent preparation aims comfortably above the bottom of that band rather than gambling on an easier form.

Training runs in three formats: iLearn (self-study video), iWeek (live online, instructor-led), and in-person delivery through a training partner. EC-Council's own guidance is that you enroll in the training program and then complete the exam; enrollment also gives you the course materials, labs, and exam voucher. Check current pricing directly with EC-Council, because cost varies by the learning method you choose.

Sources used: CHFI Certification | Computer Hacking Forensic Investigator | EC-Council — Exam Details, Course Outline, and FAQ sections; Computer Hacking Forensic Investigator (EC-Council certification page) — Exam Information and CHFI Exam Details

Who the program is for and what background helps

CHFI targets IT and forensics professionals with basic knowledge of IT and cybersecurity, computer forensics, and incident response, including law enforcement, defense, systems administrators, and legal professionals.

EC-Council states that IT and forensics professionals should possess basic knowledge of IT and cybersecurity, computer forensics, and incident response to enroll in the CHFI program. This is background knowledge rather than a prior certification requirement, but the course moves quickly, so gaps in these fundamentals will slow you down.

The stated audience also includes police and other law enforcement personnel, defense and military staff, e-business security professionals, systems administrators, legal professionals, banking and insurance professionals, government agencies, and IT managers. If your background is outside that list, budget extra early study time on the forensics fundamentals module before attempting practice questions.

Sources used: CHFI Certification | Computer Hacking Forensic Investigator | EC-Council — Exam Details, Course Outline, and FAQ sections; Computer Hacking Forensic Investigator (EC-Council certification page) — Exam Information and CHFI Exam Details

The Blueprint v4 domains and where the weight sits

The official blueprint divides the exam into six domains; digital forensics work carries the most weight at 29%, followed by digital evidence at 18% and procedures and methodology at 17%.

EC-Council's CHFI Exam Blueprint v4 is the current published map of what the exam tests. It lists domains, sub-domains, question counts, and weightings. The weights below come straight from that document, so use them to budget your study time.

Two practical conclusions follow. First, the single heaviest domain is the digital forensics domain, which centers on reviewing anti-forensic techniques and defeating them, so anti-forensics is not an optional extra. Second, the three technical domains together account for 64% of the exam, since digital evidence (18%), procedures and methodology (17%), and digital forensics (29%) combine to nearly two-thirds, which is why this guide teaches the investigation process before the specialized evidence sources.

Blueprint domainWeight
1. Forensic Science (cybercrimes, investigator roles)15%
2. Regulations, Policies and Ethics (search and seizure, evidence)10%
3. Digital Evidence18%
4. Procedures and Methodology17%
5. Digital Forensics (anti-forensic techniques and analysis)29%
6. Tools/Systems/Programs11%

Sources used: CHFI Exam Blueprint v4 (EC-Council) — Domain weight table and sub-domain listings

The investigation process from first response to report

CHFI frames forensics as a repeatable process: first response, pre-investigation, investigation, and post-investigation phases, with a data acquisition methodology whose steps you should know as taught topics.

The curriculum walks the full sequence: first response and the first responder's role, documenting the electronic crime scene, search and seizure, evidence preservation, data acquisition, case analysis, reporting, and testifying as an expert witness. Learn the named phases and what changes at each one, because the process domain supports questions everywhere else in the blueprint.

The course's data acquisition methodology lists these steps: determine the data acquisition method, select the acquisition tool, sanitize the target media, acquire volatile data, enable write protection on the evidence media, acquire non-volatile data, plan for contingency, and validate the acquisition. Know what each step is for, and be able to explain the terms the blueprint names alongside it, such as live and dead acquisition and the order of volatility. This guide presents the steps as curriculum content to learn; it does not prescribe how you should act at an actual scene.

EC-Council also states that its official courseware is developed independently of exam content, so treat course modules as study material and the published blueprint as your scope authority. The exercise below rehearses the volatile and non-volatile distinction that the methodology's steps depend on.

Practice exercise

Using the definitions given in EC-Council's CHFI sample questions, classify each data item as volatile or non-volatile: (1) running process memory and the current process-to-port mapping, (2) documents stored on the computer's hard drive, (3) the current logged-on users and open files, (4) long-term persisting data held in secondary storage.

Show answer

Items 1 and 3 are volatile data; items 2 and 4 are non-volatile data.

EC-Council's CHFI sample questions define volatile data as items held in running system state, listing system time, logged-on users, open files, network information, process-to-port mapping, process memory, clipboard contents, and command history as examples. They define non-volatile data as long-term persisting data used for secondary storage. Documents on a hard drive are non-volatile even though their contents can change, because the classification follows where the data persists, not whether it changes.

Sources used: CHFI Certification | Computer Hacking Forensic Investigator | EC-Council — Exam Details, Course Outline, and FAQ sections; CHFI Exam Blueprint v4 (EC-Council) — Domain weight table and sub-domain listings; EC-Council candidate FAQ: exam preparation and blueprint updates — Exam Preparation:

Anti-forensics and disk evidence: study these first

The two heaviest domains cover anti-forensics techniques and their countermeasures, and digital evidence fundamentals from disk and SSD structure through logs, encoding, and file formats.

The 29% digital forensics domain centers on reviewing anti-forensic techniques and defeating them. The blueprint names the topics: data and file deletion and what happens when a file is deleted in Windows, the Recycle Bin, file carving, recovering deleted partitions, password protection and cracking, steganography, alternate data streams, trail obfuscation, artifact wiping, overwriting data and metadata, encryption, program packers, and exploiting or detecting forensics tools. Study each technique together with its detection countermeasure, since the blueprint pairs them deliberately.

The 18% digital evidence domain is the technical foundation for everything else. It covers hard disks and solid-state drives, the logical structure of disks, RAID and virtualization, NAS and SAN storage, disk interfaces, boot processes for Windows, macOS, and Linux, file systems across those operating systems, log types and event log structure, character encoding standards and hex editors, and analysis of common file formats including image files with EXIF data. Mobile device architecture, cellular networks, and the SIM also sit in this domain.

Given that these two domains alone approach half the exam, master them before spending equal time on the smaller, more specialized areas. The official blueprint lists the full sub-topics for both domains and is the right checklist for self-assessment.

Sources used: CHFI Exam Blueprint v4 (EC-Council) — Domain weight table and sub-domain listings; CHFI Certification | Computer Hacking Forensic Investigator | EC-Council — Exam Details, Course Outline, and FAQ sections

Operating systems, networks, and newer evidence sources

The remaining domains map to Windows, Linux, and macOS artifacts; network log correlation; malware analysis; mobile, cloud, dark web, email, social media, and IoT forensics; and the tools that perform each task.

Operating system forensics spans volatile and non-volatile collection, memory and registry analysis, web browser forensics, and the Windows artifact set the course names explicitly: ShellBags, LNK files, jump lists, and event logs, with corresponding collection and memory work for Linux and macOS. Treat each artifact as a topic to study in the official materials, because the blueprint expects you to know what it records and which tools examine it.

Network forensics emphasizes correlation rather than single-log reading. The blueprint lists firewall, IDS, honeypot, router, DHCP, switch, VPN, and DNS server logs, event correlation types and approaches, packet analysis for specific attack traffic, rogue access point detection, and SIEM-based centralized logging. Practice tracing one suspected event across at least two or three independent log sources; that habit matches how the domain is structured.

Malware, mobile, cloud, and the newer sources each carry their own acquisition rules. Malware analysis divides into static and dynamic types, with dynamic analysis performed in a sandboxed environment. Mobile work contrasts logical and physical acquisition on Android and iOS, including SIM data and cell site analysis. Cloud forensics covers where data and logs live in AWS, Azure, and Google Cloud and how to acquire VMs and volumes there. The blueprint also lists dark web and Tor browser artifacts, email crime investigation steps, social media forensics, IoT device forensics, and Python-based forensics scripting. The exercise below rehearses the malware distinction.

Practice exercise

Classify each statement about a suspicious PDF as a finding from static analysis or dynamic analysis: (1) Inspecting the file's headers and embedded strings reveals an embedded launch action. (2) In a single run inside an isolated, authorized lab environment, the executed sample writes files to a startup folder and opens a network connection.

Show answer

Statement 1 is a static-analysis finding; statement 2 is a dynamic-analysis finding.

Static analysis examines a file's structure and content — headers, strings, and embedded objects — without running it, so it establishes only what the file contains. Dynamic analysis executes the sample and records what it actually does, and the blueprint specifies performing this in a sandboxed environment. The two answer different questions: a file can contain a capability it never executes, and behavior recorded in one lab run describes that run rather than guaranteeing containment or matching every environment. Handling any real suspicious sample belongs only in an authorized, isolated lab; this exercise is a definitions drill, not a handling procedure.

Evidence sourceBlueprint focus areas
WindowsMemory and registry analysis, browser forensics, ShellBags, LNK files, jump lists, event logs
Linux and macOSVolatile and non-volatile collection, Linux memory forensics, APFS analysis, Mac directories and logs
Network and wirelessFirewall, IDS, DHCP, DNS, VPN logs; event correlation; packet analysis; rogue access points
MobileAndroid and iOS architecture, logical and physical acquisition, SIM and cellular data
CloudData storage and logs in AWS, Azure, and Google Cloud; VM and snapshot acquisition
MalwareStatic and dynamic analysis, system and network behavior analysis, ransomware analysis

Sources used: CHFI Certification | Computer Hacking Forensic Investigator | EC-Council — Exam Details, Course Outline, and FAQ sections; CHFI Exam Blueprint v4 (EC-Council) — Domain weight table and sub-domain listings

A preparation sequence and pitfalls to avoid

Work through the blueprint in weight order, anchor tools to tasks, learn the process and methodology material as taught topics, and finish with rotations through the specialized evidence sources.

The following sequence is study advice, not an official requirement. Start with the process and methodology material, including the volatile and non-volatile classification exercise above, because it supports the rest of the exam. Move next to the two heaviest domains: anti-forensics techniques with their countermeasures, and the digital evidence fundamentals. Then rotate through operating system, network, malware, mobile, cloud, dark web, email, and IoT topics, keeping earlier domains warm with short weekly reviews.

Three pitfalls are worth naming. Do not memorize tool names without the forensic task each performs; the tools domain tests purpose as much as product. Do not assume a fixed pass mark, since the cut score varies by exam form within the 60% to 85% range. And do not treat reading as a substitute for the hands-on labs; the program's 68 labs and crafted evidence files exist because artifact analysis is a practiced skill, and paper preparation alone cannot establish it.

  • Pass one: investigation process, regulations, and acquisition methodology.
  • Pass two: anti-forensics and digital evidence fundamentals, using the blueprint sub-topics as your checklist.
  • Pass three: rotating reviews of OS, network, malware, mobile, cloud, dark web, email, and IoT topics.
  • Ongoing: attach every new tool to the task it performs and rehearse classifying data sources as volatile or non-volatile.

Sources used: CHFI Certification | Computer Hacking Forensic Investigator | EC-Council — Exam Details, Course Outline, and FAQ sections; Computer Hacking Forensic Investigator (EC-Council certification page) — Exam Information and CHFI Exam Details; CHFI Exam Blueprint v4 (EC-Council) — Domain weight table and sub-domain listings

Career routes and adjacent credentials

CHFI maps to digital forensics and DFIR roles, is recognized in three DoD 8140 workforce roles, and pairs naturally with EC-Council's network defense and incident response credentials.

EC-Council lists a wide set of roles CHFI holders pursue, including digital forensics analyst, computer forensic examiner, cybercrime investigator, cyber defense forensics analyst, DFIR engineer, malware analyst, and mobile forensic analyst. Under the US DoD 8140 framework, CHFI is listed for the Forensic Analyst (211), Cyber Defense Forensics Analyst (212), and Cyber Crime Investigator (221) work roles.

If you are planning a path around CHFI, EC-Council suggests blue-team companions such as CND, ECIH, CSA, and CTIA for network defense, incident handling, and threat intelligence, and positions CEH and CPENT for offensive skills. Choose based on the roles you are targeting rather than collecting credentials broadly.

Sources used: CHFI Certification | Computer Hacking Forensic Investigator | EC-Council — Exam Details, Course Outline, and FAQ sections

Sources used

Exam facts verified against EC-Council sources:

Your next steps

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for EC-Council Computer Hacking Forensic Investigator (CHFI).

Is CHFI a hacking exam despite the name?
No. CHFI validates digital forensics investigation skills: detecting attack traces, gathering evidence soundly, and supporting prosecution or incident response. Hacking attacks appear in the curriculum as things you investigate and document, not techniques you perform.
Is CHFI accredited and recognized?
EC-Council states CHFI is accredited under ANAB (ANSI) ISO/IEC 17024 for personnel certification and approved under US DoD 8140/8570, with mapping to the NICE framework. Verify current status on EC-Council's accreditation pages before relying on it for an employer or government requirement.
How much does CHFI cost and do I need official training?
EC-Council says certification cost varies by learning method and directs candidates to its website and career advisors for current pricing. Its guidance also states you enroll in the CHFI training program and then complete the exam; enrollment includes course materials, labs, and an exam voucher. Confirm both points with EC-Council when you register.
Which CHFI version should I study?
Study against EC-Council's CHFI Exam Blueprint v4, the current published blueprint, which lists the six domains, sub-topics, question counts, and weights used in this guide. Download it from cert.eccouncil.org and use its sub-topic lists as your final self-assessment checklist.
Can I pass CHFI without hands-on forensics experience?
EC-Council expects basic knowledge of IT and cybersecurity, computer forensics, and incident response rather than prior certification, and the exam itself is multiple choice. That said, the curriculum is built around 68 labs for a reason: artifact and acquisition questions are easiest to answer when you have actually performed the tasks, so use labs or an isolated home lab where possible.

Keep Reading

Related Study Guides

Explore related guides and preparation topics.