C)NFE logo
Focused certification exam prep
Start practice

C)NFE Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • The exam is 100 multiple-choice questions in about 2 hours, with a minimum passing score of 70%.
  • Preparation scope is 20 unweighted Mile2 course modules, so no single domain should be skipped.
  • The Exam Combo includes two attempts; further paid access is needed once both are used.
  • Credential validity is 3 years; renewal paths include 60 documented CEUs and the U.S. renewal fee is $200.

The One-Glance Exam Snapshot

This page condenses what a Certified Network Forensics Examiner candidate needs to hold in working memory on exam day. It is not a replacement for the full course material, but it is a fast way to confirm that you know the format, the scope, and the topics that tend to separate prepared candidates from underprepared ones.

ItemMust-Know Fact
Certifying bodyMile2
Question format100 multiple-choice questions
Time allowedApproximately 2 hours
Minimum passing score70%
DeliveryThrough your Mile2 account / Learning Management System; standard Mile2 exams are described as online and on demand
Recommended background2 years networking, 2 years IT security, TCP/IP knowledge
Credential validity3 years
Renewal path (one option)60 documented qualifying CEUs within the 3-year cycle plus the applicable renewal fee
U.S. CE-renewal fee$200

Pace is the first practical implication. With 100 questions in roughly 2 hours, you have a little over a minute per question. Network forensics questions often present a scenario (a capture excerpt, a log fragment, a described device behavior) and ask what the examiner should do or conclude. Read the scenario once, identify what is actually being asked, and move on rather than re-deriving everything from first principles.

Which C)NFE This Sheet Covers

The acronym is shared by several unrelated credentials in the industry, so confirm you are studying the right one. This cheat sheet covers the Certified Network Forensics Examiner offered by Mile2, and nothing else. If you are weighing it against alternatives, the explainers on what C)NFE is and what C)NFE stands for will help you confirm the match before you spend money or study time.

Scope, Not Weighting: The 20 domains listed below reproduce the official course modules as preparation scope. They are unweighted, and they are not a published, exhaustive exam blueprint. Treat every module as fair game and avoid building a plan around guesses about which domains count more.

Evidence and Methodology Core (Domains 1-4)

The first four domains establish how a network forensics examiner thinks. Questions here tend to be conceptual and procedural rather than tool-specific, which makes them some of the most reliable points available if you prepare deliberately.

Domain 1: Digital Evidence Concepts

Know what makes digital evidence usable and defensible.

  • Preservation, integrity, and documentation of evidence
  • Chain of custody and why gaps undermine findings
  • The difference between volatile and persistent data

Domain 2: Network Evidence Challenges

Network evidence behaves differently from disk evidence, and the exam expects you to understand why.

  • Data in motion is transient; if it is not captured, it is gone
  • Volume, encryption, and distributed sources complicate collection
  • Legal and privacy considerations around interception

Domain 3: Network Forensics Investigative Methodology

Expect process questions: what comes first, what comes next, and why.

  • Structured phases from planning and identification through collection, analysis, and reporting
  • Scoping an incident before collecting indiscriminately
  • Documenting actions so another examiner could reproduce them

Domain 4: Network-Based Evidence

Know the sources an examiner draws from.

  • Full packet captures versus flow records versus logs
  • What each source can and cannot prove
  • Choosing the right source for a given investigative question

A useful memory hook for this block: if it was not captured or logged, it cannot be examined later. Many scenario questions reduce to choosing the evidence source that would actually contain the answer.

Network Fundamentals and Acquisition (Domains 5-9)

This block mixes foundational networking with the mechanics of getting traffic in front of you. The recommended TCP/IP background matters most here, since weak fundamentals make every later domain harder. If this block feels shaky, the C)NFE requirements guide explains the readiness profile in more detail.

Domain 5: Network Principles

Layered models and how data moves between devices.

  • Layer responsibilities and which devices operate at which layer
  • Addressing, switching, and routing basics

Domain 6: Internet Protocol Suite

The protocols you will be reading in captures.

  • IP, TCP, and UDP behavior, including the TCP handshake and teardown
  • Common application protocols and what their normal traffic looks like
  • Recognizing anomalies against a mental baseline of normal

Domain 7: Physical Interception

Getting access to traffic at the wire level.

  • Taps versus hubs versus switch mirror (SPAN) ports
  • Tradeoffs: fidelity, risk of dropped packets, and detectability

Domain 8: Traffic Acquisition Software

Capture tooling and capture technique.

  • Packet capture tools, capture filters, and saving captures in a way that preserves evidence
  • Understanding why filtering at capture time can discard evidence you later need

Domain 9: Live Acquisition

Collecting from running systems and networks.

  • Order of volatility: collect the most fleeting data first
  • Minimizing the footprint of your own actions on a live system
Tap vs. SPAN, a Classic Trap: Questions comparing interception methods usually hinge on a single tradeoff. A mirror port can drop packets under load and may not carry every frame, while a dedicated tap is built to pass traffic faithfully. Read the scenario for the clue (fidelity, cost, disruption, or stealth) before choosing.

Analysis and Layer 2 (Domains 10-11)

Domain 10: Analysis

Turning raw captures into conclusions.

  • Reconstructing sessions and following conversations between hosts
  • Extracting files and artifacts from captured streams
  • Correlating timestamps across sources, including awareness of clock differences

Domain 11: Layer 2 Protocol

The data link layer is where many local attacks live.

  • Ethernet framing and MAC addressing
  • ARP behavior and how spoofing or poisoning shows up in traffic
  • Switch behavior, including how MAC address tables influence what an examiner can see

Analysis questions reward pattern recognition. The more captures you have actually read, the faster you will recognize a normal handshake, a scan, or a poisoning attempt on sight. Reading about them is not the same as seeing them.

Wireless Block (Domains 12-14)

Three consecutive domains cover wireless, which is a clear signal that the course treats it as a major area. Candidates who come from wired-only backgrounds often need extra time here.

Domain 12: Wireless Access Points

  • How access points operate, authenticate, and log activity
  • Identifying rogue or misconfigured access points

Domain 13: Wireless Capture Traffic and Analysis

  • Monitor mode versus managed mode and why it matters for capture
  • Reading 802.11 management, control, and data frames
  • Limits imposed by wireless encryption on what you can read

Domain 14: Wireless Attacks

  • Common attack categories such as deauthentication, rogue access points, and evil twins
  • What each attack leaves behind as forensic evidence

For this block, think in terms of evidence artifacts: for each attack, ask what it would look like in a capture or an access point log. That framing matches how scenario questions are typically built.

IDS, Logging and Device Forensics (Domains 15-17)

Domain 15: NIDS_Snort

Snort is named explicitly in the module list, so expect tool-specific content.

  • Network intrusion detection concepts: signature-based detection versus anomaly-based approaches
  • Snort operating modes (sniffer, packet logger, intrusion detection)
  • Reading rule structure: header, options, and what triggers an alert
  • Interpreting alerts and recognizing false positives

Domain 16: Centralized Logging and Syslog

  • Why centralizing logs protects evidence from tampering on a compromised host
  • Syslog facilities and severity levels
  • Time synchronization as a prerequisite for trustworthy correlation

Domain 17: Investigating Network Devices

  • Routers, switches, and firewalls as evidence sources
  • Collecting configuration and volatile state from devices
  • Recognizing signs of device compromise or unauthorized changes

Key Takeaway

Logging questions often turn on trust: a log stored only on the compromised machine is weak evidence, while a copy forwarded to a separate collector is stronger. When a scenario asks how to improve evidentiary value, look for centralization and synchronized time.

Proxies, Tunnels and Malware (Domains 18-20)

Domain 18: Web Proxies and Encryption

  • What proxy logs reveal about user and application behavior
  • How encryption limits payload visibility and what metadata remains available
  • Examiner options when traffic is encrypted

Domain 19: Network Tunneling

  • How tunneling encapsulates one protocol inside another
  • Why tunnels are used both legitimately and to evade controls
  • Spotting tunneling indicators such as unexpected protocol behavior or unusual traffic patterns on common ports

Domain 20: Malware Forensics

  • Network-visible behavior of malware, including beaconing and command-and-control patterns
  • Using network artifacts to identify infection and scope its spread
  • Safe handling of malicious samples during an investigation

These final domains tie the course together: a tunneled, encrypted channel carrying malware command traffic touches nearly every earlier module. Practicing scenarios that cross domains is more valuable here than memorizing isolated facts. For a deeper breakdown of each content area, see the complete guide to all 20 C)NFE content areas.

Registration, Attempts and Renewal Cheat Lines

Logistics trip up well-prepared candidates, so memorize these lines.

  • Course purchase is not required. The training is separate from the exam. The five-day course and its 40 course CEUs are optional extras, not a gate.
  • The Exam Combo bundles more than the exam. It includes the certification exam, a preparation guide, a practice quiz or simulator, and two exam attempts.
  • Two attempts, then more access. Once both attempts are exhausted, further paid access is needed.
  • Recommended background is a readiness profile. The 2 years of networking and 2 years of IT security are guidance, not an asserted admission gate.
  • Follow your purchase instructions. Mile2 describes standard exams as online and on demand, but the exam-specific instructions supplied with your purchase govern the details.
  • Validity is 3 years. This is separate from course and voucher access periods, so do not confuse an expiring voucher with an expiring credential.
Renewal, Stated Carefully: Current renewal paths offer 60 documented qualifying CEUs within the 3-year cycle with the applicable renewal fee, or an accepted current-examination route. Policy and ethics acknowledgment applies. The U.S. CE-renewal fee is $200. Always check the current renewal-path policy rather than assuming an exam plus CEUs are both required.

For cost planning beyond these basics, the C)NFE certification cost breakdown goes through pricing considerations, and the passing score guide expands on the 70% threshold.

A Domain-Ordered Review Schedule

If you are using this sheet for a final pass, order your review by dependency rather than by the order modules appear. Foundations first, because weak TCP/IP skills slow down everything after them.

Week 1

Foundations and Evidence

  • Domains 5 and 6 first, since every capture depends on them
  • Domains 1-4 for process and evidence-handling vocabulary
Week 2

Acquisition and Analysis

  • Domains 7-9 on interception and capture
  • Domains 10-11, reading real captures for Layer 2 and session patterns
Week 3

Wireless and Detection

  • Domains 12-14 as one connected block
  • Domains 15-17 including Snort rule reading and syslog
Week 4

Advanced Topics and Integration

  • Domains 18-20 with cross-domain scenarios
  • Full-length timed practice to rehearse the 2-hour pace

For a fuller plan, the C)NFE study guide covers preparation in more depth, and you can pressure-test your recall with the practice questions on the main practice test site. If you are still deciding how demanding to expect the exam to be, how hard the C)NFE exam is sets realistic expectations.

Quick Answers

How many questions are on the C)NFE exam, and how long do I have?

The exam has 100 multiple-choice questions and runs approximately 2 hours. The minimum passing score is 70%.

Do I have to buy the Mile2 course to sit the exam?

No. Purchasing a course is not required. The five-day training and its 40 course CEUs are separate from the exam. Many candidates choose the Exam Combo, which bundles the exam, a preparation guide, a practice quiz or simulator, and two attempts.

Are the 20 domains weighted?

The domains reproduce 20 official unweighted course modules as preparation scope. They are not a separately established weighted blueprint, so plan to cover all of them rather than favoring a few.

How long is the credential valid, and how do I renew?

The credential is valid for 3 years. Current renewal paths include 60 documented qualifying CEUs within the cycle with the applicable renewal fee (the U.S. CE-renewal fee is $200), or an accepted current-examination route, along with policy and ethics acknowledgment. Verify the current policy before you renew.

What happens if I fail my first attempt?

The Exam Combo includes two attempts, so you have a second try. After both are exhausted, further paid access is needed. Use the first attempt's experience to identify weak domains and review them before retaking.

Keep this sheet nearby during your final days of review, and when you are ready to test yourself against realistic questions, head to the C)NFE practice tests. To think about what the credential can do for your career, the guides on whether the C)NFE is worth it and C)NFE jobs are good next reads.

Ready to pass your C)NFE exam?

Put this into practice with free C)NFE questions across every exam domain.