- The One-Glance Exam Snapshot
- Which C)NFE This Sheet Covers
- Evidence and Methodology Core (Domains 1-4)
- Network Fundamentals and Acquisition (Domains 5-9)
- Analysis and Layer 2 (Domains 10-11)
- Wireless Block (Domains 12-14)
- IDS, Logging and Device Forensics (Domains 15-17)
- Proxies, Tunnels and Malware (Domains 18-20)
- Registration, Attempts and Renewal Cheat Lines
- A Domain-Ordered Review Schedule
- Quick Answers
- The exam is 100 multiple-choice questions in about 2 hours, with a minimum passing score of 70%.
- Preparation scope is 20 unweighted Mile2 course modules, so no single domain should be skipped.
- The Exam Combo includes two attempts; further paid access is needed once both are used.
- Credential validity is 3 years; renewal paths include 60 documented CEUs and the U.S. renewal fee is $200.
The One-Glance Exam Snapshot
This page condenses what a Certified Network Forensics Examiner candidate needs to hold in working memory on exam day. It is not a replacement for the full course material, but it is a fast way to confirm that you know the format, the scope, and the topics that tend to separate prepared candidates from underprepared ones.
| Item | Must-Know Fact |
|---|---|
| Certifying body | Mile2 |
| Question format | 100 multiple-choice questions |
| Time allowed | Approximately 2 hours |
| Minimum passing score | 70% |
| Delivery | Through your Mile2 account / Learning Management System; standard Mile2 exams are described as online and on demand |
| Recommended background | 2 years networking, 2 years IT security, TCP/IP knowledge |
| Credential validity | 3 years |
| Renewal path (one option) | 60 documented qualifying CEUs within the 3-year cycle plus the applicable renewal fee |
| U.S. CE-renewal fee | $200 |
Pace is the first practical implication. With 100 questions in roughly 2 hours, you have a little over a minute per question. Network forensics questions often present a scenario (a capture excerpt, a log fragment, a described device behavior) and ask what the examiner should do or conclude. Read the scenario once, identify what is actually being asked, and move on rather than re-deriving everything from first principles.
Which C)NFE This Sheet Covers
The acronym is shared by several unrelated credentials in the industry, so confirm you are studying the right one. This cheat sheet covers the Certified Network Forensics Examiner offered by Mile2, and nothing else. If you are weighing it against alternatives, the explainers on what C)NFE is and what C)NFE stands for will help you confirm the match before you spend money or study time.
Evidence and Methodology Core (Domains 1-4)
The first four domains establish how a network forensics examiner thinks. Questions here tend to be conceptual and procedural rather than tool-specific, which makes them some of the most reliable points available if you prepare deliberately.
Domain 1: Digital Evidence Concepts
Know what makes digital evidence usable and defensible.
- Preservation, integrity, and documentation of evidence
- Chain of custody and why gaps undermine findings
- The difference between volatile and persistent data
Domain 2: Network Evidence Challenges
Network evidence behaves differently from disk evidence, and the exam expects you to understand why.
- Data in motion is transient; if it is not captured, it is gone
- Volume, encryption, and distributed sources complicate collection
- Legal and privacy considerations around interception
Domain 3: Network Forensics Investigative Methodology
Expect process questions: what comes first, what comes next, and why.
- Structured phases from planning and identification through collection, analysis, and reporting
- Scoping an incident before collecting indiscriminately
- Documenting actions so another examiner could reproduce them
Domain 4: Network-Based Evidence
Know the sources an examiner draws from.
- Full packet captures versus flow records versus logs
- What each source can and cannot prove
- Choosing the right source for a given investigative question
A useful memory hook for this block: if it was not captured or logged, it cannot be examined later. Many scenario questions reduce to choosing the evidence source that would actually contain the answer.
Network Fundamentals and Acquisition (Domains 5-9)
This block mixes foundational networking with the mechanics of getting traffic in front of you. The recommended TCP/IP background matters most here, since weak fundamentals make every later domain harder. If this block feels shaky, the C)NFE requirements guide explains the readiness profile in more detail.
Domain 5: Network Principles
Layered models and how data moves between devices.
- Layer responsibilities and which devices operate at which layer
- Addressing, switching, and routing basics
Domain 6: Internet Protocol Suite
The protocols you will be reading in captures.
- IP, TCP, and UDP behavior, including the TCP handshake and teardown
- Common application protocols and what their normal traffic looks like
- Recognizing anomalies against a mental baseline of normal
Domain 7: Physical Interception
Getting access to traffic at the wire level.
- Taps versus hubs versus switch mirror (SPAN) ports
- Tradeoffs: fidelity, risk of dropped packets, and detectability
Domain 8: Traffic Acquisition Software
Capture tooling and capture technique.
- Packet capture tools, capture filters, and saving captures in a way that preserves evidence
- Understanding why filtering at capture time can discard evidence you later need
Domain 9: Live Acquisition
Collecting from running systems and networks.
- Order of volatility: collect the most fleeting data first
- Minimizing the footprint of your own actions on a live system
Analysis and Layer 2 (Domains 10-11)
Domain 10: Analysis
Turning raw captures into conclusions.
- Reconstructing sessions and following conversations between hosts
- Extracting files and artifacts from captured streams
- Correlating timestamps across sources, including awareness of clock differences
Domain 11: Layer 2 Protocol
The data link layer is where many local attacks live.
- Ethernet framing and MAC addressing
- ARP behavior and how spoofing or poisoning shows up in traffic
- Switch behavior, including how MAC address tables influence what an examiner can see
Analysis questions reward pattern recognition. The more captures you have actually read, the faster you will recognize a normal handshake, a scan, or a poisoning attempt on sight. Reading about them is not the same as seeing them.
Wireless Block (Domains 12-14)
Three consecutive domains cover wireless, which is a clear signal that the course treats it as a major area. Candidates who come from wired-only backgrounds often need extra time here.
Domain 12: Wireless Access Points
- How access points operate, authenticate, and log activity
- Identifying rogue or misconfigured access points
Domain 13: Wireless Capture Traffic and Analysis
- Monitor mode versus managed mode and why it matters for capture
- Reading 802.11 management, control, and data frames
- Limits imposed by wireless encryption on what you can read
Domain 14: Wireless Attacks
- Common attack categories such as deauthentication, rogue access points, and evil twins
- What each attack leaves behind as forensic evidence
For this block, think in terms of evidence artifacts: for each attack, ask what it would look like in a capture or an access point log. That framing matches how scenario questions are typically built.
IDS, Logging and Device Forensics (Domains 15-17)
Domain 15: NIDS_Snort
Snort is named explicitly in the module list, so expect tool-specific content.
- Network intrusion detection concepts: signature-based detection versus anomaly-based approaches
- Snort operating modes (sniffer, packet logger, intrusion detection)
- Reading rule structure: header, options, and what triggers an alert
- Interpreting alerts and recognizing false positives
Domain 16: Centralized Logging and Syslog
- Why centralizing logs protects evidence from tampering on a compromised host
- Syslog facilities and severity levels
- Time synchronization as a prerequisite for trustworthy correlation
Domain 17: Investigating Network Devices
- Routers, switches, and firewalls as evidence sources
- Collecting configuration and volatile state from devices
- Recognizing signs of device compromise or unauthorized changes
Key Takeaway
Logging questions often turn on trust: a log stored only on the compromised machine is weak evidence, while a copy forwarded to a separate collector is stronger. When a scenario asks how to improve evidentiary value, look for centralization and synchronized time.
Proxies, Tunnels and Malware (Domains 18-20)
Domain 18: Web Proxies and Encryption
- What proxy logs reveal about user and application behavior
- How encryption limits payload visibility and what metadata remains available
- Examiner options when traffic is encrypted
Domain 19: Network Tunneling
- How tunneling encapsulates one protocol inside another
- Why tunnels are used both legitimately and to evade controls
- Spotting tunneling indicators such as unexpected protocol behavior or unusual traffic patterns on common ports
Domain 20: Malware Forensics
- Network-visible behavior of malware, including beaconing and command-and-control patterns
- Using network artifacts to identify infection and scope its spread
- Safe handling of malicious samples during an investigation
These final domains tie the course together: a tunneled, encrypted channel carrying malware command traffic touches nearly every earlier module. Practicing scenarios that cross domains is more valuable here than memorizing isolated facts. For a deeper breakdown of each content area, see the complete guide to all 20 C)NFE content areas.
Registration, Attempts and Renewal Cheat Lines
Logistics trip up well-prepared candidates, so memorize these lines.
- Course purchase is not required. The training is separate from the exam. The five-day course and its 40 course CEUs are optional extras, not a gate.
- The Exam Combo bundles more than the exam. It includes the certification exam, a preparation guide, a practice quiz or simulator, and two exam attempts.
- Two attempts, then more access. Once both attempts are exhausted, further paid access is needed.
- Recommended background is a readiness profile. The 2 years of networking and 2 years of IT security are guidance, not an asserted admission gate.
- Follow your purchase instructions. Mile2 describes standard exams as online and on demand, but the exam-specific instructions supplied with your purchase govern the details.
- Validity is 3 years. This is separate from course and voucher access periods, so do not confuse an expiring voucher with an expiring credential.
For cost planning beyond these basics, the C)NFE certification cost breakdown goes through pricing considerations, and the passing score guide expands on the 70% threshold.
A Domain-Ordered Review Schedule
If you are using this sheet for a final pass, order your review by dependency rather than by the order modules appear. Foundations first, because weak TCP/IP skills slow down everything after them.
Foundations and Evidence
- Domains 5 and 6 first, since every capture depends on them
- Domains 1-4 for process and evidence-handling vocabulary
Acquisition and Analysis
- Domains 7-9 on interception and capture
- Domains 10-11, reading real captures for Layer 2 and session patterns
Wireless and Detection
- Domains 12-14 as one connected block
- Domains 15-17 including Snort rule reading and syslog
Advanced Topics and Integration
- Domains 18-20 with cross-domain scenarios
- Full-length timed practice to rehearse the 2-hour pace
For a fuller plan, the C)NFE study guide covers preparation in more depth, and you can pressure-test your recall with the practice questions on the main practice test site. If you are still deciding how demanding to expect the exam to be, how hard the C)NFE exam is sets realistic expectations.
Quick Answers
The exam has 100 multiple-choice questions and runs approximately 2 hours. The minimum passing score is 70%.
No. Purchasing a course is not required. The five-day training and its 40 course CEUs are separate from the exam. Many candidates choose the Exam Combo, which bundles the exam, a preparation guide, a practice quiz or simulator, and two attempts.
The domains reproduce 20 official unweighted course modules as preparation scope. They are not a separately established weighted blueprint, so plan to cover all of them rather than favoring a few.
The credential is valid for 3 years. Current renewal paths include 60 documented qualifying CEUs within the cycle with the applicable renewal fee (the U.S. CE-renewal fee is $200), or an accepted current-examination route, along with policy and ethics acknowledgment. Verify the current policy before you renew.
The Exam Combo includes two attempts, so you have a second try. After both are exhausted, further paid access is needed. Use the first attempt's experience to identify weak domains and review them before retaking.
Keep this sheet nearby during your final days of review, and when you are ready to test yourself against realistic questions, head to the C)NFE practice tests. To think about what the credential can do for your career, the guides on whether the C)NFE is worth it and C)NFE jobs are good next reads.