C)NFE logo
Focused certification exam prep
Start practice

C)NFE Exam Domains 2026: Complete Guide to All 20 Content Areas

TL;DR
  • The Certified Network Forensics Examiner (C)NFE) from Mile2 maps to 20 official course modules, published without domain weights.
  • The exam is 100 multiple-choice questions in about 2 hours, with a 70% minimum passing score.
  • Recommended readiness: 2 years of networking, 2 years of IT security, and solid TCP/IP knowledge.
  • The credential is valid for 3 years; renewal uses 60 documented CEUs or an accepted current-exam route.

How to Read the 20 Modules

The Certified Network Forensics Examiner credential from Mile2 is organized around 20 course modules. Those modules are the best public statement of what a candidate should be prepared to know. One caveat matters before you build a study plan: the module list is an unweighted preparation scope. It is not a separately published, weighted exam blueprint, and nobody should tell you that "Domain 15 is worth exactly this many questions." Treat all 20 areas as fair game and allocate your time by your own weaknesses rather than by invented percentages.

If you are new to the credential, the explainers on what C)NFE certification is and what C)NFE stands for cover the basics. This article goes domain by domain through the 20 modules, explaining what each one asks of you and why it matters to a working network forensics examiner.

Why the structure matters: The 20 modules follow the investigator's real workflow. You learn the evidence rules and methodology first, then the network fundamentals, then how to capture traffic, then how to analyze it, and finally the specialized territory of wireless, IDS, logging, proxies, tunneling and malware. Studying in that order mirrors how a case unfolds.

Exam Format and Registration Mechanics

Before the domains, the logistics. The C)NFE examination is taken through your Mile2 account and Learning Management System. It consists of 100 multiple-choice questions in roughly 2 hours, and the minimum passing score is 70%. For a closer look at the threshold, see our page on the C)NFE passing score.

ItemWhat Mile2 Specifies
Question format100 multiple-choice questions
Time allowedApproximately 2 hours
Minimum passing score70%
DeliveryThrough your Mile2 account/LMS; Mile2's general FAQ describes standard exams as online and on demand, so follow the instructions supplied with your purchase
Exam Combo contentsCertification exam, preparation guide, practice quiz or simulator, and two exam attempts
After both attemptsFurther paid access is required
Course purchaseNot required to sit the exam

The recommended background is two years of networking, two years of IT security, and working knowledge of TCP/IP. Read this as a readiness profile, not an admission gate; the C)NFE requirements article explains the distinction. The five-day training and its 40 course CEUs are a separate offering from the exam, so you can pursue the exam without buying the course. For the money side, see the C)NFE certification cost breakdown.

Domains 1-3: Evidence and Methodology

The first three modules establish the professional frame. Candidates who skip them to rush toward packet analysis tend to miss the scenario questions that test judgment rather than tool syntax.

Domain 1: Digital Evidence Concepts

This module covers what counts as digital evidence and how it must be handled to remain useful. Expect to reason about preservation, documentation and the handling of volatile material.

  • Chain of custody and why gaps undermine a case
  • Distinguishing original evidence from derived copies and working data
  • Documenting collection so another examiner could reproduce your steps

Domain 2: Network Evidence Challenges

Network evidence is fleeting. Unlike a seized disk, traffic exists only while it crosses the wire, and this module explores the problems that follow from that.

  • Volatility: data you fail to capture in the moment is gone
  • Volume: capturing everything is rarely feasible, so scoping decisions matter
  • Encryption and privacy constraints on what you can see and lawfully collect

Domain 3: Network Forensics Investigative Methodology

Here the course gives you a repeatable process for working a case from trigger to report. Exam items in this area tend to present a scenario and ask for the correct next step.

  • Ordering of phases: preparation, detection, collection, analysis, reporting
  • Choosing what to collect first when time is short
  • Presenting findings in a way that withstands scrutiny

Domains 4-6: Network Evidence and Protocol Foundations

Domains 4 through 6 are the technical bedrock. If your networking experience has gaps, this is where they will show, and it is why the recommended two years of networking background carries weight.

Domain 4: Network-Based Evidence

This module catalogs where evidence lives on a network and what each source can and cannot tell you.

  • Packet captures versus flow records versus device logs
  • Strengths and blind spots of each evidence type
  • Correlating multiple sources into one timeline

Domain 5: Network Principles

Core networking concepts, applied from an investigator's viewpoint rather than an administrator's.

  • How the layered models structure communication
  • Addressing, switching and routing as they affect where you can observe traffic
  • Topology awareness: knowing where a capture point sits determines what it can see

Domain 6: Internet Protocol Suite

TCP/IP in depth. Because the recommended background explicitly includes TCP/IP, expect questions that assume fluency.

  • Header fields and what anomalies in them can indicate
  • TCP handshake, session behavior and teardown
  • Common application protocols and how they appear on the wire
A practical rule: You cannot analyze what you cannot read. Candidates who can look at a raw header and say what is normal and what is not find the later analysis, wireless and tunneling modules dramatically easier.

Domains 7-9: Getting the Traffic

Three modules deal with acquisition, which is the step where network forensics most differs from disk forensics.

Domain 7: Physical Interception

How traffic is tapped or mirrored at the physical or near-physical level.

  • Passive taps versus switch port mirroring and the trade-offs of each
  • What interception points introduce in terms of packet loss or alteration risk
  • Choosing a capture location that sees the traffic of interest

Domain 8: Traffic Acquisition Software

The software side of capture: tools, filters and configuration choices.

  • Capture filters versus display filters, and when each applies
  • Capture settings that affect completeness and file size
  • Verifying and documenting captures so they are defensible

Domain 9: Live Acquisition

Collecting evidence from systems and networks that cannot simply be powered down.

  • Order of volatility when gathering from a running environment
  • Minimizing your own footprint on a live system
  • Balancing business continuity against evidence preservation

Domains 10-11: Analysis and Layer 2

Domain 10: Analysis

Where captured data becomes findings. This is the heart of the discipline, and it rewards hands-on practice more than memorization.

  • Reconstructing sessions and extracting artifacts from captures
  • Identifying anomalies against a baseline of normal behavior
  • Building a timeline that ties network events to host and log evidence

Domain 11: Layer 2 Protocol

The data link layer is where many local attacks live and where many examiners are least comfortable.

  • How switching and address resolution work, and how they can be abused
  • Recognizing spoofing and poisoning behavior in captures
  • Why Layer 2 evidence is often local and easy to miss from a distance

Analysis is also where the question of difficulty bites. If you want a realistic picture of what to expect, the C)NFE difficulty guide discusses it without relying on invented numbers.

Domains 12-14: Wireless Forensics

Three of the 20 modules are devoted to wireless, which is a clear signal of how seriously the course treats it. Candidates from wired-only backgrounds should budget extra time here.

Domain 12: Wireless Access Points

Understanding the infrastructure before you investigate it.

  • How access points operate and what they log
  • Identifying rogue or misconfigured access points
  • Evidence an access point can yield about connected clients

Domain 13: Wireless Capture Traffic and Analysis

Capturing over the air differs from capturing on a cable, and the analysis differs too.

  • Monitor-mode capture and why ordinary capture settings are insufficient
  • Reading management, control and data frames
  • Handling encrypted wireless traffic and what remains visible regardless

Domain 14: Wireless Attacks

The attack patterns an examiner needs to recognize after the fact.

  • Deauthentication, rogue AP and evil-twin behavior and their traces
  • Attacks against wireless authentication and encryption
  • Translating attack signatures into evidence you can report

Domains 15-17: IDS, Logging and Network Devices

Domain 15: NIDS_Snort

The course uses Snort as its network intrusion detection reference. Know it as both a source of alerts and a source of evidence.

  • Reading and interpreting Snort rule structure
  • Understanding alerts versus the packets that triggered them
  • False positives, tuning, and what an alert does and does not prove

Domain 16: Centralized Logging and Syslog

Logs are often the only record that survives, so how they are collected and protected matters.

  • Syslog architecture, facilities and severity concepts
  • Time synchronization and why unreliable timestamps wreck timelines
  • Log integrity: preventing and detecting tampering

Domain 17: Investigating Network Devices

Routers, switches, firewalls and similar devices hold evidence in their configurations and state.

  • What to collect from a device and in what order
  • Configuration review for signs of unauthorized change
  • Device logs and tables as corroboration for packet evidence

Key Takeaway

Domains 15 through 17 teach you that the packet capture is rarely the whole story. Expect scenario questions that ask you to combine an IDS alert, a syslog entry and a device state into one coherent conclusion.

Domains 18-20: Proxies, Tunneling and Malware

The final three modules cover the topics that complicate real investigations most: traffic that hides its content, traffic that hides its protocol, and the malicious software that produces both.

Domain 18: Web Proxies and Encryption

Web traffic dominates modern networks and much of it is encrypted.

  • What proxy logs reveal even when payloads are encrypted
  • How encryption limits visibility and what metadata remains
  • Investigative value of proxy and cache evidence

Domain 19: Network Tunneling

Tunneling wraps one protocol inside another, often to evade controls.

  • Recognizing tunneled traffic from timing, size and protocol oddities
  • Legitimate versus malicious uses of tunnels
  • Why tunnels frustrate signature-based detection

Domain 20: Malware Forensics

Closing the course, this module ties network behavior back to the malicious code driving it.

  • Network indicators of compromise: beaconing, command-and-control patterns
  • Connecting host artifacts to the traffic they generated
  • Documenting malware behavior for incident response and reporting

Sequencing the Domains in Your Prep

Generic study advice is plentiful, so here is one short, C)NFE-specific scheduling suggestion. The point is ordering, because the later modules assume the earlier ones. For a fuller plan, see the C)NFE study guide.

Phase 1

Frame and Foundations (Domains 1-6)

  • Lock down evidence handling and the investigative process
  • Refresh TCP/IP until headers read naturally
Phase 2

Capture and Analyze (Domains 7-11)

  • Practice captures and filters hands-on
  • Work Layer 2 examples alongside analysis
Phase 3

Specialized Territory (Domains 12-20)

  • Give wireless and Snort the most time if they are new to you
  • Finish with tunneling and malware to tie everything together

Once you have worked through the material, test yourself. Our C)NFE practice tests help you find which of the 20 areas still need work, and the one-page C)NFE cheat sheet is useful for final review.

Credential Validity and Renewal

Passing is not the end of the commitment. The credential is valid for 3 years, and that validity is separate from any course or voucher access period. Mile2's current renewal paths allow you to renew with 60 documented qualifying CEUs earned within the 3-year cycle plus the applicable renewal fee, or through an accepted current-examination route. A policy and ethics acknowledgment applies. The U.S. CE-renewal fee is $200.

Note that an exam and CEUs are not universally cumulative requirements; follow Mile2's current renewal-path policy rather than assuming you must do both. If you are weighing whether the investment pays off, the C)NFE ROI analysis and the overview of C)NFE jobs are good next reads.

Frequently Asked Questions

Are the 20 C)NFE domains weighted?

No weights are published. The 20 items are official course modules presented as an unweighted preparation scope, so they should not be treated as a weighted or exhaustive exam blueprint. Plan to study all of them.

How many questions are on the C)NFE exam, and what score passes?

The exam has 100 multiple-choice questions to be completed in approximately 2 hours. The minimum passing score is 70%.

Do I need to buy the course to take the exam?

No. Purchasing the course is not required. The Exam Combo bundles the exam, a preparation guide, a practice quiz or simulator, and two exam attempts. Once both attempts are used, further paid access is needed.

What background should I have before attempting C)NFE?

The recommended profile is two years of networking, two years of IT security, and TCP/IP knowledge. These are course prerequisites describing readiness, not an asserted exam-admission gate.

How long does the credential last and how is it renewed?

It is valid for 3 years. Renewal currently runs through 60 documented qualifying CEUs within the cycle with the applicable fee, or an accepted current-examination route, along with a policy and ethics acknowledgment. The U.S. CE-renewal fee is $200.

Ready to pass your C)NFE exam?

Put this into practice with free C)NFE questions across every exam domain.