- How to Read the 20 Modules
- Exam Format and Registration Mechanics
- Domains 1-3: Evidence and Methodology
- Domains 4-6: Network Evidence and Protocol Foundations
- Domains 7-9: Getting the Traffic
- Domains 10-11: Analysis and Layer 2
- Domains 12-14: Wireless Forensics
- Domains 15-17: IDS, Logging and Network Devices
- Domains 18-20: Proxies, Tunneling and Malware
- Sequencing the Domains in Your Prep
- Credential Validity and Renewal
- Frequently Asked Questions
- The Certified Network Forensics Examiner (C)NFE) from Mile2 maps to 20 official course modules, published without domain weights.
- The exam is 100 multiple-choice questions in about 2 hours, with a 70% minimum passing score.
- Recommended readiness: 2 years of networking, 2 years of IT security, and solid TCP/IP knowledge.
- The credential is valid for 3 years; renewal uses 60 documented CEUs or an accepted current-exam route.
How to Read the 20 Modules
The Certified Network Forensics Examiner credential from Mile2 is organized around 20 course modules. Those modules are the best public statement of what a candidate should be prepared to know. One caveat matters before you build a study plan: the module list is an unweighted preparation scope. It is not a separately published, weighted exam blueprint, and nobody should tell you that "Domain 15 is worth exactly this many questions." Treat all 20 areas as fair game and allocate your time by your own weaknesses rather than by invented percentages.
If you are new to the credential, the explainers on what C)NFE certification is and what C)NFE stands for cover the basics. This article goes domain by domain through the 20 modules, explaining what each one asks of you and why it matters to a working network forensics examiner.
Exam Format and Registration Mechanics
Before the domains, the logistics. The C)NFE examination is taken through your Mile2 account and Learning Management System. It consists of 100 multiple-choice questions in roughly 2 hours, and the minimum passing score is 70%. For a closer look at the threshold, see our page on the C)NFE passing score.
| Item | What Mile2 Specifies |
|---|---|
| Question format | 100 multiple-choice questions |
| Time allowed | Approximately 2 hours |
| Minimum passing score | 70% |
| Delivery | Through your Mile2 account/LMS; Mile2's general FAQ describes standard exams as online and on demand, so follow the instructions supplied with your purchase |
| Exam Combo contents | Certification exam, preparation guide, practice quiz or simulator, and two exam attempts |
| After both attempts | Further paid access is required |
| Course purchase | Not required to sit the exam |
The recommended background is two years of networking, two years of IT security, and working knowledge of TCP/IP. Read this as a readiness profile, not an admission gate; the C)NFE requirements article explains the distinction. The five-day training and its 40 course CEUs are a separate offering from the exam, so you can pursue the exam without buying the course. For the money side, see the C)NFE certification cost breakdown.
Domains 1-3: Evidence and Methodology
The first three modules establish the professional frame. Candidates who skip them to rush toward packet analysis tend to miss the scenario questions that test judgment rather than tool syntax.
Domain 1: Digital Evidence Concepts
This module covers what counts as digital evidence and how it must be handled to remain useful. Expect to reason about preservation, documentation and the handling of volatile material.
- Chain of custody and why gaps undermine a case
- Distinguishing original evidence from derived copies and working data
- Documenting collection so another examiner could reproduce your steps
Domain 2: Network Evidence Challenges
Network evidence is fleeting. Unlike a seized disk, traffic exists only while it crosses the wire, and this module explores the problems that follow from that.
- Volatility: data you fail to capture in the moment is gone
- Volume: capturing everything is rarely feasible, so scoping decisions matter
- Encryption and privacy constraints on what you can see and lawfully collect
Domain 3: Network Forensics Investigative Methodology
Here the course gives you a repeatable process for working a case from trigger to report. Exam items in this area tend to present a scenario and ask for the correct next step.
- Ordering of phases: preparation, detection, collection, analysis, reporting
- Choosing what to collect first when time is short
- Presenting findings in a way that withstands scrutiny
Domains 4-6: Network Evidence and Protocol Foundations
Domains 4 through 6 are the technical bedrock. If your networking experience has gaps, this is where they will show, and it is why the recommended two years of networking background carries weight.
Domain 4: Network-Based Evidence
This module catalogs where evidence lives on a network and what each source can and cannot tell you.
- Packet captures versus flow records versus device logs
- Strengths and blind spots of each evidence type
- Correlating multiple sources into one timeline
Domain 5: Network Principles
Core networking concepts, applied from an investigator's viewpoint rather than an administrator's.
- How the layered models structure communication
- Addressing, switching and routing as they affect where you can observe traffic
- Topology awareness: knowing where a capture point sits determines what it can see
Domain 6: Internet Protocol Suite
TCP/IP in depth. Because the recommended background explicitly includes TCP/IP, expect questions that assume fluency.
- Header fields and what anomalies in them can indicate
- TCP handshake, session behavior and teardown
- Common application protocols and how they appear on the wire
Domains 7-9: Getting the Traffic
Three modules deal with acquisition, which is the step where network forensics most differs from disk forensics.
Domain 7: Physical Interception
How traffic is tapped or mirrored at the physical or near-physical level.
- Passive taps versus switch port mirroring and the trade-offs of each
- What interception points introduce in terms of packet loss or alteration risk
- Choosing a capture location that sees the traffic of interest
Domain 8: Traffic Acquisition Software
The software side of capture: tools, filters and configuration choices.
- Capture filters versus display filters, and when each applies
- Capture settings that affect completeness and file size
- Verifying and documenting captures so they are defensible
Domain 9: Live Acquisition
Collecting evidence from systems and networks that cannot simply be powered down.
- Order of volatility when gathering from a running environment
- Minimizing your own footprint on a live system
- Balancing business continuity against evidence preservation
Domains 10-11: Analysis and Layer 2
Domain 10: Analysis
Where captured data becomes findings. This is the heart of the discipline, and it rewards hands-on practice more than memorization.
- Reconstructing sessions and extracting artifacts from captures
- Identifying anomalies against a baseline of normal behavior
- Building a timeline that ties network events to host and log evidence
Domain 11: Layer 2 Protocol
The data link layer is where many local attacks live and where many examiners are least comfortable.
- How switching and address resolution work, and how they can be abused
- Recognizing spoofing and poisoning behavior in captures
- Why Layer 2 evidence is often local and easy to miss from a distance
Analysis is also where the question of difficulty bites. If you want a realistic picture of what to expect, the C)NFE difficulty guide discusses it without relying on invented numbers.
Domains 12-14: Wireless Forensics
Three of the 20 modules are devoted to wireless, which is a clear signal of how seriously the course treats it. Candidates from wired-only backgrounds should budget extra time here.
Domain 12: Wireless Access Points
Understanding the infrastructure before you investigate it.
- How access points operate and what they log
- Identifying rogue or misconfigured access points
- Evidence an access point can yield about connected clients
Domain 13: Wireless Capture Traffic and Analysis
Capturing over the air differs from capturing on a cable, and the analysis differs too.
- Monitor-mode capture and why ordinary capture settings are insufficient
- Reading management, control and data frames
- Handling encrypted wireless traffic and what remains visible regardless
Domain 14: Wireless Attacks
The attack patterns an examiner needs to recognize after the fact.
- Deauthentication, rogue AP and evil-twin behavior and their traces
- Attacks against wireless authentication and encryption
- Translating attack signatures into evidence you can report
Domains 15-17: IDS, Logging and Network Devices
Domain 15: NIDS_Snort
The course uses Snort as its network intrusion detection reference. Know it as both a source of alerts and a source of evidence.
- Reading and interpreting Snort rule structure
- Understanding alerts versus the packets that triggered them
- False positives, tuning, and what an alert does and does not prove
Domain 16: Centralized Logging and Syslog
Logs are often the only record that survives, so how they are collected and protected matters.
- Syslog architecture, facilities and severity concepts
- Time synchronization and why unreliable timestamps wreck timelines
- Log integrity: preventing and detecting tampering
Domain 17: Investigating Network Devices
Routers, switches, firewalls and similar devices hold evidence in their configurations and state.
- What to collect from a device and in what order
- Configuration review for signs of unauthorized change
- Device logs and tables as corroboration for packet evidence
Key Takeaway
Domains 15 through 17 teach you that the packet capture is rarely the whole story. Expect scenario questions that ask you to combine an IDS alert, a syslog entry and a device state into one coherent conclusion.
Domains 18-20: Proxies, Tunneling and Malware
The final three modules cover the topics that complicate real investigations most: traffic that hides its content, traffic that hides its protocol, and the malicious software that produces both.
Domain 18: Web Proxies and Encryption
Web traffic dominates modern networks and much of it is encrypted.
- What proxy logs reveal even when payloads are encrypted
- How encryption limits visibility and what metadata remains
- Investigative value of proxy and cache evidence
Domain 19: Network Tunneling
Tunneling wraps one protocol inside another, often to evade controls.
- Recognizing tunneled traffic from timing, size and protocol oddities
- Legitimate versus malicious uses of tunnels
- Why tunnels frustrate signature-based detection
Domain 20: Malware Forensics
Closing the course, this module ties network behavior back to the malicious code driving it.
- Network indicators of compromise: beaconing, command-and-control patterns
- Connecting host artifacts to the traffic they generated
- Documenting malware behavior for incident response and reporting
Sequencing the Domains in Your Prep
Generic study advice is plentiful, so here is one short, C)NFE-specific scheduling suggestion. The point is ordering, because the later modules assume the earlier ones. For a fuller plan, see the C)NFE study guide.
Frame and Foundations (Domains 1-6)
- Lock down evidence handling and the investigative process
- Refresh TCP/IP until headers read naturally
Capture and Analyze (Domains 7-11)
- Practice captures and filters hands-on
- Work Layer 2 examples alongside analysis
Specialized Territory (Domains 12-20)
- Give wireless and Snort the most time if they are new to you
- Finish with tunneling and malware to tie everything together
Once you have worked through the material, test yourself. Our C)NFE practice tests help you find which of the 20 areas still need work, and the one-page C)NFE cheat sheet is useful for final review.
Credential Validity and Renewal
Passing is not the end of the commitment. The credential is valid for 3 years, and that validity is separate from any course or voucher access period. Mile2's current renewal paths allow you to renew with 60 documented qualifying CEUs earned within the 3-year cycle plus the applicable renewal fee, or through an accepted current-examination route. A policy and ethics acknowledgment applies. The U.S. CE-renewal fee is $200.
Note that an exam and CEUs are not universally cumulative requirements; follow Mile2's current renewal-path policy rather than assuming you must do both. If you are weighing whether the investment pays off, the C)NFE ROI analysis and the overview of C)NFE jobs are good next reads.
Frequently Asked Questions
No weights are published. The 20 items are official course modules presented as an unweighted preparation scope, so they should not be treated as a weighted or exhaustive exam blueprint. Plan to study all of them.
The exam has 100 multiple-choice questions to be completed in approximately 2 hours. The minimum passing score is 70%.
No. Purchasing the course is not required. The Exam Combo bundles the exam, a preparation guide, a practice quiz or simulator, and two exam attempts. Once both attempts are used, further paid access is needed.
The recommended profile is two years of networking, two years of IT security, and TCP/IP knowledge. These are course prerequisites describing readiness, not an asserted exam-admission gate.
It is valid for 3 years. Renewal currently runs through 60 documented qualifying CEUs within the cycle with the applicable fee, or an accepted current-examination route, along with a policy and ethics acknowledgment. The U.S. CE-renewal fee is $200.