Certified Network Forensics Examiner Exam Prep
Free practice questions

Free C)NFE Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The C)NFE exam has 100 questions and runs 2 hours.

These 10 free C)NFE questions are organized by exam domain, so you can see how each part of the Certified Network Forensics Examiner blueprint is tested. Reveal the answer and explanation under each question.

Domain 3: Network Forensics Investigative Methodology

Question 1

A forensic examiner defines scope, identifies evidence sources, and establishes investigative objectives before collecting data. Which methodology is being applied?

Show answer & explanation

Correct answer: A - OSCAR network forensic methodology

Domain 5: Network Principles

Question 2

Adding headers as data moves down network layers and removing them during receipt describes which concept?

Show answer & explanation

Correct answer: A - Encapsulation and de-encapsulation

Domain 8: Traffic Acquisition Software

Question 3

Which tool is designed to capture packets from a network interface using libpcap?

Show answer & explanation

Correct answer: A - tcpdump

Domain 9: Live Acquisition

Question 4

A running server may contain valuable volatile evidence that would disappear after shutdown. What should the examiner prioritize?

Show answer & explanation

Correct answer: A - Live acquisition of volatile information

Domain 10: Analysis

Question 5

An analyst reviews packet details, flows, and application-layer behavior to reconstruct an incident. What activity is this?

Show answer & explanation

Correct answer: A - Network traffic analysis

Domain 11: Layer 2 Protocol

Question 6

An investigation focuses on Spanning Tree Protocol manipulation on a switch. Which area is involved?

Show answer & explanation

Correct answer: A - Layer 2 protocol analysis

Domain 13: Wireless Capture Traffic and Analysis

Question 7

When analyzing an 802.11 capture, which evidence is most relevant?

Show answer & explanation

Correct answer: A - Wireless frames and associated traffic

Domain 15: NIDS_Snort

Question 8

A NIDS alert identifies suspicious traffic. What evidence should validate the activity?

Show answer & explanation

Correct answer: A - Packet captures and NIDS evidence

Domain 16: Centralized Logging and Syslog

Question 9

Why collect router, firewall, and server logs in a centralized repository?

Show answer & explanation

Correct answer: A - To correlate distributed events

Domain 17: Investigating Network Devices

Question 10

Evidence collected from a router involved in suspicious routing activity belongs to which investigation area?

Show answer & explanation

Correct answer: A - Investigating network devices

The rest of the C)NFE blueprint

The C)NFE exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more C)NFE questions with explanations.

Continue in the free practice test →

View plans