EC-Council CHFI Computer Hacking Forensic Investigator Exam Practice Test

140 questions available

Build your confidence for EC-Council CHFI Computer Hacking Forensic Investigator Exam. Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.

Try a sample question
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
Certification exam
150 Exam questions
4 hours Time Limit
Your practice
140 Practice questions
2 hours 20 minutes Practice Time
Try 5 free questions
No account needed. A free account includes 20 questions for this exam.
The bar to clear 70 Published passing score for this certification.
Explore exam topics
EC-Council140 practice questions

Exam overview and details

The EC-Council Computer Hacking Forensic Investigator (CHFI) certification is a vendor-neutral, globally recognized credential that validates a professional's ability to conduct comprehensive digital forensic investigations. It equips cybersecurity professionals with the necessary skills to identify, preserve, analyze, and present digital evidence in a forensically sound manner. The certification covers the entire forensic investigation process, from first response and evidence acquisition to analysis and expert witness testimony in a court of law. CHFI-certified individuals are trained to investigate a wide array of cybercrimes, including data breaches, corporate espionage, insider threats, and other complex security incidents. By mastering tools, techniques, and legal standards, CHFI holders demonstrate a critical competency in the cybersecurity ecosystem, bridging the gap between incident response and legal prosecution. This certification is essential for roles that require methodical investigation to uncover the who, what, when, where, and how of a security breach, making it a cornerstone credential for professionals in digital forensics, incident response, and law enforcement.

Sample Questions

Choose an answer and explore the explanation to see how practice works.

Investigating Email Crimes

An email examined as evidence shows a DKIM-Signature header with d=example.com s=mail2024 b=. The examiner runs `dig example.com._domainkey.example.com TXT` and the response is empty (NXDOMAIN). What forensic conclusion is MOST defensible?

Network Forensics

An examiner reviewing Bro/Zeek logs from a Network Security Monitoring (NSM) deployment finds the following file in conn.log: a long-lived TCP connection (4 hours) from internal 10.0.5.42 to external 198.51.100.7 on port 443, with low byte counts (~2 KB total) and beacon-like timing (small packet every 60 seconds). What is the MOST plausible interpretation?

Dark Web Forensics

A digital forensic team is investigating an alleged dark-web marketplace transaction for stolen credit cards. The team has the URL of the .onion site and a Bitcoin address used by the suspect to fund the marketplace deposit. Which lawful investigative approach is MOST consistent with CHFI methodology?

Investigating Email Crimes

Microsoft 365's Unified Audit Log records mailbox-related activities. Which user action is recorded with the operation name "MailItemsAccessed" and what forensic value does it provide?

Network Forensics

An examiner is analyzing a PCAP and observes a flow with TLS handshakes but no plaintext HTTP. The CLIENT HELLO message contains an SNI (Server Name Indication) of "exfil.example.com". What useful evidence can be derived from the PCAP without breaking the encryption?

Career Opportunities & Salary

Median salary: $129,180– Information Security Analysts

Source: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Exam insights and study advice

The CHFI certification matters because it provides formal, industry-recognized validation of specialized forensic skills that are in high demand. In an era of escalating cybercrime and stringent regulatory compliance requirements, organizations and law enforcement agencies require proven experts who can conduct defensible investigations. Earning the CHFI distinguishes you as a qualified forensic investigator, significantly enhancing your credibility, employability, and earning potential. It signals to employers, clients, and courts that you possess the rigorous technical knowledge and adherence to legal procedures necessary to produce evidence that can withstand legal scrutiny. This certification is often a prerequisite or highly preferred qualification for advanced roles in cybersecurity forensics, incident response teams, and consulting firms, solidifying your position as a critical asset in the fight against cybercrime.

What this exam covers

01Cloud Forensics

02Computer Forensics in Today's World

03Computer Forensics Investigation Process

04Dark Web Forensics

05Data Acquisition and Duplication

06Database Forensics

07Defeating Anti-Forensics Techniques

08Investigating Email Crimes

09Investigating Web Attacks

10IoT Forensics

11Linux and Mac Forensics

12Malware Forensics

13Mobile Forensics

14Network Forensics

15Understanding Hard Disks and File Systems

16Windows Forensics

Exam Details 312-49 | $500 USD | 4 hours

Exam Code 312-49
Vendor EC-Council
Exam Cost $500 USD
Passing Score 70
Time Limit 4 hours
Exam questions 150
Question TypesMultiple Choice
Retake Policy No official waiting period specified between retakes. Full exam fee required for each retake.
Exam Format Linear
Online Proctoring Available
Available In
English

Frequently Asked Questions

What are the prerequisites for taking the CHFI exam?

How does CHFI differ from other digital forensics certifications?

What is the exam format and passing score?

What career roles is the CHFI certification suited for?

Is the CHFI certification recognized globally?