EC-Council · CHFI
Validates the ability to detect hacking attacks, extract and preserve digital evidence, and conduct forensic investigations, covering digital forensics methodology, evidence acquisition, chain-of-custody procedures, dark web forensics, IoT forensics, and malware forensics.
Practice Questions
589
≈ 4 practice exams
Duration
240 minutes
Passing Score
60%-85% (varies)
Difficulty
AssociateLast Updated
Oct 2026
CHFI v11 covers the complete digital-forensics process: lawful preparation, acquisition and preservation, examination, analysis, and reporting across disks, file systems, memory, networks, web attacks, databases, email, malware, cloud services, mobile devices, the dark web, and IoT. The goal is defensible evidence handling and reconstruction, not simply knowing forensic-tool names.
Exam 312-49 has 150 multiple-choice questions and allows four hours through the EC-Council Exam Portal. EC-Council uses multiple exam forms and says the cut score can vary from 60% to 85% depending on the form, so 70% is not a universal passing score. Official training grants eligibility; self-study candidates need two years of information-security experience and an approved eligibility application.
Use these 589 questions to practise the investigation sequence and preserve evidentiary integrity at every step. Pair review with hands-on acquisition and analysis of disk images, memory dumps, packet captures, logs, and cloud artifacts, and be able to explain hashing, write blocking, chain of custody, timelines, anti-forensics, and reporting decisions.
EC-Council Computer Hacking Forensic Investigator (CHFI) v11 validates the digital-forensics process from preparation and evidence acquisition through examination, analysis, and reporting. It covers storage and file systems, operating systems, memory, networks, web attacks, databases, email, malware, cloud services, mobile devices, the dark web, and IoT.
The central skill is producing reliable, defensible findings while preserving evidence integrity and chain of custody. Candidates need both technical analysis and an understanding of the procedural and legal context in which evidence is collected and reported.
CHFI is designed for cybersecurity and IT professionals who investigate, respond to, or prosecute cybercrime. Primary job roles include forensic computer analysts, cyber defense forensic analysts, malware analysts, incident responders, information security professionals, and IT auditors. It is also well-suited for law enforcement personnel, military and defense professionals, legal professionals who need to understand digital evidence, and banking or insurance professionals dealing with fraud investigations.
Candidates typically have a background in information technology or cybersecurity and are looking to specialize in digital forensics. The program is appropriate for both practitioners aiming to formalize existing skills and professionals transitioning into a DFIR-focused role. While there is no strict experience prerequisite if attending official training, those applying via the self-study eligibility path should have at least two years of information security experience.
There are no mandatory prerequisites for candidates who enroll in an official EC-Council authorized training program (via Training Partner, iLearn self-study, or iWeek live online). Attending the official CHFI course grants automatic eligibility to sit the exam upon completion.
Candidates who wish to challenge the exam without attending official training must submit an EC-Council Exam Eligibility Application, pay a non-refundable $100 eligibility fee, and demonstrate a minimum of two years of professional experience in the information security field. Practically, EC-Council recommends that candidates possess foundational knowledge of networking concepts, operating systems (Windows, Linux, macOS), cybersecurity fundamentals, and basic incident response procedures before undertaking CHFI study. Prior exposure to ethical hacking concepts (such as through CEH) is beneficial but not required.
CHFI exam 312-49 has 150 multiple-choice questions and allows four hours through the EC-Council Exam Portal. EC-Council administers multiple exam forms and states that the cut score can range from 60% to 85% according to the form, so 70% is not a universal passing score.
Candidates who complete official training are eligible for the exam. Self-study candidates must document at least two years of information-security experience and obtain approval through EC-Council's eligibility application process.
CHFI demonstrates a broad foundation for digital-forensics and incident-response work, including evidence handling, acquisition, analysis, reconstruction, and reporting. It is relevant to forensic analyst, incident responder, cybercrime investigator, malware analyst, and security-investigation roles.
The credential is most useful when paired with demonstrable lab work and familiarity with the evidence sources used in the target role. Holders maintain it through EC-Council's continuing-education cycle.
5 sample questions with answers and explanations. The full bank has 589 questions, enough for 4 full-length practice exams.
Preview — answers shown1. A forensic analyst uses Hashcat to crack NTLM password hashes recovered from a Windows system. Which Hashcat mode number (-m parameter) should be used for NTLM hashes? (Select one!)
Explanation
Hashcat mode 1000 (-m 1000) is specifically designated for NTLM hashes recovered from Windows systems. NTLM is the authentication protocol hash format used in modern Windows environments. Mode 0 (-m 0) is for MD5 hashes. Mode 100 (-m 100) is for SHA1 hashes. Mode 5600 (-m 5600) is for NetNTLMv2 challenge-response hashes captured during network authentication, which differs from the stored NTLM password hashes in SAM or memory dumps.
2. An investigator analyzing an iOS device backup discovers timestamps stored in Apple/Cocoa time format showing a value of 725846400. What is the correct Unix timestamp for this value? (Select one!)
Explanation
Apple/Cocoa time measures seconds since January 1, 2001, while Unix time measures seconds since January 1, 1970. The conversion requires adding 978,307,200 seconds (the difference between the two epochs) to the Cocoa timestamp. Calculation: 725,846,400 + 978,307,200 = 1,704,153,600, which converts to January 2, 2024 00:00:00 UTC. Using the raw Cocoa value without conversion produces incorrect dates. The value 1546300800 represents January 1, 2019 but does not correspond to the given Cocoa timestamp. The value 978307200 is the conversion constant itself, not the converted timestamp.
3. A cybersecurity incident response team discovers that the Windows Security event log has been cleared during a suspected breach. Which Event ID would appear in the logs to indicate this anti-forensics activity? (Select one!)
Explanation
Event ID 1102 indicates the audit log was cleared and is a critical indicator of evidence tampering or anti-forensics activity. This event is recorded when an attacker or insider clears the Security log to hide their activities. The event captures who cleared the log and when, making it valuable evidence of intentional log manipulation. Event ID 4624 records successful logon events used to track user activity and lateral movement. Event ID 4688 records process creation events useful for execution timelines. Event ID 7045 appears in the System log when a new service is installed, indicating persistence mechanisms. Only Event ID 1102 specifically indicates log clearing activity.
4. A malware analyst examines a memory dump using Volatility and wants to detect API hooks that malware may have installed. Which Volatility 2 plugin identifies hooked API functions in user mode and kernel mode? (Select one!)
Explanation
The apihooks plugin in Volatility 2 detects API hooks in both user mode (Inline hooks, IAT hooks, EAT hooks) and kernel mode. It identifies when API functions have been redirected to malicious code, a common malware persistence and evasion technique. The malfind plugin detects injected code via memory characteristics but not specifically API hooks. The ssdt plugin examines the System Service Descriptor Table for kernel-level SSDT hooks but not user-mode API hooks. The idt plugin checks the Interrupt Descriptor Table for interrupt hooks, which is different from API hooking.
5. During Android forensics of a device with File-Based Encryption (FBE), an investigator examines data accessible before the first user unlock. Where is this DirectBoot data located? (Select one!)
Explanation
Android File-Based Encryption introduced DirectBoot mode where certain data remains accessible before first user authentication. This device-encrypted (DE) storage is located at /data/user_de/ and contains data needed for core system functions like alarm clock and accessibility services. After first unlock, credential-encrypted (CE) storage at /data/user/0/ becomes accessible with full user data. The /data/data/ path is a legacy symlink to /data/user/0/. Understanding FBE's two-tier encryption model is critical for Android forensics as it affects what data can be extracted in different device states.
The EC-Council Computer Hacking Forensic Investigator exam code is 312-49, aligned to CHFI v11.
CHFI has 150 multiple-choice questions and a four-hour time limit.
There is no universal 70% cut score. EC-Council says the threshold varies by exam form from 60% to 85%.
Yes, after EC-Council approves an eligibility application based on at least two years of information-security experience; an application fee applies.
It covers forensic process, storage and file systems, acquisition, anti-forensics, operating systems, networks, web attacks, databases, email, malware, cloud, mobile, dark-web, and IoT evidence.
CHFI participates in EC-Council's continuing-education program and is maintained on a three-year cycle.
Digital Forensics Essentials (DFE)
DFE · 626 questions
EC-Council Certified Incident Handler (ECIH)
ECIH · 590 questions
Certified Ethical Hacker (CEH)
CEH · 594 questions
Certified Chief Information Security Officer (CCISO)
CCISO · 578 questions
Certified EC-Council Instructor (CEI)
CEI · 611 questions
Certified Cloud Security Engineer (CCSE)
CCSE · 624 questions
$17.99
One-time access to this exam