CHFI (312-49)
CHFI is EC-Council's hands-on digital-forensics certification — the credential that proves you can acquire, preserve, and analyze evidence after a breach without breaking the chain of custody. It is ANSI/ISO-IEC 17024 accredited and DoD 8140-aligned, so for many SOC, incident-response, and government roles it is a hiring gate, not a nice-to-have. The exam is long and detail-heavy: 150 scenario questions across 15 forensics modules in a single 4-hour sitting, where a fail means a retake fee and a delayed clearance. This page breaks down exactly what 312-49 tests, how it's delivered, and how to get it done right the first time.
Pay Only After You Pass
No upfront fee — you settle only after your verified passing result. We advertise guaranteed results — 100% pass guaranteed or money back.
How the CHFI 312-49 exam is built — at a glance
150
Scenario-based multiple-choice items drawn from a large question bank. The exam is linear, not adaptive — you can flag and revisit questions freely within the time limit.
240
A full 4-hour window — roughly 96 seconds per question. Pacing is the real enemy: the case-study wording is long, so the time can disappear faster than it looks.
15
From hard-disk and file-system forensics to cloud, mobile, and IoT — every module is fair game, so broad coverage beats deep specialization in one area.
Expect tool-and-artifact questions ("which utility, which registry hive, or which log proves X?") wrapped in short investigation scenarios. Most are single-best-answer. Because there is no penalty for wrong answers, you should answer every question, flag the unsure ones, and circle back before time runs out.
EC-Council pulls each exam form from a bank and sets a per-form cut score based on item difficulty, so the threshold you must clear lands somewhere between 60% and 85%. You don't see your exact percentage in advance — you get a pass/fail result and, on failure, a score report by module so you know where to focus a retake.
CHFI v11 spans 15 modules across the full digital-forensics lifecycle
Computer forensics in today's world, the investigation process, legal compliance, chain of custody, and building a forensically sound case from first response to reporting.
Hard-disk structure, boot processes, and the FAT, NTFS, ext, and HFS+ file systems — interpreting where deleted and hidden data physically lives.
Write-blockers, bit-stream imaging, hashing for integrity, and live vs. dead acquisition — capturing evidence without altering the source.
Recognizing and countering data hiding, encryption, steganography, log tampering, and artifact wiping used to obstruct investigations.
Registry, event logs, prefetch, shellbags, and OS-specific artifacts across Windows, Linux, and macOS that reveal user and attacker activity.
Packet and log analysis, intrusion reconstruction, and static/dynamic malware analysis to trace how an attack moved through a network.
Investigating web attacks and server logs, tracing dark-web and Tor activity, and analyzing email headers in fraud and phishing cases.
Acquiring and analyzing evidence from AWS, Azure, and Microsoft 365 environments where data is shared, ephemeral, and jurisdiction-bound.
Extracting evidence from iOS and Android devices and from IoT hardware, app data, and embedded storage in connected-device investigations.
EC-Council does not publish a fixed per-module weighting, but in practice file-system, Windows, data-acquisition, and network/malware forensics carry the most questions. A balanced command of tools (Autopsy, FTK, EnCase, Wireshark, Volatility) plus the legal procedure around chain of custody is what separates a pass from a near-miss.
Where you can sit 312-49 — and what to expect on test day
EC-Council exams can be scheduled through Pearson VUE and taken in a quiet, monitored room. Staff verify your government-issued ID, store your belongings, and watch the room. You sit at a provided workstation with on-screen tools — no personal materials allowed.
CHFI can also be taken remotely from a private room — through Pearson VUE OnVUE (Remote Proctor Services) or the ECC Exam Portal. You'll complete a system test, a webcam room scan, and an ID check, then a live proctor monitors you for the full 4 hours.
A valid, unexpired government photo ID whose name matches your EC-Council registration exactly. The proctor captures a photo before the exam unlocks.
A clear desk, no second monitor, no phone within reach, and a 360° webcam scan of the room. No reference materials, notes, or other people in the space.
Stay in frame and on-camera the entire time. Breaks are restricted in the online format, and leaving the seat, talking aloud, or losing connection can flag the session.
CHFI is built for digital-forensics and incident-response roles
Two eligibility paths — and a broad, detail-heavy exam
Difficulty: CHFI is wide rather than deep. The trap is breadth — 15 modules of tool names, file-system artifacts, log formats, and legal procedure that all blur together under a 4-hour clock. Most candidates report needing genuine hands-on lab time, not just reading, which is exactly the kind of pressure point our help is designed to remove.
CHFI 312-49 is a long, broad, high-stakes exam standing between you and a forensics role or a security clearance. Exam Assist pairs you with a vetted digital-forensics specialist and works on a pay-after-you-pass model — so the risk sits with us, not you. No upfront fee, guaranteed results: Exam Assist handles the sitting end to end, and you settle only after the verified result.
Tell us your eligibility path, delivery method (Pearson VUE center, OnVUE, or ECC Portal), target test date, and where you stand on the 15 modules. Takes a couple of minutes over WhatsApp, Telegram, or Discord.
We review your timeline and target and tell you plainly whether it's realistic — before any money is discussed. If it isn't a fit, we say so.
Exam Assist handles the sitting end to end. You're matched with a CHFI specialist who maps the work around the high-yield modules, the tool/artifact question style, and your delivery environment — discreetly and confidentially.
You only pay once your passing result is confirmed. No verified result, nothing owed.
Tell us your exam details and get an honest, pay-after-you-pass plan — no upfront fee.
Straight answers about the CHFI 312-49 exam
Get help, or compare CHFI with sibling cybersecurity exams
Pair with a vetted digital-forensics specialist on a results-first arrangement. No upfront fee — settle only after a verified passing result.
Book CHFI help CEHEC-Council's flagship offensive-security cert — the natural counterpart to CHFI's defensive, forensic side.
View exam GCFEGIAC's Windows-focused forensics credential — a common alternative or complement to CHFI for DFIR roles.
View exam GCIHGIAC's incident-response credential — a natural DFIR companion to CHFI for SOC and breach-response work.
View exam CISAISACA's audit and assurance certification — frequently paired with forensics work in governance and compliance roles.
View exam CatalogExplore the full catalog of certification and admissions exams we support — from cybersecurity to cloud and beyond.
View catalogGet expert CHFI help with no upfront fee — you settle only after your verified passing result. Honest feasibility answer first, results-first arrangement always.