- The CCE exam has a 60-minute online component with at least 100 randomly generated multiple-choice questions, no notes or internet allowed.
- Candidates must also complete three consecutive forensic practical investigations with written reports.
- ISFCE's ten training modules - the "domains" in this guide - are preparation topics, not a published weighted blueprint.
- The Exam Process policy requires equal weighting across four components and an overall average of at least 80%.
How the CCE Exam Is Actually Structured
Before breaking down the ten content areas, it helps to understand what the Certified Computer Examiner (CCE) credential actually tests. The CCE is administered by the International Society of Forensic Computer Examiners (ISFCE), and its current Exam Process policy describes two distinct pieces: a proctored online component and a set of hands-on practical investigations.
The online component consists of at least 100 randomly generated multiple-choice questions delivered in a 60-minute sitting. ISFCE's Evaluation Standards policy requires this portion to be completed without books, notes, outside assistance, internet sites, or other reference materials - it's a closed-book assessment of foundational knowledge. The policy also permits up to ten experimental questions that are excluded from scoring, which means the exact scored-versus-unscored split delivered to any individual candidate isn't publicly documented.
After the knowledge component, candidates move into three consecutive forensic practical investigations, each requiring a written report. This practical phase is where the ten domains below get applied directly to simulated case evidence rather than tested as abstract trivia.
The 10 CCE Preparation Domains, Explained
ISFCE's current training page organizes CCE preparation into ten modules. These are the content areas most candidates refer to informally as "exam domains," and they're the backbone of this guide. It's worth being precise here: the module count reflects the structure of the issuer's training course, not a confirmed, officially weighted examination blueprint. No dated public exam version or per-topic percentage breakdown has been verified. Treat the list below as the most reliable public map of what you need to know - not as a guarantee of how many points each area is worth on test day.
Domain 1: Introduction to Digital Forensics
Foundational vocabulary and process. This sets up everything else - chain of custody, evidence handling, the forensic examination lifecycle, and the legal context examiners operate within.
- Chain-of-custody documentation habits
- Core forensic process stages: identification, preservation, analysis, reporting
Domain 2: Forensic Imaging
The mechanics of creating a defensible forensic copy of digital media. Expect emphasis on write-blocking, bit-stream imaging, and hash verification as the backbone of evidentiary integrity.
- Write-blocker use and justification
- Hash algorithms for image verification
- Common image file formats and their tradeoffs
Domain 3: File Types and Structures
Recognizing file signatures, headers, and internal structures independent of file extensions - a skill tested heavily when extensions have been altered or stripped.
- File signature (magic number) identification
- Metadata extraction and interpretation
- File carving fundamentals
Domain 4: File Systems: FAT, exFAT, Linux, UDF
Understanding how non-NTFS file systems allocate space, track directory entries, and leave recoverable traces after deletion.
- FAT/exFAT allocation table structures
- Linux file system artifacts
- UDF structures relevant to optical and removable media
Domain 5: NTFS File System
A deep-dive module given how dominant NTFS is in Windows forensic casework. The Master File Table, journaling, and alternate data streams are central concepts.
- Master File Table ($MFT) interpretation
- $LogFile and journaling artifacts
- Alternate data streams and timestamp behavior
Domain 6: Windows Forensics
Applying file-system knowledge to the broader Windows operating environment - the registry, logs, and user-activity artifacts examiners rely on most.
- Registry hives and key forensic locations
- Event logs, prefetch files, shellbags, and link files
- User activity reconstruction
Domain 7: macOS Forensics
Apple's file system and logging conventions differ substantially from Windows, and this module covers the structures unique to macOS examinations.
- APFS structures and volume behavior
- Property list (plist) files
- Unified logging artifacts
Domain 8: Mobile Forensics
Acquisition and analysis considerations specific to smartphones, where physical access restrictions and encrypted backups complicate standard imaging approaches.
- iOS and Android acquisition differences
- Backup file analysis
- App-level data artifacts
Domain 9: Email & Cloud Forensics
Tracing communications and remotely stored evidence, including the chain-of-custody challenges unique to data that doesn't live on a seized device.
- Email header and routing analysis
- Cloud service artifact collection
- Preservation considerations for remote data
Domain 10: Legal, Reporting & Ethics
Ties the technical modules back to admissibility and professional conduct - arguably the module most directly tested in the written practical reports.
- Report-writing standards for forensic findings
- Expert testimony fundamentals
- ISFCE ethics agreement and professional conduct expectations
If you want a condensed, single-page version of these ten areas for last-minute review, the CCE Cheat Sheet 2026: One-Page Review of Must-Know Facts consolidates the highest-value points from each module.
How the Domains Map to MCQ vs. Practical Work
Not every domain shows up the same way in both halves of the exam. The 60-minute online component draws broadly across conceptual knowledge - definitions, process steps, legal context, and file-system theory are well suited to multiple-choice format. The three practical investigations, by contrast, are where imaging, file-system analysis, OS-specific artifact recovery, and report writing get tested through actual simulated evidence.
| Exam Component | Format | Time/Structure | Domain Emphasis |
|---|---|---|---|
| Online knowledge component | ≥100 randomly generated multiple-choice questions | 60 minutes, closed-book, no internet or notes | Broad coverage across all 10 modules, weighted toward conceptual recall |
| Three practical investigations | Hands-on forensic case work with written reports | Completed consecutively; exact duration not publicly verified | Imaging, file systems, OS artifacts, and legal/reporting domains applied directly |
Key Takeaway
Don't study the ten modules as isolated flashcard topics. Domains 2 through 9 (imaging through cloud forensics) are the raw material for the practical investigations, while Domain 10's reporting and ethics expectations shape how your written reports are judged across all three practicals.
Scoring, Weighting, and the 80% Average
ISFCE's Exam Process policy specifies equal weighting across four components and requires an overall average of at least 80% to pass. Public policy language also references 75% as a component and retake threshold, alongside a separate rule removing candidates from the practical process below 70% - but the published wording is inconsistent about whether the 75% boundary is inclusive or exclusive. Because of that conflict, candidates should confirm the exact passing boundary and retake treatment directly with ISFCE rather than relying on secondhand interpretations. For a full breakdown of what's confirmed versus what needs verification, see CCE Passing Score 2026: Exactly What You Need to Pass.
Timing also matters beyond the 60-minute sitting itself. The online score carries a 90-day validity window, and candidates who tested after completing training must register to begin certification within 90 days as well. Confirm these windows match your own testing timeline - they are policy-driven deadlines, not flexible suggestions.
Registration, Fees, and Eligibility Routes
ISFCE's indexed store lists a $495 initial exam fee, a $150 retake fee, a $250 two-year recertification fee, and a $250 reinstatement fee. The public materials don't specify a member/non-member price split, so budget around the listed figures rather than assuming a discount tier exists. A full cost breakdown, including how these fees compare across the certification lifecycle, is covered in CCE Certification Cost 2026: Complete Pricing Breakdown.
Eligibility is where candidates most often get tripped up, because ISFCE's own pages describe it two different ways. The certification page lists alternative entry routes through issuer or authorized training, 18 months of verifiable experience, or a board-accepted digital-forensics credential - with full Member status requiring 18 months of experience while Associate status is available without it. The separately linked Exam Process policy instead describes training or a digital-forensics degree combined with 18 months of experience and 40 hours of documented self-study. These two descriptions aren't fully reconcilable from the public text alone, so confirm your specific path with ISFCE before assuming you qualify. Certification also requires a background check, an ethics agreement, a notarized independent-work statement, and board approval. The full eligibility picture, including these inconsistencies, is laid out in CCE Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Who Hires Around These Domains
The ten domains above aren't academic - they map directly to the work digital forensics examiners do in law enforcement, corporate incident response, e-discovery, and litigation support roles. Employers scanning resumes for forensic imaging competence, NTFS and mobile-device analysis skills, or report-writing experience are effectively screening for the same content areas this credential covers. If you're evaluating whether the CCE translates into employer recognition in your target sector, CCE Jobs breaks down the types of roles and hiring contexts where the certification tends to come up, and Is the CCE Certification Worth It? Complete ROI Analysis 2026 weighs the credential against the cost and time investment.
Scheduling Your Domain Review
Because the ten modules build on each other - file-type and file-system knowledge underpins both the Windows and macOS modules, and imaging fundamentals underpin all three practicals - a sequential review schedule tends to work better than jumping around. The timeline below sequences review by dependency rather than by arbitrary difficulty.
Foundations
- Domain 1: process, chain of custody, legal basics
- Domain 2: imaging and write-blocking mechanics
File-Level Knowledge
- Domain 3: file types and signatures
- Domain 4: FAT/exFAT/Linux/UDF structures
Operating System Depth
- Domain 5: NTFS internals
- Domain 6: Windows artifacts
- Domain 7: macOS artifacts
Devices, Communications, and Reporting
- Domain 8: mobile acquisition
- Domain 9: email and cloud artifacts
- Domain 10: reporting and ethics, plus practice investigations
Run timed practice sessions that mirror the real 60-minute, no-notes constraint rather than open-book review once you've covered the material once. Pairing content review with full practice exams is the fastest way to find weak domains before test day - our practice test platform lets you drill questions by topic area so you can spend extra reps on whichever module felt shakiest during Week 1 through 4. For a broader first-attempt strategy that goes beyond domain sequencing, see CCE Study Guide 2026: How to Pass on Your First Attempt.
Frequently Asked Questions
ISFCE's current training page lists ten preparation modules, which this guide treats as the domain structure. However, that module count reflects the issuer's training course organization, not a confirmed, officially weighted examination blueprint.
The online component includes at least 100 randomly generated multiple-choice questions drawn broadly from knowledge areas, but no verified public source breaks down exactly how many questions come from each of the ten modules.
The Exam Process policy requires equal weighting across four components and an overall average of at least 80%, but exact per-domain grading criteria for the practical investigations aren't published publicly. Confirm specifics with ISFCE.
Since the online component and all three practical investigations draw on this material broad
Ready to pass your CCE exam?
Put this into practice with free CCE questions across every exam domain.