CCE Study Guide 2026
Everything you need to pass the CCE exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.
📋 CCE Exam Format at a Glance
📚 CCE Topics to Study (37)
✍️ Sample CCE Questions & Answers
1. Which mobile device extraction method provides the most comprehensive forensic data, including deleted files and unallocated space?
Physical extraction creates a bit-by-bit copy of the entire device storage, including deleted data and unallocated space, making it the most comprehensive method.
2. What does JTAG stand for in the context of mobile device forensics?
JTAG stands for Joint Test Action Group, an industry standard hardware interface originally for circuit testing that forensic examiners use to access device memory directly through test ports.
3. A first responder arrives at a scene where a desktop computer is running. Network cables are connected. What should be done regarding the network connection?
The examiner should document the current state of network connections before taking any action, as the decision to disconnect depends on case specifics and may need to be justified later.
4. What is 'chip-off' forensics and when is it typically employed?
Chip-off forensics involves physically desoldering and removing flash memory chips (NAND/NOR) from a device to read their raw contents when software-based acquisition methods fail.
5. Which layer of the OSI model do MAC addresses belong to, and why is this relevant to network forensics?
MAC addresses operate at Layer 2 (Data Link) and can help investigators identify specific network interface cards involved in an incident.
6. When examining the $UsnJrnl ($J) file in NTFS, what type of evidence does a forensic examiner primarily find?
The NTFS Update Sequence Number Journal ($UsnJrnl) records change reasons and timestamps for file and directory operations, providing a timeline of file system activity.