CCE Study Guide 2026

Everything you need to pass the CCE exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.

📋 CCE Exam Format at a Glance

100
Questions
60 min
Time Limit
75.00%
Passing Score

📚 CCE Topics to Study (37)

✍️ Sample CCE Questions & Answers

1. Which mobile device extraction method provides the most comprehensive forensic data, including deleted files and unallocated space?
Physical extraction

Physical extraction creates a bit-by-bit copy of the entire device storage, including deleted data and unallocated space, making it the most comprehensive method.

2. What does JTAG stand for in the context of mobile device forensics?
Joint Test Action Group

JTAG stands for Joint Test Action Group, an industry standard hardware interface originally for circuit testing that forensic examiners use to access device memory directly through test ports.

3. A first responder arrives at a scene where a desktop computer is running. Network cables are connected. What should be done regarding the network connection?
Document the connection state before deciding whether to disconnect

The examiner should document the current state of network connections before taking any action, as the decision to disconnect depends on case specifics and may need to be justified later.

4. What is 'chip-off' forensics and when is it typically employed?
Physically removing flash memory chips from a device to read them directly with specialized equipment

Chip-off forensics involves physically desoldering and removing flash memory chips (NAND/NOR) from a device to read their raw contents when software-based acquisition methods fail.

5. Which layer of the OSI model do MAC addresses belong to, and why is this relevant to network forensics?
Layer 2 – Data Link

MAC addresses operate at Layer 2 (Data Link) and can help investigators identify specific network interface cards involved in an incident.

6. When examining the $UsnJrnl ($J) file in NTFS, what type of evidence does a forensic examiner primarily find?
A chronological log of file system changes including creates, deletes, and renames

The NTFS Update Sequence Number Journal ($UsnJrnl) records change reasons and timestamps for file and directory operations, providing a timeline of file system activity.

🎯 Free CCE Practice Tests

📖 CCE Guides & Articles

Your CCE Study Path
1. Learn with Flashcards → 2. Drill Practice Tests → 3. Take the Full Exam Simulation
Was this helpful?