National data — wages and growth are not published by state for this view.
Certification
Certified Forensic Computer Examiner (CFCE)
International Association of Computer Investigative Specialists
Median earnings
—
Cost
$800
Duration
—
Completion
—
The Certified Forensic Computer Examiner (CFCE) certification program is based on a series of core competencies in the field of core competencies in the field of computer/digital forensics. The candidate is required to demonstrate their knowledge of the CFCE core competencies and practical skills by successfully completing the peer review, practical and written examination instruments.
Apply rules of evidence and ethical standards in computer forensic investigationsConduct computer search and seizure procedures using proper documentation and photographic methods in forensic contextsExplain on-scene evidence preservation actions for physical and volatile digital evidence including mobile devicesEstablish and document a forensically sound examination environment in digital investigationsRecognize evidential potential of computer hardware and small-scale devices in forensic examinationsInterpret BIOS, UEFI, and boot processes in computer forensic analysisApply binary, decimal, and hexadecimal numbering systems in digital forensic investigationsAnalyze storage structures including sectors, clusters, volumes, and file slack in forensic contextsDifferentiate between logical and physical drives and files in forensic analysisExplain media formatting processes and their impact on data in forensic investigationsIdentify partition schemes and their structures across systems in forensic analysisDifferentiate between primary and extended partitions in disk management contextsExplain the use of GUIDs in partitioning and system identification contextsAnalyze file system structures including FAT, exFAT, and NTFS in forensic examinationsExamine and parse NTFS master file table attributes in digital forensic investigationsIdentify and analyze deleted or orphaned files in forensic file system analysisIdentify file systems used by Apple and Linux operating systems in forensic contextsApply hashing techniques to validate data integrity in forensic investigationsGenerate and validate forensically sterile media for evidence handlingCreate and verify forensic images of digital media in investigationsCapture volatile data from memory in digital forensic contextsAnalyze file headers and fragmentation in data recovery processesExtract metadata and data from common and compound file types in forensic analysisApply techniques to recover encrypted data and analyze internet and browser artifacts in investigationsCollect and analyze data from cloud storage environments in forensic contextsLocate and analyze Windows artifacts including registry, event logs, and system files in forensic investigationsExtract and interpret data from Windows registry, recycle bin, and system caches in forensic analysisAnalyze system artifacts such as shell links, jump lists, and virtual drives in Windows environmentsInterpret swap files, hibernation files, and shadow copies for forensic evidenceDraw conclusions from forensic findings to support investigative outcomes