- Certification-only entry costs $800 USD and requires 36 documented hours of competency-aligned training.
- The written exam is 125 questions, eight hours, open-book, unproctored, and needs an 80% minimum score.
- After passing the written exam, candidates complete a 30-day practical using forensic images and Windows artifacts.
- Only one retest is shared across the written exam and the practical combined - there is no separate retake pool.
Quick Facts Snapshot
This page exists to be reread the night before you sit the written exam, or the morning you start your 30-day practical clock. It is deliberately compressed - for the full breakdown of any single fact, see the CAWFE Study Guide 2026 or the dedicated pages on certification cost and eligibility requirements. Certified Advanced Windows Forensic Examiner (CAWFE) is administered by the International Association of Computer Investigative Specialists (IACIS) through its Advanced Certification Subcommittee, delivered via IACIS Moodle.
| Item | Detail |
|---|---|
| Certifying body | IACIS, via Advanced Certification Subcommittee |
| 2026 certification-only fee | $800 USD |
| Training prerequisite | 36 hours of competency-aligned training (documented) |
| Written exam length | 125 questions, 8-hour limit |
| Written passing score | 80% minimum |
| Written exam format | Open-book, unproctored, remote; clock cannot be paused |
| Question types | True/false, multiple choice, matching, short fill-in |
| Practical component | 30 days; forensic images and Windows artifacts; any tool allowed |
| Retest policy | One retest shared across written exam and practical combined |
| Scope document | Six WFE core competencies v1.1, effective April 4, 2024 |
| Renewal cycle | Every 3 years |
The Six Domains at a Glance
Everything on the written exam and in the practical traces back to six official Windows Forensic Examiner (WFE) core competencies. Memorize the names below cold - not just the topics, but the exact domain boundaries, because the exam writes questions that test whether you know which domain an artifact belongs to. A full walkthrough of each area lives in the CAWFE Exam Domains 2026 guide.
Domain 1: Windows Virtualization Technologies and Inbuilt Security Mechanisms
Covers how virtualization and native Windows protections shape what evidence exists and where it lives.
- Recognize virtual machine artifact locations and host/guest evidentiary implications
Domain 2: Windows Partitioning Schemes
Covers disk-level structures that determine how you locate and interpret file systems.
- Differentiate partition table types and their impact on evidence recovery
Domain 3: Windows File Systems
Covers the structures examiners rely on to recover, timestamp, and validate files.
- Understand metadata structures and how deletion/recovery behaves at the file-system level
Domain 4: Windows Registry
Covers hive structure and the registry keys examiners cite most often in casework.
- Locate user activity, device history, and system configuration artifacts within hives
Domain 5: Windows Artifacts
Covers the broad set of OS and application artifacts outside the registry that establish user activity.
- Know artifact locations, what each one proves, and common misinterpretation traps
Domain 6: Live Memory Acquisition and Analysis
Covers volatile evidence - what it captures, how it's acquired, and how it's analyzed.
- Understand acquisition order-of-operations and what memory reveals that disk images don't
Key Takeaway
Study domain names verbatim before content. On matching and fill-in questions, precise domain terminology (e.g., "partitioning scheme" vs. "file system") is often the difference between a wrong and right answer.
Exam Mechanics You Cannot Forget
The written exam's logistics trip up more candidates than the actual forensic content does. Keep these mechanics fixed in your head:
- 125 questions, eight hours. That's roughly 3.8 minutes per question if you use the full window - plenty of time if you're not also researching every answer from scratch.
- Open-book, but unproctored and remote. You may consult references, but the exam is still timed and the clock cannot be paused for any reason, including connectivity issues.
- Four question formats. True/false and multiple choice reward recognition; matching and short fill-in answers reward precise recall of terminology (registry key names, artifact paths, tool-agnostic concepts).
- 80% minimum to pass. There is no partial credit narrative - see the exact scoring mechanics in the CAWFE Passing Score breakdown.
For a realistic sense of how these mechanics translate into difficulty, read How Hard Is the CAWFE Exam? and cross-reference against documented outcomes in the CAWFE Pass Rate 2026 analysis before you schedule your attempt.
The 30-Day Practical, Distilled
Passing the written exam only clears you for the second component: a 30-day practical exercise built on forensic images and Windows artifacts drawn from the same six domains. Two mechanics define this stage:
- Any forensic tool may be used. There's no mandated toolset - commercial suites, open-source utilities, or a mix are all acceptable as long as your findings and methodology hold up.
- One retest, shared. The retest allowance applies across both the written exam and the practical combined, not separately to each. Fail the practical after already using your retest on the written exam, and there's no second cushion.
Key Takeaway
Treat the shared retest as a single life preserver for the entire certification path, not two. Prepare thoroughly enough for the written exam that you never need to spend it before the practical even begins.
Because the practical draws on the same Windows Registry, Windows Artifacts, and Live Memory Acquisition and Analysis domains as the written exam, strong domain notes from your written-exam prep double as your practical reference sheet. This overlap is exactly why the CAWFE Study Guide recommends building domain-by-domain artifact reference sheets rather than generic flashcards.
Renewal and Continuing Requirements
Certification is not permanent. Renewal runs on a three-year cycle and bundles several obligations together:
- A proficiency exercise completed in the third year of the cycle
- 40 documented continuing-education hours accumulated across the cycle
- Qualifying forensic work or proficiency tests to demonstrate active practice
- Ongoing ethical compliance
- Paid dues, or the applicable $150 nonmember/delinquent renewal fee if dues lapse
Final-Week Review Schedule
If you're reading this cheat sheet in the final stretch before your written exam date, don't restart your study plan - use the remaining days to compress and rehearse. This is the one place in this cheat sheet where generic study mechanics apply, and only because they map directly onto the six CAWFE domains.
Domains 1-2 Compression
- Rebuild your Virtualization/Security and Partitioning Schemes notes into one-page summaries
- Drill matching-style terminology for partition and virtualization concepts
Domains 3-4 Compression
- Condense File Systems metadata behavior and Registry key locations into quick-reference tables
- Practice short fill-in recall on hive and key names without notes
Domains 5-6 Compression
- Review Windows Artifacts locations and what each proves evidentially
- Rehearse Live Memory Acquisition order-of-operations from memory
Full Simulation
- Time yourself against a realistic question set spanning all six domains
- Confirm your open-book references are indexed and ready given the unpaused eight-hour clock
Run practice questions against the actual domain distribution rather than generic forensics trivia - the full practice test platform is built around these exact six domains so your final-week rehearsal matches the real exam structure.
Who Actually Uses This Credential
CAWFE sits above entry-level digital forensics work. It's built for examiners who already handle Windows-based investigations and need a credential that validates depth across virtualization, partitioning, file systems, registry, artifacts, and live memory - not a generalist survey certification. That specificity affects who values it on a resume and how it factors into hiring conversations; see the CAWFE Jobs overview and the CAWFE Salary Guide 2026 for how the credential is positioned in job postings and career progression. If you're still deciding whether the time and $800 investment make sense for your role, the ROI analysis weighs the certification against alternative uses of that same preparation time.
For readers who landed on this cheat sheet without the full background, start with What Is CAWFE? or CAWFE Meaning before diving into domain-level prep, and confirm your eligibility and scheduling window before committing to a study timeline. Formal CAWFE training can help satisfy the 36-hour competency-aligned training documentation required at registration.
Key Takeaway
This cheat sheet is a compression tool, not a first read. Use the CAWFE Study Guide and Exam Domains Guide to build understanding first, then return here for rapid-fire review.
FAQ
The written exam has 125 questions with an eight-hour time limit. It is open-book and unproctored but the clock cannot be paused once started.
You need a minimum score of 80% on the 125-question written exam to pass and move on to the 30-day practical component.
No. Only one retest is shared across both the written exam and the practical combined, so using it on the written exam leaves no separate retake for the practical.
Any forensic tool may be used for the practical component, which is built around forensic images and Windows artifacts spanning the six WFE core competencies.
Renewal occurs every three years and requires a third-year proficiency exercise, 40 documented continuing-education hours, qualifying forensic work or proficiency tests, ethical compliance, and paid dues or the applicable $150 nonmember/delinquent renewal fee.