CAWFE logo
Focused certification exam prep
Start practice

CAWFE Exam Domains 2026: Complete Guide to All 6 Content Areas

TL;DR
  • The CAWFE scope follows six official WFE core competencies, version 1.1, effective April 4, 2024.
  • Domains cover virtualization, partitioning, file systems, registry, artifacts, and live memory analysis.
  • The 125-question written exam has an eight-hour limit and requires an 80% minimum score.
  • A 30-day practical using forensic images tests the same six domains hands-on, with any tool allowed.

Overview: How the Six Domains Fit Together

Every question on the CAWFE written exam and every task in the practical component traces back to one of six official WFE core competencies (version 1.1, effective April 4, 2024). These domains are not arbitrary categories invented by a training vendor - they represent the actual workflow of a Windows forensic examiner, from identifying how a suspect system was configured down to pulling volatile evidence out of live memory before it disappears.

Understanding this structure matters because IACIS' Advanced Certification Subcommittee builds both the 125-question written exam and the 30-day practical around the same competencies. If you know the six domains cold, you're not just prepping for a written test - you're prepping for the entire certification, including the parts your grader won't multiple-choice for you. For a broader walkthrough of how to sequence your prep, see the CAWFE Study Guide 2026. This article focuses specifically on what lives inside each domain.

Why Domain Fluency Beats Memorization: The written exam is open-book and unproctored, which means IACIS isn't testing whether you can recall a fact under pressure - it's testing whether you can locate, interpret, and apply Windows forensic knowledge fast enough to finish 125 questions in eight hours. Domain fluency, not flashcard memorization, is what gets you through in time.

Domain 1: Windows Virtualization Technologies and Security Mechanisms

What Candidates Must Understand

This domain covers how Windows systems run inside virtual environments and how built-in security features affect what an examiner can see and recover. Virtualization changes where evidence lives - a virtual machine's disk may be a single file, its memory state may be suspended rather than live, and its security boundary may differ from a physical host.

  • Common Windows virtualization platforms and how their disk/snapshot files are structured
  • How hypervisor-level isolation affects evidence acquisition
  • Windows inbuilt security mechanisms (encryption, credential protection, secure boot concepts) and how they alter accessibility of artifacts
  • Recognizing when a target system is virtualized versus physical during triage

Examiners who skip this domain often assume every image they touch is a straightforward physical disk capture. In practice, virtualized environments are increasingly common in both corporate and criminal casework, and the CAWFE written exam expects you to reason through how virtualization changes acquisition and analysis decisions - not just define terms.

Domain 2: Windows Partitioning Schemes

What Candidates Must Understand

Before you can analyze a file system, you need to correctly interpret how a disk is partitioned. This domain tests your ability to read partition tables and understand how Windows organizes storage at the disk level.

  • MBR versus GPT partition structures and how to identify each
  • Boot sector and partition table field interpretation
  • How partition offsets affect file system parsing and evidence location
  • Recognizing hidden, deleted, or unallocated partition space

Partitioning questions on the written exam frequently present raw hex or structural data and ask you to identify what you're looking at. This is a domain where hands-on repetition with real disk images pays off far more than reading definitions - a point worth remembering when you plan your CAWFE training hours.

Domain 3: Windows File Systems

What Candidates Must Understand

File system knowledge is the backbone of Windows forensics. This domain expects command of how Windows file systems store, timestamp, and delete data, and how examiners reconstruct file activity from structural remnants.

  • NTFS structures including the Master File Table, attributes, and metadata timestamps
  • How file creation, modification, access, and deletion are recorded and how they can be manipulated
  • Slack space, unallocated clusters, and file carving concepts
  • Differences between file systems an examiner may encounter on Windows systems

This domain carries significant weight in practical terms because so many later artifacts (Domain 5) and registry findings (Domain 4) depend on correctly interpreting the underlying file system first. Get the file system wrong, and everything built on top of it is suspect.

Key Takeaway

Treat file system mastery as a prerequisite skill, not a standalone topic - nearly every artifact and registry question assumes you already understand where and how the data was stored.

Domain 4: Windows Registry

What Candidates Must Understand

The registry is one of the richest sources of Windows evidence, and this domain tests both structural knowledge and investigative application.

  • Registry hive structure, locations, and load order
  • Key artifacts stored in the registry: user activity, device history, network connections, program execution evidence
  • Interpreting timestamps and values within registry keys for timeline reconstruction
  • Recovering and interpreting deleted or backup registry data

Registry questions on the written exam tend to be scenario-driven: you're given a described finding and asked what it indicates about user or system behavior. This is a domain where short fill-in answer formats on the exam reward precise recall of hive and key names, not just general familiarity.

Domain 5: Windows Artifacts

What Candidates Must Understand

This is the broadest domain, covering the wide range of Windows-generated artifacts examiners rely on to reconstruct user and system activity outside the registry itself.

  • Event logs and their role in timeline reconstruction
  • Link files, jump lists, and recent-activity artifacts
  • Browser and application artifacts relevant to user behavior
  • Prefetch, thumbnail caches, and other execution or access indicators

Because the practical component gives you 30 days with forensic images and lets you use any forensic tool, Domain 5 is where tool proficiency and artifact knowledge intersect most directly. Knowing an artifact exists is not enough - you need to know where to find it and how to explain its evidentiary meaning in your written findings.

Breadth Warning: Domain 5 spans more individual artifact types than any other domain. Candidates who underestimate its scope often discover gaps only after starting the practical, where there's no multiple-choice list to jog their memory.

Domain 6: Live Memory Acquisition and Analysis

What Candidates Must Understand

Live memory work rounds out the six domains and tests skills distinct from static disk analysis. Volatile data has to be captured correctly and interpreted with an understanding of what's lost the moment a system powers down.

  • Memory acquisition methods and their impact on evidence integrity
  • Process, network connection, and loaded-module analysis from memory captures
  • Identifying malicious or anomalous activity through memory artifacts
  • Correlating memory findings with disk-based evidence from other domains

Live memory questions on the written exam often require you to reason about acquisition order and evidentiary priority - a conceptual skill, not just a tool-button skill. This domain benefits from deliberate practice using captured memory images well before exam day.

How the Domains Map to the Written Exam and Practical

The CAWFE assessment has two distinct components, and both draw from the same six domains, just in different formats.

ComponentFormatTime LimitPassing Standard
Written ExamTrue/false, multiple choice, matching, short fill-in8 hours, unproctored, remote80% minimum
PracticalForensic images and Windows artifact analysis, any tool allowed30 daysEvaluated by Advanced Certification Subcommittee

The written exam is open-book and remotely accessible, but its clock cannot be paused - so domain fluency directly determines how much time you spend searching versus answering. The practical, by contrast, gives you a full month but no multiple-choice cues; you have to independently apply Domain 1 through Domain 6 knowledge to real images. For a full breakdown of what "passing" actually requires numerically, see CAWFE Passing Score 2026, and for a candid look at overall difficulty across both components, read How Hard Is the CAWFE Exam?.

Remember also that only one retest is shared across both the written exam and the practical - so a weak grasp of even one domain can cost you your only safety net. That's a strong argument for treating domain review as inseparable from exam registration planning; check CAWFE Requirements 2026 and CAWFE Exam Dates 2026 before you commit to a testing window.

Scheduling Your Prep Around the Domains

Rather than studying domains in the order IACIS lists them, sequence your review based on dependency. File systems (Domain 3) underpin registry analysis (Domain 4) and artifact interpretation (Domain 5), so those three domains work best studied in close succession. Virtualization (Domain 1) and partitioning (Domain 2) are more self-contained and can be studied early or reviewed briefly at the end. Live memory analysis (Domain 6) is distinct enough to deserve its own dedicated block.

Weeks 1-2

Foundations

  • Domain 2: Windows Partitioning Schemes
  • Domain 1: Virtualization Technologies and Security Mechanisms
Weeks 3-5

Core File and Registry Analysis

  • Domain 3: Windows File Systems
  • Domain 4: Windows Registry
  • Domain 5: Windows Artifacts
Week 6

Volatile Evidence

  • Domain 6: Live Memory Acquisition and Analysis
Weeks 7-8

Integration and Timed Practice

  • Cross-domain scenario review
  • Timed practice runs to simulate the eight-hour written exam clock

This sequencing isn't a generic productivity template - it's built around how the domains actually depend on each other in real casework, and how the exam tends to blend them in scenario-based questions. If you want a condensed reference to keep nearby during final review, the CAWFE Cheat Sheet 2026 summarizes must-know facts across all six domains in one page.

Also budget time for practicing with actual timed question sets rather than just reading materials. Running full-length simulations on our practice test platform before exam day helps you gauge whether your domain knowledge translates into speed under the unproctored eight-hour clock.

Training and Fee Context: The 2026 certification-only entry fee is $800 USD, and candidates must document 36 hours of competency-aligned training before sitting the exam. Make sure whatever training you complete explicitly maps to these six domains - see CAWFE Certification Cost 2026 for the full pricing breakdown.

Because the domains are so specific to Windows internals, generic digital forensics courses won't necessarily satisfy the training requirement or prepare you adequately. Look for training that explicitly names virtualization, partitioning, file systems, registry, artifacts, and live memory as separate modules - that alignment is a good signal the material was built with this exact certification in mind. For context on who values this credential and where it leads professionally, see the CAWFE Salary Guide 2026 and CAWFE Jobs, or step back and evaluate whether the certification is worth it for your career goals.

Frequently Asked Questions

How many domains are on the CAWFE exam?

There are six official WFE core competencies, version 1.1, effective April 4, 2024: Windows Virtualization Technologies and Security Mechanisms, Windows Partitioning Schemes, Windows File Systems, Windows Registry, Windows Artifacts, and Live Memory Acquisition and Analysis.

Are all six domains weighted equally on the written exam?

IACIS has not published specific per-domain weighting, so candidates should prepare all six domains thoroughly rather than assuming any single domain carries more or less weight than another.

Do the six domains apply to the practical component too?

Yes. The 30-day practical uses forensic images and Windows artifacts, drawing on the same six domains tested in the written exam, so domain knowledge must translate into hands-on tool application.

Which domain should I study first?

Many candidates start with partitioning schemes and virtualization since they're relatively self-contained, then move into file systems, registry, and artifacts, which build on one another before tackling live memory analysis.

Can I use any forensic tool to study for the artifact and memory domains?

Yes, the practical component allows any forensic tool, so candidates can practice with whichever tools they're most proficient in while still needing to demonstrate domain knowledge across all six competency areas.

Ready to pass your CAWFE exam?

Put this into practice with free CAWFE questions across every exam domain.