- How the 30 Domains Fit Into the CSFA Exam
- Legal, Evidence & Reporting Domains
- File System & Data Structure Domains
- Windows Artifact Domains
- Acquisition, Recovery & Network Domains
- How Domains Map to the 30/70 Scoring Split
- Registration, Fee, and Eligibility Facts
- Sequencing Domain Study Across a Prep Timeline
- Who Actually Tests These Domains on the Job
- FAQ
- The CyberSecurity Institute organizes the CSFA around 30 named content areas spanning legal, file-system, and Windows-artifact topics.
- A 50-question written exam (30% of the score) and a hands-on forensic case (70%) both draw from these 30 domains.
- Candidates need an overall 85% across roughly 29 hours 30 minutes of scheduled testing at Edmonds College.
- Domains like Windows registry, NTFS, and chain of custody appear repeatedly because the practical case tests them together, not in isolation.
How the 30 Domains Fit Into the CSFA Exam
The CyberSecurity Forensic Analyst (CSFA) credential, administered by the CyberSecurity Institute, doesn't test its 30 domains as separate quiz sections. Instead, the domains describe the full body of knowledge that a three-day advanced assessment draws from: a 50-question multiple-choice written portion worth 30% of the final score, and a hands-on forensic case worth 70%. Both halves feed into a single overall score, and candidates need 85% to pass.
Scheduled active testing runs 29 hours 30 minutes in total, all proctored in person exclusively at Edmonds College. That timeframe matters because it tells you something important about how the domains are actually tested: this isn't a credential you cram for the night before. The practical case alone consumes most of that time, and it forces you to move fluidly between domains - acquiring media, parsing file systems, recovering artifacts, and writing a legally defensible report - inside one continuous scenario rather than in neatly separated sections.
If you haven't yet reviewed the exam's overall difficulty profile, How Hard Is the CSFA Exam? Complete Difficulty Guide 2026 is a useful companion piece before diving into domain-level prep. For the exact scoring mechanics behind that 85% threshold, see CSFA Passing Score 2026: Exactly What You Need to Pass.
Legal, Evidence & Reporting Domains
A meaningful chunk of the 30 domains has nothing to do with hex editors or hashing algorithms - they concern whether your findings will survive contact with a courtroom. This cluster includes:
Domain 2: Affidavits, Motions, and Subpoenas
Candidates must understand the legal documents that authorize or compel forensic examination, and how to draft language that accurately reflects technical findings without overstating conclusions.
- Distinguishing an affidavit from a declaration in scope and evidentiary weight
Domain 7: Documentation, Chain of Custody, and Evidence Handling Procedures
Every acquisition and analysis step must be logged in a way that a third party could reconstruct. Chain-of-custody gaps are one of the fastest ways to lose credibility on the practical case.
- Recording hash values, timestamps, and custodian handoffs consistently
Domain 22: Rules of Evidence
You need working familiarity with how digital evidence is authenticated, admitted, and challenged - enough to shape both your acquisition methodology and your final report.
Rounding out this group: Domain 5 (creating understandable and accurate reports), Domain 13 (insurance/liability issues), Domain 21 (privacy issues), and Domain 30 (working as an expert technical witness). Together these seven domains explain why the exam explicitly expects candidates to already have comprehensive report-writing experience walking in - this isn't something you can learn from scratch during exam week.
Key Takeaway
Treat the report you produce for the practical case as if it will actually be read by an attorney. Vague findings or missing custody notes will cost points even if your technical analysis is correct.
File System & Data Structure Domains
This is the technical core most candidates associate with "digital forensics," and it's dense: FAT 16/32, NTFS, file headers and footers, hashes and checksums, encryption, and the various layers of slack and unallocated space.
Domain 18: NTFS
Deep knowledge of NTFS structures - MFT entries, alternate data streams, timestamp behavior - is non-negotiable since most modern Windows evidence you'll encounter uses this file system.
- How MFT resident vs. non-resident data affects recovery
Domain 10: File Slack, RAM Slack, Drive Slack, and Unallocated Space
Candidates must be able to explain and locate residual data in these areas, and articulate why data found there is or isn't reliable evidence.
Domain 19: Overcoming Encryption Mechanisms and Password Protection
You're expected to know practical approaches to encountering encrypted containers or password-protected files within a legally sound workflow - not theoretical cryptography.
Domains 8 (FAT 16/32), 9 (file headers and footers), 11 (hashes and checksums), and 16 (manual and automated data recovery) all interlock here. On the practical case, you'll likely need to identify a file type from its header after an extension has been altered, verify integrity with a hash, and recover it manually if a tool misses it - all in the same exhibit.
Windows Artifact Domains
Six domains focus specifically on Windows-native artifacts that consistently appear in real investigations and, by extension, in the CSFA's forensic case:
| Domain | What It Tests |
|---|---|
| Domain 24: Windows Print Spool Files | Evidence of printed documents and their content/metadata |
| Domain 25: Windows Prefetch | Program execution history and timeline reconstruction |
| Domain 26: Windows Registry | User activity, device history, installed software, configuration artifacts |
| Domain 27: Windows Shortcuts | LNK files as evidence of file/device access |
| Domain 28: Windows Swap File | Residual memory contents written to disk |
| Domain 29: Windows Volume Shadow Copy | Recovering deleted or prior versions of files and system state |
The registry (Domain 26) is arguably the densest single domain on the list - it touches user profiles, USB device history, network connections, and installed applications simultaneously. Expect the practical case to require you to pull several of these artifact types together to build a coherent timeline of user activity, rather than testing each one as an isolated fact.
Acquisition, Recovery & Network Domains
The remaining domains cover acquisition mechanics, search techniques, mobile devices, optical media, and networking fundamentals:
- Domain 1: Active, archival, and latent data - understanding where evidence physically and logically resides
- Domain 3: Compact Disc analysis
- Domain 4: Conducting keyword boolean searches across large data sets
- Domain 6: Creating forensically sound working copies or images of media
- Domain 12: Imaging handheld devices
- Domain 14: Interpretation of various log formats
- Domain 15: Interpreting Internet history and HTTP concepts
- Domain 17: Metadata for Microsoft Office and PDF documents
- Domain 20: PC hardware concepts
- Domain 23: TCP/IP concepts
Notice how closely this list mirrors the scenario language the exam itself uses: candidates should expect Windows media acquisition and analysis, mobile-device work, and legally useful reporting to appear together in a single case narrative. Domain 6 (forensically sound imaging) is the entry point for nearly every other domain on this page - if your working copy isn't sound, nothing recovered from it holds up.
How Domains Map to the 30/70 Scoring Split
Because the CyberSecurity Institute doesn't publish a percentage weighting per domain, the practical way to think about coverage is by exam component rather than by individual topic:
- Written exam (30%): 50 multiple-choice questions, closed reference, no Internet access. This section leans on domains that can be tested as discrete facts - file system structures, hash/checksum concepts, log format interpretation, legal definitions.
- Practical forensic case (70%): A continuous scenario where legal domains (chain of custody, reporting, affidavits) and technical domains (registry, NTFS, Prefetch, encryption) are exercised together against real evidence.
Given that the practical case carries more than double the weight of the written test, most of your preparation time should go toward hands-on domain application rather than flashcard-style memorization. For a full walkthrough of how to structure that preparation, CSFA Study Guide 2026: How to Pass on Your First Attempt goes deeper into method, while this article stays focused on domain content itself.
Registration, Fee, and Eligibility Facts
A few concrete logistics affect how you plan your domain study:
- The exam fee is $750, waived for Edmonds College students.
- All testing happens in person at Edmonds College - there is no remote-proctoring option.
- Candidates must complete an FBI criminal background check, which can take up to three months, so this needs to start well before you finalize a domain study schedule.
- The exam expects candidates to arrive with existing practical digital-forensics and report-writing experience - the domains assume a working foundation, not an introduction to the field.
Because the background check timeline alone can run three months, it's worth reviewing CSFA Requirements 2026: Eligibility, Prerequisites & How to Qualify and CSFA Exam Dates 2026: Testing Windows, Deadlines & Scheduling before you commit domain study time to a specific sitting. If you're still weighing whether the fee and time investment make sense for your career stage, CSFA Certification Cost 2026: Complete Pricing Breakdown lays out the full cost picture alongside these domains.
Sequencing Domain Study Across a Prep Timeline
Rather than studying all 30 domains in the order they're listed, group them by how they'll actually appear together in the practical case, and schedule the densest technical clusters earliest so they have time to solidify.
File Systems & Core Data Structures
- NTFS and FAT 16/32 (Domains 8, 18)
- File slack, RAM slack, unallocated space (Domain 10)
- Hashes, checksums, headers/footers (Domains 9, 11)
Windows Artifacts
- Registry, Prefetch, shortcuts, swap file (Domains 24-28)
- Volume Shadow Copy recovery (Domain 29)
Acquisition, Recovery & Networking
- Imaging media and handheld devices (Domains 6, 12)
- TCP/IP, log formats, Internet history (Domains 14, 15, 23)
Legal, Reporting & Full Case Simulation
- Chain of custody, affidavits, rules of evidence (Domains 2, 7, 22)
- Full timed practical simulation combining multiple domains
This sequencing isn't a generic template - it's built around how the CSFA practical case actually layers domains on top of each other. Once you've run through a full cycle, a condensed reference like CSFA Cheat Sheet 2026: One-Page Review of Must-Know Facts can help with final-week reinforcement.
Who Actually Tests These Domains on the Job
The domain list reads less like an academic syllabus and more like a checklist for practitioners who move between technical analysis and legal proceedings: law enforcement digital forensics units, corporate incident response teams, e-discovery and litigation support firms, and independent forensic consultants who prepare exhibits and testify as expert witnesses (Domain 30 directly). If you're evaluating whether this domain coverage aligns with your career direction, CSFA Jobs outlines the roles that typically reference this credential, and CSFA Salary Guide 2026: Complete Earnings Analysis and Is the CSFA Certification Worth It? Complete ROI Analysis 2026 can help you weigh the investment against where these 30 domains apply professionally.
Before you register, it's worth running a few practice scenarios that mirror this domain breadth rather than isolated trivia questions - our CSFA practice test platform is built specifically around these 30 content areas so you can gauge readiness domain by domain instead of guessing. You can also revisit the full CSFA prep hub for supporting guides as you move through each cluster above.
Frequently Asked Questions
The CyberSecurity Institute does not publish per-domain percentage weightings. Instead, domains are assessed across a 50-question written test (30% of the score) and a hands-on forensic case (70%), with technical and legal domains frequently tested together in the practical portion.
Windows registry (Domain 26), NTFS (Domain 18), and chain of custody/reporting (Domains 5 and 7) tend to require the most preparation time because they involve both technical depth and the ability to translate findings into a legally usable report.
Yes. Candidates should already have practical digital-forensics and comprehensive report-writing experience; the domains assume a working foundation rather than teaching forensics from zero.
During the practical portion, yes - Internet access, reference materials, and forensic hardware/software are permitted, though evidence images cannot leave the testing center. The written portion covering domain facts is closed reference with no Internet access.
Scheduled active testing totals 29 hours 30 minutes across the three-day advanced assessment, combining the written test and the hands-on forensic case.