CERTIFIED CYBER CRIME
INVESTIGATOR (CCCI)
EXAM
QUESTIONS AND
VERIFIED ANSWERS
WITH RATIONALES
EXAM SPECIFICATIONS
Time Allocation: 3 Hours
Total Questions: 100 Questions
Question Format: Multiple Choice with Detailed Rationales
Minimum Competency: 75% Required to Pass
Core Focus: Digital Forensics, Cyber Law, Evidence, Investigation, Incident Resp
Certified Cyber Crime Investigator CCCI Exam Page 1
, Exam Overview & Content Outline
EXAM PURPOSE
Certified Cyber Crime Investigator (CCCI) Exam validates competency in digital forensics, cybercrime
investigation, evidence handling, cyber law, and incident response per current standards. Required
for professionals investigating computer crimes, data breaches, and digital evidence.
CONTENT DISTRIBUTION
• Digital Forensics Fundamentals (25%) — Forensic process, acquisition, imaging, hashing, chain
of custody
• Cyber Law & Legal Issues (25%) — CFAA, ECPA, 4th Amendment, search warrants, admissibility,
privacy
• Investigation Techniques (30%) — Windows/Unix artifacts, network forensics, mobile forensics,
malware analysis
• Incident Response & Reporting (20%) — IR lifecycle, containment, eradication, recovery, report
writing
QUESTION FORMAT & SCORING
Each item presents four options. Correct answers are highlighted in green with checkmark (✓).
Every question includes detailed rationale with legal and technical standards. Requires 75% to pass.
STUDY STRATEGY
Master forensic acquisition and hashing. Know chain of custody and evidence handling. Understand
4th Amendment and warrant requirements. Study Windows Registry, logs, and artifacts. Review
network forensics and packet analysis. Know IR phases: preparation, detection, containment,
eradication, recovery, lessons learned.
CURRICULUM ALIGNMENT
Questions reflect current standards: NIST SP 800-86, NIST SP 800-61, Federal Rules of Evidence,
Computer Fraud and Abuse Act (CFAA), Electronic Communications Privacy Act (ECPA), and digital
forensics best practices.
Certified Cyber Crime Investigator CCCI Exam Page 2
, SECTION I: Digital Forensics Fundamentals
1. First step in forensic investigation per NIST SP 800-86:
A. Analyze data
✓ B. Collection/Acquisition
C. Report findings
D. Eradicate malware
Rationale: NIST SP 800-86 forensic process: Collection → Examination → Analysis → Reporting.
Collection/Acquisition first: identify sources, acquire data using forensically sound methods. Must maintain
integrity. Order of volatility: memory → network → processes → disk. Never work on original evidence.
2. Hash function used to verify evidence integrity:
A. Encryption
✓ B. MD5 or SHA-256
C. Compression
D. Encoding
Rationale: Hashing: One-way function creates unique fingerprint. MD5 (128-bit, deprecated), SHA-1
(160-bit, deprecated), SHA-256 (256-bit, current). Hash original and image, must match. Any change =
different hash. Chain of custody documents hash values. Collision resistance critical. MD5/SHA-1
vulnerable, use SHA-256+.
3. Chain of custody documents:
A. Suspect name only
✓ B. Who collected, when, where, who possessed, transfers
C. Case number only
D. Not required
Rationale: Chain of Custody: Documents chronological history of evidence handling. Includes: unique
identifier, description, who collected (name, signature, date, time, location), each transfer (from/to, date,
time, purpose), storage location, condition. Gaps break chain, evidence inadmissible. Required for court.
4. Write blocker purpose:
A. Encrypt evidence
✓ B. Prevent writes to source drive during acquisition
C. Speed up imaging
D. Delete data
Rationale: Write Blocker: Hardware or software prevents modification of source evidence during imaging.
Hardware preferred (USB, SATA, IDE). Software write-blockers exist but less reliable. Required for
forensically sound acquisition. Verify with known-good drive. Without it, timestamps/access times change,
evidence tainted.
5. Live acquisition vs dead acquisition:
A. No difference
Certified Cyber Crime Investigator CCCI Exam Page 3
INVESTIGATOR (CCCI)
EXAM
QUESTIONS AND
VERIFIED ANSWERS
WITH RATIONALES
EXAM SPECIFICATIONS
Time Allocation: 3 Hours
Total Questions: 100 Questions
Question Format: Multiple Choice with Detailed Rationales
Minimum Competency: 75% Required to Pass
Core Focus: Digital Forensics, Cyber Law, Evidence, Investigation, Incident Resp
Certified Cyber Crime Investigator CCCI Exam Page 1
, Exam Overview & Content Outline
EXAM PURPOSE
Certified Cyber Crime Investigator (CCCI) Exam validates competency in digital forensics, cybercrime
investigation, evidence handling, cyber law, and incident response per current standards. Required
for professionals investigating computer crimes, data breaches, and digital evidence.
CONTENT DISTRIBUTION
• Digital Forensics Fundamentals (25%) — Forensic process, acquisition, imaging, hashing, chain
of custody
• Cyber Law & Legal Issues (25%) — CFAA, ECPA, 4th Amendment, search warrants, admissibility,
privacy
• Investigation Techniques (30%) — Windows/Unix artifacts, network forensics, mobile forensics,
malware analysis
• Incident Response & Reporting (20%) — IR lifecycle, containment, eradication, recovery, report
writing
QUESTION FORMAT & SCORING
Each item presents four options. Correct answers are highlighted in green with checkmark (✓).
Every question includes detailed rationale with legal and technical standards. Requires 75% to pass.
STUDY STRATEGY
Master forensic acquisition and hashing. Know chain of custody and evidence handling. Understand
4th Amendment and warrant requirements. Study Windows Registry, logs, and artifacts. Review
network forensics and packet analysis. Know IR phases: preparation, detection, containment,
eradication, recovery, lessons learned.
CURRICULUM ALIGNMENT
Questions reflect current standards: NIST SP 800-86, NIST SP 800-61, Federal Rules of Evidence,
Computer Fraud and Abuse Act (CFAA), Electronic Communications Privacy Act (ECPA), and digital
forensics best practices.
Certified Cyber Crime Investigator CCCI Exam Page 2
, SECTION I: Digital Forensics Fundamentals
1. First step in forensic investigation per NIST SP 800-86:
A. Analyze data
✓ B. Collection/Acquisition
C. Report findings
D. Eradicate malware
Rationale: NIST SP 800-86 forensic process: Collection → Examination → Analysis → Reporting.
Collection/Acquisition first: identify sources, acquire data using forensically sound methods. Must maintain
integrity. Order of volatility: memory → network → processes → disk. Never work on original evidence.
2. Hash function used to verify evidence integrity:
A. Encryption
✓ B. MD5 or SHA-256
C. Compression
D. Encoding
Rationale: Hashing: One-way function creates unique fingerprint. MD5 (128-bit, deprecated), SHA-1
(160-bit, deprecated), SHA-256 (256-bit, current). Hash original and image, must match. Any change =
different hash. Chain of custody documents hash values. Collision resistance critical. MD5/SHA-1
vulnerable, use SHA-256+.
3. Chain of custody documents:
A. Suspect name only
✓ B. Who collected, when, where, who possessed, transfers
C. Case number only
D. Not required
Rationale: Chain of Custody: Documents chronological history of evidence handling. Includes: unique
identifier, description, who collected (name, signature, date, time, location), each transfer (from/to, date,
time, purpose), storage location, condition. Gaps break chain, evidence inadmissible. Required for court.
4. Write blocker purpose:
A. Encrypt evidence
✓ B. Prevent writes to source drive during acquisition
C. Speed up imaging
D. Delete data
Rationale: Write Blocker: Hardware or software prevents modification of source evidence during imaging.
Hardware preferred (USB, SATA, IDE). Software write-blockers exist but less reliable. Required for
forensically sound acquisition. Verify with known-good drive. Without it, timestamps/access times change,
evidence tainted.
5. Live acquisition vs dead acquisition:
A. No difference
Certified Cyber Crime Investigator CCCI Exam Page 3