Skip to content
Cyber5W Certified Evidence Handler (CCEH)

So I tried Cyber5W — Certified Evidence Handler (CCEH) exam, How was it?

May 2025Cyber5WPassed
Certification
CCEH
Provider
Cyber5W
Difficulty
Beginner
Rating
★★★★½4.5/5.0
Introduction

Cyber5W is a training and certification provider for blue teamers, co-founded by Ali Hadi, well known in the Digital Forensics community and the author of the popular eCDFP certification and course from INE. My experience with eCDFP was not the most satisfying; it could have been more challenging and engaging, and the hands-on portion felt underwhelming. So I've always been on the lookout for a Digital Forensics certification that is actually fun and relevant to real forensics work.

Cyber5W Certified Evidence Handler exam page
Figure 1

When I heard about the Certified Evidence Handler (CCEH) exam (which features both theory and hands-on parts, just like eCDFP), I wanted to take it and compare the two, expecting at least a step up in quality given that CCEH was released much later.

CCEH certification overview
Figure 2

There was one more reason I decided to purchase this cert: the name. I joked with a friend, "If I pass this exam, I'll have (C)CEH 🤣", and with all of that combined, here we are.

Exam Preparation
CCEH required skills listed on the certification page
Figure 3

As the name implies, this certification tests your knowledge as a Digital Forensics Evidence Handler. All the required skills are listed on the certification page. If you don't yet have those skills but still want to take the exam, here are the Cyber5W courses that will help you prepare.

C5W-100 Introduction to Digital Forensics course bundle
Figure 4

First, the C5W-100: Introduction to Digital Forensics bundle combines 10 courses (both paid and free) and is offered at no cost to anyone interested in the field. It's a solid resource, though not everything in the bundle is exam-relevant. The five courses most applicable to CCEH are:

  • Digital Forensics Concepts
  • Working with Virtual Hard Disk
  • Evidence Acquisition under Windows
  • Working with FTK Imager
  • Writing Forensic Reports

There is also one additional course outside the bundle worth looking at: Introduction to Evidence Acquisition.

Exam structure: 24-hour window, theory and hands-on parts, VM provided
Figure 5

A few key things to know about the exam format:

  • You have 24 hours to complete the exam.
  • It is split into two parts: theory-based questions and hands-on questions.
  • A virtual machine is provided for the hands-on lab.

What they don't mention up front: the hands-on portion also includes an Incident Response component, so you'll need to know how to conduct basic dynamic malware analysis as well. All questions throughout (including the hands-on section) are multiple choice.

The exam costs $50 per attempt. If you fail, you'll need to purchase another attempt separately.

Exam Experience
Exam purchased on Friday 2nd May 2025
Figure 6

I purchased the exam on Friday, 2nd May 2025, during the workday (with my own money, of course) without any prior preparation, and planned to take it on Saturday. But after nearly a month of grinding nonstop for OSCP, I was burned out and wanted something to re-ignite my motivation. So after finishing work and getting back to my apartment, I started the exam right away at 6:26:57 PM.

Exam started — theory questions first, hands-on second
Figure 7

After starting, I was presented with theory-based questions first, followed by hands-on questions. There were two distinct hands-on labs. I couldn't get an exact question count, but compared to eCDFP (which has 15 theory + 15 hands-on), CCEH has more than 40 questions across both parts combined.

The theory questions are roughly 80% technical and 20% conceptual: if you're comfortable with evidence acquisition tools and processes, they should be straightforward.

For the hands-on section, you're given a machine provisioned via Apache Guacamole, accessible entirely through a browser, so only an internet connection is required. You also have the option to download the artifacts locally, though the provided VM is more than sufficient.

Hands-on lab environment via Guacamole
Figure 8
Second hands-on lab — artifact download option available
Figure 9

I finished the entire exam in about an hour and a half. I spent most of that time on the theory section and the first hands-on lab; the second lab was much quicker. Overall it was a genuinely fun and challenging exam.

Exam completion page
Figure 10

After finishing and landing on the completion page, I noticed there was no certificate in sight and wondered where it was. I emailed Cyber5W support, and they replied within an hour with the certificate attached as a PDF, and that wrapped up my journey with this exam (if you can really call it a journey 😄).

Certificate received via email as a PDF attachment
Figure 11
Exam Tips & Key Takeaways
  • Have a stable internet connection.
  • Perform the hands-on lab on the provided virtual machine.
  • Understand each disk image format: E01, dd (raw), AFF.
  • Learn how to use FTK Imager to acquire different disk image formats.
  • Learn how to conduct basic dynamic malware analysis.
  • The exam window is 24 hours: rest when you need to.

So who is this certification for? It targets first responders who need to acquire digital evidence and maintain its integrity throughout the chain of custody.

Overall, the exam was fun and challenging. That said, if you're looking for something to boost your resume, this probably isn't the right pick: even eCDFP doesn't move the needle much with HR. There isn't really a widely recognized Digital Forensics certification at the entry level yet. But if you want to take it for the fun of it, like I did, $50 is a fair price and well worth it.

Peace out~ ✌