CCIP logo
Focused certification exam prep
Start practice

CCIP Exam Domains 2026: Complete Guide to All 13 Content Areas

TL;DR
  • CCIP here means McAfee Institute's Certified Cyber Intelligence Professional; its thirteen domains are editorial preparation categories, not an official...
  • The exam is online proctored, runs three hours, and requires at least 70% on the final examination.
  • Standalone exam-only access costs $450 and includes one attempt plus a one-year exam license.
  • Question count, scored/unscored split, and domain weights are unverified, so study every domain rather than gambling on a "heavy" one.

What "13 Domains" Actually Means for the CCIP

Most certification guides hand you a tidy table of domains with percentage weights. The Certified Cyber Intelligence Professional (CCIP) from McAfee Institute doesn't work that way, and any guide pretending otherwise is guessing. The issuer describes its curriculum in narrative prose and advertises a 25-module course, but it does not publish numbered exam domains, official domain names, or weights.

The thirteen areas in this guide come from the subjects the publisher names in that narrative: cyber-intelligence foundations, OSINT, privacy, secure research environments, social-media investigations, auction fraud, deep-web research, advanced searching, deception analysis, digital evidence, documentation, law-enforcement partnerships, and program development. We've separated them into thirteen preparation categories so you can organize your study. They are not the advertised 25 module titles, and they are not a confirmed map of what appears on exam day.

Read this before you plan your study time: Because no official blueprint is public, nobody can honestly tell you which CCIP domain is "largest" or which to skip. The 15 legal and 35 technical training hours that appear in the course metadata are course-delivery figures, not exam percentages. Treat all thirteen areas as fair game and weight your time by your own weak spots, not by a rumored distribution.

If you're still orienting yourself to the credential itself, start with what CCIP certification is and the broader CCIP certification overview, then come back here for the content breakdown.

Verified Exam Facts Before You Study

Knowing the container helps you prepare for the content. Here is what the issuer's public pages support, along with what remains unconfirmed.

ItemWhat is verifiedWhat is not verified
DeliveryOnline proctored; proctor license includedName of the external proctoring provider
Time limitThree hoursWhether breaks are permitted
Passing criterionAt least 70% on the final examinationActual pass rate (not publicly disclosed)
Exam-only price$450 for one attempt and a one-year licenseDetailed retake rules
Training bundle$1,797; 50 hours, 40 CPE, lifetime course accessIndividual titles of the 25 modules
Question countNone confirmedTotal items, scored/unscored split, item formats, adaptive status
Domain weightsNone publishedAny official domain list or percentages

The exam-only product text excludes the manual, quizzes, and training, so if you buy the $450 option you are sourcing your own preparation. Compare the options in our CCIP certification cost breakdown, and read the CCIP passing score guide for how the 70% threshold works in practice. For eligibility alternatives (a bachelor's degree plus three relevant years, an associate's plus four, or high school plus five), see CCIP requirements.

Foundations: Cyber-Intelligence Basics, OSINT, Privacy, and Secure Environments

The first four categories establish how a cyber intelligence practitioner thinks, collects, and protects themselves while doing it. Candidates from an investigative background often breeze through the mindset material but underestimate the operational-security content.

Domain 1: Cyber-Intelligence Foundations

This is the conceptual base: what cyber intelligence is, how collection feeds analysis, and how analytical integration turns raw data into something a decision-maker can use.

  • Cyber-intelligence collection versus analysis, and how they connect
  • Investigative frameworks and methodologies (the first stated performance objective asks you to explain them)
  • Legal considerations that shape what you may collect and how
  • Where strategic and operational intelligence needs differ

Domain 2: OSINT

Open-source intelligence is the backbone of the program. Expect to reason about sources, not just name tools.

  • Identifying and categorizing publicly available sources
  • Judging source reliability before relying on a finding
  • Combining multiple open sources to build a picture no single source provides
  • Recognizing the limits and gaps of what open sources can tell you

Domain 3: Privacy

Privacy appears twice over: protecting your own identity as an investigator and respecting the legal boundaries around other people's information.

  • Limiting your own digital footprint during research
  • Understanding privacy-related legal constraints on collection
  • Handling personal information responsibly in case files and reports

Domain 4: Secure Research Environments

Where and how you research matters as much as what you find. This category covers building a setup that protects both you and the integrity of your work.

  • Separating investigative activity from personal and organizational identities
  • Reducing the chance that a subject can detect or trace your research
  • Maintaining a controlled environment so evidence stays clean

These topics overlap heavily with the evidence-handling material later on. A weak research environment can contaminate a case, which is why scenario questions can blend these areas. For a quick-reference version of the essentials, keep the CCIP cheat sheet handy.

Collection Skills: Social Media, Auction Fraud, Deep Web, and Advanced Searching

The middle of the curriculum is the most hands-on. These four categories correspond closely to the learning outcomes about social media investigation and deep-web exploration, and they are where "applied knowledge" is most visible.

Domain 5: Social-Media Investigations

Social platforms are rich and messy sources. The program explicitly lists practicing social media investigation skills as a learning outcome.

  • Extracting investigative value from profiles, connections, and activity patterns
  • Evaluating whether an account or claim is authentic
  • Preserving what you find in a way that supports later reporting
  • Staying within legal and ethical limits while collecting

Domain 6: Auction Fraud

This is a distinctive inclusion that many cyber-intelligence credentials skip. It applies investigative method to online marketplace deception.

  • Recognizing patterns of fraudulent listings and seller behavior
  • Tracing relationships between accounts, listings, and transactions
  • Documenting fraud indicators so a case can be referred or prosecuted

Domain 7: Deep-Web Research

The curriculum covers content that standard search engines do not surface. Focus on method and risk, not just definitions.

  • Distinguishing the surface web from content that is not indexed
  • Approaching restricted or hidden sources safely and legally
  • Assessing the reliability of material found in less-visible spaces

Domain 8: Advanced Searching

Searching well is a skill, and the program treats it as one. Think structured query construction and systematic coverage.

  • Building precise queries to narrow noisy results
  • Using multiple engines and sources to avoid single-source blind spots
  • Iterating searches as new identifiers and leads emerge
Why this cluster matters for scoring: Questions in these areas tend to reward judgment about what to do next in an investigation, not recall of a definition. Practice reading a short scenario and deciding which source to check, how to preserve what you find, and what the finding does and does not prove. You can drill that style with the CCIP practice tests.

Analysis and Evidence: Deception Analysis, Digital Evidence, and Documentation

This cluster is where collection becomes a defensible product. It maps to the learning outcomes on analyzing digital evidence and documenting findings for intelligence reporting.

Domain 9: Deception Analysis

Adversaries and subjects mislead. This category is about detecting and accounting for that.

  • Spotting fabricated personas, manipulated content, and misleading narratives
  • Handling conflicting information without forcing a premature conclusion
  • Stating uncertainty and assumptions openly when deception is possible

Domain 10: Digital Evidence

Evidence is only useful if it is collected and kept properly. Expect emphasis on integrity and traceability.

  • Identifying and preserving digital artifacts in a defensible manner
  • Maintaining a clear record of how evidence was obtained and handled
  • Corroborating digital findings against independent sources

Domain 11: Documentation

This is the output side of the whole program: professional intelligence reporting and case management.

  • Writing assessments a decision-maker can act on
  • Separating facts, assumptions, information gaps, and supported judgments
  • Managing a case file so another investigator could follow your work

Documentation is easy to dismiss as paperwork, but the third performance objective asks you to deliver assessments suitable for strategic or operational decision-making. That is a reporting skill, and it shows up as a distinct learning outcome. If you want a sense of how tough this material is for newcomers, see how hard the CCIP exam is.

Partnerships and Program Development

Domain 12: Law-Enforcement Partnerships

Cyber intelligence rarely ends with the analyst. This category covers working with agencies and handing off findings.

  • Packaging findings so law enforcement can use them
  • Understanding what partners need for referral, follow-up, or prosecution
  • Respecting legal limits on information sharing

Domain 13: Program Development

The final category looks upward: building and managing a cyber intelligence capability rather than just performing individual investigations.

  • Structuring a repeatable intelligence process within an organization
  • Aligning collection and analysis with decision-maker needs
  • Managing cases and resources at the program level

These last two categories point to the audience: investigators, analysts, corporate security staff, and supervisors who need to run or support intelligence work. If you're weighing where the credential leads, review CCIP jobs and the CCIP ROI analysis for a balanced view.

Cross-Cutting Analytic Skills the Course Emphasizes

Beyond the thirteen subject areas, the published preparation context highlights a set of analytic habits that cut across every domain. Candidates who treat the program as a terminology exercise miss these, and they are likely to surface in scenario-style questions.

  • Source reliability: Rate where information came from before you build on it.
  • Corroboration: Seek independent confirmation rather than repeating a single source.
  • Uncertainty: Say how confident you are and why.
  • Assumptions: Name what you are taking for granted so a reader can challenge it.
  • Information gaps: Flag what you do not know and what would close the gap.
  • Conflicting information: Present competing evidence honestly instead of cherry-picking.
  • Supported judgments: Tie every conclusion to evidence a reader can trace.

Key Takeaway

When a scenario question offers several plausible answers, favor the one that corroborates, states its uncertainty, and ties the judgment to evidence. That pattern matches how the program frames good intelligence work.

Learning Outcomes and Performance Objectives

The issuer publishes six learning outcomes and three performance objectives. These describe what the program wants you to be able to do; they are not weighted exam domains, and the foundation/applied/exit labels describe learning progression rather than score weights.

Published learning outcomeMost related study categories
Develop comprehensive cyber intelligence techniquesFoundations, OSINT, Advanced searching
Practice social media investigation skillsSocial-media investigations, Privacy
Explore the deep web and advanced search techniquesDeep-web research, Advanced searching
Manage cyber investigations and case managementDocumentation, Program development, Partnerships
Analyze digital evidence effectivelyDigital evidence, Deception analysis
Document findings for intelligence reportingDocumentation, Law-enforcement partnerships

The three performance objectives set the bar for depth:

  1. Explain advanced cyber intelligence methodologies and investigative frameworks.
  2. Perform complex cyber intelligence analysis integrating multiple data sources.
  3. Deliver advanced cyber intelligence assessments suitable for strategic or operational decision-making.

Notice the verbs: explain, perform, deliver. That progression signals that rote memorization will not carry you; you need to apply methods to integrated, multi-source problems. The CCIP study guide walks through how to build that applied skill.

Sequencing the Domains Over Your Prep

Since no official weights exist, sequence by dependency rather than by rumor. Foundations and tradecraft first, then collection, then analysis and reporting, then the organizational layer. Adjust the pacing to your background, but keep the order, because later topics assume earlier ones.

Week 1

Foundations and protection

  • Cyber-intelligence foundations and legal considerations
  • OSINT source types and reliability
  • Privacy and secure research environments, since they shape everything after
Week 2

Collection domains

  • Social-media investigations and auction fraud
  • Deep-web research and advanced searching
  • Practice turning a lead into a documented search plan
Week 3

Analysis and evidence

  • Deception analysis and conflicting information
  • Digital evidence handling and corroboration
  • Documentation, case management, and supported judgments
Week 4

Partnerships, programs, and timed practice

  • Law-enforcement partnerships and program development
  • Full-length timed sessions against the three-hour limit
  • Targeted review of whichever domain you scored lowest on

Book your attempt only after your practice results are consistently above the 70% threshold; the CCIP exam dates and scheduling guide covers the logistics, and the CCIP pass rate discussion explains why no pass-rate figure should be assumed. For questions in the style you are likely to face, work through the CCIP exam prep platform.

Frequently Asked Questions

Are the 13 domains an official CCIP exam blueprint?

No. They are thirteen preparation categories drawn from the subjects McAfee Institute names in its public curriculum narrative. The issuer has not published numbered exam domains or official weights, so use them as a study framework rather than a confirmed exam map.

Which CCIP domain carries the most weight?

That cannot be stated, because official weights are not published. The 15 legal and 35 technical training hours in the course metadata are delivery figures, not exam percentages, so distribute your preparation across all thirteen areas.

How long is the exam and what score do I need?

The exam is online proctored with a three-hour time limit, and the published passing criterion is at least 70% on the final examination. The number of questions and the item formats are not verified in public sources.

How much does the CCIP exam cost?

The exam-only option is $450 and includes one attempt and a one-year exam license. A training bundle is listed at $1,797 and adds the 50-hour course, 40 CPE credits, and lifetime course access. The exam-only product excludes the manual, quizzes, and training.

Do the 25 course modules equal 25 exam domains?

No. The program advertises 25 course modules, but their individual titles are not publicly supplied, and they are not treated as exam domains. The thirteen categories in this guide are a separate editorial grouping of the published curriculum subjects.

Ready to pass your CCIP exam?

Put this into practice with free CCIP questions across every exam domain.