- What "13 Domains" Actually Means for the CCIP
- Verified Exam Facts Before You Study
- Foundations: Cyber-Intelligence Basics, OSINT, Privacy, Secure Environments
- Collection Skills: Social Media, Auction Fraud, Deep Web, Advanced Searching
- Analysis and Evidence: Deception, Digital Evidence, Documentation
- Partnerships and Program Development
- Cross-Cutting Analytic Skills the Course Emphasizes
- Learning Outcomes and Performance Objectives
- Sequencing the Domains Over Your Prep
- Frequently Asked Questions
- CCIP here means McAfee Institute's Certified Cyber Intelligence Professional; its thirteen domains are editorial preparation categories, not an official...
- The exam is online proctored, runs three hours, and requires at least 70% on the final examination.
- Standalone exam-only access costs $450 and includes one attempt plus a one-year exam license.
- Question count, scored/unscored split, and domain weights are unverified, so study every domain rather than gambling on a "heavy" one.
What "13 Domains" Actually Means for the CCIP
Most certification guides hand you a tidy table of domains with percentage weights. The Certified Cyber Intelligence Professional (CCIP) from McAfee Institute doesn't work that way, and any guide pretending otherwise is guessing. The issuer describes its curriculum in narrative prose and advertises a 25-module course, but it does not publish numbered exam domains, official domain names, or weights.
The thirteen areas in this guide come from the subjects the publisher names in that narrative: cyber-intelligence foundations, OSINT, privacy, secure research environments, social-media investigations, auction fraud, deep-web research, advanced searching, deception analysis, digital evidence, documentation, law-enforcement partnerships, and program development. We've separated them into thirteen preparation categories so you can organize your study. They are not the advertised 25 module titles, and they are not a confirmed map of what appears on exam day.
If you're still orienting yourself to the credential itself, start with what CCIP certification is and the broader CCIP certification overview, then come back here for the content breakdown.
Verified Exam Facts Before You Study
Knowing the container helps you prepare for the content. Here is what the issuer's public pages support, along with what remains unconfirmed.
| Item | What is verified | What is not verified |
|---|---|---|
| Delivery | Online proctored; proctor license included | Name of the external proctoring provider |
| Time limit | Three hours | Whether breaks are permitted |
| Passing criterion | At least 70% on the final examination | Actual pass rate (not publicly disclosed) |
| Exam-only price | $450 for one attempt and a one-year license | Detailed retake rules |
| Training bundle | $1,797; 50 hours, 40 CPE, lifetime course access | Individual titles of the 25 modules |
| Question count | None confirmed | Total items, scored/unscored split, item formats, adaptive status |
| Domain weights | None published | Any official domain list or percentages |
The exam-only product text excludes the manual, quizzes, and training, so if you buy the $450 option you are sourcing your own preparation. Compare the options in our CCIP certification cost breakdown, and read the CCIP passing score guide for how the 70% threshold works in practice. For eligibility alternatives (a bachelor's degree plus three relevant years, an associate's plus four, or high school plus five), see CCIP requirements.
Foundations: Cyber-Intelligence Basics, OSINT, Privacy, and Secure Environments
The first four categories establish how a cyber intelligence practitioner thinks, collects, and protects themselves while doing it. Candidates from an investigative background often breeze through the mindset material but underestimate the operational-security content.
Domain 1: Cyber-Intelligence Foundations
This is the conceptual base: what cyber intelligence is, how collection feeds analysis, and how analytical integration turns raw data into something a decision-maker can use.
- Cyber-intelligence collection versus analysis, and how they connect
- Investigative frameworks and methodologies (the first stated performance objective asks you to explain them)
- Legal considerations that shape what you may collect and how
- Where strategic and operational intelligence needs differ
Domain 2: OSINT
Open-source intelligence is the backbone of the program. Expect to reason about sources, not just name tools.
- Identifying and categorizing publicly available sources
- Judging source reliability before relying on a finding
- Combining multiple open sources to build a picture no single source provides
- Recognizing the limits and gaps of what open sources can tell you
Domain 3: Privacy
Privacy appears twice over: protecting your own identity as an investigator and respecting the legal boundaries around other people's information.
- Limiting your own digital footprint during research
- Understanding privacy-related legal constraints on collection
- Handling personal information responsibly in case files and reports
Domain 4: Secure Research Environments
Where and how you research matters as much as what you find. This category covers building a setup that protects both you and the integrity of your work.
- Separating investigative activity from personal and organizational identities
- Reducing the chance that a subject can detect or trace your research
- Maintaining a controlled environment so evidence stays clean
These topics overlap heavily with the evidence-handling material later on. A weak research environment can contaminate a case, which is why scenario questions can blend these areas. For a quick-reference version of the essentials, keep the CCIP cheat sheet handy.
Collection Skills: Social Media, Auction Fraud, Deep Web, and Advanced Searching
The middle of the curriculum is the most hands-on. These four categories correspond closely to the learning outcomes about social media investigation and deep-web exploration, and they are where "applied knowledge" is most visible.
Domain 5: Social-Media Investigations
Social platforms are rich and messy sources. The program explicitly lists practicing social media investigation skills as a learning outcome.
- Extracting investigative value from profiles, connections, and activity patterns
- Evaluating whether an account or claim is authentic
- Preserving what you find in a way that supports later reporting
- Staying within legal and ethical limits while collecting
Domain 6: Auction Fraud
This is a distinctive inclusion that many cyber-intelligence credentials skip. It applies investigative method to online marketplace deception.
- Recognizing patterns of fraudulent listings and seller behavior
- Tracing relationships between accounts, listings, and transactions
- Documenting fraud indicators so a case can be referred or prosecuted
Domain 7: Deep-Web Research
The curriculum covers content that standard search engines do not surface. Focus on method and risk, not just definitions.
- Distinguishing the surface web from content that is not indexed
- Approaching restricted or hidden sources safely and legally
- Assessing the reliability of material found in less-visible spaces
Domain 8: Advanced Searching
Searching well is a skill, and the program treats it as one. Think structured query construction and systematic coverage.
- Building precise queries to narrow noisy results
- Using multiple engines and sources to avoid single-source blind spots
- Iterating searches as new identifiers and leads emerge
Analysis and Evidence: Deception Analysis, Digital Evidence, and Documentation
This cluster is where collection becomes a defensible product. It maps to the learning outcomes on analyzing digital evidence and documenting findings for intelligence reporting.
Domain 9: Deception Analysis
Adversaries and subjects mislead. This category is about detecting and accounting for that.
- Spotting fabricated personas, manipulated content, and misleading narratives
- Handling conflicting information without forcing a premature conclusion
- Stating uncertainty and assumptions openly when deception is possible
Domain 10: Digital Evidence
Evidence is only useful if it is collected and kept properly. Expect emphasis on integrity and traceability.
- Identifying and preserving digital artifacts in a defensible manner
- Maintaining a clear record of how evidence was obtained and handled
- Corroborating digital findings against independent sources
Domain 11: Documentation
This is the output side of the whole program: professional intelligence reporting and case management.
- Writing assessments a decision-maker can act on
- Separating facts, assumptions, information gaps, and supported judgments
- Managing a case file so another investigator could follow your work
Documentation is easy to dismiss as paperwork, but the third performance objective asks you to deliver assessments suitable for strategic or operational decision-making. That is a reporting skill, and it shows up as a distinct learning outcome. If you want a sense of how tough this material is for newcomers, see how hard the CCIP exam is.
Partnerships and Program Development
Domain 12: Law-Enforcement Partnerships
Cyber intelligence rarely ends with the analyst. This category covers working with agencies and handing off findings.
- Packaging findings so law enforcement can use them
- Understanding what partners need for referral, follow-up, or prosecution
- Respecting legal limits on information sharing
Domain 13: Program Development
The final category looks upward: building and managing a cyber intelligence capability rather than just performing individual investigations.
- Structuring a repeatable intelligence process within an organization
- Aligning collection and analysis with decision-maker needs
- Managing cases and resources at the program level
These last two categories point to the audience: investigators, analysts, corporate security staff, and supervisors who need to run or support intelligence work. If you're weighing where the credential leads, review CCIP jobs and the CCIP ROI analysis for a balanced view.
Cross-Cutting Analytic Skills the Course Emphasizes
Beyond the thirteen subject areas, the published preparation context highlights a set of analytic habits that cut across every domain. Candidates who treat the program as a terminology exercise miss these, and they are likely to surface in scenario-style questions.
- Source reliability: Rate where information came from before you build on it.
- Corroboration: Seek independent confirmation rather than repeating a single source.
- Uncertainty: Say how confident you are and why.
- Assumptions: Name what you are taking for granted so a reader can challenge it.
- Information gaps: Flag what you do not know and what would close the gap.
- Conflicting information: Present competing evidence honestly instead of cherry-picking.
- Supported judgments: Tie every conclusion to evidence a reader can trace.
Key Takeaway
When a scenario question offers several plausible answers, favor the one that corroborates, states its uncertainty, and ties the judgment to evidence. That pattern matches how the program frames good intelligence work.
Learning Outcomes and Performance Objectives
The issuer publishes six learning outcomes and three performance objectives. These describe what the program wants you to be able to do; they are not weighted exam domains, and the foundation/applied/exit labels describe learning progression rather than score weights.
| Published learning outcome | Most related study categories |
|---|---|
| Develop comprehensive cyber intelligence techniques | Foundations, OSINT, Advanced searching |
| Practice social media investigation skills | Social-media investigations, Privacy |
| Explore the deep web and advanced search techniques | Deep-web research, Advanced searching |
| Manage cyber investigations and case management | Documentation, Program development, Partnerships |
| Analyze digital evidence effectively | Digital evidence, Deception analysis |
| Document findings for intelligence reporting | Documentation, Law-enforcement partnerships |
The three performance objectives set the bar for depth:
- Explain advanced cyber intelligence methodologies and investigative frameworks.
- Perform complex cyber intelligence analysis integrating multiple data sources.
- Deliver advanced cyber intelligence assessments suitable for strategic or operational decision-making.
Notice the verbs: explain, perform, deliver. That progression signals that rote memorization will not carry you; you need to apply methods to integrated, multi-source problems. The CCIP study guide walks through how to build that applied skill.
Sequencing the Domains Over Your Prep
Since no official weights exist, sequence by dependency rather than by rumor. Foundations and tradecraft first, then collection, then analysis and reporting, then the organizational layer. Adjust the pacing to your background, but keep the order, because later topics assume earlier ones.
Foundations and protection
- Cyber-intelligence foundations and legal considerations
- OSINT source types and reliability
- Privacy and secure research environments, since they shape everything after
Collection domains
- Social-media investigations and auction fraud
- Deep-web research and advanced searching
- Practice turning a lead into a documented search plan
Analysis and evidence
- Deception analysis and conflicting information
- Digital evidence handling and corroboration
- Documentation, case management, and supported judgments
Partnerships, programs, and timed practice
- Law-enforcement partnerships and program development
- Full-length timed sessions against the three-hour limit
- Targeted review of whichever domain you scored lowest on
Book your attempt only after your practice results are consistently above the 70% threshold; the CCIP exam dates and scheduling guide covers the logistics, and the CCIP pass rate discussion explains why no pass-rate figure should be assumed. For questions in the style you are likely to face, work through the CCIP exam prep platform.
Frequently Asked Questions
No. They are thirteen preparation categories drawn from the subjects McAfee Institute names in its public curriculum narrative. The issuer has not published numbered exam domains or official weights, so use them as a study framework rather than a confirmed exam map.
That cannot be stated, because official weights are not published. The 15 legal and 35 technical training hours in the course metadata are delivery figures, not exam percentages, so distribute your preparation across all thirteen areas.
The exam is online proctored with a three-hour time limit, and the published passing criterion is at least 70% on the final examination. The number of questions and the item formats are not verified in public sources.
The exam-only option is $450 and includes one attempt and a one-year exam license. A training bundle is listed at $1,797 and adds the 50-hour course, 40 CPE credits, and lifetime course access. The exam-only product excludes the manual, quizzes, and training.
No. The program advertises 25 course modules, but their individual titles are not publicly supplied, and they are not treated as exam domains. The thirteen categories in this guide are a separate editorial grouping of the published curriculum subjects.