CCII logo
Focused certification exam prep
Start practice

CCII Exam Domains 2026: Complete Guide to All 5 Content Areas

TL;DR
  • The CCII exam is built from five domains, with mobile forensics, social media investigation, and legal fundamentals weighted heaviest across the 26 modules.
  • You need 70% or better on every course section and 70% or better on the final proctored exam to earn board certification.
  • All five domains map to McAfee Institute's self-paced, 24/7/365 online modules - there's no classroom or third-party testing center.
  • Domain 3 (social media) and Domain 4 (mobile/digital forensics) deserve the most study hours based on documented course weighting.

How the CCII Exam Is Actually Structured

The Certified Cyber Intelligence Investigator credential, issued by McAfee Institute, is organized around five content domains that reflect what working cyber intelligence investigators actually do: gather and analyze intelligence, manage investigative cases, track subjects across social platforms, extract evidence from mobile and digital devices, and untangle e-commerce and auction fraud schemes. Unlike exams delivered through Pearson VUE or Prometric, the CCII final exam is a proctored online assessment taken directly through McAfee Institute's own platform, drawn from content across 26 self-study modules available on demand.

Because the exam blueprint is domain-based rather than module-based, candidates often get confused about how the 26 modules translate into five testable areas. Each domain pulls from multiple modules, and some modules feed more than one domain - which is exactly why understanding domain weight matters more than counting modules. If you haven't already reviewed the mechanics of scoring, start with our breakdown of the CCII passing score requirements before diving into domain content, since the 70% threshold applies to every section individually, not just an overall average.

Format Reality Check: There is no domain-by-domain score report published publicly, and McAfee Institute does not release a percentage breakdown of how many questions come from each domain. What we know comes from the depth of module coverage - the areas with the most modules and the most detailed course material are the areas most heavily tested.

Domain 1: Cyber Intelligence and Intelligence Analysis

This domain forms the conceptual backbone of the entire certification. It covers how intelligence is collected, verified, and turned into actionable findings - the analytical mindset that separates a trained investigator from someone simply running searches.

Cyber Intelligence and Intelligence Analysis

Candidates must understand the intelligence cycle, source reliability, and how raw data becomes a defensible investigative conclusion.

  • The intelligence lifecycle: collection, processing, analysis, dissemination
  • Open-source intelligence (OSINT) collection techniques and source vetting
  • Threat actor profiling and pattern-of-life analysis
  • Distinguishing correlation from causation in analytic writing

Questions in this area tend to be scenario-driven: you're given a partial data set and asked what conclusion is analytically supportable versus speculative. This is less about memorizing terminology and more about applying a repeatable analytic process - a skill built through the practice scenarios covered in our CCII study guide.

Domain 2: Cyber Investigations and Case Management

Where Domain 1 is about thinking like an analyst, Domain 2 is about operating like an investigator with a caseload, deadlines, and chain-of-custody obligations. This domain ties directly into legal fundamentals, which McAfee Institute treats as one of the three highest-weighted subject areas in the entire course library.

Cyber Investigations and Case Management

Candidates must be able to structure an investigation from intake to closure without breaking evidentiary integrity.

  • Case initiation, scoping, and documentation standards
  • Chain of custody and evidence handling procedures
  • Legal fundamentals: subpoenas, search authority, jurisdiction, and admissibility
  • Report writing that holds up under legal or regulatory scrutiny

Legal fundamentals questions often trip up candidates coming from a purely technical background, because they test procedural and legal literacy rather than tool proficiency. If you're unsure whether your background experience qualifies you to sit the exam at all, review our CCII requirements guide, since case management competency assumes a baseline familiarity with investigative or legal work environments.

Key Takeaway

Treat Domain 2's legal fundamentals content as core material, not background reading - it's one of the three deepest-covered subject areas across all 26 modules.

Domain 3: Social Media Investigation Methodologies

Social media investigation is one of the signature strengths of the CCII curriculum and one of its three most heavily weighted subject areas. This domain reflects how much modern investigative work - fraud, harassment, threat assessment, corporate due diligence - now runs through public and semi-public social platforms.

Social Media Investigation Methodologies

Candidates need working knowledge of platform-specific investigative techniques and the documentation standards that make social media evidence usable.

  • Platform-specific search and archival techniques across major networks
  • Identifying fake, cloned, and sockpuppet accounts
  • Metadata extraction from social media posts and media files
  • Preserving social media evidence in a legally defensible format
  • Cross-referencing social identities with other digital footprints

Expect this domain to be tested through applied scenarios rather than straight definitions - for example, being asked to identify the correct next investigative step when a subject's account shows signs of impersonation. Because this is one of the exam's deepest domains, it deserves proportionally more study time than a simple "one-fifth of your schedule" approach would suggest.

Domain 4: Mobile and Digital Forensics

Mobile and digital forensics is the second of the three highest-weighted domains, and arguably the most technical section of the CCII exam. This is where candidates without a forensics background tend to spend the most additional study time.

Mobile and Digital Forensics

Candidates must understand forensic soundness principles as they apply specifically to mobile devices and digital media.

  • Mobile device data acquisition methods and their limitations
  • File system artifacts unique to iOS and Android environments
  • Digital evidence preservation, hashing, and documentation standards
  • Recovering deleted or hidden data without compromising admissibility
  • Tool-agnostic forensic principles applicable across platforms

Notice that this domain is tool-agnostic by design - the exam tests forensic reasoning and procedure, not familiarity with any single commercial forensic suite. That distinction matters when you're deciding how to allocate study time, and it's covered in more depth in our guide on how hard the CCII exam actually is.

Domain 5: E-Commerce, Fraud, Hacking, and Auction Fraud

The final domain addresses the financial and transactional side of cyber investigations - the schemes that generate the caseloads many CCII holders manage day to day, from marketplace fraud to account takeover to auction manipulation.

E-Commerce, Fraud, Hacking, and Auction Fraud

Candidates must be able to recognize common fraud typologies and trace the technical mechanics behind them.

  • Auction fraud patterns: shill bidding, non-delivery schemes, counterfeit listings
  • Account takeover and credential-stuffing investigation techniques
  • Payment fraud indicators in e-commerce transaction data
  • Basic hacking methodologies relevant to fraud investigations, including social engineering
  • Following the money: tracing fraudulent transactions across platforms

This domain draws heavily from real-world case patterns, which is consistent with who actually pursues this certification - investigators and analysts working in e-commerce trust and safety, fraud units, financial crimes, and loss prevention roles. For a broader look at who hires CCII holders and what roles they fill, see our overview of CCII jobs.

Which Domains Carry the Most Weight

McAfee Institute doesn't publish an exact percentage split across the five domains, but the course structure itself signals where the emphasis lies. Mobile forensics, social media investigation, and legal fundamentals (embedded in case management) carry the deepest coverage across the 26 modules - meaning Domains 2, 3, and 4 collectively deserve more study time than Domains 1 and 5.

DomainRelative DepthStudy Priority
Domain 1: Cyber Intelligence & AnalysisFoundationalModerate
Domain 2: Investigations & Case ManagementHigh (legal fundamentals)High
Domain 3: Social Media InvestigationHighestHighest
Domain 4: Mobile & Digital ForensicsHighestHighest
Domain 5: E-Commerce & FraudModerateModerate

This weighting isn't guesswork you have to accept blindly - it's reflected directly in module count and depth. Use it to build a study plan that mirrors actual exam risk instead of spreading effort evenly across five domains of unequal size.

Mapping the 26 Modules to a Study Timeline

Since the CCII is entirely self-paced with 24/7/365 module access, there's no fixed cohort schedule to follow - which is both a benefit and a trap. Candidates who treat "self-paced" as "no deadline" often stall out. A domain-weighted timeline solves this by front-loading the heaviest content early, while energy and momentum are highest.

Week 1

Domain 1 Foundations

  • Complete intelligence cycle and OSINT modules
  • Take all embedded quizzes to lock in the 70% section requirement early
Week 2-3

Domain 3: Social Media Investigation

  • Work through platform-specific methodology modules in full
  • Practice metadata extraction and evidence preservation scenarios
Week 4-5

Domain 4: Mobile and Digital Forensics

  • Focus on acquisition methods and file system artifacts
  • Review forensic soundness principles until they're automatic
Week 6

Domain 2: Case Management and Legal Fundamentals

  • Study chain of custody and admissibility rules in depth
  • Draft a sample investigative report using course templates
Week 7

Domain 5: Fraud and E-Commerce

  • Review auction fraud and account takeover case studies
  • Connect fraud typologies back to Domain 1 analytic techniques
Week 8

Full Review and Proctored Exam

  • Run through practice questions across all five domains
  • Schedule and complete the proctored final exam

This is a template, not a mandate - adjust the pacing to your own background. Someone coming from law enforcement may need less time on Domain 2's legal content, while someone from a pure IT background may need to extend Domain 4. For a more detailed week-by-week breakdown with specific resource recommendations, see the full CCII study guide.

Registration, Eligibility, and Scoring Mechanics

Domain content only matters once you're actually eligible to sit the exam, so it's worth reviewing the mechanics before you commit study hours. Eligibility is tiered by education and experience: a bachelor's degree plus one year of relevant experience, an associate's degree plus two years, or a high school diploma plus three years, in fields like e-commerce, fraud, investigations, intelligence, military, cybersecurity, law enforcement, forensics, or law. A felony conviction, a crime of moral turpitude, or a misdemeanor involving honesty, theft, embezzlement, or fraud disqualifies a candidate outright.

If you don't yet meet the eligibility bar, you're not locked out of studying. You can complete the training and earn a "Qualified" credential now, then purchase the standalone Certified Exam License later to convert to full "Certified" status once your experience catches up. Full pricing mechanics for both paths are covered in our CCII certification cost breakdown.

To actually earn the credential, you must submit every course quiz, score 70% or better on all course sections, score 70% or better on the final proctored exam, submit proof of eligibility with your application, and pay all fees in full. Once certified, the credential is valid for two years and requires 20 CPE credits per cycle, with at least 2 of those hours in ethics. There's a 30-day grace period after expiration - miss that window and the credential is permanently revoked, requiring a new exam license purchase to start over.

Registration Note: The CCII exam is proctored entirely through McAfee Institute's own platform - not Pearson VUE or Prometric - so there are no regional testing centers to book. Scheduling flexibility is a real advantage, but it also means you're responsible for managing your own exam window; see our CCII exam dates guide for scheduling logistics.

Beyond the certification mechanics themselves, it's worth understanding how the credential is positioned in the broader workforce landscape. The CCII is listed in the CISA NICCS Education & Training Catalog, mapped to the NIST NICE Workforce Framework, approved for Missouri POST CLEE credit, and eligible for military Credentialing Assistance and COOL funding across the Navy, Army, Air Force, Coast Guard, and DoD generally. That government-adjacent recognition is part of what separates the CCII from many vendor certifications, and it connects directly to the domain content above - the government frameworks it maps to prioritize exactly the intelligence, investigation, and forensics skill areas the exam tests. For a broader look at whether the investment pays off given your career goals, read our CCII ROI analysis, and if you want the numbers behind typical outcomes, check the CCII salary guide.

Once you have a handle on the domains, the best next step is testing your recall against realistic scenario questions rather than just re-reading module text. You can start running practice questions modeled on the five domains at the CCII practice test platform, and cross-check tricky terminology against our CCII cheat sheet before exam day. If you're still deciding whether the credential fits your path, our plain-language explainer on what CCII certification actually is is a good starting point, and returning to the main practice test site periodically as you move through each domain will help you spot weak areas before the proctored exam does.

Frequently Asked Questions

How many domains are on the CCII exam?

Five: Cyber Intelligence and Intelligence Analysis, Cyber Investigations and Case Management, Social Media Investigation Methodologies, Mobile and Digital Forensics, and E-Commerce, Fraud, Hacking, and Auction Fraud.

Which CCII domain is the hardest?

Mobile and Digital Forensics is generally the most technically demanding domain, especially for candidates without a forensics background, since it requires understanding acquisition methods and file system artifacts in detail.

Are all five domains weighted equally on the exam?

McAfee Institute does not publish exact domain percentages, but mobile forensics, social media investigation, and legal fundamentals carry the deepest coverage across the 26 modules, suggesting heavier emphasis in those areas.

Do I need to pass each domain separately?

Certification requires scoring 70% or better on all sections of the course plus 70% or better on the final proctored exam, so strong performance across every domain matters, not just an overall average.

Can I study the domains before I'm eligible to sit the exam?

Yes. You can complete the 26-module training and earn a "Qualified" credential first, then purchase a Certified Exam License later once you meet the education and experience requirements.

Ready to pass your CCII exam?

Put this into practice with free CCII questions across every exam domain.