- How the CCII Exam Is Actually Structured
- Domain 1: Cyber Intelligence and Intelligence Analysis
- Domain 2: Cyber Investigations and Case Management
- Domain 3: Social Media Investigation Methodologies
- Domain 4: Mobile and Digital Forensics
- Domain 5: E-Commerce, Fraud, Hacking, and Auction Fraud
- Which Domains Carry the Most Weight
- Mapping the 26 Modules to a Study Timeline
- Registration, Eligibility, and Scoring Mechanics
- Frequently Asked Questions
- The CCII exam is built from five domains, with mobile forensics, social media investigation, and legal fundamentals weighted heaviest across the 26 modules.
- You need 70% or better on every course section and 70% or better on the final proctored exam to earn board certification.
- All five domains map to McAfee Institute's self-paced, 24/7/365 online modules - there's no classroom or third-party testing center.
- Domain 3 (social media) and Domain 4 (mobile/digital forensics) deserve the most study hours based on documented course weighting.
How the CCII Exam Is Actually Structured
The Certified Cyber Intelligence Investigator credential, issued by McAfee Institute, is organized around five content domains that reflect what working cyber intelligence investigators actually do: gather and analyze intelligence, manage investigative cases, track subjects across social platforms, extract evidence from mobile and digital devices, and untangle e-commerce and auction fraud schemes. Unlike exams delivered through Pearson VUE or Prometric, the CCII final exam is a proctored online assessment taken directly through McAfee Institute's own platform, drawn from content across 26 self-study modules available on demand.
Because the exam blueprint is domain-based rather than module-based, candidates often get confused about how the 26 modules translate into five testable areas. Each domain pulls from multiple modules, and some modules feed more than one domain - which is exactly why understanding domain weight matters more than counting modules. If you haven't already reviewed the mechanics of scoring, start with our breakdown of the CCII passing score requirements before diving into domain content, since the 70% threshold applies to every section individually, not just an overall average.
Domain 1: Cyber Intelligence and Intelligence Analysis
This domain forms the conceptual backbone of the entire certification. It covers how intelligence is collected, verified, and turned into actionable findings - the analytical mindset that separates a trained investigator from someone simply running searches.
Cyber Intelligence and Intelligence Analysis
Candidates must understand the intelligence cycle, source reliability, and how raw data becomes a defensible investigative conclusion.
- The intelligence lifecycle: collection, processing, analysis, dissemination
- Open-source intelligence (OSINT) collection techniques and source vetting
- Threat actor profiling and pattern-of-life analysis
- Distinguishing correlation from causation in analytic writing
Questions in this area tend to be scenario-driven: you're given a partial data set and asked what conclusion is analytically supportable versus speculative. This is less about memorizing terminology and more about applying a repeatable analytic process - a skill built through the practice scenarios covered in our CCII study guide.
Domain 2: Cyber Investigations and Case Management
Where Domain 1 is about thinking like an analyst, Domain 2 is about operating like an investigator with a caseload, deadlines, and chain-of-custody obligations. This domain ties directly into legal fundamentals, which McAfee Institute treats as one of the three highest-weighted subject areas in the entire course library.
Cyber Investigations and Case Management
Candidates must be able to structure an investigation from intake to closure without breaking evidentiary integrity.
- Case initiation, scoping, and documentation standards
- Chain of custody and evidence handling procedures
- Legal fundamentals: subpoenas, search authority, jurisdiction, and admissibility
- Report writing that holds up under legal or regulatory scrutiny
Legal fundamentals questions often trip up candidates coming from a purely technical background, because they test procedural and legal literacy rather than tool proficiency. If you're unsure whether your background experience qualifies you to sit the exam at all, review our CCII requirements guide, since case management competency assumes a baseline familiarity with investigative or legal work environments.
Key Takeaway
Treat Domain 2's legal fundamentals content as core material, not background reading - it's one of the three deepest-covered subject areas across all 26 modules.
Domain 3: Social Media Investigation Methodologies
Social media investigation is one of the signature strengths of the CCII curriculum and one of its three most heavily weighted subject areas. This domain reflects how much modern investigative work - fraud, harassment, threat assessment, corporate due diligence - now runs through public and semi-public social platforms.
Social Media Investigation Methodologies
Candidates need working knowledge of platform-specific investigative techniques and the documentation standards that make social media evidence usable.
- Platform-specific search and archival techniques across major networks
- Identifying fake, cloned, and sockpuppet accounts
- Metadata extraction from social media posts and media files
- Preserving social media evidence in a legally defensible format
- Cross-referencing social identities with other digital footprints
Expect this domain to be tested through applied scenarios rather than straight definitions - for example, being asked to identify the correct next investigative step when a subject's account shows signs of impersonation. Because this is one of the exam's deepest domains, it deserves proportionally more study time than a simple "one-fifth of your schedule" approach would suggest.
Domain 4: Mobile and Digital Forensics
Mobile and digital forensics is the second of the three highest-weighted domains, and arguably the most technical section of the CCII exam. This is where candidates without a forensics background tend to spend the most additional study time.
Mobile and Digital Forensics
Candidates must understand forensic soundness principles as they apply specifically to mobile devices and digital media.
- Mobile device data acquisition methods and their limitations
- File system artifacts unique to iOS and Android environments
- Digital evidence preservation, hashing, and documentation standards
- Recovering deleted or hidden data without compromising admissibility
- Tool-agnostic forensic principles applicable across platforms
Notice that this domain is tool-agnostic by design - the exam tests forensic reasoning and procedure, not familiarity with any single commercial forensic suite. That distinction matters when you're deciding how to allocate study time, and it's covered in more depth in our guide on how hard the CCII exam actually is.
Domain 5: E-Commerce, Fraud, Hacking, and Auction Fraud
The final domain addresses the financial and transactional side of cyber investigations - the schemes that generate the caseloads many CCII holders manage day to day, from marketplace fraud to account takeover to auction manipulation.
E-Commerce, Fraud, Hacking, and Auction Fraud
Candidates must be able to recognize common fraud typologies and trace the technical mechanics behind them.
- Auction fraud patterns: shill bidding, non-delivery schemes, counterfeit listings
- Account takeover and credential-stuffing investigation techniques
- Payment fraud indicators in e-commerce transaction data
- Basic hacking methodologies relevant to fraud investigations, including social engineering
- Following the money: tracing fraudulent transactions across platforms
This domain draws heavily from real-world case patterns, which is consistent with who actually pursues this certification - investigators and analysts working in e-commerce trust and safety, fraud units, financial crimes, and loss prevention roles. For a broader look at who hires CCII holders and what roles they fill, see our overview of CCII jobs.
Which Domains Carry the Most Weight
McAfee Institute doesn't publish an exact percentage split across the five domains, but the course structure itself signals where the emphasis lies. Mobile forensics, social media investigation, and legal fundamentals (embedded in case management) carry the deepest coverage across the 26 modules - meaning Domains 2, 3, and 4 collectively deserve more study time than Domains 1 and 5.
| Domain | Relative Depth | Study Priority |
|---|---|---|
| Domain 1: Cyber Intelligence & Analysis | Foundational | Moderate |
| Domain 2: Investigations & Case Management | High (legal fundamentals) | High |
| Domain 3: Social Media Investigation | Highest | Highest |
| Domain 4: Mobile & Digital Forensics | Highest | Highest |
| Domain 5: E-Commerce & Fraud | Moderate | Moderate |
This weighting isn't guesswork you have to accept blindly - it's reflected directly in module count and depth. Use it to build a study plan that mirrors actual exam risk instead of spreading effort evenly across five domains of unequal size.
Mapping the 26 Modules to a Study Timeline
Since the CCII is entirely self-paced with 24/7/365 module access, there's no fixed cohort schedule to follow - which is both a benefit and a trap. Candidates who treat "self-paced" as "no deadline" often stall out. A domain-weighted timeline solves this by front-loading the heaviest content early, while energy and momentum are highest.
Domain 1 Foundations
- Complete intelligence cycle and OSINT modules
- Take all embedded quizzes to lock in the 70% section requirement early
Domain 3: Social Media Investigation
- Work through platform-specific methodology modules in full
- Practice metadata extraction and evidence preservation scenarios
Domain 4: Mobile and Digital Forensics
- Focus on acquisition methods and file system artifacts
- Review forensic soundness principles until they're automatic
Domain 2: Case Management and Legal Fundamentals
- Study chain of custody and admissibility rules in depth
- Draft a sample investigative report using course templates
Domain 5: Fraud and E-Commerce
- Review auction fraud and account takeover case studies
- Connect fraud typologies back to Domain 1 analytic techniques
Full Review and Proctored Exam
- Run through practice questions across all five domains
- Schedule and complete the proctored final exam
This is a template, not a mandate - adjust the pacing to your own background. Someone coming from law enforcement may need less time on Domain 2's legal content, while someone from a pure IT background may need to extend Domain 4. For a more detailed week-by-week breakdown with specific resource recommendations, see the full CCII study guide.
Registration, Eligibility, and Scoring Mechanics
Domain content only matters once you're actually eligible to sit the exam, so it's worth reviewing the mechanics before you commit study hours. Eligibility is tiered by education and experience: a bachelor's degree plus one year of relevant experience, an associate's degree plus two years, or a high school diploma plus three years, in fields like e-commerce, fraud, investigations, intelligence, military, cybersecurity, law enforcement, forensics, or law. A felony conviction, a crime of moral turpitude, or a misdemeanor involving honesty, theft, embezzlement, or fraud disqualifies a candidate outright.
If you don't yet meet the eligibility bar, you're not locked out of studying. You can complete the training and earn a "Qualified" credential now, then purchase the standalone Certified Exam License later to convert to full "Certified" status once your experience catches up. Full pricing mechanics for both paths are covered in our CCII certification cost breakdown.
To actually earn the credential, you must submit every course quiz, score 70% or better on all course sections, score 70% or better on the final proctored exam, submit proof of eligibility with your application, and pay all fees in full. Once certified, the credential is valid for two years and requires 20 CPE credits per cycle, with at least 2 of those hours in ethics. There's a 30-day grace period after expiration - miss that window and the credential is permanently revoked, requiring a new exam license purchase to start over.
Beyond the certification mechanics themselves, it's worth understanding how the credential is positioned in the broader workforce landscape. The CCII is listed in the CISA NICCS Education & Training Catalog, mapped to the NIST NICE Workforce Framework, approved for Missouri POST CLEE credit, and eligible for military Credentialing Assistance and COOL funding across the Navy, Army, Air Force, Coast Guard, and DoD generally. That government-adjacent recognition is part of what separates the CCII from many vendor certifications, and it connects directly to the domain content above - the government frameworks it maps to prioritize exactly the intelligence, investigation, and forensics skill areas the exam tests. For a broader look at whether the investment pays off given your career goals, read our CCII ROI analysis, and if you want the numbers behind typical outcomes, check the CCII salary guide.
Once you have a handle on the domains, the best next step is testing your recall against realistic scenario questions rather than just re-reading module text. You can start running practice questions modeled on the five domains at the CCII practice test platform, and cross-check tricky terminology against our CCII cheat sheet before exam day. If you're still deciding whether the credential fits your path, our plain-language explainer on what CCII certification actually is is a good starting point, and returning to the main practice test site periodically as you move through each domain will help you spot weak areas before the proctored exam does.
Frequently Asked Questions
Five: Cyber Intelligence and Intelligence Analysis, Cyber Investigations and Case Management, Social Media Investigation Methodologies, Mobile and Digital Forensics, and E-Commerce, Fraud, Hacking, and Auction Fraud.
Mobile and Digital Forensics is generally the most technically demanding domain, especially for candidates without a forensics background, since it requires understanding acquisition methods and file system artifacts in detail.
McAfee Institute does not publish exact domain percentages, but mobile forensics, social media investigation, and legal fundamentals carry the deepest coverage across the 26 modules, suggesting heavier emphasis in those areas.
Certification requires scoring 70% or better on all sections of the course plus 70% or better on the final proctored exam, so strong performance across every domain matters, not just an overall average.
Yes. You can complete the 26-module training and earn a "Qualified" credential first, then purchase a Certified Exam License later once you meet the education and experience requirements.