10 exam-style questions with answers and explanations, straight from our 1,051-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
These 10 free CCII questions are organized by exam domain, so you can see how each part of the Certified Cyber Intelligence Investigator (CCII) blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Cyber Intelligence and Intelligence Analysis
Question 1
An analyst downloads 4,000 breach-forum posts, sorts them by date, removes duplicates, and delivers the cleaned spreadsheet to a manager who must decide whether to shut down a payment channel. At the moment of delivery, what has the analyst produced?
Show answer & explanation
Correct answer: B - Information, processed but not analyzed
Question 2
An intelligence unit receives a tasking, collects on it, translates the material, analyzes it, and delivers a finished product. The consumer reads the product and asks three new questions. In the intelligence cycle, this consumer response is BEST described as:
Show answer & explanation
Correct answer: C - Evaluation and feedback, restarting the cycle
Domain 5: E-Commerce, Fraud, Hacking, and Auction Fraud
Question 3
An investigator logs into their online banking portal to review a subpoenaed statement. Which layer of the web are they accessing?
Show answer & explanation
Correct answer: A - The deep web, because the account content sits behind authentication and is not indexed
Question 4
A suspect uses Tor to browse a conventional (non-.onion) website over plain HTTP. Which relay in the circuit is able to observe the unencrypted content of that traffic?
Show answer & explanation
Correct answer: C - The exit node, which strips the final layer before forwarding
Question 5
A vendor has moved across four dark web marketplaces after successive takedowns, using a different handle each time. Historically, which factor has MOST often enabled investigators to attribute such vendors?
Show answer & explanation
Correct answer: B - Operational security mistakes by the vendor
Question 6
A fraud suspect moved funds through Bitcoin. Which statement about the resulting investigative posture is accurate?
Show answer & explanation
Correct answer: C - Bitcoin is pseudonymous; the ledger is public and regulated exchanges are the strongest attribution point
More CCII practice questions
Question 7
An investigator receives a suspicious email as a forwarded message from the recipient and needs to determine its true origin. What is the MOST significant problem with the material as received?
Show answer & explanation
Correct answer: A - Forwarding rewrites the header chain, so the original Received: path that would reveal the true origin is no longer intact
Question 8
An email purporting to come from a company's CFO passes both SPF and DKIM checks, and DMARC reports alignment. What may the investigator properly conclude?
Show answer & explanation
Correct answer: B - It came from an authorized server and was unaltered
Question 9
Responders arrive to find a suspect's desktop powered on, logged in, and running a full-disk-encrypted volume. Following the order of volatility, what should be collected FIRST?
Show answer & explanation
Correct answer: C - The contents of RAM
Question 10
An examiner is given a USB drive as evidence and connects it to a forensic workstation through a hardware write blocker. What does the write blocker accomplish?
Show answer & explanation
Correct answer: B - It permits reading while preventing any write, so mere connection cannot alter the original evidence