CECI logo
Focused certification exam prep
Start practice

CECI Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • CECI is the McAfee Institute capstone: online proctored, three hours, one attempt, USD 450, 70% passing threshold.
  • The one-year exam license is an access window for sitting the exam, not the validity period of the credential.
  • The USD 2,497 program has 43 modules and 100 hours, but modules are not weighted exam domains.
  • Official topic weights, question count and item format are unverified, so never memorize a "blueprint" claiming otherwise.

Identity Check: Which CECI This Sheet Covers

Several credentials in the wider world share the acronym "CECI." This cheat sheet covers exactly one of them: the Certified Expert in Cyber Investigations, administered by McAfee Institute. Nothing below applies to any other credential that happens to abbreviate the same way, so if you have seen fees, dates or pass-rate claims attached to a different "CECI," discard them. If you are still orienting, the explainer pages What Is CECI? and What Does CECI Stand For? cover the naming question in more depth.

This page is built for a final-week skim: hard facts first, then the technical areas named in the issuer's public curriculum narrative, then the traps that cost candidates points through confusion rather than ignorance. For a slower, full-length plan, use the CECI study guide alongside this sheet.

Exam Mechanics at a Glance

ItemWhat the issuer publishes
Certifying bodyMcAfee Institute
Role of CECICapstone certification in a multi-credential program
DeliveryOnline proctored
Time limitThree hours
AttemptsOne attempt
Standalone exam feeUSD 450
Exam licenseOne year (an access period)
Passing threshold70%
Question countUnverified: do not assume a number
Item formatUnverified: do not assume multiple choice
Official topic weightsUnverified

The single most important line in that table is "one attempt." A one-attempt, proctored, three-hour exam rewards candidates who have rehearsed pacing and scenario reasoning, not just vocabulary. See CECI Passing Score for how to think about the 70% threshold, and How Hard Is the CECI Exam? for a difficulty assessment grounded in what is actually published.

Do not infer what is not published: The current public sources do not state an exact question count, a scored versus unscored split, or a confirmed item format. Any resource that tells you "the exam has N multiple-choice questions" is guessing. Prepare for scenario-style reasoning across the whole curriculum narrative rather than optimizing for a format nobody has verified.

Eligibility Grid

CECI is experience-gated. Your education level determines how much qualifying experience you need:

EducationRequired relevant experience
Bachelor's degree or higherFour years
Associate degreeSix years
High-school diploma or equivalentSeven years

Qualifying experience must involve criminal investigations or intelligence in investigations, in law enforcement, criminal justice, the military, or a similar field. Eligibility documentation and professional-conduct requirements also apply, which means the credential is not a pure "pay and test" product. Work through the details in CECI Requirements: Eligibility, Prerequisites & How to Qualify before you budget time or money.

Money, Program Size, and What They Are Not

There are two ways to reach the exam, and the numbers attached to each are easy to cross-contaminate.

Standalone exam path

For candidates who prepare independently and qualify on experience.

  • USD 450 exam fee
  • Online proctored, three hours, one attempt
  • One-year exam license

Self-paced program path

A bundled training product with CECI as the capstone.

  • USD 2,497
  • 43 modules and 100 instructional hours
  • 100 course CPE credits
  • Training, study manual, review quizzes, a one-year exam license, and lifetime course access
  • Bundles six credentials: CFHI, CEFI, SMIA, CCIP and CCTA, with CECI as the capstone

The full economic picture, including how to compare the two paths, lives in CECI Certification Cost. If you are weighing the investment, Is the CECI Certification Worth It? and the CECI salary guide address return on investment.

Four things that are NOT what they sound like: (1) The 100 course CPE credits are not a renewal requirement. (2) The 100 instructional hours are not the exam duration. (3) The 43 modules are not an exam question count or a set of weighted domains. (4) The one-year exam license is an access period, not the lifespan of your credential. Keep these four straight and you avoid the most common cheat-sheet errors.

The Four Published Learning Outcomes

The issuer's current narrative frames the program around four outcomes. Treat these as the spine of your preparation:

  1. Advanced investigation methods: investigative playbooks, attribution, threat modeling and covert intelligence collection.
  2. Hands-on, real-world labs: simulated cases and tools, which is why practical fluency matters more than definitions alone.
  3. Forensically sound evidence: legally defensible handling, chain of custody and prosecution-ready reporting.
  4. Building and leading cyber programs: SOPs, team structure and metric-driven reporting.

Notice that two of the four are about process and defensibility (evidence handling, program leadership) rather than raw technical skill. Candidates from purely technical backgrounds often under-prepare those two.

The Thirteen Preparation Areas

The thirteen headings below organize technical areas explicitly named in the current public CECI narrative. They are editorial preparation categories, not an official blueprint and not the program's 43-module list; the public curriculum data does not expose module titles, and official weights are unverified. For the long-form treatment, see CECI Exam Domains: Complete Guide to All 13 Content Areas.

1. Intelligence foundations

The conceptual base for everything else: how intelligence differs from raw information and how it supports investigative decisions.

  • Know how playbooks, attribution and threat modeling structure an investigation
  • Be able to explain why a collection plan precedes collection

2. Open-source intelligence and online research

Methodical, documented research using publicly available sources.

  • Source evaluation and corroboration before reliance
  • Capturing and preserving what you find so it can be defended later

3. Social media intelligence

Extracting investigative value from social platforms without compromising the case.

  • Account and relationship analysis
  • Preservation of volatile, easily deleted content

4. Cybercrime investigations

Working technology-enabled offenses from complaint through attribution.

  • Linking digital artifacts to actors
  • Coordinating with other disciplines on multi-part cases

5. Counterintelligence

Protecting investigative operations and information from hostile collection and compromise.

  • Recognizing exposure risks to sources, methods and teams

6. Fraud investigations

Reconstructing deceptive schemes and the financial or digital trail they leave.

  • Pattern recognition and evidence linkage across records

7. Organized retail crime

Investigating coordinated theft and resale operations as networks rather than isolated incidents.

  • Connecting individual events into a group-level case

8. Electronic discovery

Identifying, preserving and producing electronically stored information in a defensible way.

  • Scope, preservation and handling of ESI

9. Computer forensics

Acquiring and analyzing data from computing systems while keeping evidence admissible.

  • Forensically sound acquisition and documentation
  • Chain of custody from seizure to reporting

10. Mobile forensics

Extracting and interpreting data from mobile devices.

  • Handling devices to preserve volatile data
  • Tying device artifacts to timeline and attribution

11. Surveillance

Observation techniques and their legal and operational constraints.

  • Documentation discipline and lawful conduct

12. Informants

Developing, managing and corroborating human sources.

  • Reliability assessment and corroboration
  • Protecting the source and the case

13. Case development and professional reporting

Turning findings into a coherent, prosecution-ready product.

  • Clear, defensible reports that stand up to scrutiny
  • SOPs and metric-driven reporting at the program level

Evidence and Reporting Rules to Know Cold

Because "forensically sound evidence" and "prosecution-ready reporting" are named learning outcomes, expect scenario reasoning to reward defensible process. A few principles to internalize, framed as reasoning habits rather than memorized trivia:

  • Document before you act. If a step changes the evidence or its context, the record of why and how should exist first.
  • Preserve volatile material early. Social media content, device state and online records can disappear; the earlier the capture, the stronger the case.
  • Maintain an unbroken custody trail. Every transfer, access and storage point should be accounted for.
  • Corroborate before you rely. Whether the input is an informant, an open-source post or a device artifact, independent confirmation strengthens the finding.
  • Write for the reader who was not there. A prosecutor, supervisor or reviewing party should be able to follow your reasoning from the report alone.
  • Stay inside lawful authority. Surveillance, collection and handling questions often hinge on whether the method is legally defensible, not merely effective.

Key Takeaway

When a scenario offers a fast technical shortcut and a slower defensible process, the defensible process is almost always the intended direction. Practice explaining why a step protects admissibility, not just that it does. You can drill this reasoning style on the CECI practice tests.

Numbers That Get Confused

This is the section to reread the night before. Each pair below mixes two figures that candidates routinely blur together.

FigureWhat it actually isWhat it is not
USD 450Standalone exam feeThe cost of the full program
USD 2,497Self-paced program priceThe exam fee
100 hoursInstructional hours in the programExam length (that is three hours)
100 CPE creditsCourse credits awarded by the programA renewal requirement
43 modulesProgram structureWeighted exam domains or a question count
One-year licenseExam access windowCredential validity period
Six credentialsBundle with CECI as capstoneSix CECI exam domains or identical exams
70%Published passing thresholdAn observed pass rate

That last row matters: a passing threshold is a rule, while a pass rate is an outcome statistic, and no verified pass rate is published. The CECI pass rate page explains how to treat pass-rate claims you encounter elsewhere, and CECI Exam Dates covers scheduling within your license window.

Sequencing the Areas Across Your Prep

You do not need a generic study philosophy here, just a sensible order that follows how the thirteen areas depend on each other. One workable arrangement over four weeks:

Week 1

Foundations and collection

  • Intelligence foundations first, because every later area assumes its vocabulary
  • Open-source intelligence and social media intelligence, since both are collection methods built on the same sourcing discipline
Week 2

Offense-specific investigations

  • Cybercrime, fraud and organized retail crime, studied together to practice linking separate incidents into one case
  • Counterintelligence alongside, to keep exposure risk in view
Week 3

Technical evidence

  • Electronic discovery, computer forensics and mobile forensics in sequence, centered on chain of custody and defensible handling
Week 4

Human sources, surveillance, reporting

  • Surveillance and informants, then case development and professional reporting last, because reporting synthesizes everything before it
  • Finish with full timed scenario practice to rehearse the three-hour limit

The logic: reporting goes last because it consumes the outputs of every other area, and foundations go first because everything else leans on them. Adjust the weeks to your own background; a seasoned digital forensics examiner might compress Week 3 and spend longer on informants and surveillance, which are often the thinner areas for technical candidates.

Where the Credential Fits in Casework and Hiring

CECI targets multidisciplinary investigative casework, meaning the kind of work where a single case touches open-source research, digital evidence, human sources and formal reporting. The eligibility rules signal the intended audience: people with real experience in criminal investigations or intelligence, in law enforcement, criminal justice, the military or similar settings. That makes it relevant to investigators, analysts and program leads who need to show breadth across the investigative lifecycle, not just depth in one tool.

Because the fourth learning outcome covers building and leading cyber programs (SOPs, team structure, metric-driven reporting), the credential also speaks to supervisory and program-management roles. For a view of the job landscape, see CECI Jobs, and for the training pathway options, CECI Training. When you are ready to test yourself against realistic scenarios, start a session on the main practice site.

A note on scope: This sheet is built from the issuer's current public sources, reviewed for supplementary CECI preparation. Private course modules and live examination questions were not accessed, and nothing here replaces the official course, experience eligibility, conduct review or the proctored assessment itself. Always confirm current fees and policies on McAfee Institute's official CECI pages before you pay.

Frequently Asked Questions

How many questions are on the CECI exam?

The current public sources do not state a question count, a scored versus unscored split, or a confirmed item format. What is published is the delivery model: online proctored, three-hour limit, one attempt, and a 70% passing threshold. Treat any specific question count you see elsewhere as unverified.

Does the one-year exam license mean my certification expires after a year?

No. The one-year exam license is an access period during which you can sit the exam. It is separate from certification validity, so do not read it as a renewal clock. Check the issuer's official pages for current credential terms.

Are the 43 program modules the same as the exam domains?

No. The 43 modules describe the structure of the USD 2,497 self-paced program, which bundles six credentials with CECI as the capstone. They are not weighted exam domains, and the thirteen areas on this page are editorial preparation categories rather than an official blueprint.

Do the 100 CPE credits count toward renewing CECI?

The 100 CPE credits are course credits awarded by completing the program. They are not a renewal requirement, and they are not an exam question count or duration. Verify any current maintenance expectations directly with McAfee Institute.

Can I take the exam with no investigations experience?

Eligibility is experience-based: four years with a bachelor's degree or higher, six with an associate degree, or seven with a high-school diploma or equivalent, in criminal investigations or intelligence in investigations, law enforcement, criminal justice, the military or a similar field. Documentation and professional-conduct requirements also apply, so review the full requirements first.

Ready to pass your CECI exam?

Put this into practice with free CECI questions across every exam domain.