- How to Read the 13 Content Areas
- Exam Facts That Frame Your Preparation
- Intelligence Foundations, OSINT and SOCMINT
- Cybercrime Investigations and Counterintelligence
- Fraud, Organized Retail Crime and Electronic Discovery
- Computer Forensics and Mobile Forensics
- Surveillance and Informants
- Case Development and Professional Reporting
- Mapping the Four Published Learning Outcomes
- Sequencing the Domains in Your Schedule
- Frequently Asked Questions
- The 13 domains here are editorial preparation categories drawn from the public CECI narrative, not official weighted exam sections.
- CECI is the capstone of a six-credential McAfee Institute program, but that does not create six exam domains.
- The standalone exam costs USD 450, allows one attempt, runs online proctored for three hours, and requires 70% to pass.
- Official topic weights, question count and item format are unverified, so prepare across all 13 areas rather than guessing at emphasis.
How to Read the 13 Content Areas
The Certified Expert in Cyber Investigations (CECI) credential from McAfee Institute is unusual because it is not a narrow technical certification. It spans intelligence tradecraft, online research, digital forensics, fraud, field techniques and case reporting. Candidates coming from a single specialty, whether patrol, fraud examination, or lab-based forensics, often discover that a third of the material sits outside their daily work.
This guide organizes that breadth into thirteen headings. Each corresponds to a technical area explicitly named in the current public CECI curriculum narrative. A few honest caveats shape how you should use them:
- These are editorial preparation categories. McAfee Institute has not published official topic weights, so no percentage should be attached to any domain.
- The public course listing does not expose its full 43-module outline, and this article does not attempt to reconstruct module titles.
- Exhaustive examination coverage is unverified. Treat this guide as a map of the published scope, not a leaked blueprint of live questions.
For a broader view of how to turn this map into a plan, pair this article with the CECI Study Guide 2026: How to Pass on Your First Attempt.
Exam Facts That Frame Your Preparation
Before diving into the domains, anchor yourself in what is actually published about the assessment. The facts below come from McAfee Institute's current public pages.
| Item | Published detail |
|---|---|
| Administering body | McAfee Institute |
| Standalone exam fee | USD 450 |
| Attempts | One attempt |
| Delivery | Online proctored |
| Time limit | Three hours |
| Exam license | One year (an access period, not credential validity) |
| Passing threshold | 70% |
| Question count and item format | Not verified publicly |
Two implications stand out. First, with a single attempt, breadth matters more than depth in any one comfortable area. Second, because the question count and format are not published, you should not build your preparation around an assumed multiple-choice structure. Instead, practice reasoning through scenarios, justifying decisions, and recalling terminology across all thirteen areas. Details on scoring live in CECI Passing Score 2026: Exactly What You Need to Pass, and a candid look at difficulty is in How Hard Is the CECI Exam? Complete Difficulty Guide 2026.
Intelligence Foundations, OSINT and SOCMINT
The first three domains form the analytic backbone of the credential. They teach you how to think like an intelligence-led investigator before you touch a forensic tool.
Domain 1: Intelligence foundations
This area establishes the vocabulary and method that later domains rely on. The published learning outcomes highlight investigative playbooks, attribution, threat modeling and covert intelligence collection as part of advanced investigation methods.
- How intelligence differs from raw information, and why that distinction matters in a case file
- Structuring an investigative playbook so repeat case types follow consistent steps
- Attribution as a reasoned judgment with stated confidence, not a certainty claim
- Threat modeling to anticipate how a subject or adversary might behave
Domain 2: Open-source intelligence and online research
OSINT is research from publicly available sources. For exam purposes, think about method, documentation and lawful boundaries rather than a catalog of websites.
- Planning a search so it is repeatable and documented
- Capturing and preserving online content so it can later support a report
- Recognizing the limits of public sources and the risk of unreliable or manipulated material
- Corroborating a single online finding with an independent source before relying on it
Domain 3: Social media intelligence
Social media intelligence applies research discipline to platforms where subjects reveal associations, locations, routines and intent.
- Identifying relationships and patterns across accounts while avoiding assumptions of identity
- Preserving posts, profiles and timestamps in a way that supports later use as evidence
- Understanding how platform terms, privacy settings and legal process affect what you may lawfully obtain
A useful exercise: take a hypothetical missing-persons or harassment scenario and write out, in order, what you would research, what you would preserve, and what you would corroborate. If your steps skip documentation, you are missing the theme the exam keeps returning to.
Cybercrime Investigations and Counterintelligence
Domain 4: Cybercrime investigations
This domain covers how investigators approach offenses that occur through or against computer systems and networks. Expect to reason about how a cyber incident becomes a criminal case.
- Identifying what digital artifacts a given offense is likely to leave behind
- Linking technical findings to a person, which connects directly back to attribution in Domain 1
- Coordinating with legal process, service providers and other agencies
- Protecting volatile and fragile evidence early in an incident
Domain 5: Counterintelligence
Counterintelligence focuses on detecting and countering efforts by others to gather information about your organization, investigation or personnel.
- Recognizing signs that an investigation or team has been compromised or observed
- Protecting sources, methods and case information from leaks
- Understanding insider risk in the context of an organization's investigative or security function
Candidates often underestimate counterintelligence because it feels abstract. Anchor it in practice: ask how a subject could learn that you are investigating them, and what you would change to prevent it. That mindset ties directly into the covert collection element of the published learning outcomes.
Fraud, Organized Retail Crime and Electronic Discovery
Domains 6 through 8 are where the credential's multidisciplinary character is most visible. They reflect casework common in corporate security, loss prevention, financial investigations and civil or regulatory matters.
Domain 6: Fraud investigations
Fraud work blends documentary analysis, interviewing, and digital evidence. The central skill is reconstructing what happened and who benefited, then proving it in a defensible way.
- Following transactions and records to establish a pattern of deception
- Distinguishing error from intent in how you describe findings
- Combining digital artifacts with business records into a coherent narrative
Domain 7: Organized retail crime
Organized retail crime investigations address coordinated theft and resale activity rather than isolated incidents. The investigative challenge is connecting separate events into one organized scheme.
- Linking individual incidents to a larger network through shared indicators
- Using intelligence methods from earlier domains to map participants and roles
- Building a case that a prosecutor can present as organized activity, not scattered petty offenses
Domain 8: Electronic discovery
Electronic discovery concerns identifying, preserving, collecting and producing electronically stored information for legal matters.
- Why preservation must happen before data is altered or lost
- Scoping collection so it is defensible rather than overbroad or incomplete
- Documenting handling so authenticity and integrity can be demonstrated
Computer Forensics and Mobile Forensics
The two forensic domains test whether you understand how digital evidence is acquired and handled, not just how tools behave. The published outcome on forensically sound evidence emphasizes legally defensible handling, chain of custody and prosecution-ready reporting.
Domain 9: Computer forensics
Computer forensics addresses evidence on computers and storage media.
- Preserving original media and working from verified copies
- Recording who handled evidence, when and why, to maintain chain of custody
- Interpreting artifacts such as file activity, user accounts and timelines with appropriate caution
- Documenting methods so another examiner could reproduce your results
Domain 10: Mobile forensics
Mobile forensics deals with phones and similar devices, which hold communications, location history and application data.
- Recognizing that mobile devices change state quickly and may be affected by remote actions or network connectivity
- Understanding that lawful authority and consent affect what you may examine
- Correlating device data with other sources to build a timeline of activity
The program's hands-on labs use simulated cases and tools, so expect the practical side of forensics to matter in training. For the exam itself, prioritize principles: preservation, documentation, authority and reproducibility. Specific tool menus are less likely to be the lasting takeaway than the reasoning behind each step.
Surveillance and Informants
Domains 11 and 12 move from the screen to the street, and from data to people. They carry legal and ethical weight, so precision about authority and documentation is essential.
Domain 11: Surveillance
Surveillance covers observing people, places or activity to gather investigative information.
- Planning an operation around its objective, legal limits and documentation needs
- Recording observations contemporaneously so they can support later testimony or reporting
- Balancing effectiveness against the risk of exposure, tying back to counterintelligence
Domain 12: Informants
Informant handling concerns how investigators obtain, evaluate and protect information from human sources.
- Assessing source reliability and motivation rather than accepting claims at face value
- Protecting source identity and managing the relationship professionally
- Corroborating informant information independently before acting on it
Scenario reasoning is the best preparation here. Practice explaining why you would corroborate a tip, how you would document a surveillance session, and what could jeopardize a source. If you want to see how others approach this material, our CECI Training overview explains how the course is structured.
Case Development and Professional Reporting
Domain 13: Case development and professional reporting
This domain is where everything converges. A strong investigation that cannot be communicated clearly, or cannot withstand scrutiny, fails at the last step.
- Organizing findings into a logical, defensible case narrative
- Writing reports that are accurate, objective and prosecution-ready
- Distinguishing facts, inferences and opinions so readers know what each represents
- Supporting the report with documented chain of custody and traceable sources
It also connects to the fourth published learning outcome: building and leading cyber programs, including SOPs, team structure and metric-driven reporting. Candidates should be comfortable thinking beyond a single case to how an investigative unit documents procedures, assigns responsibilities and measures its output.
Key Takeaway
Treat Domain 13 as a review lens for the other twelve. After studying any area, ask how you would report it: what you did, what you found, how you preserved it, and why a reader should trust it.
Mapping the Four Published Learning Outcomes
McAfee Institute publishes four learning outcomes for the CECI program. They are not domains, but they help you see which domains support which professional capability.
| Published learning outcome | Domains it draws on most |
|---|---|
| Advanced investigation methods: playbooks, attribution, threat modeling, covert intelligence collection | Intelligence foundations, Counterintelligence, Surveillance, Informants |
| Hands-on real-world labs with simulated cases and tools | Cybercrime investigations, Computer forensics, Mobile forensics, OSINT |
| Forensically sound evidence: legally defensible handling, chain of custody, prosecution-ready reporting | Electronic discovery, Computer forensics, Mobile forensics, Case development |
| Building and leading cyber programs: SOPs, team structure, metric-driven reporting | Case development and professional reporting, Intelligence foundations |
This mapping is an editorial aid, not an official blueprint. It simply shows that the same competencies recur across several areas, which is why isolated memorization tends to be less effective than connected understanding.
Sequencing the Domains in Your Schedule
Because official weights are unverified, a sensible plan gives every domain attention and orders them by dependency. One approach, tied to how the material builds on itself:
Analytic foundations
- Intelligence foundations, then OSINT and social media intelligence
- Why first: these supply the vocabulary and documentation habits used everywhere else
Offense-specific investigations
- Cybercrime investigations, counterintelligence, fraud and organized retail crime
- Practice connecting separate incidents into one organized case
Evidence handling
- Electronic discovery, computer forensics and mobile forensics
- Rehearse preservation, chain of custody and reproducibility until they feel automatic
Field craft and reporting
- Surveillance, informants, then case development and professional reporting
- Finish with full-scope review so reporting ties the earlier domains together
Adjust the order to your background. A forensic examiner may compress Week 3 and spend longer on informants and counterintelligence, while a former detective may do the reverse. For a concise recall aid close to exam day, see the CECI Cheat Sheet 2026: One-Page Review of Must-Know Facts, and to pressure-test your recall under realistic conditions, try the CECI practice tests.
Eligibility and Cost Context
Mastering the domains is only part of the path. Candidates must also meet experience-based eligibility: a bachelor's degree or higher plus four years of relevant experience, an associate degree plus six years, or a high school diploma or equivalent plus seven years. The experience must involve criminal investigations or intelligence in investigations, law enforcement, criminal justice, military, or a similar field. Eligibility documentation and professional-conduct requirements apply. The full breakdown is in CECI Requirements 2026: Eligibility, Prerequisites & How to Qualify.
On cost, the standalone exam is USD 450. The separate self-paced program is USD 2,497 and contains 43 modules and 100 instructional hours, with 100 course CPE credits, a study manual, review quizzes, a one-year exam license and lifetime course access. It bundles six credentials, with CECI as the capstone. See CECI Certification Cost 2026: Complete Pricing Breakdown for a side-by-side comparison of the two routes.
Frequently Asked Questions
No. They are editorial preparation categories built from technical areas named in the public CECI curriculum narrative. McAfee Institute has not published official topic weights, so no domain should be assumed to carry a particular percentage.
No. The program bundles six credentials with CECI as the capstone, but that does not establish six exam domains or identical examinations. The 43 course modules are also not weighted exam domains.
The current question count, scored versus unscored allocation and exact item format are not publicly verified. The published facts are a three-hour online proctored session, one attempt and a 70% passing threshold, so avoid assuming any specific item count.
Start with intelligence foundations, OSINT and social media intelligence, because the documentation, attribution and corroboration habits they teach apply to every later domain. Finish with case development and reporting to tie everything together.
See CECI Jobs for the kinds of investigative roles where the credential is relevant, and Is the CECI Certification Worth It? Complete ROI Analysis 2026 for a qualitative look at value.