CECI logo
Focused certification exam prep
Start practice

CECI Exam Domains 2026: Complete Guide to All 13 Content Areas

TL;DR
  • The 13 domains here are editorial preparation categories drawn from the public CECI narrative, not official weighted exam sections.
  • CECI is the capstone of a six-credential McAfee Institute program, but that does not create six exam domains.
  • The standalone exam costs USD 450, allows one attempt, runs online proctored for three hours, and requires 70% to pass.
  • Official topic weights, question count and item format are unverified, so prepare across all 13 areas rather than guessing at emphasis.

How to Read the 13 Content Areas

The Certified Expert in Cyber Investigations (CECI) credential from McAfee Institute is unusual because it is not a narrow technical certification. It spans intelligence tradecraft, online research, digital forensics, fraud, field techniques and case reporting. Candidates coming from a single specialty, whether patrol, fraud examination, or lab-based forensics, often discover that a third of the material sits outside their daily work.

This guide organizes that breadth into thirteen headings. Each corresponds to a technical area explicitly named in the current public CECI curriculum narrative. A few honest caveats shape how you should use them:

  • These are editorial preparation categories. McAfee Institute has not published official topic weights, so no percentage should be attached to any domain.
  • The public course listing does not expose its full 43-module outline, and this article does not attempt to reconstruct module titles.
  • Exhaustive examination coverage is unverified. Treat this guide as a map of the published scope, not a leaked blueprint of live questions.

For a broader view of how to turn this map into a plan, pair this article with the CECI Study Guide 2026: How to Pass on Your First Attempt.

Exam Facts That Frame Your Preparation

Before diving into the domains, anchor yourself in what is actually published about the assessment. The facts below come from McAfee Institute's current public pages.

ItemPublished detail
Administering bodyMcAfee Institute
Standalone exam feeUSD 450
AttemptsOne attempt
DeliveryOnline proctored
Time limitThree hours
Exam licenseOne year (an access period, not credential validity)
Passing threshold70%
Question count and item formatNot verified publicly

Two implications stand out. First, with a single attempt, breadth matters more than depth in any one comfortable area. Second, because the question count and format are not published, you should not build your preparation around an assumed multiple-choice structure. Instead, practice reasoning through scenarios, justifying decisions, and recalling terminology across all thirteen areas. Details on scoring live in CECI Passing Score 2026: Exactly What You Need to Pass, and a candid look at difficulty is in How Hard Is the CECI Exam? Complete Difficulty Guide 2026.

Exam license is not certification validity: The one-year exam license only governs the window in which you can sit the exam. It says nothing about how long the credential remains valid. Likewise, the 100 course CPE credits earned through the training program are not a renewal requirement. Keep these three ideas separate in your notes.

Intelligence Foundations, OSINT and SOCMINT

The first three domains form the analytic backbone of the credential. They teach you how to think like an intelligence-led investigator before you touch a forensic tool.

Domain 1: Intelligence foundations

This area establishes the vocabulary and method that later domains rely on. The published learning outcomes highlight investigative playbooks, attribution, threat modeling and covert intelligence collection as part of advanced investigation methods.

  • How intelligence differs from raw information, and why that distinction matters in a case file
  • Structuring an investigative playbook so repeat case types follow consistent steps
  • Attribution as a reasoned judgment with stated confidence, not a certainty claim
  • Threat modeling to anticipate how a subject or adversary might behave

Domain 2: Open-source intelligence and online research

OSINT is research from publicly available sources. For exam purposes, think about method, documentation and lawful boundaries rather than a catalog of websites.

  • Planning a search so it is repeatable and documented
  • Capturing and preserving online content so it can later support a report
  • Recognizing the limits of public sources and the risk of unreliable or manipulated material
  • Corroborating a single online finding with an independent source before relying on it

Domain 3: Social media intelligence

Social media intelligence applies research discipline to platforms where subjects reveal associations, locations, routines and intent.

  • Identifying relationships and patterns across accounts while avoiding assumptions of identity
  • Preserving posts, profiles and timestamps in a way that supports later use as evidence
  • Understanding how platform terms, privacy settings and legal process affect what you may lawfully obtain

A useful exercise: take a hypothetical missing-persons or harassment scenario and write out, in order, what you would research, what you would preserve, and what you would corroborate. If your steps skip documentation, you are missing the theme the exam keeps returning to.

Cybercrime Investigations and Counterintelligence

Domain 4: Cybercrime investigations

This domain covers how investigators approach offenses that occur through or against computer systems and networks. Expect to reason about how a cyber incident becomes a criminal case.

  • Identifying what digital artifacts a given offense is likely to leave behind
  • Linking technical findings to a person, which connects directly back to attribution in Domain 1
  • Coordinating with legal process, service providers and other agencies
  • Protecting volatile and fragile evidence early in an incident

Domain 5: Counterintelligence

Counterintelligence focuses on detecting and countering efforts by others to gather information about your organization, investigation or personnel.

  • Recognizing signs that an investigation or team has been compromised or observed
  • Protecting sources, methods and case information from leaks
  • Understanding insider risk in the context of an organization's investigative or security function

Candidates often underestimate counterintelligence because it feels abstract. Anchor it in practice: ask how a subject could learn that you are investigating them, and what you would change to prevent it. That mindset ties directly into the covert collection element of the published learning outcomes.

Fraud, Organized Retail Crime and Electronic Discovery

Domains 6 through 8 are where the credential's multidisciplinary character is most visible. They reflect casework common in corporate security, loss prevention, financial investigations and civil or regulatory matters.

Domain 6: Fraud investigations

Fraud work blends documentary analysis, interviewing, and digital evidence. The central skill is reconstructing what happened and who benefited, then proving it in a defensible way.

  • Following transactions and records to establish a pattern of deception
  • Distinguishing error from intent in how you describe findings
  • Combining digital artifacts with business records into a coherent narrative

Domain 7: Organized retail crime

Organized retail crime investigations address coordinated theft and resale activity rather than isolated incidents. The investigative challenge is connecting separate events into one organized scheme.

  • Linking individual incidents to a larger network through shared indicators
  • Using intelligence methods from earlier domains to map participants and roles
  • Building a case that a prosecutor can present as organized activity, not scattered petty offenses

Domain 8: Electronic discovery

Electronic discovery concerns identifying, preserving, collecting and producing electronically stored information for legal matters.

  • Why preservation must happen before data is altered or lost
  • Scoping collection so it is defensible rather than overbroad or incomplete
  • Documenting handling so authenticity and integrity can be demonstrated
The connecting thread: Fraud, retail crime and electronic discovery look different on the surface, yet each ends the same way: a collection of facts must be preserved, organized and presented so someone else can rely on them. When a scenario seems unfamiliar, ask what a reviewer would need to trust your conclusions.

Computer Forensics and Mobile Forensics

The two forensic domains test whether you understand how digital evidence is acquired and handled, not just how tools behave. The published outcome on forensically sound evidence emphasizes legally defensible handling, chain of custody and prosecution-ready reporting.

Domain 9: Computer forensics

Computer forensics addresses evidence on computers and storage media.

  • Preserving original media and working from verified copies
  • Recording who handled evidence, when and why, to maintain chain of custody
  • Interpreting artifacts such as file activity, user accounts and timelines with appropriate caution
  • Documenting methods so another examiner could reproduce your results

Domain 10: Mobile forensics

Mobile forensics deals with phones and similar devices, which hold communications, location history and application data.

  • Recognizing that mobile devices change state quickly and may be affected by remote actions or network connectivity
  • Understanding that lawful authority and consent affect what you may examine
  • Correlating device data with other sources to build a timeline of activity

The program's hands-on labs use simulated cases and tools, so expect the practical side of forensics to matter in training. For the exam itself, prioritize principles: preservation, documentation, authority and reproducibility. Specific tool menus are less likely to be the lasting takeaway than the reasoning behind each step.

Surveillance and Informants

Domains 11 and 12 move from the screen to the street, and from data to people. They carry legal and ethical weight, so precision about authority and documentation is essential.

Domain 11: Surveillance

Surveillance covers observing people, places or activity to gather investigative information.

  • Planning an operation around its objective, legal limits and documentation needs
  • Recording observations contemporaneously so they can support later testimony or reporting
  • Balancing effectiveness against the risk of exposure, tying back to counterintelligence

Domain 12: Informants

Informant handling concerns how investigators obtain, evaluate and protect information from human sources.

  • Assessing source reliability and motivation rather than accepting claims at face value
  • Protecting source identity and managing the relationship professionally
  • Corroborating informant information independently before acting on it

Scenario reasoning is the best preparation here. Practice explaining why you would corroborate a tip, how you would document a surveillance session, and what could jeopardize a source. If you want to see how others approach this material, our CECI Training overview explains how the course is structured.

Case Development and Professional Reporting

Domain 13: Case development and professional reporting

This domain is where everything converges. A strong investigation that cannot be communicated clearly, or cannot withstand scrutiny, fails at the last step.

  • Organizing findings into a logical, defensible case narrative
  • Writing reports that are accurate, objective and prosecution-ready
  • Distinguishing facts, inferences and opinions so readers know what each represents
  • Supporting the report with documented chain of custody and traceable sources

It also connects to the fourth published learning outcome: building and leading cyber programs, including SOPs, team structure and metric-driven reporting. Candidates should be comfortable thinking beyond a single case to how an investigative unit documents procedures, assigns responsibilities and measures its output.

Key Takeaway

Treat Domain 13 as a review lens for the other twelve. After studying any area, ask how you would report it: what you did, what you found, how you preserved it, and why a reader should trust it.

Mapping the Four Published Learning Outcomes

McAfee Institute publishes four learning outcomes for the CECI program. They are not domains, but they help you see which domains support which professional capability.

Published learning outcomeDomains it draws on most
Advanced investigation methods: playbooks, attribution, threat modeling, covert intelligence collectionIntelligence foundations, Counterintelligence, Surveillance, Informants
Hands-on real-world labs with simulated cases and toolsCybercrime investigations, Computer forensics, Mobile forensics, OSINT
Forensically sound evidence: legally defensible handling, chain of custody, prosecution-ready reportingElectronic discovery, Computer forensics, Mobile forensics, Case development
Building and leading cyber programs: SOPs, team structure, metric-driven reportingCase development and professional reporting, Intelligence foundations

This mapping is an editorial aid, not an official blueprint. It simply shows that the same competencies recur across several areas, which is why isolated memorization tends to be less effective than connected understanding.

Sequencing the Domains in Your Schedule

Because official weights are unverified, a sensible plan gives every domain attention and orders them by dependency. One approach, tied to how the material builds on itself:

Week 1

Analytic foundations

  • Intelligence foundations, then OSINT and social media intelligence
  • Why first: these supply the vocabulary and documentation habits used everywhere else
Week 2

Offense-specific investigations

  • Cybercrime investigations, counterintelligence, fraud and organized retail crime
  • Practice connecting separate incidents into one organized case
Week 3

Evidence handling

  • Electronic discovery, computer forensics and mobile forensics
  • Rehearse preservation, chain of custody and reproducibility until they feel automatic
Week 4

Field craft and reporting

  • Surveillance, informants, then case development and professional reporting
  • Finish with full-scope review so reporting ties the earlier domains together

Adjust the order to your background. A forensic examiner may compress Week 3 and spend longer on informants and counterintelligence, while a former detective may do the reverse. For a concise recall aid close to exam day, see the CECI Cheat Sheet 2026: One-Page Review of Must-Know Facts, and to pressure-test your recall under realistic conditions, try the CECI practice tests.

Eligibility and Cost Context

Mastering the domains is only part of the path. Candidates must also meet experience-based eligibility: a bachelor's degree or higher plus four years of relevant experience, an associate degree plus six years, or a high school diploma or equivalent plus seven years. The experience must involve criminal investigations or intelligence in investigations, law enforcement, criminal justice, military, or a similar field. Eligibility documentation and professional-conduct requirements apply. The full breakdown is in CECI Requirements 2026: Eligibility, Prerequisites & How to Qualify.

On cost, the standalone exam is USD 450. The separate self-paced program is USD 2,497 and contains 43 modules and 100 instructional hours, with 100 course CPE credits, a study manual, review quizzes, a one-year exam license and lifetime course access. It bundles six credentials, with CECI as the capstone. See CECI Certification Cost 2026: Complete Pricing Breakdown for a side-by-side comparison of the two routes.

Preparation is not a substitute: Studying these thirteen areas does not replace the official course, meeting the experience requirement, passing conduct review, or sitting the proctored assessment. Use this guide to organize your thinking, and rely on McAfee Institute's official pages for current policies.

Frequently Asked Questions

Are the 13 domains in this guide the official CECI exam sections?

No. They are editorial preparation categories built from technical areas named in the public CECI curriculum narrative. McAfee Institute has not published official topic weights, so no domain should be assumed to carry a particular percentage.

Does CECI cover six domains because it is the capstone of six credentials?

No. The program bundles six credentials with CECI as the capstone, but that does not establish six exam domains or identical examinations. The 43 course modules are also not weighted exam domains.

How many questions are on the CECI exam, and what format do they use?

The current question count, scored versus unscored allocation and exact item format are not publicly verified. The published facts are a three-hour online proctored session, one attempt and a 70% passing threshold, so avoid assuming any specific item count.

Which domain should I study first?

Start with intelligence foundations, OSINT and social media intelligence, because the documentation, attribution and corroboration habits they teach apply to every later domain. Finish with case development and reporting to tie everything together.

Where can I learn more about who hires for this credential and what it may be worth?

See CECI Jobs for the kinds of investigative roles where the credential is relevant, and Is the CECI Certification Worth It? Complete ROI Analysis 2026 for a qualitative look at value.

Ready to pass your CECI exam?

Put this into practice with free CECI questions across every exam domain.