- CCTA stands for Certified Counterintelligence Threat Analyst, published by McAfee Institute.
- The curriculum runs 19 modules; modules 02-18 cover 17 substantive preparation topics.
- The program describes a proctored final exam with a 70% passing minimum and a one-year exam license.
- The shared issuer overview cites roughly 200 questions across true/false, multiple-choice, and scenario formats over about three hours.
What Is the CCTA Certification?
The Certified Counterintelligence Threat Analyst (CCTA) is a credential built around open-source intelligence (OSINT), social media investigations, and counterintelligence tradecraft. It's designed for people who need to identify threats, trace digital footprints, and apply structured intelligence methodologies in real investigative work. If you're just starting to research the credential, our overview on What Is CCTA? and the related breakdown of What Does CCTA Stand For? are good entry points before you dive into the specifics below.
Unlike generic security-awareness certificates, CCTA is deliberately narrow in focus: it trains analysts to find, verify, and act on information gathered from open and semi-open sources rather than classified channels. That focus shows up clearly once you look at the module list that forms the backbone of the course.
Who Publishes the CCTA
CCTA is developed and published by McAfee Institute, which structures the certification as a self-paced course followed by a proctored final assessment. Course access on its own is a learning step, not a credential - candidates still need to pass the final board exam to earn the certification itself. For a deeper dive into eligibility mechanics, see CCTA Requirements 2026: Eligibility, Prerequisites & How to Qualify, and for cost specifics check CCTA Certification Cost 2026: Complete Pricing Breakdown.
Because McAfee Institute controls both the curriculum and the assessment, the module list below functions as the most reliable public signal of what the exam actually tests - even though it's published as preparation content rather than a formal weighted blueprint.
The 17 CCTA Content Modules
The full CCTA curriculum spans 19 modules. Module 01 ("Welcome to the CCTA!") is orientation, and Module 19 is the Final Board Exam itself. That leaves 17 substantive preparation topics in modules 02 through 18 - these are the areas candidates should actually study. They are not officially "weighted domains" in the sense of a published exam blueprint; think of them as the editorial map of what the course - and by extension the exam - covers. For a topic-by-topic breakdown, see CCTA Exam Domains 2026: Complete Guide to All 17 Content Areas.
Domain 1: The Foundation of OSINT
Establishes core OSINT vocabulary, legal boundaries, and the mindset shift from casual searching to structured intelligence gathering.
- Distinguishing OSINT from other collection disciplines
- Ethical and legal constraints on open-source collection
Domain 2: The Intelligence Cycle
Covers the planning-collection-processing-analysis-dissemination loop that underpins every investigative task in later modules.
- Where requirements originate and how they shape collection
- Feedback loops between analysis and new collection requirements
Domain 3: Intelligence Collection Disciplines
Contrasts HUMINT, SIGINT, OSINT, and related disciplines so candidates know when each is appropriate and how they complement each other.
- Strengths and limitations of each collection type
- Fusion of multiple disciplines in a single case
Domain 4: Privacy and Data Protection
Addresses the legal and ethical guardrails analysts must respect while collecting personal data from open sources.
- Data handling and retention concerns
- Balancing investigative need against privacy exposure
Domain 5: Setting Up a Lab & Virtual Machine
Hands-on technical setup for conducting investigations safely, isolated from an analyst's personal digital footprint.
- Sock-puppet and attribution-safe browsing environments
- Virtual machine configuration basics
Domain 6 & 7: Social Media Investigations (Core and Advanced)
These two modules build from basic platform searching to advanced techniques for tracing accounts, networks, and activity across platforms.
- Cross-platform username and image correlation
- Mapping relationships and networks from public profiles
Domain 8: Exploring the Deep Web
Introduces the layers of the web beyond standard search engines and how analysts navigate them responsibly.
- Distinguishing deep web from dark web
- Access tools and associated risks
Domain 9: Advanced Searching
Search-operator techniques and query construction for pulling precise results out of large, noisy data sets.
- Boolean and advanced operator syntax
- Search engine-specific quirks and limitations
Domain 10: Identification of Deception in Social Media
Teaches recognition of fake accounts, manipulated media, and disinformation patterns in investigative contexts.
- Indicators of bot and sock-puppet accounts
- Verifying authenticity of shared content
Domain 11 & 12: Open Source Intelligence and OSINT Research
Builds on the foundation module with applied research methodology for building full intelligence products from open sources.
- Structured research workflows
- Source reliability and corroboration
Domain 13: Mobile Forensics
Covers how mobile device data and metadata factor into counterintelligence investigations.
- Metadata extraction basics
- Mobile app artifacts relevant to investigations
Domain 14 & 15: Chatting Applications and Online Dating Applications
Focuses on investigative techniques specific to messaging platforms and dating apps, common vectors in counterintelligence and fraud cases.
- Platform-specific investigative approaches
- Identifying catfishing and romance-scam patterns
Domain 16: Applying Intelligence Methodologies
Ties earlier modules together into structured analytic techniques for producing actionable assessments.
- Structured analytic techniques application
- Avoiding cognitive bias in analysis
Domain 17: Cyber Terrorism & Hackers
Closes the curriculum with threat actor profiling relevant to counterintelligence work against hostile cyber actors.
- Motivations and tactics of threat actor groups
- Recognizing indicators of coordinated cyber threats
Key Takeaway
Treat these 17 modules as your real study checklist rather than searching for an official percentage weighting - none has been published. Our CCTA Cheat Sheet 2026: One-Page Review of Must-Know Facts condenses them into a quick-reference format.
Exam Format and Passing Minimum
CCTA culminates in a proctored final board exam. According to the program's published materials, candidates need a 70% passing minimum to earn certification, and the exam license is valid for one year from issuance. The shared issuer exam-license overview - which applies across multiple McAfee Institute credentials, not just CCTA specifically - describes an assessment of approximately 200 questions, delivered over roughly three hours, using true/false, multiple-choice, and scenario-based question formats.
It's worth being precise here: that 200-question, three-hour figure comes from the shared assessment overview rather than a CCTA-specific confirmation, so treat it as a strong planning estimate rather than a guaranteed exact count. The exact CCTA-specific question count and duration remain unverified publicly. For a closer look at what that passing threshold means in practice, read CCTA Passing Score 2026: Exactly What You Need to Pass.
Scenario-based questions deserve extra attention during prep. Rather than asking you to define a term, they place you inside a short investigative situation - say, verifying a suspicious social media profile or deciding which collection discipline fits a given requirement - and ask what you'd do next. That format rewards candidates who have practiced applying the modules above, not just memorized them. If you want a sense of how tough that application-based testing feels in practice, see How Hard Is the CCTA Exam? Complete Difficulty Guide 2026.
Who Hires CCTA Holders
CCTA sits at the intersection of counterintelligence, fraud investigation, and open-source research, which makes it relevant to a specific slice of the job market rather than a broad IT-security audience. Employers and roles that value OSINT-and-counterintelligence skill sets typically include:
- Corporate security and insider-threat teams running background and due-diligence investigations
- Fraud and trust-and-safety units at platforms dealing with fake accounts and social engineering
- Investigative units that rely on social media and deep-web research to build case files
- Government-adjacent and contractor roles where OSINT supplements classified collection
- Private investigation and risk-consulting firms handling digital footprint and background work
If you're evaluating whether this credential lines up with a role you're targeting, our guides on CCTA Jobs and CCTA Salary Guide 2026: Complete Earnings Analysis go further into real-world positioning, and Is the CCTA Certification Worth It? Complete ROI Analysis 2026 weighs the credential against the time investment required to earn it.
Mapping a Study Plan to the Modules
Generic study tricks matter less here than sequencing the right modules at the right time. Because Domains 1-3 establish vocabulary and methodology that every later module assumes you know, they should come first regardless of which technique - flashcards, spaced repetition, timed drills - you use to retain them.
Foundational Modules (1-4)
- Lock in OSINT fundamentals and the intelligence cycle before moving to hands-on work
- Review privacy and data protection boundaries early - they govern every later technique
Technical and Social Media Modules (5-10)
- Practice lab/VM setup hands-on rather than just reading about it
- Run real (ethical) cross-platform search exercises for Domains 6, 7, and 10
Research and Device Modules (11-15)
- Build a few practice OSINT research products end-to-end
- Study mobile forensics and chat/dating-app investigation patterns together - they share tooling logic
Synthesis and Review (16-17 plus full review)
- Apply structured analytic techniques from Domain 16 to review scenarios
- Finish with Domain 17 threat-actor profiling, then run full-module review and timed scenario practice
For a complete week-by-week plan with more detail on pacing and review cycles, see CCTA Study Guide 2026: How to Pass on Your First Attempt. And once you've worked through the modules, running timed scenario questions on our CCTA practice test platform is the most direct way to simulate the true/false, multiple-choice, and scenario mix described in the exam-license overview.
CCTA vs. General Intelligence Training
A useful way to understand CCTA's niche is to compare its module emphasis against generic intelligence-analyst training that doesn't focus specifically on OSINT and digital investigation.
| Attribute | CCTA (McAfee Institute) | Generic Intelligence/Analyst Training |
|---|---|---|
| Core focus | OSINT, social media, deep web, counterintelligence tradecraft | Broad analytic theory, often without platform-specific technique |
| Hands-on components | Lab/VM setup, mobile forensics, chat/dating app investigations | Varies; often classroom-only |
| Assessment style | Proctored exam, true/false, multiple-choice, and scenario questions | Varies widely by provider |
| Passing standard | 70% minimum, one-year exam license | Varies widely by provider |
| Best fit for | Investigators, fraud/trust-and-safety analysts, OSINT researchers | General analytic career paths |
This narrower, more technique-driven focus is exactly why candidates researching the credential often search broader terms like CCTA Meaning, What Is A CCTA?, or What Does CCTA Mean? before committing - the acronym overlap with unrelated certifications makes it easy to find mismatched information elsewhere. Always confirm you're reading about McAfee Institute's Certified Counterintelligence Threat Analyst specifically.
Frequently Asked Questions
The published curriculum has 19 modules total. Module 01 is an orientation welcome module and Module 19 is the Final Board Exam, leaving 17 substantive content modules (02-18) that form the real study scope.
No. Course access gives you the instructional content, but certification requires passing the separate proctored final board exam with the required 70% minimum score.
An exact CCTA-specific duration hasn't been independently verified. The shared issuer exam-license overview, which covers multiple McAfee Institute credentials, describes roughly three hours and about 200 questions as a general reference point.
Based on the shared assessment overview, expect a mix of true/false, multiple-choice, and scenario-based questions that test applied judgment, not just recall of terminology.
The program lists a one-year exam license. Check current renewal or revalidation details directly with McAfee Institute, since specific renewal mechanics can change.