- CCTA is issued by McAfee Institute and covers 17 unweighted preparation modules (02-18 of 19 total).
- The shared issuer exam-license overview describes roughly 200 questions, three hours, and a 70% passing minimum.
- Format mixes true/false, multiple-choice, and scenario-based questions - not pure recall.
- The 40-hour figure refers to instruction time, not the exam duration itself.
What the CCTA Actually Tests
The Certified Counterintelligence Threat Analyst (CCTA) credential, published by McAfee Institute, is built around open-source intelligence (OSINT) tradecraft, digital investigation technique, and counterintelligence analysis. It is not a generic "cybersecurity" cert and it is not a project-management or infrastructure-focused credential - despite the acronym overlapping with other programs in other industries. On this site, every reference to "CCTA" means this specific analyst-track certification and nothing else.
This cheat sheet condenses the facts a candidate actually needs on exam week: the module list, the scoring threshold, the license term, and the logistics around the proctored test. If you want the long-form walkthrough of any single topic, pair this page with the full CCTA Study Guide 2026 or the domain-by-domain breakdown in the CCTA Exam Domains 2026 guide.
Core Facts Snapshot
Before diving into domains, lock in these baseline facts. They come directly from the CCTA program page and the shared McAfee Institute exam-license overview - not from any other certification that happens to share the same letters.
| Item | Detail |
|---|---|
| Certifying body | McAfee Institute |
| Credential name | Certified Counterintelligence Threat Analyst (CCTA) |
| Preparation modules | 17 (modules 02-18 of a 19-module curriculum) |
| Passing minimum | 70% |
| Exam license term | One year |
| Instruction length | 40 hours (course instruction, not exam duration) |
| Shared assessment overview | ~200 questions, approx. 3 hours, true/false + multiple-choice + scenario formats |
Note the wording carefully: the ~200-question, three-hour figure comes from the shared issuer exam-license overview that applies across McAfee Institute credentials. It is not confirmed as a CCTA-exclusive guarantee, so treat it as a strong planning estimate rather than a contractual spec. For a deeper dive into exactly what "passing" requires, see the CCTA Passing Score 2026 guide.
17-Domain Rundown
These are the 17 CCTA content modules in order. Treat the "Domain" label as a count of preparation topics, not a verified weighted exam blueprint - McAfee Institute does not publish a scored percentage breakdown per module.
Domain 1: The Foundation of OSINT
Establishes core open-source intelligence vocabulary and the ethical/legal boundaries analysts operate within.
- Know the difference between OSINT, SOCMINT, and classified collection
Domain 2: The Intelligence Cycle
Covers the planning, collection, processing, analysis, and dissemination stages analysts cycle through.
- Be able to place any investigative action into the correct cycle stage
Domain 3: Intelligence Collection Disciplines
Distinguishes HUMINT, SIGINT, GEOINT, and related disciplines and how they complement OSINT work.
- Memorize which discipline applies to which collection scenario
Domain 4: Privacy and Data Protection
Addresses legal and ethical handling of personal data gathered during investigations.
- Understand data-minimization and retention concepts as applied to analyst work
Domain 5: Setting Up a Lab & Virtual Machine
Practical setup of isolated research environments to protect investigator identity and systems.
- Know why analysts never investigate from their live, identifiable machine
Domain 6: Social Media Investigations
Foundational techniques for tracing identity and activity across mainstream platforms.
- Recognize platform-specific metadata and search operators
Domain 7: Advanced Social Media Investigations
Builds on Domain 6 with cross-platform correlation and persona-tracking techniques.
- Practice linking multiple accounts to a single real-world subject
Domain 8: Exploring the Deep Web
Differentiates deep web from dark web and introduces safe access methods for research.
- Know the distinction between "deep" and "dark" terminology - a frequent exam trap
Domain 9: Advanced Searching
Boolean logic, search operators, and query refinement for efficient OSINT research.
- Drill advanced search operators until they're automatic
Domain 10: Identification of Deception in Social Media
Pattern-recognition for fake profiles, bots, and manipulated content.
- Study common bot and sockpuppet indicators
Domain 11: Open Source Intelligence
Expands core OSINT theory into applied research methodology across source types.
- Review source credibility and corroboration standards
Domain 12: Open Source Intelligence Research
Hands-on research workflows: documenting findings and preserving chain of custody for evidence.
- Practice structuring an investigative research report
Domain 13: Mobile Forensics
Introduces how mobile device data and artifacts factor into counterintelligence investigations.
- Know basic mobile artifact categories analysts may encounter
Domain 14: Chatting Applications
Covers investigative considerations specific to messaging platforms.
- Understand metadata differences across chat app types
Domain 15: On-Line Dating Applications
Focuses on investigative and deception-detection techniques unique to dating platforms.
- Study common catfishing and romance-scam indicators
Domain 16: Applying Intelligence Methodologies
Synthesizes prior modules into structured analytical methodology for real cases.
- Practice applying the intelligence cycle to a full mock scenario
Domain 17: Cyber Terrorism & Hackers
Covers threat actor profiling, motivations, and counterintelligence response concepts.
- Review hacker typologies and extremist online behavior patterns
For a longer breakdown of each module with example question angles, read the complete CCTA Exam Domains 2026 guide. If you're still assessing difficulty before committing study hours, the How Hard Is the CCTA Exam guide is a useful companion read.
Exam Logistics & Format
The CCTA final exam is proctored. Course access through the McAfee Institute platform does not by itself confer certification - you must sit for and pass the final board exam. Based on the shared issuer exam-license overview that governs CCTA and sibling credentials, expect:
- Approximately 200 questions
- A roughly three-hour time allotment
- A mix of true/false, multiple-choice, and scenario-based question formats
- A 70% passing minimum
Because these figures come from a shared overview rather than a CCTA-exclusive published spec, treat the exact count and timing as a planning estimate, not a contractual guarantee. The 40-hour figure you'll see associated with the course describes instructional content length - it has nothing to do with how long you get to sit the exam itself.
Scoring & License Terms
Passing requires meeting the 70% minimum threshold described in the CCTA program materials. Once earned, the certification is tied to a one-year exam license - plan ahead for renewal rather than treating certification as a permanent, static credential. For the exact mechanics behind the passing threshold and how it's calculated across question formats, see the CCTA Passing Score 2026 breakdown.
If you're budgeting for the exam, registration, and potential retake costs, review the CCTA Certification Cost 2026 pricing breakdown before you schedule. And if you need to know when exam windows open or how scheduling deadlines work, check the CCTA Exam Dates 2026 guide.
Key Takeaway
Treat the one-year exam license as a planning deadline: schedule your proctored exam attempt with enough buffer to retake it if needed, rather than waiting until the license window is nearly closed.
A One-Week Sprint Plan
If you've already studied the full curriculum and just need a condensed final-week review, structure your days by module cluster rather than generic review techniques. This is the only methodology section in this cheat sheet - everything here is tied directly to CCTA's own module sequence.
Foundations (Domains 1-5)
- Re-read OSINT definitions, the intelligence cycle stages, collection disciplines, privacy rules, and lab setup steps
Social & Deep Web (Domains 6-10)
- Drill social media investigation techniques, deep web navigation, advanced search operators, and deception indicators
Research & Forensics (Domains 11-15)
- Review OSINT research workflows, mobile forensics basics, chat app metadata, and dating app deception patterns
Synthesis & Scenario Practice (Domains 16-17)
- Work through full mock scenarios applying intelligence methodology and threat-actor profiling; take a timed practice run
For a fuller multi-week version of this plan built around a first-attempt pass strategy, see the complete CCTA Study Guide 2026. You can also run timed scenario drills using the practice platform on the main CCTA practice test site to simulate the real question mix before exam day.
Who Hires CCTA Holders
CCTA's curriculum - OSINT, social media investigation, mobile forensics, and counterintelligence methodology - maps to roles in corporate security, insider threat analysis, fraud investigation, law enforcement support, and private intelligence/investigative consulting. The emphasis on deep web navigation (Domain 8), deception identification (Domain 10), and cyber threat-actor profiling (Domain 17) also appeals to employers running digital risk and threat intelligence functions.
If you're weighing whether the credential translates into career movement, read the CCTA Salary Guide 2026 and the broader Is the CCTA Certification Worth It ROI analysis. For open roles and how employers list the credential in postings, see CCTA Jobs.
Common Mix-Ups to Avoid
Because "CCTA" is used by several unrelated credentials across different industries, candidates researching online sometimes land on information that has nothing to do with this program. When you're fact-checking anything about this certification, confirm it ties back to McAfee Institute's Certified Counterintelligence Threat Analyst specifically - not a similarly-named credential in IT service management or another field. If you're unsure what the letters stand for in this context, the quick-reference pages below clear it up fast:
- What Is CCTA?
- CCTA Meaning
- What Does CCTA Stand For?
- What Is A CCTA?
- What Does CCTA Mean?
- What Is CCTA Certification?
For a general orientation to the credential and its purpose, start with CCTA Certification, and for formal training pathway details, see CCTA Training. If you'd rather jump straight into practice questions modeled on the module list above, visit the practice test homepage to get started.
Frequently Asked Questions
The published curriculum lists 17 content modules, spanning module 02 through module 18 of a 19-module course. Modules 01 and 19 are orientation and the final board exam, respectively, not instructional domains.
The shared McAfee Institute exam-license overview describes approximately 200 questions across true/false, multiple-choice, and scenario formats. This figure is shared across credentials and not confirmed as CCTA-exclusive, so use it as a planning estimate.
The program lists a 70% passing minimum on the proctored final exam. See the CCTA Passing Score guide for more detail.
No. Course access alone does not confer certification - candidates must pass the separate proctored final board exam to earn the credential.
The program lists a one-year exam license. Confirm current renewal mechanics directly with McAfee Institute before your license period ends.