CCTA logo
Focused certification exam prep
Start practice

CCTA Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • CCTA is issued by McAfee Institute and covers 17 unweighted preparation modules (02-18 of 19 total).
  • The shared issuer exam-license overview describes roughly 200 questions, three hours, and a 70% passing minimum.
  • Format mixes true/false, multiple-choice, and scenario-based questions - not pure recall.
  • The 40-hour figure refers to instruction time, not the exam duration itself.

What the CCTA Actually Tests

The Certified Counterintelligence Threat Analyst (CCTA) credential, published by McAfee Institute, is built around open-source intelligence (OSINT) tradecraft, digital investigation technique, and counterintelligence analysis. It is not a generic "cybersecurity" cert and it is not a project-management or infrastructure-focused credential - despite the acronym overlapping with other programs in other industries. On this site, every reference to "CCTA" means this specific analyst-track certification and nothing else.

This cheat sheet condenses the facts a candidate actually needs on exam week: the module list, the scoring threshold, the license term, and the logistics around the proctored test. If you want the long-form walkthrough of any single topic, pair this page with the full CCTA Study Guide 2026 or the domain-by-domain breakdown in the CCTA Exam Domains 2026 guide.

Scope Note: This cheat sheet reflects content modules 02 through 18 of the published 19-module CCTA curriculum. Module 01 ("Welcome to the CCTA!") is orientation and Module 19 is the Final Board Exam - both are excluded here because they are not instructional content modules.

Core Facts Snapshot

Before diving into domains, lock in these baseline facts. They come directly from the CCTA program page and the shared McAfee Institute exam-license overview - not from any other certification that happens to share the same letters.

ItemDetail
Certifying bodyMcAfee Institute
Credential nameCertified Counterintelligence Threat Analyst (CCTA)
Preparation modules17 (modules 02-18 of a 19-module curriculum)
Passing minimum70%
Exam license termOne year
Instruction length40 hours (course instruction, not exam duration)
Shared assessment overview~200 questions, approx. 3 hours, true/false + multiple-choice + scenario formats

Note the wording carefully: the ~200-question, three-hour figure comes from the shared issuer exam-license overview that applies across McAfee Institute credentials. It is not confirmed as a CCTA-exclusive guarantee, so treat it as a strong planning estimate rather than a contractual spec. For a deeper dive into exactly what "passing" requires, see the CCTA Passing Score 2026 guide.

17-Domain Rundown

These are the 17 CCTA content modules in order. Treat the "Domain" label as a count of preparation topics, not a verified weighted exam blueprint - McAfee Institute does not publish a scored percentage breakdown per module.

Domain 1: The Foundation of OSINT

Establishes core open-source intelligence vocabulary and the ethical/legal boundaries analysts operate within.

  • Know the difference between OSINT, SOCMINT, and classified collection

Domain 2: The Intelligence Cycle

Covers the planning, collection, processing, analysis, and dissemination stages analysts cycle through.

  • Be able to place any investigative action into the correct cycle stage

Domain 3: Intelligence Collection Disciplines

Distinguishes HUMINT, SIGINT, GEOINT, and related disciplines and how they complement OSINT work.

  • Memorize which discipline applies to which collection scenario

Domain 4: Privacy and Data Protection

Addresses legal and ethical handling of personal data gathered during investigations.

  • Understand data-minimization and retention concepts as applied to analyst work

Domain 5: Setting Up a Lab & Virtual Machine

Practical setup of isolated research environments to protect investigator identity and systems.

  • Know why analysts never investigate from their live, identifiable machine

Domain 6: Social Media Investigations

Foundational techniques for tracing identity and activity across mainstream platforms.

  • Recognize platform-specific metadata and search operators

Domain 7: Advanced Social Media Investigations

Builds on Domain 6 with cross-platform correlation and persona-tracking techniques.

  • Practice linking multiple accounts to a single real-world subject

Domain 8: Exploring the Deep Web

Differentiates deep web from dark web and introduces safe access methods for research.

  • Know the distinction between "deep" and "dark" terminology - a frequent exam trap

Domain 9: Advanced Searching

Boolean logic, search operators, and query refinement for efficient OSINT research.

  • Drill advanced search operators until they're automatic

Domain 10: Identification of Deception in Social Media

Pattern-recognition for fake profiles, bots, and manipulated content.

  • Study common bot and sockpuppet indicators

Domain 11: Open Source Intelligence

Expands core OSINT theory into applied research methodology across source types.

  • Review source credibility and corroboration standards

Domain 12: Open Source Intelligence Research

Hands-on research workflows: documenting findings and preserving chain of custody for evidence.

  • Practice structuring an investigative research report

Domain 13: Mobile Forensics

Introduces how mobile device data and artifacts factor into counterintelligence investigations.

  • Know basic mobile artifact categories analysts may encounter

Domain 14: Chatting Applications

Covers investigative considerations specific to messaging platforms.

  • Understand metadata differences across chat app types

Domain 15: On-Line Dating Applications

Focuses on investigative and deception-detection techniques unique to dating platforms.

  • Study common catfishing and romance-scam indicators

Domain 16: Applying Intelligence Methodologies

Synthesizes prior modules into structured analytical methodology for real cases.

  • Practice applying the intelligence cycle to a full mock scenario

Domain 17: Cyber Terrorism & Hackers

Covers threat actor profiling, motivations, and counterintelligence response concepts.

  • Review hacker typologies and extremist online behavior patterns

For a longer breakdown of each module with example question angles, read the complete CCTA Exam Domains 2026 guide. If you're still assessing difficulty before committing study hours, the How Hard Is the CCTA Exam guide is a useful companion read.

Exam Logistics & Format

The CCTA final exam is proctored. Course access through the McAfee Institute platform does not by itself confer certification - you must sit for and pass the final board exam. Based on the shared issuer exam-license overview that governs CCTA and sibling credentials, expect:

  • Approximately 200 questions
  • A roughly three-hour time allotment
  • A mix of true/false, multiple-choice, and scenario-based question formats
  • A 70% passing minimum

Because these figures come from a shared overview rather than a CCTA-exclusive published spec, treat the exact count and timing as a planning estimate, not a contractual guarantee. The 40-hour figure you'll see associated with the course describes instructional content length - it has nothing to do with how long you get to sit the exam itself.

Format Reminder: Scenario-based questions mean you'll be asked to apply a domain concept to a short investigative situation, not just recall a definition. Expect this especially around Domains 10, 15, and 16.

Scoring & License Terms

Passing requires meeting the 70% minimum threshold described in the CCTA program materials. Once earned, the certification is tied to a one-year exam license - plan ahead for renewal rather than treating certification as a permanent, static credential. For the exact mechanics behind the passing threshold and how it's calculated across question formats, see the CCTA Passing Score 2026 breakdown.

If you're budgeting for the exam, registration, and potential retake costs, review the CCTA Certification Cost 2026 pricing breakdown before you schedule. And if you need to know when exam windows open or how scheduling deadlines work, check the CCTA Exam Dates 2026 guide.

Key Takeaway

Treat the one-year exam license as a planning deadline: schedule your proctored exam attempt with enough buffer to retake it if needed, rather than waiting until the license window is nearly closed.

A One-Week Sprint Plan

If you've already studied the full curriculum and just need a condensed final-week review, structure your days by module cluster rather than generic review techniques. This is the only methodology section in this cheat sheet - everything here is tied directly to CCTA's own module sequence.

Day 1-2

Foundations (Domains 1-5)

  • Re-read OSINT definitions, the intelligence cycle stages, collection disciplines, privacy rules, and lab setup steps
Day 3-4

Social & Deep Web (Domains 6-10)

  • Drill social media investigation techniques, deep web navigation, advanced search operators, and deception indicators
Day 5

Research & Forensics (Domains 11-15)

  • Review OSINT research workflows, mobile forensics basics, chat app metadata, and dating app deception patterns
Day 6-7

Synthesis & Scenario Practice (Domains 16-17)

  • Work through full mock scenarios applying intelligence methodology and threat-actor profiling; take a timed practice run

For a fuller multi-week version of this plan built around a first-attempt pass strategy, see the complete CCTA Study Guide 2026. You can also run timed scenario drills using the practice platform on the main CCTA practice test site to simulate the real question mix before exam day.

Who Hires CCTA Holders

CCTA's curriculum - OSINT, social media investigation, mobile forensics, and counterintelligence methodology - maps to roles in corporate security, insider threat analysis, fraud investigation, law enforcement support, and private intelligence/investigative consulting. The emphasis on deep web navigation (Domain 8), deception identification (Domain 10), and cyber threat-actor profiling (Domain 17) also appeals to employers running digital risk and threat intelligence functions.

If you're weighing whether the credential translates into career movement, read the CCTA Salary Guide 2026 and the broader Is the CCTA Certification Worth It ROI analysis. For open roles and how employers list the credential in postings, see CCTA Jobs.

Eligibility Check: Before you register, confirm you meet the program's prerequisites. Details are covered in the CCTA Requirements 2026 guide, which lays out eligibility and qualification steps separately from the study content itself.

Common Mix-Ups to Avoid

Because "CCTA" is used by several unrelated credentials across different industries, candidates researching online sometimes land on information that has nothing to do with this program. When you're fact-checking anything about this certification, confirm it ties back to McAfee Institute's Certified Counterintelligence Threat Analyst specifically - not a similarly-named credential in IT service management or another field. If you're unsure what the letters stand for in this context, the quick-reference pages below clear it up fast:

For a general orientation to the credential and its purpose, start with CCTA Certification, and for formal training pathway details, see CCTA Training. If you'd rather jump straight into practice questions modeled on the module list above, visit the practice test homepage to get started.

Frequently Asked Questions

How many domains does the CCTA cover?

The published curriculum lists 17 content modules, spanning module 02 through module 18 of a 19-module course. Modules 01 and 19 are orientation and the final board exam, respectively, not instructional domains.

How many questions are on the CCTA exam?

The shared McAfee Institute exam-license overview describes approximately 200 questions across true/false, multiple-choice, and scenario formats. This figure is shared across credentials and not confirmed as CCTA-exclusive, so use it as a planning estimate.

What score do I need to pass the CCTA?

The program lists a 70% passing minimum on the proctored final exam. See the CCTA Passing Score guide for more detail.

Does finishing the course automatically certify me?

No. Course access alone does not confer certification - candidates must pass the separate proctored final board exam to earn the credential.

How long is the CCTA certification valid?

The program lists a one-year exam license. Confirm current renewal mechanics directly with McAfee Institute before your license period ends.

Ready to pass your CCTA exam?

Put this into practice with free CCTA questions across every exam domain.