CCTA logo
Focused certification exam prep
Start practice

CCTA Exam Domains 2026: Complete Guide to All 17 Content Areas

TL;DR
  • CCTA's curriculum spans 17 preparation modules (modules 2-18 of 19), bookended by an orientation module and a final board exam.
  • These are McAfee Institute course modules, not a verified official exam blueprint - treat weighting as editorial, not guaranteed.
  • The shared exam-license overview describes roughly 200 questions over three hours with a 70% passing minimum.
  • Domains cluster into OSINT fundamentals, legal/technical setup, social platform investigations, deep web and search, mobile forensics, and applied threat...

What the 17 CCTA Domains Actually Are

If you're preparing for the Certified Counterintelligence Threat Analyst credential from McAfee Institute, the first thing to understand is where the "17 domains" actually come from. They map to content modules 02 through 18 of the published 19-module CCTA curriculum. Module 01 ("Welcome to the CCTA!") is orientation, and module 19 is the CCTA Final Board Exam itself - neither is a content domain, which is why the working list lands at 17.

It's worth being precise here: these are instructional modules used to organize the 40 hours of coursework, not a publicly verified examination blueprint with disclosed weighting percentages. McAfee Institute has not published an official breakdown of how many questions come from each module. Any allocation you see in a practice bank - including the priority guidance later in this article - is editorial judgment, not a confirmed exam weighting. For a broader orientation to the credential before diving into domains, our What Is CCTA? overview and CCTA Certification page are good starting points.

Why This Matters for Study Planning: Because there's no confirmed per-domain weighting, the smartest approach is to treat every domain as "must know" rather than gambling on a handful of topics. Breadth beats guesswork with this exam.

Cluster 1: OSINT Foundations & the Intelligence Cycle

Five of the 17 domains form the conceptual backbone of the certification. They establish how intelligence analysts think before they ever open a browser tab.

Domain 1: The Foundation of OSINT

Covers what open source intelligence is, how it differs from classified collection, and why it matters to counterintelligence work specifically.

  • Definitions and scope of OSINT within the broader intelligence disciplines

Domain 2: The Intelligence Cycle

The planning, collection, processing, analysis, and dissemination loop that structures every professional intelligence product.

  • Know each stage and what feeds into the next

Domain 3: Intelligence Collection Disciplines

Differentiates HUMINT, SIGINT, OSINT, and related collection types so candidates can place OSINT in proper context.

  • Expect comparison-style questions between disciplines

Domains 11 and 12 - Open Source Intelligence and Open Source Intelligence Research - circle back to this cluster later in the curriculum, reinforcing the same foundational vocabulary with applied research techniques. Treat 1, 2, 3, 11, and 12 as a connected unit when you study rather than five isolated topics.

Cluster 2: Privacy, Legal Boundaries & Lab Setup

Before touching investigative tools, candidates need to understand the legal guardrails and the technical environment analysts work inside.

Domain 4: Privacy and Data Protection

Focuses on the legal and ethical limits around collecting personal data during an investigation - a frequent source of scenario-based exam questions.

  • Know the difference between publicly available data and protected personal information

Domain 5: Setting Up a Lab & Virtual Machine

Covers the practical setup of a sock-puppet-safe research environment, including virtual machines used to isolate investigative activity.

  • Understand why analysts isolate research machines from personal devices

These two domains are easy to underweight because they feel procedural, but they set up everything in the social media and deep web clusters that follow.

Cluster 3: Social Media Investigations & Deception Detection

This is the largest thematic cluster in the 17-domain curriculum, and it's where a lot of the practical investigative skill lives.

Domain 6: Social Media Investigations

Core techniques for researching individuals and organizations across mainstream social platforms.

Domain 7: Advanced Social Media Investigations

Builds on Domain 6 with deeper pivoting techniques, cross-platform correlation, and more complex target profiles.

Domain 10: Identification of Deception in Social Media

Teaches candidates to recognize fake accounts, manipulated content, and disinformation patterns - a direct counterintelligence skill.

  • Study the indicators of inauthentic or synthetic profiles

Because domains 6, 7, and 10 share a platform-based focus, it's efficient to study them back-to-back rather than spacing them out across your prep schedule.

Two domains address where information hides and how to retrieve it efficiently.

Domain 8: Exploring the Deep Web

Covers the layers of the internet beyond indexed search results and the access considerations unique to that environment.

Domain 9: Advanced Searching

Search operators, query construction, and techniques for surfacing information that basic searches miss.

These pair naturally with the lab setup content from Domain 5 - you'll want a safe, isolated environment configured before practicing deep web navigation techniques for the exam or in real investigative work.

Cluster 5: Mobile Forensics & Communication Platforms

Three domains shift focus to mobile devices and the apps people use to communicate and connect.

Domain 13: Mobile Forensics

Introduces how investigators extract and interpret data from mobile devices in an investigative context.

Domain 14: Chatting Applications

Covers investigative considerations specific to messaging and chat platforms used by subjects of interest.

Domain 15: On-Line Dating Applications

Addresses the unique investigative patterns and risks tied to dating platform research.

This cluster is heavily scenario-driven. Expect questions that describe a situation involving a messaging app or dating profile and ask what the correct investigative or ethical response would be.

Cluster 6: Applied Methodology & Cyber Threats

The curriculum closes its content portion by tying everything together and introducing the threat landscape.

Domain 16: Applying Intelligence Methodologies

Synthesizes the intelligence cycle and collection disciplines from earlier domains into applied analytical practice.

Domain 17: Cyber Terrorism & Hackers

Introduces the counterintelligence-relevant threat actors - cyber terrorists and hacking groups - that OSINT and social media investigations are frequently used to track.

ClusterDomains IncludedCore Focus
OSINT Foundations1, 2, 3, 11, 12Intelligence theory and research fundamentals
Privacy & Lab Setup4, 5Legal limits and safe research environments
Social Media & Deception6, 7, 10Platform investigations and spotting fakes
Deep Web & Search8, 9Access and query technique
Mobile & Communication Apps13, 14, 15Device and app-based investigation
Applied Methodology & Threats16, 17Synthesis and threat actor awareness

How the Domains Show Up on Exam Day

The CCTA uses a proctored final exam, and the shared McAfee Institute exam-license overview describes assessments across its credential line as roughly 200 questions, delivered over about three hours, in true/false, multiple-choice, and scenario-based formats, with a 70% passing minimum. Because this figure comes from a shared issuer overview rather than a CCTA-specific confirmation, treat the exact question count and timing as a close estimate rather than a guarantee. If you want a deeper breakdown of how format intersects with difficulty, see How Hard Is the CCTA Exam? Complete Difficulty Guide 2026 and the specifics on CCTA Passing Score 2026: Exactly What You Need to Pass.

Scenario-based questions are especially relevant here given the content: expect situational prompts built around social media profiles, chat conversations, or dating app interactions where you have to apply the correct investigative or privacy-conscious response rather than recall a definition. The 40-hour course length describes instructional time, not the exam duration - don't confuse the two when planning your schedule.

Note also that completing the course does not automatically certify you. You still need to pass the proctored final exam, and the program lists a one-year exam license, meaning your window to sit for that exam is time-bound. For logistics around that window, check CCTA Exam Dates 2026: Testing Windows, Deadlines & Scheduling.

Key Takeaway

Plan your study pace around the one-year exam license, not just the 40 hours of coursework - give yourself buffer time before that license expires.

Which Domains Deserve Extra Prep Time

Since there's no officially published weighting across the 17 domains, prioritization here is editorial judgment based on how foundational or scenario-heavy a domain is - not a confirmed scoring breakdown.

  • Foundational, hard to skip: Domain 1 (The Foundation of OSINT) and Domain 2 (The Intelligence Cycle) underpin nearly every later module.
  • Scenario-dense: Domains 6, 7, 10, 14, and 15 lend themselves naturally to the situational question formats described in the shared exam overview.
  • Technical/procedural: Domain 5 (lab/VM setup) and Domain 13 (mobile forensics) reward hands-on familiarity over memorization.
  • Synthesis: Domain 16 (Applying Intelligence Methodologies) ties earlier concepts together and is worth reviewing last, after the others are solid.

For a more complete walkthrough of how to sequence your overall preparation - not just domain order - see our CCTA Study Guide 2026: How to Pass on Your First Attempt.

A Domain-Ordered Study Timeline

A simple way to turn 17 domains into a manageable plan is to study them in clusters rather than in strict numerical order, since several domains reinforce each other.

Week 1

Foundations

  • Domains 1, 2, 3 - intelligence cycle and collection disciplines
  • Domain 4 - privacy and legal boundaries before touching any tools
Week 2

Setup & Research Skills

  • Domain 5 - lab and VM configuration
  • Domains 11 and 12 - OSINT and OSINT research applied
Week 3

Platforms & Deception

  • Domains 6, 7, 10 - social media investigation and spotting fakes
  • Domains 8, 9 - deep web and advanced search technique
Week 4

Mobile, Threats & Review

  • Domains 13, 14, 15 - mobile forensics and communication apps
  • Domains 16, 17 - applied methodology and cyber terrorism/hackers
  • Full review and timed practice against the proctored exam format

If you're using a timer-based method like Pomodoro blocks or spaced repetition flashcards, apply them inside each week above rather than as a generic study system - for example, spacing repetition specifically on Domain 1 and 2 vocabulary in week one tends to pay off later when Domain 16 asks you to apply those same concepts.

Who Actually Uses These 17 Domains on the Job

The domain list isn't academic - it mirrors the day-to-day work expected of counterintelligence and threat analysts in corporate security, government-adjacent contracting, fraud investigation, and insider threat units. Skills from the social media and deep web clusters map directly to due-diligence and threat-actor research, while the mobile forensics and communication app domains align with digital investigations roles. If you're evaluating whether this skill set fits your career path, our CCTA Jobs page and Is the CCTA Certification Worth It? Complete ROI Analysis 2026 article go deeper on where this credential is applied. You can also review baseline eligibility before enrolling through CCTA Requirements 2026: Eligibility, Prerequisites & How to Qualify.

Before committing time to all 17 domains, it also helps to understand the full cost picture - course access, exam license, and any retake considerations - covered in CCTA Certification Cost 2026: Complete Pricing Breakdown.

Once you've mapped out the domains conceptually, the most effective next step is testing yourself against realistic scenario-style questions on our CCTA practice test platform rather than re-reading notes passively. Running timed sets through the practice exam engine also helps you get comfortable with the roughly three-hour pacing described in the shared exam-license overview before test day arrives.

Frequently Asked Questions

Are all 17 CCTA domains equally weighted on the exam?

There's no officially published weighting for the Certified Counterintelligence Threat Analyst exam. The 17 domains come from instructional course modules, not a disclosed scoring breakdown, so it's safest to prepare for all of them thoroughly rather than assuming any domain is skippable.

Why are there 19 modules but only 17 domains?

The full McAfee Institute CCTA curriculum has 19 modules. Module 01 is an orientation ("Welcome to the CCTA!") and Module 19 is the Final Board Exam itself - neither functions as a content domain, leaving 17 substantive topic areas, numbered 02 through 18.

How many questions come from each domain?

That breakdown isn't publicly verified. The shared McAfee Institute exam-license overview describes roughly 200 questions across true/false, multiple-choice, and scenario formats in about three hours, with a 70% passing minimum - but it does not specify how those questions are distributed across the 17 domains.

Does finishing all 17 modules mean I'm certified?

No. Course access and module completion are preparation steps. Certification requires passing the proctored final exam, and the program lists a one-year exam license during which you must sit for and pass that exam.

Which domains should I study first if I'm short on time?

Start with Domain 1 (The Foundation of OSINT) and Domain 2 (The Intelligence Cycle), since later domains like Domain 16 (Applying Intelligence Methodologies) build directly on them. From there, move into the social media and deep web clusters, which carry the most scenario-style questions.

Ready to pass your CCTA exam?

Put this into practice with free CCTA questions across every exam domain.