CCTA logo
Focused certification exam prep
Start practice

CCTA Passing Score 2026: Exactly What You Need to Pass

TL;DR
  • CCTA requires a 70% passing minimum on a proctored final examination from McAfee Institute.
  • The shared issuer exam-license overview describes roughly 200 questions across three hours in true/false, multiple-choice, and scenario formats.
  • Your exam license is valid for one year - plan your study timeline around that window.
  • Coursework spans 17 content modules (02-18) covering OSINT, deep web research, mobile forensics, and more.

What the CCTA Passing Score Actually Is

If you're preparing for the Certified Counterintelligence Threat Analyst credential, the single number that matters most is 70%. McAfee Institute, the governing body and course publisher behind CCTA, sets a 70% passing minimum on the proctored final examination. That's the bar - not a curve, not a percentile rank against other candidates, just a fixed threshold you need to clear.

What that means practically: course access by itself doesn't confer certification. You can work through all 17 content modules, watch every video, and still not be "certified" until you sit the proctored final and score at or above that 70% line. This distinction trips up candidates who assume finishing the course is the finish line - it isn't. The course is preparation; the exam is the gate.

Quick Clarification: The 70% figure comes from McAfee Institute's published CCTA program description and the shared issuer exam-license overview. It applies to the proctored final exam specifically, not to quiz scores or module checkpoints inside the course.

Exam Format: Questions, Time, and Style

According to McAfee Institute's shared exam-license overview - the same assessment framework referenced across its credentialing programs - candidates can expect an exam built around:

  • Approximately 200 questions
  • A roughly three-hour time allotment
  • A mix of true/false, multiple-choice, and scenario-based question formats
  • A 70% passing minimum to earn certification

It's worth being precise here: these figures come from the shared issuer overview that applies broadly across McAfee Institute exam licenses, not from a CCTA-specific published blueprint. The exact CCTA question count and duration remain unverified at a program-specific level, so treat the ~200 question, three-hour framework as the best available reference point rather than a guaranteed exact spec. Don't confuse this with the 40-hour course figure, either - that number describes the instructional content you work through before the exam, not how long you'll have to sit the test itself.

The scenario-based questions deserve extra attention during prep. These aren't simple recall items - they typically describe a situation (a suspicious online contact, a questionable social media persona, a deceptive recruitment attempt) and ask you to apply a methodology rather than just define a term. That format rewards candidates who've practiced applying intelligence tradecraft, not just memorizing it.

Key Takeaway

Budget your exam-day time with scenario questions in mind - they take longer to read and reason through than a straightforward true/false item, so don't pace yourself as if every question is equally quick.

The 17 CCTA Content Areas You're Scored On

CCTA's published curriculum runs 19 modules total, but modules 01 (orientation) and 19 (the final board exam itself) sit outside the scored content. That leaves 17 core preparation topics, drawn from modules 02 through 18, that make up the body of knowledge the exam draws from:

Domain 1: The Foundation of OSINT

Core open-source intelligence principles and terminology that underpin everything else in the course.

Domain 2: The Intelligence Cycle

Planning, collection, processing, analysis, and dissemination as a repeatable analytical workflow.

Domain 3: Intelligence Collection Disciplines

How HUMINT, SIGINT, OSINT, and related disciplines differ and complement one another in a counterintelligence context.

Domain 4: Privacy and Data Protection

Legal and ethical boundaries investigators must respect while collecting information.

Domain 5: Setting Up a Lab & Virtual Machine

Building a safe, isolated research environment before conducting sensitive online investigations.

Domain 6 & 7: Social Media Investigations (Foundational and Advanced)

Tracing identities, networks, and activity patterns across mainstream platforms, including more advanced pivoting techniques.

Domain 8: Exploring the Deep Web

Understanding what sits beyond standard search indexing and how to navigate it responsibly.

Domain 9: Advanced Searching

Search operators and techniques for surfacing information standard queries miss.

Domain 10: Identification of Deception in Social Media

Spotting fake personas, bot activity, and manipulated narratives - a core counterintelligence skill.

Domain 11 & 12: Open Source Intelligence and OSINT Research

Applying structured research methods to real-world collection tasks and validating findings.

Domain 13: Mobile Forensics

Extracting and interpreting data from mobile devices as part of an investigation.

Domain 14 & 15: Chatting Applications and On-Line Dating Applications

Investigative approaches specific to messaging platforms and dating services, both common vectors for deception and recruitment attempts.

Domain 16: Applying Intelligence Methodologies

Synthesizing collection and analysis techniques into a coherent investigative approach.

Domain 17: Cyber Terrorism & Hackers

Threat actor behavior, motivations, and digital footprints relevant to counterintelligence analysis.

It's important to be precise about what these 17 areas represent: they're the course's unweighted preparation topics, not a verified official examination blueprint with published percentage weightings. No exhaustive scoring breakdown by domain has been published, so treat domain study time as a matter of candidate judgment, not official allocation. For a deeper walkthrough of each topic and how they connect, see our complete guide to all 17 CCTA content areas.

Which Domains Trip Up Candidates Most

Because the exam leans on scenario-based questions, the domains that tend to feel hardest aren't necessarily the most conceptually complex - they're the ones that require you to apply judgment under ambiguity. Based on the structure of the curriculum, a few areas are worth flagging:

  • Identification of Deception in Social Media (Domain 10) - requires pattern recognition skills that are hard to cram; they develop through repeated practice.
  • Applying Intelligence Methodologies (Domain 16) - a synthesis domain, meaning weak spots in earlier modules will surface here.
  • Mobile Forensics (Domain 13) - technical vocabulary and device-specific concepts that are easy to skim past but hard to recall under time pressure.

If you're trying to gauge overall exam difficulty before you commit study hours, our CCTA exam difficulty breakdown walks through what makes this certification more demanding than a typical multiple-choice test, and our pass rate analysis looks at what's actually known - and not known - about how candidates perform.

Practical Note: Scenario questions reward candidates who've seen varied examples of deception, not just definitions of it. Spend time reviewing real-world social media and messaging examples rather than only memorizing glossary terms.

A Domain-Based Prep Timeline

Generic study techniques - spaced repetition, timed practice blocks, teach-it-back review - work fine for CCTA, but they're only useful once mapped to the actual content. Here's one way to sequence an eight-week run-up to exam day, front-loading foundational domains and ending with synthesis and review:

Weeks 1-2

Foundations

  • Domain 1: The Foundation of OSINT
  • Domain 2: The Intelligence Cycle
  • Domain 3: Intelligence Collection Disciplines
Weeks 3-4

Technical Setup and Research Skills

  • Domain 4: Privacy and Data Protection
  • Domain 5: Setting Up a Lab & Virtual Machine
  • Domain 8: Exploring the Deep Web
  • Domain 9: Advanced Searching
Weeks 5-6

Platform-Specific Investigation

  • Domains 6-7: Social Media Investigations
  • Domain 10: Identification of Deception
  • Domains 14-15: Chatting and Dating Apps
  • Domain 13: Mobile Forensics
Weeks 7-8

Synthesis and Review

  • Domains 11-12: OSINT and OSINT Research
  • Domain 16: Applying Intelligence Methodologies
  • Domain 17: Cyber Terrorism & Hackers
  • Full scenario-question practice runs

For a more detailed first-attempt strategy - including how to pace review against the 40-hour course content - check our CCTA study guide for passing on your first attempt. And if you want every must-know fact condensed into a single reference, our one-page CCTA cheat sheet is built for final-week review.

The One-Year Exam License and What Happens If You Fall Short

McAfee Institute's CCTA program issues a one-year exam license alongside course enrollment. That window is your working deadline - it's the span during which you're expected to complete the coursework and sit the proctored final. Treat that year as a real constraint when planning study pace, not just a formality.

If you don't clear the 70% threshold on your first sitting, don't treat it as catastrophic - but also don't treat it casually. Go back to the domains where scenario questions felt hardest, particularly synthesis-heavy areas like Applying Intelligence Methodologies, and rebuild from there rather than re-reading everything linearly. Our guide to CCTA testing windows and scheduling covers how the licensing timeline interacts with when you can realistically sit for a retake.

Key Takeaway

Don't let the one-year license quietly expire while you "get around to" scheduling the final exam. Build your study timeline backward from that deadline, not forward from whenever you feel ready.

Cost, Access, and What "Passing" Doesn't Include

Passing the exam is the certification trigger, but it sits inside a broader set of program mechanics worth understanding before you enroll. Course access itself is a separate step from certification - you pay for and complete the 40-hour instructional program, then separately clear the proctored final at 70% or above to actually earn the credential. If you're budgeting for the full path, our CCTA certification cost breakdown lays out the pricing structure in detail, and our CCTA eligibility and prerequisites guide covers who qualifies to enroll in the first place.

It's also worth stepping back and asking whether the certification is worth pursuing for your specific career goals - our ROI analysis of the CCTA credential and CCTA salary guide look at how the certification tends to factor into counterintelligence, OSINT, and threat-analysis roles. If you're specifically scouting what kinds of positions value this credential, our CCTA jobs overview is a useful next read.

Once you're ready to test your readiness against realistic scenario-style questions rather than flashcards alone, our practice test platform is built specifically around that format. Working through full-length timed sets on the main practice site is one of the most direct ways to simulate the three-hour, scenario-heavy pressure you'll face on exam day.

ElementWhat's Confirmed
Passing minimum70%
Exam formatTrue/false, multiple-choice, scenario-based (shared issuer overview)
Approximate question count~200 (shared overview, not CCTA-specific verified)
Approximate duration~3 hours (shared overview, not CCTA-specific verified)
Exam license validityOne year
DeliveryProctored final examination
Scored content modules17 (modules 02-18 of 19)

Frequently Asked Questions

What score do I need to pass the CCTA exam?

You need to score at least 70% on the proctored final examination, per McAfee Institute's published CCTA program description. This is a fixed minimum, not a relative ranking against other candidates.

How many questions are on the CCTA exam and how long do I get?

McAfee Institute's shared exam-license overview describes approximately 200 questions across roughly three hours, mixing true/false, multiple-choice, and scenario formats. These figures come from the shared assessment framework rather than a CCTA-specific verified blueprint, so treat them as a close approximation.

Does completing the 40-hour course mean I'm certified?

No. Course access and completion are separate from certification. You still need to pass the proctored final exam at or above the 70% threshold to earn the CCTA credential.

Is the passing score the same across all 17 domains, or weighted by domain?

No official weighted breakdown by domain has been published. The 17 content areas are unweighted preparation topics rather than a verified official examination blueprint, so the 70% threshold applies to overall exam performance rather than domain-by-domain minimums.

What happens if my one-year exam license expires before I pass?

The one-year window is tied to your exam license, so it's important to plan your study schedule and testing date well within that period rather than waiting until the end. Check current program terms directly with McAfee Institute for specifics on renewal or extension options.

Ready to pass your CCTA exam?

Put this into practice with free CCTA questions across every exam domain.