- How to Read the Five Content Areas
- Exam Format and Logistics That Shape Your Prep
- Domain 1: Open Source Intelligence
- Domain 2: Social Media Intelligence
- Domain 3: Cyber Investigations
- Domain 4: Intelligence Collection
- Domain 5: Legal Fundamentals
- Sequencing the Domains Across Your Prep
- Eligibility, Fees, and Validity: What to Confirm
- Where the Credential Fits Professionally
- Frequently Asked Questions
- The five preparation areas are Open Source Intelligence, Social Media Intelligence, Cyber Investigations, Intelligence Collection, and Legal Fundamentals.
- These areas are unweighted preparation topics, not a verified official blueprint, so study all five rather than gambling on one.
- The exam is a three-hour, online proctored test with a stated 70% passing threshold.
- The exam-only listing is $450 USD for one attempt and includes a one-year exam license.
How to Read the Five Content Areas
The Certified in Open Source Intelligence credential is issued and administered by McAfee Institute, which styles it C|OSINT. This site uses C/OSINT as its abbreviation, and everything below refers only to that McAfee Institute credential. Other certifications share a similar acronym, so be careful when you search for study material: a resource that describes different fee schedules, domain weights, or pass rates is almost certainly about a different program.
The issuer's exam product lists five preparation areas in its curriculum overview: Open Source Intelligence, Social Media Intelligence, Cyber Investigations, Intelligence Collection, and Legal Fundamentals. It is worth being precise about what that list is. These are the topics the issuer names for preparation. They are not published as weighted exam domains with percentage allocations, and the detailed blueprint was not available in the public listing. The paid course manual is where the full detail lives.
Exam Format and Logistics That Shape Your Prep
Knowing the delivery format changes how you study. The exam-only listing describes a three-hour online proctored examination with a stated passing threshold of 70%. The institute-wide examination page describes closed-book, on-demand AI remote proctoring, with true/false, multiple-choice, and scenario-based question formats. That page gives only an approximate question count for the institute's exams generally, so do not assume a specific item total for this credential.
| Item | What the issuer materials state |
|---|---|
| Administrator | McAfee Institute |
| Exam-only price | $450 USD, one attempt |
| Exam license | One year |
| Duration | Three hours, online proctored |
| Passing threshold | 70% |
| Question styles | True/false, multiple-choice, scenario-based (institute-wide page) |
| Training product | 55 instructional hours, 50 CPE credits |
| Training price at verification | $2,497 standard tuition; $997 scholarship price |
The scenario-based format is the part that most affects preparation. Scenario questions reward candidates who can apply a concept to a fact pattern, such as deciding which collection method fits a situation or whether a particular action raises a legal concern. Memorizing definitions alone will not carry you through those items. For the full numbers behind the threshold, our article on the C/OSINT passing score breaks down what 70% means in practice, and the C/OSINT certification cost guide covers the pricing in more detail.
Domain 1: Open Source Intelligence
The first area is the discipline itself. Candidates should be fluent in what open source intelligence is, where it sits within the broader intelligence picture, and how an open source investigation is structured from question to finished product. This is the conceptual backbone for everything else on the exam.
Open Source Intelligence
Expect to demonstrate that you understand the purpose, process, and limits of working with publicly available information.
- The distinction between information, data, and finished intelligence
- How an investigative question is framed before any searching begins
- Evaluating source reliability and information credibility
- Recognizing bias, deception, and disinformation in public sources
- Documenting methods so findings can be reproduced and defended
Source evaluation deserves extra attention because scenario questions often hinge on it. A candidate who can articulate why a single uncorroborated post is weak evidence, and how corroboration across independent sources changes confidence, will handle those questions far better than one who only knows search syntax. If you are new to the field, our explainer on what C/OSINT is is a useful orientation before you dive into the technical material.
Domain 2: Social Media Intelligence
Social media intelligence applies open source methods to platform-based content. The exam topic here concerns how people, networks, and events can be understood through publicly visible social activity, and how an investigator should handle that material responsibly.
Social Media Intelligence
Focus on the investigative value of social content and the care required to use it properly.
- Identifying and attributing accounts, and the limits of attribution
- Mapping relationships, connections, and communities
- Reading timestamps, metadata, and contextual clues in posts
- Preserving social content before it is edited or deleted
- Understanding platform terms, privacy settings, and what counts as public
One recurring theme in this area is preservation. Social content is volatile, and a strong investigator captures it in a way that retains context and supports later review. Another is restraint: knowing the difference between observing what is genuinely public and crossing into conduct that raises legal or ethical problems. That boundary connects directly to the fifth domain, so study the two together.
Domain 3: Cyber Investigations
Cyber investigations covers the technical and infrastructure-facing side of open source work. Candidates should be comfortable with how online activity leaves traces and how an investigator can follow those traces using publicly available means.
Cyber Investigations
Think of this as the intersection between investigative method and digital infrastructure.
- How domains, IP addresses, and hosting relationships can reveal ownership or linkage
- Email and username investigation concepts
- Digital footprints and how they accumulate
- Basic operational security for the investigator
- Recognizing the line between passive research and active intrusion
You do not need to be a network engineer, but you should be able to explain what a given technical artifact tells an investigator and what it does not. Overstating what an artifact proves is a common mistake, and scenario questions may probe exactly that kind of overreach.
Domain 4: Intelligence Collection
This area is about the planning and execution of collection. Where the first domain defines the discipline, this one addresses how to actually gather information in an organized, purposeful way and how to turn raw collection into something usable.
Intelligence Collection
The emphasis is on method: collecting deliberately rather than aimlessly.
- Defining collection requirements from the investigative question
- Selecting appropriate sources and tools for a given requirement
- Organizing, logging, and managing collected material
- Moving from collection to analysis and reporting
- Avoiding collection that exceeds the authorized scope
A useful way to think about this domain is as the workflow layer. Questions may describe a situation and ask what the sensible next step is. The strongest answers usually reflect a disciplined sequence: clarify the requirement, choose a fitting method, collect and document, then assess. Candidates who skip straight to tools without defining the requirement tend to choose weaker answers.
Domain 5: Legal Fundamentals
Legal fundamentals is the area that keeps an otherwise skilled investigator out of trouble. Because open source work touches privacy, platform rules, and the handling of personal information, candidates are expected to understand the legal and ethical guardrails around their activity.
Legal Fundamentals
Know the principles that govern what an investigator may collect, how, and why it matters.
- Privacy considerations when handling personal information
- Authorization and the boundary of lawful access
- Ethical conduct and professional responsibility
- Evidence handling and documentation for defensibility
- The importance of consulting counsel and policy when uncertain
Key Takeaway
Do not treat Legal Fundamentals as the "easy" or "soft" area. Legal and ethical reasoning shows up inside the other four domains, particularly in scenario questions about social media and cyber investigations. Law varies by jurisdiction, so focus on the principles your course materials emphasize rather than assuming a single universal rule.
Sequencing the Domains Across Your Prep
Because the domains build on one another, order matters more than any generic study technique. The sequence below ties each week to a specific C/OSINT area and explains the reasoning. Adjust the pacing to the time you have; the logic is what counts. For a broader plan, see our C/OSINT study guide.
Open Source Intelligence and Legal Fundamentals
- Learn the core vocabulary and process first, since every other area assumes it
- Pair it early with legal and ethical principles so they frame everything that follows
Intelligence Collection
- Study the collection workflow while the foundational concepts are fresh
- Practice turning a vague question into a clear collection requirement
Social Media Intelligence
- Apply collection method to platform content
- Revisit legal boundaries around public versus private information
Cyber Investigations and full review
- Cover the technical layer last, once the method and legal frame are solid
- Finish with mixed scenario practice across all five areas
The reason to place legal material at the start rather than the end is that scenario questions rarely isolate it. A question about a social media lead or a technical trace may quietly test whether you recognize an authorization problem. Building the legal frame first makes those cues easier to spot. When you are ready to test yourself, take a few scenario-style sets on the C/OSINT practice test site and note which areas produce your misses.
Eligibility, Fees, and Validity: What to Confirm
Beyond content, there are several administrative points where the issuer's own materials are inconsistent or require confirmation. It pays to resolve them before you pay.
Eligibility needs issuer review
The exam page lists three routes: a bachelor's degree or higher with no required experience, an associate degree with two years, or a high-school diploma or equivalent with three years of relevant investigative or intelligence experience. The same page also describes candidates as currently employed full-time in paid investigative or intelligence work. That language creates tension with the zero-experience route, so do not assume unrestricted entry. Criminal-history disclosure and a conduct review also apply. Our C/OSINT requirements article walks through qualifying in more depth.
Check what your purchase includes
The exam-only page excludes training, the manual, and review quizzes from its package description, yet a later generic benefits section appears to include them. Confirm the inclusions of the exact SKU you are buying. The separate training product advertises lifetime course access, which is not the same as lifetime credential validity.
Renewal terms conflict across issuer pages
The current renewal help article specifies two-year validity, two-year extensions, and a 30-day post-expiration grace period. An issuer blog post dated June 15, 2026 promotes non-expiring credentials, which contradicts that article. Rely on written, credential-specific confirmation from the issuer rather than marketing copy. Also note that the 50 CPE credits awarded by the course are not a verified renewal quota.
Where the Credential Fits Professionally
The five domains map neatly onto work that investigators and analysts actually do: researching subjects from public sources, working with social platforms, tracing digital infrastructure, collecting methodically, and staying within legal bounds. Roles that touch investigations, intelligence analysis, corporate security, fraud and threat research, and similar functions are the natural fit. The issuer's eligibility language itself points toward people already working in investigative or intelligence settings.
Be cautious about any specific salary claim you encounter, since no verified earnings data is tied to this credential in the issuer's materials. For an honest framing of earnings and value, see our C/OSINT salary guide, our analysis of whether the certification is worth it, and our overview of C/OSINT jobs.
Frequently Asked Questions
The issuer's exam listing names Open Source Intelligence, Social Media Intelligence, Cyber Investigations, Intelligence Collection, and Legal Fundamentals as the preparation areas. They are presented as unweighted topics rather than a verified official domain blueprint.
Not in the public materials. The issuer lists the areas without published percentages, and the full detailed curriculum sits in the paid manual. Prepare for all five rather than assuming any one area dominates.
The exam-only listing describes a three-hour online proctored examination with a stated passing threshold of 70%. The institute-wide page describes closed-book remote proctoring with true/false, multiple-choice, and scenario-based questions. No exact item count should be assumed.
The exam-only listing is $450 USD for one attempt with a one-year exam license. The separate training product, which has 55 instructional hours and awards 50 CPE credits, displayed $2,497 USD standard tuition and a $997 USD scholarship price at verification. See our pricing breakdown for detail.
The current renewal help article states two-year validity with two-year extensions and a 30-day post-expiration grace period, while a June 2026 issuer blog promotes non-expiring credentials. Get written, credential-specific confirmation from the issuer before relying on either claim.