C/OSINT logo
Focused certification exam prep
Start practice

C/OSINT Exam Domains 2026: Complete Guide to All 5 Content Areas

TL;DR
  • The five preparation areas are Open Source Intelligence, Social Media Intelligence, Cyber Investigations, Intelligence Collection, and Legal Fundamentals.
  • These areas are unweighted preparation topics, not a verified official blueprint, so study all five rather than gambling on one.
  • The exam is a three-hour, online proctored test with a stated 70% passing threshold.
  • The exam-only listing is $450 USD for one attempt and includes a one-year exam license.

How to Read the Five Content Areas

The Certified in Open Source Intelligence credential is issued and administered by McAfee Institute, which styles it C|OSINT. This site uses C/OSINT as its abbreviation, and everything below refers only to that McAfee Institute credential. Other certifications share a similar acronym, so be careful when you search for study material: a resource that describes different fee schedules, domain weights, or pass rates is almost certainly about a different program.

The issuer's exam product lists five preparation areas in its curriculum overview: Open Source Intelligence, Social Media Intelligence, Cyber Investigations, Intelligence Collection, and Legal Fundamentals. It is worth being precise about what that list is. These are the topics the issuer names for preparation. They are not published as weighted exam domains with percentage allocations, and the detailed blueprint was not available in the public listing. The paid course manual is where the full detail lives.

Why weights matter here: Many certifications publish a percentage per domain so candidates can budget study time proportionally. This one does not, as far as the public materials show. Treat every area as fair game, and be skeptical of any third-party site that claims to know exactly how many questions come from each area. For a deeper look at how candidates gauge difficulty without an official blueprint, see our guide on how hard the C/OSINT exam is.

Exam Format and Logistics That Shape Your Prep

Knowing the delivery format changes how you study. The exam-only listing describes a three-hour online proctored examination with a stated passing threshold of 70%. The institute-wide examination page describes closed-book, on-demand AI remote proctoring, with true/false, multiple-choice, and scenario-based question formats. That page gives only an approximate question count for the institute's exams generally, so do not assume a specific item total for this credential.

ItemWhat the issuer materials state
AdministratorMcAfee Institute
Exam-only price$450 USD, one attempt
Exam licenseOne year
DurationThree hours, online proctored
Passing threshold70%
Question stylesTrue/false, multiple-choice, scenario-based (institute-wide page)
Training product55 instructional hours, 50 CPE credits
Training price at verification$2,497 standard tuition; $997 scholarship price

The scenario-based format is the part that most affects preparation. Scenario questions reward candidates who can apply a concept to a fact pattern, such as deciding which collection method fits a situation or whether a particular action raises a legal concern. Memorizing definitions alone will not carry you through those items. For the full numbers behind the threshold, our article on the C/OSINT passing score breaks down what 70% means in practice, and the C/OSINT certification cost guide covers the pricing in more detail.

Three different time and credit numbers: The 55 instructional hours describe the training course, the 50 CPE credits are what the course awards, and the one-year exam license is how long your exam purchase stays usable. These are separate quantities. None of them is the same as how long the certification itself remains valid.

Domain 1: Open Source Intelligence

The first area is the discipline itself. Candidates should be fluent in what open source intelligence is, where it sits within the broader intelligence picture, and how an open source investigation is structured from question to finished product. This is the conceptual backbone for everything else on the exam.

Open Source Intelligence

Expect to demonstrate that you understand the purpose, process, and limits of working with publicly available information.

  • The distinction between information, data, and finished intelligence
  • How an investigative question is framed before any searching begins
  • Evaluating source reliability and information credibility
  • Recognizing bias, deception, and disinformation in public sources
  • Documenting methods so findings can be reproduced and defended

Source evaluation deserves extra attention because scenario questions often hinge on it. A candidate who can articulate why a single uncorroborated post is weak evidence, and how corroboration across independent sources changes confidence, will handle those questions far better than one who only knows search syntax. If you are new to the field, our explainer on what C/OSINT is is a useful orientation before you dive into the technical material.

Domain 2: Social Media Intelligence

Social media intelligence applies open source methods to platform-based content. The exam topic here concerns how people, networks, and events can be understood through publicly visible social activity, and how an investigator should handle that material responsibly.

Social Media Intelligence

Focus on the investigative value of social content and the care required to use it properly.

  • Identifying and attributing accounts, and the limits of attribution
  • Mapping relationships, connections, and communities
  • Reading timestamps, metadata, and contextual clues in posts
  • Preserving social content before it is edited or deleted
  • Understanding platform terms, privacy settings, and what counts as public

One recurring theme in this area is preservation. Social content is volatile, and a strong investigator captures it in a way that retains context and supports later review. Another is restraint: knowing the difference between observing what is genuinely public and crossing into conduct that raises legal or ethical problems. That boundary connects directly to the fifth domain, so study the two together.

Domain 3: Cyber Investigations

Cyber investigations covers the technical and infrastructure-facing side of open source work. Candidates should be comfortable with how online activity leaves traces and how an investigator can follow those traces using publicly available means.

Cyber Investigations

Think of this as the intersection between investigative method and digital infrastructure.

  • How domains, IP addresses, and hosting relationships can reveal ownership or linkage
  • Email and username investigation concepts
  • Digital footprints and how they accumulate
  • Basic operational security for the investigator
  • Recognizing the line between passive research and active intrusion
Operational security is testable: Protecting your own identity and attribution while researching is a classic scenario topic. Be prepared to reason about why an investigator would separate research identities, avoid tipping off a subject, and avoid actions that could be interpreted as unauthorized access.

You do not need to be a network engineer, but you should be able to explain what a given technical artifact tells an investigator and what it does not. Overstating what an artifact proves is a common mistake, and scenario questions may probe exactly that kind of overreach.

Domain 4: Intelligence Collection

This area is about the planning and execution of collection. Where the first domain defines the discipline, this one addresses how to actually gather information in an organized, purposeful way and how to turn raw collection into something usable.

Intelligence Collection

The emphasis is on method: collecting deliberately rather than aimlessly.

  • Defining collection requirements from the investigative question
  • Selecting appropriate sources and tools for a given requirement
  • Organizing, logging, and managing collected material
  • Moving from collection to analysis and reporting
  • Avoiding collection that exceeds the authorized scope

A useful way to think about this domain is as the workflow layer. Questions may describe a situation and ask what the sensible next step is. The strongest answers usually reflect a disciplined sequence: clarify the requirement, choose a fitting method, collect and document, then assess. Candidates who skip straight to tools without defining the requirement tend to choose weaker answers.

Domain 5: Legal Fundamentals

Legal fundamentals is the area that keeps an otherwise skilled investigator out of trouble. Because open source work touches privacy, platform rules, and the handling of personal information, candidates are expected to understand the legal and ethical guardrails around their activity.

Legal Fundamentals

Know the principles that govern what an investigator may collect, how, and why it matters.

  • Privacy considerations when handling personal information
  • Authorization and the boundary of lawful access
  • Ethical conduct and professional responsibility
  • Evidence handling and documentation for defensibility
  • The importance of consulting counsel and policy when uncertain

Key Takeaway

Do not treat Legal Fundamentals as the "easy" or "soft" area. Legal and ethical reasoning shows up inside the other four domains, particularly in scenario questions about social media and cyber investigations. Law varies by jurisdiction, so focus on the principles your course materials emphasize rather than assuming a single universal rule.

Sequencing the Domains Across Your Prep

Because the domains build on one another, order matters more than any generic study technique. The sequence below ties each week to a specific C/OSINT area and explains the reasoning. Adjust the pacing to the time you have; the logic is what counts. For a broader plan, see our C/OSINT study guide.

Week 1

Open Source Intelligence and Legal Fundamentals

  • Learn the core vocabulary and process first, since every other area assumes it
  • Pair it early with legal and ethical principles so they frame everything that follows
Week 2

Intelligence Collection

  • Study the collection workflow while the foundational concepts are fresh
  • Practice turning a vague question into a clear collection requirement
Week 3

Social Media Intelligence

  • Apply collection method to platform content
  • Revisit legal boundaries around public versus private information
Week 4

Cyber Investigations and full review

  • Cover the technical layer last, once the method and legal frame are solid
  • Finish with mixed scenario practice across all five areas

The reason to place legal material at the start rather than the end is that scenario questions rarely isolate it. A question about a social media lead or a technical trace may quietly test whether you recognize an authorization problem. Building the legal frame first makes those cues easier to spot. When you are ready to test yourself, take a few scenario-style sets on the C/OSINT practice test site and note which areas produce your misses.

Eligibility, Fees, and Validity: What to Confirm

Beyond content, there are several administrative points where the issuer's own materials are inconsistent or require confirmation. It pays to resolve them before you pay.

Eligibility needs issuer review

The exam page lists three routes: a bachelor's degree or higher with no required experience, an associate degree with two years, or a high-school diploma or equivalent with three years of relevant investigative or intelligence experience. The same page also describes candidates as currently employed full-time in paid investigative or intelligence work. That language creates tension with the zero-experience route, so do not assume unrestricted entry. Criminal-history disclosure and a conduct review also apply. Our C/OSINT requirements article walks through qualifying in more depth.

Check what your purchase includes

The exam-only page excludes training, the manual, and review quizzes from its package description, yet a later generic benefits section appears to include them. Confirm the inclusions of the exact SKU you are buying. The separate training product advertises lifetime course access, which is not the same as lifetime credential validity.

Renewal terms conflict across issuer pages

The current renewal help article specifies two-year validity, two-year extensions, and a 30-day post-expiration grace period. An issuer blog post dated June 15, 2026 promotes non-expiring credentials, which contradicts that article. Rely on written, credential-specific confirmation from the issuer rather than marketing copy. Also note that the 50 CPE credits awarded by the course are not a verified renewal quota.

Scheduling and timing: Because the exam license lasts one year and delivery is on-demand with remote proctoring, you have flexibility but not unlimited time. For how scheduling works in practice, read our guide to C/OSINT exam dates.

Where the Credential Fits Professionally

The five domains map neatly onto work that investigators and analysts actually do: researching subjects from public sources, working with social platforms, tracing digital infrastructure, collecting methodically, and staying within legal bounds. Roles that touch investigations, intelligence analysis, corporate security, fraud and threat research, and similar functions are the natural fit. The issuer's eligibility language itself points toward people already working in investigative or intelligence settings.

Be cautious about any specific salary claim you encounter, since no verified earnings data is tied to this credential in the issuer's materials. For an honest framing of earnings and value, see our C/OSINT salary guide, our analysis of whether the certification is worth it, and our overview of C/OSINT jobs.

Frequently Asked Questions

What are the five C/OSINT content areas?

The issuer's exam listing names Open Source Intelligence, Social Media Intelligence, Cyber Investigations, Intelligence Collection, and Legal Fundamentals as the preparation areas. They are presented as unweighted topics rather than a verified official domain blueprint.

Are the domains weighted by percentage?

Not in the public materials. The issuer lists the areas without published percentages, and the full detailed curriculum sits in the paid manual. Prepare for all five rather than assuming any one area dominates.

How long is the exam and what score do I need?

The exam-only listing describes a three-hour online proctored examination with a stated passing threshold of 70%. The institute-wide page describes closed-book remote proctoring with true/false, multiple-choice, and scenario-based questions. No exact item count should be assumed.

How much does the exam cost?

The exam-only listing is $450 USD for one attempt with a one-year exam license. The separate training product, which has 55 instructional hours and awards 50 CPE credits, displayed $2,497 USD standard tuition and a $997 USD scholarship price at verification. See our pricing breakdown for detail.

Does the certification expire?

The current renewal help article states two-year validity with two-year extensions and a 30-day post-expiration grace period, while a June 2026 issuer blog promotes non-expiring credentials. Get written, credential-specific confirmation from the issuer before relying on either claim.

Ready to pass your C/OSINT exam?

Put this into practice with free C/OSINT questions across every exam domain.