- The 70% Threshold: What the Issuer States
- What the Number Doesn't Tell You
- Exam Format and Delivery Mechanics
- The Five Preparation Areas Behind the Score
- Fees, Exam License, and One-Attempt Economics
- Eligibility Comes Before the Score
- Turning 70% Into a Preparation Target
- After You Pass: Validity and Renewal
- Frequently Asked Questions
- McAfee Institute states a 70% passing threshold for the Certified in Open Source Intelligence exam.
- The exam-only listing costs $450 USD for one attempt, with a one-year exam license and three-hour online proctored sitting.
- Delivery is closed-book, on-demand AI remote proctoring; formats include true/false, multiple-choice, and scenario-based questions.
- No exact question count or scoring-scale conversion is verified, so avoid guessing how many misses 70% allows.
The 70% Threshold: What the Issuer States
The Certified in Open Source Intelligence credential is issued and examined by McAfee Institute, and the exam product lists a stated passing threshold of 70%. That is the one scoring figure you can anchor your preparation to. If you searched for a cut score, a scaled-score range, or a table showing how many questions you can miss, the honest answer is that the issuer's public listing gives a percentage threshold and not much else.
This article treats that distinction seriously. A lot of exam-prep content invents precision: "you need 42 out of 60," "the cut score is adjusted by form," "most candidates land at 78%." None of those numbers appear in the verified information for this credential, so none appear here. What follows is what is known, what is unknown, and how to build a study plan that clears 70% with margin regardless of how the issuer arrives at the final number.
For a wider view of how this fits with the rest of the certification process, see our overview of C/OSINT certification and the breakdown of C/OSINT requirements and eligibility.
What the Number Doesn't Tell You
Several things people assume about passing scores are not established for this exam. Being clear about them prevents bad planning.
No verified item count
The institute-wide examination page describes the exam experience in general terms, including an approximate question count for the institute's exams overall. That approximation should not be converted into an exact number of items on the C/OSINT exam. Without a verified count, any statement like "you can miss 18 questions" is fabrication. Plan around the percentage, not an imagined item total.
No published domain weighting
The five preparation topics listed in the exam product's curriculum overview are unweighted. They are the areas the product explicitly names, not a verified official blueprint with percentage allocations. You cannot assume that Legal Fundamentals is 10% or that Intelligence Collection is 30%. Treat each area as potentially significant.
No verified pass rate
There is no authoritative, issuer-published first-attempt pass rate to cite. Our page on the C/OSINT pass rate explains what the available evidence does and does not support, and how hard the C/OSINT exam is frames difficulty without leaning on invented statistics.
Exam Format and Delivery Mechanics
The exam-only listing describes a three-hour online proctored examination. The institute-wide examination page adds that delivery is closed-book, on-demand, with AI remote proctoring, and that questions come in true/false, multiple-choice, and scenario-based formats.
| Element | What the issuer states |
|---|---|
| Passing threshold | 70% |
| Duration | Three hours, online proctored |
| Book policy | Closed-book |
| Scheduling | On-demand, AI remote proctoring |
| Question styles | True/false, multiple-choice, scenario-based |
| Exact item count | Not verified for this exam |
| Domain weighting | Not published; topics are unweighted |
Why the scenario-based format shapes how you score
True/false and multiple-choice items reward recall: you either know the definition, the tool category, or the legal concept, or you don't. Scenario-based items reward judgment. An investigator is handed a situation, such as a subject whose public profiles span several platforms, and must choose the lawful, defensible, and effective next step. Candidates who memorize terminology but have never reasoned through an investigative workflow tend to lose points here. Since you cannot see a per-format scoring breakdown, build both skills.
Because the exam is closed-book and remotely proctored, you also need to be comfortable with the testing environment itself. For scheduling specifics and windows, see C/OSINT exam dates and scheduling.
The Five Preparation Areas Behind the Score
The exam product's curriculum overview lists five preparation areas. They are not a verified weighted blueprint, but they are the best public map of what the 70% is measured against. Our full walkthrough is in the C/OSINT exam domains guide; here is how each area connects to scoring.
Domain 1: Open Source Intelligence
The foundation. Expect the exam to test what OSINT is, how open-source information differs from other intelligence disciplines, and how an investigator frames a collection problem.
- Definitions and the role of publicly available information
- Source types and how to evaluate reliability and relevance
- Structuring a question before you start searching
Domain 2: Social Media Intelligence
Social platforms are often the richest public source about a person, group, or event. Questions in this area tend to be scenario-driven.
- Profile, connection, and content analysis across platforms
- Understanding what platforms expose publicly versus privately
- Preserving and documenting social content in an investigatively sound way
Domain 3: Cyber Investigations
This area links open-source work to the digital environment: infrastructure, accounts, and online activity trails.
- Digital footprints and attribution concepts
- Investigative handling of online evidence
- Recognizing the limits of what open sources can establish
Domain 4: Intelligence Collection
The process side of the work: how information is gathered, organized, and turned into something usable.
- Collection planning and source management
- Documentation and chain-of-custody thinking for gathered material
- Moving from raw data to supported findings
Domain 5: Legal Fundamentals
Often underestimated, and the area where a confident-but-wrong answer is most costly. Scenario items frequently hinge on what an investigator may and may not do.
- Lawful versus unlawful collection and access
- Privacy considerations and evidentiary defensibility
- Professional and ethical boundaries in investigative work
Key Takeaway
Do not let Legal Fundamentals become the area you "get to later." On a scenario-based exam, a single misjudged legal call can invalidate an otherwise correct investigative approach, and with no published weighting you cannot safely assume it is a small slice.
Fees, Exam License, and One-Attempt Economics
The passing score matters more once you understand the price of a miss. The exam-only listing is $450 USD for one attempt, with a one-year exam license. The institute-wide examination page also lists an examination and retake license price of $450 USD. Treat these as the verified figures and confirm current pricing at checkout, since listings change.
| Product | Verified details |
|---|---|
| Exam-only listing | $450 USD, one attempt, one-year exam license, three-hour online proctored exam |
| Exam and retake license (institute-wide page) | $450 USD |
| Training product | 55 instructional hours, 50 CPE credits; $2,497 USD standard tuition, $997 USD scholarship price at verification |
Three different clocks
Candidates routinely conflate separate quantities. Keep them apart:
- Course duration: 55 instructional hours of training.
- CPE earned: 50 CPE credits awarded by the course.
- Exam-license validity: one year to use your purchased attempt.
Credential validity after you pass is a fourth, separate matter covered below. The 50 CPE credits from the course are not a verified renewal quota.
For a full pricing view, including how the exam-only route compares to the training route, see the C/OSINT certification cost breakdown, and for what the training covers, C/OSINT training.
Eligibility Comes Before the Score
You cannot pass an exam you are not cleared to sit. The exam page lists three eligibility routes based on education and experience:
- Bachelor's degree or higher with zero required experience
- Associate degree with two years of relevant investigative or intelligence experience
- High-school diploma or equivalent with three years of relevant investigative or intelligence experience
The same page also describes candidates as currently employed full-time in paid investigative or intelligence work. That language sits awkwardly beside the zero-experience degree route, so the degree-only path should be treated as subject to issuer eligibility review rather than unrestricted entry. Criminal-history disclosure and a conduct review also apply under the Eligibility and Conduct Policy.
Key Takeaway
Clarify your eligibility with McAfee Institute before purchasing. A $450 license is a poor way to discover that your background needs review. Our requirements guide walks through each route in more detail.
Turning 70% Into a Preparation Target
Because the weighting is unpublished and the item count unverified, the right way to use the 70% figure is as a floor to clear comfortably, not a number to hit exactly. Aim for a consistent practice score well above it in every domain before you sit the exam. Here is one way to sequence the five areas, tied to how they build on one another:
Open Source Intelligence
- Lock down core definitions and the collection mindset
- Everything later depends on this vocabulary
Social Media Intelligence
- Work through multi-platform scenarios
- Practice documenting what you find
Cyber Investigations and Intelligence Collection
- Connect digital footprints to a collection plan
- Focus on process and defensible documentation
Legal Fundamentals, then mixed review
- Study legal boundaries last so they frame earlier scenarios
- Finish with full mixed-domain practice under closed-book conditions
Legal Fundamentals sits late deliberately: once you understand the investigative techniques, the legal limits on them make more sense and stick better. Finish with timed, closed-book mixed practice so the three-hour format feels routine. The C/OSINT study guide expands this into a full first-attempt plan, and the C/OSINT cheat sheet is useful for the final review pass.
To measure where you actually stand against that 70% line, take a full-length run on the C/OSINT practice test site and review every miss by domain. A pattern of misses in one area is your signal to rebalance, and you can keep drilling with additional practice questions until your scores are steady across all five.
After You Pass: Validity and Renewal
A passing score earns the credential, but how long it stays valid is where issuer information conflicts. The current renewal help article specifies two-year validity and two-year extensions, with a 30-day post-expiration grace period. However, an issuer blog dated June 15, 2026 promotes non-expiring credentials, which contradicts that article.
The training product advertises lifetime course access, which is not the same as lifetime credential validity. Do not read course access as credential permanence.
If you are weighing whether the investment pays off, our analyses of whether the certification is worth it, the salary picture, and the kinds of roles discussed under C/OSINT jobs give context beyond the exam itself.
Frequently Asked Questions
McAfee Institute's exam listing states a passing threshold of 70%. The public information does not provide a verified scaled-score range or a conversion into a specific number of correct answers.
That cannot be stated reliably. The exact question count for this exam is not verified, and the institute-wide page's approximate count should not be converted into an exact figure. Plan around the 70% threshold rather than an item total.
The weighting is not published. The five areas are Open Source Intelligence, Social Media Intelligence, Cyber Investigations, Intelligence Collection, and Legal Fundamentals, and they are unweighted preparation topics rather than a verified official blueprint. Prepare for all five.
The exam-only listing is $450 USD for one attempt with a one-year exam license. The exam is a three-hour online proctored sitting. Confirm current pricing and the exact inclusions of your purchased SKU before checkout.
Not necessarily. The renewal help article specifies two-year validity with two-year extensions and a 30-day post-expiration grace period, while a separate issuer blog promotes non-expiring credentials. Request written, credential-specific renewal confirmation from McAfee Institute.