- What You Are Actually Studying For
- Exam Mechanics: Format, Fee, and Passing Threshold
- The Five Preparation Areas, Mapped to Real Work
- Eligibility and Purchase Checks Before You Study
- Preparing for True/False, Multiple-Choice, and Scenario Questions
- A Domain-Ordered Study Sequence
- Training Course vs. Exam-Only Route
- After You Pass: Validity, Renewal, and Where the Credential Fits
- Frequently Asked Questions
- The exam-only listing is $450 USD for one attempt, a one-year exam license, and a three-hour online proctored test.
- The stated passing threshold is 70%, delivered closed-book through AI remote proctoring.
- Five preparation areas drive study: OSINT, social media intelligence, cyber investigations, intelligence collection, and legal fundamentals.
- Eligibility depends on education plus investigative experience, so confirm your route with McAfee Institute before paying.
What You Are Actually Studying For
The Certified in Open Source Intelligence credential is issued and examined by McAfee Institute, which styles it C|OSINT. This site abbreviates it C/OSINT. It is a practitioner credential aimed at people who gather, validate, and use publicly available information in investigative or intelligence work. If you are still orienting yourself, start with What Is C/OSINT Certification? and What Does C/OSINT Stand For?, then return here for the preparation plan.
One point of honesty shapes everything below. The issuer's product page lists five preparation areas but does not publish a weighted, itemized exam blueprint. That means nobody can responsibly tell you "Domain 3 is worth a fixed share of your score." The right approach is to build competence across all five areas and treat any claim of exact weightings with suspicion. For a deeper walk through each area, see C/OSINT Exam Domains 2026: Complete Guide to All 5 Content Areas.
Exam Mechanics: Format, Fee, and Passing Threshold
Knowing the mechanics up front removes a lot of exam-day anxiety. Here is what the issuer's listings state.
| Item | What the issuer states |
|---|---|
| Exam-only price | $450 USD for one attempt |
| Exam license | One year |
| Duration | Three hours, online proctored |
| Passing threshold | 70% |
| Delivery | Closed-book, on-demand, AI remote proctoring |
| Question formats | True/false, multiple-choice, and scenario-based |
Notice what is missing: an exact question count. The institute-wide examination page gives only an approximate figure for exams in general, and it should not be treated as the item count for this specific test. Plan around the three-hour window and the 70% threshold rather than a number you cannot verify. Our C/OSINT Passing Score article covers the threshold in more detail, and C/OSINT Certification Cost breaks down the pricing options.
The Five Preparation Areas, Mapped to Real Work
The five headings below are the preparation topics the issuer lists. They are unweighted, and they are not an exhaustive outline, so treat each as a starting scope and expect adjacent material to appear.
Domain 1: Open Source Intelligence
The foundation. You need to understand what counts as open source information, how it differs from other intelligence disciplines, and how it moves through a collection-to-product workflow.
- Define open source versus closed or restricted sources, and know why the distinction matters operationally
- Understand source evaluation: reliability of the source versus credibility of the information
- Recognize how OSINT supports investigations, threat assessment, and corporate or government decision-making
- Know the vocabulary precisely, since true/false items often hinge on definitions
Domain 2: Social Media Intelligence
Platforms are rich collection environments, and they raise distinct technical and ethical questions.
- Understand what public profiles, posts, connections, and metadata can reveal about a subject
- Know the difference between passive observation and any interaction that alters the subject's awareness
- Be able to reason about attribution: linking accounts to a real person and the confidence that linkage deserves
- Expect scenarios asking what you should do, or avoid doing, when working a platform-based lead
Domain 3: Cyber Investigations
This area connects open source collection to the digital footprint of people and infrastructure.
- Understand digital artifacts: domains, IP addresses, usernames, emails, and the trail they leave
- Know how investigators preserve and document digital findings so they remain usable
- Grasp operational security for the investigator, including how your own activity can expose you or your inquiry
- Be comfortable reasoning about how an online identity can be traced, and where that tracing hits limits
Domain 4: Intelligence Collection
This is the tradecraft layer: planning, gathering, organizing, and validating.
- Understand the intelligence cycle and where collection sits within it
- Know how to turn a question into collection requirements and a defensible search approach
- Practice corroboration: confirming a finding through independent sources before relying on it
- Recognize cognitive bias and deception, including manipulated or fabricated content
Domain 5: Legal Fundamentals
Many candidates under-prepare here because it feels less technical, yet legal judgment is what separates a usable investigation from a compromised one.
- Understand privacy expectations and the limits of lawful collection from public sources
- Know why terms of service, authorization, and jurisdiction matter to an investigator
- Recognize the handling, retention, and documentation practices that protect admissibility and credibility
- Expect scenario items where the correct answer is the cautious, compliant one
Because the exam is scenario-capable, these areas overlap in practice. A single question can touch social media collection, a legal limit, and a corroboration step at once. Study them as an integrated workflow, not five silos.
Eligibility and Purchase Checks Before You Study
It is worth settling eligibility before you invest weeks of study. The exam page describes three routes: a bachelor's degree or higher with zero required experience, an associate degree with two years, or a high-school diploma or equivalent with three years of relevant investigative or intelligence experience. The same page also describes candidates as currently employed full-time in paid investigative or intelligence work, so the zero-experience degree route should not be assumed to mean unrestricted entry. Ask the issuer to confirm how your specific situation is treated.
Criminal-history disclosure and a conduct review also apply. If anything in your background could be relevant, read the Eligibility and Conduct Policy first and ask questions early. Our C/OSINT Requirements guide goes through the qualification routes in detail.
Preparing for True/False, Multiple-Choice, and Scenario Questions
The three formats reward different skills, so prepare for each deliberately.
True/False: precision with definitions
These items punish loose understanding. Build a short glossary of core terms and be able to state what makes a statement false, not just recognize a true one. Qualifiers like "always," "only," and "never" deserve extra suspicion.
Multiple-choice: elimination and best-answer judgment
Investigative questions often have two plausible options where one is more defensible legally or methodologically. When two answers both seem workable, prefer the one that preserves evidence integrity, respects legal limits, and avoids alerting a subject unnecessarily.
Scenario-based: walk the workflow
For a scenario, identify the objective first, then ask what collection is appropriate, what the legal constraint is, how you would verify, and how you would document. If you can narrate those four steps, you can usually find the best answer. Since the test is closed-book, you cannot look up definitions, so the narrative has to be internalized.
Key Takeaway
When a scenario leaves you torn, choose the answer that is lawful, documented, and least likely to compromise the investigation. Cautious and compliant beats clever and aggressive on a credential built for working investigators.
For a candid look at how demanding this combination is, read How Hard Is the C/OSINT Exam?. And for data-driven context, see C/OSINT Pass Rate 2026: What the Data Shows, keeping in mind that you should be wary of any pass-rate claim the issuer has not published.
A Domain-Ordered Study Sequence
Here is the one structured plan in this article, built around the content rather than generic habits. The logic is to learn the vocabulary and cycle first, layer on platform and technical collection, and finish with legal judgment so it frames everything you have learned. Adjust the length to your own background; an experienced investigator may compress it, while a career changer may stretch it.
Domain 1 and Domain 4 foundations
- Learn OSINT definitions, source types, and the intelligence cycle
- Build your glossary for true/false precision
- Practice source reliability versus information credibility
Domain 2: Social Media Intelligence
- Study what platform data and metadata can reveal
- Work through attribution and confidence reasoning
- Review passive versus active interaction boundaries
Domain 3: Cyber Investigations
- Cover domains, IPs, usernames, and digital artifacts
- Study preservation, documentation, and investigator opsec
- Link technical findings back to collection requirements
Domain 5: Legal Fundamentals and integration
- Review privacy limits, authorization, and jurisdiction
- Run mixed scenarios that cross all five areas
- Take timed practice sets under closed-book conditions
Practice under realistic conditions, meaning no notes and a three-hour clock, because the real session is proctored and closed-book. Our C/OSINT practice tests are designed for exactly this kind of timed rehearsal. When you are close to exam day, condense your notes with the C/OSINT Cheat Sheet, and confirm timing logistics in C/OSINT Exam Dates.
Training Course vs. Exam-Only Route
McAfee Institute sells the credential two ways, and the right choice depends on your existing knowledge and budget.
| Factor | Exam-only | Training product |
|---|---|---|
| Price shown | $450 USD for one attempt | $2,497 USD standard tuition; $997 USD scholarship price at verification |
| Instructional time | None described | 55 hours |
| CPE awarded | None | 50 CPE credits |
| Access | One-year exam license | Lifetime course access advertised |
| Best for | Practitioners already fluent in the material | Candidates who want structured instruction |
Pricing and scholarship offers can change, so verify current figures with the issuer before deciding. Note too that lifetime course access is not the same as lifetime credential validity. If you are weighing the investment, our analyses of whether the certification is worth it and C/OSINT training options can help you decide.
After You Pass: Validity, Renewal, and Where the Credential Fits
Plan for the credential's lifespan now, because issuer sources disagree. The current renewal help article specifies two-year validity with two-year extensions and a 30-day post-expiration grace period. Yet an issuer blog dated June 15, 2026 promotes non-expiring credentials. Do not rely on the marketing language. Get written, credential-specific confirmation of renewal terms for Certified in Open Source Intelligence before you build a career plan around it.
Likewise, the 50 CPE credits the training course awards are not a verified renewal quota, so do not assume they satisfy any particular renewal requirement. Check the issuer's CPE policy, updated January 1, 2026, for what actually counts.
On the career side, the credential is aimed at people doing investigative or intelligence work, such as corporate security, fraud and insider-threat investigation, threat intelligence, due diligence, and public-sector or law-enforcement-adjacent roles. Specific salary figures are not something we can responsibly quote, so see C/OSINT Jobs and the C/OSINT Salary Guide for a qualitative picture, and treat any precise earnings claim skeptically.
Frequently Asked Questions
The exam-only listing is $450 USD for one attempt, including a one-year exam license and a three-hour online proctored session. The separate training product is priced higher. Always confirm what your specific purchase includes, since the exam-only page is internally inconsistent about training, manual, and quiz inclusion.
The stated passing threshold is 70%. The exam is closed-book and delivered through on-demand AI remote proctoring, with true/false, multiple-choice, and scenario-based question formats. An exact question count has not been verified for this exam.
The issuer lists five preparation areas: Open Source Intelligence, Social Media Intelligence, Cyber Investigations, Intelligence Collection, and Legal Fundamentals. They are unweighted preparation topics, not a verified full blueprint, so prepare broadly rather than betting on any one area.
The exam page lists a bachelor's degree or higher with zero required experience, but it also describes candidates as employed full-time in paid investigative or intelligence work. Because of that tension, request an eligibility review from McAfee Institute rather than assuming you qualify. Conduct and criminal-history review also apply.
The current renewal help article describes two-year validity, two-year extensions, and a 30-day post-expiration grace period, while a June 2026 issuer blog promotes non-expiring credentials. Because these conflict, obtain written, credential-specific renewal confirmation from the issuer before relying on either claim.
If you want a single starting point that ties these topics together, return to our main C/OSINT study guide, and when you are ready to test yourself under realistic conditions, work through the full practice exam library.