- How to Read the 13 Content Areas
- What the Issuer Actually Publishes
- Domains 1-3: Structures and the Intelligence Foundation
- Domains 4-6: Privacy, Cyber and Auction Fraud
- Domains 7-8: Social Media and Deception Analysis
- Domains 9-11: Boosters, Fencing and Surveillance
- Domains 12-13: Legal Fundamentals and Case Development
- Sequencing the 13 Areas in Your Prep
- Exam Logistics That Shape Your Preparation
- Frequently Asked Questions
- The 13 content areas are editorial preparation headings, not official scored domains or a published exam blueprint.
- McAfee Institute's CORCI curriculum centers on six published learning objectives, from ORC foundations to legal fundamentals and surveillance.
- The standalone CORCI exam page lists a three-hour limit, online proctoring, one attempt and a one-year exam license.
- Official domain weights, question count and pass rate are unverified, so ignore any source quoting them as fact.
How to Read the 13 Content Areas
Candidates searching for the "CORCI exam domains" usually expect a tidy table of percentages: Domain 1 is 20%, Domain 2 is 15%, and so on. For the Certified Organized Retail Crime Investigator credential from McAfee Institute, that table does not exist in any public source we could verify. What does exist is a curriculum narrative and six published learning objectives, and the thirteen areas in this guide are organized directly from the topics those materials name.
Think of the 13 headings as a study map rather than an exam blueprint. They are unweighted, they are not official module titles, and they do not claim to be exhaustive. The issuer advertises 21 modules, but the public course page does not expose their complete titles or lesson contents, so we do not pretend to reproduce them. Your actual coursework will contain material beyond this map, and that coursework is the authoritative source.
If you are still orienting yourself to the credential, start with What Is CORCI Certification? and What Does CORCI Stand For?. Once you are ready to test yourself against these topics, our CORCI practice test site lets you drill them in question form.
What the Issuer Actually Publishes
Before diving into each area, it helps to separate what is confirmed from what is not. The table below reflects the current public issuer material reviewed for this guide.
| Item | Status |
|---|---|
| Credential authority | McAfee Institute |
| Published learning objectives | Six, covering ORC foundations, cyber investigation and evidence collection, auction and online-fraud investigation, social-media and OSINT investigation, booster and fencing operations, and legal fundamentals and surveillance |
| Program size | 21 modules advertised; 40 hours of instruction and 35 CPE credits described |
| Standalone exam format | Three-hour time limit, online proctoring, one attempt, one-year exam license |
| Passing threshold | At least 70% on course sections and on the final online exam |
| Official domain weights | Unverified |
| Question count and scored/unscored split | Unverified |
| Pass rate | Unverified |
Note that the 40 hours and 35 CPE credits describe the training program, not the exam timer or the number of questions. Mixing those figures up is one of the most common errors in online discussion of this credential. For the threshold itself, see CORCI Passing Score 2026, and for the data question, CORCI Pass Rate 2026: What the Data Shows.
One more clarification: McAfee Institute also offers an Associate designation, A|CORCI. Its current associate policy describes the same training curriculum and the same proctored certification examination, with professional experience distinguishing the status. Progression from associate to professional does not require retraining or retesting. So the content areas below apply to both; you are not preparing for two separate exams.
Domains 1-3: Structures and the Intelligence Foundation
The first three areas build the conceptual frame that every later investigative technique hangs on. If the first learning objective, ORC foundations, includes "fraud schemes, operational structures and business impact," then these are the topics you should be able to explain in your own words.
Domain 1: Organized-Retail-Crime Structures
This is the foundation. You need to distinguish organized retail crime from opportunistic shoplifting and understand how groups are arranged to move stolen merchandise at scale.
- Operational structures: how roles are divided among participants, from those who steal to those who move and monetize goods
- Fraud schemes that overlap with theft, and how they differ in evidence and charging posture
- Business impact: why losses extend beyond the cost of merchandise, and how that framing supports referrals and case priority
- How individual incidents link into a pattern worth an investigator's time
Domain 2: Open-Source Intelligence (OSINT)
OSINT appears directly in the learning objectives, tied to gathering evidence and building cases. Expect scenario questions about what information is legitimately collectible from public sources and how it feeds an investigation.
- Identifying public sources that can reveal people, relationships and activity
- Distinguishing a lead from corroborated evidence
- Documenting what you found, where, and when, so it survives scrutiny later
Domain 3: The Intelligence Cycle
The intelligence cycle gives your work a repeatable shape: defining what you need to know, collecting, processing, analyzing and disseminating. Candidates who understand the cycle can reason through unfamiliar scenarios by asking which stage they are in.
- Direction and requirements: starting from a question, not a pile of data
- Collection versus analysis, and why they should not blur together
- Producing something a decision-maker can act on
Because the cycle is the connective tissue, it pays to learn it early. Our CORCI Study Guide walks through how to fold these concepts into a first-attempt plan.
Domains 4-6: Privacy, Cyber and Auction Fraud
This cluster covers the digital side of the work. The published objectives name "evidence from auctions and social media to identify perpetrators and networks," plus "tracking and identifying criminal operations" in auction and online-fraud investigation. Privacy sits alongside them because collection power and collection limits travel together.
Domain 4: Privacy
Privacy is a candidate's guardrail. Even when information is technically reachable, an investigator must know what is appropriate to collect, how to handle it, and where authorization or legal process becomes necessary.
- The difference between what is publicly visible and what requires lawful process
- Handling personal information responsibly during an investigation
- How privacy missteps can undermine an otherwise strong case
Domain 5: Cyber Investigations
The cyber objective centers on evidence collection. Questions here lean toward how digital evidence is identified, preserved and attributed to a person or network.
- Recognizing digital traces that connect an online identity to a real-world actor
- Preserving evidence so its integrity can be demonstrated
- Mapping networks rather than isolated accounts
Domain 6: Auction Fraud
Stolen goods frequently surface on online marketplaces and auction platforms, which makes listings a rich evidence source. This area is about tracking and identifying the criminal operations behind those listings.
- Reading listing behavior, seller patterns and item volume for signs of a fencing outlet
- Linking an online seller to the upstream theft activity
- Preserving listing evidence before it disappears
Domains 7-8: Social Media and Deception Analysis
The fourth learning objective ties social media directly to OSINT, "gathering evidence and building cases." Social platforms often reveal associations, locations, and boasts that other sources never will. Deception analysis is the skill of weighing what you gather and what suspects say.
Domain 7: Social-Media Research
Social media research turns scattered posts into case-relevant intelligence. The emphasis is on structured collection and on connecting online presence to the individuals and groups under investigation.
- Identifying accounts, associations and patterns that reveal group membership
- Capturing content in a way that preserves context and provenance
- Avoiding assumptions: an account that looks relevant still needs corroboration
Domain 8: Deception Analysis
Investigators encounter false statements, fabricated identities and staged narratives. This area focuses on recognizing and testing deception rather than trusting surface claims.
- Spotting inconsistencies between statements, documents and observable facts
- Treating behavioral cues as prompts for verification, not proof
- Recognizing fabricated or borrowed online identities
These two areas reward a skeptical habit of mind. If you can articulate why a lead is only a lead, you will be better positioned for scenario-style items than someone who has memorized terms.
Domains 9-11: Boosters, Fencing and Surveillance
The fifth objective asks candidates to "detect and investigate" booster and fencing operational tactics, and the sixth pairs surveillance with legal fundamentals. Together these areas connect the online evidence trail to the physical world of stores, vehicles and storage locations.
Domain 9: Booster Operations
Boosters are the individuals who steal merchandise, often to order. Understanding their methods helps investigators recognize patterns across incidents.
- Common tactics and how they present in loss data and video
- How boosters fit into the larger structure from Domain 1
- Linking repeated incidents to the same actors or crews
Domain 10: Fencing Operations
Fences convert stolen goods into cash. Disrupting fencing is often the most effective way to reduce theft, because it removes the market the boosters depend on.
- How fencing operations acquire, store and resell goods
- Indicators that a seller or business is moving stolen merchandise
- Tracing the path from theft to resale, including online channels from Domain 6
Domain 11: Surveillance
Surveillance generates evidence, but it also generates legal exposure when done carelessly. The published objective pairs it with compliance, so expect both technique and constraint in your study.
- Purposes and methods of observation in an ORC context
- Documentation that supports later prosecution
- Staying within legal and policy limits while gathering evidence
Domains 12-13: Legal Fundamentals and Case Development
The final two areas are where everything converges. The sixth learning objective covers "compliance and effective evidence gathering," and case development is where an investigator turns collected material into something a prosecutor or internal decision-maker can use.
Domain 12: Legal Fundamentals
This area establishes the legal boundaries around every other technique. You are not being asked to practice law, but you must understand what makes evidence usable and what makes it vulnerable.
- Compliance requirements that govern collection and handling
- What makes evidence admissible or open to challenge
- How the line between private-sector investigators and law enforcement affects what you can do
Domain 13: Professional ORC Case Development
Case development is the capstone. It asks whether you can assemble structure, intelligence, digital evidence, surveillance and legal compliance into a coherent package.
- Organizing evidence so the story of the operation is clear
- Showing links between individuals, incidents and the broader network
- Preparing material that supports referral, recovery or prosecution
Key Takeaway
Domain 13 is not a separate body of facts so much as a test of whether Domains 1 through 12 work together. Revisit it last, and use it to find the gaps in everything you studied before it.
For a sense of where this skill set leads professionally, see CORCI Jobs and the CORCI Salary Guide. Neither the credential nor any agency listing guarantees employment or endorsement, so treat career value as something you build, not something the certificate delivers on its own.
Sequencing the 13 Areas in Your Prep
Since the exam is a single timed assessment with no verified weights, the sensible approach is to move from foundations to application rather than to cram by guesswork. This is the one place where we get tactical about study structure, and it is deliberately tied to the domain order above. The cycle in Domain 3 and the legal limits in Domain 12 act as bookends.
Foundations
- Domain 1 (structures) and Domain 3 (intelligence cycle) so later topics have a frame
- Skim Domain 12 now to understand the boundaries you will keep hitting
Digital collection
- Domains 2, 4, 5, 6 and 7 together, since OSINT, privacy, cyber, auction and social media evidence overlap heavily
- Practice explaining how a single suspect could be traced across all five
Physical operations and analysis
- Domains 8, 9, 10 and 11: deception, boosters, fencing and surveillance
- Connect each back to the online evidence from Week 2
Integration and review
- Full pass through Domain 12 and Domain 13 with the whole picture in mind
- Timed practice on the practice test site to rehearse working across a three-hour sitting
Adjust the pace to your own background. An experienced loss-prevention investigator may move quickly through Domains 1, 9 and 10 and slow down on OSINT and legal fundamentals; someone from a cyber background will likely do the opposite. For a read on relative difficulty, see How Hard Is the CORCI Exam?, and for a condensed reference, the CORCI Cheat Sheet.
Exam Logistics That Shape Your Preparation
Several verified logistics should influence how you study.
- One attempt. The standalone exam page describes a single attempt within a one-year exam license. That raises the stakes of readiness and argues against sitting the exam to "see what it's like."
- Three hours, online proctoring. You will work under identity checks and monitoring from your own location, so rehearse in conditions that resemble that setup.
- 70% threshold. Board certification requires at least 70% on course sections and on the final online exam, plus eligibility documentation and payment of all fees. That is a passing threshold, not an observed pass rate.
- Eligibility paths. The current professional program lists a bachelor's degree or higher plus one year, an associate degree plus three years, or a high-school diploma or equivalent plus five years of relevant investigative or intelligence work. Details are in CORCI Requirements.
- Cost. The current standalone exam offer is USD 450, and the full training bundle is USD 1397. Payment plans, study materials and tuition are not additional universal exam fees. See CORCI Certification Cost for the breakdown.
Finally, remember what a question bank can and cannot do. Practice questions, including ours, are editorial preparation. They do not replace the training, identity checks, eligibility review, proctoring or the issuer's own assessment. Use them to find weak spots across the 13 areas, then return to your official course material to close the gaps. Scheduling questions are covered in CORCI Exam Dates, and the bigger value question in Is the CORCI Certification Worth It?
Frequently Asked Questions
No. They are editorial preparation headings organized from topics named in the official curriculum narrative. They are not official module titles or scored domains, and the issuer has not published an exam blueprint or weights.
The current question count and scored/unscored split are unverified. The standalone exam page publishes a three-hour time limit, online proctoring, one attempt and a one-year exam license. Ignore older figures that circulate in brochures or forums.
The current published board-certification policy requires at least 70% on course sections and on the final online examination, along with eligibility documentation and payment of all fees. This is a passing threshold, not an observed pass rate.
No. McAfee Institute's associate policy describes the same training curriculum and proctored examination, with experience distinguishing professional status. Moving from associate to professional does not require retraining or retesting.
No. Those figures describe the training program. They are not an exam timer or a question count. The standalone exam page lists a three-hour limit.