- What the Ten Content Areas Actually Represent
- Exam Format, Fees and Eligibility Mechanics
- Foundation Domains: OSINT, the Intelligence Cycle and Privacy
- Technical Domains: Secure Environments, Platforms and Mobile
- Applied Domains: Investigations, Chat Apps, Legal and Case Files
- Who Hires SMIA-Certified Analysts
- Sequencing the Domains in Your Prep
- Renewal and the Numbers That Get Confused
- Frequently Asked Questions
- The Certified Social Media Intelligence Analyst (SMIA) from McAfee Institute lists 10 preparation topics, from OSINT foundations to investigative case-file...
- The standalone exam costs $450, runs 3 hours closed-book, and requires 70% to pass.
- No public blueprint gives percentage weights per domain, so treat all 10 areas as testable.
- Eligibility requires paid, full-time investigative or intelligence experience, scaled to your education level.
What the Ten Content Areas Actually Represent
The Certified Social Media Intelligence Analyst (SMIA) credential from McAfee Institute is built around social media intelligence, often shortened to SOCMINT. Candidates searching for the "domains" of this exam usually want a blueprint with percentage weights, like those published for some other certifications. That is not what is publicly available here, and it is worth being precise about what you can and cannot rely on.
The ten domains in this guide are the explicitly named preparation topics from McAfee Institute's current public curriculum summary. They are unweighted. They are also not the same thing as the 15 training modules in the paid course, and they should not be read as an exhaustive statement of everything the exam can touch. In practical terms: the ten areas below are the best public map of what to master, but no official source tells you that Domain 3 is worth a certain percentage of your score.
If you are still orienting yourself on the credential itself, start with What Is SMIA Certification? and then return here for the content breakdown.
Exam Format, Fees and Eligibility Mechanics
Before diving into the domains, it helps to know the container they are tested in. The mechanics below come from McAfee Institute's published exam and licensing pages.
| Item | What Is Published |
|---|---|
| Standalone exam fee | $450 for one attempt, with online proctoring |
| Exam license duration | 1 year |
| Retake license | $450 |
| Duration | 3 hours, one sitting |
| Book policy | Closed-book |
| Passing threshold | 70% |
| Question formats | True/false, multiple-choice and scenario-based |
| Exact question count | Not verified in public sources |
| Candidate pass rate | Not verified in public sources |
Two practical notes. First, the proctoring description is inconsistent across McAfee Institute pages: the shared examination page describes AI-powered proctoring while its FAQ names ProctorU. The instructions you receive at enrollment govern your actual setup, so read them carefully rather than relying on a blog post, this one included. Second, the format mix matters for how you study. Scenario-based questions reward applied judgment, which is especially relevant for domains like legal fundamentals and case-file preparation. For a full cost picture, see the SMIA certification cost breakdown, and for score details see SMIA Passing Score 2026.
Eligibility for the Professional Credential
The professional SMIA credential is not open to anyone who simply pays the fee. Eligibility is based on a combination of education and relevant paid, full-time investigative or intelligence experience:
- Bachelor's degree or higher plus 1 year of experience
- Associate degree plus 2 years of experience
- High-school diploma or equivalent plus 4 years of experience
Qualifying duties include investigative, law-enforcement, criminal-justice, military and criminal-intelligence work. Eligibility is subject to evidence review and a conduct review. The full training course is optional for eligible exam-only candidates. The broader SMIA requirements guide covers qualification in more depth.
Foundation Domains: OSINT, the Intelligence Cycle and Privacy
The first three domains establish the vocabulary and discipline that everything else in the credential depends on. Candidates with a law-enforcement or military intelligence background will find some of this familiar, but social media framing adds specifics worth drilling.
Domain 1: OSINT Foundations
Open-source intelligence is the umbrella discipline under which social media intelligence sits. Expect the exam to test whether you understand what counts as open-source material, how it differs from other collection disciplines, and where its limits lie.
- What qualifies as publicly available information versus restricted access
- How social media intelligence relates to the wider OSINT field
- The strengths and weaknesses of open-source material as evidence or lead generation
- Core terminology you will need for the rest of the exam
Domain 2: The Intelligence Cycle
The intelligence cycle gives structure to how requirements become finished intelligence. For a closed-book exam, you should be able to name the phases, describe what happens in each, and recognize which phase a scenario is describing.
- Planning and direction, collection, processing, analysis and dissemination
- How a vague investigative question becomes a collection requirement
- Where social media collection fits and where analytic judgment replaces raw gathering
- Why feedback loops matter when new information changes the question
Domain 3: Privacy
Privacy is a standalone domain, which signals that the credential treats it as a core professional competency rather than a footnote. Social media analysts constantly work near the boundary between public information and personal expectation of privacy.
- Distinguishing public content from content shielded by platform privacy settings
- Responsible handling and minimization of personal data
- How privacy considerations shape what you collect, store and share
- The relationship between privacy practice and the legal fundamentals covered in Domain 9
These three domains are conceptual, which makes them well suited to scenario questions: you are given a situation and asked which principle applies. Reading them as isolated definitions is a mistake. Practice connecting them, for instance by asking which intelligence-cycle phase a given privacy decision belongs to.
Technical Domains: Secure Environments, Platforms and Mobile
Domains 4 through 7 move from principles to tradecraft. They cover how you protect yourself while researching, how you work across platforms, and how mobile devices factor into investigations.
Domain 4: Secure Research Environments
An analyst who researches subjects carelessly can expose the investigation, contaminate evidence or compromise their own identity. This domain addresses setting up and operating from a controlled environment.
- Separating investigative activity from personal accounts and devices
- Reducing the digital footprint that links an analyst to an inquiry
- Operational security habits that protect both the analyst and the case
- Why environment discipline affects the defensibility of what you collect
Domain 5: Social Media Investigations
This is the namesake domain of the credential and the one most candidates expect to carry significant weight, though no public source confirms any weighting. It covers the practical work of investigating people, networks and activity across social platforms.
- Identifying and mapping accounts, connections and relationships
- Extracting investigative leads from profiles, posts and interactions
- Attribution questions: how confident can you be that an account belongs to a subject
- Documenting what you find so it supports later analysis
Domain 6: Advanced Platform Research
Beyond basic profile review, advanced platform research addresses deeper techniques for extracting information that is not obvious from a platform's default interface.
- Platform-specific search capabilities and their limitations
- Correlating information across multiple platforms
- Recognizing how platform features change what is discoverable
- Knowing when a technique is appropriate and when it crosses a legal or ethical line
Domain 7: Mobile Forensics
Mobile devices are where much social media activity originates. This domain connects online investigation to the device layer, which matters for analysts who work alongside examiners or handle device-derived evidence.
- How mobile devices store and expose social media artifacts
- The relationship between app activity and recoverable device data
- Preservation concerns when a device becomes part of an investigation
- Understanding what mobile analysis can add to an open-source picture
Applied Domains: Investigations, Chat Apps, Legal and Case Files
The final three domains tie technique to real casework: communications platforms, the legal frame around everything you do, and the end product of an investigation.
Domain 8: Chat and Dating Applications
Messaging and dating apps present distinct challenges compared with public social networks. They are more private by design, which raises both investigative value and legal sensitivity.
- How chat and dating platforms differ from open social networks
- What information these apps can reveal in investigative contexts such as exploitation, fraud and missing-persons work
- Access limitations and the boundary between open-source research and legal process
- Handling sensitive personal content responsibly
Domain 9: Legal Fundamentals
Legal fundamentals underpin every other domain. A technically skilled analyst whose collection is unlawful or inadmissible has produced nothing of value. Expect scenario questions that ask what you may do, what requires legal authority, and what could jeopardize a case.
- Lawful collection versus activity that requires warrants, subpoenas or other process
- Terms-of-service issues and their relationship to legality
- Admissibility concerns for open-source material
- How agency, employer or jurisdictional rules shape permissible practice
Domain 10: Investigative Case-File Preparation
The last domain is about turning research into something usable. Findings that cannot be organized, sourced and presented clearly do not help a prosecutor, supervisor or client.
- Structuring a case file so findings are traceable to sources
- Documenting methods so another analyst could understand and reproduce them
- Preserving and presenting evidence in a defensible form
- Writing for the audience that will rely on your work
Key Takeaway
Domains 9 and 10 are where scenario questions are most likely to test judgment rather than recall. Practice reading a short investigative situation and naming both the legal constraint and the documentation step that follows.
Who Hires SMIA-Certified Analysts
Because eligibility is built on investigative and intelligence experience, the credential naturally attracts people already working in or adjacent to those fields. Qualifying backgrounds named by McAfee Institute include law enforcement, criminal justice, military and criminal intelligence. The employers that tend to value social media intelligence skills follow from that:
- Law-enforcement and criminal-intelligence units that use social media to develop leads and support cases
- Military and government intelligence functions with open-source collection needs
- Corporate security, fraud and investigations teams that research subjects online
- Private investigation and litigation-support firms that build open-source case files
No verified salary or hiring-volume figures are available in the public sources used for this article, so none are quoted here. For discussion of earning potential and role types, see the SMIA salary guide and the overview of SMIA jobs. Whether the credential justifies its cost for you is a personal calculation, covered in Is the SMIA Certification Worth It?
Sequencing the Domains in Your Prep
Because no weights are published, an even spread across all ten areas is the safest default. The sequencing below follows how the domains build on each other rather than any claim about exam emphasis. Adjust it for your own background: a detective may compress the legal and case-file weeks, while an analyst from a non-law-enforcement setting may need to expand them.
Vocabulary and Process
- Domain 1: OSINT foundations
- Domain 2: The intelligence cycle
- Learn to label any scenario by cycle phase
Boundaries and Protection
- Domain 3: Privacy
- Domain 4: Secure research environments
- Domain 9: Legal fundamentals, started early because it frames everything
Core Investigative Technique
- Domain 5: Social media investigations
- Domain 6: Advanced platform research
Devices, Apps and the Final Product
- Domain 7: Mobile forensics
- Domain 8: Chat and dating applications
- Domain 10: Investigative case-file preparation
- Full closed-book review across all ten areas
Study materials are separate from the standalone exam license, so exam-only candidates should plan how they will source preparation content. The SMIA study guide expands on first-attempt strategy, and the SMIA cheat sheet offers a compact review of key facts. When you are ready to test retention, work through realistic questions on the SMIA practice test site, and use the practice exams to check that you can handle scenario-style items under a 3-hour clock.
Renewal and the Numbers That Get Confused
Candidates frequently mix up several different figures that all sound like durations or counts. Keeping them straight avoids planning errors, particularly if you are comparing the exam-only and training routes.
| Measure | What It Refers To |
|---|---|
| 40 instructional hours | Length of the full training course |
| 15 modules | Course structure, which is not the same as the 10 preparation domains |
| 35 CPE credits | Credits awarded for completing the course |
| Lifetime course access | How long you can return to the training material |
| 1-year exam license | How long you have to take the exam after purchase |
| 15 CPE every 2 years | Renewal requirement for the credential itself |
| $125 | Published renewal fee |
The training-and-exam bundle is priced at $1,397 and includes the 40-hour course, 15 modules, lifetime course access and a 1-year exam license. The training route also requires at least 70% on course assessments, and completing the training alone does not award certification: you still need to pass the exam. For scheduling questions, see SMIA exam dates, and for the training product itself, see SMIA training.
Frequently Asked Questions
There is no verified official 10-domain exam structure. The ten domains in this guide are named preparation topics from McAfee Institute's public curriculum summary: OSINT foundations, the intelligence cycle, privacy, secure research environments, social media investigations, advanced platform research, mobile forensics, chat and dating applications, legal fundamentals, and investigative case-file preparation.
No public percentage weights were found for this exam. Because the topics are unweighted and the list is not presented as an exhaustive blueprint, prepare for all ten areas rather than assuming some will be lightly tested.
The published passing threshold is 70%. The exam lasts 3 hours in one sitting and is closed-book, with true/false, multiple-choice and scenario-based formats. An exact question count was not verified.
Not if you are an eligible exam-only candidate. The full course is optional in that case, though study materials are separate from the $450 standalone exam license. The training-and-exam bundle at $1,397 is the alternative route.
Renewal requires 15 CPE credits every 2 years and the published $125 renewal fee. Note that the 35 CPE credits awarded for course completion, the 1-year exam license and lifetime course access are separate measures from credential renewal.