- Identity Check: Which RCCI This Sheet Covers
- Exam Snapshot at a Glance
- The Five Preparation Domains, Condensed
- Evidence Rules You Must Not Fumble
- Artifact and Timeline Quick Map
- Specialized Investigations Crib Notes
- Reporting and Capstone Reminders
- Conflicting Records: Fees, Codes, and Question Counts
- Scheduling the Domains Across a Study Plan
- Frequently Asked Questions
- RCCI here means Rocheston Certified Cybercrime Investigator, a digital forensics and court-ready reporting credential.
- The current course page lists 100 questions, two hours, and a 70% passing score.
- The exam is online with Rocheston Ramsys proctoring; registration runs through cert.rocheston.com.
- Five preparation domains run from cybercrime law and evidence to court-ready reporting and the capstone.
Identity Check: Which RCCI This Sheet Covers
The acronym RCCI is shared by several unrelated credentials, and mixing them up is the fastest way to study the wrong material. This cheat sheet covers one credential only: the Rocheston Certified Cybercrime Investigator, issued through the Rocheston Department of Certification. It is a digital forensics and investigation credential built around evidence handling, forensic analysis, and court-ready reporting.
If you are still orienting yourself, the explainers on what RCCI certification is and what RCCI stands for cover the naming and background in more depth. This page assumes you have decided to pursue it and want a compact, scannable review.
Exam Snapshot at a Glance
The table below reproduces the exam specifications as stated on Rocheston's current RCCI course page. Sources were checked on October 5, 2026.
| Item | What the Current Course Page States |
|---|---|
| Credential | Rocheston Certified Cybercrime Investigator (RCCI) |
| Issuer | Rocheston, via the Rocheston Department of Certification |
| Questions | 100 |
| Time limit | Two hours |
| Question formats | Multiple-choice, true/false, and short-answer |
| Passing score | 70% |
| Delivery | Online, proctored through Rocheston Ramsys |
| Registration | cert.rocheston.com |
| Recommended background | Cybersecurity, IT, incident-response, or investigative knowledge |
| Law-enforcement experience | Not required |
Two quick consequences follow from these numbers. First, 100 questions in two hours averages out to roughly 72 seconds per question, which is workable for multiple-choice and true/false items but tight if several short-answer items demand written explanations. Second, a 70% threshold means you need at least 70 of 100 questions correct if every question is weighted equally. The page does not say whether items carry different weights, so do not assume they do. For deeper treatment, see the RCCI passing score breakdown.
The Five Preparation Domains, Condensed
The five domain lines below mirror the day-level headings of Rocheston's five-day preparation curriculum. They are unweighted preparation topics. No formal weighted exam blueprint was verified, and the headings should not be read as proof of exhaustive exam coverage or as an official count of exam domains. Think of them as a structured way to organize your review. The long-form version lives in the complete guide to the RCCI content areas.
Domain 1: Cybercrime, Law & Evidence
The legal and conceptual foundation. Everything downstream depends on understanding what makes digital evidence admissible and trustworthy.
- Cybercrime law and how it frames an investigation
- What counts as evidence and how it must be handled
- Chain of custody: who held what, when, and why
Domain 2: IR & Evidence Acquisition
Where incident response meets forensic discipline. The core tension is acting fast without destroying evidence.
- Incident containment versus evidence preservation
- Forensic imaging of storage media
- Hash verification to prove an image matches its source
- Volatile evidence that disappears when a system loses power
Domain 3: Forensic Analysis & Timelines
Turning acquired data into findings and reconstructing events in order.
- Deleted files and recovery considerations
- Registry artifacts and what they reveal about activity
- Logs as a source of corroboration
- Timeline construction from multiple sources
Domain 4: Specialized Investigations
Evidence sources and scenarios that require their own handling approach.
- Cloud, mobile, and network evidence
- Insider threat investigations
- Cryptocurrency and digital payment trails
- Dark-web investigations
- AI-related topics and deepfakes
Domain 5: Court-Ready Reporting & Capstone
Communicating findings so they survive scrutiny.
- Court-ready reporting of technical findings
- Capstone exercise tied to the training experience
The topic list inside these boxes draws on the publicly retrieved RCCI Course Outline, which provides a broader preparation curriculum without exam weights and carries no published date or numbered version. Because no dated curriculum version was verified, check Rocheston's course page for updates as your exam date nears.
Evidence Rules You Must Not Fumble
If you only have time to polish one area, polish this one. Domains 1 and 2 supply the principles that every scenario question in the later domains quietly assumes. Candidates who understand why evidence handling rules exist can reason through unfamiliar scenarios instead of memorizing answers.
Containment versus preservation
The classic trap: a responder's instinct is to shut down or isolate a compromised system immediately. Containment stops the damage, but a careless approach can destroy volatile evidence or alter the state of the machine. Expect scenarios that ask you to pick the action that balances both goals. The right answer typically protects evidence integrity while still limiting harm, and the reasoning matters as much as the action.
Chain of custody
Chain of custody is the documented trail showing who handled evidence, when, and under what conditions. A break in the chain gives an opposing party grounds to question whether the evidence was altered. Remember the purpose: it exists to demonstrate integrity and continuity, not merely to satisfy paperwork.
Imaging and hash verification
Forensic imaging creates a bit-for-bit copy of storage so analysis happens on the copy rather than the original. Hash verification then proves the copy matches the source: if the hash values match, the image is a faithful duplicate, and if either changes, integrity is in question. Know why you hash both at acquisition and again after any transfer or handling step.
Order of volatility
Volatile evidence, such as data held in memory, vanishes on power loss, so it is generally gathered before more persistent sources. When a question lists several evidence sources and asks what to collect first, think about which will disappear soonest.
Key Takeaway
When a scenario question feels ambiguous, ask two things: which action preserves evidence integrity, and which action can be defended afterward in a legal setting? The best answer usually satisfies both.
Artifact and Timeline Quick Map
Domain 3 is where raw data becomes a narrative. Use this map as a mental index of what each artifact category contributes to an investigation.
| Artifact Category | What It Helps Establish |
|---|---|
| Deleted files | Whether data existed and was removed, and what a user may have tried to hide |
| Registry artifacts | System and user activity traces on the machine |
| Logs | Time-stamped records that corroborate or contradict other findings |
| Timelines | The ordered sequence of events assembled from several sources |
| Volatile evidence | The system's live state at the moment of acquisition |
The central skill is correlation. A single artifact rarely proves a case; several independent artifacts pointing at the same sequence of events do. When you build or interpret a timeline, check that timestamps from different sources agree, and consider whether any source could have been tampered with or misconfigured. Questions in this area tend to reward candidates who think about corroboration rather than isolated facts.
Specialized Investigations Crib Notes
Domain 4 spans the widest range of subject matter, so a compact checklist helps. For each source below, ask what evidence exists, where it lives, who controls it, and how it can be preserved.
- Cloud evidence: Data may sit on infrastructure you do not control, which affects how it can be collected and preserved.
- Mobile evidence: Phones hold rich personal data and can change state while powered, so handling choices matter.
- Network evidence: Traffic records and related logs can show communication patterns between systems.
- Insider threats: Investigations here involve authorized users, so distinguishing normal access from misuse becomes the central analytical problem.
- Cryptocurrency and digital payment trails: Transactions leave traces that can be followed, even when the parties behind them are not immediately identifiable.
- Dark-web investigations: Anonymity-oriented environments change how investigators gather and attribute information.
- AI and deepfakes: Synthetic media creates new questions about authenticity and how to evaluate whether content is genuine.
Reporting and Capstone Reminders
Domain 5 is the reason this credential has "court-ready" in its title. A technically perfect investigation can still fail if its findings are not communicated clearly, accurately, and defensibly. Court-ready reporting means separating observed facts from conclusions, documenting methods so another examiner could reproduce them, and writing for an audience that may not be technical.
One distinction deserves care. The training includes Winston OS forensic labs and the Operation Silent Trace capstone, and these are training activities, separate from the two-hour exam. No separate practical-assessment timer is established. Do not assume you will be asked to perform a live lab during the two-hour test; plan around the documented format of 100 questions across multiple-choice, true/false, and short-answer items. Use the labs to build understanding, then expect that understanding to be tested through questions.
What the Numbers Do and Do Not Tell You
Because the exam is scored at 70%, your goal is steady competence across all five domains rather than perfection in any one. Candidates sometimes over-invest in the area they already know. If your background is in incident response, for example, you may breeze through Domain 2 but underestimate the legal framing in Domain 1 or the reporting standards in Domain 5. A candid self-assessment against the five domains will tell you where your points are most at risk. For a realistic sense of effort, read how hard the RCCI exam is, and note that the RCCI pass rate discussion explains why published success figures should be treated carefully.
Conflicting Records: Fees, Codes, and Question Counts
This is the part of the cheat sheet most candidates skip and later regret. Rocheston's own pages do not fully agree with each other, so you need to know where the discrepancies are before you book.
| Source | What It Says |
|---|---|
| Current RCCI course page | 100 questions, two hours, 70% passing score, online with Rocheston Ramsys proctoring; no exam code established |
| Rocheston Credly badge | Describes a 120-question exam under the code RCT-005 |
| Separate certification page at cert.rocheston.com | Links Pearson VUE and lists USD 799 for the exam, USD 400 for a retake, and USD 1299 for training |
This guide follows the current course page's 100-question, Ramsys specifications and does not attach the badge's RT-005 style code to the exam. If a booking confirmation shows a different question count or a code, take that as a prompt to ask Rocheston which assessment you are scheduled for. For more on budgeting, see the RCCI certification cost breakdown.
Also beware of a documentation trap: a Candidate Handbook is linked on Rocheston's site, but it is explicitly specific to a different Rocheston credential (RCCE). It is not a source for RCCI prerequisites, exam rules, or renewal. RCCI-specific renewal requirements were not established, so do not borrow another credential's renewal terms. For eligibility questions, the RCCI requirements guide lays out what is and is not documented.
Scheduling the Domains Across a Study Plan
Since the curriculum itself runs across five days, a five-block review that mirrors the domain order is a natural fit. The sequencing logic matters more than the exact calendar: legal and evidence foundations first, because later domains depend on them, and reporting last, because it synthesizes everything.
Domain 1: Law & Evidence
- Define chain of custody in your own words
- List what makes evidence defensible
Domain 2: Acquisition
- Walk through imaging and hash verification step by step
- Practice containment-versus-preservation scenarios
Domain 3: Analysis & Timelines
- Connect registry, log, and deleted-file findings into a sequence
Domain 4: Specialized Investigations
- Build a one-line evidence checklist per source type
Domain 5: Reporting
- Draft a short report separating facts from conclusions
- Take a timed practice run at the RCCI practice test
After the final block, simulate exam pacing with timed questions. The RCCI Exam Prep practice questions are useful for exactly this, and a final pass through weak areas pays off more than rereading material you already know. When you are ready to lock in a date, see RCCI exam dates and scheduling for how to approach timing.
Why This Credential Appeals to Employers and Candidates
Rocheston positions the RCCI for people who need to investigate cyber incidents in a way that holds up under scrutiny. Because law-enforcement experience is not required, the credential is approachable for IT, security, and incident-response professionals who want to move toward investigative work. Roles that value this skill set include digital forensics analysts, incident responders who support legal or HR matters, corporate investigators handling insider cases, and consultants who prepare evidence for disputes. For a closer look at the job landscape, see RCCI jobs, and for earnings context see the RCCI salary guide. Whether it justifies the investment for you is a personal calculation; the RCCI ROI analysis walks through the considerations.
Frequently Asked Questions
Rocheston's current RCCI course page specifies 100 questions in two hours. Rocheston's Credly badge describes a 120-question exam under the code RCT-005, so confirm which assessment applies when you book through cert.rocheston.com.
The current course page lists a 70% passing score. The page does not describe weighting by item, so aim for solid performance across all five preparation domains rather than relying on one strong area.
Yes. The course page describes online delivery with Rocheston Ramsys proctoring. A separate certification page references Pearson VUE, so verify the delivery method on your booking confirmation.
No. Law-enforcement experience is not required. Cybersecurity, IT, incident-response, or investigative knowledge is recommended, which suits professionals moving toward digital investigation work.
No. They are training activities separate from the exam, and no separate practical-assessment timer is established. Use them to build skill, then expect the exam itself to be question-based.
For the broader picture beyond this one-page review, the RCCI study guide and the RCCI certification overview are good next steps.