CSC Cheat Sheet 2026
The 30 highest-yield CSC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
100 questions
120 min time limit
70.00% to pass
- What is the primary advantage of using an 'anti-passback' feature in an electronic access control system? → Preventing the same credential from being used to enter and exit in the wrong sequence
- What is the MAIN security risk associated with using a cloud-based video storage service for surveillance footage? → Potential unauthorized access to footage if the provider is breached
- When a security officer witnesses another officer using excessive force, the witnessing officer's legal and ethical duty is best described as: → Intervene to stop the excessive force and report the incident
- A security consultant recommends mass notification system (MNS) testing. What is the recommended minimum test frequency? → Monthly
- When documenting a social engineering assessment in a report, what information must be handled with particular sensitivity? → The identities of employees who failed simulated phishing tests
- The concept of 'threat vulnerability asset' (TVA) mapping in business continuity planning is primarily used to: → Correlate identified threats and vulnerabilities to specific critical assets
- A facility security director wants to test the effectiveness of the physical security program without alerting staff. This type of assessment is called a: → Red team or penetration test
- What is the primary purpose of security auditing? → To identify vulnerabilities and verify compliance with security policies
- What is the role of the General Data Protection Regulation (GDPR)? → It protects personal data and privacy of EU citizens
- Which concept describes a layered approach where each ring of security around a VIP is designed to detect or stop a threat before it reaches the inner ring? → Concentric zone security
- Which type of perimeter sensor is BEST suited for detecting intrusion along an unlit chain-link fence at night? → Fiber optic fence sensor
- In electronic access control, what is the purpose of a 'request-to-exit' (REX) sensor? → To allow free egress without triggering an alarm
- During a post-incident review following a business disruption, the MOST important outcome a security consultant should document is: → Lessons learned and recommended improvements to the continuity plan
- Which of the following is a common risk mitigation strategy? → Implementing access controls
- What is the principle of least privilege? → Granting users only the minimum access necessary to perform their duties
- What is the role of encryption in data security? → Protecting data confidentiality during storage and transmission
- What should be done if an error is discovered in existing records? → Draw a single line through the error, note the correction, date, and initial
- What is residual risk? → The remaining risk after mitigation
- How should security incidents be handled? → Following an established incident response plan with documentation
- What is the MAIN reason security consultants use standardized templates for report writing? → To ensure consistency, completeness, and professional quality across all deliverables
- Which law primarily governs data privacy and protection in the U.S. healthcare sector? → HIPAA
- According to standard physical security practice, a security post order should be reviewed and updated at a MINIMUM of: → Annually or after any significant incident or operational change
- Which risk treatment option involves sharing the financial impact of a risk with a third party, such as through insurance? → Risk transference
- Which scenario BEST exemplifies a risk avoidance strategy? → Discontinuing an e-commerce feature that cannot be secured adequately
- A security officer detains a shoplifting suspect for 4 hours without contacting police or releasing the suspect. This extended detention most likely violates: → False imprisonment statutes
- How should Court Security Specialist professionals approach quality improvement? → Through systematic evaluation of outcomes and implementation of evidence-based changes
- Under Title VII of the Civil Rights Act, a security company with 15 or more employees is prohibited from discriminating in hiring based on: → Race, color, religion, sex, or national origin
- What is the most important principle in professional Court Security Specialist practice? → Maintaining competence through continuous learning and adherence to standards
- What is the recommended practice regarding the principal's daily schedule and travel routes from a security standpoint? → Vary routes, times, and patterns regularly to prevent predictability
- Which of the following BEST describes the concept of 'inherent risk'? → The risk level that exists before any controls are implemented
Turn these facts into recall:
Was this helpful?