CSC Cheat Sheet 2026

The 30 highest-yield CSC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

  1. Which cloud security concept involves automatically discovering and classifying sensitive data stored across cloud services to support compliance reporting? → Data Loss Prevention (DLP)
  2. Why is policy development important in cybersecurity? → To establish security standards and accountability
  3. When assessing whether a further processing purpose is compatible with the original purpose, GDPR Article 6(4) requires controllers to consider all EXCEPT: → The revenue impact on the controller's business
  4. What is the main objective of Annex A control A.18.2 (Information Security Reviews)? → To verify compliance of information processing with security policies and standards
  5. An organization wants to ensure audit trails cannot be tampered with by system administrators. Which control BEST achieves this? → Forwarding logs to a remote, isolated SIEM where admins lack write access
  6. Which metric is used in quantitative risk analysis to represent the expected monetary loss from a single risk event? → Single Loss Expectancy (SLE)
  7. The Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 requires defense contractors to: → Implement NIST SP 800-171 controls and report cyber incidents within 72 hours
  8. Which encryption approach ensures that a cloud provider cannot decrypt customer data even when compelled by a legal order? → Client-side encryption with customer-managed keys
  9. Which NIST CSF function is MOST associated with activities like log review, SIEM alerting, and anomaly detection? → Detect
  10. GDPR's 'right to erasure' (right to be forgotten) allows individuals to request deletion of their personal data EXCEPT when: → Processing is necessary for compliance with a legal obligation
  11. A company's board of directors wants to ensure cybersecurity risk is addressed at the highest level. Which governance structure best achieves this? → Establishing a board-level cybersecurity committee with executive oversight
  12. Which legal theory holds organizations liable for cybersecurity failures when they knew or should have known about a vulnerability but failed to address it? → Negligence
  13. Under GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing: → Data that is likely to result in high risk to individuals' rights and freedoms
  14. A HIPAA Security Officer at a covered entity is drafting workforce sanction policies. What must these policies include to meet HIPAA requirements? → Consequences for workforce members who fail to comply with security policies
  15. An auditor requests evidence that privileged user activity is being monitored. Which control BEST satisfies this requirement? → Implementing a Privileged Access Management (PAM) solution with session recording
  16. ISO 27001 control A.14 covers which domain? → System Acquisition, Development and Maintenance
  17. A company using IaaS must patch its operating systems. Under the shared responsibility model, which party is responsible for this task? → The customer, because IaaS shifts OS management to the tenant
  18. An e-commerce site collects a customer's full medical history during checkout 'just in case it's useful later.' Which GDPR principle is most directly violated? → Data minimisation
  19. What is a Qualified Security Assessor (QSA) in the context of PCI DSS? → A company certified by PCI SSC to conduct PCI DSS compliance assessments
  20. Under FERPA, which category of records may schools disclose without student consent? → Directory information, unless the student opts out
  21. Which access control model grants permissions based on security labels assigned to resources and user clearance levels? → Mandatory Access Control (MAC)
  22. What is the primary objective of cybersecurity regulations? → To secure systems and protect data
  23. Which step in the RMF was added in Revision 2 of NIST SP 800-37 to better align security with the system development lifecycle? → Prepare
  24. Which scenario best illustrates a violation of the HIPAA Security Rule's Workstation Use standard? → A receptionist uses a shared workstation to browse social media while logged into the EHR
  25. Under the GDPR, the 'accountability' principle requires a data controller to do which of the following? → Be responsible for and able to demonstrate compliance with the GDPR principles.
  26. Under the California Consumer Privacy Act (CCPA), what right allows consumers to request that a business delete their personal information? → Right to deletion
  27. Which RMF step involves continuously tracking changes to the system and its environment that may affect security posture? → Monitor
  28. Which element is most critical to include in a Vendor Risk Register? → Risk rating, inherent and residual risk scores, and status of remediation actions
  29. What is the primary purpose of a Cloud Access Security Broker (CASB)? → To enforce security policies between cloud users and cloud service providers
  30. Which ISO 27001 Annex A control specifically requires organizations to screen personnel before employment? → A.7.1.1 Screening
Turn these facts into recall:
Was this helpful?