CSC Cheat Sheet 2026
The 30 highest-yield CSC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
- Which cloud security concept involves automatically discovering and classifying sensitive data stored across cloud services to support compliance reporting? → Data Loss Prevention (DLP)
- Why is policy development important in cybersecurity? → To establish security standards and accountability
- When assessing whether a further processing purpose is compatible with the original purpose, GDPR Article 6(4) requires controllers to consider all EXCEPT: → The revenue impact on the controller's business
- What is the main objective of Annex A control A.18.2 (Information Security Reviews)? → To verify compliance of information processing with security policies and standards
- An organization wants to ensure audit trails cannot be tampered with by system administrators. Which control BEST achieves this? → Forwarding logs to a remote, isolated SIEM where admins lack write access
- Which metric is used in quantitative risk analysis to represent the expected monetary loss from a single risk event? → Single Loss Expectancy (SLE)
- The Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 requires defense contractors to: → Implement NIST SP 800-171 controls and report cyber incidents within 72 hours
- Which encryption approach ensures that a cloud provider cannot decrypt customer data even when compelled by a legal order? → Client-side encryption with customer-managed keys
- Which NIST CSF function is MOST associated with activities like log review, SIEM alerting, and anomaly detection? → Detect
- GDPR's 'right to erasure' (right to be forgotten) allows individuals to request deletion of their personal data EXCEPT when: → Processing is necessary for compliance with a legal obligation
- A company's board of directors wants to ensure cybersecurity risk is addressed at the highest level. Which governance structure best achieves this? → Establishing a board-level cybersecurity committee with executive oversight
- Which legal theory holds organizations liable for cybersecurity failures when they knew or should have known about a vulnerability but failed to address it? → Negligence
- Under GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing: → Data that is likely to result in high risk to individuals' rights and freedoms
- A HIPAA Security Officer at a covered entity is drafting workforce sanction policies. What must these policies include to meet HIPAA requirements? → Consequences for workforce members who fail to comply with security policies
- An auditor requests evidence that privileged user activity is being monitored. Which control BEST satisfies this requirement? → Implementing a Privileged Access Management (PAM) solution with session recording
- ISO 27001 control A.14 covers which domain? → System Acquisition, Development and Maintenance
- A company using IaaS must patch its operating systems. Under the shared responsibility model, which party is responsible for this task? → The customer, because IaaS shifts OS management to the tenant
- An e-commerce site collects a customer's full medical history during checkout 'just in case it's useful later.' Which GDPR principle is most directly violated? → Data minimisation
- What is a Qualified Security Assessor (QSA) in the context of PCI DSS? → A company certified by PCI SSC to conduct PCI DSS compliance assessments
- Under FERPA, which category of records may schools disclose without student consent? → Directory information, unless the student opts out
- Which access control model grants permissions based on security labels assigned to resources and user clearance levels? → Mandatory Access Control (MAC)
- What is the primary objective of cybersecurity regulations? → To secure systems and protect data
- Which step in the RMF was added in Revision 2 of NIST SP 800-37 to better align security with the system development lifecycle? → Prepare
- Which scenario best illustrates a violation of the HIPAA Security Rule's Workstation Use standard? → A receptionist uses a shared workstation to browse social media while logged into the EHR
- Under the GDPR, the 'accountability' principle requires a data controller to do which of the following? → Be responsible for and able to demonstrate compliance with the GDPR principles.
- Under the California Consumer Privacy Act (CCPA), what right allows consumers to request that a business delete their personal information? → Right to deletion
- Which RMF step involves continuously tracking changes to the system and its environment that may affect security posture? → Monitor
- Which element is most critical to include in a Vendor Risk Register? → Risk rating, inherent and residual risk scores, and status of remediation actions
- What is the primary purpose of a Cloud Access Security Broker (CASB)? → To enforce security policies between cloud users and cloud service providers
- Which ISO 27001 Annex A control specifically requires organizations to screen personnel before employment? → A.7.1.1 Screening
Turn these facts into recall:
Was this helpful?