CSC Cheat Sheet 2026

The 30 highest-yield CSC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

  1. Which cloud security concept involves automatically discovering and classifying sensitive data stored across cloud services to support compliance reporting? Data Loss Prevention (DLP)
  2. Why is policy development important in cybersecurity? To establish security standards and accountability
  3. When assessing whether a further processing purpose is compatible with the original purpose, GDPR Article 6(4) requires controllers to consider all EXCEPT: The revenue impact on the controller's business
  4. What is the main objective of Annex A control A.18.2 (Information Security Reviews)? To verify compliance of information processing with security policies and standards
  5. An organization wants to ensure audit trails cannot be tampered with by system administrators. Which control BEST achieves this? Forwarding logs to a remote, isolated SIEM where admins lack write access
  6. Which metric is used in quantitative risk analysis to represent the expected monetary loss from a single risk event? Single Loss Expectancy (SLE)
  7. The Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 requires defense contractors to: Implement NIST SP 800-171 controls and report cyber incidents within 72 hours
  8. Which encryption approach ensures that a cloud provider cannot decrypt customer data even when compelled by a legal order? Client-side encryption with customer-managed keys
  9. Which NIST CSF function is MOST associated with activities like log review, SIEM alerting, and anomaly detection? Detect
  10. GDPR's 'right to erasure' (right to be forgotten) allows individuals to request deletion of their personal data EXCEPT when: Processing is necessary for compliance with a legal obligation
  11. A company's board of directors wants to ensure cybersecurity risk is addressed at the highest level. Which governance structure best achieves this? Establishing a board-level cybersecurity committee with executive oversight
  12. Which legal theory holds organizations liable for cybersecurity failures when they knew or should have known about a vulnerability but failed to address it? Negligence
  13. Under GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing: Data that is likely to result in high risk to individuals' rights and freedoms
  14. A HIPAA Security Officer at a covered entity is drafting workforce sanction policies. What must these policies include to meet HIPAA requirements? Consequences for workforce members who fail to comply with security policies
  15. An auditor requests evidence that privileged user activity is being monitored. Which control BEST satisfies this requirement? Implementing a Privileged Access Management (PAM) solution with session recording
  16. ISO 27001 control A.14 covers which domain? System Acquisition, Development and Maintenance
  17. A company using IaaS must patch its operating systems. Under the shared responsibility model, which party is responsible for this task? The customer, because IaaS shifts OS management to the tenant
  18. An e-commerce site collects a customer's full medical history during checkout 'just in case it's useful later.' Which GDPR principle is most directly violated? Data minimisation
  19. What is a Qualified Security Assessor (QSA) in the context of PCI DSS? A company certified by PCI SSC to conduct PCI DSS compliance assessments
  20. Under FERPA, which category of records may schools disclose without student consent? Directory information, unless the student opts out
  21. Which access control model grants permissions based on security labels assigned to resources and user clearance levels? Mandatory Access Control (MAC)
  22. What is the primary objective of cybersecurity regulations? To secure systems and protect data
  23. Which step in the RMF was added in Revision 2 of NIST SP 800-37 to better align security with the system development lifecycle? Prepare
  24. Which scenario best illustrates a violation of the HIPAA Security Rule's Workstation Use standard? A receptionist uses a shared workstation to browse social media while logged into the EHR
  25. Under the GDPR, the 'accountability' principle requires a data controller to do which of the following? Be responsible for and able to demonstrate compliance with the GDPR principles.
  26. Under the California Consumer Privacy Act (CCPA), what right allows consumers to request that a business delete their personal information? Right to deletion
  27. Which RMF step involves continuously tracking changes to the system and its environment that may affect security posture? Monitor
  28. Which element is most critical to include in a Vendor Risk Register? Risk rating, inherent and residual risk scores, and status of remediation actions
  29. What is the primary purpose of a Cloud Access Security Broker (CASB)? To enforce security policies between cloud users and cloud service providers
  30. Which ISO 27001 Annex A control specifically requires organizations to screen personnel before employment? A.7.1.1 Screening
Turn these facts into recall:
Was this helpful?