CSC Study Guide 2026

Everything you need to pass the CSC exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.

📚 CSC Topics to Study (69)

✍️ Sample CSC Questions & Answers

1. What is the purpose of a System Security Plan (SSP) in the federal compliance context?
It documents the security requirements and controls implemented for an information system

An SSP describes the security requirements of a system and documents how controls are implemented to satisfy those requirements, typically required by FISMA.

2. Which of the following best describes the primary purpose of the 'Prepare' step in the NIST Risk Management Framework (RMF)?
To establish the context and foundation for managing security and privacy risk at both the organization and system levels.

The 'Prepare' step (Step 1) is foundational and focuses on activities at both the organization and system levels to ensure that the organization is ready to manage its security and privacy risks. This includes establishing a risk management strategy, identifying key roles, determining risk tolerance, and identifying common controls.

3. Which regulatory framework specifically requires covered entities to have Business Associate Agreements with vendors that handle protected health information?
HIPAA

HIPAA mandates Business Associate Agreements (BAAs) with any vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity.

4. An auditor requests evidence that privileged user activity is being monitored. Which control BEST satisfies this requirement?
Implementing a Privileged Access Management (PAM) solution with session recording

PAM solutions with session recording provide direct evidence of privileged activity monitoring, including command logs and video playback.

5. Under GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing:
Data that is likely to result in high risk to individuals' rights and freedoms

GDPR Article 35 requires a DPIA when processing is likely to result in high risk to the rights and freedoms of natural persons, particularly for large-scale processing or systematic monitoring.

6. What is the primary purpose of a vendor offboarding process from a cybersecurity perspective?
To revoke all vendor access and retrieve or destroy organizational data

Secure offboarding ensures that vendor access credentials are revoked, shared data is returned or destroyed, and no residual access vectors remain.

🎯 Free CSC Practice Tests

📖 CSC Guides & Articles

Your CSC Study Path
1. Learn with Flashcards → 2. Drill Practice Tests → 3. Take the Full Exam Simulation
Was this helpful?