CSC Study Guide 2026
Everything you need to pass the CSC exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.
📚 CSC Topics to Study (69)
✍️ Sample CSC Questions & Answers
1. What is the purpose of a System Security Plan (SSP) in the federal compliance context?
An SSP describes the security requirements of a system and documents how controls are implemented to satisfy those requirements, typically required by FISMA.
2. Which of the following best describes the primary purpose of the 'Prepare' step in the NIST Risk Management Framework (RMF)?
The 'Prepare' step (Step 1) is foundational and focuses on activities at both the organization and system levels to ensure that the organization is ready to manage its security and privacy risks. This includes establishing a risk management strategy, identifying key roles, determining risk tolerance, and identifying common controls.
3. Which regulatory framework specifically requires covered entities to have Business Associate Agreements with vendors that handle protected health information?
HIPAA mandates Business Associate Agreements (BAAs) with any vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity.
4. An auditor requests evidence that privileged user activity is being monitored. Which control BEST satisfies this requirement?
PAM solutions with session recording provide direct evidence of privileged activity monitoring, including command logs and video playback.
5. Under GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing:
GDPR Article 35 requires a DPIA when processing is likely to result in high risk to the rights and freedoms of natural persons, particularly for large-scale processing or systematic monitoring.
6. What is the primary purpose of a vendor offboarding process from a cybersecurity perspective?
Secure offboarding ensures that vendor access credentials are revoked, shared data is returned or destroyed, and no residual access vectors remain.