CSL Cheat Sheet 2026

The 30 highest-yield CSL facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

100 questions
120 min time limit
70.00% to pass
  1. Which principle of international law determines which country's laws apply when a cyberattack originates in one country but causes harm in another? Effects-based jurisdiction
  2. What is the main goal of ethical hacking? To help organizations identify and fix vulnerabilities
  3. What is a Data Protection Impact Assessment (DPIA) in the context of cybersecurity? A process to evaluate risks to data protection and privacy
  4. The Tallinn Manual, published by NATO's CCDCOE, addresses which aspect of international law as applied to cyberspace? International law applicable to cyber warfare and state-sponsored attacks
  5. What does the Computer Fraud and Abuse Act (CFAA) primarily address? Prohibiting unauthorized access to computers and data theft
  6. What mechanism does the EU's General Data Protection Regulation (GDPR) provide for lawfully transferring personal data to the United States? Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework
  7. A defense contractor handling Controlled Unclassified Information (CUI) must comply with which cybersecurity framework to obtain DoD contracts? CMMC (Cybersecurity Maturity Model Certification)
  8. Which agency enforces the Children's Online Privacy Protection Act (COPPA) in the United States? Federal Trade Commission
  9. What is the primary purpose of a non-disclosure agreement (NDA) in the context of trade secret protection? To establish that reasonable measures were taken to protect the secret
  10. Which international treaty requires member nations to provide legal protections for technological protection measures similar to the DMCA? WIPO Copyright Treaty (WCT)
  11. What is the main objective of data breach notification requirements under data protection laws? To inform individuals so they can protect their data
  12. Which legal doctrine allows incident responders to access third-party systems without a warrant when the system owner provides consent? Third-party consent doctrine
  13. Under the NIST Risk Management Framework (RMF), what step directly follows the 'Categorize' step? Select
  14. Under what legal authority can U.S. law enforcement compel a suspect to provide biometric authentication (e.g., fingerprint) to unlock a device? Biometrics are non-testimonial and not Fifth Amendment protected
  15. Why is ethical hacking important for organizations? To identify and fix security weaknesses before malicious actors exploit them
  16. The Health Insurance Portability and Accountability Act (HIPAA) Security Rule specifically governs which type of health information? Electronic protected health information (ePHI) only
  17. What DMCA exemption allows security researchers to bypass TPMs for good-faith security research? Section 1201(j) security research exemption
  18. The SEC's cybersecurity disclosure rules (effective 2023) require public companies to disclose material cybersecurity incidents within how many business days? 4 business days
  19. Under the NIST Cybersecurity Framework, which function focuses on developing and implementing appropriate safeguards to ensure delivery of critical services? Protect
  20. The NIST Cybersecurity Framework is best characterized as which type of instrument? A voluntary framework providing guidelines for managing cybersecurity risk
  21. Which U.S. agency leads cybercrime investigations under Title 18 (federal criminal statutes) and operates the Internet Crime Complaint Center (IC3)? Federal Bureau of Investigation (FBI)
  22. The Defend Trade Secrets Act (DTSA) of 2016 created a federal civil cause of action for trade secret misappropriation. What is the statute of limitations? 3 years
  23. What contractual provision governs how a vendor handles client data after contract termination? Data return and destruction clause
  24. When conducting a forensic examination of a suspect's smartphone, which constitutional amendment primarily protects against warrantless searches? Fourth Amendment
  25. Which safe harbor provision under U.S. law protects companies that share cyberthreat information with the government from antitrust and liability concerns? Cybersecurity Information Sharing Act (CISA) of 2015
  26. Under GDPR, what is the maximum timeframe for notifying the supervisory authority after discovering a personal data breach? 72 hours
  27. What is a security breach in the context of incident response? When unauthorized access leads to data or system compromise
  28. Under the EU's GDPR, what obligation does the 'one-stop-shop' mechanism create for multinationals operating across EU member states? They deal primarily with the DPA of their EU main establishment
  29. Under HIPAA, which covered entity bears primary liability when a business associate suffers a data breach? Both can face independent liability to HHS
  30. Which doctrine permits law enforcement to seize digital evidence immediately visible on a computer screen without a warrant during a lawful premises search? Plain view doctrine
Turn these facts into recall:
Was this helpful?