CSL Cheat Sheet 2026
The 30 highest-yield CSL facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
100 questions
120 min time limit
70.00% to pass
- Which principle of international law determines which country's laws apply when a cyberattack originates in one country but causes harm in another? → Effects-based jurisdiction
- What is the main goal of ethical hacking? → To help organizations identify and fix vulnerabilities
- What is a Data Protection Impact Assessment (DPIA) in the context of cybersecurity? → A process to evaluate risks to data protection and privacy
- The Tallinn Manual, published by NATO's CCDCOE, addresses which aspect of international law as applied to cyberspace? → International law applicable to cyber warfare and state-sponsored attacks
- What does the Computer Fraud and Abuse Act (CFAA) primarily address? → Prohibiting unauthorized access to computers and data theft
- What mechanism does the EU's General Data Protection Regulation (GDPR) provide for lawfully transferring personal data to the United States? → Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework
- A defense contractor handling Controlled Unclassified Information (CUI) must comply with which cybersecurity framework to obtain DoD contracts? → CMMC (Cybersecurity Maturity Model Certification)
- Which agency enforces the Children's Online Privacy Protection Act (COPPA) in the United States? → Federal Trade Commission
- What is the primary purpose of a non-disclosure agreement (NDA) in the context of trade secret protection? → To establish that reasonable measures were taken to protect the secret
- Which international treaty requires member nations to provide legal protections for technological protection measures similar to the DMCA? → WIPO Copyright Treaty (WCT)
- What is the main objective of data breach notification requirements under data protection laws? → To inform individuals so they can protect their data
- Which legal doctrine allows incident responders to access third-party systems without a warrant when the system owner provides consent? → Third-party consent doctrine
- Under the NIST Risk Management Framework (RMF), what step directly follows the 'Categorize' step? → Select
- Under what legal authority can U.S. law enforcement compel a suspect to provide biometric authentication (e.g., fingerprint) to unlock a device? → Biometrics are non-testimonial and not Fifth Amendment protected
- Why is ethical hacking important for organizations? → To identify and fix security weaknesses before malicious actors exploit them
- The Health Insurance Portability and Accountability Act (HIPAA) Security Rule specifically governs which type of health information? → Electronic protected health information (ePHI) only
- What DMCA exemption allows security researchers to bypass TPMs for good-faith security research? → Section 1201(j) security research exemption
- The SEC's cybersecurity disclosure rules (effective 2023) require public companies to disclose material cybersecurity incidents within how many business days? → 4 business days
- Under the NIST Cybersecurity Framework, which function focuses on developing and implementing appropriate safeguards to ensure delivery of critical services? → Protect
- The NIST Cybersecurity Framework is best characterized as which type of instrument? → A voluntary framework providing guidelines for managing cybersecurity risk
- Which U.S. agency leads cybercrime investigations under Title 18 (federal criminal statutes) and operates the Internet Crime Complaint Center (IC3)? → Federal Bureau of Investigation (FBI)
- The Defend Trade Secrets Act (DTSA) of 2016 created a federal civil cause of action for trade secret misappropriation. What is the statute of limitations? → 3 years
- What contractual provision governs how a vendor handles client data after contract termination? → Data return and destruction clause
- When conducting a forensic examination of a suspect's smartphone, which constitutional amendment primarily protects against warrantless searches? → Fourth Amendment
- Which safe harbor provision under U.S. law protects companies that share cyberthreat information with the government from antitrust and liability concerns? → Cybersecurity Information Sharing Act (CISA) of 2015
- Under GDPR, what is the maximum timeframe for notifying the supervisory authority after discovering a personal data breach? → 72 hours
- What is a security breach in the context of incident response? → When unauthorized access leads to data or system compromise
- Under the EU's GDPR, what obligation does the 'one-stop-shop' mechanism create for multinationals operating across EU member states? → They deal primarily with the DPA of their EU main establishment
- Under HIPAA, which covered entity bears primary liability when a business associate suffers a data breach? → Both can face independent liability to HHS
- Which doctrine permits law enforcement to seize digital evidence immediately visible on a computer screen without a warrant during a lawful premises search? → Plain view doctrine
Turn these facts into recall:
Was this helpful?