Cybersecurity Law Certification (CSL) โ Questions and Answers
Question 1: Which privacy concept requires that organizations collect only the minimum amount of personal data necessary for the specified purpose?
- Storage limitation
- Data minimization (Correct answer)
- Data accuracy
- Purpose limitation
Correct answer: Data minimization
Data minimization (GDPR Article 5(1)(c)) mandates that personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
Question 2: What is the primary purpose of a non-disclosure agreement (NDA) in the context of trade secret protection?
- To create a patent priority date
- To establish that reasonable measures were taken to protect the secret (Correct answer)
- To comply with DTSA registration requirements
- To create copyright protection for shared information
Correct answer: To establish that reasonable measures were taken to protect the secret
NDAs demonstrate that the trade secret owner took reasonable measures to maintain secrecy, which is a required element for trade secret protection under both state and federal law.
Question 3: What is a common limitation in cyber insurance policies that companies must understand when assessing coverage for nation-state cyberattacks?
- Coverage is limited to $1 million regardless of policy limits
- Only CISA-designated incidents qualify for coverage
- War exclusion clauses may exclude nation-state attacks (Correct answer)
- Cyber policies never cover any cyberattacks
Correct answer: War exclusion clauses may exclude nation-state attacks
Many cyber insurance policies include war exclusion clauses that insurers have attempted to invoke to deny coverage for nation-state attacks, as seen in the NotPetya litigation.
Question 4: What is the key to effective incident response?
- A proactive and well-organized response (Correct answer)
- Ignoring the incident until it escalates
- Reactive actions without planning
- Providing public statements before analysis
Correct answer: A proactive and well-organized response
Effective incident response relies on proactive planning, including having a clear strategy, defined roles, and established procedures before an incident occurs. A well-organized response ensures that the team can act swiftly, coordinate efforts, and follow a structured approach to contain, eradicate, and recover from the incident, minimizing its impact. Reactive, unplanned actions often lead to greater damage and longer recovery times.
Question 5: What export control regulation specifically covers the export of cybersecurity tools, including intrusion and surveillance software?
- Export Administration Regulations (EAR) (Correct answer)
- International Traffic in Arms Regulations (ITAR)
- Office of Foreign Assets Control (OFAC) rules
- Wassenaar Arrangement directly
Correct answer: Export Administration Regulations (EAR)
The EAR, administered by the Bureau of Industry and Security, implements Wassenaar Arrangement controls on dual-use items including cybersecurity tools.
Question 6: What legal standard describes a vendor's obligation to implement reasonable security measures to protect client data under a contract?
- Subrogation
- Due diligence / duty of care (Correct answer)
- Safe harbor
- Sovereign immunity
Correct answer: Due diligence / duty of care
Due diligence and duty of care are legal standards requiring vendors to implement reasonable, appropriate security measures to protect client data they access or process.
Question 7: A company subject to PCI DSS stores cardholder data. Which PCI DSS requirement directly addresses the protection of stored cardholder data?
- Requirement 3 (Correct answer)
- Requirement 10
- Requirement 6
- Requirement 1
Correct answer: Requirement 3
PCI DSS Requirement 3 specifically mandates protecting stored cardholder data through encryption, masking, and other techniques.
Question 8: Which U.S. Supreme Court case established that warrantless cell-site location information (CSLI) collection violates the Fourth Amendment?
- United States v. Jones
- Kyllo v. United States
- Carpenter v. United States (Correct answer)
- Riley v. California
Correct answer: Carpenter v. United States
In Carpenter v. United States (2018), the Supreme Court held that accessing historical CSLI without a warrant violates the Fourth Amendment.
Question 9: Which GDPR right allows an individual to request that their personal data be transferred from one controller to another in a machine-readable format?
- Right to data portability (Correct answer)
- Right to rectification
- Right to erasure
- Right to restriction of processing
Correct answer: Right to data portability
GDPR Article 20 grants the right to data portability, enabling individuals to receive and transfer their data between controllers.
Question 10: What is the primary legal challenge in attributing state responsibility for cyberattacks under international law?
- Cyberattacks never reach the threshold for state responsibility
- The requirement to prove that the state 'directed or controlled' the specific operation (Correct answer)
- International law does not recognize cyber operations as state acts
- MLAT treaties prevent attribution claims
Correct answer: The requirement to prove that the state 'directed or controlled' the specific operation
Under the ILC Articles on State Responsibility, holding a state responsible requires showing the state directed or controlled the private actors conducting the cyber operation (Article 8).
Question 11: Presidential Policy Directive 21 (PPD-21) designates how many critical infrastructure sectors in the United States?
- 16 sectors (Correct answer)
- 14 sectors
- 10 sectors
- 20 sectors
Correct answer: 16 sectors
PPD-21 identifies 16 critical infrastructure sectors whose disruption would have a debilitating effect on national security, economic security, or public health and safety.
Question 12: The Defend Trade Secrets Act (DTSA) of 2016 created a federal civil cause of action for trade secret misappropriation. What is the statute of limitations?
- 5 years
- 3 years (Correct answer)
- 1 year
- 2 years
Correct answer: 3 years
The DTSA has a 3-year statute of limitations running from the date the misappropriation was discovered or should have been discovered.
Question 13: Which federal statute, enacted in 1986, addresses unauthorized access to 'protected computers' and is the primary U.S. law used to prosecute hacking offenses?
- Cybersecurity Information Sharing Act
- Computer Fraud and Abuse Act (Correct answer)
- Electronic Communications Privacy Act
- Federal Information Security Modernization Act
Correct answer: Computer Fraud and Abuse Act
The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. ยง 1030, is the cornerstone federal statute criminalizing unauthorized access to and damage of protected computers.
Question 14: Which concept in corporate cybersecurity law refers to the baseline security practices that a reasonable company in a given industry should implement?
- Safe harbor baseline
- Minimum viable security
- Industry standard of care (Correct answer)
- Regulatory floor
Correct answer: Industry standard of care
The industry standard of care sets the benchmark for negligence claims by measuring a company's security practices against what is reasonable for its industry.
Question 15: Under the National Security Act and related authorities, which body coordinates national-level intelligence on cyber threats and integrates cybersecurity with national security?
- CISA alone
- FBI Cyber Division only
- NSC Cybersecurity Directorate and ONCD (Correct answer)
- NIST Cybersecurity Center
Correct answer: NSC Cybersecurity Directorate and ONCD
The National Security Council's Cyber Directorate and the Office of the National Cyber Director (ONCD), created in 2021, coordinate national cybersecurity strategy and policy.
Question 16: The EU's NIS2 Directive (2022) replaced the original NIS Directive and expanded its scope. Which of the following is a key addition in NIS2?
- It only applies to companies with over 500 employees
- It eliminates member state discretion in implementation
- It only applies to critical infrastructure operators
- It imposes supply chain security requirements on essential and important entities (Correct answer)
Correct answer: It imposes supply chain security requirements on essential and important entities
NIS2 significantly expanded the original directive by adding supply chain security obligations, requiring entities to assess cybersecurity risks in their supplier relationships.
Question 17: The TSA cybersecurity directives issued after the Colonial Pipeline attack apply to which sector and require what primary security measure?
- Pipeline and rail sectors; network segmentation and incident reporting (Correct answer)
- Financial sector; zero trust architecture
- Healthcare sector; ransomware playbooks
- Water sector; mandatory CISA reporting
Correct answer: Pipeline and rail sectors; network segmentation and incident reporting
TSA issued emergency cybersecurity directives to pipeline and surface transportation operators requiring network segmentation, cybersecurity coordinator designation, and CISA incident reporting.
Question 18: A ransomware group encrypts hospital systems and demands Bitcoin payment. Under the CFAA, which provision most directly covers the act of knowingly causing damage to a protected computer used in interstate commerce?
- 18 U.S.C. ยง 1030(a)(5) โ intentional damage to a protected computer (Correct answer)
- 18 U.S.C. ยง 1030(a)(7) โ extortionate threats
- 18 U.S.C. ยง 1030(a)(2) โ unauthorized access to obtain information
- 18 U.S.C. ยง 1030(a)(4) โ fraud and obtaining value
Correct answer: 18 U.S.C. ยง 1030(a)(5) โ intentional damage to a protected computer
Section 1030(a)(5) criminalizes intentionally causing damage to a protected computer, making it the primary provision for ransomware and destructive malware attacks.
Question 19: What is the first step in incident response?
- Eradication of the threat
- Identification of the incident
- Preparation and setting up response systems (Correct answer)
- Containment of the incident
Correct answer: Preparation and setting up response systems
The first and most crucial step in incident response is preparation. This involves developing an incident response plan, establishing a dedicated team, defining roles and responsibilities, and setting up the necessary tools and technologies. Effective preparation ensures that an organization can respond quickly and efficiently when an actual incident occurs, minimizing potential damage.
Question 20: Under 18 U.S.C. ยง 1030(c), what threshold of loss within a one-year period elevates a CFAA violation to a felony offense?
- $500
- $10,000
- $1,000
- $5,000 (Correct answer)
Correct answer: $5,000
A CFAA violation becomes a felony when it causes loss aggregating at least $5,000 in value within any one-year period to one or more persons.
Question 21: What does 'source code escrow' refer to in software vendor contracts with security implications?
- An insurance policy covering software vulnerabilities and zero-day exploits
- A payment holdback mechanism for poor security performance
- A neutral third-party arrangement where source code is deposited for client access if the vendor goes out of business (Correct answer)
- A government-mandated data backup requirement for critical software
Correct answer: A neutral third-party arrangement where source code is deposited for client access if the vendor goes out of business
Software escrow involves depositing source code with a neutral third party so the client can access it if the vendor becomes insolvent or fails to maintain the software, protecting business continuity.
Question 22: A company subject to the EU-U.S. Data Privacy Framework (DPF) must recertify with the U.S. Department of Commerce how frequently?
- Every 6 months
- Every 3 years
- Annually (Correct answer)
- Every 2 years
Correct answer: Annually
Organizations participating in the EU-U.S. Data Privacy Framework must self-certify and renew their certification annually with the Department of Commerce.
Question 23: The Tallinn Manual, published by NATO's CCDCOE, addresses which aspect of international law as applied to cyberspace?
- International law applicable to cyber warfare and state-sponsored attacks (Correct answer)
- International human rights law in cyber operations
- EU cybersecurity regulatory standards
- Mutual legal assistance treaty (MLAT) procedures
Correct answer: International law applicable to cyber warfare and state-sponsored attacks
The Tallinn Manual analyzes how existing international law (jus ad bellum, jus in bello, state responsibility) applies to state-sponsored cyber operations.
Question 24: What is the role of the Cybersecurity and Infrastructure Security Agency (CISA)?
- To monitor personal internet usage
- To manage internet censorship across countries
- To enforce cybercrime laws by arresting hackers
- To improve cybersecurity defenses and respond to threats (Correct answer)
Correct answer: To improve cybersecurity defenses and respond to threats
The Cybersecurity and Infrastructure Security Agency (CISA) is a U.S. federal agency responsible for strengthening the security and resilience of the nation's critical infrastructure against cyber and physical threats. CISA works with government and private sector partners to provide cybersecurity tools, incident response services, and guidance to protect essential systems and networks. Its role is proactive defense and collaborative threat response.
Question 25: What is the legal standard for obtaining a warrant to search digital devices under the Fourth Amendment?
- Clear and convincing evidence
- Probable cause (Correct answer)
- Preponderance of evidence
- Reasonable suspicion
Correct answer: Probable cause
A search warrant requires probable cause, meaning a reasonable belief based on articulable facts that evidence of a crime will be found.
Question 26: Which regulatory framework most directly impacts vendor contract requirements for companies handling payment card data?
- HIPAA
- FERPA
- PCI DSS (Correct answer)
- COPPA
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) imposes specific contractual requirements on merchants and service providers handling payment card data, including vendor oversight and security obligations.
Question 27: An ethical hacker finds credentials for a client's partner company during a test. What should the tester do?
- Report the credentials to the client and stop any further use immediately (Correct answer)
- Notify the partner company directly without telling the client
- Delete the credentials and continue the engagement
- Use the credentials to test the partner's systems for additional vulnerabilities
Correct answer: Report the credentials to the client and stop any further use immediately
Discovered third-party credentials must be reported to the client immediately without being used, as testing the partner's systems would exceed authorized scope.
Question 28: Which state was the first in the U.S. to enact a comprehensive data security law requiring businesses to implement reasonable security measures for personal information?
- California
- Texas
- Massachusetts (Correct answer)
- New York
Correct answer: Massachusetts
Massachusetts enacted 201 CMR 17.00 in 2010, one of the earliest and most prescriptive state laws requiring a Written Information Security Program (WISP).
Question 29: Under CCPA, which of the following is NOT one of the consumer rights explicitly granted?
- Right to delete personal information
- Right to know what personal information is collected
- Right to opt out of the sale of personal information
- Right to data portability across all service providers (Correct answer)
Correct answer: Right to data portability across all service providers
CCPA originally granted rights to know, delete, opt-out of sale, and non-discrimination; unlimited cross-provider portability is a GDPR construct not originally in CCPA.
Question 30: What legal obligation does the New York SHIELD Act create for businesses that own private information of New York residents?
- Third-party penetration testing every two years
- Reasonable safeguards appropriate to the size and complexity of the business (Correct answer)
- Mandatory cyber insurance with minimum $1M coverage
- Annual NIST CSF assessments
Correct answer: Reasonable safeguards appropriate to the size and complexity of the business
NY's SHIELD Act requires businesses to implement reasonable administrative, technical, and physical safeguards appropriate to their size and the sensitivity of data held.
Question 31: Under the FTC Act Section 5, the FTC can take enforcement action against companies for privacy violations primarily on what legal theory?
- Failure to pay federal privacy registration fees
- Non-compliance with state breach notification laws
- Unfair or deceptive acts or practices in or affecting commerce (Correct answer)
- Violations of specific federal data protection statutes
Correct answer: Unfair or deceptive acts or practices in or affecting commerce
The FTC uses its Section 5 authority to pursue companies whose privacy practices constitute unfair or deceptive acts or practices harming consumers.
Question 32: When conducting a forensic examination of a suspect's smartphone, which constitutional amendment primarily protects against warrantless searches?
- First Amendment
- Fifth Amendment
- Sixth Amendment
- Fourth Amendment (Correct answer)
Correct answer: Fourth Amendment
The Fourth Amendment protects against unreasonable searches and seizures, and the Supreme Court in Riley v. California held that police must get a warrant to search a cell phone.
Cybersecurity Law Certification (CSL)
The CSL exam validates knowledge of cybersecurity law across ten domains including data protection, privacy regulations, digital forensics, corporate liability, intellectual property, and legal compliance frameworks such as GDPR, HIPAA, and the Computer Fraud and Abuse Act (CFAA).
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong โ answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds