CSM Cheat Sheet 2026

The 30 highest-yield CSM facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

100 questions
120 min time limit
70% to pass
  1. How can a software company mitigate risks associated with data breaches? By implementing strong security measures and regular updates
  2. A software manager is evaluating a team member using a 360-degree feedback process. What distinguishes this from a traditional top-down review? It collects feedback from peers, subordinates, and customers in addition to the manager
  3. A software team uses static application security testing (SAST) tools. At what stage of the SDLC is SAST MOST effectively applied? During the coding and build phase
  4. In a software project using a responsibility assignment matrix (RAM), the 'A' in RACI stands for: Accountable
  5. Which SDLC phase involves making the software available for use by the end-users? Deployment
  6. What is the purpose of a risk breakdown structure (RBS) in software project management? To hierarchically categorize risks by source or type
  7. In a software governance context, what does 'separation of duties' primarily prevent? Single individuals from having unchecked control over critical processes
  8. What is the difference between manual and automated testing? Manual testing is more flexible, while automated testing is faster for repetitive tasks
  9. A software manager discovers that a top performer is planning to resign due to lack of career growth. What is the BEST retention strategy? Create a personalized development plan with clear advancement opportunities
  10. A software manager wants to measure the effectiveness of stakeholder communications. Which metric is MOST directly relevant? Stakeholder satisfaction scores gathered through surveys or feedback sessions
  11. In the V-Model (Verification and Validation model), which testing phase directly corresponds to requirements specification? Acceptance Testing
  12. A project manager wants to show the distribution of defects by category to identify the most significant causes. Which quality tool should they use? Pareto Chart
  13. Which of the following BEST describes a version control branching strategy that uses short-lived feature branches merged frequently into the main branch? Trunk-based development
  14. Which approach to software quality focuses on preventing defects rather than detecting them after the fact? Quality Assurance (QA)
  15. When communicating technical risks to a non-technical executive stakeholder, which approach is most effective? Present risks in terms of business impact, timelines, and costs
  16. In a risk register, which field records the planned actions to reduce a risk's probability or impact? Mitigation plan
  17. A software manager wants to track whether all requirements have been tested. Which artifact maps requirements to test cases? Requirements traceability matrix (RTM)
  18. Which configuration management activity involves recording the current state and history of all configuration items? Configuration status accounting
  19. Under PCI DSS, what is the maximum number of digits that may be displayed when truncating a Primary Account Number (PAN) for display purposes? First 6 and last 4 digits only
  20. In CSM practice, what is the purpose of a standard operating procedure (SOP)? To document step-by-step instructions for routine tasks to ensure consistency and quality
  21. What is the primary legal risk of software underlicensing? Legal liability for using more software copies than licensed
  22. A software manager uses Monte Carlo simulation to estimate project completion dates. What is the primary advantage over a single-point estimate? It produces a probability distribution of outcomes rather than one deterministic date
  23. When calculating a risk's Expected Monetary Value (EMV), which formula is used? EMV = Impact × Probability
  24. Which leadership style is MOST effective when managing highly experienced software engineers who require little supervision? Delegative (laissez-faire) leadership
  25. Which testing level verifies that separately developed software modules work correctly when combined? Integration testing
  26. Which conflict resolution approach involves finding a solution that partially satisfies all parties but fully satisfies none? Compromising
  27. A software project has a Schedule Performance Index (SPI) of 1.2. What does this indicate? The project is progressing 20% faster than planned
  28. Which of the following is a key advantage of automated testing? It can be executed repeatedly, saving time in the long run
  29. What is the primary purpose of software security? To protect the software from security breaches
  30. Which technique is BEST suited for identifying all relevant stakeholders at the start of a software project? Conducting stakeholder brainstorming sessions with the project team
Turn these facts into recall:
Was this helpful?