CSM Cheat Sheet 2026
The 30 highest-yield CSM facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
100 questions
120 min time limit
70% to pass
- How can a software company mitigate risks associated with data breaches? → By implementing strong security measures and regular updates
- A software manager is evaluating a team member using a 360-degree feedback process. What distinguishes this from a traditional top-down review? → It collects feedback from peers, subordinates, and customers in addition to the manager
- A software team uses static application security testing (SAST) tools. At what stage of the SDLC is SAST MOST effectively applied? → During the coding and build phase
- In a software project using a responsibility assignment matrix (RAM), the 'A' in RACI stands for: → Accountable
- Which SDLC phase involves making the software available for use by the end-users? → Deployment
- What is the purpose of a risk breakdown structure (RBS) in software project management? → To hierarchically categorize risks by source or type
- In a software governance context, what does 'separation of duties' primarily prevent? → Single individuals from having unchecked control over critical processes
- What is the difference between manual and automated testing? → Manual testing is more flexible, while automated testing is faster for repetitive tasks
- A software manager discovers that a top performer is planning to resign due to lack of career growth. What is the BEST retention strategy? → Create a personalized development plan with clear advancement opportunities
- A software manager wants to measure the effectiveness of stakeholder communications. Which metric is MOST directly relevant? → Stakeholder satisfaction scores gathered through surveys or feedback sessions
- In the V-Model (Verification and Validation model), which testing phase directly corresponds to requirements specification? → Acceptance Testing
- A project manager wants to show the distribution of defects by category to identify the most significant causes. Which quality tool should they use? → Pareto Chart
- Which of the following BEST describes a version control branching strategy that uses short-lived feature branches merged frequently into the main branch? → Trunk-based development
- Which approach to software quality focuses on preventing defects rather than detecting them after the fact? → Quality Assurance (QA)
- When communicating technical risks to a non-technical executive stakeholder, which approach is most effective? → Present risks in terms of business impact, timelines, and costs
- In a risk register, which field records the planned actions to reduce a risk's probability or impact? → Mitigation plan
- A software manager wants to track whether all requirements have been tested. Which artifact maps requirements to test cases? → Requirements traceability matrix (RTM)
- Which configuration management activity involves recording the current state and history of all configuration items? → Configuration status accounting
- Under PCI DSS, what is the maximum number of digits that may be displayed when truncating a Primary Account Number (PAN) for display purposes? → First 6 and last 4 digits only
- In CSM practice, what is the purpose of a standard operating procedure (SOP)? → To document step-by-step instructions for routine tasks to ensure consistency and quality
- What is the primary legal risk of software underlicensing? → Legal liability for using more software copies than licensed
- A software manager uses Monte Carlo simulation to estimate project completion dates. What is the primary advantage over a single-point estimate? → It produces a probability distribution of outcomes rather than one deterministic date
- When calculating a risk's Expected Monetary Value (EMV), which formula is used? → EMV = Impact × Probability
- Which leadership style is MOST effective when managing highly experienced software engineers who require little supervision? → Delegative (laissez-faire) leadership
- Which testing level verifies that separately developed software modules work correctly when combined? → Integration testing
- Which conflict resolution approach involves finding a solution that partially satisfies all parties but fully satisfies none? → Compromising
- A software project has a Schedule Performance Index (SPI) of 1.2. What does this indicate? → The project is progressing 20% faster than planned
- Which of the following is a key advantage of automated testing? → It can be executed repeatedly, saving time in the long run
- What is the primary purpose of software security? → To protect the software from security breaches
- Which technique is BEST suited for identifying all relevant stakeholders at the start of a software project? → Conducting stakeholder brainstorming sessions with the project team
Turn these facts into recall:
Was this helpful?