CSPM Cheat Sheet 2026

The 30 highest-yield CSPM facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

150 questions
120 min time limit
70% to pass
  1. A project manager is applying the MoSCoW method during security requirements planning. What does 'W' stand for? Won't have this time
  2. When conducting security control testing during project execution, which approach ensures coverage without duplicating effort? Use a requirements traceability matrix to map controls to test cases
  3. Which risk response strategy involves transferring financial consequences of a security risk to a third party, such as through cyber insurance? Transfer
  4. A security project manager is closing a network segmentation project. What is the FIRST step before handing over to operations? Conduct a final security assessment to verify deliverables meet requirements
  5. A qualitative risk assessment differs from a quantitative risk assessment primarily because it: Relies on descriptive ratings such as High, Medium, and Low
  6. Which governance document provides the formal authorization for a security project manager to use organizational resources and lead a security initiative? Project charter
  7. What does project closing ensure? Completion of project objectives
  8. A CSPM is creating a responsibility assignment matrix. The 'A' in RACI stands for: Accountable
  9. Which assessment method provides the MOST reliable data for CSPM professionals making critical decisions? Standardized tools combined with professional observation
  10. How does conflict resolution contribute to project execution? By addressing issues and keeping the project on track
  11. What is the role of the change control board (CCB) during security project execution? To approve or reject changes to project baselines
  12. What are security project deliverables? Physical and technical assets of the security system
  13. Why is resource allocation important in project planning? It ensures efficiency and timely task completion
  14. Why is client feedback important during project closing? To verify if the deliverables meet client expectations
  15. What is the significance of a project schedule? It ensures tasks are completed within the set timelines
  16. A security project manager plans to use earned value management (EVM). If the project's EV is $80,000 and PV is $100,000, what does this indicate? The project is behind schedule
  17. In security project planning, 'gold plating' refers to: Adding features or functionality beyond what was agreed in scope
  18. A CSPM professional conducting a security program gap analysis compares the current state against: A desired target state or recognized security standard
  19. What is the purpose of security system testing? To identify any malfunction or performance issues
  20. What is the primary purpose of a Statement of Applicability (SoA) in an ISO 27001 compliance project? To document which Annex A controls are applicable and whether they are implemented
  21. A security project manager is determining the critical path for an IDS deployment. What does identifying the critical path allow the manager to do? Identify tasks where delays will directly delay the project finish date
  22. What type of risk response strategy involves purchasing cyber insurance to offset potential financial losses? Risk transfer
  23. Which metric is MOST relevant when evaluating the success of a security project during closing? Reduction in identified security risks compared to baseline
  24. Which security planning document establishes the processes for managing changes to security controls during a project? Change management plan
  25. Which of the following represents a security-specific risk during project closure that is NOT typically present in non-security projects? Exposure of vulnerability data contained in project artifacts if not properly secured
  26. During project execution, a key security engineer unexpectedly resigns. Which response BEST maintains project continuity? Activate the resource management plan's contingency for critical roles
  27. What is the purpose of a Business Impact Analysis (BIA) in a security project? To identify critical assets and quantify the impact of their disruption
  28. Which risk metric represents the maximum tolerable downtime for a system before business operations are critically impaired? Recovery Time Objective (RTO)
  29. Which metric BEST indicates whether a security project's cost performance is acceptable during monitoring? Cost Performance Index (CPI)
  30. Which assessment method provides the MOST reliable data for CSPM professionals making critical decisions? Standardized tools combined with professional observation
Turn these facts into recall:
Was this helpful?