CSPM Cheat Sheet 2026
The 30 highest-yield CSPM facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
150 questions
120 min time limit
70% to pass
- A project manager is applying the MoSCoW method during security requirements planning. What does 'W' stand for? → Won't have this time
- When conducting security control testing during project execution, which approach ensures coverage without duplicating effort? → Use a requirements traceability matrix to map controls to test cases
- Which risk response strategy involves transferring financial consequences of a security risk to a third party, such as through cyber insurance? → Transfer
- A security project manager is closing a network segmentation project. What is the FIRST step before handing over to operations? → Conduct a final security assessment to verify deliverables meet requirements
- A qualitative risk assessment differs from a quantitative risk assessment primarily because it: → Relies on descriptive ratings such as High, Medium, and Low
- Which governance document provides the formal authorization for a security project manager to use organizational resources and lead a security initiative? → Project charter
- What does project closing ensure? → Completion of project objectives
- A CSPM is creating a responsibility assignment matrix. The 'A' in RACI stands for: → Accountable
- Which assessment method provides the MOST reliable data for CSPM professionals making critical decisions? → Standardized tools combined with professional observation
- How does conflict resolution contribute to project execution? → By addressing issues and keeping the project on track
- What is the role of the change control board (CCB) during security project execution? → To approve or reject changes to project baselines
- What are security project deliverables? → Physical and technical assets of the security system
- Why is resource allocation important in project planning? → It ensures efficiency and timely task completion
- Why is client feedback important during project closing? → To verify if the deliverables meet client expectations
- What is the significance of a project schedule? → It ensures tasks are completed within the set timelines
- A security project manager plans to use earned value management (EVM). If the project's EV is $80,000 and PV is $100,000, what does this indicate? → The project is behind schedule
- In security project planning, 'gold plating' refers to: → Adding features or functionality beyond what was agreed in scope
- A CSPM professional conducting a security program gap analysis compares the current state against: → A desired target state or recognized security standard
- What is the purpose of security system testing? → To identify any malfunction or performance issues
- What is the primary purpose of a Statement of Applicability (SoA) in an ISO 27001 compliance project? → To document which Annex A controls are applicable and whether they are implemented
- A security project manager is determining the critical path for an IDS deployment. What does identifying the critical path allow the manager to do? → Identify tasks where delays will directly delay the project finish date
- What type of risk response strategy involves purchasing cyber insurance to offset potential financial losses? → Risk transfer
- Which metric is MOST relevant when evaluating the success of a security project during closing? → Reduction in identified security risks compared to baseline
- Which security planning document establishes the processes for managing changes to security controls during a project? → Change management plan
- Which of the following represents a security-specific risk during project closure that is NOT typically present in non-security projects? → Exposure of vulnerability data contained in project artifacts if not properly secured
- During project execution, a key security engineer unexpectedly resigns. Which response BEST maintains project continuity? → Activate the resource management plan's contingency for critical roles
- What is the purpose of a Business Impact Analysis (BIA) in a security project? → To identify critical assets and quantify the impact of their disruption
- Which risk metric represents the maximum tolerable downtime for a system before business operations are critically impaired? → Recovery Time Objective (RTO)
- Which metric BEST indicates whether a security project's cost performance is acceptable during monitoring? → Cost Performance Index (CPI)
- Which assessment method provides the MOST reliable data for CSPM professionals making critical decisions? → Standardized tools combined with professional observation
Turn these facts into recall:
Was this helpful?