CSS Cheat Sheet 2026

The 30 highest-yield CSS facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

100 questions
120 min time limit
70.00% to pass
  1. Which asset valuation method determines value based on what it would cost to replace an asset with one of equivalent functionality at today's prices? Replacement cost
  2. A newly hired employee is onboarded without completing security policy acknowledgment. Which risk does this PRIMARILY create? Inability to enforce policy violations against the employee legally
  3. Which standard is used to automate the provisioning and deprovisioning of user accounts across systems? SCIM (System for Cross-domain Identity Management)
  4. What is an orphaned account and why is it a security risk? An account no longer associated with an active user that may be exploited by attackers
  5. What network security control is designed to detect and prevent unauthorized wireless access points? Wireless intrusion prevention system (WIPS)
  6. In threat detection, what does 'threat hunting' differ from automated monitoring in that it: Is a proactive, hypothesis-driven search for hidden threats that evaded automated controls
  7. What is the primary purpose of Cloud Security Posture Management (CSPM)? To continuously assess cloud configurations for compliance gaps and security risks
  8. Which privacy law in the United States grants California residents rights over their personal data? California Consumer Privacy Act (CCPA)
  9. What is the importance of incident documentation? To provide records for future analysis and lessons learned
  10. What is the function of a network access control (NAC) system in enterprise security? Enforces security policy compliance before granting network access
  11. Which IAM control helps prevent privilege escalation by ensuring users cannot grant themselves higher permissions than they currently hold? Constrained delegation and permission boundary enforcement
  12. An organization's acceptable use policy (AUP) is BEST described as which type of security policy? Issue-specific policy
  13. What is the significance of risk assessments in security policy development? To identify and prioritize risks in security policy development
  14. What role does recovery play in incident response? To restore normal operations and minimize the impact
  15. What is the PRIMARY distinction between a security policy and a security standard? Policies state what must be achieved; standards specify how to achieve it
  16. Why is it necessary to evaluate the likelihood and impact of each identified risk? To prioritize resources and mitigation efforts
  17. Which protocol is used to encrypt DNS queries to prevent eavesdropping and tampering? DNS over HTTPS (DoH)
  18. Which cryptographic concept ensures that a party cannot deny having performed an action? Non-repudiation
  19. Which principle best describes 'zero trust' architecture as applied to cloud environments? Never implicitly trusting any user, device, or network segment regardless of location
  20. Which attack floods a target server with half-open TCP connections to exhaust its resources? SYN flood
  21. Which standard provides guidance specifically on information security risk management processes and is part of the ISO/IEC 27000 family? ISO/IEC 27005
  22. What does the Common Vulnerability Scoring System (CVSS) Base Score measure? The intrinsic characteristics of a vulnerability independent of time or environment
  23. How does employee training contribute to effective security policy enforcement? By educating employees on policy and compliance
  24. Why is it important to involve external partners during incident recovery? To bring in expertise and support during recovery
  25. What does 'perfect forward secrecy' (PFS) ensure in TLS connections? Compromise of the server's private key does not expose past session keys
  26. What security vulnerability is MOST associated with serverless (Function as a Service) architectures? Event-data injection attacks via malicious data passed through function triggers
  27. A company implements a clean desk policy. Which type of security threat does this PRIMARILY mitigate? Insider threat via unauthorized physical access to sensitive information
  28. What does FedRAMP primarily govern? Security requirements for cloud services used by U.S. federal government agencies
  29. Which encryption mode of AES is considered most secure for bulk data encryption due to its use of an initialization vector and chaining? AES-CBC (Cipher Block Chaining)
  30. Which attack targets authentication systems by using previously captured valid authentication tokens? Pass-the-ticket / pass-the-hash attack
Turn these facts into recall:
Was this helpful?