CSX Cheat Sheet 2026
The 30 highest-yield CSX facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
75 questions
120 min time limit
65.00% to pass
- A forensic investigator uses SHA-256 to hash an evidence drive before and after imaging. What does a matching hash confirm? → The evidence was not tampered with during acquisition
- What should be regularly tested to ensure operational resilience after an incident? → Disaster recovery plan
- What is a 'preservation letter' (or evidence preservation request) used for in cybercrime investigations? → Requiring a provider to retain specific data while legal process is obtained
- Which technique allows an attacker to passively monitor Wi-Fi traffic on a network they are not associated with by placing a wireless adapter in monitor mode? → Packet capture via promiscuous mode on wireless
- Which term refers to limiting user access to only what is necessary for their job? → Least privilege
- What does the Fourth Amendment protect against in CSX operations? → Unreasonable searches and seizures by requiring probable cause or warrants
- Which endpoint protection feature uses behavioral analysis to detect malware that has never been seen before? → Heuristic/behavioral analysis
- Which port number is associated with HTTPS traffic by default? → 443
- In a resilience framework, 'redundancy' is BEST described as: → Having duplicate systems or components so operations continue if one fails
- A penetration tester discovers a critical vulnerability but the client asks to omit it from the report. What is the appropriate response? → Include it and note the client's objection
- During a full-interruption test of a disaster recovery plan, what happens to the primary systems? → They are shut down and all operations shift to the recovery site
- What does CPTED stand for in CSX security planning? → Crime Prevention Through Environmental Design
- What does SIEM stand for in cybersecurity? → Security Information and Event Management
- During incident recovery, a 'chain of custody' log is MOST important for: → Preserving evidence integrity for potential legal proceedings
- What is the 'plain view' doctrine and how does it apply to digital forensic searches? → Evidence in plain sight during a lawful search can be seized without an additional warrant
- Which of the following is the FIRST step in a Business Impact Analysis (BIA)? → Identify critical business functions and their dependencies
- Which host-based control BEST prevents unauthorized software from executing on a corporate endpoint? → Application whitelisting
- Which of the following is an example of a 'closed question' in an investigative interview? → Did you click on the link in the email?
- An organization needs to ensure users accessing a VPN from personal devices meet minimum security posture requirements. Which technology BEST enforces this? → Network Access Control (NAC)
- What is the correct order when documenting a crime scene under the 'order of volatility' principle? → CPU registers → RAM → Network state → Disk
- Which of the following BEST supports long-term sustainability of security operations after an incident? → Integrating lessons learned into updated policies, training, and controls
- Which network security control inspects traffic at the application layer and can filter based on application identity, not just port and IP? → Next-generation firewall (NGFW)
- Which component should be included in the methodology section of a penetration test report? → Scope boundaries, testing phases, and tools used
- A forensic analyst needs to document that a disk image is an exact copy of the original. Which method is most appropriate? → Comparing SHA-256 hashes of the original and the image
- What does the Fourth Amendment protect against in CSX operations? → Unreasonable searches and seizures by requiring probable cause or warrants
- Which metric indicates how quickly systems must be restored after a disruption? → Recovery Time Objective
- Why is asset classification important in threat assessment? → It identifies critical systems to secure first
- Which type of audience requires the most technical detail in a cybersecurity report? → Security operations team
- Which file system artifact records the last time a file was accessed on an NTFS volume? → $MFT entry timestamps
- An IDS generates 500 alerts per day but only 5 are confirmed malicious. What is this phenomenon called? → Alert fatigue due to false positives
Turn these facts into recall:
Was this helpful?