CSX Cheat Sheet 2026

The 30 highest-yield CSX facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

75 questions
120 min time limit
65.00% to pass
  1. A forensic investigator uses SHA-256 to hash an evidence drive before and after imaging. What does a matching hash confirm? The evidence was not tampered with during acquisition
  2. What should be regularly tested to ensure operational resilience after an incident? Disaster recovery plan
  3. What is a 'preservation letter' (or evidence preservation request) used for in cybercrime investigations? Requiring a provider to retain specific data while legal process is obtained
  4. Which technique allows an attacker to passively monitor Wi-Fi traffic on a network they are not associated with by placing a wireless adapter in monitor mode? Packet capture via promiscuous mode on wireless
  5. Which term refers to limiting user access to only what is necessary for their job? Least privilege
  6. What does the Fourth Amendment protect against in CSX operations? Unreasonable searches and seizures by requiring probable cause or warrants
  7. Which endpoint protection feature uses behavioral analysis to detect malware that has never been seen before? Heuristic/behavioral analysis
  8. Which port number is associated with HTTPS traffic by default? 443
  9. In a resilience framework, 'redundancy' is BEST described as: Having duplicate systems or components so operations continue if one fails
  10. A penetration tester discovers a critical vulnerability but the client asks to omit it from the report. What is the appropriate response? Include it and note the client's objection
  11. During a full-interruption test of a disaster recovery plan, what happens to the primary systems? They are shut down and all operations shift to the recovery site
  12. What does CPTED stand for in CSX security planning? Crime Prevention Through Environmental Design
  13. What does SIEM stand for in cybersecurity? Security Information and Event Management
  14. During incident recovery, a 'chain of custody' log is MOST important for: Preserving evidence integrity for potential legal proceedings
  15. What is the 'plain view' doctrine and how does it apply to digital forensic searches? Evidence in plain sight during a lawful search can be seized without an additional warrant
  16. Which of the following is the FIRST step in a Business Impact Analysis (BIA)? Identify critical business functions and their dependencies
  17. Which host-based control BEST prevents unauthorized software from executing on a corporate endpoint? Application whitelisting
  18. Which of the following is an example of a 'closed question' in an investigative interview? Did you click on the link in the email?
  19. An organization needs to ensure users accessing a VPN from personal devices meet minimum security posture requirements. Which technology BEST enforces this? Network Access Control (NAC)
  20. What is the correct order when documenting a crime scene under the 'order of volatility' principle? CPU registers → RAM → Network state → Disk
  21. Which of the following BEST supports long-term sustainability of security operations after an incident? Integrating lessons learned into updated policies, training, and controls
  22. Which network security control inspects traffic at the application layer and can filter based on application identity, not just port and IP? Next-generation firewall (NGFW)
  23. Which component should be included in the methodology section of a penetration test report? Scope boundaries, testing phases, and tools used
  24. A forensic analyst needs to document that a disk image is an exact copy of the original. Which method is most appropriate? Comparing SHA-256 hashes of the original and the image
  25. What does the Fourth Amendment protect against in CSX operations? Unreasonable searches and seizures by requiring probable cause or warrants
  26. Which metric indicates how quickly systems must be restored after a disruption? Recovery Time Objective
  27. Why is asset classification important in threat assessment? It identifies critical systems to secure first
  28. Which type of audience requires the most technical detail in a cybersecurity report? Security operations team
  29. Which file system artifact records the last time a file was accessed on an NTFS volume? $MFT entry timestamps
  30. An IDS generates 500 alerts per day but only 5 are confirmed malicious. What is this phenomenon called? Alert fatigue due to false positives
Turn these facts into recall:
Was this helpful?