Courseiva
Back to Certified Information Systems Auditor CISA questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Information Systems Auditor CISA practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CISA
exam code
ISACA
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CISA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymulti select
Full question →

An IT governance framework should include which TWO key components? (Select exactly two.)

Question 2mediummulti select
Full question →

An IS auditor is evaluating an organization's SDLC controls for a new system. Which TWO of the following are key controls that should be in place during the design phase? (Select TWO.)

Question 3easymulti select
Full question →

An IS auditor is reviewing the backup process for a critical database. Which TWO of the following are essential controls to ensure data recoverability?

Question 4hardmulti select
Full question →

An IS auditor is assessing the backup and recovery procedures for a critical database. Which TWO of the following are the MOST important controls to ensure recoverability?

Question 5mediummulti select
Full question →

An IS auditor is reviewing the design phase of a new procurement system. Which TWO of the following controls are MOST critical to include in the system design to prevent unauthorized purchases?

Question 6mediummulti select
Full question →

Which THREE of the following are acceptable methods for gathering audit evidence? (Select THREE.)

Question 7hardmulti select
Full question →

Which TWO of the following are primary objectives of a data loss prevention (DLP) strategy?

Question 8mediummulti select
Full question →

An IS auditor is reviewing a change management process. Which TWO elements should be documented in a normal change request to ensure adequate governance? (Select TWO)

Question 9mediummulti select
Full question →

Which TWO of the following are key elements of an effective incident response plan? (Select exactly 2.)

Question 10hardmulti select
Full question →

Which THREE of the following are essential components of a data classification program?

Question 11mediummulti select
Full question →

Which TWO of the following are primary objectives of a business continuity plan (BCP)?

Question 12hardmulti select
Full question →

An IS auditor is reviewing the organization's incident management process. Which THREE of the following are essential components of an effective incident response plan?

Question 13mediummulti select
Full question →

Which TWO of the following are considered essential components of an information security policy framework? (Choose two.)

Question 14hardmulti select
Full question →

An organization is implementing a change management process based on ITIL. Which THREE change types should be included in the policy?

Question 15mediummulti select
Full question →

Which TWO of the following are key benefits of using a system development life cycle (SDLC) methodology? (Select exactly two.)

Question 16mediummulti select
Full question →

An IS auditor is reviewing backup procedures for a critical database. Which THREE are key considerations for ensuring backup reliability and recoverability?

Question 17mediummulti select
Full question →

Which TWO of the following are key controls that an IS auditor should expect to find in a well-managed system development life cycle (SDLC)?

Question 18easymulti select
Full question →

An IS auditor is assessing the vendor management process. Which TWO are key controls for managing third-party risk?

Question 19hardmulti select
Full question →

Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)

Question 20hardmulti select
Full question →

Which TWO of the following are indicators of poor project governance that an IS auditor should identify?

These CISA practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CISA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.