Courseiva
← Back to Certified Information Systems Auditor CISA questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Information Systems Auditor CISA practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CISA
exam code
ISACA
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CISA topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymulti select
Full question →

Which TWO of the following are types of audit evidence recognized in IS audit practice?

Question 2hardmulti select
Full question →

Which THREE of the following are key considerations when selecting a software development methodology for a project?

Question 3hardmulti select
Full question →

An IS auditor is evaluating how an organization enforces segregation of duties (SoD) within its enterprise resource planning (ERP) system. Management states that SoD conflicts are identified during user provisioning. Which TWO of the following audit procedures would BEST determine whether SoD controls operate effectively on an ongoing basis? (Choose two.)

Question 4hardmulti select
Full question →

Which THREE of the following are characteristics of a SMART recommendation? (Select three.)

Question 5hardmulti select
Full question →

During a firewall rule review, an IS auditor identifies several rules that allow any-to-any traffic. Which THREE of the following should the auditor recommend as the MOST appropriate actions?

Question 6easymulti select
Full question →

Which THREE of the following are essential components of a change management process?

Question 7mediummulti select
Full question →

Which TWO of the following are key objectives of a post-implementation review of a new system?

Question 8easymulti select
Full question →

Which TWO of the following are benefits of using a version control system in software development?

Question 9hardmulti select
Full question →

Which TWO of the following are BEST indicators that a system development project is at risk of failure?

Question 10hardmulti select
Full question →

An organization is evaluating its business continuity plan (BCP) to ensure alignment with the IT disaster recovery plan. Which TWO of the following are critical elements that should be included in the BCP to support effective business resilience?

Question 11mediummulti select
Full question →

Which TWO of the following are examples of analytical procedures used as audit evidence? (Select two.)

An IS auditor is assessing the security of an organization's virtualized environment. The organization uses a type 1 hypervisor and has multiple virtual machines (VMs) running on a single physical host. The auditor is concerned about the risk of VM escape, where an attacker compromises the hypervisor from within a VM. Which of the following controls are MOST effective in mitigating this risk? (Choose two.)

Question 13hardmulti select
Full question →

Which THREE of the following are key metrics to include in a disaster recovery test report? (Select exactly 3.)

Question 14easymulti select
Full question →

Which TWO of the following are key components of an IT governance framework? (Choose two.)

Question 15mediummulti select
Full question →

An IS auditor is reviewing the organization's data inventory process for privacy compliance. Which TWO of the following are the MOST important elements that should be included in the data inventory?

Question 16mediummulti select
Full question →

An organization is migrating from a legacy system to a new ERP. Which TWO of the following are the HIGHEST risks during data migration?

Question 17mediummulti select
Full question →

An IS auditor is assessing the data inventory of a financial institution to ensure compliance with privacy regulations. Which TWO of the following are essential elements that should be included in the data inventory?

Question 18mediummulti select
Full question →

An IS auditor is selecting an appropriate audit sample. Which THREE of the following are factors that affect the sample size?

Question 19mediummulti select
Full question →

During an audit of the incident response process, the IS auditor finds that the organization relies on shared accounts for system administration. Which TWO of the following are the MOST significant risks associated with shared accounts?

Question 20hardmulti select
Full question →

Which TWO of the following are indicators that an IS auditor may need to adjust the audit approach during fieldwork? (Select TWO.)

These CISA practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CISA questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.