Courseiva
Back to Certified in Risk and Information Systems Control CRISC questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified in Risk and Information Systems Control CRISC practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CRISC
exam code
ISACA
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CRISC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymulti select
Full question →

Which TWO of the following are examples of control monitoring activities?

Question 2easymulti select
Full question →

A risk practitioner is reviewing the organization's risk response strategies for a high-value asset. Which TWO of the following are examples of risk mitigation techniques? (Choose two.)

Question 3hardmulti select
Full question →

Which THREE factors should be considered when determining the inherent risk level of a new IT project prior to any controls?

Question 4hardmulti select
Full question →

Which THREE of the following are key considerations when designing a risk reporting framework? (Choose three.)

Question 5hardmulti select
Full question →

Which THREE factors should be considered when determining the likelihood of a threat exploiting a vulnerability?

Question 6mediummulti select
Full question →

Which TWO of the following are examples of detective controls?

Question 7easymulti select
Full question →

Which TWO of the following factors should be considered when determining the frequency of control monitoring?

Question 8hardmulti select
Full question →

Which THREE of the following are effective risk treatment strategies?

Question 9hardmulti select
Full question →

Which THREE of the following are essential components of a risk register that should be documented during risk identification? (Select exactly 3.)

Question 10hardmulti select
Full question →

A financial services company is implementing a vendor risk management program. Which THREE of the following are key components of an effective vendor risk assessment process? (Select THREE)

Question 11mediummulti select
Full question →

An OT environment is being assessed for compliance with IEC 62443. Which TWO of the following are key security requirements of this standard?

Question 12mediummulti select
Full question →

A risk practitioner is developing risk scenarios for a new cloud service. Which THREE of the following elements should be included in a complete risk scenario?

Question 13mediummulti select
Full question →

Which THREE of the following are key components of an effective risk response plan?

Question 14mediummulti select
Full question →

Which TWO of the following are examples of risk avoidance?

Question 15easymulti select
Full question →

In a qualitative risk assessment, which TWO elements are typically used to determine the risk rating?

Question 16hardmulti select
Full question →

An organization is conducting a risk assessment and finds that the inherent risk for a critical asset is very high due to a high threat event frequency and high vulnerability. The current controls are assessed as adequate in design but not operating effectively. Which THREE of the following should be considered when calculating residual risk?

Question 17hardmulti select
Full question →

An organization is updating its IT risk universe to include emerging threats. The CISO wants to ensure the risk register captures realistic risk scenarios. Which THREE components are essential for constructing a complete risk scenario according to ISACA's risk scenario template?

Question 18hardmulti select
Full question →

Which THREE of the following should be included in a board-level risk report to effectively communicate the organization's risk profile?

Question 19hardmulti select
Full question →

An organization is evaluating the impact of a potential data breach. Which THREE of the following are considered indirect financial impacts?

Question 20hardmulti select
Full question →

A company's IT risk team is conducting a risk identification exercise for a new blockchain-based supply chain solution. Which THREE risks are MOST specific to this technology?

These CRISC practice questions are part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style CRISC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.