Courseiva
Back to (ISC)2 Information Systems Security Engineering Professional (CISSP-ISSEP, Aug 2025 blueprint) (ISC) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise (ISC)2 Information Systems Security Engineering Professional (CISSP-ISSEP, Aug 2025 blueprint) (ISC) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
ISC
exam code
(ISC)²
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related ISC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

Which TWO of the following are key inputs for a quantitative risk analysis?

Question 2hardmulti select
Full question →

An ISSEP is evaluating the security of an OT/ICS environment. Which THREE of the following are considered high-priority mitigation strategies to protect against common ICS cyber threats?

Question 3hardmulti select
Full question →

Which THREE of the following are essential for protecting against 'Man-in-the-Middle' (MitM) attacks in a service-oriented architecture?

Question 4hardmulti select
Full question →

You are assessing an Engineered System for cloud-native vulnerabilities. Which THREE of the following are common misconfigurations in containerized environments that an ISSEP should identify?

Question 5hardmulti select
Full question →

An ISSEP is assessing the security of a CI/CD pipeline. Which THREE of the following practices are crucial to ensure the security of the software supply chain?

Question 6hardmulti select
Full question →

Which THREE technologies are acceptable for the secure disposal of solid-state drives (SSDs)?

Question 7hardmulti select
Full question →

Which THREE items should be included in a Post-Implementation Review (PIR) for a security change?

Question 8mediummulti select
Full question →

Which TWO controls are recommended under NIST SP 800-53 for protecting data at rest in a high-impact system?

Question 9mediummulti select
Full question →

Which TWO security standards are most relevant for an ISSEP designing a secure payment processing system?

Question 10mediummulti select
Full question →

Which TWO factors must be assessed when determining if a change is 'Emergency' versus 'Standard'?

Question 11mediummulti select
Full question →

Which TWO of the following are acceptable ways to handle residual risk after implementing security controls in an RMF process?

Question 12mediummulti select
Full question →

When applying NIST SP 800-160 Systems Security Engineering principles, which THREE activities are critical during the 'System Design' phase to ensure confidentiality and integrity?

Question 13hardmulti select
Full question →

Which THREE activities are essential when conducting a 'Security Impact Analysis' for a proposed system change?

Question 14hardmulti select
Full question →

Which THREE factors are essential when performing a threat model using the STRIDE methodology?

Question 15mediummulti select
Full question →

Which TWO of the following are critical for an effective 'Continuous Monitoring' (ConMon) program under RMF?

Question 16mediummulti select
Full question →

Which TWO of the following are common pitfalls when tailoring security controls in an RMF implementation?

Question 17hardmulti select
Full question →

An ISSEP is assessing the risk of a system that uses 'Secrets Management' services (e.g., HashiCorp Vault). Which THREE of the following are best practices for securing the secrets themselves?

Question 18mediummulti select
Full question →

Which TWO of the following statements are true regarding the relationship between the System Security Plan (SSP) and the Plan of Action and Milestones (POA&M)?

Question 19mediummulti select
Full question →

Which THREE of the following are recognized categories of security controls in NIST SP 800-53?

Question 20hardmulti select
Full question →

Which THREE methods can be used to ensure high availability for a database in a secure architecture?

These ISC practice questions are part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style ISC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.