Courseiva
Back to (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
ISC
exam code
(ISC)²
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related ISC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

Which TWO of the following are effective ways to improve 'Crisis Management Leadership' effectiveness during an incident?

Question 2mediummulti select
Full question →

Which TWO aspects of the NIST Cybersecurity Framework (CSF) are most relevant when establishing a 'Compliance Program Management' function?

Question 3mediummulti select
Full question →

Which TWO actions should a security manager take to ensure an organization remains compliant with the Sarbanes-Oxley (SOX) Act regarding IT controls?

Question 4hardmulti select
Full question →

Which THREE of the following are important considerations for an ISSMP when outsourcing security functions?

Question 5hardmulti select
Full question →

When designing a Disaster Recovery Program, which THREE of the following represent common 'single points of failure' that must be addressed?

Question 6mediummulti select
Full question →

Which TWO factors must a security officer consider when performing a 'Privacy Impact Assessment' (PIA) for a new cloud application?

Question 7hardmulti select
Full question →

Which THREE of the following strategies should be included in a 'Disaster Recovery Program Oversight' function to ensure long-term viability?

Question 8mediummulti select
Full question →

Which TWO of the following are primary risks associated with an 'asynchronous' data replication strategy?

Question 9mediummulti select
Full question →

Which TWO controls should a manager verify to ensure 'Ethics in Security Leadership' is being practiced regarding internal whistleblower protections?

Question 10mediummulti select
Full question →

Which TWO of the following are metrics that provide insight into the effectiveness of security leadership?

Question 11mediummulti select
Full question →

During a BIA review, you need to identify critical assets and their recovery requirements. Which TWO of the following inputs are essential for this classification process?

Question 12hardmulti select
Full question →

Which THREE of the following are common indicators that a security program is failing to align with business objectives?

Question 13mediummulti select
Full question →

When presenting a security budget request to the Board of Directors, which THREE of the following elements should be included to ensure the request is compelling and understood?

Question 14hardmulti select
Full question →

Which THREE components are essential for a robust 'Privacy Program' when implementing data protection by design in an cloud environment?

Question 15hardmulti select
Full question →

Which THREE configurations are necessary to satisfy the 'Technical Safeguards' requirement under HIPAA for data at rest?

Question 16hardmulti select
Full question →

Which THREE items must be included in a 'Data Processing Agreement' (DPA) between a cloud provider and a controller under GDPR?

Question 17mediummulti select
Full question →

Which TWO of the following are core components of a business-aligned security strategy?

Question 18mediummulti select
Full question →

Which TWO of the following are primary components of a formal Risk Management policy?

Question 19hardmulti select
Full question →

When conducting a risk assessment on an IoT ecosystem, which THREE factors are specifically critical?

Question 20mediummulti select
Full question →

Which TWO of the following are essential components of an effective security governance framework?

These ISC practice questions are part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style ISC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.