Courseiva
← Back to ISC2 Certified in Cybersecurity CC questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise ISC2 Certified in Cybersecurity CC practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CC
exam code
ISC2
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymulti select
Full question →

Which THREE are essential elements of a disaster recovery plan? (Select THREE.)

Question 2mediummulti select
Full question →

A company is developing a business continuity plan (BCP). Which TWO of the following are essential components that must be included in a BCP?

Question 3mediummulti select
Read the full VPN explanation →

Which two of the following are common methods to secure a virtual private network (VPN) connection? (Choose two.)

Question 4hardmulti select
Full question →

A security team is investigating a potential ARP spoofing attack on the local network. Which two measures can effectively detect or prevent such attacks? (Choose two.)

Question 5mediummulti select
Full question →

Which TWO of the following are common indicators of a phishing email? (Select TWO.)

Question 6hardmulti select
Full question →

A SOC analyst is investigating an incident where an employee's workstation was compromised via a phishing email. The analyst has captured the following indicators: the email originated from a known malicious domain, the attachment was a macro-enabled document, and the macro executed a PowerShell command that downloaded a payload from a remote server. Which TWO actions should the analyst take immediately as part of the incident response process? (Choose two.)

Question 7hardmulti select
Full question →

An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)

Question 8hardmulti select
Full question →

Which THREE security mechanisms should be implemented to secure a network against ARP spoofing attacks? (Choose three.)

Question 9hardmulti select
Full question →

A security team is developing an incident response plan. Which THREE of the following are essential components of crisis communications during a data breach? (Choose three.)

Question 10mediummulti select
Full question →

Which of the following are core principles of information security?

Question 11hardmulti select
Full question →

A network administrator is implementing a defense-in-depth strategy. Which THREE of the following are considered network security controls? (Select THREE)

Question 12mediummulti select
Full question →

During a ransomware incident, the incident response team needs to communicate with stakeholders. According to best practices, which TWO groups should be notified immediately? (Select TWO.)

Question 13hardmulti select
Full question →

A company is implementing a data classification policy. According to best practices, which THREE of the following should be classified as 'restricted' or 'top secret'? (Select THREE).

Question 14easymulti select
Full question →

Which TWO of the following are fundamental principles of information security that form the CIA triad?

Question 15mediummulti select
Full question →

Which TWO are best practices for managing backup media?

Question 16mediummulti select
Full question →

Which TWO of the following are essential elements of an incident response plan?

Question 17mediummulti select
Full question →

Which THREE of the following are key objectives of a security risk management program?

Question 18mediummulti select
Full question →

Which TWO of the following are examples of Type 3 authentication? (Select TWO).

Question 19mediummulti select
Full question →

An organization is implementing a new access control system. Which TWO of the following are examples of Type 3 authentication factors?

Question 20hardmulti select
Full question →

Which THREE of the following are acceptable risk treatment options according to NIST risk management framework?

These CC practice questions are part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style CC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.