Courseiva
Back to ISC2 Certified in Cybersecurity CC questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise ISC2 Certified in Cybersecurity CC practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CC
exam code
ISC2
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

Which TWO are true about a differential backup? (Select two.)

Question 2mediummulti select
Full question →

A security administrator is implementing controls to protect a server room. Which TWO physical security layers should be included as part of a defense-in-depth strategy? (Select TWO.)

Question 3hardmulti select
Full question →

Which THREE are differences between a hot site and a cold site? (Select three.)

Question 4easymulti select
Full question →

Which TWO of the following are best practices for password management in a corporate environment?

Question 5hardmulti select
Full question →

A security operations center (SOC) analyst is investigating a potential data exfiltration. Which two indicators are most likely signs of data exfiltration?

Question 6hardmulti select
Full question →

A security team is investigating a potential ARP spoofing attack on the local network. Which two measures can effectively detect or prevent such attacks? (Choose two.)

Question 7hardmulti select
Full question →

Which THREE of the following are essential components of an incident response plan? (Select THREE.)

Question 8mediummulti select
Full question →

Which TWO of the following are examples of sensitive PII? (Select TWO.)

Question 9mediummulti select
Full question →

A financial services company is conducting a Business Impact Analysis (BIA) for its online banking platform. Which THREE of the following are correctly defined metrics used in BIA?

Question 10hardmulti select
Full question →

Which THREE of the following are considered risk management strategies? (Select THREE)

Question 11hardmulti select
Full question →

After a major power outage, an organization needs to declare a disaster and activate its DRP. Which THREE elements should be included in the initial crisis communication?

Question 12hardmulti select
Full question →

A security analyst is reviewing data handling procedures. Which THREE of the following are considered sensitive PII?

Question 13easymulti select
Full question →

A network security team is implementing a defense-in-depth strategy. Which TWO of the following controls are examples of network segmentation? (Choose two.)

Question 14mediummulti select
Full question →

Which TWO of the following are common indicators of a phishing email? (Select TWO.)

Question 15mediummulti select
Full question →

Which THREE elements are essential components of a business continuity plan (BCP)?

Question 16hardmulti select
Open the full VLAN trunking answer →

A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?

Question 17hardmulti select
Full question →

Which THREE security mechanisms should be implemented to secure a network against ARP spoofing attacks? (Choose three.)

Question 18mediummulti select
Full question →

Which TWO of the following are commonly used techniques to detect phishing emails? (Choose two.)

Question 19easymulti select
Full question →

Which TWO of the following are examples of integrity controls? (Select TWO)

Question 20easymulti select
Full question →

Which two protocols operate at the Transport layer of the OSI model? (Choose TWO.)

These CC practice questions are part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style CC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.