Courseiva
Back to (ISC)2 Information Systems Security Architecture Professional (CISSP-ISSAP, Aug 2025 blueprint) (ISC) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise (ISC)2 Information Systems Security Architecture Professional (CISSP-ISSAP, Aug 2025 blueprint) (ISC) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
ISC
exam code
(ISC)²
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related ISC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

When designing a secure multi-region cloud architecture, which THREE governance aspects must be clearly defined for data residency compliance?

Question 2mediummulti select
Full question →

Which THREE criteria are most important when selecting a Cloud Service Provider (CSP) based on the Shared Responsibility Model for an ISSAP architect?

Question 3hardmulti select
Full question →

Which TWO methods are used to prevent 'Token Replay' attacks in an OAuth/OIDC architecture?

Question 4hardmulti select
Full question →

A security architect is hardening a Linux-based server environment. Which TWO of the following kernel-level security modules should be configured to enforce mandatory access control?

Question 5hardmulti select
Full question →

To implement effective Risk Management integration into architecture using the FAIR (Factor Analysis of Information Risk) framework, which THREE metrics must an architect define for each identified scenario?

Question 6mediummulti select
Full question →

When establishing a Third-Party Risk Management (TPRM) process, which THREE factors must be considered during the initial due diligence?

Question 7hardmulti select
Full question →

An architect is evaluating compliance for an enterprise multi-cloud environment. Which THREE capabilities must be included in a centralized GRC platform for it to be effective?

Question 8easymulti select
Full question →

Which TWO factors are critical when establishing a Risk Appetite statement for a new cloud-native architecture?

Question 9hardmulti select
Full question →

Which TWO risks are significantly mitigated by implementing a Privileged Access Management (PAM) vault?

Question 10mediummulti select
Full question →

Which TWO actions should be taken when integrating a new cloud service into an existing GRC program?

Question 11hardmulti select
Full question →

Which THREE of the following are risks associated with using shared cloud storage buckets?

Question 12mediummulti select
Full question →

Which THREE types of claims are typically included in a JSON Web Token (JWT)?

Question 13mediummulti select
Full question →

Which TWO factors are mandatory for a secure 'MFA' implementation?

Question 14mediummulti select
Full question →

When designing an architecture for GDPR compliance, which THREE technical controls should be prioritized to satisfy the 'Right to be Forgotten' requirement?

Question 15mediummulti select
Full question →

Which THREE attributes should be evaluated when defining access policies in a modern Zero Trust Architecture?

Question 16mediummulti select
Full question →

Which TWO of the following are essential for protecting against SQL Injection?

Question 17mediummulti select
Full question →

Which THREE features are essential for a robust Privileged Access Management (PAM) architecture that adheres to the principle of least privilege?

Question 18hardmulti select
Full question →

Which THREE mechanisms are commonly used to secure the 'Authorization Code' in an OAuth 2.0 flow?

Question 19easymulti select
Full question →

Which THREE of the following are common network security architecture tools?

Question 20mediummulti select
Full question →

Which TWO concepts are central to 'Federated Identity'?

These ISC practice questions are part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style ISC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.