ExamGecko
Home Home / ServiceNow / CIS-RC

ServiceNow CIS-RC Practice Test - Questions Answers, Page 5

Question list
Search
Search

Control indicators may be triggered or scheduled in which state?

A.
Retired
A.
Retired
Answers
B.
Monitor
B.
Monitor
Answers
C.
Review
C.
Review
Answers
D.
Attest
D.
Attest
Answers
E.
Draft
E.
Draft
Answers
Suggested answer: D

Explanation:

Reference: https://docs.servicenow.com/bundle/orlando-governance-riskcompliance/page/product/grc-risk/task/t_CreateRisk.html

Which role reviews the risk response and moves the Risk record into the Monitor state at the appropriate time?

A.
Risk Manager
A.
Risk Manager
Answers
B.
Risk User
B.
Risk User
Answers
C.
Risk Reader
C.
Risk Reader
Answers
D.
Risk Owner
D.
Risk Owner
Answers
Suggested answer: A

Explanation:

Reference: https://docs.servicenow.com/bundle/orlando-governance-riskcompliance/page/product/grc-risk/task/t_CreateRisk.html

Entity scoping is used for what?

A.
Make sure that all of your Entities have the right visibility
A.
Make sure that all of your Entities have the right visibility
Answers
B.
Create and assign controls to the correct users
B.
Create and assign controls to the correct users
Answers
C.
Create, assign, and manage controls and risks across an enterprise
C.
Create, assign, and manage controls and risks across an enterprise
Answers
D.
Scope out the different users and roles that have access to the platform
D.
Scope out the different users and roles that have access to the platform
Answers
Suggested answer: B

Explanation:

Reference: https://docs.servicenow.com/bundle/newyork-governance-riskcompliance/page/product/grccommon/task/create-a-profile.html

The SOX content pack includes a series of policies, control, risks. How are all of these components linked together?

A.
Mapping File
A.
Mapping File
Answers
B.
Manually
B.
Manually
Answers
C.
Automatically
C.
Automatically
Answers
D.
Batch import
D.
Batch import
Answers
Suggested answer: C

UCF has a collection of what? Select all UCF terms.

(Choose three.)

A.
Control Indicators
A.
Control Indicators
Answers
B.
Authority Documents
B.
Authority Documents
Answers
C.
Policies
C.
Policies
Answers
D.
Citations
D.
Citations
Answers
E.
Controls
E.
Controls
Answers
Suggested answer: B, D, E

Explanation:

Reference: https://docs.servicenow.com/bundle/orlando-governance-riskcompliance/page/product/grc-ucfimport/concept/c_UCF.html

As a customer reaches greater GRC maturity, what can we expect to see occurring across their organization? (Choose three.)

A.
Single Risk and Control frameworks across enterprise available to all stakeholders
A.
Single Risk and Control frameworks across enterprise available to all stakeholders
Answers
B.
Reliance on spreadsheet management for risk reporting
B.
Reliance on spreadsheet management for risk reporting
Answers
C.
Continuous real-time monitoring of control performance
C.
Continuous real-time monitoring of control performance
Answers
D.
Cross-functional process automation
D.
Cross-functional process automation
Answers
E.
Reactive strategies for GRC activities
E.
Reactive strategies for GRC activities
Answers
Suggested answer: A, C, E

Which scheduled jobs in the GRC: Profiles scope help manage the population of Entity records?

(Choose two.)

A.
GRC indicator nightly run
A.
GRC indicator nightly run
Answers
B.
GRC Entity and Risk Statement Data Collection
B.
GRC Entity and Risk Statement Data Collection
Answers
C.
GRC Profile Generation
C.
GRC Profile Generation
Answers
D.
GRC Refresh Risk Scores
D.
GRC Refresh Risk Scores
Answers
Suggested answer: A, D

Which of the following is the correct statement about Risk Scoring formulas?

A.
SLE × ARO = ALE
A.
SLE × ARO = ALE
Answers
B.
ALE × ARO = Compliance Score
B.
ALE × ARO = Compliance Score
Answers
C.
ALE × ARO = SLE
C.
ALE × ARO = SLE
Answers
D.
Impact × Urgency = ALE
D.
Impact × Urgency = ALE
Answers
Suggested answer: C

For classic risk assessment, while a Risk is in the Assess state, reviewers can do which of the following? (Choose two.)

A.
Answer the assessment, moving the Risk to Respond
A.
Answer the assessment, moving the Risk to Respond
Answers
B.
Set the Risk to Monitor
B.
Set the Risk to Monitor
Answers
C.
Delete the Risk
C.
Delete the Risk
Answers
D.
Set the Risk back to Draft
D.
Set the Risk back to Draft
Answers
Suggested answer: B, D

What is the condition that must exist to edit the factor guidance of a published risk assessment methodology (RAM)?

A.
All assessment instance records are in the Monitor state
A.
All assessment instance records are in the Monitor state
Answers
B.
All assessment instance records are closed
B.
All assessment instance records are closed
Answers
C.
All assessment instance records are deleted
C.
All assessment instance records are deleted
Answers
D.
States of the assessment instance records are irrelevant
D.
States of the assessment instance records are irrelevant
Answers
E.
All assessment instance records are canceled
E.
All assessment instance records are canceled
Answers
Suggested answer: C
Total 121 questions
Go to page: of 13