Browse all practice questions for the ServiceNow Certified Implementation Specialist – Risk and Compliance (CIS-RC) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

ServiceNow Certified Implementation Specialist – Risk and Compliance (CIS-RC) Practice Exam course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which table stores the links from Control Objective to Citation?
  • What can happen if a risk is marked as Retired?
  • On which records is the entity a required field?
  • What are Risk Indicators used for in the context of risk management?
  • An external audit team needs to view all of your published policies and controls. Which role can you give the team members?
  • The ServiceNow Platform requires which external component for data ingestion from other systems?
  • What is a key reason for a company to comply with the General Data Protection Regulation?
  • Entity Types are applied to which types of records?
  • What is the next state for a Risk Response Task once it is approved?
  • Which two options can be configured in the assessment context for a risk assessment methodology RAM?
  • Control Objectives are not active until the parent policy is in which state?
  • Which table extends from the Content Table?
  • Which role(s) has the capability to create Policies?
  • Which risk scoring methods are available in ServiceNow?
  • Common controls from UCF import into which table in ServiceNow?
  • What is the database name of the table Risk statement?
  • When a Risk Response task is moved to the Review state, who is notified through Notifications?
  • What is the correct formula for Risk Scoring?
  • If Approvers are not listed for a policy, to which state does the policy proceed?
  • Which of the following is not a trigger for issue creation?
  • What are the two approaches to entity scoping?
  • Which filter navigation syntax displays the table in list view within a separate browser tab?
  • Which two types of rules can be defined for Policy Exceptions?
  • There is a direct relationship between Entity Class and Entity Type when:
  • Which two components apply to the Qualitative method in classic risk assessment?
  • In GRC, what is the purpose of risk definitions?
  • What happens when an audit engagement is approved and there are remaining open tasks or issues?
  • Which GRC application is used to manage consultancy processes aimed at proving the effectiveness of controls?
  • In which state can control indicators be triggered or scheduled?
  • Which statement best describes an Authority Document in ServiceNow?
  • What GRC module would you access in order to update Entity Types?
  • Which type of indicators is available by default? (Select three)
  • For classic risk assessment, indicator failure factor represents the impact of risk indicator failures on what score?
  • What are the terms for level of risk before and after any actions are taken? (Choose two.)
  • All of the following are tables which exist within the GRC Profiles application scope EXCEPT?
  • If the Risk thresholds in the Risk Criteria Matrix do not align with company needs, what should be done?
  • An Observation can also be commonly known as what during an audit?
  • Which feature would you use to track completion of certain tasks?
  • What baseline criteria determine when notifications are triggered in relation to audit tasks? (Choose two.)
  • Which of the following types of customers may you encounter?
  • In the audit engagement approval process, what occurs if the engagement is approved with no remaining tasks or issues?
  • Which of these indicates a status for a Risk Response Task while it is currently being evaluated?
  • What is the primary purpose of a Risk Assessment?
  • In the baseline, who is assigned to complete control attestations by default?
  • Which tables extend the Content (sn_grc_content) table? (Choose two)
  • What dependency modeling feature can be used in the Classic UI to build relationships between Entity Classes?
  • How are the components of the SOX content pack linked together?
  • What is a risk register primarily used for?
  • What are the three actions an implementer needs to configure confidentiality?
  • What ensures that every time you create an Entity from a specific table, the Class of the Entity is set according to the rule?
  • What condition must be met to edit the factor guidance of a published risk assessment methodology (RAM)?
  • Which of the following extends from items?
  • Which role is the minimum required to create a policy acknowledgement campaign?
  • In which state are campaigns created for published policy records?
  • Which of the following is not a role in ServiceNow's risk and compliance module?
  • A control objective with no controls would lead to what outcome regarding Policy Exceptions?
  • Which statement correctly describes the risk management lifecycle process?
  • What table is populated if a regulatory change is determined to be applicable?
  • EMEA Data Centers are an example of what?
  • What state does an audit engagement return to if it is rejected?
  • What type of submission method is used for Policy Exceptions via the Service Portal?
  • How does GRC: Policy and Compliance Management track compliance to Authority Documents?
  • What table, along with the Policy table, is linked to the Control Objective table by a many-to-many relationship?
  • What best describes a risk register in ServiceNow?
  • What happens when you assign an Entity Type to a Risk Statement?
  • What user experience should be provided to view policies, create policy exceptions, and search for controls?
  • Which of the following is a characteristic of Controls in compliance scoring?
  • Controls are automatically moved to which state from the attestation phase?
  • Unified Compliance Framework (UCF) uses a slightly different nomenclature structure than ServiceNow. Common controls from UCF import into which table in ServiceNow?
  • What is the primary function of the Risk Assessment User role?
  • Which of the following is not used to source control data for a customer's control framework?
  • Which component is essential for risk assessment within the GRC framework?
  • Which of the following records does not have a lifecycle?
  • Upon rejection, to which state does the engagement return in ServiceNow?
  • Which of the following are scoped applications related to the Risk and Compliance applications? (Choose four)
  • What action must be completed before a policy can be automatically published?
  • What is the Risk likelihood called when using the Quantitative method?
  • The Calculated Risk Score utilizes data from the Inherent and Residual Risk scores to determine an adjusted ALE and Score. What other data drives the adjustments?
  • Which table is used to store links from Policy to Control Objective?
  • What table does the Acknowledgement Instance table extend from within the Policy Acknowledgement module?
  • Who should perform control attestation?
  • What is the main purpose of audit trails in GRC?
  • Which component is essential for mapping controls to risk assessments in GRC?
  • If you create a control manually and later decide to create them automatically, what will be the result?
  • Which table stores the links from the Entity Type to Risk Statement?
  • In the context of risk management, what does the term 'residual risk' refer to?
  • Under what condition can a Policy Exception not be approved related to the control objective and its state?
  • What does the term 'regulatory change task' refer to?
  • What new related list was added to the risk statement and entity records after migrating to advanced risk assessment?
  • Which property, when set to true, affects Risk, Entity, and Risk Statement forms?
  • Who is able to move a Policy into Review?
  • What is necessary for controls to be generated from a Control Objective?
  • What state does an audit engagement enter when it is approved but has remaining issues?
  • Who is responsible for reviewing the risk response and moving the Risk record into the Monitor state?
  • What are key prerequisites for a control test task to be generated?
  • What is the minimum role required to create a Risk Assessment Methodology (RAM)?
  • What is the purpose of a policy exception in ServiceNow?
  • Which two tables are part of the GRC: Policy and Compliance Management application scope?
  • In the context of risk management, what is the purpose of Risk Framework?
  • What content can be ingested into ServiceNow through UCF integration?
  • What are possible regulations when Entity scoping for Healthcare?
  • Which factor is essential for risk evaluation in the Risk Criteria Matrix?
  • Which state is the risk rating determined in for a Policy Exception?
  • What is the main purpose of the GRC Workbench?
  • When calculating compliance scores, what is true about the weighting of Controls?
  • Which Script Include is defined to change who can edit a policy in the "Review" state?
  • The Citation table in the GRC system is a child table of which parent?
  • What assessment types are included in the Advanced Risk application? (Select three)
  • In which state is the Policy when all necessary approvals have been received?
  • To enable policy exception requests from other applications, which information must be provided on the integration registry form?
  • Which of the following features is commonly configured by customers to improve classic risk scoring?
  • What is required for entities and controls to be created after associating a control objective and configuration test?
  • When does the Risk, Entity, and Risk Statement forms get impacted based on property settings?
  • What is the primary focus of the Risk Management process in GRC?
  • Which of the following statements is true of a Risk Response task?
  • The Single Loss Expectancy is $1,000,000 and the Annual Rate of Occurrence is 20%. What is the Annualized Loss Expectancy?
  • Where should the Policy acknowledge be defined?
  • Which aspect is crucial for evaluating the effectiveness of risk controls?
  • In which state can reviewers send a Policy back to draft or forward it by requesting approval?
  • For Risk, which role is required to create GRC Risk Assessment metric type?
  • What mapping capability in the Classic UI allows customers to relate specific Entities to each other within an Entity Class?
  • Which ServiceNow roles can manually move a Control record into the Monitor state? (Choose two.)
  • Which is not a type of key compliance indicator?
  • When creating a new assessment scheduler record for initiating advanced risk assessments, which two options should be selected?
  • Which of the following is NOT a Risk Response Task available in the Advanced Risk application?
  • Where does a policy get published to when it is approved?
  • A control objective has been related to a risk statement and they've been scoped with the same entity type. What can we expect to occur?
  • What is a necessary step when creating new policies in ServiceNow?
  • The consolidated assessment feature can be used on which of the following?
  • Which statement is true regarding Continuous Monitoring?
  • What change occurs when you activate the Confidential records feature?
  • In GRC terminology, what does ORM stand for?
  • For Control records, who can modify the Control in the Draft state?
  • Which roles are required to set the audience for policy acknowledgment? (Select two)
  • In Risk Management, which state signifies that a risk is being actively monitored?
  • What is a primary benefit of having a centralized risk management framework?
  • What happens when you assign an Entity Type to a Control Objective?
  • Which filter navigation syntax displays the default form view of the Risk table in the Content Frame?
  • An Entity can belong to one or multiple of which of the following?
  • What option is taken when the Control effectiveness is marked as 'Effective'?
  • The compliance score calculation may be modified by changing which control factor?
  • Annualized Loss Expectancy is associated with which risk score method?
  • Which role is typically responsible for defining the scope of risks in GRC?
  • What indicates a successful creation of controls after a control objective and configuration test have been associated?
  • What does GRC stand for in the context of risk and compliance?
  • What are some baseline tables that are commonly used to build an Entity Type?
  • What role does the Compliance Manager play in risk management?
  • Which Script include can be modified to change how the compliance scores roll up?
  • What would you use to accommodate a customer's unique process around policy approvals requiring a second layer of approval?
  • How does a risk statement relate to controls in risk management?
  • Where are 80% of new customers within the GRC maturity model?
  • Which four steps are necessary for integrating Policy with O365?
  • GRC Options in Interactive Filters are only available through which feature?
  • When creating a new assessment scheduler for advanced risk assessments, which two options must you select?
  • Which role is not part of ServiceNow GRC?
  • What are the different states available out of the box for classic/standard Risk management?
  • What does the Tablename.config display?
  • How can you get the SOX content pack?
  • In which state can indicators be created to continuously monitor a risk's exposure?
  • In which state is an attestation active and sent to the control owner?
  • What information is essential when creating a risk response plan?
  • Entity Types utilize Entity Filters to generate entities based on which kind of tables?
  • Which action would you take for effective management of audit engagements?
  • What is the minimum role required for creating a Risk Response in ServiceNow?
  • What is the main purpose of control objectives within GRC?
  • Which of the following describes the function of a compliance manager in GRC?
  • What role does the Chief Risk Officer play in GRC implementations?
  • In addition to Audit Manager, which roles should be assigned to ensure effective audit and GRC function management? (Choose two)
  • Which role is necessary to view compliance reports within GRC?
  • What are the scenarios under which issues can be created in audit management? (Select four)
  • All of the following are PARENT tables within the GRC Entities application scope EXCEPT?
  • What is a key benefit of utilizing GRC tools in an organization?
  • The 'Add to Update Set' utility is available for download via which platform?
  • Why would you create Entity classes?
  • What process is used to keep GRC policies updated and aligned with business needs?
  • The content table (sn_grcs_content) is a parent table of?
  • Santa Clara Facility and Boston Facility are examples of what?
  • What are the four values leveraged for the Inherent and Residual Risk Score Types?
  • Which action can a Policy Owner perform regarding policies in ServiceNow?
  • Which table extends from the Document Table?
  • What is the minimum role required to approve a Policy?
  • What table provides a complete view of all the components installed in an application scope?
  • SLE (quantitative) is equivalent to which qualitative term?
  • What is the primary purpose of Entity Classes in ServiceNow?
  • What types of tasks are specific to the Audit module? (Choose four.)
  • A Test template can be applied to which of the following?
  • Which table would typically contain authority documents related to compliance?
  • Which of the following is a task available in the Advanced Risk application for responding to risk?
  • What does the term "Risk Transfer" imply in risk management?
  • What condition must be met to edit the risk scoring logic of a Risk Assessment Methodology (RAM)?
  • Why would a Risk Manager want to utilize Entity Types and Entities?
  • What is the primary goal of policy exceptions in risk management?
  • What criterion must a control objective and risk statement share to automatically generate a relationship between a registered risk and a control?
  • What must be established to classify the severity of a risk?
  • What records inherit the Risk Scoring values from the Risk Statement?
  • What collection of tables extends the Document table in ServiceNow?
  • What action should be taken to quickly create Entities from an Entity Filter?
  • Which table stores the links from Entity to Entity Types?
  • In the context of Policy Exceptions, when do audit managers determine whether to audit entities?
  • Which methods does ServiceNow support for migrating new policies?
  • Which role is responsible for approving policies in ServiceNow?
  • When reviewing the Control Objective Table form with your customer, what are the most common choice lists to be configured? (Choose three.)
  • What action does a Business Rule take if there are Verification rules for the Policy Exception?
  • Who can manually retire the Policy? (Choose two)
  • Where can you configure the Regulatory Change Management impact assessment template?
  • Which GRC application would you use to determine where the organization is the most vulnerable or has the most exposure?
  • What are the primary tables for the GRC Advanced Risk application scope?
  • What types of tasks are specific to the Audit module?
  • Which segment of the financial industry governs the use of electronic forms of payment?
  • Which concept refers to the elimination of risk by avoiding related activities?
  • Which of the following describes an appropriate scenario for applying Risk Acceptance in risk management?
  • Who can move a Policy record from Review into the next state?
  • A customer wants to restrict access to compliance and risk information on the instance. What can be implemented? (Select two)
  • Control Failure Factor impacts which score?
  • What does the term "residual risk" refer to?
  • What role is essential for accessing GRC Risk Assessment functionalities?
  • What is the purpose of the annualized rate of occurrence (ARO) in risk assessment?
  • What is the primary purpose of entity scoping?
  • Controls are put in place to ensure adherence to policies and regulations. When are they also helpful?
  • What role does the Risk Owner play in the risk management process?
  • With which 'template' records can a control objective maintain a relationship?
  • What minimum role is needed to bulk initiate risk assessments using the risk assessment scheduler?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy