CIS-RC Risk and Compliance Practice Questions
Prepare for CIS-RC with more than an answer.
- Exam fee
- $450 USD
- Level
- Specialist
- Valid for
- Valid until next platform release
Domains covered on the exam 7
- GRC Overview11.67%
- Implementation Planning5%
- Entity Framework20%
- Policy and Compliance25%
- Risk and Advanced Risk25%
- Common Elements and Extended Capabilities8.33%
- Audit and Advanced Audit5%
- 1
A risk manager is configuring an Advanced Risk Assessment. They want to ensure that if a risk's calculated score exceeds 20 (on a 1-25 scale), an Issue is automatically generated and assigned to the risk owner for immediate action. How should this be implemented?
Show answer details
Correct answer: C
The Risk Assessment Methodology (RAM) record in Advanced Risk Assessment provides built-in functionality for thresholds. You can define a threshold for the final computed score and configure an action, such as 'Create Issue', to be triggered automatically when the score crosses that threshold. This is the correct, codeless way to implement this requirement.
- 2
What are the primary drivers for an organization to choose the Entity Class scoping method over the Entity Type method? (Select THREE)
Show answer details
Correct answer: B, C, E
Entity Classes excel at this. They use filter conditions on a source table to automatically create, update, and retire entities as the underlying data (e.g., CMDB) changes.
Entity Classes can be configured to create parent-child relationships that reflect relationships in the source data (e.g., a server contained within a data center), allowing for the automatic generation of a meaningful entity hierarchy.
For large, dynamic populations of entities (like servers, applications, or vendors), the automated nature of Entity Classes is far more scalable and maintainable than manually managing them in an Entity Type.
- 3
During implementation planning for a small startup with 50 employees, the project manager argues that the GRC module is too complex and they should just use spreadsheets. What is a key benefit of the ServiceNow GRC platform that directly addresses the limitations of a spreadsheet-based approach?
Show answer details
Correct answer: B
This is a core value proposition of ServiceNow GRC. Spreadsheets are siloed and lack the ability to create and maintain auditable links between different GRC objects (e.g., showing which controls support a policy, and which risks are mitigated by those controls). The platform provides this relational data model, ensuring data integrity and simplifying audits.
- 4
A control owner has submitted a request for a policy exception because a legacy server cannot be patched to meet a specific security control's requirement. The exception is granted for 90 days. What should happen automatically when the 90-day period expires?
Show answer details
Correct answer: A
When a policy exception that made a control 'Compliant' (via the exception) expires, the system automatically re-evaluates the control's compliance. Since the underlying condition that required the exception still exists, the control's state will revert to 'Non-Compliant', triggering notifications and appearing on dashboards. This automated reassessment is a key feature of the exception management process.
- 5
A GRC administrator is troubleshooting why a specific control, CTRL005001, which is linked to a published policy, has not been generated for a newly created Entity, ENT003001. The Entity was created successfully by an Entity Class rule. What is the most likely cause of this issue?
Show answer details
Correct answer: C
This is a common implementation mistake. Controls are generated for an entity when that entity is in scope for the parent policy. A policy's scope is defined by the Entity Types linked to it. Even if an Entity record exists, if it does not belong to the Entity Type that scopes the policy, no controls from that policy will be generated for it. The fact that the entity was created via an Entity Class is irrelevant to how the policy is scoped.
- 6
A financial services firm is implementing Advanced Risk Assessment. They need to define a risk scoring methodology where the final score is calculated as a product of 'Likelihood' and 'Business Impact', but only if the 'Control Environment Effectiveness' is below a certain threshold. If effectiveness is high, the impact should be halved before calculation. Which ServiceNow GRC component is best suited for configuring this custom logic?
Show answer details
Correct answer: A
Risk Assessment Methodologies (RAMs) in Advanced Risk allow for highly customized scoring logic. Using a 'Factor' of type 'Scripted' enables a developer to write a custom script that can implement complex conditional logic, such as modifying the impact based on control effectiveness before calculating the final score. Standard qualitative factors or risk matrix configurations do not support this level of conditional logic.
- 7
During an implementation, an organization with thousands of servers wants to automatically create Entities for any server that hosts a 'PCI-Relevant' application. The list of these applications is managed in the CMDB. What is the most efficient and scalable way to configure this in the Entity Framework?
Show answer details
Correct answer: A
The Entity Class approach is designed for this purpose. By creating a class on the Server table and using an advanced filter condition (dot-walking to the related application CI), entities can be generated dynamically and automatically. This is the most scalable and maintainable solution that leverages the CMDB relationship.
- 8
A compliance manager has published a new 'Data Encryption Policy'. They need to ensure that all database administrators attest that they have read and understood the policy within 10 business days. Which of the following features should be used to manage this process? (Select TWO)
Show answer details
Correct answer: C, D
Policy Acknowledgement campaigns are the specific feature designed to send out requests for users to acknowledge that they have read and will comply with a policy. It tracks responses and manages reminders.
The 'Acknowledgement Audience' related list on the Policy record is where you define who needs to acknowledge the policy. This can be based on user groups (like 'Database Administrators'), roles, or individual users, and is a prerequisite for launching the campaign.
- 9
True or False: In the GRC Entity Framework, an Entity Class can only reference a table that is a direct extension of the Configuration Item [cmdb_ci] table.
Show answer details
Correct answer: B
An Entity Class can be created on any table in ServiceNow, not just those extending from [cmdb_ci]. This allows organizations to define entities from tables like Core Company [core_company], Department [cmn_department], or even custom tables, providing flexibility to model the organization's structure.
- 10
A risk manager is reviewing the Risk Heatmap and notices that a critical risk, RSK001001, is showing in the 'Green' quadrant (Low/Low), despite having a calculated inherent score that should place it in the 'Red' quadrant (High/High). The controls associated with the risk are all in 'Monitor' state and have an effectiveness of 90%. What is the most likely reason for this discrepancy on the heatmap?
Show answer details
Correct answer: D
Risk Heatmaps can be configured to plot risks based on either their inherent (pre-control) or residual (post-control) scores. Given that the controls are highly effective (90%), the residual score would be significantly lower than the inherent score. This would correctly place the risk in a lower-risk quadrant on a heatmap configured to show residual risk.
