CIS-VR Vulnerability Response Practice Questions
Prepare for CIS-VR with more than an answer.
- Exam fee
- $450 USD
- Level
- Specialist
- Valid for
- 2 years
Domains covered on the exam 5
- Vulnerability Response Applications and Modules25%
- Getting Data into Vulnerability Response25%
- Tools to Manage Vulnerability Response23%
- Automating Vulnerability Response20%
- Vulnerability Response Dashboards and Reports7%
- 1
During a data import from a Rapid7 scanner, the Discovered Item [sn_vul_discovered_item] records are being created, but no Vulnerable Item [sn_vul_vulnerable_item] records are generated. The import set is completing without errors. What is the most likely reason for this behavior?
Show answer details
Correct answer: B
The creation of a Vulnerable Item (VIT) requires both a matched CI and a recognized vulnerability from a third-party source (like NVD). The Discovered Item record holds the raw data from the scanner. If this data lacks a valid identifier (CVE, Nessus ID, etc.) that can be matched to an entry in the Vulnerability [sn_vul_vulnerability] table, ServiceNow cannot create a VIT, even if the CI is successfully matched. The process stops after creating the Discovered Item.
- 2
What is the primary purpose of a Remediation Target Rule in Vulnerability Response?
Show answer details
Correct answer: B
Remediation Target Rules are essentially SLAs for vulnerabilities. They define a time-based target for remediation based on conditions, most commonly the risk rating of the Vulnerable Item. For example, a rule might state that all 'Critical' vulnerabilities must have a target resolution date of 15 days from detection. This target date is then used for reporting and escalation.
- 3
When marking a Vulnerable Item as a False Positive, the system can automatically close other existing VITs. What criteria must be met for another active VIT to be automatically closed as part of this action?
Show answer details
Correct answer: C
When a VIT is marked as a false positive, the system looks for other open VITs that share the exact same combination of Vulnerability, Configuration Item, and Port. This ensures that only identical findings are closed automatically. For example, if CVE-2023-1234 on port 443 of server 'web01' is a false positive, other VITs for the same CVE on the same server and port will also be closed.
- 4
A security manager wants to create a report showing the top 10 most common vulnerabilities (by CVE) across the entire organization. Which table would this report be based on?
Show answer details
Correct answer: B
The Vulnerable Item [sn_vul_vulnerable_item] table contains each specific instance of a vulnerability on a configuration item. To find the most common vulnerabilities, you would create a report on this table, group the results by the 'Vulnerability' field (which references the CVE), and then sort by the count in descending order to find the top 10.
- 5
The Container Vulnerability Response (CVR) module integrates with scanners to find vulnerabilities in container images. Where in ServiceNow are the details of a specific vulnerable container image stored?
Show answer details
Correct answer: B
Container Vulnerability Response extends the CMDB with new classes to accurately model containerized environments. A specific container image (e.g., 'nginx:1.21.1') is stored as a record in the 'Container Image' [cmdb_ci_container_image] table. Vulnerabilities found in that image are then linked to this CI record.
- 6
A financial services firm has integrated their Tenable.sc scanner with ServiceNow VR. During the initial import, a significant number of vulnerabilities are linked to 'Unclassed Hardware' CIs instead of the correct server CIs. The scanner reports assets by their FQDN, which exists in the
namefield of thecmdb_ci_servertable. Investigation reveals that the default CI Lookup Rules are failing. Which modification is the most effective way to resolve this matching issue for future imports?Show answer details
Correct answer: B
The most effective and scalable solution is to create a new, high-priority CI Lookup Rule. This rule explicitly tells the matching engine how to correlate the data provided by the scanner (FQDN) with the data in the CMDB (
namefield on the server table). This automates the process correctly for all future imports. Manual reassignment is not scalable. Modifying the base table or the integration itself is more complex and less aligned with best practices than using the built-in lookup rule functionality. - 7
A global enterprise needs to create a complex vulnerability assignment rule. The requirement is to assign vulnerabilities on any Oracle Database CI located in their Frankfurt or London datacenters to the 'EMEA DB Admin' group. However, if the vulnerability's CVSS base score is 9.0 or higher, it must be assigned directly to the 'Tier 3 Security' group, regardless of location. Which set of conditions in a single Assignment Rule would achieve this?
Show answer details
Correct answer: A
ServiceNow assignment rules are processed in order. The most effective way to handle this is with two separate rules. The first rule (with a lower order number, e.g., 100) should have the condition 'CVSS Score >= 9.0' and assign to 'Tier 3 Security'. The second rule (with a higher order number, e.g., 200) would handle the condition for Oracle DBs in specific locations and assign to 'EMEA DB Admin'. This ensures the high-criticality override is always processed first. Trying to combine this logic into a single rule with complex OR/AND conditions is prone to error and less maintainable.
- 8
A remediation owner finds that a critical vulnerability on a web server cannot be patched immediately due to the risk of breaking a legacy application. They need to request a temporary deferral of the remediation task. What is the standard process within the Vulnerability Response module for handling this situation?
Show answer details
Correct answer: C
The correct, out-of-the-box process for deferring a valid vulnerability is to use the Exception Management feature. From the Vulnerable Item (VIT), the user can request an exception, which formally documents the reason for the deferral, any compensating controls, and a requested duration. This request then goes through a formal approval process, providing an audit trail. Marking as a false positive is incorrect because the vulnerability is real. Closing it would remove it from active tracking. Changing the state to 'In Review' is not the final step for deferral.
- 9
The CISO of a large retail company wants a dashboard widget that displays the total number of active critical-risk Vulnerable Items, categorized by the Business Service they impact (e.g., 'E-commerce Platform', 'Inventory Management', 'Point of Sale Systems'). Which components are essential to build this specific widget? (Select THREE)
Show answer details
Correct answer: A, B, E
- 10
A mature organization is expanding its VR program to include application security. They use a SAST scanner that identifies vulnerabilities in their custom Java applications. To properly manage these findings in ServiceNow, which specific module should be implemented and configured?
Show answer details
Correct answer: D
Application Vulnerability Response (AVR) is the specific ServiceNow module designed to ingest, track, and manage vulnerabilities found in application code by tools like Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) scanners. CVR is for container images, ITOM VR is a broader term, and Configuration Compliance deals with misconfigurations, not code-level vulnerabilities.
