CIS-SIR Security Incident Response Practice Questions
Prepare for CIS-SIR with more than an answer.
- Exam fee
- $450 USD
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 6
- Security Incident Response Overview and Data Visualization15%
- Security Incident Creation and Threat Intelligence14%
- Security Incident and Threat Intelligence Integrations14%
- Security Incident Response Management15%
- Risk Calculations and Post Incident Response12%
- Automation and Standard Processes30%
- 1
Security tag used when a piece of information requires support to be effectively acted upon, yet carries risks to privacy, reputation, or operations if shared outside of the organizations involved.
Show answer details
Correct answer: B
B
- 2
A pre-planned response process contains which sequence of events?
Show answer details
Correct answer: A
A
- 3
Which of the following tag classifications are provided baseline? (Choose three.)
Show answer details
Correct answer: A, C, G
A, C, G -- Reference; https://docs.servicenow.com/bundle/paris-security-management/page/product/security-operations-common/task/create-class-qroup-and-taqs.ht.ml
- 4
A Post Incident Review can contain which of the following? (Choose three.)
Show answer details
Correct answer: A, B, D
A, B, D
A, B, D
A, B, D
- 5
In order to see the Actions in Flow Designer for Security Incident, what plugin must be activated?
Show answer details
- 6
Which of the following process definitions allow only single-step progress through the process defined without allowing step skipping?
Show answer details
Correct answer: B
B
- 7
What is the primary role of an ingestion rule in the User Reported Phishing V2 process?
sequenceDiagram participant User participant Mail Server participant ServiceNow participant SIR User->>Mail Server: Forwards Phishing Email Mail Server->>ServiceNow: Delivers Email ServiceNow->>ServiceNow: Inbound Action Runs ServiceNow->>SIR: Creates Phishing Record SIR->>SIR: **Ingestion Rule Evaluates** SIR-->>SIR: Creates/Updates Security IncidentShow answer details
Correct answer: B
After the inbound action creates a record in the Security Phishing Email table, the ingestion rule is triggered. Its main purpose is to provide de-duplication and aggregation logic. It evaluates the submission to see if it relates to an existing, active phishing campaign (in which case it would update the sighting count on the existing incident) or if it's a new threat that requires the creation of a brand new security incident.
- 8
What does a flow require?
Show answer details
Correct answer: D
D
- 9
Which one of the following reasons best describes why roles for Security Incident Response (SIR) begin with "sn_si"?
Show answer details
Correct answer: B
B
- 10
A flow consists of ___________. (Choose two.)
Show answer details
Correct answer: B, E
