CIS-VR Vulnerability Response Practice Questions
Prepare for CIS-VR with more than an answer.
- Exam fee
- $450 USD
- Level
- Specialist
- Valid for
- 2 years
Domains covered on the exam 5
- Vulnerability Response Applications and Modules25%
- Getting Data into Vulnerability Response25%
- Tools to Manage Vulnerability Response23%
- Automating Vulnerability Response20%
- Vulnerability Response Dashboards and Reports7%
- 1
Case Study
A multinational corporation, GlobalCorp, has just completed its initial implementation of ServiceNow Vulnerability Response. They have integrated Qualys for infrastructure scanning and Veracode for application scanning. The CMDB is populated by ServiceNow Discovery but has known data quality issues, with many servers lacking a value for the 'Support group' and 'Managed by' fields. The security team is overwhelmed with the volume of newly created Vulnerable Items (VITs).
The Head of Security Operations has outlined three primary objectives:
- Ensure all new critical VITs are assigned to the correct remediation team within 4 hours.
- Reduce the noise by automatically closing low-risk vulnerabilities on development systems.
- Provide a clear way for application owners to request exceptions for vulnerabilities that cannot be immediately fixed.
Given the state of the CMDB and the stated objectives, which of the following represents the most effective strategy to implement first?
flowchart TD subgraph Qualys_Data A[Scanner Results] --> B{CI Matching} end subgraph CMDB C[Server CIs] -- Has Support Group? --> D{Yes/No} end subgraph Veracode_Data E[App Scan Results] --> F{AVI Creation} end B --> G[VIT Creation] D -->|No| H[Unassigned VITs] D -->|Yes| I[Assigned VITs]Show answer details
Correct answer: B
This strategy directly addresses all three objectives with practical, immediate steps. 1) The default assignment rule ensures critical VITs don't remain unassigned, meeting the 4-hour goal by routing them for manual triage while CMDB issues are fixed. 2) The auto-close rule immediately reduces noise, allowing the team to focus on higher-risk items. 3) Activating the exception workflow provides the required process for application owners. This pragmatic approach provides immediate value while the longer-term CMDB cleanup occurs in parallel.
- 2
The
sn_vul.vulnerability_analystrole is considered a primary operational role in Vulnerability Response. Which of the following tasks can a user with ONLY this role perform? (Select TWO)Show answer details
Correct answer: B, C
- 3
During a data import from a Rapid7 scanner, the Discovered Item [sn_vul_discovered_item] records are being created, but no Vulnerable Item [sn_vul_vulnerable_item] records are generated. The import set is completing without errors. What is the most likely reason for this behavior?
Show answer details
Correct answer: B
The creation of a Vulnerable Item (VIT) requires both a matched CI and a recognized vulnerability from a third-party source (like NVD). The Discovered Item record holds the raw data from the scanner. If this data lacks a valid identifier (CVE, Nessus ID, etc.) that can be matched to an entry in the Vulnerability [sn_vul_vulnerability] table, ServiceNow cannot create a VIT, even if the CI is successfully matched. The process stops after creating the Discovered Item.
- 4
What is the primary purpose of a Remediation Target Rule in Vulnerability Response?
Show answer details
Correct answer: B
Remediation Target Rules are essentially SLAs for vulnerabilities. They define a time-based target for remediation based on conditions, most commonly the risk rating of the Vulnerable Item. For example, a rule might state that all 'Critical' vulnerabilities must have a target resolution date of 15 days from detection. This target date is then used for reporting and escalation.
- 5
When marking a Vulnerable Item as a False Positive, the system can automatically close other existing VITs. What criteria must be met for another active VIT to be automatically closed as part of this action?
Show answer details
Correct answer: C
When a VIT is marked as a false positive, the system looks for other open VITs that share the exact same combination of Vulnerability, Configuration Item, and Port. This ensures that only identical findings are closed automatically. For example, if CVE-2023-1234 on port 443 of server 'web01' is a false positive, other VITs for the same CVE on the same server and port will also be closed.
- 6
A security manager wants to create a report showing the top 10 most common vulnerabilities (by CVE) across the entire organization. Which table would this report be based on?
Show answer details
Correct answer: B
The Vulnerable Item [sn_vul_vulnerable_item] table contains each specific instance of a vulnerability on a configuration item. To find the most common vulnerabilities, you would create a report on this table, group the results by the 'Vulnerability' field (which references the CVE), and then sort by the count in descending order to find the top 10.
- 7
The Container Vulnerability Response (CVR) module integrates with scanners to find vulnerabilities in container images. Where in ServiceNow are the details of a specific vulnerable container image stored?
Show answer details
Correct answer: B
Container Vulnerability Response extends the CMDB with new classes to accurately model containerized environments. A specific container image (e.g., 'nginx:1.21.1') is stored as a record in the 'Container Image' [cmdb_ci_container_image] table. Vulnerabilities found in that image are then linked to this CI record.
- 8
A financial services firm has integrated their Tenable.sc scanner with ServiceNow VR. During the initial import, a significant number of vulnerabilities are linked to 'Unclassed Hardware' CIs instead of the correct server CIs. The scanner reports assets by their FQDN, which exists in the
namefield of thecmdb_ci_servertable. Investigation reveals that the default CI Lookup Rules are failing. Which modification is the most effective way to resolve this matching issue for future imports?Show answer details
Correct answer: B
The most effective and scalable solution is to create a new, high-priority CI Lookup Rule. This rule explicitly tells the matching engine how to correlate the data provided by the scanner (FQDN) with the data in the CMDB (
namefield on the server table). This automates the process correctly for all future imports. Manual reassignment is not scalable. Modifying the base table or the integration itself is more complex and less aligned with best practices than using the built-in lookup rule functionality. - 9
A global enterprise needs to create a complex vulnerability assignment rule. The requirement is to assign vulnerabilities on any Oracle Database CI located in their Frankfurt or London datacenters to the 'EMEA DB Admin' group. However, if the vulnerability's CVSS base score is 9.0 or higher, it must be assigned directly to the 'Tier 3 Security' group, regardless of location. Which set of conditions in a single Assignment Rule would achieve this?
Show answer details
Correct answer: A
ServiceNow assignment rules are processed in order. The most effective way to handle this is with two separate rules. The first rule (with a lower order number, e.g., 100) should have the condition 'CVSS Score >= 9.0' and assign to 'Tier 3 Security'. The second rule (with a higher order number, e.g., 200) would handle the condition for Oracle DBs in specific locations and assign to 'EMEA DB Admin'. This ensures the high-criticality override is always processed first. Trying to combine this logic into a single rule with complex OR/AND conditions is prone to error and less maintainable.
- 10
A remediation owner finds that a critical vulnerability on a web server cannot be patched immediately due to the risk of breaking a legacy application. They need to request a temporary deferral of the remediation task. What is the standard process within the Vulnerability Response module for handling this situation?
Show answer details
Correct answer: C
The correct, out-of-the-box process for deferring a valid vulnerability is to use the Exception Management feature. From the Vulnerable Item (VIT), the user can request an exception, which formally documents the reason for the deferral, any compensating controls, and a requested duration. This request then goes through a formal approval process, providing an audit trail. Marking as a false positive is incorrect because the vulnerability is real. Closing it would remove it from active tracking. Changing the state to 'In Review' is not the final step for deferral.
