Vendor Risk Management Practice Questions
Prepare for CIS-VRM with more than an answer.
- Exam fee
- $450 USD
- Level
- Specialist
- Valid for
- 2 years
Domains covered on the exam 6
- Third-party Risk Management Fundamentals and Review23%
- Core Configuration14%
- Assessment Configuration33%
- Third-party Portal Configuration12%
- Third-party Supporting Processes12%
- Other Application Relationships6%
- 1
A company has integrated ServiceNow TPRM with a third-party risk intelligence provider that continuously monitors for security incidents. An alert is received indicating a critical data breach at a 'Tier 1' third party. Which ServiceNow application should this alert be routed to for immediate investigation and response, while also linking it back to the third party's risk profile?
Show answer details
Correct answer: C
For security-related events like data breaches, the best practice is to route the alert to the Security Incident Response (SIR) application within ServiceNow Security Operations. A security incident can be created, which allows for a formal, structured investigation by the security team. The security incident can then be linked to the third party's company record and a corresponding GRC Issue can be created to track the risk impact within the TPRM application.
- 2
True or False: The
sn_vdr_risk.vendor_adminrole allows a user to configure all aspects of the Third-party Risk Management application, including creating questionnaire templates and modifying risk scoring calculations.Show answer details
Correct answer: B
False. The
sn_vdr_risk.vendor_adminrole has limited administrative capabilities, primarily focused on managing vendor records and contacts. The role required to configure core application settings like questionnaire templates, risk scoring, and tiering rules issn_vdr_risk_asmt.vendor_risk_manager. - 3
A risk manager is reviewing a completed assessment and finds several answers from the third party that are unsatisfactory. What is the most direct, out-of-the-box action the risk manager can take from the assessment record to flag these specific answers for remediation?
Show answer details
Correct answer: C
The platform provides a 'Create Issue' UI action on the Question [asmt_metric] records within a completed assessment. This allows the assessor to generate a formal GRC Issue record that is automatically linked to the unsatisfactory answer, the assessment, and the third party, providing a clear audit trail for remediation.
- 4
A company policy mandates that all 'Tier 1' third parties must be reassessed every 12 months, while 'Tier 2' third parties must be reassessed every 24 months. Where is this logic for assessment frequency configured?
Show answer details
Correct answer: D
The frequency of recurring assessments is controlled by the Repeating Assessment [sn_vdr_risk_asmt_repeating_assessment] records. An administrator can create separate repeating assessment configurations, apply a filter (e.g., Tier is Tier 1), specify the assessment template to use, and set the repeat interval (e.g., 12 months). A separate record would be created for Tier 2 with a 24-month interval.
- 5
An organization wants to present a list of Frequently Asked Questions (FAQs) and key policy documents to third parties when they log into the portal. Which portal configuration capabilities should be used to achieve this? (Select TWO)
Show answer details
Correct answer: B, D
The best practice is to store FAQs and policy documents in a dedicated ServiceNow Knowledge Base. This allows for version control, approvals, and easy management. To display this information on the portal, you would use widgets like 'Icon Link' (to link to specific key articles or documents) or 'Simple List' (to show a list of articles from a specific category).
- 6
A TPRM implementation requires that the overall risk score for an assessment is calculated as a simple average of all risk area scores (e.g., Financial, Cybersecurity, Operational). The default calculation, however, is a weighted average. Where would a developer modify the calculation logic?
Show answer details
Correct answer: C
The core logic for calculating assessment risk scores is encapsulated in the
VdrAssessmentRiskCalculatorScript Include. To change the calculation method from a weighted average to a simple average, the best practice is to create a new script include that extends the original one and overrides the specific function responsible for the calculation. This preserves the original script for future upgrades while allowing for the required customization. - 7
Case Study: MedSecure, a healthcare provider, uses ServiceNow TPRM to manage risks associated with its suppliers. They are preparing for an external audit of their third-party compliance with the Health Insurance Portability and Accountability Act (HIPAA).
Process Overview: MedSecure has a GRC authority document for HIPAA in ServiceNow, with all relevant citations and controls defined. When a supplier is onboarded, they undergo a tiering assessment. Suppliers handling Protected Health Information (PHI) are tiered as 'High' and receive a HIPAA-specific questionnaire. Any 'No' answer to a critical question automatically generates a GRC Issue.
Auditor's Request: The auditor has asked for a report that demonstrates the following:
- A list of all 'High' tier suppliers.
- For each 'High' tier supplier, proof that they completed the HIPAA assessment within the last 12 months.
- A list of all open issues related to failed HIPAA controls for these suppliers.
- Evidence that these open issues are linked back to the specific HIPAA controls in the GRC authority document.
To fulfill this request efficiently, which relationship is MOST critical to have correctly established in the system?
Show answer details
Correct answer: B
While all relationships are important, the most critical one for satisfying the auditor's request (specifically point 4) is the link between the GRC Issue (generated from the failed assessment question) and the GRC Control Objective (the specific HIPAA control). This relationship provides the end-to-end traceability from a third party's operational failure to the specific compliance requirement, which is the cornerstone of a defensible audit.
- 8
A financial services firm is configuring their ServiceNow TPRM instance to automatically calculate a third-party's tier based on responses to an Inherent Risk Questionnaire (IRQ). The requirement is that if the third party will handle Personally Identifiable Information (PII) AND will be integrated with production systems, they must be assigned to the 'Tier 1 - Critical' level. However, if they only handle PII but are not integrated, they should be 'Tier 2 - High'. A risk manager reports that a new third party answering 'Yes' to both questions is incorrectly being assigned 'Tier 2'. Which of the following is the most likely cause of this misconfiguration?
Show answer details
Correct answer: A
ServiceNow evaluates tiering rules based on the 'Order' field, starting with the lowest number. If the conditions for 'Tier 2' (handles PII) are met by a rule with a lower order number, the system will assign that tier and stop processing further rules, even if the third party also meets the criteria for the 'Tier 1' rule which has a higher order number. The other options are incorrect because the script include
VdrTieringhandles the logic but is driven by the rule configuration, a data policy would prevent saving but not mis-tier, and UI policies only affect the user interface. - 9
A global manufacturing company wants to streamline its third-party risk assessment process. Their goal is to automatically trigger a specific set of questionnaires and document requests based on the inherent risk identified during the onboarding process. Which of the following components are essential to configure this automation? (Select THREE)
Show answer details
Correct answer: A, B, E
To automate assessment generation based on inherent risk, you need three key elements: 1) The IRQ to gather the initial risk data, 2) The Questionnaire Templates that will be sent out, and 3) Third-party Risk Assessment records (often called Assessment Templates or Due Diligence Requests in this context) which act as the trigger records that link the IRQ responses to the specific questionnaires.
- 10
During a TPRM implementation, a consultant is tasked with configuring risk rating and scoring. The client requires a weighted average calculation for the overall risk score, where the 'Cybersecurity' risk area is three times more important than 'Financial Stability'. Where would the consultant configure these weights to ensure risk scores are calculated according to the client's requirement?
Show answer details
Correct answer: C
The weighting for different risk categories (e.g., Cybersecurity, Financial, Reputational) used in the overall risk score calculation is defined in the 'Weight' field on the Risk Area [sn_vdr_risk_asmt_risk_area] records. By setting the weight for 'Cybersecurity' higher than other areas, it will have a greater impact on the final aggregated score.
