Certified Implementation Specialist - Risk and Compliance Free Sample Questions

20 free sample questions156 in the full practice test

Try simulator

CIS-RC Sample Questions

  1. Question 1

    A financial services firm is implementing Advanced Risk Assessment. They need to define a risk scoring methodology where the final score is calculated as a product of 'Likelihood' and 'Business Impact', but only if the 'Control Environment Effectiveness' is below a certain threshold. If effectiveness is high, the impact should be halved before calculation. Which ServiceNow GRC component is best suited for configuring this custom logic?

    Answer and explanation

    Correct answer: A

    Risk Assessment Methodologies (RAMs) in Advanced Risk allow for highly customized scoring logic. Using a 'Factor' of type 'Scripted' enables a developer to write a custom script that can implement complex conditional logic, such as modifying the impact based on control effectiveness before calculating the final score. Standard qualitative factors or risk matrix configurations do not support this level of conditional logic.

  2. Question 2

    During an implementation, an organization with thousands of servers wants to automatically create Entities for any server that hosts a 'PCI-Relevant' application. The list of these applications is managed in the CMDB. What is the most efficient and scalable way to configure this in the Entity Framework?

    Answer and explanation

    Correct answer: B

    The Entity Class approach is designed for this purpose. By creating a class on the Server table and using an advanced filter condition (dot-walking to the related application CI), entities can be generated dynamically and automatically. This is the most scalable and maintainable solution that leverages the CMDB relationship.

  3. Question 3

    Multiple answers

    A compliance manager has published a new 'Data Encryption Policy'. They need to ensure that all database administrators attest that they have read and understood the policy within 10 business days. Which of the following features should be used to manage this process? (Select TWO)

    Answer and explanation

    Correct answers: A, B

    Policy Acknowledgement campaigns are the specific feature designed to send out requests for users to acknowledge that they have read and will comply with a policy. It tracks responses and manages reminders.

    The 'Acknowledgement Audience' related list on the Policy record is where you define who needs to acknowledge the policy. This can be based on user groups (like 'Database Administrators'), roles, or individual users, and is a prerequisite for launching the campaign.

  4. Question 4

    True or False: In the GRC Entity Framework, an Entity Class can only reference a table that is a direct extension of the Configuration Item [cmdb_ci] table.

    Answer and explanation

    Correct answer: B

    An Entity Class can be created on any table in ServiceNow, not just those extending from [cmdb_ci]. This allows organizations to define entities from tables like Core Company [core_company], Department [cmn_department], or even custom tables, providing flexibility to model the organization's structure.

  5. Question 5

    A risk manager is reviewing the Risk Heatmap and notices that a critical risk, RSK001001, is showing in the 'Green' quadrant (Low/Low), despite having a calculated inherent score that should place it in the 'Red' quadrant (High/High). The controls associated with the risk are all in 'Monitor' state and have an effectiveness of 90%. What is the most likely reason for this discrepancy on the heatmap?

    Answer and explanation

    Correct answer: A

    Risk Heatmaps can be configured to plot risks based on either their inherent (pre-control) or residual (post-control) scores. Given that the controls are highly effective (90%), the residual score would be significantly lower than the inherent score. This would correctly place the risk in a lower-risk quadrant on a heatmap configured to show residual risk.

  6. Question 6

    A global retailer is setting up its Policy and Compliance module. They have a parent 'Code of Conduct' policy that applies to all employees worldwide. They also have regional 'Acceptable Use' policies for North America, Europe, and Asia, which contain specific clauses relevant to local regulations. What is the best practice for structuring these policies in ServiceNow?

    Answer and explanation

    Correct answer: B

    Using the parent/child policy relationship is the designed best practice for this scenario. It allows for a clear hierarchy, separate ownership and review cycles for the regional child policies, and the ability to link common controls from the parent down to the children. This structure is scalable and easy to navigate.

  7. Question 7

    A GRC implementation requires a new role for junior compliance analysts. This role should allow users to view Policies, Control Objectives, and Controls, and to create evidence requests. However, they should NOT be able to approve policy exceptions or move a control into the 'Attest' state. Which base GRC role would be the most appropriate starting point to clone and modify for this purpose?

    Answer and explanation

    Correct answer: C

    The sn_compliance.user role provides the correct baseline of permissions. It allows users to interact with compliance records, such as responding to requests and creating evidence, but does not grant high-level administrative or managerial permissions like approving exceptions or changing control states. It is the ideal starting point to clone for a junior analyst role.

  8. Question 8

    A hospital system is using ServiceNow GRC to manage HIPAA compliance. They need to generate controls for every department that handles Protected Health Information (PHI). They have a CMDB, but the concept of a 'department handling PHI' is a business construct, not a specific CI class. The list of these 30 departments is maintained by the compliance team. Which approach should be used to define these departments as Entities?

    Answer and explanation

    Correct answer: B

    The Entity Type approach is ideal for this scenario. It is designed for creating a manually curated collection of entities that may not be easily grouped by a simple filter condition. Since the list of 30 departments is small and maintained by a specific team, an Entity Type provides a direct and simple way to group them for GRC purposes.

  9. Question 9

    The scheduled job GRC Profile Generation is responsible for which of the following actions?

    Answer and explanation

    Correct answer: A

    This scheduled job runs periodically to evaluate the filter conditions on all active Entity Classes. It creates new Entity (Profile) records for source records that now match the filter, retires Entities whose source records no longer match, and updates existing Entities if their source data has changed.

  10. Question 10

    Multiple answers

    Which two of the following are valid response options for a risk identified during an assessment? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    Accept is a standard risk response strategy where the organization acknowledges the risk and decides not to take any action to reduce it, often because the cost of mitigation outweighs the potential loss.

    Mitigate is a common risk response strategy that involves implementing controls or countermeasures to reduce the likelihood or impact of the risk.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 156 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon