Certified Implementation Specialist - Vulnerability Response Free Sample Questions

20 free sample questions257 in the full practice test

Try simulator

CIS-VR Sample Questions

  1. Question 1

    A financial services firm has integrated their Tenable.sc scanner with ServiceNow VR. During the initial import, a significant number of vulnerabilities are linked to 'Unclassed Hardware' CIs instead of the correct server CIs. The scanner reports assets by their FQDN, which exists in the name field of the cmdb_ci_server table. Investigation reveals that the default CI Lookup Rules are failing. Which modification is the most effective way to resolve this matching issue for future imports?

    Answer and explanation

    Correct answer: B

    The most effective and scalable solution is to create a new, high-priority CI Lookup Rule. This rule explicitly tells the matching engine how to correlate the data provided by the scanner (FQDN) with the data in the CMDB (name field on the server table). This automates the process correctly for all future imports. Manual reassignment is not scalable. Modifying the base table or the integration itself is more complex and less aligned with best practices than using the built-in lookup rule functionality.

  2. Question 2

    A global enterprise needs to create a complex vulnerability assignment rule. The requirement is to assign vulnerabilities on any Oracle Database CI located in their Frankfurt or London datacenters to the 'EMEA DB Admin' group. However, if the vulnerability's CVSS base score is 9.0 or higher, it must be assigned directly to the 'Tier 3 Security' group, regardless of location. Which set of conditions in a single Assignment Rule would achieve this?

    Answer and explanation

    Correct answer: A

    ServiceNow assignment rules are processed in order. The most effective way to handle this is with two separate rules. The first rule (with a lower order number, e.g., 100) should have the condition 'CVSS Score >= 9.0' and assign to 'Tier 3 Security'. The second rule (with a higher order number, e.g., 200) would handle the condition for Oracle DBs in specific locations and assign to 'EMEA DB Admin'. This ensures the high-criticality override is always processed first. Trying to combine this logic into a single rule with complex OR/AND conditions is prone to error and less maintainable.

  3. Question 3

    A remediation owner finds that a critical vulnerability on a web server cannot be patched immediately due to the risk of breaking a legacy application. They need to request a temporary deferral of the remediation task. What is the standard process within the Vulnerability Response module for handling this situation?

    Answer and explanation

    Correct answer: C

    The correct, out-of-the-box process for deferring a valid vulnerability is to use the Exception Management feature. From the Vulnerable Item (VIT), the user can request an exception, which formally documents the reason for the deferral, any compensating controls, and a requested duration. This request then goes through a formal approval process, providing an audit trail. Marking as a false positive is incorrect because the vulnerability is real. Closing it would remove it from active tracking. Changing the state to 'In Review' is not the final step for deferral.

  4. Question 4

    Multiple answers

    The CISO of a large retail company wants a dashboard widget that displays the total number of active critical-risk Vulnerable Items, categorized by the Business Service they impact (e.g., 'E-commerce Platform', 'Inventory Management', 'Point of Sale Systems'). Which components are essential to build this specific widget? (Select THREE)

    Answer and explanation

    Correct answers: A, B, E

  5. Question 5

    A mature organization is expanding its VR program to include application security. They use a SAST scanner that identifies vulnerabilities in their custom Java applications. To properly manage these findings in ServiceNow, which specific module should be implemented and configured?

    Answer and explanation

    Correct answer: D

    Application Vulnerability Response (AVR) is the specific ServiceNow module designed to ingest, track, and manage vulnerabilities found in application code by tools like Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) scanners. CVR is for container images, ITOM VR is a broader term, and Configuration Compliance deals with misconfigurations, not code-level vulnerabilities.

  6. Question 6

    True or False: By default, the ServiceNow Vulnerability Response integration with Tenable.io only imports vulnerabilities that have been detected within the last 90 days.

    Answer and explanation

    Correct answer: A

    This is true. The 'Vulnerability Import since' property for the Tenable.io integration is set to 90 days by default. This is a configurable setting designed to prevent the import of a massive amount of historical, potentially irrelevant vulnerability data on the first run. Administrators can and often should adjust this value based on their specific requirements.

  7. Question 7

    An organization's risk calculation model needs to be updated. The new model requires that any vulnerability on a CI that is part of a 'PCI Compliant' business service automatically has its risk score increased by 20 points, in addition to the standard CVSS-based calculation. Which component of Vulnerability Response should be customized to implement this requirement?

    Answer and explanation

    Correct answer: B

    Vulnerability Calculator Groups contain one or more Vulnerability Calculators that define how the risk score is calculated. To add custom logic, such as increasing the score based on a CI's relationship to a business service, you would typically clone the default calculator and modify its script. This script can query related records (like the Business Service) and adjust the score accordingly. This modified calculator is then made active within the group.

  8. Question 8

    A hospital is using ServiceNow VR to manage vulnerabilities on medical devices. When a high-severity vulnerability is confirmed on a device, a standard change request must be created and linked to the Vulnerability Group for patching. Which ServiceNow feature is best suited to automate the creation of this change request when the Vulnerability Group's state is moved to 'Awaiting Change'?

    Answer and explanation

    Correct answer: C

    Flow Designer is ServiceNow's modern, low-code solution for process automation. It is the ideal tool for this scenario. A flow can be configured with a trigger that runs whenever a Vulnerability Group record is updated and its 'State' field changes to 'Awaiting Change'. The flow can then use the 'Create Record' action to generate a new change request, populating its fields with data from the vulnerability group.

  9. Question 9

    A SecOps manager wants to analyze the Mean Time to Remediate (MTTR) for vulnerabilities, but wants to see the data trended over time and broken down by the CI's operating system. What Performance Analytics component allows for filtering the indicator data by operating system?

    Answer and explanation

    Correct answer: C

    In Performance Analytics, a Breakdown is used to group or filter indicator scores for more detailed analysis. To see MTTR (the Indicator) by operating system, you would create a Breakdown based on the 'Operating System' field of the Configuration Item table. This allows users to view the overall MTTR score and then drill down to see the scores for Windows, Linux, etc., individually.

  10. Question 10

    When implementing Application Vulnerability Response (AVR), a developer needs to understand how ServiceNow uniquely identifies an application vulnerability finding. Which combination of fields is typically used to create a unique key for an Application Vulnerable Item (AVI)?

    Answer and explanation

    Correct answer: A

    For Application Vulnerable Items (AVIs), ServiceNow needs to distinguish the same vulnerability (e.g., a specific CWE) across different codebases. The unique key is typically a combination of the specific vulnerability identifier (from the scanner), the application or repository being scanned, and the specific branch where the vulnerability was found. This allows for tracking the same SQL injection flaw in the 'main' branch and a 'feature' branch as two distinct AVIs.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 257 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon