CIS-RC Practice Questions

Certified Implementation Specialist - Risk and Compliance

60 practice questions across 7 topics • 15 free

Exam Overview

60
Exam Questions
90 min
Duration
70%
Passing Score
$450
Exam Cost
60+
Practice Questions
15
Free Questions

Practice Questions

60 questions from 7 topics
1
knowledge

Before using any GRC applications, what must be verified first?

APlatform version compatibility
BEntitlement to the applications (valid licenses)
CDemo data availability
DPlugin dependencies

👆 Click an option above to select your answer

2
knowledgeSelect all that apply

Which GRC applications are available for download from the ServiceNow Store? (Choose three.)

AAudit Management
BBusiness Continuity Management
CService Catalog Management
DRegulatory Change Management
EKnowledge Management

👆 Click an option above to select your answer

3
understanding

Starting with Orlando, what happens when you activate a core GRC application?

ADemo data is automatically loaded
BDependency plugins are automatically activated
CUser roles are automatically assigned
DAll related GRC applications are activated

👆 Click an option above to select your answer

4
knowledge

What role is required to activate an entitled GRC ServiceNow Store application?

Asn_audit.manager
Bsn_compliance.admin
Cadmin
Dsn_grc.user

👆 Click an option above to select your answer

5
knowledgeSelect all that apply

Which roles are required to accept, reject, or cancel an evidence request? (Choose two.)

Asn_audit.user
Bsn_compliance.manager
Csn_audit.admin
Ditil

👆 Click an option above to select your answer

6
understanding

When you add an entity to an audit engagement, what else is automatically added to the engagement?

AOnly the associated controls
BThe corresponding risks, controls, test plans, and indicator results of the entity
COnly the associated risks
DOnly the auditor assignments

👆 Click an option above to select your answer

7
knowledgeSelect all that apply

Which roles can add entities to an engagement scope in the Workspace? (Choose two.)

Asn_audit.manager
Bsn_audit_ws.supervisor
Csn_audit.user
Ditil

👆 Click an option above to select your answer

8
knowledge

What are the available actions when reviewing an evidence request?

AAccept, Reject, Archive
BAccept Evidence, Request Revision, Cancel, Delete
CApprove, Deny, Escalate
DSubmit, Review, Close

👆 Click an option above to select your answer

9
understanding

What is the purpose of indicators in continuous monitoring?

ATo track user login attempts
BTo collect data to monitor controls and risks, and collect audit evidence
CTo measure system performance
DTo track incident response times

👆 Click an option above to select your answer

10
understanding

What does Audit Management use compliance and risk data for?

ATo generate financial reports
BTo scope, plan, and prioritize audit engagements
CTo manage vendor contracts
DTo track employee performance

👆 Click an option above to select your answer

11
understandingSelect all that apply

Which items are reviewed by auditors to identify potential issues before they become audit failures? (Choose three.)

APolicies and procedures
BRisks
CEmployee salaries
DControl breakdowns
EOffice furniture inventory

👆 Click an option above to select your answer

12
knowledge

Where can you obtain the Analytics and Reporting Solution for GRC: Audit Management?

AIt's included with the base platform
BThe ServiceNow Store
CThird-party vendors only
DCustomer support request

👆 Click an option above to select your answer

13
understanding

What do Platform Analytics data visualizations use to show data over time?

AStatic reports only
BPerformance Analytics indicator data
CManual data entry
DExternal database queries

👆 Click an option above to select your answer

14
knowledgeSelect all that apply

Which states are part of the audit observation lifecycle? (Choose three.)

ADraft
BReview
CPending
DFinalize
EArchived

👆 Click an option above to select your answer

15
understanding

Who can create an observation from an engagement?

AOnly the audit manager
BAn audit user if the engagement is not in Follow Up or Closed states
COnly external auditors
DAny ServiceNow user

👆 Click an option above to select your answer

Exam Domains

GRC Overview

12%

GRC positioning and framework, key terminology, and technical details

Implementation Planning

5%

Use cases, implementation team and checklist, risk and compliance personas, groups and roles

Entity Framework

20%

Entity scoping overview, entity type approach, entity class approach, and entity architecture

Policy and Compliance

25%

Policy and compliance record lifecycles, architecture, configuration, and supporting processes

Risk and Advanced Risk

25%

Risk and advanced risk record lifecycles, architecture, and configuration

Common Elements and Extended Capabilities

8%

Integrations, content packs, platform capabilities, regulatory change management, and continuous monitoring

Audit and Advanced Audit

5%

Audit and advanced audit lifecycles, architecture, personas, groups, and roles

More Study Resources

Explore additional materials to boost your exam preparation