View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps
Question 1.
What is a primary objective of ServiceNow Risk and Compliance capabilities?
- To manage only software source code
2. To connect organizational risks, controls, policies, and compliance activities in a structured process
3. To replace all incident management processes
4. To manage only employee schedules
Correct Answer: 2. To connect organizational risks, controls, policies, and compliance activities in a structured process
Explanation:
ServiceNow Risk and Compliance capabilities help organizations manage governance, risk, and compliance information in a structured and connected way. Risks can be associated with business entities, controls can help mitigate those risks, policies can document organizational requirements, and compliance activities can evaluate whether obligations are being met. Connecting these areas improves visibility and supports consistent reporting and remediation. Source-code management, employee scheduling, and incident management are separate ServiceNow functions and do not represent the primary purpose of Risk and Compliance.
Question 2.
Which record typically represents a potential event or condition that could negatively affect organizational objectives?
- Risk
2. Knowledge Article
3. Change Request
4. Service Catalog Item
Correct Answer: 1. Risk
Explanation:
A risk represents uncertainty or a potential event that could affect an organization’s objectives. Risk records can be evaluated using attributes such as likelihood, impact, inherent risk, residual risk, and treatment decisions depending on the implementation. Risks are commonly related to business entities and controls so organizations can understand exposure and mitigation. Knowledge articles, change requests, and catalog items serve other platform purposes and do not represent organizational risk exposure.
Question 3.
What is the main purpose of a control in a risk and compliance program?
- To define a user-interface theme
2. To create employee schedules
3. To reduce or manage identified risks and support compliance requirements
4. To replace every policy document
Correct Answer: 3. To reduce or manage identified risks and support compliance requirements
Explanation:
Controls are activities, processes, or mechanisms intended to reduce risk or help an organization satisfy regulatory, policy, or contractual requirements. Examples can include access reviews, approval requirements, reconciliations, monitoring activities, or technical safeguards. Controls can be tested or assessed to determine whether they are designed and operating effectively. They do not replace policies, and they are unrelated to interface themes or employee scheduling.
Question 4.
Which concept represents the amount of risk that exists before controls or mitigation activities are considered?
- Residual risk
2. Accepted risk
3. Target risk
4. Inherent risk**
Correct Answer: 4. Inherent risk
Explanation:
Inherent risk is the level of exposure that exists before considering the effect of controls or other mitigation measures. It provides a baseline for understanding how significant a risk would be if no safeguards were in place. After controls and treatments are considered, the organization can evaluate residual risk. Comparing inherent and residual risk helps determine how much risk reduction is being achieved through the control environment.
Question 5.
What does residual risk represent?
- The risk remaining after controls or mitigation measures are considered
2. The risk before any controls exist
3. A deleted risk record
4. A risk that can never be assessed
Correct Answer: 1. The risk remaining after controls or mitigation measures are considered
Explanation:
Residual risk is the exposure that remains after relevant controls, safeguards, or treatment actions are taken into account. Organizations commonly compare residual risk with risk tolerance or appetite to determine whether additional action is required. A strong control environment may significantly reduce inherent risk, but rarely eliminates all risk. Residual risk therefore helps decision-makers understand the remaining exposure that the organization must accept, transfer, avoid, or further mitigate.
Question 6.
Which activity is most directly associated with determining whether a control is designed and operating effectively?
- Creating a catalog item
2. Control assessment or testing
3. Updating an application theme
4. Resetting a user password
Correct Answer: 2. Control assessment or testing
Explanation:
Control assessments or testing activities are used to evaluate whether controls are appropriately designed and whether they operate as intended. Evidence may be collected, responses may be reviewed, and issues can be identified when controls fail or are ineffective. This provides assurance that the control environment is actually reducing risk and supporting compliance. Catalog items, themes, and password resets are unrelated to systematic control evaluation.
Question 7.
An organization identifies that a control is not operating effectively. What should typically happen next?
- Delete the related risk
2. Ignore the result until the next year
3. Record the deficiency or issue and track remediation
4. Close all related policies
Correct Answer: 3. Record the deficiency or issue and track remediation
Explanation:
When a control is ineffective, the organization should document the finding and manage the resulting issue through remediation. This creates accountability, identifies ownership, and allows corrective actions to be tracked through completion. The failure may also affect risk scoring or compliance status depending on the configuration. Deleting the risk or ignoring the control failure would reduce visibility and prevent the organization from addressing the underlying weakness.
Question 8.
What is the purpose of a policy in a governance, risk, and compliance program?
- To schedule field technicians
2. To calculate asset depreciation
3. To manage browser settings
4. To document organizational requirements, expectations, or rules**
Correct Answer: 4. To document organizational requirements, expectations, or rules
Explanation:
Policies communicate organizational requirements and expectations. They can help translate regulatory, contractual, or internal governance requirements into clear rules employees and business units are expected to follow. Policies may be related to controls, authority documents, citations, or other compliance records depending on the implementation. They are governance artifacts rather than tools for technician scheduling, asset depreciation, or browser management.
Question 9.
Which record is commonly used to represent a law, regulation, standard, or other external source of compliance requirements?
- Authority document
2. Incident
3. Problem
4. Service offering
Correct Answer: 1. Authority document
Explanation:
An authority document can represent an external source of requirements such as a law, regulation, standard, contractual framework, or industry mandate. Organizations can use authority-related structures to connect external obligations with internal policies and controls. This helps demonstrate how external requirements are addressed within the organization. Incidents and problems belong to operational service management and do not represent compliance authorities.
Question 10.
What is a key benefit of mapping one control to multiple compliance requirements?
- It prevents the control from being assessed
2. It allows one control to support evidence of compliance across multiple obligations
3. It automatically eliminates all risks
4. It removes the need for policies
Correct Answer: 2. It allows one control to support evidence of compliance across multiple obligations
Explanation:
A single well-designed control may satisfy or support several regulatory, policy, or framework requirements. Mapping that control to multiple obligations can reduce duplicate work and provide a clearer view of how internal controls address different compliance needs. This is especially valuable when organizations are subject to several overlapping frameworks. The mapping does not eliminate risk or remove the need for policy governance, but it can make compliance management more efficient.
Question 11.
Which factor is commonly used with likelihood when calculating or evaluating risk exposure?
- User-interface color
2. Knowledge article count
3. Impact
4. Password length
Correct Answer: 3. Impact
Explanation:
Risk exposure is commonly evaluated using likelihood and impact. Likelihood reflects how probable it is that a risk event will occur, while impact represents the potential consequence if it does occur. Organizations may use qualitative or quantitative scales to combine these factors into a risk score. The exact calculation can vary by methodology. Interface colors, knowledge counts, and password length are not general risk-scoring factors.
Question 12.
A risk owner decides that the remaining exposure is within the organization’s tolerance and no additional mitigation is needed. Which response best describes this decision?
- Risk escalation
2. Risk transfer
3. Risk avoidance
4. Risk acceptance**
Correct Answer: 4. Risk acceptance
Explanation:
Risk acceptance means the organization chooses to retain the remaining exposure because it is considered tolerable or because further mitigation is not justified. This decision should generally be documented and approved according to the organization’s governance process. Other treatment options can include mitigation, transfer, or avoidance. Acceptance does not mean the risk disappears; it means decision-makers consciously accept the residual exposure.
Question 13.
Which risk response involves taking actions designed to reduce the likelihood or impact of a risk?
- Mitigation
2. Avoidance
3. Transfer
4. Acceptance
Correct Answer: 1. Mitigation
Explanation:
Risk mitigation involves implementing controls or other actions intended to reduce the likelihood, impact, or overall exposure associated with a risk. Examples may include stronger approvals, technical safeguards, monitoring, training, or process changes. Avoidance eliminates the activity creating the risk, transfer shifts some exposure to another party, and acceptance retains the risk. Mitigation is therefore the response most directly associated with reducing risk through corrective or preventive action.
Question 14.
Which role is generally responsible for overseeing and making decisions about a specific risk?
- Knowledge author
2. Risk owner
3. Catalog administrator
4. UI designer
Correct Answer: 2. Risk owner
Explanation:
A risk owner is typically accountable for understanding, monitoring, and making decisions regarding a specific risk. The owner may review assessments, approve treatment activities, evaluate residual exposure, and ensure appropriate actions are taken. Governance models vary by organization, but assigning ownership establishes accountability. Knowledge authors and UI designers have different responsibilities and are not generally accountable for organizational risk decisions.
Question 15.
An organization wants to evaluate whether a business unit is complying with required controls. Which activity is most appropriate?
- Change scheduling
2. Asset depreciation
3. Compliance or control assessment
4. Service catalog publishing
Correct Answer: 3. Compliance or control assessment
Explanation:
Compliance and control assessments allow organizations to evaluate whether required practices are being followed and whether controls are operating effectively. Responses, evidence, attestations, or test results may be collected depending on the assessment design. Findings can lead to issues and remediation when deficiencies are identified. Change scheduling and catalog publishing are unrelated to evaluating the effectiveness of a compliance control environment.
Question 16.
What is a major benefit of using issues to track control or compliance deficiencies?
- Issues automatically remove every risk
2. Issues replace all policies
3. Issues prevent future assessments
4. Issues provide structured ownership, remediation, and status tracking**
Correct Answer: 4. Issues provide structured ownership, remediation, and status tracking
Explanation:
Issues provide a structured mechanism for documenting deficiencies and tracking corrective action. They can identify the problem, assign responsibility, establish due dates, record remediation activities, and provide status visibility. This helps organizations ensure that control weaknesses and compliance gaps are not forgotten after discovery. Issues do not automatically eliminate risks or replace policies; rather, they support accountable remediation of identified problems.
Question 17.
Why is linking risks to business entities useful?
- It helps show where risk exposure exists within the organization
2. It changes the application theme automatically
3. It eliminates the need for controls
4. It prevents risk assessments
Correct Answer: 1. It helps show where risk exposure exists within the organization
Explanation:
Associating risks with business entities provides context about which organizational units, processes, applications, vendors, or other scoped objects are exposed to a particular risk. This supports reporting, ownership, assessments, and prioritization. Entity-based risk information can help management compare exposure across different parts of the organization. Linking a risk to an entity does not remove the need for controls or prevent future assessments.
Question 18.
A control owner is asked to confirm periodically that a control is still being performed. Which mechanism is most appropriate?
- Application theme review
2. Attestation or assessment
3. Browser upgrade
4. Catalog item approval
Correct Answer: 2. Attestation or assessment
Explanation:
An attestation or assessment can be used to obtain confirmation from a control owner or responsible party that a control is being performed and remains effective. Responses and supporting evidence can be reviewed as part of the assurance process. Periodic assessments help identify changes or control failures over time. Browser upgrades and catalog approvals are unrelated to verifying whether governance and compliance controls continue to operate as intended.
Question 19.
What is one advantage of maintaining relationships among risks, controls, policies, and compliance requirements in one platform?
- It removes all regulatory obligations
2. It prevents audit activity
3. It improves traceability and impact analysis across the compliance program
4. It eliminates the need for risk owners
Correct Answer: 3. It improves traceability and impact analysis across the compliance program
Explanation:
Connected records make it easier to understand how external requirements relate to internal policies, how controls address those requirements, and which risks may be affected when a control fails. This traceability improves reporting and impact analysis and can reduce duplicated compliance work. It also supports stronger evidence for audits and assessments. Maintaining these relationships does not eliminate regulatory obligations, audits, or the need for accountable risk ownership.
Question 20.
Which practice best supports a mature ServiceNow Risk and Compliance implementation?
- Keep risks, controls, policies, and issues in disconnected spreadsheets
2. Assess controls only after a major failure
3. Avoid assigning ownership to risks and remediation activities
4. Maintain connected, accurate records for entities, risks, controls, policies, assessments, issues, and remediation**
Correct Answer: 4. Maintain connected, accurate records for entities, risks, controls, policies, assessments, issues, and remediation
Explanation:
A mature Risk and Compliance implementation depends on structured, connected, and trustworthy data. Business entities provide context, risks capture exposure, controls represent mitigation, policies define expectations, assessments test effectiveness, and issues track deficiencies and remediation. Assigning clear ownership and maintaining relationships among these records improves reporting, traceability, and decision-making. Disconnected spreadsheets and incomplete ownership make it harder to understand enterprise risk and compliance status consistently.