View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps
Question 41.
An organization wants to know the level of exposure before any controls are considered. Which value should it review?
- Inherent risk
2. Residual risk
3. Accepted risk
4. Transferred risk
Correct Answer: 1. Inherent risk
Explanation:
Inherent risk represents the level of exposure that exists before controls, safeguards, or other mitigation measures are taken into account. It establishes a baseline that helps the organization understand the underlying severity of the risk. Residual risk is evaluated after controls are considered. Comparing inherent and residual risk helps show how much risk reduction the control environment is expected to provide and whether the remaining exposure is within acceptable levels.
Question 42.
A control is designed correctly but is not being performed consistently. Which type of concern does this most directly represent?
- Policy ownership issue
2. Control operating effectiveness issue
3. Authority document issue
4. Entity classification issue
Correct Answer: 2. Control operating effectiveness issue
Explanation:
A control may be well designed but still fail if it is not performed consistently or as intended. This represents an operating effectiveness concern rather than a design problem. Control testing can identify whether the activity is actually being executed over time. When failures are found, the organization may create an issue and track remediation. Design effectiveness and operating effectiveness should be evaluated separately because a control can succeed in one area while failing in the other.
Question 43.
Which record most directly identifies who is accountable for managing a specific risk?
- Control owner
2. Policy owner
3. Risk owner
4. Knowledge owner
Correct Answer: 3. Risk owner
Explanation:
The risk owner is typically accountable for understanding and managing a particular risk. Responsibilities can include reviewing assessment results, approving treatment decisions, monitoring residual exposure, and ensuring that appropriate actions are taken. Control owners are accountable for controls, while policy owners manage policy content and governance. Clear ownership helps establish accountability and makes it easier to escalate risks that exceed tolerance or require additional treatment.
Question 44.
A company decides to stop offering a particular service because the associated regulatory risk is unacceptable. Which risk response is this?
- Acceptance
2. Mitigation
3. Transfer
4. Avoidance**
Correct Answer: 4. Avoidance
Explanation:
Risk avoidance means eliminating the activity that creates the exposure. If the organization stops offering the service entirely, it removes the source of the risk rather than trying to reduce or transfer it. Mitigation would involve implementing controls to lower the risk, transfer would shift some consequences to another party, and acceptance would retain the exposure. Avoidance is therefore the response most consistent with discontinuing the risky activity.
Question 45.
An organization wants to document a requirement from an external standard and relate it to internal controls. Which structure is most appropriate?
- Authority document and related citation or requirement
2. Incident and problem record
3. Catalog item and request
4. Change request and implementation task
Correct Answer: 1. Authority document and related citation or requirement
Explanation:
An authority document can represent the broader external standard, regulation, or law, while citations or requirement records represent the specific obligations contained within it. These requirements can then be mapped to internal controls and policies. This provides traceability between external expectations and internal compliance activities. Incident, problem, catalog, and change records serve operational service-management purposes and do not provide the same compliance structure.
Question 46.
Why is mapping a control to several regulatory requirements useful?
- It eliminates the need for testing
2. It allows one control to demonstrate support for multiple obligations
3. It automatically closes all related risks
4. It removes the need for policies
Correct Answer: 2. It allows one control to demonstrate support for multiple obligations
Explanation:
A single control may support multiple overlapping regulations, standards, or internal requirements. Mapping the relationships helps the organization avoid duplicating controls and can reduce repeated evidence collection or testing. It also improves traceability by showing which obligations depend on the same safeguard. If the control later fails, the organization can identify the affected requirements more quickly. The mapping does not eliminate testing, policies, or the underlying risks.
Question 47.
A control assessment identifies a serious deficiency. Which action is most appropriate?
- Delete the assessment
2. Mark the control effective anyway
3. Create and manage an issue for remediation
4. Remove the related authority document
Correct Answer: 3. Create and manage an issue for remediation
Explanation:
A material control deficiency should be documented as an issue and managed through a structured remediation process. This allows the organization to assign ownership, set target dates, track corrective actions, and monitor progress. The related risk may also need to be reassessed if the control failure increases residual exposure. Deleting the assessment or marking the control effective would hide the problem rather than address it.
Question 48.
A business unit formally agrees to retain a risk because the remaining exposure is within approved tolerance. Which response is being used?
- Avoidance
2. Transfer
3. Mitigation
4. Acceptance**
Correct Answer: 4. Acceptance
Explanation:
Risk acceptance occurs when authorized decision-makers decide that the remaining exposure is tolerable and no additional treatment is required. This decision should usually be documented and approved according to organizational governance. Acceptance does not mean the risk has disappeared; it means the organization consciously retains it. Other options include mitigation, transfer, and avoidance, which involve reducing, shifting, or eliminating the exposure.
Question 49.
Which factor is commonly combined with likelihood to determine a risk score?
- Impact
2. Policy age
3. Control owner tenure
4. Number of knowledge articles
Correct Answer: 1. Impact
Explanation:
Likelihood and impact are common dimensions used in risk assessment. Likelihood represents the probability of the risk event occurring, while impact describes the potential consequences if it does occur. Organizations may combine these values using qualitative or quantitative methods to determine overall risk exposure. The specific scoring model can vary, but impact is one of the most common factors paired with likelihood. Policy age and knowledge counts are not standard risk-scoring dimensions.
Question 50.
A control owner is asked to confirm quarterly that a required review is still being performed. Which mechanism is most appropriate?
- Catalog approval
2. Attestation or assessment
3. Update set review
4. Application theme check
Correct Answer: 2. Attestation or assessment
Explanation:
An attestation or assessment can be used to obtain periodic confirmation that a control is still being performed as expected. The owner may be asked to respond to questions, provide evidence, or confirm specific statements about control operation. This creates a repeatable assurance process and can help identify control deterioration over time. Catalog approvals and application configuration checks do not provide the same compliance assurance function.
Question 51.
A company buys cyber insurance to reduce the financial impact of a security event. Which risk response does this represent?
- Avoidance
2. Acceptance
3. Transfer
4. Mitigation
Correct Answer: 3. Transfer
Explanation:
Insurance is a common example of risk transfer because some of the financial consequences of a risk event are shifted to another party. The underlying event may still occur, but the organization reduces its direct exposure to certain losses. Transfer differs from mitigation, which reduces likelihood or impact through controls, and from avoidance, which eliminates the risky activity. Acceptance means retaining the exposure without additional transfer or mitigation.
Question 52.
Why is collecting evidence during a control assessment important?
- It automatically eliminates the related risk
2. It replaces the need for policies
3. It changes the risk owner
4. It provides support that the control was actually performed**
Correct Answer: 4. It provides support that the control was actually performed
Explanation:
Evidence provides objective support for evaluating whether a control was executed and whether it operated as intended. Examples may include reports, approvals, logs, screenshots, reconciliations, or other relevant records. Without evidence, an assessment may rely only on unsupported statements. Evidence strengthens assurance, supports audit readiness, and helps reviewers make more reliable conclusions about control effectiveness. It does not by itself eliminate risk or replace governance processes.
Question 53.
What is a major benefit of relating risks to business entities?
- It helps identify which parts of the organization are exposed
2. It eliminates the need for control owners
3. It automatically closes remediation issues
4. It prevents future assessments
Correct Answer: 1. It helps identify which parts of the organization are exposed
Explanation:
Relating risks to business entities provides organizational context. It helps management understand whether a particular business unit, application, process, vendor, or other scoped object is affected by the risk. This supports entity-based reporting, prioritization, ownership, and assessment. It can also help compare exposure across different parts of the enterprise. The relationship does not eliminate accountability or remove the need for future assessments.
Question 54.
A control is tested and found to be consistently effective. What does this generally indicate?
- The related risk can always be deleted
2. The control is providing the expected mitigation or compliance support
3. No future testing is required
4. All organizational risks are eliminated
Correct Answer: 2. The control is providing the expected mitigation or compliance support
Explanation:
An effective control is functioning as intended and providing the expected support for risk reduction or compliance. This can lower residual exposure, but it does not mean that the related risk disappears entirely. Controls can also become ineffective over time because processes, systems, or threats change. Periodic reassessment remains important. Effective control results provide assurance, but they do not eliminate all organizational risk or future testing requirements.
Question 55.
Which record is best suited for tracking ownership, due dates, status, and corrective actions for a compliance deficiency?
- Knowledge Article
2. Change Request
3. Issue
4. Service Offering
Correct Answer: 3. Issue
Explanation:
An issue provides a structured way to manage identified deficiencies. It can capture the problem, assign an owner, establish due dates, track remediation activities, and provide status visibility. This helps ensure that control failures, compliance gaps, and assessment findings are not forgotten after discovery. Knowledge articles and service offerings serve other purposes and do not provide the same structured remediation lifecycle.
Question 56.
What is the main purpose of linking policies to related requirements and controls?
- To remove the need for compliance assessments
2. To change user permissions
3. To eliminate regulatory obligations
4. To provide traceability from requirements to internal expectations and safeguards**
Correct Answer: 4. To provide traceability from requirements to internal expectations and safeguards
Explanation:
Linking policies, requirements, and controls creates a clear compliance chain. External or internal requirements can be connected to policies that explain organizational expectations, while controls demonstrate how those expectations are implemented. This traceability improves impact analysis, audit readiness, and governance reporting. If a regulation changes or a control fails, related policies and obligations can be identified more quickly. The relationships do not eliminate assessments or regulatory responsibilities.
Question 57.
A risk has high inherent exposure but effective controls reduce the remaining exposure to a low level. Which value reflects the low remaining exposure?
- Residual risk
2. Inherent risk
3. Gross risk
4. Authority risk
Correct Answer: 1. Residual risk
Explanation:
Residual risk represents the exposure remaining after controls and other mitigation activities are considered. In this scenario, the inherent risk is high because the underlying exposure is significant, but effective controls reduce the remaining risk to a lower level. Comparing inherent and residual risk helps demonstrate the expected effect of the control environment. Organizations can then compare residual risk against tolerance or appetite to determine whether further action is necessary.
Question 58.
An organization adds stronger approval checks to reduce the likelihood of fraudulent payments. Which risk response is being used?
- Avoidance
2. Mitigation
3. Transfer
4. Acceptance
Correct Answer: 2. Mitigation
Explanation:
Adding stronger approval controls is a form of risk mitigation because it is intended to reduce the likelihood or impact of fraudulent payments. The risky activity continues, but additional safeguards are introduced to lower exposure. Avoidance would eliminate the activity, transfer would shift some consequences to another party, and acceptance would retain the risk without additional treatment. Mitigation is one of the most common responses to manageable organizational risks.
Question 59.
A manager wants to understand every requirement that could be affected if a shared control fails. Which capability is most valuable?
- User-interface personalization
2. Password history
3. Relationship mapping and impact analysis
4. Knowledge article versioning
Correct Answer: 3. Relationship mapping and impact analysis
Explanation:
When a shared control supports multiple requirements, maintaining accurate relationships allows the organization to identify every obligation that depends on that control. This makes impact analysis much faster when the control fails or changes. It also helps with remediation prioritization and compliance reporting. User-interface settings and password history do not provide the cross-record traceability needed to understand the broader compliance impact of a control deficiency.
Question 60.
Which practice best supports a scalable Risk and Compliance program?
- Track all findings only through email
2. Keep controls separate from related risks and requirements
3. Avoid documenting ownership
4. Maintain accurate, connected records for entities, risks, controls, requirements, policies, assessments, evidence, issues, and remediation**
Correct Answer: 4. Maintain accurate, connected records for entities, risks, controls, requirements, policies, assessments, evidence, issues, and remediation
Explanation:
A scalable Risk and Compliance program depends on structured and connected data. Entities provide business context, risks represent exposure, controls provide mitigation, requirements and policies define obligations, assessments and evidence evaluate effectiveness, and issues track remediation. Maintaining these relationships supports reporting, accountability, impact analysis, and audit readiness. Disconnected records and informal email tracking make it harder to understand the organization’s overall compliance position and to manage deficiencies consistently as the program grows.