View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps
Question 101.
An organization wants to identify which business areas are affected by a particular risk. Which relationship is most useful?
- Risk linked to the relevant business entity
2. Policy linked to a browser version
3. Control linked to a user theme
4. Issue linked only to an email message
Correct Answer: 1. Risk linked to the relevant business entity
Explanation:
Linking a risk to the relevant business entity provides context about where the exposure exists. The entity might represent a business unit, application, process, vendor, or another scoped object. This supports reporting, ownership, prioritization, and assessment. Management can also compare risk exposure across different entities. Browser versions and user themes do not provide meaningful business-risk context, while issue tracking through email alone does not create structured organizational relationships.
Question 102.
A control is appropriately designed, but evidence shows it was performed only sporadically during the review period. What is the primary concern?
- Authority document completeness
2. Control operating effectiveness
3. Policy ownership
4. Entity classification
Correct Answer: 2. Control operating effectiveness
Explanation:
Operating effectiveness focuses on whether a control is consistently performed as intended over time. A well-designed control can still fail to reduce risk if it is executed only occasionally or inconsistently. Assessment evidence can help determine whether the control actually operated throughout the required period. A design effectiveness problem would exist if the control itself could not achieve its intended objective even when properly performed.
Question 103.
A risk assessment uses probability and business consequence to determine exposure. Which two concepts are being evaluated?
- Policy and evidence
2. Control and issue
3. Likelihood and impact
4. Owner and reviewer
Correct Answer: 3. Likelihood and impact
Explanation:
Likelihood measures the probability that a risk event will occur, while impact measures the potential consequence if it does. These two dimensions are commonly combined to determine a risk score or severity level. Organizations may use qualitative scales, quantitative values, or custom methodologies, but likelihood and impact remain common inputs. Policies and evidence support other parts of the risk and compliance process but are not equivalent to probability and consequence.
Question 104.
An organization completely stops an activity because its risk exceeds acceptable levels. Which risk treatment is being applied?
- Acceptance
2. Mitigation
3. Transfer
4. Avoidance**
Correct Answer: 4. Avoidance
Explanation:
Risk avoidance means eliminating the activity that creates the exposure. When an organization stops the activity completely, it removes the source of the risk rather than trying to reduce, transfer, or accept it. Mitigation uses controls to reduce likelihood or impact, transfer shifts some exposure to another party, and acceptance means consciously retaining the risk. Avoidance is appropriate when the exposure is considered unacceptable and cannot be managed sufficiently through other treatments.
Question 105.
A regulatory requirement is supported by several internal policies and controls. What is the main benefit of maintaining these relationships?
- Better compliance traceability and impact analysis
2. Automatic elimination of all related risks
3. Removal of all future assessment requirements
4. Automatic closure of issues
Correct Answer: 1. Better compliance traceability and impact analysis
Explanation:
Relationships among requirements, policies, and controls allow the organization to understand how an external obligation is interpreted internally and which safeguards support compliance. If the requirement changes, related policies and controls can be identified quickly. Likewise, a control failure can be traced back to affected requirements. These relationships improve governance and audit readiness but do not eliminate risks, assessments, or remediation activities.
Question 106.
An assessor needs proof that a quarterly access review was actually completed. Which item should be requested?
- Risk appetite statement
2. Control evidence
3. Authority document title
4. Policy publication date
Correct Answer: 2. Control evidence
Explanation:
Control evidence provides objective support that a control was performed. For an access review, evidence might include review reports, approvals, sign-offs, system logs, or related documentation. Evidence allows the assessor to evaluate whether the control operated as intended rather than relying only on verbal confirmation. Risk appetite and policy dates are important governance information but do not prove that the specific control activity was completed.
Question 107.
A control deficiency has been identified and needs assigned ownership, a target date, and corrective actions. Which record should be used?
- Knowledge Article
2. Catalog Item
3. Issue
4. Service Offering
Correct Answer: 3. Issue
Explanation:
An issue provides a structured way to manage a control or compliance deficiency through remediation. It can capture the problem, assign an owner, establish target dates, define corrective actions, and track progress to closure. This creates accountability and visibility. Knowledge articles and catalog items do not provide the same remediation lifecycle for identified governance, risk, or compliance weaknesses.
Question 108.
A company purchases insurance to limit the financial impact of a potential loss. Which risk response is this?
- Avoidance
2. Mitigation
3. Acceptance
4. Transfer**
Correct Answer: 4. Transfer
Explanation:
Risk transfer moves part of the financial or operational consequence of a risk to another party. Insurance is a common example because the insurer assumes specified losses according to the policy terms. The underlying event may still occur, so the risk is not eliminated. Mitigation reduces exposure through controls, avoidance eliminates the activity, and acceptance means the organization chooses to retain the remaining risk.
Question 109.
A risk has a high inherent score, but strong controls reduce the remaining exposure substantially. Which measure captures the lower remaining exposure?
- Residual risk
2. Inherent risk
3. Authority risk
4. Gross policy risk
Correct Answer: 1. Residual risk
Explanation:
Residual risk represents the exposure remaining after controls and treatment activities are considered. Inherent risk reflects the exposure before controls. Comparing the two provides insight into how much risk reduction the control environment is providing. If residual risk remains within the organization’s tolerance or appetite, additional treatment may not be necessary. If it remains too high, further mitigation or another response may be required.
Question 110.
A control owner must periodically confirm that a required activity is still being performed. Which process is most suitable?
- Change request
2. Attestation or assessment
3. Catalog request
4. Problem investigation
Correct Answer: 2. Attestation or assessment
Explanation:
An attestation or assessment can be used to obtain periodic confirmation that a control continues to operate. The control owner may answer structured questions, certify statements, or provide supporting evidence. This creates a repeatable assurance mechanism and helps identify controls that are no longer functioning as intended. Change requests and catalog requests support different operational processes and do not provide the same control verification function.
Question 111.
An organization adds additional monitoring and approval steps to reduce fraudulent transactions. Which risk treatment is being used?
- Transfer
2. Acceptance
3. Mitigation
4. Avoidance
Correct Answer: 3. Mitigation
Explanation:
Mitigation involves implementing safeguards intended to reduce the likelihood or impact of a risk. Additional monitoring and approval steps make fraudulent transactions harder to complete and can improve detection. The organization continues the underlying business activity but strengthens its controls. Avoidance would stop the activity, transfer would shift some exposure to another party, and acceptance would retain the risk without additional treatment.
Question 112.
A control supports requirements from four different regulatory frameworks. What is the main advantage of mapping all four requirements to the same control?
- The control will never need testing
2. All related risks are automatically accepted
3. Policies become unnecessary
4. Duplicate compliance work can be reduced**
Correct Answer: 4. Duplicate compliance work can be reduced
Explanation:
Mapping multiple requirements to one control helps organizations reuse the same safeguard, evidence, and testing activities across overlapping frameworks. This can reduce redundant controls and repeated compliance work. It also improves traceability and makes impact analysis easier if the control fails. The mapping does not remove the need for testing or policies and does not automatically change the treatment of related risks.
Question 113.
A policy is revised and management wants employees to formally confirm that they have read it. Which process best supports this?
- Policy acknowledgment or attestation
2. Risk acceptance
3. Control retirement
4. Authority document replacement
Correct Answer: 1. Policy acknowledgment or attestation
Explanation:
Policy acknowledgment or attestation provides evidence that designated employees have reviewed or accepted updated policy content. This can support governance, awareness, and audit requirements. It does not prove that related controls are operating effectively, so control testing may still be required. Risk acceptance and authority document management address different parts of the governance and compliance lifecycle.
Question 114.
A control is performed consistently, but even perfect execution cannot adequately address the intended risk. What is the issue?
- Operating effectiveness
2. Design effectiveness
3. Risk ownership
4. Evidence retention
Correct Answer: 2. Design effectiveness
Explanation:
Design effectiveness asks whether the control is capable of achieving its intended objective. If the control cannot sufficiently reduce the risk even when employees perform it exactly as designed, then the problem lies in the control design. The organization may need to redesign or replace the safeguard. Operating effectiveness refers to whether a properly designed control is consistently performed in practice.
Question 115.
A risk owner decides that the residual exposure is within approved tolerance and formally chooses to retain it. Which response applies?
- Avoidance
2. Transfer
3. Acceptance
4. Mitigation
Correct Answer: 3. Acceptance
Explanation:
Risk acceptance occurs when authorized stakeholders consciously decide to retain the remaining exposure because it is within tolerance or because further treatment is not justified. The decision should generally be documented and approved according to governance requirements. Acceptance does not make the risk disappear. Instead, it confirms that the organization understands and is willing to retain the residual exposure.
Question 116.
A compliance requirement changes. Which information is most useful for determining what internal records may need review?
- User-interface settings
2. Password reset history
3. Browser compatibility data
4. Relationships among the requirement, policies, controls, and risks**
Correct Answer: 4. Relationships among the requirement, policies, controls, and risks
Explanation:
Connected relationships make impact analysis much easier when an obligation changes. The organization can identify which policies interpret the requirement, which controls address it, and which risks or entities may be affected. Without these mappings, teams may need to manually search across many disconnected documents. Maintaining accurate relationships is therefore a key part of scalable compliance management and regulatory change analysis.
Question 117.
Why should identified remediation work have a clear owner and due date?
- To establish accountability and make overdue work visible
2. To eliminate the need for control assessments
3. To automatically reduce inherent risk
4. To replace policy governance
Correct Answer: 1. To establish accountability and make overdue work visible
Explanation:
Clear ownership identifies who is responsible for completing remediation, while a due date establishes the expected timeframe. Together with status tracking and corrective actions, these fields help management identify overdue work and escalate unresolved deficiencies. They do not automatically reduce risk or eliminate the need for assessments. Accountability is essential for ensuring that identified control and compliance weaknesses are actually corrected.
Question 118.
A manager wants to know why a control failure could affect several compliance frameworks at once. Which concept explains this?
- Risk acceptance
2. Shared control mapping
3. Entity retirement
4. Policy acknowledgment
Correct Answer: 2. Shared control mapping
Explanation:
A shared control may be mapped to requirements from several frameworks. If that control fails, every requirement that depends on it may be affected. Maintaining these mappings allows the organization to quickly identify the broader compliance impact of a deficiency. This is one reason shared controls can improve efficiency while also making relationship management important. Policy acknowledgment and risk acceptance do not explain cross-framework dependency.
Question 119.
A control test fails and management believes the related risk exposure has increased. What should happen next?
- Delete the control
2. Close the risk automatically
3. Record the deficiency and reassess the risk as appropriate
4. Remove the related regulation
Correct Answer: 3. Record the deficiency and reassess the risk as appropriate
Explanation:
A failed control may reduce the expected level of mitigation and therefore increase residual risk. The deficiency should be documented and remediation initiated. The related risk should also be reviewed to determine whether its current score still reflects actual exposure. Automatically deleting the control or closing the risk would hide the problem rather than manage it. The regulatory requirement remains relevant even when a control fails.
Question 120.
Which practice best supports consistent and scalable Risk and Compliance operations?
- Keep risks, controls, and policies in unrelated spreadsheets
2. Track remediation only through email
3. Avoid linking requirements to controls
4. Maintain accurate connected data for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation**
Correct Answer: 4. Maintain accurate connected data for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation
Explanation:
Scalable Risk and Compliance operations depend on structured, connected, and current data. Entities provide context, risks represent exposure, controls provide mitigation, policies and requirements define obligations, assessments and evidence support assurance, and issues manage remediation. Relationships among these records improve reporting, impact analysis, accountability, and audit readiness. Disconnected spreadsheets and email-only tracking become difficult to manage as the number of risks, controls, and regulatory obligations increases.