View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps
Question 221.
An organization wants to identify the level of risk that exists before any safeguards are considered. Which measure should it review?
- Residual risk
2. Inherent risk
3. Accepted risk
4. Transferred risk
Correct Answer: 2. Inherent risk
Explanation:
Inherent risk represents the exposure that exists before controls, safeguards, or other treatment activities are taken into account. It provides a baseline that helps management understand the underlying severity of the risk. Residual risk is evaluated after the effects of controls are considered. Comparing inherent and residual risk can help demonstrate how much mitigation the control environment provides and whether the remaining exposure is within approved tolerance.
Question 222.
A control is performed exactly as documented, but it still does not adequately reduce the intended risk. Which area should be reviewed?
- Control design effectiveness
2. Operating effectiveness
3. Risk ownership
4. Policy acknowledgment
Correct Answer: 1. Control design effectiveness
Explanation:
Design effectiveness evaluates whether a control is capable of achieving its intended objective. If a control is performed correctly but still does not adequately reduce the associated risk, the design itself may be insufficient. The organization may need to redesign the control or introduce additional safeguards. Operating effectiveness would be the concern if the control were well designed but not performed consistently in practice.
Question 223.
A compliance team wants to know which internal safeguard satisfies a specific regulatory obligation. What should it review?
- User-role mappings
2. Knowledge article categories
3. Control-to-requirement mapping
4. Browser configuration
Correct Answer: 3. Control-to-requirement mapping
Explanation:
Control-to-requirement mappings provide traceability between external or internal obligations and the controls used to address them. This helps compliance teams understand how a regulatory requirement is implemented and provides useful evidence during audits and assessments. These relationships also support impact analysis when a control changes or fails. User-role and browser information do not show which safeguard supports a compliance obligation.
Question 224.
A company decides to stop an activity entirely because its risk cannot be reduced sufficiently. Which response is being used?
- Mitigation
2. Acceptance
3. Transfer
4. Avoidance**
Correct Answer: 4. Avoidance
Explanation:
Risk avoidance removes the activity that creates the exposure. By stopping the activity entirely, the organization eliminates the source of the risk instead of reducing, transferring, or accepting it. Mitigation introduces safeguards while continuing the activity, transfer shifts some consequences to another party, and acceptance means consciously retaining the remaining exposure. Avoidance is appropriate when the activity itself is considered too risky to continue.
Question 225.
A failed control assessment results in a corrective-action plan. Which record is best suited to track the work through completion?
- Issue
2. Knowledge Article
3. Service Offering
4. Catalog Item
Correct Answer: 1. Issue
Explanation:
An issue provides a structured method for tracking deficiencies and remediation. It can include ownership, due dates, corrective actions, status, and supporting information. This makes it possible to monitor the problem until it is resolved and to escalate overdue work. Knowledge articles and catalog items serve other purposes and do not provide the same governance-focused remediation lifecycle required for control and compliance findings.
Question 226.
An assessor needs proof that a monthly review control was completed. Which item should the assessor request?
- Risk tolerance
2. Control evidence
3. Entity hierarchy
4. Policy owner profile
Correct Answer: 2. Control evidence
Explanation:
Control evidence provides objective support that the required control activity was performed. Examples may include reports, approval records, logs, screenshots, reconciliations, or other documentation. Evidence strengthens the assessment conclusion and supports audit readiness. Risk tolerance and entity information are useful governance data, but they do not demonstrate that a particular monthly control was actually executed.
Question 227.
An organization adds additional transaction approvals to reduce fraud risk. Which risk treatment does this represent?
- Acceptance
2. Transfer
3. Mitigation
4. Avoidance
Correct Answer: 3. Mitigation
Explanation:
Mitigation involves adding controls or other measures that reduce the likelihood or impact of a risk. Additional transaction approvals can reduce the probability of unauthorized or fraudulent activity while allowing the underlying business process to continue. Avoidance would eliminate the activity, transfer would shift part of the consequences to another party, and acceptance would retain the risk without additional treatment.
Question 228.
A company purchases insurance for losses associated with a specific risk. Which response is being used?
- Acceptance
2. Avoidance
3. Mitigation
4. Transfer**
Correct Answer: 4. Transfer
Explanation:
Insurance is a common form of risk transfer because part of the financial consequence of a risk event is shifted to another party. The underlying event may still occur, but the organization reduces the portion of loss it must bear directly. Mitigation reduces exposure through controls, avoidance eliminates the risky activity, and acceptance means knowingly retaining the exposure.
Question 229.
Why is it useful to link risks to specific business entities?
- It helps show where exposure exists across the organization
2. It automatically closes all issues
3. It eliminates the need for controls
4. It prevents future assessments
Correct Answer: 1. It helps show where exposure exists across the organization
Explanation:
Business entities provide organizational context for risks. They can represent business units, processes, applications, vendors, or other scoped objects. Linking risks to entities helps management understand which areas are exposed and supports reporting, prioritization, ownership, and assessments. These relationships improve risk visibility but do not replace controls or automatically resolve issues.
Question 230.
A control owner must confirm every year that a control remains active and is still being performed. Which mechanism is best suited to this?
- Incident
2. Attestation or assessment
3. Change Request
4. Catalog Request
Correct Answer: 2. Attestation or assessment
Explanation:
An attestation or assessment can provide periodic confirmation that a control remains in place and continues to operate. The owner may answer structured questions, certify statements, or submit supporting evidence. This creates a repeatable assurance process and helps identify controls that have degraded or changed over time. Incident and catalog processes do not provide the same governance-focused verification.
Question 231.
Which two dimensions are most commonly used together to determine risk severity?
- Evidence and ownership
2. Policy age and control count
3. Likelihood and impact
4. Issue age and remediation status
Correct Answer: 3. Likelihood and impact
Explanation:
Likelihood represents how probable it is that a risk event will occur, while impact represents the potential consequence if it does. These two dimensions are commonly combined in qualitative or quantitative risk-scoring methodologies. Organizations may define their own scales and formulas, but likelihood and impact remain common foundational measures. Evidence and issue age support other governance activities but are not the primary probability-and-consequence dimensions of risk.
Question 232.
A risk owner decides that the remaining exposure is acceptable and no further treatment is required. Which response applies?
- Avoidance
2. Mitigation
3. Transfer
4. Acceptance**
Correct Answer: 4. Acceptance
Explanation:
Risk acceptance means authorized stakeholders knowingly retain the residual exposure because it is within approved tolerance or because further treatment is not justified. The decision should generally be documented and governed according to organizational policy. Acceptance does not eliminate the risk. Instead, it confirms that management understands the remaining exposure and chooses to retain it under current conditions.
Question 233.
A shared control supports requirements from several standards. What is a key benefit of maintaining this mapping?
- It can reduce duplicate testing and evidence collection
2. It permanently guarantees compliance
3. It eliminates all related risks
4. It removes the need for future assessments
Correct Answer: 1. It can reduce duplicate testing and evidence collection
Explanation:
When one control supports multiple requirements, the same assessment results and evidence can often be reused across several frameworks. This reduces duplicate compliance effort and improves traceability. The mapping also helps identify all obligations affected when a control fails. Shared controls still require ongoing maintenance and assessment, so the relationship does not guarantee permanent compliance or eliminate risk.
Question 234.
Employees must formally confirm that they reviewed a revised policy. Which process should be used?
- Risk assessment
2. Policy acknowledgment or attestation
3. Control retirement
4. Authority document deletion
Correct Answer: 2. Policy acknowledgment or attestation
Explanation:
Policy acknowledgment or attestation provides evidence that designated employees reviewed or formally accepted updated policy content. This supports governance, awareness, and audit readiness. It can also help management identify users who have not completed the required acknowledgment. The process does not replace control testing or risk assessments, but it is well suited to demonstrating policy communication and employee review.
Question 235.
A risk has a high inherent score but a low residual score. What does this most likely indicate?
- No controls are associated with the risk
2. The risk has been deleted
3. Existing controls are significantly reducing exposure
4. The organization has stopped assessing the risk
Correct Answer: 3. Existing controls are significantly reducing exposure
Explanation:
Inherent risk represents exposure before controls are considered, while residual risk reflects what remains after controls are taken into account. A large reduction between the two values indicates that the control environment is providing meaningful mitigation. Management should still compare the residual value with risk tolerance to determine whether the remaining exposure is acceptable or whether further treatment is required.
Question 236.
A regulatory requirement changes. Which capability is most useful for identifying related policies, controls, and risks?
- Browser compatibility reporting
2. Password history
3. User-interface personalization
4. Relationship mapping and impact analysis**
Correct Answer: 4. Relationship mapping and impact analysis
Explanation:
Connected relationships among requirements, policies, controls, risks, and entities allow compliance teams to identify internal dependencies quickly when an external obligation changes. This improves regulatory change management and reduces the need to search manually through disconnected documents. Relationship mapping also helps ensure that affected controls and policies are not overlooked during impact analysis.
Question 237.
A remediation issue is overdue. Which information is most important for determining accountability?
- Assigned owner and target date
2. Policy font
3. Number of evidence attachments
4. Browser type
Correct Answer: 1. Assigned owner and target date
Explanation:
The assigned owner identifies who is responsible for completing remediation, while the target date establishes when the work should be finished. Status and corrective-action details provide further context and support escalation. Without clear ownership and deadlines, deficiencies may remain unresolved. Policy formatting and browser information do not establish responsibility for overdue remediation.
Question 238.
A shared control fails and the compliance team wants to know which frameworks may be affected. What should it review?
- User preference records
2. Control-to-requirement mappings
3. Knowledge article categories
4. Application themes
Correct Answer: 2. Control-to-requirement mappings
Explanation:
Control-to-requirement mappings show which obligations depend on a particular safeguard. When a shared control fails, these relationships allow the compliance team to identify affected regulations, standards, or internal requirements quickly. This supports remediation prioritization, reporting, and impact analysis. User preferences and application themes do not provide compliance dependency information.
Question 239.
A critical control fails and management believes residual risk may have increased. What should happen next?
- Delete the related risk
2. Ignore the result until the next annual review
3. Record the deficiency, track remediation, and reassess the related risk as appropriate
4. Remove the underlying requirement
Correct Answer: 3. Record the deficiency, track remediation, and reassess the related risk as appropriate
Explanation:
A failed control may reduce the expected level of mitigation and cause residual exposure to increase. The organization should document the deficiency, assign remediation, and review the related risk to determine whether its current rating remains accurate. This keeps risk reporting aligned with the actual control environment. Deleting records or ignoring the result would hide the exposure rather than manage it responsibly.
Question 240.
Which practice best supports a scalable Risk and Compliance program across many business units and regulations?
- Track findings primarily through email
2. Keep risks and controls disconnected
3. Avoid mapping requirements to internal safeguards
4. Maintain accurate connected records for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation**
Correct Answer: 4. Maintain accurate connected records for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation
Explanation:
Scalable Risk and Compliance operations depend on structured and connected information. Business entities provide context, risks represent exposure, controls provide mitigation, policies and requirements define obligations, assessments and evidence support assurance, and issues manage remediation. Accurate relationships among these records improve reporting, impact analysis, accountability, and audit readiness. Disconnected spreadsheets and email-based tracking become increasingly difficult to govern as regulatory scope and organizational complexity grow.