View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps
Question 361.
An organization wants an early-warning metric that signals when a business condition may be increasing risk exposure. Which concept best fits this need?
- Policy acknowledgment
2. Key risk indicator
3. Control objective
4. Issue closure evidence
Correct Answer: 2. Key risk indicator
Explanation:
A key risk indicator, or KRI, is a measurable value used to monitor conditions that may signal increasing or decreasing risk exposure. KRIs are often associated with thresholds and trends so management can identify changes before a formal risk assessment cycle occurs. A policy acknowledgment confirms policy review, while control objectives describe intended control outcomes. Issue closure evidence supports remediation verification rather than providing ongoing risk-warning information.
Question 362.
A risk indicator remains within its threshold but moves steadily in an unfavorable direction for five reporting periods. What should management do?
- Review the trend and investigate whether exposure is increasing
2. Ignore the indicator until the threshold is breached
3. Automatically accept the related risk
4. Delete the associated control
Correct Answer: 1. Review the trend and investigate whether exposure is increasing
Explanation:
Trend information can provide valuable warning before a formal threshold is crossed. A steadily worsening indicator may signal changes in the business environment, control performance, or underlying exposure. Management should review the cause and determine whether additional monitoring, treatment, or reassessment is appropriate. Waiting until the threshold is exceeded can delay action. The trend does not automatically prove the risk has increased, but it provides a reason for further investigation.
Question 363.
Which statement best describes the relationship between risk appetite and risk tolerance?
- They are always identical terms
2. Risk tolerance applies only to control testing
3. Risk appetite is broad, while risk tolerance usually defines more specific acceptable limits
4. Risk appetite is used only after an issue is closed
Correct Answer: 3. Risk appetite is broad, while risk tolerance usually defines more specific acceptable limits
Explanation:
Risk appetite provides broad guidance about the amount and type of risk an organization is willing to pursue or retain. Risk tolerance typically translates that broad guidance into more specific limits, ranges, or acceptable variations for particular risks or activities. Together, they support decision-making and escalation. Neither concept is limited to control testing or issue closure, and they should not automatically be treated as identical.
Question 364.
A preferred preventive control cannot be implemented because of a legacy-platform limitation. What is the best governance response?
- Ignore the requirement
2. Mark the unavailable control as effective
3. Automatically accept the risk
4. Implement and document an appropriate compensating control**
Correct Answer: 4. Implement and document an appropriate compensating control
Explanation:
A compensating control provides an alternative safeguard when the preferred control cannot be implemented. The organization should document why the primary control is unavailable, what alternative control is being used, how it addresses the intended objective, and who approved the approach. The compensating control should also be assessed and monitored. Simply marking an unavailable control effective would weaken governance and could create an inaccurate view of compliance.
Question 365.
What is the primary purpose of a preventive control?
- To reduce the likelihood of an undesirable event before it occurs
2. To record a risk after it is accepted
3. To identify an event only after it occurs
4. To archive obsolete policies
Correct Answer: 1. To reduce the likelihood of an undesirable event before it occurs
Explanation:
Preventive controls are intended to stop or reduce the likelihood of undesirable events before they happen. Examples can include approval requirements, access restrictions, validation checks, and segregation of duties. Detective controls identify problems during or after occurrence, while corrective activities address consequences afterward. Preventive controls therefore play an important role in reducing exposure before an adverse event materializes.
Question 366.
A transaction-monitoring process identifies suspicious activity after transactions have already been processed. Which type of control is this?
- Preventive
2. Detective
3. Compensating
4. Risk acceptance
Correct Answer: 2. Detective
Explanation:
Detective controls identify errors, exceptions, or undesirable activity during or after occurrence. Transaction monitoring, reconciliations, exception reports, and log reviews are common examples. Preventive controls attempt to stop an event beforehand. A compensating control is an alternative safeguard used when a preferred control is unavailable, while risk acceptance is a treatment decision rather than a control classification.
Question 367.
An organization wants to group risks consistently into categories such as strategic, operational, compliance, and technology. What should it establish?
- Policy exception schedule
2. Control-testing calendar
3. Risk taxonomy
4. Evidence-retention issue
Correct Answer: 3. Risk taxonomy
Explanation:
A risk taxonomy provides a structured set of categories and subcategories used to classify risks consistently. This improves reporting, aggregation, comparison, and enterprise visibility. A common taxonomy also helps different business units use the same terminology when discussing exposure. It does not change the underlying risk itself, but it makes risk data easier to organize, analyze, and communicate across the organization.
Question 368.
A policy has been replaced by a newly approved version. What should happen to the superseded policy?
- Keep both versions active indefinitely
2. Delete all historical evidence
3. Convert the old version into a control
4. Retire or archive it according to the policy lifecycle**
Correct Answer: 4. Retire or archive it according to the policy lifecycle
Explanation:
Superseded policies should generally be retired or archived so users are not confused about which version is current. Historical versions may still need to be preserved for legal, audit, or governance purposes. A mature policy lifecycle includes drafting, review, approval, publication, periodic review, revision, and retirement. Deleting all historical records can remove important evidence about prior obligations and approvals.
Question 369.
A policy exception is approved temporarily. Which information is most important for preventing the exception from becoming an uncontrolled permanent deviation?
- Expiration date and review requirement
2. Browser version
3. Knowledge article rating
4. Interface theme
Correct Answer: 1. Expiration date and review requirement
Explanation:
Temporary exceptions should have clear expiration and review requirements so they do not remain active indefinitely without governance oversight. Good exception management also includes rationale, approver, scope, associated risk, and compensating safeguards. The exception should be reassessed before expiration and either closed, renewed, or replaced with a permanent solution. Interface settings and knowledge ratings do not support exception governance.
Question 370.
A control was remediated after failing an assessment. What is the best next step before considering the issue resolved?
- Delete the original assessment
2. Re-test or reassess the control
3. Automatically lower the risk score
4. Remove the control owner
Correct Answer: 2. Re-test or reassess the control
Explanation:
Re-testing verifies whether remediation actually corrected the original weakness. Without verification, the organization cannot confidently conclude that the control now operates effectively. The original assessment should usually remain part of the historical record, and issue closure should be supported by appropriate evidence. Successful remediation may influence the related risk assessment, but the risk score should not simply be lowered automatically without evaluating the actual effect.
Question 371.
Why should control evidence be recent enough to cover the relevant assessment period?
- To make policies easier to publish
2. To reduce the number of business entities
3. To demonstrate current rather than merely historical control performance
4. To eliminate the need for testing
Correct Answer: 3. To demonstrate current rather than merely historical control performance
Explanation:
Evidence should support conclusions about the period being assessed. Old documentation may show that a control operated in the past, but it does not necessarily prove current performance. Evidence freshness is especially important for recurring controls that operate monthly, quarterly, or continuously. Current evidence helps assessors determine whether the control remains effective and reduces the risk of relying on outdated information.
Question 372.
A major system implementation significantly changes a business process and its control environment. What should happen to related risks?
- They should remain unchanged until the next routine cycle
2. They should automatically be accepted
3. They should be deleted and recreated
4. They should be reassessed because exposure and controls may have changed**
Correct Answer: 4. They should be reassessed because exposure and controls may have changed
Explanation:
Major changes to systems, processes, organizational structures, or responsibilities can affect likelihood, impact, control effectiveness, and ownership. Reassessment helps ensure that risk information still reflects actual conditions. Related controls and treatment plans may also require review. Waiting for a routine cycle could leave management relying on outdated risk information during a period of significant change.
Question 373.
What is the main purpose of a risk register?
- To maintain a consolidated inventory of identified risks and key risk information
2. To publish employee policies
3. To store only closed issues
4. To replace control evidence
Correct Answer: 1. To maintain a consolidated inventory of identified risks and key risk information
Explanation:
A risk register provides a centralized inventory of known risks and commonly includes information such as ownership, category, status, assessment results, treatment decisions, and residual exposure. It supports monitoring, prioritization, reporting, and governance. A risk register does not replace policies, issues, or evidence. Instead, it provides a structured view of the organization’s identified risk landscape.
Question 374.
Why is a common risk-scoring methodology useful across multiple business entities?
- It guarantees every entity receives the same scores
2. It improves consistency and comparability of assessment results
3. It eliminates the need for risk owners
4. It prevents all residual risk
Correct Answer: 2. It improves consistency and comparability of assessment results
Explanation:
A common methodology establishes consistent definitions, scales, and criteria so similar risks are evaluated in a comparable way across entities. This improves enterprise reporting, aggregation, and prioritization. Different entities may still receive different scores because their exposures differ. Consistency in methodology does not eliminate ownership or residual risk, but it makes results more meaningful when compared across the organization.
Question 375.
A compliance assessment cannot obtain required evidence for a control. What should the assessor do?
- Assume the control is effective
2. Ignore the missing evidence
3. Document the evidence gap and evaluate its effect on the assessment conclusion
4. Delete the control
Correct Answer: 3. Document the evidence gap and evaluate its effect on the assessment conclusion
Explanation:
Missing evidence can prevent an assessor from reaching a reliable conclusion about control effectiveness. The gap should be documented and evaluated according to the assessment methodology. Depending on significance, the organization may request additional evidence, record a deficiency, or adjust the assessment result. Assuming effectiveness without support would weaken assurance and could create inaccurate compliance reporting.
Question 376.
An organization uses automated feeds to monitor risk indicators daily. What is the greatest advantage of this approach?
- It eliminates the need for risk governance
2. It guarantees that risks never exceed tolerance
3. It removes all manual assessments
4. It can identify changing risk conditions more quickly**
Correct Answer: 4. It can identify changing risk conditions more quickly
Explanation:
Automated and continuous monitoring can provide more timely information about risk conditions than periodic manual reviews alone. Threshold breaches, unusual patterns, or deteriorating trends may be identified sooner, giving management more time to respond. Human oversight remains important for interpreting results and making treatment decisions. Continuous monitoring improves timeliness but does not guarantee that risks remain within acceptable limits.
Question 377.
Why can separating control ownership from control testing strengthen assurance?
- It can provide a more independent evaluation of control effectiveness
2. It eliminates the need for control owners
3. It guarantees a passing result
4. It removes all evidence requirements
Correct Answer: 1. It can provide a more independent evaluation of control effectiveness
Explanation:
Separating ownership from testing helps reduce conflicts of interest and provides greater objectivity. The control owner remains responsible for operating and maintaining the control, while an independent tester evaluates design, execution, and evidence. This separation can strengthen confidence in assessment results. It does not guarantee that the control will pass, and testers still need appropriate evidence to support their conclusions.
Question 378.
A risk treatment plan contains multiple remediation actions. Why should each action have an owner and due date?
- To automatically eliminate the risk
2. To make treatment execution accountable and measurable
3. To replace the risk assessment
4. To prevent future monitoring
Correct Answer: 2. To make treatment execution accountable and measurable
Explanation:
Owners and due dates turn a treatment plan into actionable work. Ownership establishes responsibility, while due dates create measurable expectations for completion and enable escalation when activities become overdue. Treatment actions may involve implementing controls, changing processes, or other risk-reduction activities. The risk should still be monitored and reassessed as treatment progresses, because assigning actions alone does not eliminate exposure.
Question 379.
An organization wants to assess the same compliance requirement across multiple subsidiaries while preserving local context. What is most useful?
- A separate unrelated framework for every subsidiary
2. One global issue with no entity information
3. Entity-based scoping of assessments and controls
4. Removing all common controls
Correct Answer: 3. Entity-based scoping of assessments and controls
Explanation:
Entity-based scoping allows an organization to apply common requirements while evaluating control performance in the specific context of each subsidiary, application, process, or other business entity. This helps identify localized weaknesses and compare results across entities. Common controls can still be reused where appropriate. Removing entity context would make it harder to understand where compliance strengths and deficiencies actually exist.
Question 380.
What foundation should be established before extensive automation of Risk and Compliance workflows?
- Maximum form customization
2. Automatic closure of overdue issues
3. Separate spreadsheets for each department
4. Clear governance, ownership, methodologies, data standards, and escalation rules**
Correct Answer: 4. Clear governance, ownership, methodologies, data standards, and escalation rules
Explanation:
Automation is most effective when the underlying governance model is already defined. Organizations should establish clear ownership, risk and control methodologies, data standards, approval requirements, assessment rules, and escalation paths before automating workflows. Otherwise, automation may simply accelerate inconsistent or poorly designed processes. A strong governance foundation helps ensure that automated Risk and Compliance activities remain reliable, scalable, and auditable.