View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps
Question 181.
An organization wants to know which controls currently reduce a particular risk. Which information is most important?
- Control-to-risk relationships
2. Browser support data
3. Knowledge article ratings
4. UI preferences
Correct Answer: 1. Control-to-risk relationships
Explanation:
Control-to-risk relationships show which safeguards are expected to reduce a specific risk. This provides important context for understanding the difference between inherent and residual exposure and supports impact analysis if a control later fails. Risk owners can use these relationships to identify which controls are critical to their risk treatment strategy. Browser settings, knowledge ratings, and user-interface preferences do not provide meaningful information about how organizational risks are mitigated.
Question 182.
A control is capable of reducing a risk, but evidence shows it was performed only half of the required times. Which aspect is deficient?
- Policy scope
2. Operating effectiveness
3. Authority document design
4. Entity ownership
Correct Answer: 2. Operating effectiveness
Explanation:
Operating effectiveness evaluates whether a control is performed consistently and correctly in practice. In this scenario, the control design is capable of achieving its purpose, but execution is inconsistent. That makes operating effectiveness the primary concern. Assessment results and evidence can help determine the extent of the failure and whether remediation is required. Design effectiveness would instead be questioned if the control could not achieve its objective even when executed properly.
Question 183.
A compliance team wants to represent a specific obligation contained within a larger regulation. Which record is most appropriate?
- Risk
2. Issue
3. Citation or requirement record
4. Service Offering
Correct Answer: 3. Citation or requirement record
Explanation:
A citation or requirement record commonly represents a specific obligation contained within a broader authority document such as a regulation, law, or standard. This allows the organization to connect the individual requirement to internal policies and controls. These relationships improve compliance traceability and make it easier to determine how each external obligation is addressed. Risk and issue records serve different governance purposes and do not represent the regulatory requirement itself.
Question 184.
A company completely stops an activity because management determines its exposure is unacceptable. Which risk response is this?
- Acceptance
2. Mitigation
3. Transfer
4. Avoidance**
Correct Answer: 4. Avoidance
Explanation:
Risk avoidance means eliminating the activity or condition that creates the exposure. By stopping the activity entirely, the organization removes the source of the risk instead of attempting to reduce, transfer, or accept it. Mitigation would introduce controls while continuing the activity, transfer would shift part of the consequences elsewhere, and acceptance would mean knowingly retaining the exposure. Avoidance is generally appropriate when a risk cannot be reduced to an acceptable level.
Question 185.
A control failure requires corrective action. Which record provides the best structure for assigning responsibility and tracking remediation?
- Issue
2. Knowledge Article
3. Catalog Item
4. Service Offering
Correct Answer: 1. Issue
Explanation:
An issue provides a structured remediation lifecycle for identified deficiencies. It can include ownership, target dates, corrective actions, status, evidence, and escalation information. This allows the organization to monitor the weakness until it is resolved and helps ensure accountability. Knowledge articles and catalog items do not provide the same governance-focused remediation capabilities. Issues are therefore well suited to managing control and compliance findings.
Question 186.
An assessor requests reports and approval records to verify that a quarterly control was performed. What is being collected?
- Risk tolerance
2. Control evidence
3. Policy ownership
4. Entity criteria
Correct Answer: 2. Control evidence
Explanation:
Control evidence consists of records that support the conclusion that a control was actually performed. Reports, approval records, screenshots, logs, reconciliations, and similar documentation can all serve as evidence depending on the control. Evidence improves assessment reliability and supports audit readiness. Risk tolerance and entity information provide governance context but do not prove that a specific control activity occurred during the assessment period.
Question 187.
A company introduces additional monitoring to reduce the probability of unauthorized payments. Which risk response is being used?
- Avoidance
2. Transfer
3. Mitigation
4. Acceptance
Correct Answer: 3. Mitigation
Explanation:
Mitigation involves implementing controls or other actions intended to reduce the likelihood or impact of a risk. Additional monitoring can help detect or prevent unauthorized payments and therefore lower exposure. The organization continues the underlying business activity but strengthens the control environment. Avoidance would stop the activity, transfer would shift some consequences to another party, and acceptance would retain the exposure without introducing further safeguards.
Question 188.
A company purchases insurance against a significant operational loss. Which treatment strategy does this represent?
- Mitigation
2. Acceptance
3. Avoidance
4. Transfer**
Correct Answer: 4. Transfer
Explanation:
Insurance is a common form of risk transfer because some of the financial consequences of a risk event are shifted to an insurer. The event itself may still occur, but the organization changes how the loss is distributed. Transfer differs from mitigation, which reduces the likelihood or impact through safeguards, and from avoidance, which eliminates the underlying activity. Acceptance means knowingly retaining the exposure without additional transfer.
Question 189.
Why is linking risks to business entities valuable?
- It provides context about which organizational areas are exposed
2. It automatically lowers every risk score
3. It eliminates the need for controls
4. It prevents future assessments
Correct Answer: 1. It provides context about which organizational areas are exposed
Explanation:
Business entities help scope risks to specific parts of the organization, such as business units, applications, processes, or vendors. Linking risks to entities improves reporting, ownership, prioritization, and assessments because management can understand where exposure exists. It also supports comparisons across different areas of the enterprise. Entity relationships do not automatically change risk scores or eliminate the need for controls and ongoing assessments.
Question 190.
A control owner must formally confirm every year that a control continues to operate. Which mechanism is most appropriate?
- Change Request
2. Attestation or assessment
3. Catalog Item
4. Incident
Correct Answer: 2. Attestation or assessment
Explanation:
An attestation or assessment can be used to obtain periodic confirmation that a control remains in place and continues to operate. The owner may answer structured questions, certify statements, or provide supporting evidence. This creates a repeatable assurance process and can reveal changes in control performance over time. Change requests and incidents serve different operational purposes and are not intended primarily for recurring control verification.
Question 191.
A risk assessment evaluates both how likely an event is and how serious the consequences would be. What are these two dimensions?
- Evidence and ownership
2. Policy and control
3. Likelihood and impact
4. Issue and remediation
Correct Answer: 3. Likelihood and impact
Explanation:
Likelihood represents the probability that a risk event will occur, while impact represents the potential consequences if it does. These two dimensions are commonly used together in risk scoring methodologies. Organizations may use qualitative labels, numeric values, or more advanced calculations, but likelihood and impact remain common foundational factors. Evidence, ownership, and remediation support other parts of the risk management process but are not risk-severity dimensions themselves.
Question 192.
A risk owner approves retaining the remaining exposure because it is within established tolerance. Which treatment decision applies?
- Mitigation
2. Transfer
3. Avoidance
4. Acceptance**
Correct Answer: 4. Acceptance
Explanation:
Risk acceptance occurs when authorized decision-makers determine that residual exposure is within tolerance or otherwise acceptable. The decision should generally be documented and approved according to governance requirements. Acceptance does not eliminate the risk; it means the organization consciously retains it. Other responses include mitigation, transfer, and avoidance, which involve reducing, shifting, or eliminating exposure rather than retaining it.
Question 193.
A single control supports requirements from several compliance frameworks. What is a major benefit of maintaining these mappings?
- Reduced duplicate testing and evidence collection
2. Guaranteed permanent compliance
3. Elimination of all related risks
4. Removal of future assessment requirements
Correct Answer: 1. Reduced duplicate testing and evidence collection
Explanation:
Shared control mappings allow one control to support multiple overlapping requirements. This can reduce duplicate testing, control definitions, and evidence requests while improving traceability. If the control changes or fails, teams can quickly identify the affected obligations. The mapping does not guarantee compliance permanently, and the control still requires ongoing maintenance and assessment. It is primarily an efficiency and traceability benefit.
Question 194.
A policy is revised and employees must confirm that they reviewed the new version. Which process should be used?
- Risk transfer
2. Policy acknowledgment or attestation
3. Control retirement
4. Issue closure
Correct Answer: 2. Policy acknowledgment or attestation
Explanation:
Policy acknowledgment or attestation provides evidence that designated employees reviewed or formally accepted policy content. This supports governance, awareness, and audit readiness. It can also help management identify users who have not completed the required acknowledgment. The process does not replace control testing or risk assessment, but it is well suited to demonstrating that policy communications have reached the intended audience.
Question 195.
A control is performed consistently, but even perfect execution cannot adequately reduce the intended risk. What is the problem?
- Evidence quality
2. Policy acknowledgment
3. Design effectiveness
4. Operating effectiveness
Correct Answer: 3. Design effectiveness
Explanation:
Design effectiveness evaluates whether the control is capable of achieving its intended objective. If the control is performed correctly but still cannot reduce the risk sufficiently, the control design is inadequate. The organization may need to redesign or replace the safeguard. Operating effectiveness applies when a well-designed control is not executed consistently. In this scenario, execution is not the problem; the control itself is fundamentally insufficient.
Question 196.
A regulation changes and management needs to know which internal policies and controls might be affected. What is most useful?
- Browser compatibility reports
2. User preference data
3. Password history
4. Relationship mapping among requirements, policies, controls, and risks**
Correct Answer: 4. Relationship mapping among requirements, policies, controls, and risks
Explanation:
Relationship mapping supports rapid impact analysis when a regulation or standard changes. By maintaining connections among external requirements, internal policies, controls, risks, and entities, the organization can identify affected records without manually searching disconnected documents. This improves regulatory change management and reduces the chance that dependent controls or policies are overlooked. Browser and password data do not provide meaningful compliance dependency information.
Question 197.
An issue is overdue and management wants clear accountability for completing the remediation. Which information is most important?
- Issue owner and target date
2. Policy publication date
3. Authority document title
4. Number of evidence attachments
Correct Answer: 1. Issue owner and target date
Explanation:
The issue owner identifies who is accountable for completing remediation, while the target date defines the expected completion timeframe. Together with status and corrective actions, these fields make overdue remediation visible and support escalation. Policy dates and evidence counts may provide context but do not establish who is responsible for resolving the deficiency or when the work should be completed.
Question 198.
A shared control fails and the compliance team needs to understand which regulations may be affected. What should they review first?
- Application themes
2. Control-to-requirement mappings
3. User login history
4. Knowledge article activity
Correct Answer: 2. Control-to-requirement mappings
Explanation:
Control-to-requirement mappings reveal which regulations, standards, or internal obligations depend on a particular control. When a shared control fails, these mappings help compliance teams quickly determine the broader impact and prioritize remediation. Accurate relationships are especially valuable when a single control supports many frameworks. User logins and interface settings do not provide this compliance dependency information.
Question 199.
A critical control fails during testing and residual risk may now be higher than previously recorded. What should the organization do?
- Delete the risk
2. Ignore the failure until the next assessment cycle
3. Record the deficiency, track remediation, and reassess the risk as appropriate
4. Remove the related authority document
Correct Answer: 3. Record the deficiency, track remediation, and reassess the risk as appropriate
Explanation:
A failed control may reduce the amount of mitigation the organization previously assumed was operating. Residual exposure can therefore increase. The deficiency should be documented and remediation tracked, while the related risk should be reviewed to determine whether its current rating remains accurate. Ignoring or deleting the records would hide the problem instead of managing it. The authority document remains relevant regardless of control performance.
Question 200.
Which approach best supports a mature and scalable ServiceNow Risk and Compliance program?
- Track remediation mainly through email
2. Keep risks and controls disconnected
3. Avoid maintaining requirement mappings
4. Maintain accurate connected records for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation**
Correct Answer: 4. Maintain accurate connected records for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation
Explanation:
A mature Risk and Compliance program depends on structured, connected, and current information. Entities provide business context, risks represent exposure, controls provide mitigation, requirements and policies define obligations, assessments and evidence support assurance, and issues manage remediation. Maintaining these relationships improves reporting, accountability, impact analysis, and audit readiness. Disconnected spreadsheets and informal tracking become increasingly difficult to manage as the compliance environment and organizational scope grow.