ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part16 Q301-320

View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps

 

Question 301.

An organization wants to determine the amount of exposure that remains after all existing controls are considered. Which value should it review?

  1. Inherent risk
    2. Residual risk
    3. Accepted risk
    4. Authority risk

Correct Answer: 2. Residual risk

Explanation:

Residual risk represents the exposure remaining after controls, safeguards, and other treatment measures are taken into account. Inherent risk represents the exposure before those controls are considered. Comparing inherent and residual risk helps management understand how much mitigation the control environment provides. Residual risk can then be compared with organizational tolerance or appetite to determine whether additional mitigation, transfer, avoidance, or formal acceptance is required.

Question 302.

A control is performed consistently, but the activity itself is not capable of addressing the intended risk. Which area is deficient?

  1. Design effectiveness
    2. Operating effectiveness
    3. Evidence collection
    4. Risk ownership

Correct Answer: 1. Design effectiveness

Explanation:

Design effectiveness evaluates whether a control is capable of achieving its intended objective. If the control is consistently performed but cannot meaningfully reduce the associated risk or satisfy the requirement, the design is inadequate. The organization may need to redesign or replace the control. Operating effectiveness would instead be the concern if a properly designed control were performed inconsistently or incorrectly.

Question 303.

A compliance analyst wants to trace a regulatory obligation to the safeguards that address it. What relationship is most important?

  1. Risk-to-owner mapping
    2. User-to-role mapping
    3. Requirement-to-control mapping
    4. Issue-to-email mapping

Correct Answer: 3. Requirement-to-control mapping

Explanation:

Requirement-to-control mapping provides traceability between an obligation and the safeguards used to address it. This relationship helps demonstrate how regulations or standards are implemented internally and is valuable for audits, impact analysis, and compliance reporting. If a control fails, teams can identify which requirements may be affected. User-role and email relationships do not provide the same compliance traceability.

Question 304.

Management permanently stops a business activity because its exposure cannot be reduced to an acceptable level. Which treatment applies?

  1. Mitigation
    2. Acceptance
    3. Transfer
    4. Avoidance**

Correct Answer: 4. Avoidance

Explanation:

Risk avoidance removes the source of exposure by discontinuing the activity that creates it. Unlike mitigation, the organization does not continue the activity with additional safeguards. Transfer shifts some consequences to another party, while acceptance means retaining the exposure. Avoidance is appropriate when management concludes that continuing the activity would create unacceptable risk even after reasonable control measures are considered.

Question 305.

A failed control requires corrective action and management wants to track ownership, due dates, and progress. Which record should be used?

  1. Issue
    2. Knowledge Article
    3. Catalog Item
    4. Service Offering

Correct Answer: 1. Issue

Explanation:

An issue provides a structured way to manage deficiencies through remediation. It can include an assigned owner, target date, status, corrective actions, and supporting documentation. This helps ensure that identified weaknesses are tracked through resolution and that overdue remediation can be escalated. Knowledge articles and catalog items serve different purposes and do not provide the same governance-focused remediation lifecycle.

Question 306.

During an assessment, an auditor requests logs and signed approvals to verify that a control was performed. What is being requested?

  1. Risk appetite
    2. Control evidence
    3. Policy scope
    4. Entity criteria

Correct Answer: 2. Control evidence

Explanation:

Control evidence provides objective support that a control was actually performed and operated as expected. Logs, approvals, reports, screenshots, and reconciliations are common examples. Evidence strengthens assessment conclusions and supports audit readiness. Risk appetite and entity criteria provide governance context but do not prove that a specific control activity took place during the required period.

Question 307.

An organization introduces additional monitoring to reduce the likelihood that fraudulent activity goes undetected. Which response is being used?

  1. Transfer
    2. Acceptance
    3. Mitigation
    4. Avoidance

Correct Answer: 3. Mitigation

Explanation:

Mitigation involves implementing safeguards intended to reduce the likelihood or impact of a risk. Additional monitoring can help detect suspicious activity and therefore lower exposure. The business activity continues, but stronger controls are introduced. Avoidance would stop the activity, transfer would shift some consequences elsewhere, and acceptance would retain the exposure without further treatment.

Question 308.

A company enters an insurance agreement that covers certain losses. Which risk treatment does this most closely represent?

  1. Avoidance
    2. Mitigation
    3. Acceptance
    4. Transfer**

Correct Answer: 4. Transfer

Explanation:

Insurance transfers part of the financial consequence of a risk event to another party. The underlying event may still occur, but the organization reduces the amount of loss it must bear directly. Mitigation reduces exposure through safeguards, avoidance eliminates the risky activity, and acceptance means consciously retaining the exposure. Transfer changes how the consequences of the risk are distributed.

Question 309.

Why should risks be linked to the business entities they affect?

  1. To provide context about where exposure exists
    2. To automatically close remediation issues
    3. To eliminate the need for controls
    4. To prevent future risk assessments

Correct Answer: 1. To provide context about where exposure exists

Explanation:

Business entities provide organizational context for risk. They can represent business units, applications, processes, vendors, or other scoped objects. Linking risks to these entities helps management understand where exposure exists and supports reporting, prioritization, ownership, and assessment. Entity relationships do not remove the need for controls or risk assessments, but they improve enterprise visibility.

Question 310.

A control owner must formally confirm every quarter that a control remains active and continues to operate. Which process is most appropriate?

  1. Incident management
    2. Attestation or assessment
    3. Catalog fulfillment
    4. Change implementation

Correct Answer: 2. Attestation or assessment

Explanation:

An attestation or assessment provides a structured way to obtain periodic confirmation that a control remains in place and continues to operate. The owner can answer questions, certify statements, or submit evidence. This creates a repeatable assurance process and helps identify control deterioration over time. Incident and catalog processes are designed for different operational purposes.

Question 311.

Which two dimensions are commonly combined when evaluating risk severity?

  1. Evidence and remediation
    2. Policy age and issue count
    3. Likelihood and impact
    4. Control age and owner tenure

Correct Answer: 3. Likelihood and impact

Explanation:

Likelihood represents the probability that a risk event will occur, while impact reflects the potential consequence if it does. These two dimensions are commonly combined in qualitative or quantitative risk-scoring methodologies. Organizations may define customized scales and formulas, but likelihood and impact remain common foundational measures. Evidence and issue information support other governance processes but are not core risk-severity dimensions.

Question 312.

A risk owner concludes that residual exposure is within tolerance and formally chooses to retain it. Which response applies?

  1. Avoidance
    2. Mitigation
    3. Transfer
    4. Acceptance**

Correct Answer: 4. Acceptance

Explanation:

Risk acceptance occurs when authorized stakeholders knowingly retain residual exposure because it is within approved tolerance or because further treatment is not justified. The decision should generally be documented according to governance requirements. Acceptance does not remove the risk. It confirms that management understands the remaining exposure and is willing to retain it under current conditions.

Question 313.

One control supports obligations from several compliance frameworks. What is one important benefit of maintaining these mappings?

  1. Reduced duplicate testing and evidence collection
    2. Permanent elimination of compliance risk
    3. Automatic closure of all issues
    4. Removal of all future assessments

Correct Answer: 1. Reduced duplicate testing and evidence collection

Explanation:

A shared control can support multiple overlapping requirements, allowing the same testing and evidence to be reused across frameworks. This can reduce duplicated work and improve compliance traceability. The mappings also help identify which obligations are affected if the control later fails. Shared controls still require ongoing assessment and maintenance, so they do not guarantee permanent compliance.

Question 314.

Employees must formally confirm that they have reviewed an updated policy. Which process best supports this requirement?

  1. Risk transfer
    2. Policy acknowledgment or attestation
    3. Control retirement
    4. Issue closure

Correct Answer: 2. Policy acknowledgment or attestation

Explanation:

Policy acknowledgment or attestation provides documented evidence that designated employees reviewed or accepted policy content. This supports governance, awareness, and audit readiness. It can also help identify users who have not completed the required acknowledgment. This process does not replace control testing or risk assessments, but it is appropriate for proving that revised policy information was communicated to the intended audience.

Question 315.

A control is well designed but is frequently skipped by employees. Which area is weak?

  1. Evidence retention
    2. Design effectiveness
    3. Operating effectiveness
    4. Risk acceptance

Correct Answer: 3. Operating effectiveness

Explanation:

Operating effectiveness focuses on whether a control is actually performed consistently and correctly in practice. A control may have a sound design but still fail to reduce risk if employees skip it or execute it inconsistently. Testing and evidence can reveal these operational failures. Design effectiveness would instead be the concern if the control were incapable of achieving its objective even when performed exactly as intended.

Question 316.

A regulation changes and the compliance team needs to identify affected internal policies, controls, and risks. What is most useful?

  1. Browser version reports
    2. Password reset logs
    3. User-interface preferences
    4. Relationship mapping and impact analysis**

Correct Answer: 4. Relationship mapping and impact analysis

Explanation:

Connected relationships among requirements, policies, controls, risks, and entities support efficient regulatory change analysis. Compliance teams can quickly identify which internal records may need review instead of searching through disconnected documents manually. This improves traceability and reduces the chance that affected safeguards or policies are overlooked. Browser and password data do not reveal compliance dependencies.

Question 317.

A remediation issue is overdue. Which information is most important for accountability?

  1. Assigned owner, target date, status, and corrective actions
    2. Policy formatting
    3. Browser type
    4. Number of knowledge articles

Correct Answer: 1. Assigned owner, target date, status, and corrective actions

Explanation:

Clear ownership and deadlines are essential for remediation accountability. The assigned owner identifies who is responsible, the target date establishes when the work should be completed, status shows progress, and corrective actions define what remains to be done. These details support escalation when remediation becomes overdue. Formatting and browser information do not contribute to corrective-action accountability.

Question 318.

A shared control fails. Which information should management review to determine which external obligations may be affected?

  1. User-role assignments
    2. Control-to-requirement mappings
    3. Application themes
    4. Knowledge article activity

Correct Answer: 2. Control-to-requirement mappings

Explanation:

Control-to-requirement mappings identify the obligations that depend on a particular safeguard. When a shared control fails, these relationships allow management to understand which regulations, standards, or internal requirements may be affected. This supports impact analysis, remediation prioritization, and compliance reporting. User roles and application themes do not provide the necessary dependency information.

Question 319.

A critical control fails and residual risk may now be understated. What should the organization do?

  1. Delete the related risk
    2. Ignore the finding until the next annual assessment
    3. Record the deficiency, track remediation, and reassess the risk as appropriate
    4. Remove the associated regulation

Correct Answer: 3. Record the deficiency, track remediation, and reassess the risk as appropriate

Explanation:

A failed critical control may reduce the expected amount of mitigation and cause residual exposure to increase. The deficiency should be documented, corrective actions should be assigned, and the related risk should be reviewed to determine whether the existing rating is still accurate. Ignoring or deleting the finding would hide the exposure rather than manage it responsibly.

Question 320.

Which practice best supports scalable ServiceNow Risk and Compliance operations?

  1. Track deficiencies only through email
    2. Keep controls and requirements disconnected
    3. Avoid linking risks to business entities
    4. Maintain accurate connected records for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation**

Correct Answer: 4. Maintain accurate connected records for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation

Explanation:

Scalable Risk and Compliance operations depend on reliable, structured, and connected data. Business entities provide context, risks represent exposure, controls provide mitigation, policies and requirements define obligations, assessments and evidence support assurance, and issues manage remediation. Maintaining these relationships improves reporting, audit readiness, accountability, and impact analysis. Disconnected spreadsheets and email-only tracking become increasingly difficult to govern as organizational and regulatory complexity grows.