View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps
Question 321.
An organization defines the overall amount and type of risk it is willing to pursue or retain in support of its objectives. Which concept does this describe?
- Risk appetite
2. Residual risk
3. Control evidence
4. Issue severity
Correct Answer: 1. Risk appetite
Explanation:
Risk appetite expresses the broad level and type of risk an organization is willing to accept while pursuing its objectives. It provides strategic guidance for risk-taking and helps establish more specific limits or tolerances. Residual risk represents exposure remaining after controls, while control evidence supports assurance activities. Clearly defined appetite helps risk owners and executives determine whether current exposures align with organizational expectations.
Question 322.
A business unit has exceeded the maximum acceptable level defined for a specific operational risk. Which concept has most directly been exceeded?
- Risk taxonomy
2. Risk tolerance
3. Control frequency
4. Policy acknowledgment
Correct Answer: 2. Risk tolerance
Explanation:
Risk tolerance represents a more specific acceptable variation or limit for a particular risk, metric, or activity. It is typically more operational than broad risk appetite. When exposure exceeds tolerance, the organization may need additional treatment, escalation, or formal approval. A taxonomy categorizes risks, while control frequency and policy acknowledgment support other governance activities and do not define acceptable exposure levels.
Question 323.
A key risk indicator exceeds its defined threshold for three consecutive reporting periods. What is the most appropriate interpretation?
- The related risk should automatically be deleted
2. The control should automatically be retired
3. The trend may indicate increasing exposure and should be reviewed
4. The organization is automatically compliant
Correct Answer: 3. The trend may indicate increasing exposure and should be reviewed
Explanation:
A key risk indicator provides measurable information about conditions that may signal changing risk exposure. Repeated threshold breaches can indicate that risk is increasing or that existing controls are becoming less effective. The appropriate response is to review the underlying risk, related controls, and treatment actions. Threshold breaches do not automatically prove a control failure or require deleting records, but they provide valuable monitoring information that can trigger further assessment.
Question 324.
Which control type is primarily intended to stop an undesirable event before it occurs?
- Detective control
2. Corrective control
3. Compensating control
4. Preventive control**
Correct Answer: 4. Preventive control
Explanation:
Preventive controls are designed to reduce the likelihood of an undesirable event before it happens. Examples can include access restrictions, approval requirements, segregation of duties, and validation checks. Detective controls identify events after or while they occur, while corrective controls help restore conditions afterward. A compensating control is an alternative safeguard used when a preferred control cannot be implemented effectively.
Question 325.
A company cannot implement its preferred security control because of a legacy-system limitation. It introduces an alternative safeguard that provides comparable protection. What is this alternative called?
- Compensating control
2. Residual risk
3. Risk appetite
4. Policy exception
Correct Answer: 1. Compensating control
Explanation:
A compensating control is an alternative safeguard used when the preferred or standard control cannot be implemented. It should provide sufficient protection to address the intended risk or requirement. The organization should document why the primary control is unavailable and how the alternative provides adequate coverage. Residual risk and risk appetite describe exposure concepts, while a policy exception documents deviation rather than serving as the alternative control itself.
Question 326.
A control requires evidence every month, but the most recent evidence is eight months old. What is the primary concern?
- The risk taxonomy is incomplete
2. The evidence may no longer demonstrate current control performance
3. The policy owner must be replaced
4. The authority document should be retired
Correct Answer: 2. The evidence may no longer demonstrate current control performance
Explanation:
Evidence should be sufficiently current to support conclusions about control performance for the relevant assessment period. If a monthly control has only eight-month-old evidence, the assessor cannot confidently conclude that the control continues to operate. Evidence freshness is therefore important. Older evidence may still provide historical context, but it generally cannot substitute for proof that a recurring control has operated during the current review period.
Question 327.
A control failed, remediation was completed, and management wants assurance that the corrected control now works. What should happen next?
- Close the issue without further review
2. Delete the original assessment
3. Re-test or reassess the control
4. Accept the risk automatically
Correct Answer: 3. Re-test or reassess the control
Explanation:
After remediation, re-testing or reassessment helps confirm that the corrective action resolved the underlying deficiency and that the control now operates effectively. Closing an issue without verification can leave unresolved weaknesses hidden. The original assessment should remain part of the historical record. Depending on governance requirements, closure evidence and successful re-testing may be required before the issue is considered fully resolved.
Question 328.
An organization wants to apply one risk assessment methodology consistently across several subsidiaries and business units. What is the main benefit?
- It guarantees that all risks will have identical scores
2. It removes the need for risk owners
3. It eliminates control testing
4. It improves comparability of risk results across entities**
Correct Answer: 4. It improves comparability of risk results across entities
Explanation:
Using a consistent methodology makes risk scores and assessments easier to compare across entities because similar criteria, scales, and definitions are applied. This supports enterprise reporting, aggregation, and prioritization. It does not mean every risk will receive the same score, because exposure can vary significantly by entity. Consistency improves interpretation without eliminating ownership or control assurance requirements.
Question 329.
Which record or view is most useful for maintaining a consolidated list of identified organizational risks and their key details?
- Risk register
2. Knowledge base
3. Service catalog
4. Change calendar
Correct Answer: 1. Risk register
Explanation:
A risk register provides a consolidated view of identified risks and commonly includes information such as ownership, category, status, assessments, treatments, and current exposure. It helps management monitor the organization’s risk landscape and supports prioritization and reporting. Knowledge bases and service catalogs serve different operational purposes and are not designed to provide a comprehensive view of enterprise risk.
Question 330.
A company wants to detect unusual transaction patterns after transactions have occurred. Which control type is most appropriate?
- Preventive control
2. Detective control
3. Risk acceptance
4. Policy exception
Correct Answer: 2. Detective control
Explanation:
Detective controls are designed to identify events, errors, or irregularities after or while they occur. Transaction monitoring, exception reports, reconciliations, and log reviews are common examples. Preventive controls try to stop undesirable activity before it happens. Detective controls are valuable because they can reveal failures that preventive controls did not stop and can trigger corrective action or further investigation.
Question 331.
A policy has not been reviewed for several years, even though regulations and business processes have changed. What is the greatest governance concern?
- The policy contains too many acknowledgments
2. The control owner has too much evidence
3. The policy may no longer reflect current obligations or practices
4. The risk register is automatically invalid
Correct Answer: 3. The policy may no longer reflect current obligations or practices
Explanation:
Policies should be reviewed periodically to ensure they remain aligned with current regulations, business processes, organizational responsibilities, and control expectations. An outdated policy may create gaps between documented requirements and actual practices. Regular review cycles help identify needed revisions and support good policy governance. A stale policy does not automatically invalidate every related risk or control, but it can weaken the overall compliance program.
Question 332.
A business unit receives temporary approval to deviate from a policy requirement while a system upgrade is underway. What governance mechanism best represents this situation?
- Risk avoidance
2. Control retirement
3. Authority deletion
4. Policy exception or waiver**
Correct Answer: 4. Policy exception or waiver
Explanation:
A policy exception or waiver documents an approved temporary deviation from a policy requirement. Effective exception governance should identify the reason, scope, approver, expiration date, compensating safeguards, and any associated risk. It should not become an indefinite way to bypass requirements. Once the underlying condition is resolved, the exception should be reviewed, closed, or renewed according to established governance.
Question 333.
A new acquisition significantly changes an organization’s processes and technology environment. What should happen to relevant risks?
- They should be reassessed because material business changes can alter exposure
2. They should automatically be accepted
3. They should be closed permanently
4. Their control mappings should be removed
Correct Answer: 1. They should be reassessed because material business changes can alter exposure
Explanation:
Major business changes such as acquisitions, reorganizations, new systems, or substantial process changes can affect likelihood, impact, control effectiveness, and ownership. Relevant risks should therefore be reassessed to ensure current ratings still reflect actual exposure. Existing control mappings may also need review. Automatically accepting or closing risks could leave significant new exposures unrecognized.
Question 334.
An organization uses automated data feeds to monitor risk indicators and control conditions continuously. What is the primary advantage?
- It removes all need for human oversight
2. It can identify changing conditions sooner than periodic manual reviews
3. It permanently eliminates residual risk
4. It guarantees regulatory compliance
Correct Answer: 2. It can identify changing conditions sooner than periodic manual reviews
Explanation:
Continuous monitoring can provide more timely visibility into changing risk indicators, control conditions, or compliance exceptions. Automated data feeds may detect threshold breaches or anomalies earlier than quarterly or annual manual reviews. Human review and governance are still important for interpreting results and deciding what action to take. Continuous monitoring improves timeliness, but it does not guarantee compliance or eliminate risk.
Question 335.
An organization wants to group risks into areas such as operational, compliance, strategic, and technology. What concept supports this?
- Evidence freshness
2. Issue aging
3. Risk taxonomy or categorization
4. Policy acknowledgment
Correct Answer: 3. Risk taxonomy or categorization
Explanation:
A risk taxonomy organizes risks into meaningful categories and subcategories. This helps organizations classify risks consistently, improve reporting, identify concentration, and compare exposure across the enterprise. Categories such as operational, strategic, compliance, and technology are common examples. A clear taxonomy also supports governance and aggregation without changing the actual likelihood or impact of individual risks.
Question 336.
A policy reaches the end of its useful life and has been replaced by a newer approved version. What should happen to the obsolete policy?
- Keep it active indefinitely
2. Delete all historical references immediately
3. Convert it into a risk record
4. Retire or archive it according to the policy lifecycle**
Correct Answer: 4. Retire or archive it according to the policy lifecycle
Explanation:
A mature policy lifecycle includes creation, review, approval, publication, periodic review, revision, and eventual retirement or archival. When a policy has been superseded, it should no longer remain active as if it were current. Historical versions may still need to be retained for audit, legal, or governance purposes. Retirement preserves lifecycle integrity while preventing users from relying on obsolete guidance.
Question 337.
A risk treatment plan includes several specific actions assigned to different owners. What is the main purpose of these actions?
- To implement and track the selected risk response
2. To replace all related policies
3. To remove the risk from the register immediately
4. To eliminate the need for future monitoring
Correct Answer: 1. To implement and track the selected risk response
Explanation:
Risk treatment actions translate a selected response into concrete work. They may include implementing controls, changing processes, transferring exposure, or completing other mitigation activities. Assigning owners and target dates makes the treatment measurable and accountable. A risk normally remains subject to monitoring until treatment is complete and the resulting residual exposure is understood. Treatment actions therefore support execution rather than simply documenting intent.
Question 338.
An organization wants to distinguish control ownership from independent control testing. Why is this separation valuable?
- It eliminates the need for evidence
2. It supports more objective assurance over control effectiveness
3. It automatically lowers residual risk
4. It removes the need for control owners
Correct Answer: 2. It supports more objective assurance over control effectiveness
Explanation:
Separating control ownership from independent testing can strengthen assurance because the person responsible for operating a control is not solely responsible for evaluating its effectiveness. Independent review can reduce conflicts of interest and provide a more objective assessment of design, operation, and evidence. Control owners remain responsible for the control itself, while testers provide assurance regarding whether it functions as intended.
Question 339.
A risk indicator is below threshold today, but its values have increased steadily for six months. Why should the trend still be reviewed?
- Any upward trend automatically proves a control failure
2. Trends are irrelevant until a threshold is breached
3. A sustained increase may provide early warning of worsening exposure
4. The related risk should automatically be closed
Correct Answer: 3. A sustained increase may provide early warning of worsening exposure
Explanation:
Risk monitoring should consider both current threshold status and trend direction. A steadily increasing indicator can provide early warning that exposure is worsening even before a formal threshold is crossed. Reviewing trends enables management to investigate causes and consider preventive action sooner. An upward trend does not automatically prove a control failure, but it can signal that existing assumptions, controls, or treatment plans should be reviewed.
Question 340.
Before automating a large Risk and Compliance program, what should an organization establish first?
- As many custom fields as possible
2. A separate spreadsheet for every department
3. Automated issue closure rules without review
4. Clear governance, methodology, ownership, and data requirements**
Correct Answer: 4. Clear governance, methodology, ownership, and data requirements
Explanation:
Automation is most effective when the organization first defines how risk and compliance processes should operate. Clear methodology, ownership, approval rules, data standards, assessment approaches, and escalation paths provide the foundation for reliable automation. Automating an undefined or inconsistent process can simply make poor practices happen faster. Establishing governance first helps ensure that workflows, reports, assessments, and monitoring support consistent enterprise objectives.