ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part18 Q341-360

View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps

 

Question 341.

A risk indicator crosses its warning threshold before the related risk reaches an unacceptable score. What is the best use of this information?

  1. Ignore it until the risk score changes
    2. Use it as an early warning and investigate the underlying condition
    3. Automatically close the risk
    4. Retire all related controls

Correct Answer: 2. Use it as an early warning and investigate the underlying condition

Explanation:

Risk indicators can provide early warning that exposure is changing before a formal risk assessment shows a significant increase. A threshold breach should prompt review of the underlying business condition, related controls, recent trends, and treatment plans. It does not automatically prove that a control has failed or that the risk score must change, but it gives management timely information that may justify further investigation or reassessment.

Question 342.

An organization wants to compare risks across multiple business units using consistent scoring. What should it define first?

  1. A common risk assessment methodology and criteria
    2. A different scoring scale for every department
    3. A unique policy for every risk
    4. Separate evidence standards for each user

Correct Answer: 1. A common risk assessment methodology and criteria

Explanation:

Consistent risk scoring depends on clearly defined criteria, scales, terminology, and assessment methods. A common methodology improves comparability across entities and reduces the chance that similar risks are rated differently simply because different teams use different rules. Business units may still have unique exposure levels, but applying consistent criteria enables more reliable enterprise reporting, aggregation, and prioritization.

Question 343.

A control identifies unauthorized access after it has already occurred. Which control type does this represent?

  1. Preventive control
    2. Compensating control
    3. Detective control
    4. Risk acceptance

Correct Answer: 3. Detective control

Explanation:

Detective controls identify undesirable events, errors, or exceptions during or after they occur. Examples include log reviews, exception reports, transaction monitoring, and reconciliations. Preventive controls are designed to stop an event before it happens. A compensating control is an alternative safeguard used when a preferred control cannot be implemented, while risk acceptance is a treatment decision rather than a control type.

Question 344.

A policy exception is approved for six months. Which additional information is most important for sound governance?

  1. Browser version
    2. Knowledge article count
    3. User-interface theme
    4. Expiration date, approver, rationale, and compensating safeguards**

Correct Answer: 4. Expiration date, approver, rationale, and compensating safeguards

Explanation:

A policy exception should be governed carefully so it does not become a permanent undocumented bypass. Important information includes why the exception is necessary, who approved it, how long it remains valid, and what safeguards reduce the associated exposure. The exception should also be reviewed before expiration. This creates accountability and helps ensure temporary deviations are controlled and reassessed appropriately.

Question 345.

A newly acquired company uses different risk categories from the parent organization. What would best support enterprise-wide reporting?

  1. Align the acquired company to a common risk taxonomy
    2. Delete all acquired-company risks
    3. Convert every risk into an issue
    4. Stop performing risk assessments

Correct Answer: 1. Align the acquired company to a common risk taxonomy

Explanation:

A common risk taxonomy improves consistency in classification and reporting across different parts of the organization. Aligning categories allows management to aggregate similar risks, identify concentration, and compare exposure across business units. Existing risks do not need to be deleted simply because their categories differ. Instead, mapping or standardizing them to the enterprise taxonomy improves reporting quality and governance.

Question 346.

A control has been remediated after a failed assessment. What should be completed before the related issue is considered fully resolved?

  1. Delete the original failure result
    2. Re-test the control and confirm the corrective action is effective
    3. Remove the control owner
    4. Automatically accept the associated risk

Correct Answer: 2. Re-test the control and confirm the corrective action is effective

Explanation:

Remediation should be verified rather than assumed. Re-testing the control provides evidence that the corrective action addressed the original weakness and that the control now operates as expected. This supports defensible issue closure and prevents unresolved weaknesses from being hidden. Historical assessment results should generally remain available because they provide important evidence of the control and remediation lifecycle.

Question 347.

A risk owner wants to track whether exposure is moving closer to or farther from acceptable levels over time. Which information is most useful?

  1. Policy font style
    2. Number of catalog items
    3. Risk indicators, thresholds, and trends
    4. Browser compatibility data

Correct Answer: 3. Risk indicators, thresholds, and trends

Explanation:

Risk indicators provide measurable information about conditions related to exposure. Thresholds define levels that may require attention, while trends show whether those indicators are improving or deteriorating over time. Together, these elements support ongoing risk monitoring between formal assessment cycles. They can help management recognize changes early and decide whether additional treatment or reassessment is necessary.

Question 348.

An organization cannot implement a required control exactly as designed because of a technical limitation. What is the best next step?

  1. Ignore the requirement
    2. Delete the related risk
    3. Mark the control effective without evidence
    4. Implement an appropriate compensating control and document the rationale**

Correct Answer: 4. Implement an appropriate compensating control and document the rationale

Explanation:

A compensating control provides an alternative way to address the intended objective when the preferred control cannot be implemented. The organization should document why the original control is not feasible, how the alternative reduces the relevant exposure, and who approved the approach. The compensating control should also be assessed and monitored like other safeguards. Ignoring the requirement would leave the risk unmanaged.

Question 349.

Which record helps management maintain a consolidated view of known risks, owners, ratings, and treatment status?

  1. Risk register
    2. Service catalog
    3. Knowledge base
    4. Change calendar

Correct Answer: 1. Risk register

Explanation:

A risk register provides a centralized view of identified risks and commonly includes information such as ownership, category, assessment results, treatment decisions, status, and residual exposure. It supports monitoring, prioritization, reporting, and governance. A service catalog and knowledge base serve operational and informational purposes but are not intended to provide an enterprise inventory of risk.

Question 350.

A control requires monthly evidence. Which evidence is most useful during a current-quarter assessment?

  1. Evidence from several years ago
    2. Recent evidence covering the required assessment period
    3. A policy with no control relationship
    4. A risk owner’s verbal statement only

Correct Answer: 2. Recent evidence covering the required assessment period

Explanation:

Evidence should be relevant to the period being assessed and sufficiently current to demonstrate that the control continues to operate. Old evidence may show that the control existed historically, but it does not prove current performance. Recent evidence aligned with the control frequency gives assessors stronger support for their conclusions. Verbal confirmation alone is generally weaker than objective documentation.

Question 351.

A company wants to stop unauthorized changes before they are implemented. Which type of control is most appropriate?

  1. Detective
    2. Corrective
    3. Preventive
    4. Acceptance

Correct Answer: 3. Preventive

Explanation:

Preventive controls are designed to stop undesirable events before they happen. Examples can include required approvals, access restrictions, segregation of duties, or automated validation checks. Detective controls identify problems after or during occurrence, while corrective controls address the consequences afterward. Risk acceptance is a treatment decision rather than a control type.

Question 352.

A policy has been replaced by a newly approved version. What should happen to the old version?

  1. Keep both versions active indefinitely
    2. Convert the old policy into a risk
    3. Delete all evidence linked to the old policy
    4. Retire or archive the superseded version according to policy governance**

Correct Answer: 4. Retire or archive the superseded version according to policy governance

Explanation:

A mature policy lifecycle includes controlled retirement or archival of obsolete versions. The superseded policy should no longer appear to be the current governing document, but historical versions may need to be retained for legal, audit, or governance purposes. Proper retirement avoids user confusion while preserving an appropriate historical record. Simply deleting old versions can remove valuable evidence of prior requirements and approvals.

Question 353.

What is the primary purpose of defining risk treatment actions with owners and due dates?

  1. To make the selected treatment measurable and accountable
    2. To remove the risk from the register immediately
    3. To eliminate the need for future assessments
    4. To replace every related control

Correct Answer: 1. To make the selected treatment measurable and accountable

Explanation:

Risk treatment actions convert a treatment decision into specific work that can be assigned and tracked. Owners establish responsibility, while due dates create measurable expectations for completion. These actions may involve implementing controls, changing processes, transferring exposure, or performing other remediation. The risk usually remains under monitoring until the treatment is complete and the resulting residual exposure is understood.

Question 354.

Why is separating control ownership from independent control testing useful?

  1. It removes the need for evidence
    2. It supports more objective assurance over control effectiveness
    3. It guarantees that controls will never fail
    4. It eliminates control-owner responsibilities

Correct Answer: 2. It supports more objective assurance over control effectiveness

Explanation:

Separating the person responsible for operating a control from the person evaluating it can improve objectivity. Independent testing reduces the chance that control performance is assessed solely by the person accountable for the activity. The control owner still remains responsible for operation and remediation, while the tester provides assurance based on evidence, procedures, and assessment criteria.

Question 355.

A significant business process changes after a system replacement. What should happen to the related risk assessment?

  1. It should automatically be closed
    2. It should remain unchanged permanently
    3. It should be reassessed because the exposure and controls may have changed
    4. All related requirements should be deleted

Correct Answer: 3. It should be reassessed because the exposure and controls may have changed

Explanation:

Material changes to systems, processes, organizational structures, or responsibilities can alter likelihood, impact, control effectiveness, and ownership. Reassessing affected risks helps ensure that recorded exposure remains accurate after the change. Existing controls may need to be reviewed or redesigned as well. Keeping an outdated risk score could give management a misleading view of current conditions.

Question 356.

Which approach is most appropriate when evidence requested for a control assessment is missing?

  1. Assume the control is effective
    2. Close the assessment without comment
    3. Delete the control
    4. Document the evidence gap and evaluate whether it affects the assessment conclusion**

Correct Answer: 4. Document the evidence gap and evaluate whether it affects the assessment conclusion

Explanation:

Missing evidence can limit the assessor’s ability to conclude that a control operated effectively. The gap should be documented and evaluated according to the assessment methodology. Depending on significance, the organization may request additional evidence, record a deficiency, or adjust the assessment result. Automatically assuming effectiveness would weaken assurance and reduce the reliability of compliance reporting.

Question 357.

An enterprise wants to monitor the same control across several business entities. What is the main advantage of entity-based scoping?

  1. It allows control performance and exposure to be evaluated in the correct business context
    2. It eliminates the need for control owners
    3. It guarantees identical results for every entity
    4. It removes the need for evidence

Correct Answer: 1. It allows control performance and exposure to be evaluated in the correct business context

Explanation:

Entity-based scoping helps organizations evaluate risks, controls, and compliance requirements within the specific business areas they affect. A control may perform differently across applications, subsidiaries, processes, or vendors. Scoping assessments to relevant entities allows management to compare results and identify localized weaknesses. It does not guarantee identical outcomes or eliminate the need for ownership and evidence.

Question 358.

A control is tested using a sample of transactions rather than every transaction. What is the purpose of sampling?

  1. To avoid collecting any evidence
    2. To evaluate control performance using a representative subset when full testing is impractical
    3. To guarantee control effectiveness
    4. To replace the control owner

Correct Answer: 2. To evaluate control performance using a representative subset when full testing is impractical

Explanation:

Sampling allows an assessor to examine a subset of transactions or control executions when testing every item would be impractical. The sample should be selected according to an appropriate testing methodology so conclusions are reasonably supported. Sampling does not guarantee effectiveness, and poorly chosen samples can produce misleading results. Evidence and professional judgment remain important parts of the testing process.

Question 359.

A key risk indicator remains below its threshold but has deteriorated steadily for several reporting periods. What should management do?

  1. Ignore the trend because the threshold has not been crossed
    2. Automatically close the related risk
    3. Review the trend because it may indicate worsening exposure
    4. Retire all associated controls

Correct Answer: 3. Review the trend because it may indicate worsening exposure

Explanation:

Thresholds provide useful trigger points, but trend direction can reveal emerging problems before a formal limit is exceeded. A steady deterioration may indicate that the underlying risk environment or control performance is changing. Management should investigate the cause and determine whether additional monitoring, treatment, or reassessment is necessary. Waiting for a threshold breach can delay action on a developing exposure.

Question 360.

What should an organization establish before heavily automating Risk and Compliance workflows?

  1. A separate spreadsheet for every business unit
    2. Automatic closure of all overdue issues
    3. Maximum customization of every form
    4. Clear governance, roles, methodologies, data standards, and escalation rules**

Correct Answer: 4. Clear governance, roles, methodologies, data standards, and escalation rules

Explanation:

Automation works best when the underlying governance process is already clearly defined. Organizations should establish roles, risk and control methodologies, data standards, approval paths, assessment rules, and escalation expectations before automating workflows. Otherwise, technology may simply accelerate inconsistent or poorly governed processes. A strong governance foundation helps ensure that automation produces reliable, scalable, and auditable Risk and Compliance operations.