ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part2 Q21-40

View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps

 

Question 21.

An organization wants to understand how much risk remains after existing controls are taken into account. Which risk measure should it review?

  1. Residual risk
    2. Inherent risk
    3. Gross risk
    4. Unassigned risk

Correct Answer: 1. Residual risk

Explanation:

Residual risk represents the amount of exposure remaining after relevant controls, safeguards, and mitigation activities have been considered. Organizations often compare residual risk with defined tolerance or appetite levels to determine whether additional treatment is needed. Inherent risk, by contrast, describes exposure before controls are considered. Reviewing residual risk helps decision-makers understand whether the current control environment is reducing exposure sufficiently or whether more mitigation, transfer, avoidance, or formal acceptance is appropriate.

Question 22.

A control is found to be poorly designed and unable to address the risk it was intended to mitigate. What is the most appropriate next step?

  1. Close the risk immediately
    2. Record the control deficiency and initiate remediation
    3. Delete the control record
    4. Mark the control effective because it exists

Correct Answer: 2. Record the control deficiency and initiate remediation

Explanation:

A control that is poorly designed cannot reliably reduce the intended risk, even if employees attempt to perform it. The deficiency should be documented and tracked through a structured remediation process. This creates ownership, due dates, and visibility into corrective actions. The related risk may also need to be reassessed because ineffective control design can increase residual exposure. Simply deleting the control or marking it effective would hide the weakness rather than address it.

Question 23.

Which record commonly represents a specific requirement within an authority document such as a regulation or standard?

  1. Incident
    2. Service Offering
    3. Citation or requirement record
    4. Change Request

Correct Answer: 3. Citation or requirement record

Explanation:

Authority documents represent broader external sources such as regulations, laws, standards, or contractual frameworks, while citations or requirement records commonly represent the individual obligations contained within them. These requirements can then be related to internal controls and policies to demonstrate how the organization addresses external expectations. Incidents and change requests are operational service management records and do not normally represent individual regulatory or standards-based obligations.

Question 24.

A risk owner decides that a risky business activity should be stopped completely because the exposure is too high. Which risk response is being used?

  1. Acceptance
    2. Transfer
    3. Mitigation
    4. Avoidance**

Correct Answer: 4. Avoidance

Explanation:

Risk avoidance means eliminating the activity or condition that creates the risk. This response is appropriate when the organization determines that the exposure is unacceptable and cannot be reduced to a tolerable level through controls or other treatments. Mitigation reduces risk, transfer shifts part of the exposure to another party, and acceptance means consciously retaining it. Avoidance is therefore the response that most directly removes the source of the risk.

Question 25.

What is the main purpose of assigning an owner to a control?

  1. To establish accountability for maintaining and operating the control
    2. To define the organization’s application theme
    3. To calculate asset depreciation
    4. To eliminate the need for assessments

Correct Answer: 1. To establish accountability for maintaining and operating the control

Explanation:

A control owner is accountable for ensuring that the control is appropriately maintained and performed. Ownership also provides a clear contact for assessments, evidence requests, remediation discussions, and questions about control operation. Assigning accountability helps prevent controls from becoming neglected or outdated. Control ownership does not remove the need for independent testing or assessment and is unrelated to interface themes or asset depreciation.

Question 26.

An organization wants to determine whether a control is actually being performed according to its documented procedure. Which activity best supports this objective?

  1. Publishing a knowledge article
    2. Control testing or assessment
    3. Changing the application scope
    4. Creating a catalog request

Correct Answer: 2. Control testing or assessment

Explanation:

Control testing or assessment is used to determine whether the control is operating as intended. Assessors may review evidence, obtain attestations, inspect samples, or evaluate control performance according to the organization’s methodology. This provides assurance beyond simply documenting that a control exists. If testing identifies a failure, an issue and remediation process may follow. Knowledge publishing and catalog requests do not evaluate control operating effectiveness.

Question 27.

Which relationship is most useful for showing how an internal safeguard addresses a regulatory requirement?

  1. Risk to browser version
    2. Policy to application theme
    3. Control mapped to the relevant requirement
    4. Incident mapped to a password policy

Correct Answer: 3. Control mapped to the relevant requirement

Explanation:

Mapping a control to the requirement it supports creates traceability between the organization’s internal safeguards and external or internal obligations. This helps demonstrate how regulatory requirements are being addressed and can reduce duplicate effort when the same control supports several frameworks. The relationship also improves impact analysis if the control later fails. Browser versions and unrelated operational records do not provide meaningful compliance traceability.

Question 28.

A risk assessment determines that the probability of a threat occurring is high, but the business impact would be low. Which two factors are being evaluated?

  1. Control cost and policy age
    2. Ownership and remediation
    3. Evidence and attestation
    4. Likelihood and impact**

Correct Answer: 4. Likelihood and impact

Explanation:

Likelihood and impact are two common dimensions used to evaluate risk exposure. Likelihood reflects the probability that a risk event will occur, while impact reflects the consequence if it does occur. Organizations may combine these factors through qualitative or quantitative methods to calculate a risk score. Exact scoring models vary by organization, but likelihood and impact are widely used inputs. Control cost and policy age are not equivalent risk-rating dimensions.

Question 29.

A control failure is identified during an assessment. Why might the related risk need to be reassessed?

  1. The failed control may result in greater residual exposure
    2. Every control failure automatically deletes the risk
    3. The risk owner must always be changed
    4. The authority document becomes invalid

Correct Answer: 1. The failed control may result in greater residual exposure

Explanation:

Residual risk depends partly on how effectively controls reduce the underlying exposure. If a control fails or is found ineffective, the organization may no longer be receiving the expected level of risk reduction. Reassessing the risk helps determine whether residual exposure has increased and whether additional remediation or treatment is needed. The risk itself is not automatically deleted, and a control failure does not invalidate the regulatory source.

Question 30.

What is one primary purpose of a policy acknowledgment or attestation process?

  1. To calculate inherent risk automatically
    2. To confirm that designated users have reviewed or acknowledged a policy
    3. To create new authority documents
    4. To replace control testing

Correct Answer: 2. To confirm that designated users have reviewed or acknowledged a policy

Explanation:

Policy acknowledgment or attestation provides evidence that required users have reviewed, understood, or formally acknowledged a policy according to organizational requirements. This can support governance, awareness, and audit evidence. It does not prove that every related control operates effectively, so it should not be viewed as a replacement for control testing. It also does not create authority documents or independently calculate risk exposure.

Question 31.

A company purchases insurance to reduce the financial consequences of a specific risk event. Which risk response does this most closely represent?

  1. Avoidance
    2. Acceptance
    3. Transfer
    4. Elimination

Correct Answer: 3. Transfer

Explanation:

Risk transfer shifts some financial or operational consequences of a risk to another party. Insurance is a common example because the organization pays a premium in exchange for coverage of certain losses. Transfer does not necessarily remove the underlying risk event itself, but it changes who bears part of the impact. Avoidance removes the activity, mitigation reduces the exposure, and acceptance means retaining the risk without additional treatment.

Question 32.

An organization discovers that several compliance requirements are satisfied by the same access-review control. What is the main benefit of maintaining these relationships?

  1. It prevents future assessments
    2. It eliminates all related risks
    3. It makes the policy unnecessary
    4. It reduces duplicate compliance effort and improves traceability**

Correct Answer: 4. It reduces duplicate compliance effort and improves traceability

Explanation:

When one control addresses several requirements, mapping those relationships helps the organization avoid creating separate controls for every overlapping obligation. This can reduce duplicate testing, evidence collection, and maintenance effort. It also provides traceability showing which regulatory or policy requirements depend on that control. If the control fails, the organization can identify all affected obligations more efficiently. The mapping does not eliminate the underlying risks or remove the need for policies.

Question 33.

A business unit repeatedly misses remediation due dates for compliance issues. Which capability is most important for improving accountability?

  1. Structured issue ownership, due dates, and status tracking
    2. More knowledge article categories
    3. A different application theme
    4. Fewer risk assessments

Correct Answer: 1. Structured issue ownership, due dates, and status tracking

Explanation:

Issues should be managed with clear ownership, target dates, remediation activities, and status visibility. This creates accountability and makes overdue corrective actions easier to identify and escalate. Reliable issue tracking also helps management understand whether compliance weaknesses are being resolved in a timely manner. Changing interface themes or reducing assessments would not address the underlying problem of missed remediation commitments.

Question 34.

Which statement best describes inherent risk?

  1. Exposure remaining after controls have been applied
    2. Exposure evaluated before considering controls or mitigation
    3. A risk that has already been accepted
    4. A risk that has been transferred to a third party

Correct Answer: 2. Exposure evaluated before considering controls or mitigation

Explanation:

Inherent risk represents the level of exposure that exists before the effect of controls or other treatments is considered. It helps establish a baseline for understanding the significance of the risk. Residual risk is then evaluated after controls are taken into account. Comparing inherent and residual risk allows an organization to understand how much reduction the control environment is expected to provide and whether the remaining exposure is acceptable.

Question 35.

An assessment asks a control owner to provide screenshots, reports, or other proof that a control was performed. What is being collected?

  1. Risk appetite
    2. Service catalog data
    3. Control evidence
    4. Application metadata

Correct Answer: 3. Control evidence

Explanation:

Control evidence provides support that a control was actually performed and can be evaluated during testing or assessment. Examples may include reports, screenshots, approvals, logs, reconciliations, or other documentation relevant to the control activity. Evidence helps assessors determine whether the control is operating as expected. Risk appetite is a governance concept describing acceptable exposure and is not the same as proof of control execution.

Question 36.

Why is maintaining accurate relationships between business entities and risks important?

  1. It automatically closes every issue
    2. It removes the need for risk owners
    3. It prevents all control failures
    4. It helps identify where exposure exists and supports entity-based reporting**

Correct Answer: 4. It helps identify where exposure exists and supports entity-based reporting

Explanation:

Associating risks with business entities provides organizational context. It helps management understand which business units, processes, applications, vendors, or other scoped objects are affected by particular risks. These relationships support assessments, reporting, prioritization, and ownership decisions. Accurate entity-risk relationships do not automatically close issues or prevent control failures, but they improve visibility into where risk exposure exists across the enterprise.

Question 37.

A control assessment shows that a control is effective and consistently performed. What does this generally indicate?

  1. The control is providing the expected mitigation or compliance support
    2. The related risk can always be deleted
    3. No future assessment is necessary
    4. All organizational risks are eliminated

Correct Answer: 1. The control is providing the expected mitigation or compliance support

Explanation:

An effective control is operating in a manner consistent with its intended design and is providing the expected support for risk reduction or compliance. This does not mean the related risk disappears or that future testing is unnecessary. Risks may still have residual exposure, and controls can become ineffective over time as processes, systems, or threats change. Periodic assessment remains important to confirm continued effectiveness.

Question 38.

A company decides that the cost of additional mitigation is greater than the benefit and formally approves the remaining exposure. Which response is being used?

  1. Avoidance
    2. Acceptance
    3. Transfer
    4. Elimination

Correct Answer: 2. Acceptance

Explanation:

Risk acceptance occurs when authorized decision-makers consciously choose to retain the remaining exposure. This may happen when residual risk is within tolerance or when the cost of further mitigation is disproportionate to the expected benefit. The decision should generally be documented and approved according to the organization’s governance process. Acceptance does not eliminate the risk; it confirms that the organization is willing to retain it under defined conditions.

Question 39.

What is the strongest reason to connect policies with related controls and compliance requirements?

  1. To change application permissions automatically
    2. To eliminate the need for regulatory monitoring
    3. To provide traceability between organizational expectations and how they are implemented
    4. To prevent control testing

Correct Answer: 3. To provide traceability between organizational expectations and how they are implemented

Explanation:

Connecting policies to controls and requirements creates a clear chain from external or internal obligations to organizational expectations and the safeguards used to enforce them. This traceability improves impact analysis, audit readiness, and governance reporting. If a requirement changes or a control fails, related policies can be identified more easily. These relationships do not remove the need for monitoring, assessments, or ongoing compliance management.

Question 40.

Which practice best supports an effective Risk and Compliance program over time?

  1. Review risks only after major incidents
    2. Keep policies and controls in disconnected documents
    3. Avoid documenting failed assessments
    4. Continuously maintain relationships among entities, risks, controls, requirements, policies, assessments, issues, and remediation**

Correct Answer: 4. Continuously maintain relationships among entities, risks, controls, requirements, policies, assessments, issues, and remediation

Explanation:

A mature Risk and Compliance program depends on connected and current information. Entities provide business context, risks describe exposure, controls provide mitigation, requirements and policies define obligations, assessments evaluate effectiveness, and issues track deficiencies and remediation. Maintaining these relationships improves traceability, reporting, accountability, and impact analysis. Disconnected records and incomplete assessment history make it harder to understand the organization’s true risk and compliance position or to respond effectively when conditions change.