ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part20 Q381-400

View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps

 

Question 381.

An organization wants to define a measurable warning point for a key risk indicator. What should it configure conceptually?

  1. A threshold
    2. A policy exception
    3. A control objective
    4. A remediation task

Correct Answer: 1. A threshold

Explanation:

A threshold defines a level at which a risk indicator should trigger attention, investigation, escalation, or another governance response. Thresholds help translate indicator values into actionable monitoring. They are particularly useful when combined with trends because management can see both whether a limit has been crossed and whether conditions are moving toward that limit. A policy exception documents a deviation, while control objectives and remediation tasks serve different purposes.

Question 382.

A key risk indicator has not breached its threshold, but its value is worsening every month. What is the best response?

  1. Wait until the threshold is exceeded
    2. Review the trend and investigate the underlying risk condition
    3. Close the related risk
    4. Retire the associated controls

Correct Answer: 2. Review the trend and investigate the underlying risk condition

Explanation:

A deteriorating trend can provide early warning even before a formal threshold is crossed. Reviewing the trend allows management to investigate whether the risk environment, control performance, or business conditions are changing. This may lead to additional monitoring, treatment, or reassessment. Waiting until the limit is breached can delay action. The trend does not automatically prove that the risk has increased, but it provides meaningful information for proactive risk management.

Question 383.

A business unit exceeds a specific acceptable exposure limit that was derived from the organization’s broader risk appetite. What has most directly been exceeded?

  1. Risk register
    2. Control frequency
    3. Risk tolerance
    4. Policy lifecycle

Correct Answer: 3. Risk tolerance

Explanation:

Risk tolerance expresses a more specific acceptable boundary or variation for a particular risk, metric, or activity. It is often derived from the organization’s broader risk appetite. When actual exposure exceeds tolerance, the situation may require escalation, additional treatment, or formal approval. Risk appetite provides broader strategic guidance, while tolerance establishes more operationally specific limits that can be monitored and acted upon.

Question 384.

Which control type is designed primarily to identify an undesirable event after or while it occurs?

  1. Preventive control
    2. Compensating control
    3. Corrective control
    4. Detective control**

Correct Answer: 4. Detective control

Explanation:

Detective controls identify errors, exceptions, or undesirable events after or while they occur. Examples can include reconciliations, log reviews, exception reports, and transaction monitoring. Preventive controls attempt to stop events before they happen, while corrective controls help address consequences afterward. Compensating controls provide alternative protection when a preferred control cannot be implemented.

Question 385.

A required control cannot be implemented because of a legacy-system limitation. What should the organization consider?

  1. Implementing an appropriate compensating control
    2. Deleting the requirement
    3. Marking the control effective without evidence
    4. Ignoring the related risk

Correct Answer: 1. Implementing an appropriate compensating control

Explanation:

A compensating control is an alternative safeguard used when the preferred control cannot be implemented. The organization should document why the original control is unavailable, how the alternative addresses the intended objective, and who approved the approach. The compensating control should be tested and monitored like other controls. Simply ignoring the requirement or marking the original control effective would produce inaccurate compliance and risk information.

Question 386.

A monthly control has only evidence from nine months ago. What is the primary assessment concern?

  1. The policy has too many versions
    2. The evidence may not demonstrate current operating effectiveness
    3. The risk taxonomy is incorrect
    4. The business entity should be retired

Correct Answer: 2. The evidence may not demonstrate current operating effectiveness

Explanation:

Evidence should be relevant to the assessment period and sufficiently current to support conclusions about control performance. Nine-month-old evidence may show that a monthly control operated historically, but it does not establish that the activity continues to occur. Evidence freshness is therefore an important consideration when evaluating recurring controls. Additional current evidence may be needed before the assessor can conclude that the control remains effective.

Question 387.

A control failed, corrective action was completed, and the issue owner wants to close the deficiency. What should occur first?

  1. Delete the previous failed assessment
    2. Automatically lower the related risk score
    3. Re-test or reassess the remediated control
    4. Remove the control owner

Correct Answer: 3. Re-test or reassess the remediated control

Explanation:

Re-testing helps verify that remediation actually corrected the original deficiency. Without this verification, closing the issue could leave an ineffective control in place. The original assessment should usually remain available as part of the historical record. Successful re-testing, along with appropriate closure evidence, provides a stronger basis for determining that corrective actions were effective and the issue can be resolved.

Question 388.

Why is a consistent risk assessment methodology valuable across multiple subsidiaries?

  1. It guarantees identical risk scores
    2. It removes the need for entity-specific context
    3. It eliminates risk ownership
    4. It improves comparability and aggregation of risk results**

Correct Answer: 4. It improves comparability and aggregation of risk results

Explanation:

A consistent methodology applies common definitions, scales, and criteria across entities. This makes it easier to compare similar exposures, aggregate enterprise risk information, and prioritize treatment. Different subsidiaries may still receive different scores because their actual conditions and controls differ. Consistency improves interpretability without removing the need for local context, ownership, or professional judgment.

Question 389.

Which concept provides a structured classification of risks into categories and subcategories?

  1. Risk taxonomy
    2. Policy acknowledgment
    3. Control evidence
    4. Issue aging

Correct Answer: 1. Risk taxonomy

Explanation:

A risk taxonomy organizes risks into defined categories and subcategories such as strategic, operational, technology, compliance, or financial. Using a common taxonomy improves reporting, aggregation, communication, and consistency across the organization. It helps management understand concentrations of exposure and compare similar risks. A taxonomy does not determine the actual risk score; it provides structure for classification and analysis.

Question 390.

A company wants to prevent unauthorized transactions before they are processed. Which control type is most appropriate?

  1. Detective control
    2. Preventive control
    3. Corrective control
    4. Risk acceptance

Correct Answer: 2. Preventive control

Explanation:

Preventive controls are designed to stop undesirable events before they occur. Examples include approval workflows, access restrictions, segregation of duties, and automated validation rules. Detective controls identify events after or while they occur, while corrective controls help address consequences afterward. Risk acceptance is not a control type; it is a decision to retain exposure.

Question 391.

A policy has reached the end of its review cycle. What should happen next?

  1. It should automatically remain active forever
    2. All related controls should be deleted
    3. The policy should be reviewed and either reaffirmed, revised, or retired
    4. The policy should be converted into an issue

Correct Answer: 3. The policy should be reviewed and either reaffirmed, revised, or retired

Explanation:

Periodic policy review helps ensure that policies remain aligned with current regulations, business processes, organizational responsibilities, and control expectations. At the end of a review cycle, the policy should be evaluated and then reaffirmed, updated, or retired as appropriate. This supports an effective policy lifecycle and reduces the risk that obsolete guidance remains in force.

Question 392.

A temporary policy exception has been approved. Which information is most important to record?

  1. Browser type
    2. Knowledge article count
    3. User-interface preferences
    4. Rationale, approver, scope, expiration date, and compensating safeguards**

Correct Answer: 4. Rationale, approver, scope, expiration date, and compensating safeguards

Explanation:

A well-governed policy exception should clearly document why the exception is needed, who approved it, what it covers, how long it remains valid, and what alternative safeguards are in place. This prevents temporary deviations from becoming uncontrolled permanent practices. The exception should also be reviewed before expiration and either closed, renewed, or replaced with a more permanent solution.

Question 393.

A major acquisition changes systems, processes, and business responsibilities. What should happen to affected risks?

  1. They should be reassessed because the exposure environment has materially changed
    2. They should automatically be accepted
    3. They should all be closed
    4. Their control relationships should be removed

Correct Answer: 1. They should be reassessed because the exposure environment has materially changed

Explanation:

Material business changes can alter likelihood, impact, ownership, control effectiveness, and treatment assumptions. An acquisition may introduce new systems, processes, vendors, regulations, or organizational dependencies. Reassessing affected risks helps ensure that current ratings reflect actual conditions. Existing control mappings and treatment plans may also need review so the combined organization maintains an accurate risk profile.

Question 394.

An organization uses automated feeds to monitor key risk indicators every day. What is the main advantage?

  1. It eliminates human oversight
    2. It provides more timely visibility into changing risk conditions
    3. It guarantees risks remain within tolerance
    4. It permanently replaces formal assessments

Correct Answer: 2. It provides more timely visibility into changing risk conditions

Explanation:

Automated monitoring can detect threshold breaches, anomalies, or deteriorating trends more quickly than periodic manual reviews alone. This allows management to investigate and respond to changing conditions sooner. Human judgment remains important for interpreting results and deciding what action to take. Continuous monitoring improves timeliness, but it does not guarantee compliance, eliminate risk, or completely replace formal assessments.

Question 395.

An assessor cannot obtain required evidence for a control. What should happen?

  1. Assume the control is effective
    2. Close the assessment without comment
    3. Document the evidence gap and evaluate its effect on the conclusion
    4. Delete the control

Correct Answer: 3. Document the evidence gap and evaluate its effect on the conclusion

Explanation:

Missing evidence can limit the assessor’s ability to support a conclusion about control effectiveness. The gap should be documented and evaluated according to the assessment methodology. Additional evidence may be requested, or the missing support may contribute to a deficiency or an unfavorable result. Assuming effectiveness without objective support would weaken assurance and could produce misleading compliance reporting.

Question 396.

Why should control owners and independent control testers be different when practical?

  1. To eliminate the need for controls
    2. To ensure every assessment passes
    3. To avoid collecting evidence
    4. To improve objectivity in evaluating control effectiveness**

Correct Answer: 4. To improve objectivity in evaluating control effectiveness

Explanation:

Separating control operation from independent testing can reduce conflicts of interest and strengthen assurance. The control owner remains accountable for operating and maintaining the control, while the tester evaluates its design, operation, and supporting evidence. Independence does not guarantee a passing result, but it can improve confidence that the assessment reflects actual control performance rather than the owner’s unsupported judgment.

Question 397.

A risk treatment plan includes several actions. Why should each action have a clear owner and due date?

  1. To make treatment execution measurable and accountable
    2. To automatically remove the risk from the register
    3. To eliminate the need for residual risk assessment
    4. To replace all controls

Correct Answer: 1. To make treatment execution measurable and accountable

Explanation:

Owners and due dates convert treatment decisions into trackable work. Ownership establishes responsibility, while deadlines make progress measurable and support escalation when actions become overdue. Treatment actions may involve implementing controls, modifying processes, transferring exposure, or completing other mitigation work. The related risk should remain monitored until treatment is complete and the resulting residual exposure is understood.

Question 398.

An organization wants to apply the same compliance requirement across several subsidiaries while preserving local differences. What approach is most useful?

  1. Remove all entity information
    2. Use entity-based scoping for assessments and controls
    3. Create unrelated frameworks for every subsidiary
    4. Eliminate all shared controls

Correct Answer: 2. Use entity-based scoping for assessments and controls

Explanation:

Entity-based scoping allows common requirements to be evaluated in the context of each subsidiary, application, process, or business area. This makes it possible to identify localized control weaknesses while still maintaining enterprise consistency. Shared controls can be reused where appropriate, and entity-specific evidence can show how performance differs across the organization. Removing entity context would make reporting less meaningful.

Question 399.

A risk register contains several risks whose owners have left the organization. What should management do?

  1. Leave the ownership fields unchanged for historical consistency
    2. Delete the affected risks
    3. Assign appropriate current owners and review the risks for accuracy
    4. Automatically accept the risks

Correct Answer: 3. Assign appropriate current owners and review the risks for accuracy

Explanation:

Risk ownership should reflect current accountability. When owners leave or change roles, affected risks should be reassigned to appropriate stakeholders and reviewed to ensure ratings, controls, treatments, and status remain accurate. Leaving obsolete ownership in place can weaken governance and delay action. Reassignment does not require deleting or accepting the risk; it ensures that someone remains accountable for monitoring and managing it.

Question 400.

What is the strongest foundation for a scalable ServiceNow Risk and Compliance implementation?

  1. Extensive customization before defining requirements
    2. Separate spreadsheets for each business unit
    3. Automatic closure of all overdue items
    4. Clear governance, consistent methodologies, defined ownership, reliable data, and connected records**

Correct Answer: 4. Clear governance, consistent methodologies, defined ownership, reliable data, and connected records

Explanation:

A scalable Risk and Compliance implementation depends on more than technology. Organizations need clear governance, consistent risk and control methodologies, defined accountability, strong data standards, and reliable relationships among entities, risks, controls, policies, requirements, assessments, evidence, and issues. Automation and reporting become much more effective when these foundations are established first. Excessive customization or fragmented spreadsheets usually make long-term governance and scalability more difficult.