View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps
Question 61.
An organization wants to compare the amount of risk before and after controls are applied. Which two measures should it compare?
- Inherent risk and residual risk
2. Accepted risk and transferred risk
3. Policy risk and control risk
4. Gross risk and knowledge risk
Correct Answer: 1. Inherent risk and residual risk
Explanation:
Inherent risk represents the exposure before controls or mitigation are considered, while residual risk represents the exposure that remains after those controls are taken into account. Comparing the two helps an organization understand the effect of its control environment and whether mitigation is working as expected. If residual risk remains too high, additional treatment may be necessary. Accepted or transferred risk describe treatment decisions rather than the basic before-and-after comparison of risk exposure.
Question 62.
A control exists and is documented correctly, but employees frequently skip the required activity. What should the organization evaluate?
- Authority document validity
2. Control operating effectiveness
3. Policy publication date
4. Business entity ownership
Correct Answer: 2. Control operating effectiveness
Explanation:
Operating effectiveness focuses on whether a control is actually being performed consistently and as intended. A control may be designed properly but still fail in practice if employees skip required steps or do not follow the procedure. Testing or assessment can provide evidence of how reliably the control operates. If the control is not functioning effectively, an issue may be created and remediation tracked. Design and operation should therefore be assessed as separate dimensions.
Question 63.
Which record is most appropriate for documenting a specific compliance obligation taken from a regulatory framework?
- Incident
2. Service Offering
3. Citation or requirement record
4. Change Task
Correct Answer: 3. Citation or requirement record
Explanation:
A citation or requirement record represents a specific obligation contained within a broader authority document such as a law, regulation, or standard. This structure allows the organization to connect external requirements to internal policies and controls. Those relationships improve compliance traceability and impact analysis. Incidents and change tasks are operational records and do not normally represent individual regulatory obligations.
Question 64.
A company decides to stop processing a certain type of transaction because the associated risk cannot be reduced to an acceptable level. Which response is being used?
- Mitigation
2. Acceptance
3. Transfer
4. Avoidance**
Correct Answer: 4. Avoidance
Explanation:
Risk avoidance removes the activity that creates the exposure. In this case, the company stops processing the transaction entirely because the risk cannot be reduced sufficiently. Mitigation would attempt to lower the risk through controls, transfer would shift some consequences to another party, and acceptance would retain the risk. Avoidance is the appropriate term when the organization eliminates the risky activity itself.
Question 65.
Why is assigning ownership to a risk important?
- It establishes accountability for monitoring and managing that risk
2. It automatically reduces the risk score
3. It replaces the need for controls
4. It prevents future assessments
Correct Answer: 1. It establishes accountability for monitoring and managing that risk
Explanation:
Risk ownership identifies the person or role accountable for understanding, reviewing, and managing a specific risk. The owner may evaluate assessment results, approve treatment decisions, monitor residual exposure, and ensure appropriate actions are taken when risk exceeds tolerance. Ownership improves accountability and governance. Assigning an owner does not automatically change the risk score or eliminate the need for controls and future assessments.
Question 66.
An assessor requests logs, screenshots, and approval records to verify that a control was performed. What is the assessor collecting?
- Risk tolerance
2. Control evidence
3. Policy metadata
4. Entity hierarchy
Correct Answer: 2. Control evidence
Explanation:
Control evidence provides objective support that a control was performed and operated as expected. Examples can include logs, screenshots, approval records, reports, reconciliations, and other documentation relevant to the control activity. Evidence strengthens control assessments and audit readiness by reducing reliance on unsupported statements. Risk tolerance and entity structures are important governance concepts, but they do not represent proof that a control was actually executed.
Question 67.
A control failure is discovered that affects several regulatory obligations. Which capability is most useful for identifying the broader compliance impact?
- User theme configuration
2. Password history
3. Relationship mapping among controls and requirements
4. Knowledge article ratings
Correct Answer: 3. Relationship mapping among controls and requirements
Explanation:
When one control supports several requirements, accurate relationship mapping allows the organization to identify all obligations affected by a control failure. This improves impact analysis, remediation prioritization, and compliance reporting. Without these relationships, teams may have to manually search for every dependent requirement. User-interface and password information do not provide the cross-record traceability needed to understand the broader impact of a failed control.
Question 68.
A risk owner formally agrees that the remaining exposure is acceptable and does not require additional treatment. Which response is being used?
- Avoidance
2. Mitigation
3. Transfer
4. Acceptance**
Correct Answer: 4. Acceptance
Explanation:
Risk acceptance occurs when authorized decision-makers determine that the remaining exposure is within tolerance or otherwise acceptable. The decision should generally be documented and approved according to governance requirements. Acceptance does not eliminate the risk; it means the organization consciously retains it. Mitigation reduces risk, transfer shifts some impact elsewhere, and avoidance removes the activity that creates the exposure.
Question 69.
Which two factors are commonly combined to evaluate risk severity?
- Likelihood and impact
2. Policy age and control owner tenure
3. Number of issues and knowledge articles
4. User count and application scope
Correct Answer: 1. Likelihood and impact
Explanation:
Likelihood estimates how probable a risk event is, while impact reflects the potential consequence if it occurs. These two dimensions are commonly combined to evaluate overall risk severity or exposure. Organizations may use qualitative scales, numeric values, or more sophisticated scoring models, but likelihood and impact remain common inputs. Policy age and knowledge counts are not standard measures of risk severity.
Question 70.
A control owner must confirm every six months that a required activity continues to be performed. Which mechanism is most appropriate?
- Service Catalog request
2. Attestation or assessment
3. Update set review
4. User role audit only
Correct Answer: 2. Attestation or assessment
Explanation:
An attestation or assessment can be used to periodically confirm that a control is still being performed and remains effective. The control owner may be asked to answer questions, certify statements, or provide supporting evidence. This creates a repeatable assurance process and helps identify controls that have stopped operating correctly. Service Catalog requests and update set reviews do not provide the same structured compliance verification.
Question 71.
A company purchases insurance against losses from a specific business risk. Which treatment strategy does this represent?
- Avoidance
2. Mitigation
3. Transfer
4. Acceptance
Correct Answer: 3. Transfer
Explanation:
Insurance is a common risk-transfer mechanism because some financial consequences of a risk event are shifted to another party. The underlying event may still occur, but the organization reduces the amount of loss it must bear directly. Transfer differs from mitigation, which reduces likelihood or impact through controls, and from avoidance, which eliminates the risky activity. Acceptance means retaining the exposure without additional treatment.
Question 72.
A control is mapped to five separate regulatory requirements. What is a major advantage of this design?
- The control never needs reassessment
2. The related risks are automatically closed
3. Policies are no longer necessary
4. One control can support multiple obligations and reduce duplicated compliance work**
Correct Answer: 4. One control can support multiple obligations and reduce duplicated compliance work
Explanation:
A single control may satisfy several overlapping regulatory or internal requirements. Mapping those relationships helps reduce duplicate controls, repeated testing, and redundant evidence collection. It also improves traceability and makes impact analysis easier if the control later fails. However, the control still requires ongoing assessment, and related risks and policies remain relevant. Mapping improves efficiency but does not remove governance responsibilities.
Question 73.
A remediation issue has remained overdue for several months. Which information is most important for accountability?
- Assigned owner, due date, status, and remediation actions
2. Application theme
3. Knowledge article count
4. Browser version
Correct Answer: 1. Assigned owner, due date, status, and remediation actions
Explanation:
Structured issue management should identify who owns the remediation, when it is due, what corrective actions are required, and the current status. This makes overdue items visible and supports escalation and accountability. Without clear ownership and target dates, deficiencies can remain unresolved. Interface themes, browser versions, and knowledge counts do not help manage remediation responsibilities or measure progress.
Question 74.
Which statement best describes residual risk?
- Risk before any controls exist
2. Risk remaining after controls and mitigation are considered
3. A risk that has not been assigned an owner
4. A risk that has been deleted
Correct Answer: 2. Risk remaining after controls and mitigation are considered
Explanation:
Residual risk is the remaining exposure after the organization considers the effect of existing controls and other treatments. It is often compared with risk appetite or tolerance to determine whether more action is necessary. Inherent risk represents exposure before controls. Understanding residual risk helps management decide whether to accept, further mitigate, transfer, or avoid the remaining exposure.
Question 75.
An assessment identifies that a control cannot achieve its intended objective even when employees perform it exactly as documented. What kind of issue is this?
- Policy acknowledgment issue
2. Entity ownership issue
3. Control design effectiveness issue
4. Application access issue
Correct Answer: 3. Control design effectiveness issue
Explanation:
Design effectiveness considers whether a control is capable of addressing the intended risk or compliance requirement when performed as designed. If the control cannot achieve its objective even when executed correctly, the problem lies in its design rather than in day-to-day operation. The organization should redesign or replace the control and track the deficiency through remediation. Operating effectiveness becomes relevant when a properly designed control is not performed consistently.
Question 76.
Why is linking risks to business entities valuable for enterprise reporting?
- It guarantees that no control will fail
2. It eliminates risk ownership
3. It prevents assessment requests
4. It shows which organizational areas are exposed to specific risks**
Correct Answer: 4. It shows which organizational areas are exposed to specific risks
Explanation:
Associating risks with business entities provides context about where exposure exists across the organization. Entities may represent business units, applications, processes, vendors, or other scoped objects. These relationships support reporting, prioritization, assessments, and ownership decisions. They can also help management compare exposure across different areas. Entity relationships do not eliminate control failures or replace the need for accountable risk ownership.
Question 77.
An organization implements stronger approval requirements to lower the probability of unauthorized transactions. Which risk response is this?
- Mitigation
2. Transfer
3. Acceptance
4. Avoidance
Correct Answer: 1. Mitigation
Explanation:
Mitigation involves implementing controls or actions intended to reduce the likelihood or impact of a risk. Stronger approval requirements are designed to make unauthorized transactions less likely and therefore reduce exposure. The organization continues the activity but adds safeguards. Transfer shifts some consequences to another party, avoidance stops the risky activity, and acceptance retains the risk without further treatment.
Question 78.
A company wants proof that employees have reviewed a newly published policy. Which mechanism is most appropriate?
- Risk assessment
2. Policy acknowledgment or attestation
3. Control retirement
4. Authority document import
Correct Answer: 2. Policy acknowledgment or attestation
Explanation:
Policy acknowledgments or attestations can provide evidence that designated employees have reviewed or formally acknowledged a policy. This supports governance, awareness, and auditability. It does not prove that every related control is operating effectively, so control assessments remain necessary. Risk assessments and authority document imports serve different purposes and do not specifically demonstrate employee acknowledgment of policy content.
Question 79.
A manager wants to understand the full impact of changing a compliance requirement. What information is most valuable?
- User-interface preferences
2. Password reset history
3. Connected relationships among requirements, policies, controls, and risks
4. Browser support data
Correct Answer: 3. Connected relationships among requirements, policies, controls, and risks
Explanation:
Connected relationships allow the organization to see which policies interpret a requirement, which controls address it, and which risks may be affected by a change. This supports efficient impact analysis and reduces the likelihood that dependent records are overlooked. Without these relationships, teams may need to perform manual reviews across disconnected documents. Interface preferences and browser data do not provide meaningful compliance dependency information.
Question 80.
Which practice best supports reliable governance, risk, and compliance reporting?
- Use only email to track control failures
2. Avoid maintaining relationships among records
3. Record issues without owners or due dates
4. Keep entity, risk, control, policy, requirement, assessment, evidence, issue, and remediation data accurate and connected**
Correct Answer: 4. Keep entity, risk, control, policy, requirement, assessment, evidence, issue, and remediation data accurate and connected
Explanation:
Reliable reporting depends on complete, accurate, and connected data. Entities provide business context, risks represent exposure, controls provide mitigation, policies and requirements define expectations, assessments and evidence support assurance, and issues track remediation. Maintaining clear relationships among these records makes reporting, impact analysis, and audit preparation more effective. Disconnected data or informal issue tracking makes it difficult to determine the organization’s true compliance and risk position.