View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps
Question 121.
An organization wants to understand which controls are responsible for reducing a specific business risk. Which relationship is most important?
- Risk linked to relevant controls
2. Policy linked to browser settings
3. Issue linked to UI preferences
4. Knowledge article linked to an update set
Correct Answer: 1. Risk linked to relevant controls
Explanation:
Linking risks to the controls that mitigate them provides visibility into how the organization manages exposure. This relationship helps explain why residual risk may be lower than inherent risk and supports impact analysis when a control fails. It also helps risk owners understand which safeguards are critical to their risk profile. Browser settings, UI preferences, and update sets do not provide meaningful risk mitigation context.
Question 122.
A control is capable of addressing its intended risk, but the required review was skipped during several months. What is the primary weakness?
- Authority document design
2. Operating effectiveness
3. Policy scope
4. Entity classification
Correct Answer: 2. Operating effectiveness
Explanation:
The control appears to be designed appropriately because it can address the intended risk when performed correctly. The problem is that employees are not executing it consistently. This is an operating effectiveness issue. Control assessments and supporting evidence can help determine how often the control was missed and whether remediation is required. Design effectiveness would be the concern if the control could not achieve its objective even when performed correctly.
Question 123.
An organization identifies a requirement in a new industry standard. Which record structure best supports tracking the requirement and mapping it to controls?
- Incident with related tasks
2. Problem record
3. Authority document with related citation or requirement
4. Service Catalog item
Correct Answer: 3. Authority document with related citation or requirement
Explanation:
An authority document can represent the overall industry standard, while individual citations or requirement records represent specific obligations contained in that standard. These requirements can then be related to internal policies and controls. This provides traceability and makes it easier to understand the impact of regulatory changes. Incidents and catalog items support operational processes rather than structured compliance obligation management.
Question 124.
A company permanently stops using a high-risk process instead of trying to control it. Which risk response is this?
- Acceptance
2. Transfer
3. Mitigation
4. Avoidance**
Correct Answer: 4. Avoidance
Explanation:
Risk avoidance eliminates the activity that creates the exposure. If the organization stops using the process entirely, it removes the source of the risk instead of reducing or transferring it. Mitigation would add safeguards to lower the risk, transfer would shift part of the impact to another party, and acceptance would retain the exposure. Avoidance is generally used when the organization decides the activity is not worth the associated risk.
Question 125.
What is the main purpose of a risk owner?
- To provide accountability for monitoring and managing the risk
2. To perform every related control personally
3. To publish all compliance policies
4. To eliminate all residual risk
Correct Answer: 1. To provide accountability for monitoring and managing the risk
Explanation:
A risk owner is accountable for understanding and overseeing a specific risk. Responsibilities may include reviewing assessments, monitoring residual exposure, evaluating treatment options, and ensuring that appropriate actions occur when the risk exceeds tolerance. The risk owner does not necessarily perform every related control. Clear ownership creates governance accountability and helps ensure that significant exposures receive appropriate attention.
Question 126.
An assessor reviews system logs and signed approvals to determine whether a control operated during the testing period. What are these materials?
- Risk appetite
2. Control evidence
3. Entity criteria
4. Policy metadata
Correct Answer: 2. Control evidence
Explanation:
Control evidence supports the assessor’s conclusion about whether a control was actually performed. Examples can include logs, reports, screenshots, signed approvals, reconciliations, or other records demonstrating execution. Evidence provides stronger assurance than verbal statements alone. It can also support audits and future reviews. Risk appetite and policy metadata serve different governance purposes and do not prove that a specific control activity occurred.
Question 127.
A failed control creates a compliance gap that needs corrective action, an owner, and a target completion date. Which record should be created?
- Knowledge Article
2. Service Request
3. Issue
4. Change Template
Correct Answer: 3. Issue
Explanation:
An issue is used to document and manage a deficiency through remediation. It can include ownership, due dates, corrective actions, status, and supporting information. This creates accountability and makes it possible to monitor progress until the problem is resolved. A knowledge article or service request does not provide the same structured governance and remediation lifecycle needed for control and compliance deficiencies.
Question 128.
A company enters a contract that shifts part of a business risk to another organization. Which risk response is being used?
- Mitigation
2. Acceptance
3. Avoidance
4. Transfer**
Correct Answer: 4. Transfer
Explanation:
Risk transfer shifts some of the consequences or responsibilities associated with a risk to another party. Contracts, outsourcing arrangements, and insurance can all be examples depending on the circumstances. The risk itself may still exist, but responsibility for part of the impact changes. Mitigation reduces exposure through safeguards, avoidance eliminates the activity, and acceptance means retaining the remaining risk.
Question 129.
Which value represents risk exposure before existing controls are considered?
- Inherent risk
2. Residual risk
3. Accepted risk
4. Transferred risk
Correct Answer: 1. Inherent risk
Explanation:
Inherent risk describes the level of exposure before controls or mitigation measures are taken into account. It provides a baseline for understanding how serious the underlying risk is. Residual risk represents the amount remaining after controls are considered. Comparing inherent and residual risk helps management understand how effective the control environment is at reducing exposure.
Question 130.
A control owner is required to certify every quarter that a control continues to operate. Which process best supports this requirement?
- Change approval
2. Attestation or assessment
3. Service request
4. Knowledge feedback
Correct Answer: 2. Attestation or assessment
Explanation:
An attestation or assessment provides a structured way to obtain periodic confirmation that a control continues to operate. The control owner may answer questions, certify statements, or provide evidence supporting the control’s performance. This helps identify controls that have stopped functioning or changed over time. Change approvals and service requests support different operational processes and are not intended for recurring control assurance.
Question 131.
A company adds transaction monitoring to lower the chance that fraudulent activity will go undetected. Which treatment is being used?
- Avoidance
2. Transfer
3. Mitigation
4. Acceptance
Correct Answer: 3. Mitigation
Explanation:
Mitigation involves introducing controls intended to reduce the likelihood or impact of a risk. Transaction monitoring can detect suspicious activity and reduce the chance or consequences of fraud. The organization continues the business activity but strengthens its safeguards. Transfer shifts some exposure elsewhere, avoidance stops the activity, and acceptance retains the risk without additional treatment.
Question 132.
One control supports requirements from several standards. What is the primary compliance benefit of mapping those relationships?
- The control never needs reassessment
2. All risks become low automatically
3. Policies can be deleted
4. Evidence and testing can be reused across multiple obligations**
Correct Answer: 4. Evidence and testing can be reused across multiple obligations
Explanation:
When a shared control addresses several requirements, accurate mapping can reduce duplicate compliance work. Testing results and evidence collected for that control may support several frameworks, improving efficiency and traceability. The mappings also help identify which obligations may be affected if the control fails. Shared control mapping does not eliminate the need for future testing or automatically change risk levels.
Question 133.
An updated policy must be reviewed by all employees in a specific department. Which process can provide evidence that the review occurred?
- Policy acknowledgment or attestation
2. Risk transfer
3. Control retirement
4. Authority document deletion
Correct Answer: 1. Policy acknowledgment or attestation
Explanation:
Policy acknowledgment or attestation provides documented evidence that designated users reviewed or formally acknowledged a policy. This supports governance, awareness, and audit readiness. It is particularly useful for demonstrating distribution of important policies to defined populations. Policy acknowledgment does not replace control testing or risk assessments, but it provides evidence that employees received the required policy information.
Question 134.
A control is performed exactly as documented but still fails to reduce the associated risk meaningfully. What should be evaluated?
- Operating effectiveness
2. Design effectiveness
3. Risk owner tenure
4. Evidence format
Correct Answer: 2. Design effectiveness
Explanation:
Design effectiveness evaluates whether the control is capable of achieving its intended objective. If a control is consistently performed yet still does not adequately reduce the risk, the design itself may be insufficient. The organization may need to redesign or replace the control. Operating effectiveness would be the focus if the control design were adequate but employees were not performing it consistently.
Question 135.
A risk owner reviews the remaining exposure and formally determines that it is within tolerance. Which treatment decision applies?
- Avoidance
2. Transfer
3. Acceptance
4. Mitigation
Correct Answer: 3. Acceptance
Explanation:
Risk acceptance means authorized stakeholders consciously choose to retain the residual exposure because it is considered tolerable. The acceptance decision should usually be documented and approved according to the organization’s governance process. Acceptance does not eliminate the risk; it confirms that further treatment is not currently required. The risk may still need monitoring and periodic reassessment.
Question 136.
A regulator changes a requirement. Which capability is most important for identifying the internal impact quickly?
- UI personalization
2. Password history
3. Browser compatibility
4. Relationship mapping among requirements, policies, controls, and risks**
Correct Answer: 4. Relationship mapping among requirements, policies, controls, and risks
Explanation:
Accurate relationships allow the organization to see which policies interpret the changed requirement, which controls address it, and which risks or entities may be affected. This significantly improves regulatory change impact analysis. Without connected records, teams may need to search manually through many documents. UI and browser information provide no meaningful insight into compliance dependencies.
Question 137.
Why should a remediation issue have a clearly assigned owner?
- To establish responsibility for correcting the deficiency
2. To eliminate inherent risk automatically
3. To replace the control owner
4. To prevent future assessments
Correct Answer: 1. To establish responsibility for correcting the deficiency
Explanation:
Assigning an owner makes it clear who is responsible for progressing the remediation and meeting target dates. Ownership, due dates, status, and corrective actions provide the foundation for accountable issue management. Without a responsible owner, identified deficiencies may remain unresolved. Issue ownership does not automatically reduce risk or remove the need for future control testing.
Question 138.
A shared control fails and management wants to know which frameworks could be affected. What should they review?
- User login records
2. Mappings between the control and compliance requirements
3. Application themes
4. Policy acknowledgment history only
Correct Answer: 2. Mappings between the control and compliance requirements
Explanation:
Control-to-requirement mappings show which regulatory, standards-based, or internal obligations depend on the control. When the control fails, these relationships allow management to identify the broader compliance impact quickly. This supports issue prioritization, reporting, and remediation planning. User login information and application themes do not provide the necessary compliance dependency information.
Question 139.
A control assessment fails and the control was expected to significantly reduce a high risk. What should the organization consider doing?
- Delete the assessment
2. Ignore the result until the next cycle
3. Reassess the related risk and track remediation
4. Remove the authority document
Correct Answer: 3. Reassess the related risk and track remediation
Explanation:
If an important control fails, the organization may no longer be receiving the expected level of mitigation. Residual risk could therefore be higher than previously assessed. The deficiency should be documented, remediation should be tracked, and the related risk should be reviewed to determine whether its current rating remains accurate. Ignoring or deleting the result would hide meaningful exposure rather than address it.
Question 140.
Which practice best supports reliable enterprise Risk and Compliance reporting?
- Keep findings only in email
2. Maintain policies independently with no control mappings
3. Avoid recording remediation status
4. Maintain accurate connected data for entities, risks, controls, requirements, policies, assessments, evidence, issues, and remediation**
Correct Answer: 4. Maintain accurate connected data for entities, risks, controls, requirements, policies, assessments, evidence, issues, and remediation
Explanation:
Reliable reporting depends on complete, current, and connected information. Entities provide business context, risks represent exposure, controls provide mitigation, policies and requirements define obligations, assessments and evidence support assurance, and issues track remediation. Maintaining these relationships enables stronger reporting, audit readiness, accountability, and impact analysis. Disconnected or incomplete records make it difficult to understand the organization’s true risk and compliance position.