ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part9 Q161-180

View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps

 

Question 161.

An organization wants to determine whether a control is capable of addressing its intended risk before reviewing how consistently it is performed. What should be evaluated first?

  1. Operating effectiveness
    2. Policy acknowledgment
    3. Design effectiveness
    4. Risk acceptance

Correct Answer: 3. Design effectiveness

Explanation:

Design effectiveness evaluates whether a control is appropriately constructed to achieve its intended objective. Before examining whether employees perform the control consistently, the organization should determine whether the control could actually reduce the associated risk or satisfy the relevant requirement when executed as designed. Operating effectiveness addresses how reliably the control is performed in practice. A poorly designed control cannot become effective simply by being performed more frequently, so design should be evaluated independently.

Question 162.

A company wants to understand the risk level that exists after all current controls are taken into account. Which measure should it review?

  1. Residual risk
    2. Inherent risk
    3. Authority risk
    4. Policy risk

Correct Answer: 1. Residual risk

Explanation:

Residual risk represents the amount of exposure remaining after existing controls and other mitigation measures are considered. Inherent risk represents the exposure before those controls are applied. Organizations often compare residual risk with risk tolerance or appetite to determine whether further action is required. If the remaining exposure is too high, management may choose additional mitigation, transfer, avoidance, or another treatment response.

Question 163.

A compliance team wants to identify all controls that support a particular regulatory requirement. Which information is most important?

  1. User-role assignments
    2. Control-to-requirement mappings
    3. Browser versions
    4. Knowledge article ratings

Correct Answer: 2. Control-to-requirement mappings

Explanation:

Control-to-requirement mappings provide traceability between compliance obligations and the internal safeguards that address them. These relationships help auditors and compliance teams identify which controls support a specific requirement and determine the impact if one of those controls changes or fails. Mapping also reduces duplication when one control supports several frameworks. User-role assignments and browser information do not provide this compliance relationship.

Question 164.

A business unit chooses to discontinue a product because the associated legal risk is considered unacceptable. Which risk treatment is being used?

  1. Mitigation
    2. Transfer
    3. Acceptance
    4. Avoidance**

Correct Answer: 4. Avoidance

Explanation:

Risk avoidance occurs when an organization eliminates the activity that creates the exposure. By discontinuing the product, the business removes the source of the identified legal risk rather than attempting to reduce or transfer it. Mitigation would involve implementing additional safeguards, transfer would shift part of the consequences to another party, and acceptance would mean consciously retaining the remaining exposure.

Question 165.

A control assessment identifies a failure that requires corrective action. Which record should be used to manage ownership, due dates, and remediation progress?

  1. Issue
    2. Knowledge Article
    3. Service Offering
    4. Catalog Item

Correct Answer: 1. Issue

Explanation:

An issue provides a structured way to manage deficiencies identified through assessments or other compliance activities. It can include an assigned owner, target date, remediation plan, status, and supporting information. This helps ensure that control weaknesses are tracked through resolution rather than forgotten after discovery. Knowledge articles and catalog items serve other platform purposes and do not provide the same remediation lifecycle.

Question 166.

An assessor asks for approval logs and reports showing that a monthly control was performed. What is the assessor requesting?

  1. Risk appetite information
    2. Control evidence
    3. Entity hierarchy
    4. Policy scope

Correct Answer: 2. Control evidence

Explanation:

Control evidence provides objective support that a control was performed and can be used to evaluate its effectiveness. Approval logs, reports, screenshots, reconciliations, and similar records can demonstrate whether the control operated during the required period. Evidence strengthens assessment conclusions and improves audit readiness. Risk appetite and policy scope are governance information but do not prove that the specific control activity occurred.

Question 167.

A company adds an automated approval check to reduce unauthorized financial transactions. Which risk response does this represent?

  1. Avoidance
    2. Acceptance
    3. Mitigation
    4. Transfer

Correct Answer: 3. Mitigation

Explanation:

Mitigation involves implementing safeguards that reduce the likelihood or impact of a risk. An automated approval check makes unauthorized transactions less likely and therefore reduces exposure while allowing the underlying business process to continue. Avoidance would stop the activity entirely, transfer would shift some consequences elsewhere, and acceptance would retain the exposure without introducing additional treatment.

Question 168.

An organization purchases insurance to reduce the financial consequences of a potential loss. Which risk treatment is this?

  1. Mitigation
    2. Avoidance
    3. Acceptance
    4. Transfer**

Correct Answer: 4. Transfer

Explanation:

Insurance is a common example of risk transfer because it shifts part of the financial consequences of a risk event to another party. The underlying risk may still occur, but the organization reduces the portion of the loss it would bear directly. Mitigation reduces exposure through controls, avoidance eliminates the risky activity, and acceptance means retaining the exposure.

Question 169.

Why is it useful to associate risks with business entities?

  1. It shows where exposure exists within the organization
    2. It eliminates the need for risk owners
    3. It automatically closes issues
    4. It prevents control failures

Correct Answer: 1. It shows where exposure exists within the organization

Explanation:

Associating risks with business entities provides context about which business unit, application, process, vendor, or other scoped object is affected. This supports entity-based reporting, prioritization, assessments, and ownership. Management can also compare risk exposure across different organizational areas. The relationship does not eliminate the need for controls or ownership, but it improves visibility into where risks are concentrated.

Question 170.

A control owner must certify annually that a control remains in place and continues to operate. Which mechanism best supports this requirement?

  1. Change Request
    2. Attestation or assessment
    3. Catalog Request
    4. Incident

Correct Answer: 2. Attestation or assessment

Explanation:

An attestation or assessment can be used to obtain periodic confirmation that a control remains in place and is still operating. The owner may answer structured questions, certify statements, or provide supporting evidence. This creates a repeatable assurance process and helps identify changes in control performance over time. Incident and catalog processes are designed for different operational purposes.

Question 171.

A regulation contains many individual obligations. Which record commonly represents one specific obligation within that regulation?

  1. Risk
    2. Control
    3. Citation or requirement record
    4. Issue

Correct Answer: 3. Citation or requirement record

Explanation:

An authority document can represent a broader regulation, law, standard, or framework, while citation or requirement records represent the individual obligations contained within it. Those specific requirements can then be mapped to policies and controls. This structure improves compliance traceability and allows organizations to understand exactly how each obligation is addressed internally.

Question 172.

A risk owner formally approves the decision to retain residual exposure because it is within the organization’s tolerance. Which response applies?

  1. Mitigation
    2. Avoidance
    3. Transfer
    4. Acceptance**

Correct Answer: 4. Acceptance

Explanation:

Risk acceptance means that authorized stakeholders consciously decide to retain the remaining exposure because it is considered tolerable or because additional treatment is not justified. The decision should generally be documented and approved according to governance requirements. Acceptance does not eliminate the risk; it confirms that the organization knowingly retains it under defined conditions.

Question 173.

A shared control supports requirements from several regulatory frameworks. What is one major advantage of this arrangement?

  1. It can reduce duplicate evidence collection and testing
    2. It eliminates the need for policies
    3. It permanently guarantees compliance
    4. It prevents control failures

Correct Answer: 1. It can reduce duplicate evidence collection and testing

Explanation:

When one control supports multiple requirements, organizations can often reuse the same control evidence and testing results across several frameworks. This reduces duplicated effort and improves compliance efficiency. Accurate mappings also make impact analysis easier if the control fails. Shared controls do not guarantee permanent compliance and still require periodic assessment and maintenance.

Question 174.

A control works as designed, but employees fail to perform it regularly. Which aspect needs improvement?

  1. Design effectiveness
    2. Operating effectiveness
    3. Authority document mapping
    4. Risk appetite

Correct Answer: 2. Operating effectiveness

Explanation:

Operating effectiveness addresses whether a control is consistently performed in actual practice. A properly designed control may still be ineffective if employees skip it, perform it incorrectly, or fail to retain required evidence. Assessment and testing can identify these execution problems. Design effectiveness would be the concern if the control itself were incapable of meeting its objective even when performed correctly.

Question 175.

A compliance manager wants to determine what internal policies and controls might be affected by a change to an external requirement. Which capability is most important?

  1. Password history
    2. Application themes
    3. Relationship mapping and impact analysis
    4. Knowledge article ratings

Correct Answer: 3. Relationship mapping and impact analysis

Explanation:

Connected relationships among authority requirements, policies, controls, risks, and entities allow compliance teams to identify internal dependencies quickly when an external obligation changes. This significantly improves regulatory change analysis and reduces the need for manual searching across disconnected documents. Password history and application themes do not provide information about compliance dependencies.

Question 176.

A remediation item has passed its due date and management wants to know who is responsible. Which information is most important?

  1. Policy version
    2. Evidence type
    3. Risk score
    4. Issue owner and target date**

Correct Answer: 4. Issue owner and target date

Explanation:

An issue owner identifies who is responsible for completing remediation, while the target date establishes when corrective action should be completed. These fields support accountability, overdue reporting, and escalation. Status and remediation actions provide additional context. Policy versions and evidence types may be relevant elsewhere, but they do not directly identify responsibility for resolving an overdue deficiency.

Question 177.

Which two factors are most commonly used together to evaluate risk exposure?

  1. Likelihood and impact
    2. Policy age and issue count
    3. Evidence count and assessment frequency
    4. Control owner tenure and user count

Correct Answer: 1. Likelihood and impact

Explanation:

Likelihood measures the probability that a risk event will occur, while impact represents the potential consequence if it does. These two factors are commonly combined in qualitative or quantitative risk scoring models. Organizations may define custom scales, but likelihood and impact remain common foundational dimensions. Policy age and evidence count do not directly represent risk severity.

Question 178.

A policy is revised and employees must formally confirm they have reviewed the new version. Which process is most appropriate?

  1. Risk acceptance
    2. Policy acknowledgment or attestation
    3. Control retirement
    4. Issue closure

Correct Answer: 2. Policy acknowledgment or attestation

Explanation:

Policy acknowledgment or attestation provides a structured method for obtaining confirmation that designated users reviewed or accepted policy content. This creates evidence of distribution and awareness that can support governance and audit requirements. It does not replace control testing or risk assessment, but it is well suited to proving that employees received and acknowledged an updated policy.

Question 179.

A critical control fails during testing. The control was expected to reduce a high-risk exposure substantially. What should the organization consider doing?

  1. Delete the control
    2. Close the risk automatically
    3. Reassess the related risk and initiate remediation
    4. Remove the requirement from the framework

Correct Answer: 3. Reassess the related risk and initiate remediation

Explanation:

A failed critical control may mean the organization is receiving less risk reduction than previously assumed. Residual exposure could therefore be higher than the current assessment indicates. The organization should document the deficiency, track corrective action, and reassess the related risk as appropriate. Automatically closing or deleting records would hide the problem rather than manage it.

Question 180.

Which practice best supports long-term scalability in a ServiceNow Risk and Compliance implementation?

  1. Track issues only through email
    2. Keep controls and requirements disconnected
    3. Avoid linking risks to business entities
    4. Maintain accurate relationships among entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation**

Correct Answer: 4. Maintain accurate relationships among entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation

Explanation:

Scalable Risk and Compliance operations depend on structured, connected, and current data. Entities provide business context, risks represent exposure, controls provide mitigation, policies and requirements define obligations, assessments and evidence support assurance, and issues manage remediation. Maintaining these relationships improves reporting, accountability, impact analysis, and audit readiness. Disconnected spreadsheets and email-based tracking become increasingly difficult to manage as regulatory scope and organizational complexity grow.