{"id":18872,"date":"2026-09-22T10:24:56","date_gmt":"2026-09-22T10:24:56","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18872"},"modified":"2026-09-22T10:24:56","modified_gmt":"2026-09-22T10:24:56","slug":"servicenow-cis-rc-practice-test-questions-and-exam-dumps-part9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/servicenow-cis-rc-practice-test-questions-and-exam-dumps-part9-q161-180\/","title":{"rendered":"ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part9 Q161-180"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cis-rc-exam-dumps\"><b>ServiceNow CIS-RC Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 161.<\/b><\/p>\n<p><b>An organization wants to determine whether a control is capable of addressing its intended risk before reviewing how consistently it is performed. What should be evaluated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Operating effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Policy acknowledgment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Design effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk acceptance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Design effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Design effectiveness evaluates whether a control is appropriately constructed to achieve its intended objective. Before examining whether employees perform the control consistently, the organization should determine whether the control could actually reduce the associated risk or satisfy the relevant requirement when executed as designed. Operating effectiveness addresses how reliably the control is performed in practice. A poorly designed control cannot become effective simply by being performed more frequently, so design should be evaluated independently.<\/span><\/p>\n<p><b>Question 162.<\/b><\/p>\n<p><b>A company wants to understand the risk level that exists after all current controls are taken into account. Which measure should it review?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Residual risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Inherent risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Authority risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Policy risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Residual risk<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Residual risk represents the amount of exposure remaining after existing controls and other mitigation measures are considered. Inherent risk represents the exposure before those controls are applied. Organizations often compare residual risk with risk tolerance or appetite to determine whether further action is required. If the remaining exposure is too high, management may choose additional mitigation, transfer, avoidance, or another treatment response.<\/span><\/p>\n<p><b>Question 163.<\/b><\/p>\n<p><b>A compliance team wants to identify all controls that support a particular regulatory requirement. Which information is most important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User-role assignments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Control-to-requirement mappings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Browser versions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Knowledge article ratings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Control-to-requirement mappings<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control-to-requirement mappings provide traceability between compliance obligations and the internal safeguards that address them. These relationships help auditors and compliance teams identify which controls support a specific requirement and determine the impact if one of those controls changes or fails. Mapping also reduces duplication when one control supports several frameworks. User-role assignments and browser information do not provide this compliance relationship.<\/span><\/p>\n<p><b>Question 164.<\/b><\/p>\n<p><b>A business unit chooses to discontinue a product because the associated legal risk is considered unacceptable. Which risk treatment is being used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoidance**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Avoidance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk avoidance occurs when an organization eliminates the activity that creates the exposure. By discontinuing the product, the business removes the source of the identified legal risk rather than attempting to reduce or transfer it. Mitigation would involve implementing additional safeguards, transfer would shift part of the consequences to another party, and acceptance would mean consciously retaining the remaining exposure.<\/span><\/p>\n<p><b>Question 165.<\/b><\/p>\n<p><b>A control assessment identifies a failure that requires corrective action. Which record should be used to manage ownership, due dates, and remediation progress?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Issue<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Knowledge Article<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Service Offering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Catalog Item<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Issue<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An issue provides a structured way to manage deficiencies identified through assessments or other compliance activities. It can include an assigned owner, target date, remediation plan, status, and supporting information. This helps ensure that control weaknesses are tracked through resolution rather than forgotten after discovery. Knowledge articles and catalog items serve other platform purposes and do not provide the same remediation lifecycle.<\/span><\/p>\n<p><b>Question 166.<\/b><\/p>\n<p><b>An assessor asks for approval logs and reports showing that a monthly control was performed. What is the assessor requesting?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk appetite information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Control evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Entity hierarchy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Policy scope<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Control evidence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control evidence provides objective support that a control was performed and can be used to evaluate its effectiveness. Approval logs, reports, screenshots, reconciliations, and similar records can demonstrate whether the control operated during the required period. Evidence strengthens assessment conclusions and improves audit readiness. Risk appetite and policy scope are governance information but do not prove that the specific control activity occurred.<\/span><\/p>\n<p><b>Question 167.<\/b><\/p>\n<p><b>A company adds an automated approval check to reduce unauthorized financial transactions. Which risk response does this represent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Transfer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Mitigation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mitigation involves implementing safeguards that reduce the likelihood or impact of a risk. An automated approval check makes unauthorized transactions less likely and therefore reduces exposure while allowing the underlying business process to continue. Avoidance would stop the activity entirely, transfer would shift some consequences elsewhere, and acceptance would retain the exposure without introducing additional treatment.<\/span><\/p>\n<p><b>Question 168.<\/b><\/p>\n<p><b>An organization purchases insurance to reduce the financial consequences of a potential loss. Which risk treatment is this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Transfer**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Transfer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Insurance is a common example of risk transfer because it shifts part of the financial consequences of a risk event to another party. The underlying risk may still occur, but the organization reduces the portion of the loss it would bear directly. Mitigation reduces exposure through controls, avoidance eliminates the risky activity, and acceptance means retaining the exposure.<\/span><\/p>\n<p><b>Question 169.<\/b><\/p>\n<p><b>Why is it useful to associate risks with business entities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It shows where exposure exists within the organization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for risk owners<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It automatically closes issues<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It prevents control failures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It shows where exposure exists within the organization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Associating risks with business entities provides context about which business unit, application, process, vendor, or other scoped object is affected. This supports entity-based reporting, prioritization, assessments, and ownership. Management can also compare risk exposure across different organizational areas. The relationship does not eliminate the need for controls or ownership, but it improves visibility into where risks are concentrated.<\/span><\/p>\n<p><b>Question 170.<\/b><\/p>\n<p><b>A control owner must certify annually that a control remains in place and continues to operate. Which mechanism best supports this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Change Request<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Attestation or assessment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Catalog Request<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Incident<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Attestation or assessment<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An attestation or assessment can be used to obtain periodic confirmation that a control remains in place and is still operating. The owner may answer structured questions, certify statements, or provide supporting evidence. This creates a repeatable assurance process and helps identify changes in control performance over time. Incident and catalog processes are designed for different operational purposes.<\/span><\/p>\n<p><b>Question 171.<\/b><\/p>\n<p><b>A regulation contains many individual obligations. Which record commonly represents one specific obligation within that regulation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Citation or requirement record<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Issue<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Citation or requirement record<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An authority document can represent a broader regulation, law, standard, or framework, while citation or requirement records represent the individual obligations contained within it. Those specific requirements can then be mapped to policies and controls. This structure improves compliance traceability and allows organizations to understand exactly how each obligation is addressed internally.<\/span><\/p>\n<p><b>Question 172.<\/b><\/p>\n<p><b>A risk owner formally approves the decision to retain residual exposure because it is within the organization\u2019s tolerance. Which response applies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Acceptance**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Acceptance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk acceptance means that authorized stakeholders consciously decide to retain the remaining exposure because it is considered tolerable or because additional treatment is not justified. The decision should generally be documented and approved according to governance requirements. Acceptance does not eliminate the risk; it confirms that the organization knowingly retains it under defined conditions.<\/span><\/p>\n<p><b>Question 173.<\/b><\/p>\n<p><b>A shared control supports requirements from several regulatory frameworks. What is one major advantage of this arrangement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It can reduce duplicate evidence collection and testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It permanently guarantees compliance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It prevents control failures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It can reduce duplicate evidence collection and testing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When one control supports multiple requirements, organizations can often reuse the same control evidence and testing results across several frameworks. This reduces duplicated effort and improves compliance efficiency. Accurate mappings also make impact analysis easier if the control fails. Shared controls do not guarantee permanent compliance and still require periodic assessment and maintenance.<\/span><\/p>\n<p><b>Question 174.<\/b><\/p>\n<p><b>A control works as designed, but employees fail to perform it regularly. Which aspect needs improvement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Design effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Operating effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Authority document mapping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk appetite<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Operating effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Operating effectiveness addresses whether a control is consistently performed in actual practice. A properly designed control may still be ineffective if employees skip it, perform it incorrectly, or fail to retain required evidence. Assessment and testing can identify these execution problems. Design effectiveness would be the concern if the control itself were incapable of meeting its objective even when performed correctly.<\/span><\/p>\n<p><b>Question 175.<\/b><\/p>\n<p><b>A compliance manager wants to determine what internal policies and controls might be affected by a change to an external requirement. Which capability is most important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Application themes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Relationship mapping and impact analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Knowledge article ratings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Relationship mapping and impact analysis<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Connected relationships among authority requirements, policies, controls, risks, and entities allow compliance teams to identify internal dependencies quickly when an external obligation changes. This significantly improves regulatory change analysis and reduces the need for manual searching across disconnected documents. Password history and application themes do not provide information about compliance dependencies.<\/span><\/p>\n<p><b>Question 176.<\/b><\/p>\n<p><b>A remediation item has passed its due date and management wants to know who is responsible. Which information is most important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policy version<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Evidence type<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk score<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Issue owner and target date**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Issue owner and target date<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An issue owner identifies who is responsible for completing remediation, while the target date establishes when corrective action should be completed. These fields support accountability, overdue reporting, and escalation. Status and remediation actions provide additional context. Policy versions and evidence types may be relevant elsewhere, but they do not directly identify responsibility for resolving an overdue deficiency.<\/span><\/p>\n<p><b>Question 177.<\/b><\/p>\n<p><b>Which two factors are most commonly used together to evaluate risk exposure?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Likelihood and impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Policy age and issue count<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Evidence count and assessment frequency<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Control owner tenure and user count<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Likelihood and impact<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Likelihood measures the probability that a risk event will occur, while impact represents the potential consequence if it does. These two factors are commonly combined in qualitative or quantitative risk scoring models. Organizations may define custom scales, but likelihood and impact remain common foundational dimensions. Policy age and evidence count do not directly represent risk severity.<\/span><\/p>\n<p><b>Question 178.<\/b><\/p>\n<p><b>A policy is revised and employees must formally confirm they have reviewed the new version. Which process is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Policy acknowledgment or attestation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Control retirement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Issue closure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Policy acknowledgment or attestation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy acknowledgment or attestation provides a structured method for obtaining confirmation that designated users reviewed or accepted policy content. This creates evidence of distribution and awareness that can support governance and audit requirements. It does not replace control testing or risk assessment, but it is well suited to proving that employees received and acknowledged an updated policy.<\/span><\/p>\n<p><b>Question 179.<\/b><\/p>\n<p><b>A critical control fails during testing. The control was expected to reduce a high-risk exposure substantially. What should the organization consider doing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Close the risk automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reassess the related risk and initiate remediation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the requirement from the framework<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Reassess the related risk and initiate remediation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A failed critical control may mean the organization is receiving less risk reduction than previously assumed. Residual exposure could therefore be higher than the current assessment indicates. The organization should document the deficiency, track corrective action, and reassess the related risk as appropriate. Automatically closing or deleting records would hide the problem rather than manage it.<\/span><\/p>\n<p><b>Question 180.<\/b><\/p>\n<p><b>Which practice best supports long-term scalability in a ServiceNow Risk and Compliance implementation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Track issues only through email<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Keep controls and requirements disconnected<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Avoid linking risks to business entities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Maintain accurate relationships among entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Maintain accurate relationships among entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Scalable Risk and Compliance operations depend on structured, connected, and current data. Entities provide business context, risks represent exposure, controls provide mitigation, policies and requirements define obligations, assessments and evidence support assurance, and issues manage remediation. Maintaining these relationships improves reporting, accountability, impact analysis, and audit readiness. Disconnected spreadsheets and email-based tracking become increasingly difficult to manage as regulatory scope and organizational complexity grow.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps &nbsp; Question 161. An organization wants to determine whether a control is capable of addressing its intended risk before reviewing how consistently it is performed. What should be evaluated first? Operating effectiveness 2. Policy acknowledgment 3. Design effectiveness 4. Risk acceptance Correct Answer: 3. Design [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18872"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18872"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18872\/revisions"}],"predecessor-version":[{"id":18873,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18872\/revisions\/18873"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18872"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18872"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18872"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}