{"id":18882,"date":"2026-09-22T10:26:34","date_gmt":"2026-09-22T10:26:34","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18882"},"modified":"2026-09-22T10:26:34","modified_gmt":"2026-09-22T10:26:34","slug":"servicenow-cis-rc-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/servicenow-cis-rc-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cis-rc-exam-dumps\"><b>ServiceNow CIS-RC Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 261.<\/b><\/p>\n<p><b>An organization wants to understand how much exposure remains after its current control environment is considered. Which measure should it review?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Residual risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Inherent risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Policy risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Authority risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Residual risk<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Residual risk represents the level of exposure that remains after controls and other treatment activities are taken into account. Inherent risk reflects the exposure before controls are considered. Comparing the two helps management understand the effect of the control environment and whether additional treatment is needed. Residual risk is commonly compared with risk appetite or tolerance to determine whether the organization should mitigate further, transfer, avoid, or formally accept the remaining exposure.<\/span><\/p>\n<p><b>Question 262.<\/b><\/p>\n<p><b>A control is well designed but is not being performed consistently across all required periods. Which aspect should be assessed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policy acknowledgment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Operating effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Authority document scope<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Business entity ownership<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Operating effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Operating effectiveness focuses on whether a control is actually performed consistently and correctly over time. A control can be properly designed and still fail if employees skip required activities or perform them inconsistently. Testing and evidence can help determine the extent of the operational weakness. Design effectiveness would instead be the concern if the control could not achieve its objective even when performed exactly as intended.<\/span><\/p>\n<p><b>Question 263.<\/b><\/p>\n<p><b>A compliance analyst wants to identify the specific obligation contained in a regulation and connect it to internal safeguards. Which record is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Issue<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Citation or requirement record<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Service Offering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Citation or requirement record<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A citation or requirement record represents a specific obligation within a broader authority document such as a law, regulation, or standard. This allows the organization to map the obligation to internal policies and controls and demonstrate how compliance is addressed. Risks and issues serve different governance purposes, while a service offering is unrelated to regulatory obligation management. Requirement-level traceability is important for audits and impact analysis.<\/span><\/p>\n<p><b>Question 264.<\/b><\/p>\n<p><b>A company permanently stops a business process because the associated exposure exceeds acceptable levels. Which risk response is being used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoidance**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Avoidance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk avoidance eliminates the activity that creates the exposure. By permanently stopping the process, the organization removes the source of the risk rather than trying to reduce or shift it. Mitigation would introduce controls, transfer would move part of the consequence to another party, and acceptance would mean knowingly retaining the exposure. Avoidance is typically used when the risk cannot be reduced to a tolerable level.<\/span><\/p>\n<p><b>Question 265.<\/b><\/p>\n<p><b>A failed control creates a deficiency that requires an owner, a target date, and corrective actions. Which record should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Issue<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Knowledge Article<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Catalog Item<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Service Request<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Issue<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An issue provides a structured remediation process for identified deficiencies. It can capture the problem, assign responsibility, establish a target date, define corrective actions, and track progress to closure. This helps ensure control and compliance weaknesses are not forgotten after discovery. Knowledge articles and catalog records support different platform functions and do not provide the same governance-focused remediation lifecycle.<\/span><\/p>\n<p><b>Question 266.<\/b><\/p>\n<p><b>During a control assessment, an auditor asks for logs, approval records, and screenshots. What is being collected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk tolerance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Control evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Business entity criteria<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Policy hierarchy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Control evidence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control evidence provides objective support that a control activity was actually performed. Examples can include logs, screenshots, approvals, reports, reconciliations, or other records relevant to the control. Evidence helps assessors make reliable conclusions about control effectiveness and supports audit readiness. Risk tolerance and policy hierarchy provide governance context but do not prove that a specific control operated during the assessment period.<\/span><\/p>\n<p><b>Question 267.<\/b><\/p>\n<p><b>An organization adds stronger authentication and monitoring to reduce the likelihood of unauthorized access. Which treatment is being used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoidance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Mitigation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mitigation involves implementing safeguards intended to reduce the likelihood or impact of a risk. Stronger authentication and monitoring make unauthorized access less likely or easier to detect. The underlying activity continues, but additional controls are introduced. Avoidance would stop the activity, transfer would shift part of the consequences elsewhere, and acceptance would retain the risk without introducing further safeguards.<\/span><\/p>\n<p><b>Question 268.<\/b><\/p>\n<p><b>A company uses a contract to shift part of the financial consequences of a risk to another party. Which response does this represent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Transfer**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Transfer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk transfer shifts some of the financial or operational consequences of a risk to another party. Contracts, insurance, and some outsourcing arrangements can serve this purpose. The underlying event may still occur, but the distribution of its consequences changes. Mitigation reduces exposure through controls, avoidance eliminates the activity, and acceptance means retaining the remaining exposure.<\/span><\/p>\n<p><b>Question 269.<\/b><\/p>\n<p><b>Why is it useful to associate risks with business entities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It helps show where exposure exists in the organization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It automatically eliminates all control failures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It removes the need for risk owners<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It prevents future assessments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It helps show where exposure exists in the organization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business entities provide context for understanding which organizational units, applications, processes, vendors, or other scoped objects are exposed to specific risks. These relationships support reporting, prioritization, ownership, and assessments. Management can compare exposure across entities and make better-informed treatment decisions. Entity relationships do not eliminate controls or ownership, but they improve enterprise risk visibility.<\/span><\/p>\n<p><b>Question 270.<\/b><\/p>\n<p><b>A control owner must formally confirm every six months that a control remains active and continues to operate. Which mechanism best supports this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incident<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Attestation or assessment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Catalog Request<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Change Request<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Attestation or assessment<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An attestation or assessment provides a structured way to obtain recurring confirmation that a control remains in place and is still operating. The control owner may answer questions, certify statements, or provide evidence. This helps identify control deterioration over time and supports ongoing assurance. Incident and catalog processes do not provide the same recurring governance and compliance verification capability.<\/span><\/p>\n<p><b>Question 271.<\/b><\/p>\n<p><b>Which two factors are commonly used together to determine the severity of a risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evidence and remediation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Policy age and control count<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Likelihood and impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Issue age and owner tenure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Likelihood and impact<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Likelihood estimates the probability that a risk event will occur, while impact represents the potential consequences if it does. These two factors are commonly combined in risk scoring methodologies. Organizations may use qualitative or quantitative approaches, but likelihood and impact remain common foundational dimensions. Evidence and issue information support the broader risk management process but do not directly define risk severity.<\/span><\/p>\n<p><b>Question 272.<\/b><\/p>\n<p><b>A risk owner formally decides that the remaining exposure is within tolerance and no additional treatment is needed. Which response applies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Acceptance**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Acceptance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk acceptance means authorized stakeholders knowingly retain residual exposure because it is within approved tolerance or because further treatment is not justified. The decision should generally be documented and governed according to organizational policy. Acceptance does not remove the risk; it confirms that management understands the exposure and is willing to retain it under current conditions.<\/span><\/p>\n<p><b>Question 273.<\/b><\/p>\n<p><b>One shared control supports requirements from multiple compliance frameworks. What is a key benefit of mapping these relationships?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduced duplicate testing and evidence collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permanent elimination of compliance risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Removal of future assessment requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Automatic closure of all related issues<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Reduced duplicate testing and evidence collection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Shared control mappings allow one safeguard to support several overlapping requirements. This can reduce duplicated control definitions, testing, and evidence requests while improving traceability. If the control fails, the organization can also identify all affected obligations more quickly. The mapping does not guarantee permanent compliance and does not remove the need for future assessments or remediation.<\/span><\/p>\n<p><b>Question 274.<\/b><\/p>\n<p><b>Employees are required to formally confirm that they reviewed an updated policy. Which process is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Policy acknowledgment or attestation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Control retirement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Issue closure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Policy acknowledgment or attestation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy acknowledgment or attestation provides documented evidence that designated employees reviewed or accepted policy content. This supports governance, awareness, and audit readiness. It can also help identify users who have not completed the required acknowledgment. This process does not replace control testing or risk assessment, but it is well suited to demonstrating policy communication.<\/span><\/p>\n<p><b>Question 275.<\/b><\/p>\n<p><b>A control is performed exactly as documented but still cannot achieve its intended objective. Which area is deficient?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evidence retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Operating effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Design effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk ownership<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Design effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Design effectiveness evaluates whether a control is capable of achieving its intended purpose. If a control is executed correctly but still cannot reduce the intended risk or satisfy the requirement, the design itself is inadequate. The organization may need to redesign or replace the safeguard. Operating effectiveness would instead be the concern if a properly designed control were not being executed consistently.<\/span><\/p>\n<p><b>Question 276.<\/b><\/p>\n<p><b>A regulatory requirement is updated. What is the most efficient way to identify affected internal policies, controls, and risks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review password-reset history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Review browser compatibility<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Review user-interface preferences<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Use relationship mapping and impact analysis**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Use relationship mapping and impact analysis<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Connected relationships among requirements, policies, controls, risks, and entities allow compliance teams to determine the internal impact of regulatory changes quickly. This reduces manual searching and helps ensure that affected records are not overlooked. Accurate relationship mapping is therefore important for efficient regulatory change management, audit readiness, and compliance traceability.<\/span><\/p>\n<p><b>Question 277.<\/b><\/p>\n<p><b>A remediation issue is overdue and management wants to know who is responsible for completing it. Which information is most important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assigned owner and target date<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Policy format<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Browser type<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Number of knowledge articles<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Assigned owner and target date<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The assigned owner identifies who is responsible for completing the remediation, while the target date establishes when the work should be finished. Together with status and corrective actions, these fields support accountability and escalation. Without clear ownership and deadlines, identified deficiencies may remain unresolved. Formatting and browser information do not provide remediation accountability.<\/span><\/p>\n<p><b>Question 278.<\/b><\/p>\n<p><b>A shared control fails. Which information should the compliance team review to identify all affected external requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User-role assignments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Control-to-requirement mappings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Application themes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Knowledge article categories<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Control-to-requirement mappings<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control-to-requirement mappings show which regulatory, standards-based, or internal obligations depend on a particular safeguard. When a shared control fails, these relationships allow the organization to identify the broader compliance impact quickly. This supports remediation prioritization, reporting, and impact analysis. User roles and application themes do not provide this dependency information.<\/span><\/p>\n<p><b>Question 279.<\/b><\/p>\n<p><b>A critical control fails during testing and residual exposure may now be higher. What should the organization do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the failed control until next year<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Record the deficiency, track remediation, and reassess the risk as appropriate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the associated regulation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Record the deficiency, track remediation, and reassess the risk as appropriate<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A failed critical control may reduce the expected amount of risk mitigation and cause residual exposure to increase. The deficiency should be documented, corrective actions should be tracked, and the related risk should be reviewed to determine whether its current rating remains accurate. Ignoring or deleting the records would hide the issue rather than manage it responsibly.<\/span><\/p>\n<p><b>Question 280.<\/b><\/p>\n<p><b>Which practice best supports scalable ServiceNow Risk and Compliance operations across many entities and frameworks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Track issues primarily by email<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Keep controls and requirements disconnected<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Avoid maintaining business-entity relationships<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Maintain accurate connected records for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Maintain accurate connected records for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Scalable Risk and Compliance operations depend on reliable, structured, and connected data. Entities provide business context, risks represent exposure, controls provide mitigation, policies and requirements define obligations, assessments and evidence support assurance, and issues manage remediation. Maintaining these relationships improves reporting, accountability, audit readiness, and impact analysis. Disconnected spreadsheets and email-based tracking become difficult to govern as regulatory and organizational complexity increases.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps &nbsp; Question 261. An organization wants to understand how much exposure remains after its current control environment is considered. Which measure should it review? Residual risk 2. Inherent risk 3. Policy risk 4. Authority risk Correct Answer: 1. Residual risk Explanation: Residual risk represents the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18882"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18882"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18882\/revisions"}],"predecessor-version":[{"id":18883,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18882\/revisions\/18883"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18882"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}