{"id":18886,"date":"2026-09-22T10:27:07","date_gmt":"2026-09-22T10:27:07","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18886"},"modified":"2026-09-22T10:27:07","modified_gmt":"2026-09-22T10:27:07","slug":"servicenow-cis-rc-practice-test-questions-and-exam-dumps-part16-q301-320","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/servicenow-cis-rc-practice-test-questions-and-exam-dumps-part16-q301-320\/","title":{"rendered":"ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part16 Q301-320"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cis-rc-exam-dumps\"><b>ServiceNow CIS-RC Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 301.<\/b><\/p>\n<p><b>An organization wants to determine the amount of exposure that remains after all existing controls are considered. Which value should it review?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inherent risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Residual risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Accepted risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Authority risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Residual risk<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Residual risk represents the exposure remaining after controls, safeguards, and other treatment measures are taken into account. Inherent risk represents the exposure before those controls are considered. Comparing inherent and residual risk helps management understand how much mitigation the control environment provides. Residual risk can then be compared with organizational tolerance or appetite to determine whether additional mitigation, transfer, avoidance, or formal acceptance is required.<\/span><\/p>\n<p><b>Question 302.<\/b><\/p>\n<p><b>A control is performed consistently, but the activity itself is not capable of addressing the intended risk. Which area is deficient?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Design effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Operating effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Evidence collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk ownership<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Design effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Design effectiveness evaluates whether a control is capable of achieving its intended objective. If the control is consistently performed but cannot meaningfully reduce the associated risk or satisfy the requirement, the design is inadequate. The organization may need to redesign or replace the control. Operating effectiveness would instead be the concern if a properly designed control were performed inconsistently or incorrectly.<\/span><\/p>\n<p><b>Question 303.<\/b><\/p>\n<p><b>A compliance analyst wants to trace a regulatory obligation to the safeguards that address it. What relationship is most important?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk-to-owner mapping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> User-to-role mapping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Requirement-to-control mapping<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Issue-to-email mapping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Requirement-to-control mapping<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Requirement-to-control mapping provides traceability between an obligation and the safeguards used to address it. This relationship helps demonstrate how regulations or standards are implemented internally and is valuable for audits, impact analysis, and compliance reporting. If a control fails, teams can identify which requirements may be affected. User-role and email relationships do not provide the same compliance traceability.<\/span><\/p>\n<p><b>Question 304.<\/b><\/p>\n<p><b>Management permanently stops a business activity because its exposure cannot be reduced to an acceptable level. Which treatment applies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoidance**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Avoidance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk avoidance removes the source of exposure by discontinuing the activity that creates it. Unlike mitigation, the organization does not continue the activity with additional safeguards. Transfer shifts some consequences to another party, while acceptance means retaining the exposure. Avoidance is appropriate when management concludes that continuing the activity would create unacceptable risk even after reasonable control measures are considered.<\/span><\/p>\n<p><b>Question 305.<\/b><\/p>\n<p><b>A failed control requires corrective action and management wants to track ownership, due dates, and progress. Which record should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Issue<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Knowledge Article<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Catalog Item<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Service Offering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Issue<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An issue provides a structured way to manage deficiencies through remediation. It can include an assigned owner, target date, status, corrective actions, and supporting documentation. This helps ensure that identified weaknesses are tracked through resolution and that overdue remediation can be escalated. Knowledge articles and catalog items serve different purposes and do not provide the same governance-focused remediation lifecycle.<\/span><\/p>\n<p><b>Question 306.<\/b><\/p>\n<p><b>During an assessment, an auditor requests logs and signed approvals to verify that a control was performed. What is being requested?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk appetite<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Control evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Policy scope<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Entity criteria<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Control evidence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control evidence provides objective support that a control was actually performed and operated as expected. Logs, approvals, reports, screenshots, and reconciliations are common examples. Evidence strengthens assessment conclusions and supports audit readiness. Risk appetite and entity criteria provide governance context but do not prove that a specific control activity took place during the required period.<\/span><\/p>\n<p><b>Question 307.<\/b><\/p>\n<p><b>An organization introduces additional monitoring to reduce the likelihood that fraudulent activity goes undetected. Which response is being used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Avoidance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Mitigation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Mitigation involves implementing safeguards intended to reduce the likelihood or impact of a risk. Additional monitoring can help detect suspicious activity and therefore lower exposure. The business activity continues, but stronger controls are introduced. Avoidance would stop the activity, transfer would shift some consequences elsewhere, and acceptance would retain the exposure without further treatment.<\/span><\/p>\n<p><b>Question 308.<\/b><\/p>\n<p><b>A company enters an insurance agreement that covers certain losses. Which risk treatment does this most closely represent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Transfer**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Transfer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Insurance transfers part of the financial consequence of a risk event to another party. The underlying event may still occur, but the organization reduces the amount of loss it must bear directly. Mitigation reduces exposure through safeguards, avoidance eliminates the risky activity, and acceptance means consciously retaining the exposure. Transfer changes how the consequences of the risk are distributed.<\/span><\/p>\n<p><b>Question 309.<\/b><\/p>\n<p><b>Why should risks be linked to the business entities they affect?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide context about where exposure exists<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To automatically close remediation issues<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To prevent future risk assessments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To provide context about where exposure exists<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business entities provide organizational context for risk. They can represent business units, applications, processes, vendors, or other scoped objects. Linking risks to these entities helps management understand where exposure exists and supports reporting, prioritization, ownership, and assessment. Entity relationships do not remove the need for controls or risk assessments, but they improve enterprise visibility.<\/span><\/p>\n<p><b>Question 310.<\/b><\/p>\n<p><b>A control owner must formally confirm every quarter that a control remains active and continues to operate. Which process is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incident management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Attestation or assessment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Catalog fulfillment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Change implementation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Attestation or assessment<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An attestation or assessment provides a structured way to obtain periodic confirmation that a control remains in place and continues to operate. The owner can answer questions, certify statements, or submit evidence. This creates a repeatable assurance process and helps identify control deterioration over time. Incident and catalog processes are designed for different operational purposes.<\/span><\/p>\n<p><b>Question 311.<\/b><\/p>\n<p><b>Which two dimensions are commonly combined when evaluating risk severity?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evidence and remediation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Policy age and issue count<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Likelihood and impact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Control age and owner tenure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Likelihood and impact<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Likelihood represents the probability that a risk event will occur, while impact reflects the potential consequence if it does. These two dimensions are commonly combined in qualitative or quantitative risk-scoring methodologies. Organizations may define customized scales and formulas, but likelihood and impact remain common foundational measures. Evidence and issue information support other governance processes but are not core risk-severity dimensions.<\/span><\/p>\n<p><b>Question 312.<\/b><\/p>\n<p><b>A risk owner concludes that residual exposure is within tolerance and formally chooses to retain it. Which response applies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Mitigation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Acceptance**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Acceptance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk acceptance occurs when authorized stakeholders knowingly retain residual exposure because it is within approved tolerance or because further treatment is not justified. The decision should generally be documented according to governance requirements. Acceptance does not remove the risk. It confirms that management understands the remaining exposure and is willing to retain it under current conditions.<\/span><\/p>\n<p><b>Question 313.<\/b><\/p>\n<p><b>One control supports obligations from several compliance frameworks. What is one important benefit of maintaining these mappings?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reduced duplicate testing and evidence collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permanent elimination of compliance risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automatic closure of all issues<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Removal of all future assessments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Reduced duplicate testing and evidence collection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A shared control can support multiple overlapping requirements, allowing the same testing and evidence to be reused across frameworks. This can reduce duplicated work and improve compliance traceability. The mappings also help identify which obligations are affected if the control later fails. Shared controls still require ongoing assessment and maintenance, so they do not guarantee permanent compliance.<\/span><\/p>\n<p><b>Question 314.<\/b><\/p>\n<p><b>Employees must formally confirm that they have reviewed an updated policy. Which process best supports this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk transfer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Policy acknowledgment or attestation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Control retirement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Issue closure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Policy acknowledgment or attestation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy acknowledgment or attestation provides documented evidence that designated employees reviewed or accepted policy content. This supports governance, awareness, and audit readiness. It can also help identify users who have not completed the required acknowledgment. This process does not replace control testing or risk assessments, but it is appropriate for proving that revised policy information was communicated to the intended audience.<\/span><\/p>\n<p><b>Question 315.<\/b><\/p>\n<p><b>A control is well designed but is frequently skipped by employees. Which area is weak?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evidence retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Design effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Operating effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk acceptance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Operating effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Operating effectiveness focuses on whether a control is actually performed consistently and correctly in practice. A control may have a sound design but still fail to reduce risk if employees skip it or execute it inconsistently. Testing and evidence can reveal these operational failures. Design effectiveness would instead be the concern if the control were incapable of achieving its objective even when performed exactly as intended.<\/span><\/p>\n<p><b>Question 316.<\/b><\/p>\n<p><b>A regulation changes and the compliance team needs to identify affected internal policies, controls, and risks. What is most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Browser version reports<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Password reset logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User-interface preferences<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Relationship mapping and impact analysis**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Relationship mapping and impact analysis<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Connected relationships among requirements, policies, controls, risks, and entities support efficient regulatory change analysis. Compliance teams can quickly identify which internal records may need review instead of searching through disconnected documents manually. This improves traceability and reduces the chance that affected safeguards or policies are overlooked. Browser and password data do not reveal compliance dependencies.<\/span><\/p>\n<p><b>Question 317.<\/b><\/p>\n<p><b>A remediation issue is overdue. Which information is most important for accountability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assigned owner, target date, status, and corrective actions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Policy formatting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Browser type<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Number of knowledge articles<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Assigned owner, target date, status, and corrective actions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Clear ownership and deadlines are essential for remediation accountability. The assigned owner identifies who is responsible, the target date establishes when the work should be completed, status shows progress, and corrective actions define what remains to be done. These details support escalation when remediation becomes overdue. Formatting and browser information do not contribute to corrective-action accountability.<\/span><\/p>\n<p><b>Question 318.<\/b><\/p>\n<p><b>A shared control fails. Which information should management review to determine which external obligations may be affected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> User-role assignments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Control-to-requirement mappings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Application themes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Knowledge article activity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Control-to-requirement mappings<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control-to-requirement mappings identify the obligations that depend on a particular safeguard. When a shared control fails, these relationships allow management to understand which regulations, standards, or internal requirements may be affected. This supports impact analysis, remediation prioritization, and compliance reporting. User roles and application themes do not provide the necessary dependency information.<\/span><\/p>\n<p><b>Question 319.<\/b><\/p>\n<p><b>A critical control fails and residual risk may now be understated. What should the organization do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the related risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the finding until the next annual assessment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Record the deficiency, track remediation, and reassess the risk as appropriate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the associated regulation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Record the deficiency, track remediation, and reassess the risk as appropriate<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A failed critical control may reduce the expected amount of mitigation and cause residual exposure to increase. The deficiency should be documented, corrective actions should be assigned, and the related risk should be reviewed to determine whether the existing rating is still accurate. Ignoring or deleting the finding would hide the exposure rather than manage it responsibly.<\/span><\/p>\n<p><b>Question 320.<\/b><\/p>\n<p><b>Which practice best supports scalable ServiceNow Risk and Compliance operations?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Track deficiencies only through email<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Keep controls and requirements disconnected<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Avoid linking risks to business entities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Maintain accurate connected records for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Maintain accurate connected records for entities, risks, controls, policies, requirements, assessments, evidence, issues, and remediation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Scalable Risk and Compliance operations depend on reliable, structured, and connected data. Business entities provide context, risks represent exposure, controls provide mitigation, policies and requirements define obligations, assessments and evidence support assurance, and issues manage remediation. Maintaining these relationships improves reporting, audit readiness, accountability, and impact analysis. Disconnected spreadsheets and email-only tracking become increasingly difficult to govern as organizational and regulatory complexity grows.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps &nbsp; Question 301. An organization wants to determine the amount of exposure that remains after all existing controls are considered. Which value should it review? Inherent risk 2. Residual risk 3. Accepted risk 4. Authority risk Correct Answer: 2. Residual risk Explanation: Residual risk represents [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18886"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18886"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18886\/revisions"}],"predecessor-version":[{"id":18887,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18886\/revisions\/18887"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18886"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18886"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18886"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}