{"id":18888,"date":"2026-09-22T10:27:27","date_gmt":"2026-09-22T10:27:27","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18888"},"modified":"2026-09-22T10:27:27","modified_gmt":"2026-09-22T10:27:27","slug":"servicenow-cis-rc-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/servicenow-cis-rc-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cis-rc-exam-dumps\"><b>ServiceNow CIS-RC Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 321.<\/b><\/p>\n<p><b>An organization defines the overall amount and type of risk it is willing to pursue or retain in support of its objectives. Which concept does this describe?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk appetite<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Residual risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Control evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Issue severity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Risk appetite<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk appetite expresses the broad level and type of risk an organization is willing to accept while pursuing its objectives. It provides strategic guidance for risk-taking and helps establish more specific limits or tolerances. Residual risk represents exposure remaining after controls, while control evidence supports assurance activities. Clearly defined appetite helps risk owners and executives determine whether current exposures align with organizational expectations.<\/span><\/p>\n<p><b>Question 322.<\/b><\/p>\n<p><b>A business unit has exceeded the maximum acceptable level defined for a specific operational risk. Which concept has most directly been exceeded?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk taxonomy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Risk tolerance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Control frequency<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Policy acknowledgment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Risk tolerance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk tolerance represents a more specific acceptable variation or limit for a particular risk, metric, or activity. It is typically more operational than broad risk appetite. When exposure exceeds tolerance, the organization may need additional treatment, escalation, or formal approval. A taxonomy categorizes risks, while control frequency and policy acknowledgment support other governance activities and do not define acceptable exposure levels.<\/span><\/p>\n<p><b>Question 323.<\/b><\/p>\n<p><b>A key risk indicator exceeds its defined threshold for three consecutive reporting periods. What is the most appropriate interpretation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The related risk should automatically be deleted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The control should automatically be retired<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The trend may indicate increasing exposure and should be reviewed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The organization is automatically compliant<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The trend may indicate increasing exposure and should be reviewed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A key risk indicator provides measurable information about conditions that may signal changing risk exposure. Repeated threshold breaches can indicate that risk is increasing or that existing controls are becoming less effective. The appropriate response is to review the underlying risk, related controls, and treatment actions. Threshold breaches do not automatically prove a control failure or require deleting records, but they provide valuable monitoring information that can trigger further assessment.<\/span><\/p>\n<p><b>Question 324.<\/b><\/p>\n<p><b>Which control type is primarily intended to stop an undesirable event before it occurs?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detective control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Corrective control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Compensating control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Preventive control**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Preventive control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Preventive controls are designed to reduce the likelihood of an undesirable event before it happens. Examples can include access restrictions, approval requirements, segregation of duties, and validation checks. Detective controls identify events after or while they occur, while corrective controls help restore conditions afterward. A compensating control is an alternative safeguard used when a preferred control cannot be implemented effectively.<\/span><\/p>\n<p><b>Question 325.<\/b><\/p>\n<p><b>A company cannot implement its preferred security control because of a legacy-system limitation. It introduces an alternative safeguard that provides comparable protection. What is this alternative called?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Compensating control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Residual risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk appetite<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Policy exception<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Compensating control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control is an alternative safeguard used when the preferred or standard control cannot be implemented. It should provide sufficient protection to address the intended risk or requirement. The organization should document why the primary control is unavailable and how the alternative provides adequate coverage. Residual risk and risk appetite describe exposure concepts, while a policy exception documents deviation rather than serving as the alternative control itself.<\/span><\/p>\n<p><b>Question 326.<\/b><\/p>\n<p><b>A control requires evidence every month, but the most recent evidence is eight months old. What is the primary concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The risk taxonomy is incomplete<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The evidence may no longer demonstrate current control performance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The policy owner must be replaced<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The authority document should be retired<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The evidence may no longer demonstrate current control performance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Evidence should be sufficiently current to support conclusions about control performance for the relevant assessment period. If a monthly control has only eight-month-old evidence, the assessor cannot confidently conclude that the control continues to operate. Evidence freshness is therefore important. Older evidence may still provide historical context, but it generally cannot substitute for proof that a recurring control has operated during the current review period.<\/span><\/p>\n<p><b>Question 327.<\/b><\/p>\n<p><b>A control failed, remediation was completed, and management wants assurance that the corrected control now works. What should happen next?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Close the issue without further review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete the original assessment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Re-test or reassess the control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Accept the risk automatically<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Re-test or reassess the control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">After remediation, re-testing or reassessment helps confirm that the corrective action resolved the underlying deficiency and that the control now operates effectively. Closing an issue without verification can leave unresolved weaknesses hidden. The original assessment should remain part of the historical record. Depending on governance requirements, closure evidence and successful re-testing may be required before the issue is considered fully resolved.<\/span><\/p>\n<p><b>Question 328.<\/b><\/p>\n<p><b>An organization wants to apply one risk assessment methodology consistently across several subsidiaries and business units. What is the main benefit?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It guarantees that all risks will have identical scores<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It removes the need for risk owners<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates control testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It improves comparability of risk results across entities**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. It improves comparability of risk results across entities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Using a consistent methodology makes risk scores and assessments easier to compare across entities because similar criteria, scales, and definitions are applied. This supports enterprise reporting, aggregation, and prioritization. It does not mean every risk will receive the same score, because exposure can vary significantly by entity. Consistency improves interpretation without eliminating ownership or control assurance requirements.<\/span><\/p>\n<p><b>Question 329.<\/b><\/p>\n<p><b>Which record or view is most useful for maintaining a consolidated list of identified organizational risks and their key details?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk register<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Knowledge base<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Service catalog<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Change calendar<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Risk register<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk register provides a consolidated view of identified risks and commonly includes information such as ownership, category, status, assessments, treatments, and current exposure. It helps management monitor the organization\u2019s risk landscape and supports prioritization and reporting. Knowledge bases and service catalogs serve different operational purposes and are not designed to provide a comprehensive view of enterprise risk.<\/span><\/p>\n<p><b>Question 330.<\/b><\/p>\n<p><b>A company wants to detect unusual transaction patterns after transactions have occurred. Which control type is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Preventive control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detective control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk acceptance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Policy exception<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Detective control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detective controls are designed to identify events, errors, or irregularities after or while they occur. Transaction monitoring, exception reports, reconciliations, and log reviews are common examples. Preventive controls try to stop undesirable activity before it happens. Detective controls are valuable because they can reveal failures that preventive controls did not stop and can trigger corrective action or further investigation.<\/span><\/p>\n<p><b>Question 331.<\/b><\/p>\n<p><b>A policy has not been reviewed for several years, even though regulations and business processes have changed. What is the greatest governance concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The policy contains too many acknowledgments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The control owner has too much evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The policy may no longer reflect current obligations or practices<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The risk register is automatically invalid<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The policy may no longer reflect current obligations or practices<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policies should be reviewed periodically to ensure they remain aligned with current regulations, business processes, organizational responsibilities, and control expectations. An outdated policy may create gaps between documented requirements and actual practices. Regular review cycles help identify needed revisions and support good policy governance. A stale policy does not automatically invalidate every related risk or control, but it can weaken the overall compliance program.<\/span><\/p>\n<p><b>Question 332.<\/b><\/p>\n<p><b>A business unit receives temporary approval to deviate from a policy requirement while a system upgrade is underway. What governance mechanism best represents this situation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Control retirement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Authority deletion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Policy exception or waiver**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Policy exception or waiver<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A policy exception or waiver documents an approved temporary deviation from a policy requirement. Effective exception governance should identify the reason, scope, approver, expiration date, compensating safeguards, and any associated risk. It should not become an indefinite way to bypass requirements. Once the underlying condition is resolved, the exception should be reviewed, closed, or renewed according to established governance.<\/span><\/p>\n<p><b>Question 333.<\/b><\/p>\n<p><b>A new acquisition significantly changes an organization\u2019s processes and technology environment. What should happen to relevant risks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They should be reassessed because material business changes can alter exposure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> They should automatically be accepted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> They should be closed permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Their control mappings should be removed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. They should be reassessed because material business changes can alter exposure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Major business changes such as acquisitions, reorganizations, new systems, or substantial process changes can affect likelihood, impact, control effectiveness, and ownership. Relevant risks should therefore be reassessed to ensure current ratings still reflect actual exposure. Existing control mappings may also need review. Automatically accepting or closing risks could leave significant new exposures unrecognized.<\/span><\/p>\n<p><b>Question 334.<\/b><\/p>\n<p><b>An organization uses automated data feeds to monitor risk indicators and control conditions continuously. What is the primary advantage?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It removes all need for human oversight<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It can identify changing conditions sooner than periodic manual reviews<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It permanently eliminates residual risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It guarantees regulatory compliance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. It can identify changing conditions sooner than periodic manual reviews<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuous monitoring can provide more timely visibility into changing risk indicators, control conditions, or compliance exceptions. Automated data feeds may detect threshold breaches or anomalies earlier than quarterly or annual manual reviews. Human review and governance are still important for interpreting results and deciding what action to take. Continuous monitoring improves timeliness, but it does not guarantee compliance or eliminate risk.<\/span><\/p>\n<p><b>Question 335.<\/b><\/p>\n<p><b>An organization wants to group risks into areas such as operational, compliance, strategic, and technology. What concept supports this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evidence freshness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Issue aging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk taxonomy or categorization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Policy acknowledgment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Risk taxonomy or categorization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk taxonomy organizes risks into meaningful categories and subcategories. This helps organizations classify risks consistently, improve reporting, identify concentration, and compare exposure across the enterprise. Categories such as operational, strategic, compliance, and technology are common examples. A clear taxonomy also supports governance and aggregation without changing the actual likelihood or impact of individual risks.<\/span><\/p>\n<p><b>Question 336.<\/b><\/p>\n<p><b>A policy reaches the end of its useful life and has been replaced by a newer approved version. What should happen to the obsolete policy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep it active indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete all historical references immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Convert it into a risk record<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Retire or archive it according to the policy lifecycle**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Retire or archive it according to the policy lifecycle<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A mature policy lifecycle includes creation, review, approval, publication, periodic review, revision, and eventual retirement or archival. When a policy has been superseded, it should no longer remain active as if it were current. Historical versions may still need to be retained for audit, legal, or governance purposes. Retirement preserves lifecycle integrity while preventing users from relying on obsolete guidance.<\/span><\/p>\n<p><b>Question 337.<\/b><\/p>\n<p><b>A risk treatment plan includes several specific actions assigned to different owners. What is the main purpose of these actions?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To implement and track the selected risk response<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To replace all related policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To remove the risk from the register immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for future monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To implement and track the selected risk response<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk treatment actions translate a selected response into concrete work. They may include implementing controls, changing processes, transferring exposure, or completing other mitigation activities. Assigning owners and target dates makes the treatment measurable and accountable. A risk normally remains subject to monitoring until treatment is complete and the resulting residual exposure is understood. Treatment actions therefore support execution rather than simply documenting intent.<\/span><\/p>\n<p><b>Question 338.<\/b><\/p>\n<p><b>An organization wants to distinguish control ownership from independent control testing. Why is this separation valuable?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It eliminates the need for evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It supports more objective assurance over control effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It automatically lowers residual risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It removes the need for control owners<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. It supports more objective assurance over control effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separating control ownership from independent testing can strengthen assurance because the person responsible for operating a control is not solely responsible for evaluating its effectiveness. Independent review can reduce conflicts of interest and provide a more objective assessment of design, operation, and evidence. Control owners remain responsible for the control itself, while testers provide assurance regarding whether it functions as intended.<\/span><\/p>\n<p><b>Question 339.<\/b><\/p>\n<p><b>A risk indicator is below threshold today, but its values have increased steadily for six months. Why should the trend still be reviewed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Any upward trend automatically proves a control failure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Trends are irrelevant until a threshold is breached<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A sustained increase may provide early warning of worsening exposure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The related risk should automatically be closed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A sustained increase may provide early warning of worsening exposure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk monitoring should consider both current threshold status and trend direction. A steadily increasing indicator can provide early warning that exposure is worsening even before a formal threshold is crossed. Reviewing trends enables management to investigate causes and consider preventive action sooner. An upward trend does not automatically prove a control failure, but it can signal that existing assumptions, controls, or treatment plans should be reviewed.<\/span><\/p>\n<p><b>Question 340.<\/b><\/p>\n<p><b>Before automating a large Risk and Compliance program, what should an organization establish first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> As many custom fields as possible<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A separate spreadsheet for every department<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automated issue closure rules without review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Clear governance, methodology, ownership, and data requirements**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Clear governance, methodology, ownership, and data requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automation is most effective when the organization first defines how risk and compliance processes should operate. Clear methodology, ownership, approval rules, data standards, assessment approaches, and escalation paths provide the foundation for reliable automation. Automating an undefined or inconsistent process can simply make poor practices happen faster. Establishing governance first helps ensure that workflows, reports, assessments, and monitoring support consistent enterprise objectives.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps &nbsp; Question 321. An organization defines the overall amount and type of risk it is willing to pursue or retain in support of its objectives. Which concept does this describe? Risk appetite 2. Residual risk 3. Control evidence 4. Issue severity Correct Answer: 1. Risk [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18888"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18888"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18888\/revisions"}],"predecessor-version":[{"id":18889,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18888\/revisions\/18889"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18888"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18888"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18888"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}