{"id":18890,"date":"2026-09-22T10:27:48","date_gmt":"2026-09-22T10:27:48","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18890"},"modified":"2026-09-22T10:27:48","modified_gmt":"2026-09-22T10:27:48","slug":"servicenow-cis-rc-practice-test-questions-and-exam-dumps-part18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/servicenow-cis-rc-practice-test-questions-and-exam-dumps-part18-q341-360\/","title":{"rendered":"ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part18 Q341-360"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cis-rc-exam-dumps\"><b>ServiceNow CIS-RC Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 341.<\/b><\/p>\n<p><b>A risk indicator crosses its warning threshold before the related risk reaches an unacceptable score. What is the best use of this information?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore it until the risk score changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Use it as an early warning and investigate the underlying condition<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automatically close the risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Retire all related controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Use it as an early warning and investigate the underlying condition<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk indicators can provide early warning that exposure is changing before a formal risk assessment shows a significant increase. A threshold breach should prompt review of the underlying business condition, related controls, recent trends, and treatment plans. It does not automatically prove that a control has failed or that the risk score must change, but it gives management timely information that may justify further investigation or reassessment.<\/span><\/p>\n<p><b>Question 342.<\/b><\/p>\n<p><b>An organization wants to compare risks across multiple business units using consistent scoring. What should it define first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A common risk assessment methodology and criteria<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A different scoring scale for every department<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A unique policy for every risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Separate evidence standards for each user<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A common risk assessment methodology and criteria<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Consistent risk scoring depends on clearly defined criteria, scales, terminology, and assessment methods. A common methodology improves comparability across entities and reduces the chance that similar risks are rated differently simply because different teams use different rules. Business units may still have unique exposure levels, but applying consistent criteria enables more reliable enterprise reporting, aggregation, and prioritization.<\/span><\/p>\n<p><b>Question 343.<\/b><\/p>\n<p><b>A control identifies unauthorized access after it has already occurred. Which control type does this represent?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Preventive control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Compensating control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Detective control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk acceptance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Detective control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detective controls identify undesirable events, errors, or exceptions during or after they occur. Examples include log reviews, exception reports, transaction monitoring, and reconciliations. Preventive controls are designed to stop an event before it happens. A compensating control is an alternative safeguard used when a preferred control cannot be implemented, while risk acceptance is a treatment decision rather than a control type.<\/span><\/p>\n<p><b>Question 344.<\/b><\/p>\n<p><b>A policy exception is approved for six months. Which additional information is most important for sound governance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Browser version<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Knowledge article count<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> User-interface theme<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Expiration date, approver, rationale, and compensating safeguards**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Expiration date, approver, rationale, and compensating safeguards<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A policy exception should be governed carefully so it does not become a permanent undocumented bypass. Important information includes why the exception is necessary, who approved it, how long it remains valid, and what safeguards reduce the associated exposure. The exception should also be reviewed before expiration. This creates accountability and helps ensure temporary deviations are controlled and reassessed appropriately.<\/span><\/p>\n<p><b>Question 345.<\/b><\/p>\n<p><b>A newly acquired company uses different risk categories from the parent organization. What would best support enterprise-wide reporting?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Align the acquired company to a common risk taxonomy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete all acquired-company risks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Convert every risk into an issue<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Stop performing risk assessments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Align the acquired company to a common risk taxonomy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A common risk taxonomy improves consistency in classification and reporting across different parts of the organization. Aligning categories allows management to aggregate similar risks, identify concentration, and compare exposure across business units. Existing risks do not need to be deleted simply because their categories differ. Instead, mapping or standardizing them to the enterprise taxonomy improves reporting quality and governance.<\/span><\/p>\n<p><b>Question 346.<\/b><\/p>\n<p><b>A control has been remediated after a failed assessment. What should be completed before the related issue is considered fully resolved?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the original failure result<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Re-test the control and confirm the corrective action is effective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove the control owner<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Automatically accept the associated risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Re-test the control and confirm the corrective action is effective<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Remediation should be verified rather than assumed. Re-testing the control provides evidence that the corrective action addressed the original weakness and that the control now operates as expected. This supports defensible issue closure and prevents unresolved weaknesses from being hidden. Historical assessment results should generally remain available because they provide important evidence of the control and remediation lifecycle.<\/span><\/p>\n<p><b>Question 347.<\/b><\/p>\n<p><b>A risk owner wants to track whether exposure is moving closer to or farther from acceptable levels over time. Which information is most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policy font style<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Number of catalog items<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk indicators, thresholds, and trends<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Browser compatibility data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Risk indicators, thresholds, and trends<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk indicators provide measurable information about conditions related to exposure. Thresholds define levels that may require attention, while trends show whether those indicators are improving or deteriorating over time. Together, these elements support ongoing risk monitoring between formal assessment cycles. They can help management recognize changes early and decide whether additional treatment or reassessment is necessary.<\/span><\/p>\n<p><b>Question 348.<\/b><\/p>\n<p><b>An organization cannot implement a required control exactly as designed because of a technical limitation. What is the best next step?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the requirement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete the related risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Mark the control effective without evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Implement an appropriate compensating control and document the rationale**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Implement an appropriate compensating control and document the rationale<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control provides an alternative way to address the intended objective when the preferred control cannot be implemented. The organization should document why the original control is not feasible, how the alternative reduces the relevant exposure, and who approved the approach. The compensating control should also be assessed and monitored like other safeguards. Ignoring the requirement would leave the risk unmanaged.<\/span><\/p>\n<p><b>Question 349.<\/b><\/p>\n<p><b>Which record helps management maintain a consolidated view of known risks, owners, ratings, and treatment status?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Risk register<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Service catalog<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Knowledge base<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Change calendar<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Risk register<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk register provides a centralized view of identified risks and commonly includes information such as ownership, category, assessment results, treatment decisions, status, and residual exposure. It supports monitoring, prioritization, reporting, and governance. A service catalog and knowledge base serve operational and informational purposes but are not intended to provide an enterprise inventory of risk.<\/span><\/p>\n<p><b>Question 350.<\/b><\/p>\n<p><b>A control requires monthly evidence. Which evidence is most useful during a current-quarter assessment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evidence from several years ago<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Recent evidence covering the required assessment period<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A policy with no control relationship<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A risk owner\u2019s verbal statement only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Recent evidence covering the required assessment period<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Evidence should be relevant to the period being assessed and sufficiently current to demonstrate that the control continues to operate. Old evidence may show that the control existed historically, but it does not prove current performance. Recent evidence aligned with the control frequency gives assessors stronger support for their conclusions. Verbal confirmation alone is generally weaker than objective documentation.<\/span><\/p>\n<p><b>Question 351.<\/b><\/p>\n<p><b>A company wants to stop unauthorized changes before they are implemented. Which type of control is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Detective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Corrective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Preventive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Acceptance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Preventive<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Preventive controls are designed to stop undesirable events before they happen. Examples can include required approvals, access restrictions, segregation of duties, or automated validation checks. Detective controls identify problems after or during occurrence, while corrective controls address the consequences afterward. Risk acceptance is a treatment decision rather than a control type.<\/span><\/p>\n<p><b>Question 352.<\/b><\/p>\n<p><b>A policy has been replaced by a newly approved version. What should happen to the old version?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep both versions active indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Convert the old policy into a risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete all evidence linked to the old policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Retire or archive the superseded version according to policy governance**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Retire or archive the superseded version according to policy governance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A mature policy lifecycle includes controlled retirement or archival of obsolete versions. The superseded policy should no longer appear to be the current governing document, but historical versions may need to be retained for legal, audit, or governance purposes. Proper retirement avoids user confusion while preserving an appropriate historical record. Simply deleting old versions can remove valuable evidence of prior requirements and approvals.<\/span><\/p>\n<p><b>Question 353.<\/b><\/p>\n<p><b>What is the primary purpose of defining risk treatment actions with owners and due dates?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To make the selected treatment measurable and accountable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To remove the risk from the register immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for future assessments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To replace every related control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To make the selected treatment measurable and accountable<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk treatment actions convert a treatment decision into specific work that can be assigned and tracked. Owners establish responsibility, while due dates create measurable expectations for completion. These actions may involve implementing controls, changing processes, transferring exposure, or performing other remediation. The risk usually remains under monitoring until the treatment is complete and the resulting residual exposure is understood.<\/span><\/p>\n<p><b>Question 354.<\/b><\/p>\n<p><b>Why is separating control ownership from independent control testing useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It removes the need for evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It supports more objective assurance over control effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees that controls will never fail<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It eliminates control-owner responsibilities<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. It supports more objective assurance over control effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separating the person responsible for operating a control from the person evaluating it can improve objectivity. Independent testing reduces the chance that control performance is assessed solely by the person accountable for the activity. The control owner still remains responsible for operation and remediation, while the tester provides assurance based on evidence, procedures, and assessment criteria.<\/span><\/p>\n<p><b>Question 355.<\/b><\/p>\n<p><b>A significant business process changes after a system replacement. What should happen to the related risk assessment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It should automatically be closed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It should remain unchanged permanently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It should be reassessed because the exposure and controls may have changed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> All related requirements should be deleted<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. It should be reassessed because the exposure and controls may have changed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Material changes to systems, processes, organizational structures, or responsibilities can alter likelihood, impact, control effectiveness, and ownership. Reassessing affected risks helps ensure that recorded exposure remains accurate after the change. Existing controls may need to be reviewed or redesigned as well. Keeping an outdated risk score could give management a misleading view of current conditions.<\/span><\/p>\n<p><b>Question 356.<\/b><\/p>\n<p><b>Which approach is most appropriate when evidence requested for a control assessment is missing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume the control is effective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Close the assessment without comment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Delete the control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Document the evidence gap and evaluate whether it affects the assessment conclusion**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Document the evidence gap and evaluate whether it affects the assessment conclusion<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Missing evidence can limit the assessor\u2019s ability to conclude that a control operated effectively. The gap should be documented and evaluated according to the assessment methodology. Depending on significance, the organization may request additional evidence, record a deficiency, or adjust the assessment result. Automatically assuming effectiveness would weaken assurance and reduce the reliability of compliance reporting.<\/span><\/p>\n<p><b>Question 357.<\/b><\/p>\n<p><b>An enterprise wants to monitor the same control across several business entities. What is the main advantage of entity-based scoping?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It allows control performance and exposure to be evaluated in the correct business context<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for control owners<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees identical results for every entity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It removes the need for evidence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It allows control performance and exposure to be evaluated in the correct business context<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Entity-based scoping helps organizations evaluate risks, controls, and compliance requirements within the specific business areas they affect. A control may perform differently across applications, subsidiaries, processes, or vendors. Scoping assessments to relevant entities allows management to compare results and identify localized weaknesses. It does not guarantee identical outcomes or eliminate the need for ownership and evidence.<\/span><\/p>\n<p><b>Question 358.<\/b><\/p>\n<p><b>A control is tested using a sample of transactions rather than every transaction. What is the purpose of sampling?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To avoid collecting any evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To evaluate control performance using a representative subset when full testing is impractical<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To guarantee control effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To replace the control owner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To evaluate control performance using a representative subset when full testing is impractical<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Sampling allows an assessor to examine a subset of transactions or control executions when testing every item would be impractical. The sample should be selected according to an appropriate testing methodology so conclusions are reasonably supported. Sampling does not guarantee effectiveness, and poorly chosen samples can produce misleading results. Evidence and professional judgment remain important parts of the testing process.<\/span><\/p>\n<p><b>Question 359.<\/b><\/p>\n<p><b>A key risk indicator remains below its threshold but has deteriorated steadily for several reporting periods. What should management do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the trend because the threshold has not been crossed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Automatically close the related risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Review the trend because it may indicate worsening exposure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Retire all associated controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Review the trend because it may indicate worsening exposure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Thresholds provide useful trigger points, but trend direction can reveal emerging problems before a formal limit is exceeded. A steady deterioration may indicate that the underlying risk environment or control performance is changing. Management should investigate the cause and determine whether additional monitoring, treatment, or reassessment is necessary. Waiting for a threshold breach can delay action on a developing exposure.<\/span><\/p>\n<p><b>Question 360.<\/b><\/p>\n<p><b>What should an organization establish before heavily automating Risk and Compliance workflows?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A separate spreadsheet for every business unit<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Automatic closure of all overdue issues<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Maximum customization of every form<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Clear governance, roles, methodologies, data standards, and escalation rules**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Clear governance, roles, methodologies, data standards, and escalation rules<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automation works best when the underlying governance process is already clearly defined. Organizations should establish roles, risk and control methodologies, data standards, approval paths, assessment rules, and escalation expectations before automating workflows. Otherwise, technology may simply accelerate inconsistent or poorly governed processes. A strong governance foundation helps ensure that automation produces reliable, scalable, and auditable Risk and Compliance operations.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps &nbsp; Question 341. A risk indicator crosses its warning threshold before the related risk reaches an unacceptable score. What is the best use of this information? Ignore it until the risk score changes 2. Use it as an early warning and investigate the underlying condition [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18890"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18890"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18890\/revisions"}],"predecessor-version":[{"id":18891,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18890\/revisions\/18891"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18890"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18890"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18890"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}