{"id":18892,"date":"2026-09-22T10:28:14","date_gmt":"2026-09-22T10:28:14","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18892"},"modified":"2026-09-22T10:28:14","modified_gmt":"2026-09-22T10:28:14","slug":"servicenow-cis-rc-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/servicenow-cis-rc-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"ServiceNow CIS-RC Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cis-rc-exam-dumps\"><b>ServiceNow CIS-RC Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 361.<\/b><\/p>\n<p><b>An organization wants an early-warning metric that signals when a business condition may be increasing risk exposure. Which concept best fits this need?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policy acknowledgment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Key risk indicator<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Control objective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Issue closure evidence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Key risk indicator<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A key risk indicator, or KRI, is a measurable value used to monitor conditions that may signal increasing or decreasing risk exposure. KRIs are often associated with thresholds and trends so management can identify changes before a formal risk assessment cycle occurs. A policy acknowledgment confirms policy review, while control objectives describe intended control outcomes. Issue closure evidence supports remediation verification rather than providing ongoing risk-warning information.<\/span><\/p>\n<p><b>Question 362.<\/b><\/p>\n<p><b>A risk indicator remains within its threshold but moves steadily in an unfavorable direction for five reporting periods. What should management do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review the trend and investigate whether exposure is increasing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the indicator until the threshold is breached<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automatically accept the related risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete the associated control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Review the trend and investigate whether exposure is increasing<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Trend information can provide valuable warning before a formal threshold is crossed. A steadily worsening indicator may signal changes in the business environment, control performance, or underlying exposure. Management should review the cause and determine whether additional monitoring, treatment, or reassessment is appropriate. Waiting until the threshold is exceeded can delay action. The trend does not automatically prove the risk has increased, but it provides a reason for further investigation.<\/span><\/p>\n<p><b>Question 363.<\/b><\/p>\n<p><b>Which statement best describes the relationship between risk appetite and risk tolerance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They are always identical terms<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Risk tolerance applies only to control testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk appetite is broad, while risk tolerance usually defines more specific acceptable limits<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk appetite is used only after an issue is closed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Risk appetite is broad, while risk tolerance usually defines more specific acceptable limits<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk appetite provides broad guidance about the amount and type of risk an organization is willing to pursue or retain. Risk tolerance typically translates that broad guidance into more specific limits, ranges, or acceptable variations for particular risks or activities. Together, they support decision-making and escalation. Neither concept is limited to control testing or issue closure, and they should not automatically be treated as identical.<\/span><\/p>\n<p><b>Question 364.<\/b><\/p>\n<p><b>A preferred preventive control cannot be implemented because of a legacy-platform limitation. What is the best governance response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the requirement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Mark the unavailable control as effective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automatically accept the risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Implement and document an appropriate compensating control**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Implement and document an appropriate compensating control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control provides an alternative safeguard when the preferred control cannot be implemented. The organization should document why the primary control is unavailable, what alternative control is being used, how it addresses the intended objective, and who approved the approach. The compensating control should also be assessed and monitored. Simply marking an unavailable control effective would weaken governance and could create an inaccurate view of compliance.<\/span><\/p>\n<p><b>Question 365.<\/b><\/p>\n<p><b>What is the primary purpose of a preventive control?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To reduce the likelihood of an undesirable event before it occurs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To record a risk after it is accepted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To identify an event only after it occurs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To archive obsolete policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To reduce the likelihood of an undesirable event before it occurs<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Preventive controls are intended to stop or reduce the likelihood of undesirable events before they happen. Examples can include approval requirements, access restrictions, validation checks, and segregation of duties. Detective controls identify problems during or after occurrence, while corrective activities address consequences afterward. Preventive controls therefore play an important role in reducing exposure before an adverse event materializes.<\/span><\/p>\n<p><b>Question 366.<\/b><\/p>\n<p><b>A transaction-monitoring process identifies suspicious activity after transactions have already been processed. Which type of control is this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Preventive<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Detective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Compensating<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Risk acceptance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Detective<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Detective controls identify errors, exceptions, or undesirable activity during or after occurrence. Transaction monitoring, reconciliations, exception reports, and log reviews are common examples. Preventive controls attempt to stop an event beforehand. A compensating control is an alternative safeguard used when a preferred control is unavailable, while risk acceptance is a treatment decision rather than a control classification.<\/span><\/p>\n<p><b>Question 367.<\/b><\/p>\n<p><b>An organization wants to group risks consistently into categories such as strategic, operational, compliance, and technology. What should it establish?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policy exception schedule<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Control-testing calendar<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk taxonomy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Evidence-retention issue<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Risk taxonomy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk taxonomy provides a structured set of categories and subcategories used to classify risks consistently. This improves reporting, aggregation, comparison, and enterprise visibility. A common taxonomy also helps different business units use the same terminology when discussing exposure. It does not change the underlying risk itself, but it makes risk data easier to organize, analyze, and communicate across the organization.<\/span><\/p>\n<p><b>Question 368.<\/b><\/p>\n<p><b>A policy has been replaced by a newly approved version. What should happen to the superseded policy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep both versions active indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Delete all historical evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Convert the old version into a control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Retire or archive it according to the policy lifecycle**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Retire or archive it according to the policy lifecycle<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Superseded policies should generally be retired or archived so users are not confused about which version is current. Historical versions may still need to be preserved for legal, audit, or governance purposes. A mature policy lifecycle includes drafting, review, approval, publication, periodic review, revision, and retirement. Deleting all historical records can remove important evidence about prior obligations and approvals.<\/span><\/p>\n<p><b>Question 369.<\/b><\/p>\n<p><b>A policy exception is approved temporarily. Which information is most important for preventing the exception from becoming an uncontrolled permanent deviation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Expiration date and review requirement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Browser version<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Knowledge article rating<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Interface theme<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Expiration date and review requirement<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Temporary exceptions should have clear expiration and review requirements so they do not remain active indefinitely without governance oversight. Good exception management also includes rationale, approver, scope, associated risk, and compensating safeguards. The exception should be reassessed before expiration and either closed, renewed, or replaced with a permanent solution. Interface settings and knowledge ratings do not support exception governance.<\/span><\/p>\n<p><b>Question 370.<\/b><\/p>\n<p><b>A control was remediated after failing an assessment. What is the best next step before considering the issue resolved?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the original assessment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Re-test or reassess the control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Automatically lower the risk score<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the control owner<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Re-test or reassess the control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Re-testing verifies whether remediation actually corrected the original weakness. Without verification, the organization cannot confidently conclude that the control now operates effectively. The original assessment should usually remain part of the historical record, and issue closure should be supported by appropriate evidence. Successful remediation may influence the related risk assessment, but the risk score should not simply be lowered automatically without evaluating the actual effect.<\/span><\/p>\n<p><b>Question 371.<\/b><\/p>\n<p><b>Why should control evidence be recent enough to cover the relevant assessment period?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To make policies easier to publish<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To reduce the number of business entities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To demonstrate current rather than merely historical control performance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for testing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To demonstrate current rather than merely historical control performance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Evidence should support conclusions about the period being assessed. Old documentation may show that a control operated in the past, but it does not necessarily prove current performance. Evidence freshness is especially important for recurring controls that operate monthly, quarterly, or continuously. Current evidence helps assessors determine whether the control remains effective and reduces the risk of relying on outdated information.<\/span><\/p>\n<p><b>Question 372.<\/b><\/p>\n<p><b>A major system implementation significantly changes a business process and its control environment. What should happen to related risks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> They should remain unchanged until the next routine cycle<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> They should automatically be accepted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> They should be deleted and recreated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> They should be reassessed because exposure and controls may have changed**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. They should be reassessed because exposure and controls may have changed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Major changes to systems, processes, organizational structures, or responsibilities can affect likelihood, impact, control effectiveness, and ownership. Reassessment helps ensure that risk information still reflects actual conditions. Related controls and treatment plans may also require review. Waiting for a routine cycle could leave management relying on outdated risk information during a period of significant change.<\/span><\/p>\n<p><b>Question 373.<\/b><\/p>\n<p><b>What is the main purpose of a risk register?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To maintain a consolidated inventory of identified risks and key risk information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To publish employee policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To store only closed issues<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To replace control evidence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To maintain a consolidated inventory of identified risks and key risk information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A risk register provides a centralized inventory of known risks and commonly includes information such as ownership, category, status, assessment results, treatment decisions, and residual exposure. It supports monitoring, prioritization, reporting, and governance. A risk register does not replace policies, issues, or evidence. Instead, it provides a structured view of the organization\u2019s identified risk landscape.<\/span><\/p>\n<p><b>Question 374.<\/b><\/p>\n<p><b>Why is a common risk-scoring methodology useful across multiple business entities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It guarantees every entity receives the same scores<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It improves consistency and comparability of assessment results<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for risk owners<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It prevents all residual risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. It improves consistency and comparability of assessment results<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A common methodology establishes consistent definitions, scales, and criteria so similar risks are evaluated in a comparable way across entities. This improves enterprise reporting, aggregation, and prioritization. Different entities may still receive different scores because their exposures differ. Consistency in methodology does not eliminate ownership or residual risk, but it makes results more meaningful when compared across the organization.<\/span><\/p>\n<p><b>Question 375.<\/b><\/p>\n<p><b>A compliance assessment cannot obtain required evidence for a control. What should the assessor do?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume the control is effective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the missing evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Document the evidence gap and evaluate its effect on the assessment conclusion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Delete the control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Document the evidence gap and evaluate its effect on the assessment conclusion<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Missing evidence can prevent an assessor from reaching a reliable conclusion about control effectiveness. The gap should be documented and evaluated according to the assessment methodology. Depending on significance, the organization may request additional evidence, record a deficiency, or adjust the assessment result. Assuming effectiveness without support would weaken assurance and could create inaccurate compliance reporting.<\/span><\/p>\n<p><b>Question 376.<\/b><\/p>\n<p><b>An organization uses automated feeds to monitor risk indicators daily. What is the greatest advantage of this approach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It eliminates the need for risk governance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It guarantees that risks never exceed tolerance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It removes all manual assessments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It can identify changing risk conditions more quickly**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. It can identify changing risk conditions more quickly<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automated and continuous monitoring can provide more timely information about risk conditions than periodic manual reviews alone. Threshold breaches, unusual patterns, or deteriorating trends may be identified sooner, giving management more time to respond. Human oversight remains important for interpreting results and making treatment decisions. Continuous monitoring improves timeliness but does not guarantee that risks remain within acceptable limits.<\/span><\/p>\n<p><b>Question 377.<\/b><\/p>\n<p><b>Why can separating control ownership from control testing strengthen assurance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It can provide a more independent evaluation of control effectiveness<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for control owners<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It guarantees a passing result<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It removes all evidence requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. It can provide a more independent evaluation of control effectiveness<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Separating ownership from testing helps reduce conflicts of interest and provides greater objectivity. The control owner remains responsible for operating and maintaining the control, while an independent tester evaluates design, execution, and evidence. This separation can strengthen confidence in assessment results. It does not guarantee that the control will pass, and testers still need appropriate evidence to support their conclusions.<\/span><\/p>\n<p><b>Question 378.<\/b><\/p>\n<p><b>A risk treatment plan contains multiple remediation actions. Why should each action have an owner and due date?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To automatically eliminate the risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To make treatment execution accountable and measurable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To replace the risk assessment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To prevent future monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To make treatment execution accountable and measurable<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Owners and due dates turn a treatment plan into actionable work. Ownership establishes responsibility, while due dates create measurable expectations for completion and enable escalation when activities become overdue. Treatment actions may involve implementing controls, changing processes, or other risk-reduction activities. The risk should still be monitored and reassessed as treatment progresses, because assigning actions alone does not eliminate exposure.<\/span><\/p>\n<p><b>Question 379.<\/b><\/p>\n<p><b>An organization wants to assess the same compliance requirement across multiple subsidiaries while preserving local context. What is most useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A separate unrelated framework for every subsidiary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> One global issue with no entity information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Entity-based scoping of assessments and controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Removing all common controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Entity-based scoping of assessments and controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Entity-based scoping allows an organization to apply common requirements while evaluating control performance in the specific context of each subsidiary, application, process, or other business entity. This helps identify localized weaknesses and compare results across entities. Common controls can still be reused where appropriate. Removing entity context would make it harder to understand where compliance strengths and deficiencies actually exist.<\/span><\/p>\n<p><b>Question 380.<\/b><\/p>\n<p><b>What foundation should be established before extensive automation of Risk and Compliance workflows?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Maximum form customization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Automatic closure of overdue issues<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Separate spreadsheets for each department<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Clear governance, ownership, methodologies, data standards, and escalation rules**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Clear governance, ownership, methodologies, data standards, and escalation rules<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automation is most effective when the underlying governance model is already defined. Organizations should establish clear ownership, risk and control methodologies, data standards, approval requirements, assessment rules, and escalation paths before automating workflows. Otherwise, automation may simply accelerate inconsistent or poorly designed processes. A strong governance foundation helps ensure that automated Risk and Compliance activities remain reliable, scalable, and auditable.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full ServiceNow CIS-RC Exam Dumps and Practice Test Dumps &nbsp; Question 361. An organization wants an early-warning metric that signals when a business condition may be increasing risk exposure. Which concept best fits this need? Policy acknowledgment 2. Key risk indicator 3. Control objective 4. Issue closure evidence Correct Answer: 2. Key risk indicator [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18892"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18892"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18892\/revisions"}],"predecessor-version":[{"id":18893,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18892\/revisions\/18893"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18892"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18892"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18892"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}