📘 Free CIS-RC Sample Questions
Which of the following tables exist within the GRC: Profiles application scope? (Choose three.)
A
Document
B
Policy
C
Risk
D
Content
E
Indicator
Correct Answer:
A. Document
Explanation:
The correct answer identifies tables existing within the ServiceNow GRC: Profiles application scope, crucial
for managing organizational profiles and related elements. Here's a breakdown of why options A, D, and E are
correct, and why B and C are incorrect:
A. Document: The Document table (often named something like sn_compliance_document or similar depending
on the exact implementation) is a core element of the Profiles application. Organizations need to store and
manage documents related to their profiles, whether they're regulatory filings, standard operating
procedures, or other supporting materials. This aligns with the cloud computing concept of data management,
where structured storage and organization of documents within a cloud-based application are key. The Profile
type configuration will often relate to what documents should be kept.
D. Content: The Content table (or sn_grc_content or similar) isn't a direct profile-related table, but is connected
to the policy and compliance functions and is available within the GRC application scope. Content is related to
the storage of policy statements that are required for Profile compliance.
compliance.
E. Indicator: In the GRC: Profiles context, Indicators allow organizations to track key performance indicators
(KPIs) or key risk indicators (KRIs) that are associated with their profiles. This supports monitoring and
reporting, crucial aspects of compliance and risk management. It aligns with the cloud computing concept of
analytics and reporting, where GRC applications provide tools to visualize and analyze data related to risk and
B. Policy: While policies are crucial in GRC, the Policy table (or sn_compliance_policy typically) resides more
directly within the broader GRC: Policy and Compliance application scope, not solely the Profiles application.
The relationship is that profiles may be subject to specific policies.
C. Risk: The Risk table (often sn_risk_risk) also falls under the GRC: Risk Management application scope. While
organizational profiles are exposed to risks, the Risks are not directly stored against the Profiles. The Profiles
might be used to determine which risks are relevant to the profile.
In summary, the Document, Content and Indicator tables are directly relevant for managing profiles within the
GRC: Profiles application scope, facilitating effective profile maintenance, compliance, and risk monitoring.
Policies and Risks are related, but not directly stored against Profiles.
What are some characteristics of the ServiceNow Store? (Choose four.)
A
Some applications are certified by ServiceNow
B
All applications are certified by ServiceNow
C
Applications may be developed by ServiceNow Technology Partners
D
It houses both paid and free applications and integrations
E
Applications are built om the ServiceNow platform
F
Applications are certified by other developers
Correct Answer:
B. All applications are certified by ServiceNow
Explanation:
The provided answer, BCDE, correctly identifies characteristics of the ServiceNow Store. Let's break down
why:
B. All applications are certified by ServiceNow (Incorrect): This statement is incorrect. While ServiceNow
certifies many apps to ensure quality and security, not all apps are necessarily certified. Some might be
community-developed or earlier versions awaiting certification.
C. Applications may be developed by ServiceNow Technology Partners (Correct): The ServiceNow
ecosystem thrives on collaboration. Technology Partners are key contributors, developing applications that
extend the platform's functionality. This aligns with the platform-as-a-service (PaaS) model, where third-party
developers can build on the core platform.
D. It houses both paid and free applications and integrations (Correct): The ServiceNow Store offers a
variety of apps and integrations, some available for free and others requiring a purchase. This is a typical
marketplace model, providing options to suit different needs and budgets.
both paid and free options.
Supporting Resources:
E. Applications are built on the ServiceNow platform (Correct): Applications in the ServiceNow Store
leverage the platform's underlying infrastructure, including its workflow engine, data model, and UI
framework. This ensures seamless integration and consistent user experience. This is fundamental to
ServiceNow's PaaS offering.
In conclusion, the ServiceNow Store is a marketplace built on the ServiceNow platform, offering a range of
applications and integrations, developed by both ServiceNow and its Technology Partners, and available in
ServiceNow Store: https://store.servicenow.com/ (This link provides direct access to the ServiceNow Store,
allowing you to explore available applications and integrations.)
ServiceNow Technology Partner Program: Search for "ServiceNow Partner Program" on the official
ServiceNow website. (Provides details on the program that enables partners to develop and offer solutions in
Which role is not part of ServiceNow GRC?
A
Risk User
B
Risk Developer
C
Risk Manager
D
Risk Reader
Correct Answer:
B. Risk Developer
Explanation:
The correct answer is B. Risk Developer is not a standard, out-of-the-box role in ServiceNow GRC
(Governance, Risk, and Compliance). While developers are crucial for customizing and extending the
ServiceNow platform, including GRC applications, there isn't a specific dedicated "Risk Developer" role that
directly grants permissions within the GRC module itself. Instead, developers leverage roles like admin or
potentially custom roles granted specific access to GRC tables and functionalities.
Risk User, Risk Manager, and Risk Reader are all standard roles within ServiceNow GRC.
Risk User: Can create and manage risk events, tasks, and assessments. They are involved in the day-to-day
operations of risk management.
Risk Manager: Oversees the entire risk management program, defines policies, assigns tasks, and reviews
risk data. They have broader administrative privileges within the Risk application.
Risk Reader: Primarily has read-only access to risk information, allowing them to view reports, dashboards,
and other relevant data without the ability to modify anything. This role is suitable for stakeholders who need
visibility into the organization's risk posture.
Further Research:
The need for development-related activities in GRC environments is recognized; however, they are typically
handled by developers who are assigned existing roles that give them general admin capabilities on the
instance or are provided granular permissions through custom roles created by the customer. These custom
roles are then tailored based on the precise development tasks being executed within the GRC environment,
rather than through a single "Risk Developer" role included within the GRC module itself. These developers
would be expected to adhere to DevOps principles and follow standard software development processes
when working on any customizations for the GRC application to keep compliance integrity.
ServiceNow GRC Documentation: Check the official ServiceNow documentation for the specific version of
GRC you're interested in. It will list the available roles and their associated permissions. [Search "ServiceNow
GRC roles" in the ServiceNow product documentation portal]
ServiceNow Community Forums: Review ServiceNow community discussions to see how organizations handle
development-related tasks within their GRC environments. [Search "ServiceNow GRC Development" on the
ServiceNow Community site]
Which of the following statements is true of a Risk Response task?
A
Only one Risk Response task can be related to a Risk at a time
B
Only users with the risk_manager role or higher can be assigned to a Risk Response task
C
The risk admin role is required to assign the Risk Response task
D
The Risk Response task is automatically progressed through the states using a workflow
Correct Answer:
D. The Risk Response task is automatically progressed through the states using a workflow
Explanation:
The correct answer is D: "The Risk Response task is automatically progressed through the states using a
workflow."
Here's why: Risk Response tasks in ServiceNow's Risk Management module are designed to be automated
and guided. A workflow drives the task's progression through different states (e.g., Open, Work in Progress,
Closed). This automation ensures consistency and efficiency in handling risk responses. The workflow defines
the sequence of actions, approvals, and notifications required to manage the risk response effectively.
Option A is incorrect because multiple Risk Response tasks can be related to a single Risk, as different
responses may be required to mitigate various aspects of the risk or different risk factors.
Option B is incorrect because the roles required to be assigned to a Risk Response task may vary based on the
configuration and complexity of the task. The 'risk_manager' role is not necessarily required; it might be a
lower-level role that is assigned depending on the specific business needs.
Option C is incorrect because the "risk_admin" role is not required to assign the Risk Response task. A user
with appropriate permissions, such as a risk owner or risk analyst, might be able to assign the task, depending
on the system's configuration. The workflow, not a specific role, drives the task.
Relevant Documentation:
In summary, ServiceNow uses workflows to ensure consistent and automated progression of Risk Response
tasks. This removes manual intervention and provides a streamlined process.
ServiceNow Risk Management: https://docs.servicenow.com/bundle/utah-governance-risk-
compliance/page/product/grc/concept/risk-management.html
ServiceNow Workflow: https://docs.servicenow.com/bundle/utah-
platform/page/administer/workflow/concept/workflow.html
What table, along with the Policy table, is linked to the Control Objective table by a many-to-many relationship?
A
Entity Class
B
Citation
C
Authority Documents
D
Risk Framework
Correct Answer:
B. Citation
Explanation:
Here's a detailed justification for why the correct answer is B. Citation, along with authoritative links for
further research:
The Control Objective table in ServiceNow's Risk and Compliance application establishes many-to-many
relationships with both the Policy and the Citation tables. This means a single Control Objective can be related
to multiple Policies and multiple Citations, and vice-versa.
Why Citation? Citations represent specific clauses, sections, or references within external Authority
Documents or internal Policies that a Control Objective is designed to satisfy or comply with. Think of citations
control objective may require compliance with multiple citations.
as the granular pieces of legal text, standards, or frameworks. Each control objective might refer to several
citations spanning multiple authoritative sources. For example, a control objective focused on data encryption
could cite a specific clause in GDPR and a section from a NIST cybersecurity framework. Therefore, a many-
to-many relationship is suitable because one citation can be related to multiple control objectives, and one
Why not Entity Class? Entity Classes are used to categorize different types of entities within an organization,
such as business processes, applications, or systems. While Control Objectives are associated with Entities
(through the Entity Type and Entity fields), the relationship is not a many-to-many link via a separate table. It's
more of a direct association.
Why not Authority Documents? Authority Documents are related to Citations. The relationship between
Control Objective and Authority Documents is indirect, achieved via the Citation table which links the Control
Objective to the specific part of the Authority Document.
Why not Risk Framework? While Risk Frameworks are related to Policies, which are then connected to
Control Objectives, the Risk Framework is not directly linked to the Control Objective through a many-to-many
relationship. Instead, the Risk Framework influences the policies.
In summary, the Citation table serves as the crucial intermediary, creating a many-to-many link between
Control Objectives and the specific regulatory, legal, or policy requirements they address. The many-to-many
relationship is fulfilled by a table joining the two others (Citation and Control Objective), where you create
relationships between them.
Here are some authoritative links:
1. ServiceNow Product Documentation - GRC: This is the primary source for understanding
ServiceNow's GRC capabilities. While specific table relationships might not always be explicitly
diagrammed, exploring the documentation on Policies, Control Objectives, and Citations will reveal
their interdependencies.
Search ServiceNow Docs for "GRC Control Objective," "GRC Policy," and "GRC Citation."
2. ServiceNow Community Forums: The ServiceNow community is a valuable resource for asking
questions and finding solutions related to ServiceNow implementations. Search for discussions about
the relationships between Policies, Control Objectives, and Citations.
ServiceNow Community
By examining these resources, you can gain a comprehensive understanding of the relationships between
these tables and how they contribute to the overall functionality of ServiceNow's GRC module.
Why would you create Entity classes?
A. To show relationships between tables or objects you are tracking that doesn’t otherwise exist anywhere in
ServiceNow
B. To be assigned to risk statements, which generate risks for every Entity listed in the Entity Class
C. To be assigned to Control Objectives, which generate Controls for every Entity listed in the Entity class
D. To show relationships between Entities and Policies and map them directory to Citations
A
To show relationships between tables or objects you are tracking that doesn’t otherwise exist anywhere in
ServiceNow
B
To be assigned to risk statements, which generate risks for every Entity listed in the Entity Class
C
To be assigned to Control Objectives, which generate Controls for every Entity listed in the Entity class
D
To show relationships between Entities and Policies and map them directory to Citations
Correct Answer:
A. To show relationships between tables or objects you are tracking that doesn’t otherwise exist anywhere in
ServiceNow
Explanation:
The correct answer is A. To show relationships between tables or objects you are tracking that doesn’t
otherwise exist anywhere in ServiceNow.
Entity Classes in ServiceNow's Risk and Compliance module serve as a way to represent a group or
classification of Entities. Entities represent specific objects (applications, servers, databases, business
processes, etc.) that are subject to risks and controls. While ServiceNow inherently has relationships between
various tables (e.g., business application to server), Entity Classes are specifically helpful when you need to
define new or custom relationships that aren't already modeled within the platform's standard data model.
Options B and C are incorrect because while Entity Classes are used in conjunction with Risk Statements and
Control Objectives, they don't directly generate Risks or Controls for every Entity listed. You would need to
associate specific Entities to Risk Statements or Control Objectives for the controls/risks to become
applicable. Entity Classes help in efficient association by providing a mechanism to quickly apply these to a
group.
Option D is also incorrect. While relationships between Entities and Policies exist and can be mapped (and the
Policy module does use Citations), Entity Classes primarily exist for defining broader relationships between
entities which may then be used to link to Policies. The core purpose isn't to directly map Entities to Citations.
In essence, Entity Classes fill the gap when the standard ServiceNow data model doesn't fully capture the
relationships between the objects that are relevant to your organization's risk and compliance posture. They
are a powerful tool for categorizing entities and defining new organizational structures for risk management.
For further research and authoritative information:
ServiceNow Documentation on Entity Classes: While direct links to specific ServiceNow documentation on
Entity Classes are difficult to maintain due to ServiceNow's frequent updates, a search within the ServiceNow
product documentation (accessible with a ServiceNow instance) for "Entity Class" and "GRC" (Governance,
Risk, and Compliance) will yield the most current information.
The Tablename.config:
A
Displays the configuration list view of the table in the browser tab
B
Displays the table in list view within the Content Frame
C
Displays the table in list view within a separate browser tab
D
Displays the configuration list view of the table in the Content Frame
Correct Answer:
D. Displays the configuration list view of the table in the Content Frame
Explanation:
The correct answer is D because Tablename.config in ServiceNow typically refers to a way to access the
configuration list view of a specific table within the platform. The configuration list view allows administrators
and developers to see and manage configuration details related to that table, such as UI policies, client
scripts, business rules, and other customizations. Because ServiceNow applications run within a browser,
accessing Tablename.config usually presents the configuration information within the ServiceNow user
interface, not in a new browser tab or separate window (which options A and C suggest). The main user
interface area where ServiceNow displays information is often called the Content Frame. Therefore,
displaying the configuration list view of the table in the Content Frame accurately describes the effect of
Tablename.config. Option B is incorrect as it does not display configuration information, but instead only shows
a listing of the table's records.
The Tablename.config is a shortcut to access the configuration record list, which is extremely helpful for
developers and administrators. This allows easy navigation to table-specific configurations and helps when
debugging or understanding how a table is configured. Direct links to configurations improve workflow by
avoiding the need to search for configurations through various system administration modules. It efficiently
displays the configurations in the main content area, aligning with ServiceNow's user interface design.
For further research on ServiceNow table configurations and UI navigation, refer to the official ServiceNow
documentation. While a specific page about Tablename.config might not exist as it's a direct URL convention,
understanding table administration and UI elements is crucial. Look into topics such as:"System Definition > Tables"
"UI Policies"
"Client Scripts"
"Business Rules
These resources on the ServiceNow documentation site will provide a deeper understanding of how tables are
structured and configured within the ServiceNow platform. Understanding the relationship between tables
and associated Ul elements is fundamental to effective ServiceNow development and administration.
Which of the following extends from items?
A
Citation
B
.Controls
C
Issue
D
Policy
Correct Answer:
B. .Controls
Explanation:
The correct answer is B. Controls. Here's a detailed justification:
In ServiceNow's Risk and Compliance application, several tables extend from the GRC: Item table.
CIS-RC
Understanding this hierarchy is crucial for implementation and customization. Controls directly relate to
managing risks and ensuring compliance by implementing specific measures. These measures are
documented and managed within the 'Controls' table, which inherits attributes and functionalities from the
base 'Item' table. This inheritance allows for standardized data structures, workflow management, and
reporting across different compliance areas.
the Item.
implemented.
architecture.
A control is a preventative or detective measure implemented to mitigate a risk and enforce compliance with
policies, regulations, or standards. Because a Control is something that is actively performed it inherits from
Citations are more about referencing rules or regulations. Issues represent problems or gaps found during
audits or assessments. Policies outline organizational standards or requirements. While Issues and Policies
might indirectly relate to items, they don't directly extend from the Item table in the same way Controls do.
Issues generally relate to remediation tasks. Policies may have items such as citations that must be
The Item table provides the basic structure for all record types within the Risk and Compliance application.
The Control table inherits common attributes such as description, assigned to, and state, but also adds
specialized fields related to control objectives, test plans, and effectiveness assessment. This specialized
extension makes Controls the most appropriate answer in the context of ServiceNow's Risk and Compliance
Therefore, the Control record is where you are creating, managing, and performing some task, which an item is
most closely related to.
For further research, you can refer to the official ServiceNow documentation on the GRC application:
ServiceNow GRC Overview: https://www.servicenow.com/products/governance-risk-compliance.html
ServiceNow Documentation (search for GRC tables and hierarchy): https://docs.servicenow.com/ (Requires
ServiceNow login)
Specifically, search the ServiceNow documentation for "GRC Data Model" to see the relationships between
tables within the GRC module. This will help clarify the inheritance structure and the role of the Item table.
What happens when you assign an Entity Type to a Risk Statement?
A
An assessment will be automatically generated to test each Entity listed in the Entity Type
B
A risk assessment is created automatically for every Entity listed in the Entity Type
C
A risk is automatically generated for every Entity listed in the Entity Type
D
A risk is automatically generated for every Entity listed in the Entity Type
Correct Answer:
C. A risk is automatically generated for every Entity listed in the Entity Type
Explanation:
Here's a detailed justification for why answer C is the correct choice, explaining the relationship between
Entity Types, Risk Statements, and Risks in ServiceNow GRC:
The core principle here lies in understanding how ServiceNow's Risk and Compliance application models risk.
A Risk Statement represents a generalized potential risk. When you associate an Entity Type with a Risk
Statement, you're essentially saying, "This risk statement applies to all Entities of this type."
Answer C, "A risk is automatically generated for every Entity listed in the Entity Type," accurately reflects
this. When you assign an Entity Type to a Risk Statement, the system automatically creates individual Risk
records for each Entity within that Entity Type. Each Risk record will then inherit properties from the linked
Risk Statement, giving you a concrete, instance-level risk assessment for each affected Entity. This is how
ServiceNow operationalizes risk management, moving from a general statement to tangible instances of risk
impacting specific entities. This is crucial for assigning ownership, tracking remediation efforts, and
calculating risk scores at the individual entity level.
Now, let's examine why the other options are less accurate.
A. An assessment will be automatically generated to test each Entity listed in the Entity Type: While
assessments are related, they are not automatically triggered by the initial assignment of an Entity Type to a
Risk Statement. Assessments are typically initiated based on a defined schedule or other triggering events,
and they test the risk, not directly represent it.
B. A risk assessment is created automatically for every Entity listed in the Entity Type: This is close, but
subtly incorrect. It creates risks not an independent risk assessment record.
D. The Entity is now going to present a risk score and controls are going to be tied to it: This is partially true
as Risk scores would subsequently be related to the Entity when a Risk is associated with it.
Therefore, only option C accurately captures the immediate outcome of associating an Entity Type with a Risk
Statement.
Here are some relevant links for further research:
ServiceNow Docs - Risk Management: https://docs.servicenow.com/bundle/vancouver-governance-risk-
compliance/page/product/risk-management/concept/risk-management-overview.html
ServiceNow Community Forums - Risk Management: Search the ServiceNow Community for discussions and
examples related to Risk Statements and Entities.
There is a direct relationship between Entity Class and Entity Type when:
A
They have the same Entity Types
B
There is no direct relationship
C
They have the same Entities
D
They leverage the same reporting
Correct Answer:
B. There is no direct relationship
Explanation:
The correct answer is B. There is no direct relationship.
Here's why:
In ServiceNow's Governance, Risk, and Compliance (GRC) module, specifically within Risk and Compliance,
Entity Class and Entity Type serve distinct purposes related to organizing and categorizing entities (like
applications, systems, or business processes) that are subject to risk assessments, controls, and compliance
requirements.
An Entity Class is a high-level grouping of entities, often reflecting organizational departments or functional
areas (e.g., "IT," "Finance," "Human Resources"). It provides a broad classification mechanism. Think of it as
the top level of a classification hierarchy.
might have Entity Types like "Server" or "Database."
An Entity Type defines the specific nature of the entity (e.g., "Server," "Database," "Application," "Policy"). It
provides a more granular categorization within an Entity Class. For example, within the "IT" Entity Class, you
While an Entity Type is associated with an Entity Class (you select the Entity Class when creating or
configuring an Entity Type), there isn't a direct, fixed relationship enforcing that they must share the same
types or entities. The purpose of defining both is to allow for flexible categorization. You can have different
Entity Types within the same Entity Class, and an Entity Type can even (though not best practice in most
scenarios) be associated with multiple Entity Classes. The relationship is hierarchical, not directly equivalent.
They do not need to have the same entities, and leveraging the same reporting is more of a consequence of
their association than a direct relationship driver.
Therefore, the statement that there is a direct relationship between Entity Class and Entity Type when they
have the same Entity Types or Entities, or leverage the same reporting is incorrect. The relationship is about
classification and association within the GRC framework, not direct equivalence. The association facilitates
hierarchical organization, rather than demanding identical contents or types.
Useful links (while not a direct "Servicenow documentation" link to the exact question, they help understand
the relationship between entity classes and entity types):
ServiceNow GRC Overview: (Search on ServiceNow docs for) "Governance, Risk, and Compliance (GRC)" to
understand the general context.
ServiceNow Entity Management: (Search on ServiceNow docs for) "GRC Entity Management" to explore the
role of entities in GRC.
Questions: 1-10 out of 239
Continue Full Practice..
GET ALL 239 QUESTIONS