CIS – Risk and Compliance Brain Dump Flashcards

1
Q

what is not a key Compliance Indicator

A

Reference

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Types of key Compliance Indicator

A

Basic
Manual
PA Indicator
Scripted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Who should be on the core implementation team for a GRC implementation?

A

Risk and compliance experts

ServiceNow developer team

CMDB Expert

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

which response task helps in reducing overall risk

A

mitigate

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which of the following extends from items

A

controls

policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does a restricted script include that processes Risk responses?

A

RiskUtilsBaseV2

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The Entity Filter record requires which mandatory field to be completed?

A

Conditions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what implementers have to do to configure confidentiality?

A

Configure and identify allowed user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

UCF Control documents import into which table in ServiceNow?

A

Authority Documents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

In classic risk assessment, SLE can be used to calculate the Risk Rating, what other factors impact the risk rating?

A

Control test failure and indicator failure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Once all Approvals are received, the Policy is in which state?

A

published

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which table extends from Content Table?

A

Risk Statement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What tables are extended using the document table in GRC

A

Policy

Authority document

Risk Framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SLA definitions can be created on which tables

A

Issue

Risk response task

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What feature would you use to build out a hierarchy and relationships between entities within the organization?

A

Profile Types and Profiles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Select the correct statement about Risk Scoring formulas

A

SLE X ARO = ALE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What new related list was added to the risk statement and entity records after migrating to advanced risk assessment?

A

Aggregated risk related list

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Commonly used tables when profile scoping include

A

Location
Company
Department
Asset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

what role is given to external auditor team to view all policies and controls

A

sn_audit.external_auditor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Which of the following tables exist within the GRC: Profiles application scope?

A

Document

Content

Indicator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What does risk register consist of?

A

The repository of all Identified Risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

which assessments can be configured in RAM

A

Inherent

Residual

Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

True/ False: An entity type can contain entities from different entity classes and tiers.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is the relationship table that relates Risks to controls?

A

sn_risk_m2m_risk_control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What minimum role is needed to bulk initiate risk assessments using the risk assessment scheduler?

A

sn_risk.manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What ensures that every time you create a Profile from a specific table, the Class of the Profile is set according to the rule?

A

Profile class rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Table that stores relationships for Entities?

A

sn_grc_m2m_profile_profile_type

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

While Policy Records are in Review state, reviewers can do what?

A

Send the Policy forward by requesting approval

Send the Policy back to Draft

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

ServiceNow GRC helps eliminate an old inefficient work model by removing what?

A

Silos

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

“Santa Clara Facility” and “Boston Facility” are examples of what?

A

Profiles

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

All the following are PARENT tables which exist within the GRC Entities application scope EXCEPT.

A

Indicator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Which roles are inherited when a user is given the sn_audit.user role?

A

sn_grc.reader

sn_compliance.reader

sn_risk.reader

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What is the condition that must exist to edit the factor guidance of a published risk assessment methodology (RAM)

A

All assessment instance records are deleted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

reasons customers see for implementing GRC

A

efficiency

workflow driven

integrated reporting and transparency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Which of the following statements correctly describe the risk management lifecycle process?

A

Identify and Plan, Assess, Control, Review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

The compliance score calculation may be modified by changing which control factor?

A

Control Weight

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Which field in Policy works on redlining functionality in Office365?

A

Contributor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Concerning the two approaches to customer frameworks:
1) The Unified Compliance Framework (UCF)
2) Customer Controls, which statement is true?

A

Both approaches can be used, with no designation necessary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

Which role/s can create the Policy Acknowledgements?

A

Compliance User

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

common tables used in entity filters

A

location

service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

In ServiceNow Alex primarily leverages the Audit Management application to acknowledge and manage the audit tasks and activities that are assigned to her. Which role is assigned to Alex?

A

An audit user

42
Q

Santa Clara and one more datacenter are examples of:

A

Entities

43
Q

Certain Profiles associated to a Risk have a greater Single Loss Expectancy. What option is available?

A

Adjust the SLE for that Profile

44
Q

Advanced planning capability with PPM enables which related lists on engagement form?

A

Resource plan

Time card

Cost plan

45
Q

What happens when you assign an Entity Type to a Risk Statement?

A

A risk is automatically generated for every Entity listed in the Entity Type

46
Q

What table extends from Document Table?

A

Risk Framework

47
Q

A Risk Register is:

A

Repository for all identified risks

48
Q

Which of the following are tables in the GRC: Policy and Compliance scope?

A

Control

Citation

49
Q

Which of the following are the classic risk score types that ServiceNow tracks?

A

Residual

Inherent

Calculated

50
Q

Which of the following statements is true of a Risk Response task?

A

Only one Risk Response task can be related to a Risk at a time

51
Q

What can a risk manager do to a risk in assess state

A

Move it back to Draft

Perform Assessment and move to Respond

52
Q

Indicator Failure Factor represents the impact of Risk Indicator Failures on what score?

A

Calculated ALE

53
Q

What GRC module would you access to update Entity Types?

A

Scoping > Entity Types

54
Q

Which tables are extended from the sn_grc_content table?

A

Control Objective

Citation

Risk Statement

55
Q

SLA can be configured on which GRC tables:

A

Indicator task

Issue

56
Q

Which table stores the links from the Profile Type to Risk Statement?

A

sn_risk_m2m_risk_definition_profile_type

57
Q

Which of the following tables have a many to many relationship

A

Control Objective and Entity Types

Entity and Entity Types

Risk Statement and Entity Type

58
Q

The entity class can be leveraged by which of the methodologies:

A

Risk based Advanced Risk Assessment

Object based Advanced Risk Assessment

59
Q

When does a policy get published

A

When all the approvals on the Policy are approved

When no approvers are configured on the Policy

60
Q

What does not get tracked in an update set?

A

Data changes

61
Q

Which scheduled jobs in the GRC: Profiles scope help manage the population of Entity records?

A

GRC indicator nightly run

GRC Profile Generation

62
Q

Which states are belonging to Policy life Cycle.

A

Review

Publish

63
Q

To open Default view of the risk from in the content frame ?

A

sn_risk_risk.form

64
Q

What happens when entity type is linked to a Control Objective?

A

Each entity will have its own Control Instance created

65
Q

Which of the following are tables in the GRC: Policy and Compliance scope?

A

Control

Citation

66
Q

The Profile Type table has a many-to-many relationship with which tables?

A

Risk Statement

Policy

67
Q

Quantitative Risk Score Calculation?

A

SLE x ARO = ALE

68
Q

What is the minimum role required to create a risk assessment methodology (RAM)?

A

sn_risk.admin

69
Q

Which of the following are tables in the Risk scope?

A

Risk Framework

Risk Statement

70
Q

Profile classes are optional and can be set later in the implementation process

A

true

71
Q

Which of the following are relevant stakeholders on the core implementation team?

A

Risk and compliance experts

Account Executive

CMDB Process Owner

ServiceNow platform experts

72
Q

Which capability does Performance Analytics expand?

A

Reporting

73
Q

Which GRC application would you use to manage internal or external consultancy processes that aim to prove the effectiveness of controls?

A

Audit Management

74
Q

What packaging options are available under GRC

A

Standard

Professional

Enterprise

75
Q

Controls are created when control objective relates to which of the following:

A

Entity Type

76
Q

Which of the following roles can create issues?

A

Audit User

Compliance User

Risk User

77
Q

If the Risk Statement is reactivated, related Risks are set to which state?

A

Draft

78
Q

The Risk thresholds in the Risk Criteria Matrix (default values) do not line up with company needs. What should you do?

A

Configure the Risk Criteria in ServiceNow

79
Q

What are the different types of Activities in the Audit Engagement?

A

Activity

Walkthrough

Control Test

Interview

80
Q

Which filter navigation syntax displays the default form view of the table in the Content Frame?

A

Tablename.form

81
Q

What table extends from Document Table?

A

Risk Framework

81
Q

Which feature would you use in order to track completion of certain tasks?

A

SLAs

82
Q

Which of the following belongs to Audit management?

A

Walkthrough

Control

Interview

83
Q

The Calculated Risk Score utilizes data from the inherent and Residual Risk scores to determine an adjusted ALE and Score. What other data drives the adjustments?

A

Control and Risk Indicator Failure Factors

84
Q

Which collection of tables extend from the item (sn_grc_item) table?

A

Control

Risk

85
Q

What is used to enable consistent entity and risk mapping and modelling across the enterprise.

A

GRC workbench

86
Q

Which of the following is a trigger for issue creation

A

Indicator failure

Attestation returns the result as Not Implemented’

87
Q

In Risk Workflow what can reviewers do in Assess state?

A

Move it to Draft

Answer the assessment and move it to respond

88
Q

Control failure factor represents the impact of control failure on what score?

A

Calculated

89
Q

Which tables extend the Content (sn_grc_content) table?

A

sn_compliance_citation

sn_compliance_policy_statement

90
Q

Unified Compliance Framework (UCF) Control documents import into which ServiceNow table with the UCF integration?

A
91
Q

sn_grc_content is parent table of?

A

sn_risk_definition

92
Q

By default, Risks are created in which state?

A

Draft

93
Q

Which of the below scheduled jobs in GRC: Profile scope manage entities?

A

GRC Profile generation job

Sync Entity owner to source record

94
Q

Santa Clara are examples of what in GRC Scoping

A

Entities

95
Q

which tables extend Document table

A

authority document

policy

96
Q

Who should be on the core implementation team for a GRC implementation?

A

Risk and compliance experts

ServiceNow developer team

97
Q

Which of the following tables exist within the GRC: Profiles application scope?

A

Document

Content

Indicator

98
Q

Which of the following are scoped applications in GRC?

A

GRC: Profiles

GRC: Risk Management

99
Q

What would you use in order to accommodate a customer’s unique process around policy approvals? For example, each policy needs a second layer of approval.

A

Create a new workflow in the workflow editor

100
Q

Which of the following roles can create a policy?

A

Compliance Manager

Compliance User