Entity Scoping 25% Flashcards
- The Entity filter record requires which mandatory field to be completed?
a. Filter Date
b. Filter name
c. Conditions
d. Table
d. Table
The Control Objective is ServiceNow is often called what by people in the GRC industry? (select all that apply)
a. Risk template
b. Control objective
c. Requirement
d. Control template
b. Control objective
c. Requirement
d. Control template
- An Entity must be related to a record in a ServiceNow table.
a. True
b. False
b. False
How many Entity Types can an Entity belong to? (select all that apply)
a. none
b. one
c. multiple
d. none - because an entity is not related to an entity type
a. none
b. one
c. multiple
- If an Entity Type has 5 Entities related to it, then when that Entity Type is related to a Control Objective, 5 Controls will ALWAYS be generated
a. True
b. False
b. False
If the “Create controls automatically” box is not checked, then controls will not be generated.
- What tables are frequently used on the Entity Type filter to generate Entities?
a. Department
b. Group
c. Control
d. Indicator
e. Service
a. Department
b. Group
e. Service
The Entity Owner is derived from the “Managed By” field on the Service record for the Entity Type “Critical Service.” If the value changes on the Service record, it will not update on the GRC Entity.
a. True
b. False
a. True
The “Business Unit” Entity Type leverages the Department table to generate Entities. There are only 4 records in this table when the Entity Type is first set up. What happens when later a 5th record is created in the Department table?
a. No updates are made to the entities
b. A new Entity is created for the new record
c. A notification is sent to the Compliance Manager
b. A new Entity is created for the new record
- Which tables extend from the Document parent table?
a. Risk Framework
b. Risk Statement
c. Risk
d. Policy
e. Control Objective
d. Control
e. Authority Document
f. Citation
a. Risk Framework
d. Policy
e. Authority Document
- Which tables extend from the Content parent table?
a. Risk Framework
b. Risk Statement
c. Risk
d. Policy
e. Control Objective
d. Control
e. Authority Document
f. Citation
b. Risk Statement
e. Control Objective
f. Citation
- Which tables extend from the Item parent table?
a. Risk Framework
b. Risk Statement
c. Risk
d. Policy
e. Control Objective
d. Control
e. Authority Document
f. Citation
c. Risk
d. Control
- Which of the following tables are in the GRC: Risk scope? (Select all that apply)
a. Issue
b. Risk Framework
c. Risk Statement
d. Citation
b. Risk Framework
c. Risk Statement
- Which of the following tables are in the GRC: Policy and Compliance Scope? (Select all that apply)
a. Issue
b. Control
c. Risk
d. Citation
b. Control
d. Citation
Which of the following are scoped applications in GRC? (Select all that apply)
a. GRC: Profiles
b. GRC: Risk Management
c. Compliance and Audit Management
d. Global
a. GRC Profiles (Entities used to be called Profiles)
b. GRC: Risk Management
Which of the following IS NOT a table in the Policy and Compliance scope?
a. Policy
b. Authority Document
c. Issue
d. Control
c. Issue sn_grc_ issue
Remember to consider the scope:
sn_compliance_policy
sn_compliance_authority_document
sn_compliance_control