Test question Flashcards
Which role approves the release of content for auditors outside the organization?
Audit approver
RAM initiation guided set up is available in the Risk Workspace via a ….?
Playbook
Regulatory Change management uses what type of RAM?
Object or risk?
What is available in Classic Risk and what is only available in Advanced Risk: Risk rollup, risk response, scheduled risk assessments, risk issue something, metrics
What risk appetite ____ is configurable while risk appetite _____ is customizable?
Scale, status
What field is on the Entity Type record: Auto-update flag, Source, Compliance Score
Which indicator type leverages platform automation to gather records
basic
What is Risk Register?
collection of all identified risks
What is another word for Mitigating Actions?
Controls
What is the SN term for policy statement, control requirement, control template?
Control objective
Advanced risk table prefix
sn_risk_advanced_
Control objective table name
sn_compliance_policy_statement
Which type of record doesn’t have a life cycle?
Control Objective
If auto-update owner is selected and the owner field on the source record is cleared out, what happens to the owner field on the entity record?
Nothing, updates are not made
What are 2 terms for risk before mitigating controls are implemented?
Inherent risk and operational risk?
Many to many relationships: risk statement to control objective, indicator template to entity type, entity type to entity class
True or false: entity types can be created with any table in SN
True
How many controls will be created if 5 control objectives are created for an entity type with 5 entities?
25
What are 2 ways to populate entity classes with entity types?
Entity filter and ??? (entity tier filter?)
Which workspace is needed to
user, group, user filter
What are the steps to configure confidentiality?
identify fields used in confidentiality, identify default allowed users and groups, configure which table will inherit confidentiality
Indicator failure factor contributes to ______
Calculated Risk Factor
Who can redline policy with Office365 integration?
Reviewer (this is in the docs page linked in the IRM implementation textbook)