10 free ServiceNow CIS-SIR practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 125 questions. Work through them, then open each answer to check your reasoning.
Get all 125 questions (US$39) · Download these 10 as a PDF
Question 1
What makes a playbook appear for a Security Incident if using Flow Designer?
Show answer and explanation
Correct answer: B. Trigger set to conditions that match the security incident
A playbook in Flow Designer becomes visible for a Security Incident when the trigger conditions are configured to match the specific incident criteria. The trigger acts as the entry point that determines whether the playbook should be available and executable for incidents meeting those conditions.
Why the other options are wrong
- A. Actions that create tasks are part of the playbook's execution steps, not what makes it appear in the first place.
- C. The Runbook property controls different aspects of playbook behavior but is not the mechanism for display visibility.
- D. Service Criticality is an incident attribute that may influence severity or priority but does not control playbook visibility.
Question 2
What is the purpose of Calculator Groups as opposed to Calculators?
Show answer and explanation
Correct answer: D. To ensure one at maximum will run per group
Calculator Groups are designed to ensure that only one calculator within the group executes at maximum per evaluation cycle. This prevents multiple calculators in the same group from running simultaneously, providing mutual exclusivity and control over calculation execution.
Why the other options are wrong
- A. While groups may organize calculators, providing metadata is not their primary purpose.
- B. Agent selection of individual calculators is not the purpose of grouping them together.
- C. Setting conditions applies to individual calculators or the triggering mechanism, not the fundamental purpose of grouping.
Question 3
The following term is used to describe any observable occurrence: __________.
Show answer and explanation
Correct answer: E. Event
An Event is the standard IT term used to describe any observable occurrence in a system. Events are the foundational data points that trigger alerts, incidents, and other downstream processes in IT and security operations.
Why the other options are wrong
- A. An Incident is a categorized problem requiring response, not simply any observable occurrence.
- B. A Log is a record of events but is not the term for the occurrence itself.
- C. A Ticket is a request or case object, not the basic observable occurrence.
- D. An Alert is a notification triggered by events but is not the observable occurrence itself.
Question 4
The severity field of the security incident is influenced by what?
Show answer and explanation
Correct answer: D. The business value of the affected asset
The severity field of a security incident is primarily influenced by the business value of the affected asset. Higher-value assets carry greater severity when compromised, reflecting the potential impact and importance to the organization.
Why the other options are wrong
- A. The cost of response is a separate financial metric and does not determine severity scoring.
- B. While impact and urgency are incident attributes, severity specifically reflects the asset's business value.
- C. Resolution time is a performance metric, not a factor in severity determination.
Question 5
The Risk Score is calculated by combining all the weights using __________.
Show answer and explanation
Correct answer: A. an arithmetic mean
The Risk Score is calculated by combining all weighted components using an arithmetic mean. This approach provides a balanced average that incorporates all contributing factors proportionally into the final risk calculation.
Why the other options are wrong
- B. Simple addition would not properly normalize scores across different scales and ranges.
- C. While a script include may implement the calculation, it is not the mathematical method used.
- D. A geometric mean would emphasize lower values and is not the standard approach for risk scoring.
Question 6
What are two of the audiences identified that will need reports and insight into Security Incident Response reports? (Choose two.)
Show answer and explanation
Correct answer: A, C
A. Analysts C. Chief Information Security Officer (CISO) Analysts need incident response reports to manage and investigate cases, while the Chief Information Security Officer (CISO) requires executive-level reporting and insights to oversee security posture and strategic decisions. These two roles represent both operational and leadership audiences essential to the incident response process.
Why the other options are wrong
- B. Vulnerability Managers focus on vulnerability management rather than incident response reporting.
- D. Problem Managers handle infrastructure and service problems, not security incident response.
Question 7
What three steps enable you to include a new playbook in the Selected Playbook choice list? (Choose three.)
Show answer and explanation
Correct answer: B, C, D
B. Navigate to the sys_hub_flow.list table C. Search for the new playbook you have created using Flow Designer D. Add the sir_playbook tag to the playbooks that you want to include in the Selected Playbook choice list To include a new playbook in the Selected Playbook choice list, navigate to the sys_playbook_flow.list table, search for the newly created playbook using Flow Designer, and add the sir_playbook tag to it. The combination of tagging and proper table navigation ensures the playbook appears in selection lists for security incident response workflows.
Why the other options are wrong
- A. The TLP: GREEN tag is a traffic light protocol label used for information sharing classifications, not for playbook selection inclusion.
- E. The sys_hub_flow.list table is not the correct table for managing playbook selections; sys_playbook_flow.list is the correct location.
Question 8
Which improvement opportunity can be found baseline which can contribute towards process maturity and strengthen costumer’s overall security posture?
Show answer and explanation
Correct answer: A. Post-Incident Review
Post-Incident Review is the key improvement opportunity that contributes most to process maturity and strengthens the customer's overall security posture. This retrospective analysis enables organizations to learn from incidents, identify gaps, and implement systematic improvements to prevent recurrence and enhance resilience.
Why the other options are wrong
- B. Fast Eradication addresses speed of response but does not fundamentally contribute to long-term process maturity.
- C. Incident Containment is a tactical response step, not a strategic improvement opportunity for maturity.
- D. Incident Analysis, while valuable, is a component of response rather than the key baseline improvement for maturity development.
Question 9
What is the fastest way for security incident administrators to remove unwanted widgets from the Security Incident Catalog?
Show answer and explanation
Correct answer: D. Through the Catalog Definition record
Widgets in the Security Incident Catalog are managed through the Catalog Definition record, which is the centralized configuration point for catalog items. This method ensures consistent administration and maintains the integrity of the catalog structure, rather than allowing ad-hoc removal through UI elements or requiring administrative intervention.
Why the other options are wrong
- A. The X button on widgets typically hides or collapses them temporarily rather than permanently removing them from the catalog.
- B. While system administrators can assist, the standard operational procedure for security incident administrators is to use the Catalog Definition record directly.
- C. Widgets can be removed through proper configuration in the Catalog Definition record.
Question 10
Select the one capability that retrieves a list of running processes on a CI from a host or endpoint.
Show answer and explanation
Correct answer: C. Get Running Processes
Get Running Processes is the specific capability designed to retrieve and display a list of active processes currently executing on a Configuration Item from a connected host or endpoint. This capability is essential for security investigations and threat response activities.
Why the other options are wrong
- A. Get Network Statistics retrieves network connection data rather than process information.
- B. Isolate Host is an action that disconnects a host from the network for containment purposes.
- D. Publish Watchlist is used for creating or sharing watchlists of suspicious indicators.
- E. Block Action is a containment measure that blocks specific activities or connections.
- F. Sightings Search queries historical detection data rather than live process information.
That was 10 of 125.
The full ServiceNow CIS-SIR pack has all 125 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
