Free ServiceNow CIS-RC practice questions

10 free ServiceNow CIS-RC practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 289 questions. Work through them, then open each answer to check your reasoning.

Question 1

Which of the following tables exist within the GRC: Profiles application scope? (Choose three.)

  1. Document
  2. Policy
  3. Risk
  4. Content
  5. Indicator
Show answer and explanation

Correct answer: A, D, E

A. Document D. Content E. Indicator The GRC: Profiles application scope includes the Document, Indicator, and Content tables. These tables form the core of the profiles application and are used to manage governance-related documents, performance indicators, and content assets within the GRC module.

Why the other options are wrong

  • B. Policy is not part of the GRC: Profiles application scope; it belongs to the Policy Management application.
  • C. Risk is a separate application scope within GRC and is not included in the Profiles scope.

Question 2

What are some characteristics of the ServiceNow Store? (Choose four.)

  1. Some applications are certified by ServiceNow
  2. All applications are certified by ServiceNow
  3. Applications may be developed by ServiceNow Technology Partners
  4. It houses both paid and free applications and integrations
  5. Applications are built om the ServiceNow platform
  6. Applications are certified by other developers
Show answer and explanation

Correct answer: B, C, D, E

B. All applications are certified by ServiceNow C. Applications may be developed by ServiceNow Technology Partners D. It houses both paid and free applications and integrations E. Applications are built om the ServiceNow platform The ServiceNow Store contains applications developed by ServiceNow Technology Partners and by ServiceNow itself, offering both paid and free options. All applications in the Store are certified by ServiceNow to meet platform standards and quality requirements. Applications are built on the ServiceNow platform and provide integrations and extensions to the core system.

Why the other options are wrong

  • A. Only some applications are certified by ServiceNow, not all; this contradicts the certification requirement for Store applications.
  • F. Applications are certified by ServiceNow, not by other developers; ServiceNow maintains certification control.

Question 3

Which role is not part of ServiceNow GRC?

  1. Risk User
  2. Risk Developer
  3. Risk Manager
  4. Risk Reader
Show answer and explanation

Correct answer: B. Risk Developer

Risk Developer is not a standard role within ServiceNow GRC. The GRC module includes roles such as Risk User, Risk Manager, and Risk Reader, which are designed to manage governance, risk, and compliance activities. Developer roles are typically part of the platform administration structure rather than the GRC-specific role hierarchy.

Why the other options are wrong

  • A. Risk User is a valid GRC role for users who interact with risk-related objects.
  • C. Risk Manager is a valid GRC role responsible for managing risk activities and responses.
  • D. Risk Reader is a valid GRC role that provides read-only access to risk information.

Question 4

Which of the following statements is true of a Risk Response task?

  1. Only one Risk Response task can be related to a Risk at a time
  2. Only users with the risk_manager role or higher can be assigned to a Risk Response task
  3. The risk admin role is required to assign the Risk Response task
  4. The Risk Response task is automatically progressed through the states using a workflow
Show answer and explanation

Correct answer: D. The Risk Response task is automatically progressed through the states using a workflow

through the states using a workflow Risk Response tasks are automatically progressed through their states using a workflow. The workflow engine manages the lifecycle and state transitions of Risk Response tasks, ensuring standardized progression without manual intervention required at each step.

Why the other options are wrong

  • A. Multiple Risk Response tasks can be related to a single Risk; this relationship is not limited to one task per risk.
  • B. Users with various roles below risk_manager can be assigned to Risk Response tasks depending on configuration and permissions.
  • C. The risk_admin role is not specifically required to assign Risk Response tasks; this can be done by appropriate risk managers.

Question 5

What table, along with the Policy table, is linked to the Control Objective table by a many-to-many relationship?

  1. Entity Class
  2. Citation
  3. Authority Documents
  4. Risk Framework
Show answer and explanation

Correct answer: B. Citation

The Citation table is linked to the Control Objective table in a many-to-many relationship, along with the Policy table. Citations represent specific references or requirements that can be associated with multiple Control Objectives, and Control Objectives can be associated with multiple Citations.

Why the other options are wrong

  • A. Entity Class is not linked to Control Objective in a many-to-many relationship.
  • C. Authority Documents are not the table linked to Control Objective in a many-to-many relationship with Policy.
  • D. Risk Framework is not linked to Control Objective in a many-to-many relationship with Policy.

Question 6

Why would you create Entity classes?

  1. To show relationships between tables or objects you are tracking that doesn’t otherwise exist anywhere in ServiceNow
  2. To be assigned to risk statements, which generate risks for every Entity listed in the Entity Class
  3. To be assigned to Control Objectives, which generate Controls for every Entity listed in the Entity class
  4. To show relationships between Entities and Policies and map them directory to Citations
Show answer and explanation

Correct answer: A. To show relationships between tables or objects you are tracking that doesn’t otherwise exist anywhere in ServiceNow

are tracking that doesn’t otherwise exist anywhere in ServiceNow Entity Classes are created to establish and show relationships between tables or objects being tracked that do not otherwise have an existing relationship in ServiceNow. They provide a flexible grouping mechanism to link disparate entities together for organizational and governance purposes.

Why the other options are wrong

  • B. Entity Classes are not assigned to risk statements for automatic risk generation; Entity Classes serve a different functional purpose.
  • C. Entity Classes are not assigned to Control Objectives to generate Controls; this is not their primary function.
  • D. Entity Classes do not map entities directly to Citations; they establish relationships between entities themselves.

Question 7

The Tablename.config:

  1. Displays the configuration list view of the table in the browser tab
  2. Displays the table in list view within the Content Frame
  3. Displays the table in list view within a separate browser tab
  4. Displays the configuration list view of the table in the Content Frame
Show answer and explanation

Correct answer: D. Displays the configuration list view of the table in the Content Frame

Content Frame The Tablename.config syntax displays the configuration list view of the specified table within the Content Frame. This configuration view provides access to administrative settings and configuration options for the table without opening a separate browser tab.

Why the other options are wrong

  • A. The configuration list view is displayed in the Content Frame, not directly in the browser tab title.
  • B. Tablename.config displays the configuration list view, not the standard list view.
  • C. The view is displayed within the Content Frame rather than in a separate browser tab.

Question 8

Which of the following extends from items?

  1. Citation
  2. Controls
  3. Issue
  4. Policy Answer: B. Controls Explanation: Control/Risk[sn_grc_item] (i want to point out table label is Control/Risk…. not items….) extending to the following tables – Control[sn_compliance_control] (note the table lable is Control NOT Controls…..) – Control requirement[sn_compliance_control_rrequiement] – Risk[sn_risk_risk] the only reasonable answer is B. Controls…
Show answer and explanation

Correct answer: B. Controls

Controls extends from the item table in the GRC data model. The Control table inherits from the item base table, which provides the foundational structure and properties for control-related objects within the GRC framework.

Why the other options are wrong

  • A. Citation does not extend from items; it is a standalone table in the GRC structure.
  • C. Issue does not extend from items; it belongs to a different application module.
  • D. Policy does not extend from items; it is a primary table in the Policy Management structure.

Question 9

What happens when you assign an Entity Type to a Risk Statement?

  1. An assessment will be automatically generated to test each Entity listed in the Entity Type
  2. A risk assessment is created automatically for every Entity listed in the Entity Type
  3. A risk is automatically generated for every Entity listed in the Entity Type
  4. The Entity is now going to present a risk score and controls are going to be tied to it
Show answer and explanation

Correct answer: C. A risk is automatically generated for every Entity listed in the Entity Type

listed in the Entity Type When an Entity Type is assigned to a Risk Statement, the system automatically generates a risk for every individual Entity listed within that Entity Type. This creates a risk instance for each entity member, allowing the risk to be tracked and managed at the entity level rather than as a single generic risk.

Why the other options are wrong

  • A. Assessments are generated separately; assigning an Entity Type to a risk statement does not trigger assessment generation.
  • B. Risk assessments differ from risks themselves; the assignment creates risks, not assessments.
  • D. While risks may have scores and controls, this is not what happens specifically when assigning an Entity Type to a Risk Statement.

Question 10

There is a direct relationship between Entity Class and Entity Type when:

  1. They have the same Entity Types
  2. There is no direct relationship
  3. They have the same Entities
  4. They leverage the same reporting
Show answer and explanation

Correct answer: B. There is no direct relationship

Entity Class and Entity Type are independent constructs within GRC systems. Entity Class categorizes entities by their nature or role, while Entity Type defines groupings of specific entities. These are separate organizational structures with no direct hierarchical or structural relationship between them.

Why the other options are wrong

  • A. Entity Classes and Entity Types are separate constructs; they do not share Entity Types with each other.
  • C. While both may contain entities, this does not establish a direct relationship between the Class and Type structures themselves.
  • D. Shared reporting does not constitute a direct relationship between Entity Class and Entity Type.

That was 10 of 289.

The full ServiceNow CIS-RC pack has all 289 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack