CIS-VR

By CTA Eric · Updated Sep 22, 2026

CertificationCIS – Vulnerability Response (CIS-VIR)
Questions60
Passing Score95%
Format100% Multiple Choice
Sessions Logged0
Your progressLog in / Register to track times taken, best score, questions mastered, and coverage on this quiz.
Rating
Log in to rate

Certification Summary

The ServiceNow Certified Implementation Specialist Vulnerability Response CIS-VIR certification validates the technical proficiency of security operations professionals and implementation consultants tasked with configuring and maintaining vulnerability workflows within the Now Platform. Candidates sitting for this exam are typically security engineers or platform administrators responsible for managing integrations with third-party vulnerability scanners, defining remediation strategies, and automating the lifecycle of vulnerability data from initial discovery through final remediation.

The exam emphasizes the Vulnerability Management Lifecycle and Vulnerability Assessment and Remediation, which together comprise 60 percent of the assessment and require precise knowledge of how Remediation Target Rules govern SLA compliance and how Assignment Rules dynamically route Vulnerability Groups to technical owners. Vulnerability Response Concepts and Integration, alongside Reporting and Dashboards, account for the remaining 40 percent and test the ability to distinguish between staging table transformations and actual vulnerability item creation. The exam requires mastery of the Vulnerability Calculator logic to determine how Risk Scores are derived from Asset Value and Vulnerability Severity.

Topics covered

This quiz

Getting Data into Vulnerability Response29 (24.2%)
Tools to Manage Vulnerability Response34 (28.3%)
Automating Vulnerability Response34 (28.3%)
Vulnerability Response Applications and Modules17 (14.2%)
Vulnerability Response Dashboards and Reports6 (5%)

Exam blueprint

Official domain weights for this certification.

Vulnerability Response Concepts and Integration20%
Vulnerability Management Lifecycle30%
Vulnerability Assessment and Remediation30%
Reporting and Dashboards20%

Counts are questions tagged to each domain. A cross-domain item appears in every domain it requires, so totals can exceed the quiz length.

Getting Data into Vulnerability Response29 questions

Tools to Manage Vulnerability Response34 questions

Automating Vulnerability Response34 questions

Vulnerability Response Applications and Modules17 questions

Vulnerability Response Dashboards and Reports6 questions

Question catalog for this preview

Catalog listing of the 5 preview questions for this quiz.

Question 1

The instance is domain separated. Scanner imports use an integration user in one domain. National Vulnerability Database entries were loaded in the global domain. Each domain that participates in the integration needs its own scheduled import setup. Deferral workflows were created in only one domain.

Which of the following statements are true? Select all that apply.

Answer choices

  • A. A vulnerable item ingested by the scanner stays in the integration user's domain and is not accessible from other domains.

  • B. Remediation tasks in one domain can be viewed from the other domains.

  • C. A deferral workflow created in one domain is not visible in another domain.

  • D. National Vulnerability Database information in the global domain can be shared.

  • E. Each domain should have 2 import templates.

  • F. The risk scoring algorithm in one domain can be viewed by users outside that domain.

Question 2

The Default Risk Calculator is the active calculator for Risk Score. Vulnerability Severity is inactive. A new vulnerable item is imported, and more than one calculator rule inside the active calculator could seem relevant. Weights on the matching risk rule include severity, exploit information, and a criticality factor. An administrator also left a second calculator active in a lower order, expecting both scores to be averaged.

Which statement describes how the risk score is chosen for the new vulnerable item?

Answer choices

  • A. The first matching calculator is used, and only one calculator for Risk Score may be active, so a second active calculator is not a supported way to average scores.

  • B. Every active calculator runs, and the vulnerable item stores the average of their scores.

  • C. The Vulnerability Severity calculator overrides the Default Risk Calculator whenever the source severity is present, even if Vulnerability Severity is inactive.

  • D. No score is written on import. Scores are written only when Calculate Risk Score is clicked on the item.

  • E. The highest score among all matching calculator rules is stored, even when an earlier rule already matched.

Question 3

An approved exception rule is inside its valid window. Its remediation task was created in Deferred with grouping method exception rules. A newly imported vulnerable item matches the rule condition. An active remediation task rule would also match that item and would place it on a different open task for the same assignment group.

What happens to the new vulnerable item?

Answer choices

  • A. It is added to the exception rule's deferred remediation task, and the remediation task rule is not run for it.

  • B. It is added to both the deferred exception task and the open task from the remediation task rule.

  • C. It stays Open on the remediation task rule's task until Valid to, and only then moves to Deferred.

  • D. It is deferred in place on the remediation task rule's open task, and no exception remediation task is used.

  • E. The import skips it, because an item cannot match an exception rule and a remediation task rule in the same run.

Question 4

State synchronization is enabled. A remediation task is in Awaiting Implementation because of one change request. That change request is then Canceled. The remediation task is not Deferred and is not Closed.

What happens to the remediation task?

Answer choices

  • A. It moves back to Under Investigation.

  • B. It stays in Awaiting Implementation until a scanner closes the vulnerable items.

  • C. It moves to Resolved, because a canceled change is treated as a successful close code.

  • D. It moves to Open and its remediation target date is cleared.

  • E. It stays in Awaiting Implementation, because canceling a change request never moves a remediation task.

Question 5

Solution Management is installed. A user has manually set the preferred solution on a vulnerability. A later vendor import brings in an MSRC solution for the same vulnerability, and the scanner-solution property is true. Separately, a solution record has a highest active vulnerable item risk score of 80 and 200 active vulnerable items that list it as a potential solution.

Which statement is correct?

Answer choices

  • A. The vendor solution replaces the manual preferred solution, and the solution risk score is 80 because solution risk copies the highest vulnerable item score.

  • B. The manual preferred solution is kept, because a higher-priority selection is never overridden by a lower one. The solution risk score is 78.

  • C. The manual preferred solution is kept, and the solution risk score stays 80 because the count bonus applies only after 1,000 vulnerable items.

  • D. The scanner bulletin becomes preferred because the scanner-solution property is true, and the solution risk score is 68 with no count bonus.

  • E. Preferred solution logic ignores manual values on the vulnerability and uses only the latest superseding vendor solution. The solution risk rating for score 78 would be Critical.