ServiceNow CIS-VR and CIS-RIM - Vulnerability Response Risk Compliance IRM

By Marcus Chen · Updated May 25, 2026

Questions25
Passing Score75%
Format100% Multiple Choice
Sessions Logged648
Your progressLog in / Register to track times taken, best score, questions mastered, and coverage on this quiz.
Rating
Community rating 4.4 out of 5 from 13 ratings.
4.4 (13)

Topics covered

This quiz

Uncategorized25 (100%)

Uncategorized25 questions

Discussion

Log in to post a comment, reply, or expand a question.

Q-8725

Question Q-8725 A ServiceNow Vulnerability Response implementation needs to integrate with Microsoft…

2 comments · last active May 30, 2026

  • conz123 · May 29, 7:42 PM

    Quantitative risk: SLE × ARO = ALE for dollar-based prioritization. Qualitative heat map alone (opt A) when they ask dollars.

  • mediascreen · May 30, 10:42 AM

    Insurance premium vs control cost comparison uses ALE math.

Q-8717

Question Q-8717 A compliance manager needs to track an organization's compliance against…

2 comments · last active May 24, 2026

  • sleepybassist · May 23, 3:24 PM

    Compliance Management: policies → controls → assessments → real-time dashboard per framework.

  • BamBamWham · May 24, 5:24 AM

    Spreadsheets per regulation (opt A) won't give exec live pass/fail.

Q-8730

Question Q-8730 An organization's IRM program is mature and wants to implement…

2 comments · last active May 24, 2026

  • BboysOnAcid · May 22, 8:21 PM

    VR+IRM effectiveness dashboard: remediation rate, exception rate, audit findings closed — exec program health.

  • Recuso · May 24, 2:21 AM

    Silos per module (opt C) miss unified GRC story ServiceNow sells.

Q-8722

Question Q-8722 A compliance team is preparing for a SOC 2 Type…

2 comments · last active May 23, 2026

  • lifeiskickingme · May 22, 1:18 PM

    BCM: BIA → RTO/RPO → recovery strategies → exercise schedule. DR runbook in SharePoint only (opt B partial trap) — exam wants BCM in IRM.

  • FlgGypsy · May 23, 1:18 PM

    Tabletop exercise tracking with lessons learned is part of BCM module.

Q-8718

Question Q-8718 A security analyst discovers that a web application vulnerability (SQL…

2 comments · last active May 23, 2026

  • mttgtz7 · May 22, 6:03 AM

    Policy attestation campaigns with reminders + manager escalation — not honor system email (opt A).

  • EndersValentine · May 23, 10:03 AM

    HR integration can auto-assign policies by role/department.

Q-8720

Question Q-8720 An IRM analyst is setting up the Risk Register for…

2 comments · last active May 22, 2026

  • Ryannerker1079 · May 21, 12:56 PM

    KRI thresholds → automatic risk review tasks when metric breaches. Quarterly manual review only (opt C) is too slow.

  • dontbreakmyglass · May 22, 1:40 PM

    Failed login spike KRI example links to identity risk.

Q-8716

Question Q-8716 A company is implementing a Third-Party Risk Management (TPRM) program.…

2 comments · last active May 20, 2026

  • superrrrthrowaway123 · May 19, 5:38 PM

    TPRM: vendor tiers, questionnaires, scoring, remediation SLAs. CSM (opt C) is customer service not vendor risk.

  • starshipheartofgold · May 20, 6:38 PM

    500 vendors need tiered assessment not one-size questionnaire.

Q-8715

Question Q-8715 An auditor requests evidence that all high-risk access control changes…

2 comments · last active May 20, 2026

  • Sislo · May 19, 3:13 PM

    Audit Management: engagement, tasks, evidence requests, findings — not self-certify (opt A).

  • chervei · May 20, 7:13 AM

    Manual change export (opt C) lacks structured work papers.

Q-8711

Question Q-8711 A vulnerability management team imports 75,000 findings from their vulnerability…

2 comments · last active May 20, 2026

  • eager_muslim · May 19, 1:35 PM

    75k findings → assignment rules on CI support group + VR SLAs by CVSS band. Manual each (opt A) impossible.

    +2 votes
  • newsc2accnt · May 20, 3:35 AM

    One task for all 75k (opt D) loses accountability per finding.

Q-8712

Question Q-8712 A risk and compliance analyst wants to map ServiceNow IRM…

2 comments · last active May 20, 2026

  • break_time123 · May 19, 4:46 AM

    UCF = assess control once, maps to SOC2/ISO/NIST/GDPR. Four separate libraries (opt A) = 4x work.

  • throwaway202810 · May 20, 12:46 AM

    Auditors love single evidence artifact satisfying multiple framework reqs.

Q-8713

Question Q-8713 An organization has a critical vulnerability (CVE with CVSS 9.8)…

2 comments · last active May 18, 2026

  • Blix998 · May 18, 8:29 AM

    Can't patch 45 days → Vulnerability Exception + risk acceptance + compensating controls + expiry. Hide breach (opt A) isn't governance.

  • Laser-circus · May 18, 8:29 PM

    Delete findings (opt D) destroys audit trail — instant wrong on CIS-VR.

Q-8714

Question Q-8714 A company's IRM (Integrated Risk Management) team wants to perform…

2 comments · last active May 16, 2026

  • str8bro4upvotes · May 15, 1:42 PM

    Cloud migration → Risk Assessment on engagement: inherent vs residual after mitigations. Word doc (opt C) has no workflow.

  • meteorknife · May 16, 11:42 AM

    Likelihood × impact matrix vs risk appetite threshold is the scoring story.

Question catalog for this preview

Catalog listing of the 5 preview questions for this quiz.

Question 1

A security analyst discovers that a web application vulnerability (SQL injection) exists in a vendor-supplied component that cannot be patched immediately. The risk needs to be formally accepted by the CTO for a 90-day period. What is the correct workflow in Vulnerability Response and IRM?

Answer choices

  • A. Close the vulnerability as "Won't Fix" without documentation

  • B. Create a Risk Acceptance record in IRM — document the vulnerability details, link the Vulnerability Response record, specify the acceptance period (90 days), route to the CTO for formal digital approval, and document compensating controls (WAF SQL injection filter rules); create a Vulnerability Exception linked to the Risk Acceptance (Correct)

  • C. Simply add a work note saying the CTO verbally approved

  • D. Remove the vulnerability finding from the next scan report

Explanation

Formal risk acceptance process in ServiceNow: (1) Risk Acceptance record: creates formal documentation linking the vulnerability (from VR), the business justification, the acceptance period, and the approver; (2) Approval Workflow: routes to the CTO with full vulnerability context (CVSS score, affected systems, business impact); (3) Digital approval: CTO approves in ServiceNow — timestamp and approver identity are captured; (4) Compensating Controls: documented on the Risk Acceptance (WAF rules blocking SQL injection patterns); (5) Expiry: after 90 days, Risk Acceptance expires; if not renewed or remediated, SLA breach reporting resumes; (6) Vulnerability Exception: links to the Risk Acceptance in VR, pausing SLA clock while acceptance is active; (7) Audit Trail: complete documentation satisfies SOX/PCI-DSS risk acceptance requirements. Verbal approval (option C) is undocumentable and fails audit scrutiny.

Question 2

A compliance team is preparing for a SOC 2 Type II audit. They need to demonstrate that controls were consistently in place and effective throughout the 12-month audit period, not just at one point in time. How does ServiceNow IRM help demonstrate continuous control effectiveness?

Answer choices

  • A. Conduct one comprehensive control assessment the week before the audit

  • B. Implement continuous control testing in IRM — scheduled automated control assessments run throughout the year (monthly or quarterly), with results stored in the compliance evidence repository; auditors can review the testing history showing control effectiveness over the entire audit period (Correct)

  • C. Collect evidence once and claim it was collected monthly

  • D. The SOC 2 audit requires a separate tool; ServiceNow IRM is not suitable

Explanation

Continuous control monitoring for SOC 2 Type II: (1) Scheduled Control Assessments: configure control tests to run at defined frequencies (monthly automated, quarterly manual sampling); (2) Test Results: each assessment creates a timestamped result record (Pass/Fail) with evidence; (3) Evidence Repository: supporting evidence (screenshots, log exports, configuration captures) attached to each assessment; (4) Audit Period Coverage: 12 months of monthly assessment results provide auditors with evidence of consistent control operation; (5) Exceptions: any failed assessment during the period is documented with remediation evidence; (6) Auditor Access: auditors can be given read-only access to the IRM compliance module to review evidence directly; (7) Automated controls (Configuration Compliance checks) provide tamper-proof continuous testing evidence. Point-in-time assessment (option A) can only support SOC 2 Type I certification, not Type II which requires evidence of sustained effectiveness.

Question 3

A company processes credit card payments and needs to demonstrate PCI-DSS compliance. Their QSA (Qualified Security Assessor) needs to review evidence for all 12 PCI-DSS requirements. How should ServiceNow IRM be configured to support the QSA review process?

Answer choices

  • A. Email spreadsheets and screenshots to the QSA

  • B. Configure PCI-DSS as a Compliance Framework in IRM — map all 12 requirement domains and sub-requirements to controls; perform control assessments with evidence attached; generate a PCI-DSS Compliance Report showing each requirement's compliance status, control test results, and evidence artifacts; provide QSA with read-only Audit Portal access (Correct)

  • C. Compile evidence in SharePoint folders by requirement

  • D. Rely on the payment processor to handle PCI compliance

Explanation

PCI-DSS compliance in ServiceNow IRM: (1) Framework Configuration: import PCI-DSS v4.0 requirements (all 12 requirements, 64+ sub-requirements) into IRM as a regulatory framework; (2) Control Mapping: each PCI requirement linked to the organization's specific controls (Requirement 2.2 → System Hardening Control → CIS Benchmarks Configuration Compliance tests); (3) Control Assessments: automated (Configuration Compliance scans) and manual assessments with evidence; (4) Evidence Repository: screenshots, logs, policies stored as evidence artifacts per requirement; (5) Compliance Report: formal PCI-DSS compliance report showing each requirement: In Compliance, Partial, Non-Compliant with remediation status; (6) QSA Portal Access: create QSA user with read-only access to the IRM Compliance module for direct evidence review; (7) Reduces assessment time by 50-70% vs. manual evidence collection. SharePoint (option C) lacks the control assessment linkage and formal reporting structure QSAs require.

Question 4

A risk and compliance analyst wants to map ServiceNow IRM controls to multiple regulatory frameworks simultaneously (SOC 2, ISO 27001, NIST CSF, GDPR). Instead of creating separate control assessments for each framework, she wants to assess each control once and map to all relevant frameworks. Which IRM feature enables this?

Answer choices

  • A. Create four separate control libraries, one per framework

  • B. Unified Controls Framework (UCF) in ServiceNow IRM — a single control library maps each control to multiple regulatory/compliance frameworks simultaneously; one control assessment satisfies requirements for all mapped frameworks (Correct)

  • C. Manually cross-reference controls in a spreadsheet

  • D. Only certify for one framework at a time

Explanation

ServiceNow IRM's Unified Controls Framework: (1) Control Library — a single set of controls that represent actual security/operational practices (e.g., "Multi-factor Authentication Required"); (2) Control Framework Mapping — each control is mapped to relevant requirements across all frameworks: SOC 2 CC6.1, ISO 27001 A.9.4.2, NIST CSF PR.AC-7, GDPR Article 32; (3) Single Assessment — when control effectiveness is tested, results automatically satisfy all mapped framework requirements; (4) Compliance Dashboard — shows compliance percentage per framework derived from the same underlying control evidence; (5) Audit Evidence — one set of evidence artifacts (screenshots, logs, configurations) satisfies multiple auditor requests. Creating separate control libraries (option A) creates redundant work — the same controls assessed 4 times for each framework.

Question 5

An organization discovers that 200 of their vulnerability findings were incorrectly classified by the vulnerability scanner with wrong CVSS scores — they should be Critical (CVSS 9.0+) but were scanned as Medium (CVSS 5.0). How should these findings be corrected in Vulnerability Response without reimporting all findings?

Answer choices

  • A. Delete the 200 findings and reimport from scanner with corrected data

  • B. Use mass update or a background script to update the CVSS score and risk score fields on the 200 affected Vulnerability records; trigger SLA recalculation based on the updated severity; update assignment and priority based on new scores (Correct)

  • C. Accept the incorrect CVSS scores as scanner output cannot be modified

  • D. Manually open and edit each of the 200 records one by one

Explanation

Bulk vulnerability record correction: (1) Filter: identify the 200 affected records (by scanner, date, specific plugin ID, or manual identification list); (2) Background Script or Mass Update: use GlideRecord.updateMultiple() or the list-view mass update to correct the CVSS score field; (3) Risk Score Recalculation: trigger recalculation of the composite Risk Score based on updated CVSS (VR may need a business rule or script to recalculate after manual corrections); (4) SLA Adjustment: update the SLA target based on new severity — vulnerabilities now classified Critical get 15-day SLA applied; (5) Assignment Review: if assignment rules use severity, review assignments for the updated records; (6) Audit Note: document the correction reason in the affected records. Deleting and reimporting (option A) loses any work notes, exceptions, or remediation progress already documented on those records.