CIS-RC practice questions
ServiceNow · CIS-RC · 300 questions
Original practice questions for the ServiceNow Certified Implementation Specialist – Risk and Compliance (CIS-RC) credential, covering configuration and implementation of ServiceNow Integrated Risk Management including GRC overview, implementation planning, entity framework, policy and compliance, risk management, common elements, and audit. Aligned to the CIS-RC Mainline Exam Blueprint (KB0011655).
This course contains the use of artificial intelligence.
About the CIS-RC exam
This exam cannot be booked cold — the vendor requires prior training, experience or continuing-education credits before you may sit it.
- Time allowed
- 1 hour 30 minutes
- Questions
- 60
- Format
- 60 multiple-choice and multiple-select questions; proctored at a Pearson VUE test centre or online via OnVUE
Eligibility and registration The certification this earns
Exam details published by the vendor, checked 25 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
GRC Overview · 35 questions
- A county board asks why GRC keeps appearing in the IT roadmap when staff already keep policies in shared drives and risks in an Excel register. What should the IRM lead emphasize about an integrated platform?
- A city CIO hears IRM and GRC used interchangeably in a vendor demo and asks which product the city is actually buying. How should the implementer clarify the naming?
- A hospital compliance lead wants governance, risk, and compliance treated as one activity so meetings stay short. What distinction should the IRM coach still keep clear on an integrated platform?
- A municipal utility cites the three lines of defense in its charter and asks where day-to-day risk ownership sits versus independent assurance. Which placement is correct at overview depth?
- A state agency asks what business problem IRM solves beyond installing more software. Which value statement best answers the sponsor?
- A transit authority already runs ITSM and wonders whether implementing IRM will replace the service desk. How should the implementer position IRM?
- A county privacy office asks whether IRM is the same as a security operations center tool for handling breaches. What distinction should be taught?
- A school district board wants compliance automation immediately but has no shared model of what is being governed. What prerequisite should the IRM lead insist on first?
- A city auditor asks how IRM changes assurance work compared with a parallel paper universe of checklists. What benefit should be highlighted?
- A regulated insurer compares a classic standalone GRC suite to ServiceNow IRM at overview depth. Which ServiceNow positioning point should the candidate emphasize?
- A public-health department frames GRC only as passing the next external audit. How should the IRM lead expand that positioning?
- A city manager asks which executive outcomes IRM reporting should emphasize beyond IT operations KPIs. What is the best answer?
- A consortium of townships fears IRM is only for banks and capital markets. Which response best shows why civic organizations still need IRM?
- A CIO asks whether buying IRM means every GRC suite application must go live on day one. What phased positioning is correct?
- A new compliance analyst treats a published policy PDF as identical to a control in ServiceNow IRM. What distinction should be corrected?
- A risk coordinator uses the word risk for both a generic threat statement library entry and a scored register item for the water treatment plant. How should IRM terminology separate those ideas?
- Staff label every failed monthly access review as an audit finding, including issues raised by compliance testing outside an audit engagement. What terminology correction is needed?
- A department head asks what an entity is in ServiceNow IRM. Which definition is correct?
- A workshop treats attestation and indicator as interchangeable evidence words. How should the candidate contrast them?
- A project glossary mixes authority document and citation as if they were the same object. What is the correct IRM distinction?
- Writers still say profile while the IRM workspace says entity. What should practitioners understand about that naming?
- A lead asks what a control objective means versus a control in IRM. Which statement is accurate?
- A workshop debates casual uses of inherent risk. What is the IRM meaning that should be locked for the exam?
- Another workshop debates residual risk after hearing that controls are in place. Which definition should the candidate apply?
- A stakeholder asks what scoping means in ServiceNow GRC/IRM. Which explanation is correct?
- An intern on a municipal IRM project thinks a content pack is a PowerPoint deck for executives. What should the implementer explain a ServiceNow IRM content pack actually provides?
- A platform owner asks where Integrated Risk Management sits architecturally relative to the rest of ServiceNow. Which placement is accurate?
- An architect asks which core IRM applications the CIS-RC blueprint centers on for Risk and Compliance implementation. Which answer best reflects that core scope?
- A CMDB owner asks how IRM relates technically to configuration items in a regulated city environment. Which explanation is correct?
- A security architect proposes storing all control-test evidence only in email threads. What should the IRM implementer recommend instead?
- A developer wants to custom-script every control test on day one of a county IRM rollout. What approach should the implementer prefer first?
- An integration lead asks whether IRM needs its own separate user directory product for GRC personas. What is the correct technical answer?
- A reporting analyst asks how executives typically see IRM posture technically on the platform. Which description fits overview-level CIS-RC knowledge?
- A tech lead asks what item generation refers to in ServiceNow IRM. Which definition is correct?
- A release manager asks whether IRM configuration is basically just update sets of UI policies. How should the implementer frame technical IRM implementation?
Implementation Planning · 15 questions
- A city wants Policy and Compliance, Risk, Audit, Vendor Risk, and BCM all live in ninety days for every department. What should the implementer recommend for phase one?
- A county clerk’s office needs to show SOX-like financial control testing for a shared-services ERP. Which use-case framing best fits IRM?
- A municipal hospital prioritizes clinical application risk scoring before cleaning the policy library. What foundation must still be in place for that Risk-first use case?
- A state department of transportation wants internal audit to plan engagements from a living risk register. Which use-case approach fits IRM?
- A city payments team faces PCI obligations and asks which IRM outcome should define success for phase one. Which criteria are most appropriate?
- Before any IRM configuration, a program manager skips stakeholder mapping. Which checklist action should happen first?
- The CMDB is known to be stale, yet the team wants entity types pointed at all CIs immediately. What should the implementation checklist emphasize first?
- An implementer activates every IRM-related plugin “just in case” without a checklist. What practice should replace that approach?
- A kickoff has no RACI for who approves entity class design. What should the implementation team checklist include?
- Training and change management are omitted from an IRM go-live plan. Which checklist item should be restored?
- A city grants every IT analyst the GRC admin role for convenience. What role practice should the implementer enforce instead?
- Who should own monthly control attestations for the city’s permitting system under a normal lines-of-defense model?
- A risk manager persona needs to assess and treat risks without redesigning entity types. How should roles be separated?
- Compliance manager and audit manager both want authority to close findings the same way. How should the implementer distinguish the roles?
- Department directors request visibility limited to their entities’ risks and controls. What access approach should the implementer use?
Entity Framework · 60 questions
- A compliance lead scopes a statewide privacy policy to every configuration item in the CMDB, including printers and unused lab PCs. What is the main problem with that entity scope?
- A city risk team scopes ransomware exposure only to one forgotten departmental Access database. Critical 911 and utility billing applications are left out. What coverage problem does that create?
- Leadership asks “what are we governing?” before loading ISO control citations into ServiceNow IRM. What should the implementation team establish first?
- A municipality wants vendors, facilities, and business services all in year-one IRM scope without ranking which populations matter most. What approach should the team recommend?
- After a city reorg, half the departments marked in-scope no longer exist as active org units. What does this reveal about entity scoping?
- Internal audit asks whether entity scoping is only a compliance concept. How should the IRM lead respond?
- During a workshop, staff treat “scoping a control objective” as the same task as writing the control objective’s wording. What distinction should the implementer emphasize?
- A utility proposes dynamic scoping so newly discovered critical applications automatically enter GRC scope. Which capability does that approach rely on?
- An agency chooses purely manual entity creation for roughly 5,000 servers in scope. What should the implementer advise?
- A regulator asks which systems PCI applies to at a municipal payment processor. What should leadership point to as the durable answer?
- Two city departments argue whether a shared integration hub belongs in either department’s IRM scope. What is the soundest handling?
- Scoping workshops finish, but inclusion and exclusion choices for entity populations are never written down. What should be required next?
- A mayor demands that “everything” be scored for risk and compliance by Friday. What guidance should the IRM lead give?
- Disaster-recovery obligations cover different systems than the city’s PCI scope. How should entity scoping handle that?
- Outsourced payroll is omitted from entity scope because “it is not on our servers.” The city remains accountable for employee data protection. What correction is needed?
- An implementer creates one entity type with no table filter, so generation pulls every record from a very large table. What is wrong with that design?
- Critical applications should become IRM entities from application CIs where business criticality is high. Which configuration pattern matches that need?
- Departments must be represented as entities using existing organizational data. What entity-type approach should the team take?
- A water utility must govern treatment plants and depots as well as IT applications. How should entity types be structured?
- Admins create an entity type for critical applications but never run generation or refresh. No entities appear. What misconception does this expose?
- An entity-type filter depends on a transient custom field that only one administrator understands and plans to retire. What design change is appropriate?
- A proposed “vendors” entity type points at a random spreadsheet import table full of duplicate vendor names. What source choice is better?
- Two entity types use overlapping filters and both generate entities for the same configuration item. What problem should the team fix?
- A team wants entity types for “anything we might audit someday,” including inactive side projects with no current program. What alignment should leadership enforce?
- An applications entity type still generates entities for decommissioned CIs. What condition change should be made?
- A county IRM team proposes entity types that pull business services from CSDM-aligned service tables rather than only servers. When should the implementer accept service entities?
- An implementer clones a working entity type onto every child CMDB table 'just in case.' What approach should the IRM lead enforce instead?
- Finance process owners need 'payment processing' governed in IRM, but they reject server-level entities as meaningless to them. What entity-type approach fits?
- The city marks additional applications as business-critical in the CMDB and expects them to appear as IRM entities without hand-building each one. What should the design emphasize?
- A consultant says entity types are optional because the hospital can hand-build three EHR-related entities. How should the implementer respond for a civic-scale estate?
- Leadership wants IRM reporting rollups by Organization, Technology, and Third Party. Which construct should the implementer use to group entity types for hierarchy and reporting?
- Without entity classes, owners face a flat list of roughly 2,000 entities and cannot navigate ownership. What problem does introducing classes primarily solve?
- A utility wants scoped GRC content from a parent business-unit pattern to cascade toward child entities. What design relationship should the workshop emphasize?
- A builder tries to use entity classes as a second filter engine that duplicates entity-type table conditions. What distinction should be reinforced?
- A utility creates a new entity class for every team rename on the org chart. What taxonomy approach should the IRM architect prefer?
- Executives ask for residual risk dashboards sliced by entity class across the municipal portfolio. What must be true in the entity design?
- After a city reorg, an application entity must move from one entity class to another. How should that change be treated?
- A class-design workshop includes only CMDB admins and skips audit and risk consumers. What should the lead correct?
- Someone proposes entity classes named PCI, HIPAA, and SOX for every regulated workload. What guidance should the implementer give?
- A municipality needs parent/child links from city to department to system so ownership and rollups stay coherent. What modeling approach fits?
- A team skips the entity class approach, arguing that entity types alone are enough. What limitation should the implementer highlight?
- Under a shared Technology entity class, the city needs both application and infrastructure entity types. Is that valid?
- Controls and risks must attach to something durable in the IRM architecture. What is the architectural join point between organizational objects and GRC content?
- After associating a control objective to relevant entity types, the compliance lead expects control records on those entities. Which architecture behavior produces them?
- A risk statement is associated to hospital entity types so each in-scope entity receives a risk to assess. What parallel architecture behavior applies?
- An architecture diagram shows entities but omits the document → content → item layers, leaving the team unsure why nothing appears on entities. What distinction must be taught?
- Entity types will generate from CMDB application classes, but Discovery and ownership data are known to be stale. What architectural dependency should be called out?
- Policy, Risk, and Audit teams each need to see the same hospital EHR entity rather than three conflicting copies. What architecture principle applies?
- Attestation workflows have no assignee because ownership fields on entities are empty. What architecture requirement was missed?
- The entity hierarchy is city → department → application, and the team wants department-level scoped content to inform child applications where supported. What should the architecture emphasize?
- A municipal IRM team keeps entities in ServiceNow but a bureau proposes a parallel SharePoint list as a second master for the same governable buildings and applications. What should the architect insist on?
- CMDB and HR integrations continuously add new configuration items and org units, but GRC entities used for control scoping lag weeks behind. What should the entity architecture include?
- A county compliance program must apply policies to IT assets and to non-IT objects such as business processes and physical facilities. How should entity architecture be designed?
- An IRM admin plans a breaking redesign of entity types that already have generated controls and risks attached. What must happen before the redesign proceeds?
- A utility’s IRM reference architecture must support continuous monitoring, not only periodic questionnaires. Where should indicator hooks sit in the entity-centric model?
- Workspace UX labels objects as entities while classic tables still use older profile-oriented names. When designing architecture for a city IRM rollout, what should the answer emphasize?
- A transit agency needs blast-radius reporting that shows which applications run in which facilities when a site risk materializes. What entity-framework capability is required?
- Generating controls and risks for entities that are out of the compliance program’s agreed scope floods owners with noise. What should architecture enforce before generation?
- Why does the CIS-RC blueprint weight Entity Framework heavily relative to other domains for an IRM implementation?
- Multiple agencies keep local CMDB-like sources but must report against shared IRM entity types for a federated city program. What design approach fits?
Policy and Compliance · 75 questions
- A city must adopt NIST CSF as an external mandate library in ServiceNow IRM. Where should the Policy and Compliance content lifecycle start?
- PCI DSS requirement 8.x must be tracked as a discrete obligation under the city’s adopted PCI authority document. Which record should be created next in the lifecycle?
- The city authors an internal access-control policy that must be reviewed, approved, and made active for the organization. Which lifecycle outcome is required?
- Compliance authors a reusable outcome “Restrict privileged access” intended to satisfy multiple regulatory citations. Which content-chain record expresses that reusable outcome?
- After scoping the “Restrict privileged access” control objective to the ERP entity, what lifecycle step creates the owned work item for the ERP manager?
- Quarterly control testing is due for an active ERP access control. What Policy and Compliance lifecycle activity should the owner perform?
- A control test fails for the ERP privileged-access control. What should happen next in the lifecycle?
- A clinic department requests temporary relief from MFA policy for a legacy application. How should IRM handle the request?
- A regulation is superseded and the related authority document must leave active use. What lifecycle practice is appropriate?
- After a regulatory revision, citations under an authority document are updated. What impact must compliance managers assess?
- A policy remains in draft while authors refine wording. What lifecycle gate should prevent premature obligations?
- When is a generated control typically ready for attestation and monitoring in the lifecycle?
- Remediation tasks for a failed control are marked complete. What additional lifecycle step restores confidence that the control is effective?
- Authors upload step-by-step procedure documents that support an internal access policy. How do these differ from authority citations in the content model?
- Leadership worries policies will silently go stale over multi-year cycles. What lifecycle planning should the compliance team include?
- A county privacy office loads a new state privacy citation and finds an existing control objective already covers the same access-review requirement. What should the compliance lead do?
- Examiners ask a municipal utility for prior-year control test outcomes after the current test cycle opens. What must the compliance team preserve?
- After a city IT reorg mid-cycle, the group that owns a generated access-control record moves to a new service desk. How should ownership be handled?
- A hospital must remediate a broken logging system for sixty days and needs a temporary manual log review accepted by compliance. How should this be modeled in IRM?
- A transit authority wants every employee to confirm they read the acceptable-use policy. Which lifecycle approach fits this awareness need?
- A county decommissions a legacy permitting application that still has generated controls sitting in active testing queues. What should happen next?
- A civic IRM rollout has an authority document, citations, control objectives, generated controls, and open issues—but failed tests never create those issues. Which stage is missing in the chain?
- One quarterly access-review control must satisfy ISO, a state privacy citation, and an internal policy. What architecture should the city implement?
- Architects ask how authority documents and internal policies connect in ServiceNow Policy and Compliance. What is the architectural hinge?
- A new analyst treats every control objective as if it were already an entity-specific control. Why is that incorrect?
- Evidence from one access-review test must support several mapped regulatory citations. What architecture enables that?
- A utility publishes control objectives for encryption but never scopes them to entities. What happens architecturally?
- A consultant proposes a separate ‘compliance-only CMDB’ so IRM never touches the enterprise CMDB. What should the implementation lead answer?
- Overlapping regulations force a city to invent near-duplicate control objectives for every new mandate. How do common-controls style content packs help?
- A control requires a manager’s judgment that segregation of duties remains appropriate, while another control can be measured by an automated configuration check. How should evidence architecture differ?
- Several control tests fail across departments in a state agency. Where should remediation converge architecturally?
- A department obtains a policy exception for an unmet encryption control. What must the architecture prevent?
- Leadership wants compliance status both by business entity and by authority document. What does the data model need?
- In a workspace a record still shows older ‘policy statement’ language while docs say ‘control objective.’ What should implementers focus on architecturally?
- A large ISO-style framework needs nested clause references under one authority document. What citation structure should the team allow?
- Generated controls for a water utility appear with blank owners and nobody responds to failed tests. What accountability architecture is missing?
- A health department can auto-check encryption settings daily but still needs annual human review of exception handling. Which architecture fits?
- One control objective for backup verification is scoped to five clinic entities. What must generation create?
- Executives want a compliance scorecard for each department. What should be the system of record for those percentages?
- A city wants its internal information-security policy to demonstrate alignment to several external regulations without rewriting the policy once per regulator. What crosswalk approach should it use?
- A tax authority maps SOX, NIST, and local statute citations to one privileged-access control objective for the tax system. What should the compliance implementer configure?
- A hospital GRC lead wants generated access-review controls to appear only on applications classified as Critical Applications. How should the control objective be scoped?
- An EHR application must have access-review control tests run every three months. What frequency setting should the compliance admin configure on the control?
- Generated access-review controls for the EHR need a named owner accountable for testing and remediation. Whom should the implementer assign as control owner?
- Application owners must confirm that backup restore tests occurred this period. Which Policy and Compliance configuration supports that verification pattern?
- A privacy program needs hundreds of framework citations loaded quickly rather than typed by hand. What should the IRM implementer use?
- Policy exceptions longer than 30 days must go through formal approval before remaining active. What should the compliance admin configure?
- The information-security policy record should show which control objectives implement its requirements. What relationship should the implementer establish?
- PCI-sensitive entities require testers to attach supporting files when completing control tests. What should be configured?
- Several entities were decommissioned, but historical control test results must remain. How should active testing be handled?
- Utility SCADA entity control tests must alert owners when they become overdue. What should the implementer configure?
- Storage configuration items should show automated pass/fail for encryption at rest without waiting for a manual tester. What should be set up?
- Failed compliance tests for an entity should open issues that land with the team that supports that entity. What configuration achieves this?
- Court IT wants a compliance workspace focused only on controls for the e-filing entity. What should the admin establish?
- A new state privacy citation requires encryption, and an encryption control objective already exists. What is the preferred mapping approach?
- Before an information-security policy can publish, Legal and IT Security must approve. What should be configured?
- Lab clone entities must not receive the same generated production controls. How should generation be constrained?
- When remediation closes a compliance issue, testers should automatically receive a follow-up verification task. What should be configured?
- Examiners ask how each mapped citation is satisfied by the control design. What should compliance configure for traceability?
- Finance shared services needs coordinated year-end testing across many controls at once. What should the compliance lead configure?
- A passed access-review control test needs durable proof for later review. What supporting process should the tester follow?
- Failed controls produced many open issues; some may miss dates and need formal risk acceptance. How should the backlog be managed?
- Remediations for public-facing portals are overdue and need executive visibility. What supporting process should compliance use?
- Examiners request a file showing how payments-environment citations map to controls. What should compliance provide?
- Every department must complete annual acknowledgment of key policies. What organization-wide supporting process should compliance run?
- A county IRM lead discovers several compensating controls that have quietly become permanent workarounds for open policy exceptions. What should the compliance team validate first?
- A municipal utility's control test fails because server hardening drifted from the approved baseline. How should Policy and Compliance coordinate with ITSM without turning CIS-RC into a Change Management exam?
- Between scheduled control tests, a hospital's continuous indicator shows repeated access-review breaches on a clinical application. What should happen in compliance?
- A transit authority's attestation campaign returns dozens of identical 'yes' responses submitted within minutes. What quality-review action should compliance take?
- A state agency's external audit fieldwork starts next month, but control evidence is still scattered across email. What calendar practice should Policy and Compliance adopt?
- A new privacy regulation adds obligations that do not map cleanly to the city's current citation library. What should the compliance content team do first?
- A county GRC steering committee asks for operational health of the compliance program, not a list of policy PDFs. Which KPI set best fits?
- The same access-control fails for a fourth quarter in a row at a public hospital, and remediation keeps slipping. What supporting handoff should compliance make?
- Three different testers evaluate the same encryption control at a water utility and produce inconsistent procedures and evidence. What should compliance maintain?
- Entity owners at a regional school district ignore long email threads about overdue attestations and open issues. How should compliance close the loop?
Risk and Advanced Risk · 75 questions
- A water utility is standing up IRM for operational technology risks and staff want to jump straight into writing individual risk records. What should come first?
- A city CIO wants a reusable definition for the risk that unpatched internet-facing civic apps can be exploited. What record should the risk team author first?
- The reusable statement for internet-facing exploitation exists. How should the risk analyst generate a register entry for the permitting system?
- Before documenting controls on the hospital EHR risk, what assessment step should the risk owner complete?
- Controls for the EHR risk are documented, including preventive MFA and compensating monitoring. What assessment comes next?
- Residual risk for missing MFA on a citizen-facing portal remains above appetite. Which response and linkage is appropriate?
- A legacy internal reporting tool has low residual risk after compensating controls, and leadership will not fund further hardening. What documented treatment fits?
- Finance proposes cyber insurance for a payments-outage risk at a municipal utility. How should that decision be reflected in IRM?
- A vulnerable public kiosk system cannot be hardened cost-effectively, and the city decides to stop offering that kiosk service. Which risk treatment is that?
- A major EHR upgrade is scheduled that changes authentication and data flows. What lifecycle action should the risk team take for related risks?
- The permitting system's entity is being decommissioned and will no longer process applications. What should happen to its scoped risks?
- Between formal assessments, a risk indicator for failed backup jobs on a utility OT network breaches its threshold. What should the risk lifecycle do?
- A newly authored risk for a payments platform is scored, owned, and ready for ongoing oversight. What state progression is appropriate?
- Business managers complete a structured questionnaire about likelihood and impact for several civic service risks. How should those results enter the lifecycle?
- For a municipal payments-outage risk, leadership wants monetary loss ranges alongside qualitative scores. What assessment input should the risk team capture?
- A city utility’s IRM desk learns that quarterly access reviews for SCADA admin accounts failed their last two control tests. How should that result affect the related cyber risk record?
- A county risk owner wants to mark a privacy breach risk Mitigated after drafting three remediation tickets. What must happen first in the risk response lifecycle?
- A hospital compliance officer asks how IRM should retain last year’s scored risk assessment after this year’s workshop revises likelihood and impact. What practice keeps history for regulators?
- After three related water-main outages, a municipal GRC team wants the pattern tracked as a managed risk in IRM—not only as closed incidents. What intake path should they use?
- A transit authority’s annual risk workshop leaves scores stale for months while ridership and vendor issues shift weekly. How does Advanced Risk continuous monitoring help in the lifecycle?
- Two county departments merge and the legacy risk owner for floodplain drainage leaves. What should the IRM administrator do on active risk records?
- A city manager wants the board pack to show cyber, facilities, and workforce risks grouped under the enterprise risk framework—not a flat dump of 200 rows. What IRM practice supports that?
- Residual risk for a clinic’s EHR downtime remains above tolerance while capital funding for redundant hosting is delayed six months. What should the risk team document now?
- A library system formally accepts residual risk on a legacy catalog server. What validation prevents that acceptance from lasting forever without revisit?
- A new IRM analyst asks for the end-to-end chain from reusable content to ongoing oversight for a civic cyber risk. Which sequence best matches the Risk and Advanced Risk lifecycle?
- In IRM architecture, how does a risk statement relate to a risk on a wastewater plant entity—parallel to control objective versus control?
- A civic board packet shows two scores for the same cyber risk. What distinction must members keep as their mental model?
- When should a municipal risk committee treat versus accept a scored risk in IRM architecture terms?
- A utility IRM lead explains the common scoring model used on qualitative risk assessments. What architecture is typically applied?
- A county finance director wants dollar-loss ranges for flood risk, while operations prefers High/Medium/Low workshops. How should methodology choice be framed?
- A transit IRM design session debates Key Risk Indicators versus underlying indicators. What architectural distinction should stick?
- Why does IRM use a risk framework instead of a random folder of risk statements?
- What makes enterprise risk registers comparable across departments and applications in IRM?
- An architect insists residual risk must drop whenever any control is linked, even if the control failed testing. What correction is required?
- How should a CIS-RC implementer describe Advanced Risk relative to core risk capabilities?
- A flood-loss estimate for a riverside plant is highly uncertain. What conceptual scoring mindset fits Advanced Risk–style quantitative thinking?
- Which statement correctly describes IRM risk treatment architecture?
- A failed control test and an open risk response both point at the same access-review gap for a clinic. What architectural construct connects them?
- An Advanced Risk designer asks how assessment configuration typically nests. Which awareness is correct?
- City council asks for risk reporting they can act on. Why is a dump of 500 raw risk rows the wrong architecture?
- A county IRM architect wants internal audit to reuse risk register data for engagement planning without making audit a second risk owner. Which architecture best preserves third-line independence?
- A utility risk team notices the register mainly updates after outages are already logged. Which design best shifts the architecture toward leading risk signals?
- A city wants the same ransomware wording assessed consistently across dozens of department applications. Which Risk architecture best enables that consistency?
- During operating-model design, a municipal CIO asks who should own residual scores versus who should configure the IRM risk application. Which separation is correct?
- A hospital IRM lead wants threat-intelligence headlines to inform risk context without converting Risk into Security Incident Response. Which approach fits?
- A transit authority’s appetite breaches currently live only in a shared spreadsheet footnote. Which architecture should replace that pattern?
- Executives want a residual heat map that reflects current assessments and indicators, not last year’s workshop slide. Which architecture supports that?
- A county register shows five near-identical ransomware statements under slightly different wording, inflating rollups. Which architecture fix is most appropriate?
- A city’s risk framework must distinguish financial, operational, compliance, and technology risks for reporting. Which design choice best supports that?
- Advanced Risk continuous monitoring is active for many civic KRIs, yet reputational and judgmental risks still need expert review. Which architecture is sound?
- A GRC administrator must configure qualitative scoring for city operational risks using likelihood and impact. Which configuration action is appropriate?
- An OT-focused risk framework is already defined for water-plant entities. What should the administrator do so statements participate in that framework?
- Security leadership wants a ransomware statement applied to every public-facing web application entity. Which configuration achieves that scoping?
- Permit-system business owners must answer structured questions during risk assessment. Which configuration step is required?
- The CIO wants automatic attention when residual scores rise above High. Which configuration implements that appetite rule?
- Risk wants an early warning when failed logins spike on the citizen portal. Which configuration is appropriate?
- The risk team wants residual context from how long critical vulnerabilities sit open—without turning the item into a Vulnerability Response implementation. Which configuration fits?
- Residual calculation should reflect controls that mitigate a payment-outage risk. What must be configured?
- When owners choose Mitigate, the team wants consistent follow-up tasks. Which configuration helps?
- Leadership prioritizes continuous monitoring on the top 20 civic risks. Which configuration action matches that intent?
- Owners must be notified when residual exceeds tolerance. Which configuration is needed?
- A utility wants annual reassessment plus extra reviews when major changes land. How should that be configured?
- Department directors should see only risks tied to their entities. Which configuration approach is appropriate?
- A new municipal IRM rollout needs a starting set of IT risk statements quickly, then local tailoring. Which configuration path is sound?
- Finance wants estimated primary loss captured on a payment-outage risk alongside qualitative ratings. Which configuration awareness is correct?
- A county hospital's risk assessment for the EHR marks the residual score above appetite and flags the risk as needing treatment. How should the IRM admin wire the next step so remediation work starts without a spreadsheet handoff?
- A municipal utility wants any risk acceptance above a published residual threshold to require senior approval before the register shows Accepted. What should the implementer configure?
- A regional clinic maps ransomware exposure on its EHR entity and a related identity-provider entity that issues clinician SSO. What IRM configuration best captures that the EHR risk depends on the identity provider's posture?
- A transit authority GRC lead needs executives to see the highest residual risks grouped by entity class (Application, Facility, Vendor) on one board. What should be configured?
- A water utility is standing up Advanced Risk assessments for operational-technology assets and needs likelihood and impact factors weighted for OT criticality. Where should those factors and weights live?
- A county GRC admin notices retired clinic applications still spawning new generated risks every week. What configuration change stops that noise without deleting historical risk history?
- A municipal generator-test program can only prove monthly load-bank results with paper logs that no API can read. How should indicator collection be configured for that KRI?
- Three civic departments each invent their own 1–7 impact scales for Advanced Risk, making board heat maps incomparable. What is the sounder approach?
- A hospital board wants residual and inherent risk trends in the same executive Performance Analytics-style views used for other operational KPIs. What is the primary purpose of that integration?
- A transit GRC lead wants risk owners to update scores and responses while auditors and many managers may only view the register. What should be tuned?
Common Elements and Extended Capabilities · 25 questions
- A county wants newly discovered critical business applications in the CMDB to become GRC entities without weekly spreadsheet imports. What integration pattern should the implementer use?
- A municipal compliance issue needs a change window and assignment group that already live in ITSM for a firewall rule fix. How should IRM touch ITSM without turning the item into an ITSM-process exam?
- A hospital access-review KRI must show whether privileged AD groups still match approved membership. Where should those membership signals feed?
- A utility risk owner wants open critical findings from security tooling to nudge a ransomware residual indicator—without redesigning the item as a CIS-SIR or CIS-VR configuration exam. What is the appropriate IRM use of that data?
- Auditors ask control testers at a county clerk's office to attach the authoritative SOP PDF from a document repository rather than email attachments. What integration pattern supports that?
- A regional health district is starting Policy and Compliance and wants a fast baseline of ISO-style citations and common control objectives. What should they install?
- A city must show HIPAA, state privacy, and PCI-aligned obligations but wants fewer duplicate control objectives to test. How do common-controls content packs help?
- Before a content pack's hundreds of citations are scoped to every production civic entity, what should the GRC team do?
- When a framework version updates and the publisher revises dozens of citations, what is the preferred IRM maintenance approach versus hand-editing thousands of rows?
- Executives at a port authority ask for GRC posture—open issues, control failures, residual risk—on the same platform reporting they already trust. What capability addresses that purpose?
- A GRC admin needs overdue control-test owners at a school district to get email notifications without writing a scripted application. Which platform capability fits at configuration depth?
- Compliance analysts, risk owners, and auditors at a municipal hospital each need role-appropriate modern UI experiences rather than only classic list forms. What platform capability should the implementer emphasize?
- A new state privacy bill moves from proposed to signed and then effective. What should Regulatory Change Management in IRM emphasize for the county privacy office?
- After a regulatory-change record adds a new citation, who should decide whether existing controls already cover it?
- A standard revision publishes and several authority-document sections change. What should the GRC team do in IRM?
- A state privacy regulation becomes effective next quarter, and the CIO wants a list of which city departments and systems are in scope before briefing council. In ServiceNow IRM Regulatory Change Management, what should the GRC lead use?
- Control tests, risk responses, and audit fieldwork all surface remediation work for the same utility. How should the IRM design treat those remediation items?
- Several encryption and access controls for a county EHR need recurring evidence from the same system owners. Which common IRM capability should the implementer rely on?
- The risk office wants measurable signals on both a payment-card control and a fraud risk for the transit authority. What IRM common object fits that need?
- Leadership asks whether Vendor Risk, Business Continuity, and Privacy apps invent their own unrelated data models. What accurate purpose-level answer should the CIS-RC implementer give?
- A municipal IRM rollout spans Policy and Compliance, Risk, and Audit. How should roles and groups be patterned?
- A hospital wants encryption-at-rest indicators to re-evaluate every week instead of waiting for quarterly attestations. What should the implementer configure?
- A continuous monitoring indicator for backup success fails mid-quarter for the water utility SCADA support entity. What should happen next in a well-designed IRM setup?
- A county compliance program already runs automated encryption indicators and still needs owners to confirm process controls that cannot be fully instrumented. Which assurance design fits?
- Noisy civic telemetry keeps flipping a fraud KRI between green and red every few hours, and the risk committee is ignoring alerts. What should the implementer do?
Audit and Advanced Audit · 15 questions
- Internal Audit must plan an engagement on the city’s payments environment with clear objectives and a defined period. What lifecycle step should they complete first in Audit Management?
- During an EHR security audit, auditors need structured tasks and a place to store working papers and evidence. What should they use in the engagement lifecycle?
- Auditors note weak privilege reviews on a benefits system, then confirm the gap is real. How should the engagement progress that item?
- Findings from the payments audit are either remediated or formally risk-accepted. What should Internal Audit do to finish the engagement?
- Advanced Audit planning for a utilities review should pull scope from live IRM data. What is the best scoping approach?
- The CAE wants a maintained list of potential future audits across civic departments, not only the one engagement in flight. What should Audit maintain?
- Designers propose a second, audit-only catalog of controls that duplicates Policy and Compliance. What architecture guidance should CIS-RC favor?
- A compliance manager asks to score residual risk inside the same engagement where they designed the controls under review. Why is that a problem in IRM audit architecture?
- The annual audit plan needs to favor areas with the highest live risk. What selection approach matches IRM audit architecture?
- A confirmed audit finding on weak backup testing needs remediation tracking visible to compliance and risk teams. How should findings integrate?
- Recent control tests for encryption controls are effective and independence rules allow reliance. What should auditors do to avoid wasteful duplicate testing?
- Who should plan the audit engagement versus who should own remediation of control gaps found?
- Auditors scoping three civic entities need broad read visibility into policies, risks, and controls in scope. What access pattern is appropriate?
- Auditee groups must upload evidence for fieldwork tasks. What permission boundary should remain in place?
- The same analyst currently marks controls attested and also wants the audit role that signs off assurance on that work. What should the implementer enforce?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by the exam vendor.