Browse all practice questions for the ServiceNow Integrated Risk Management (IRM) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

ServiceNow Integrated Risk Management (IRM) Practice Exam course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is the minimum role required to bulk initiate risk assessments using the risk assessment scheduler?
  • During classic risk assessment, while a Risk is in the Assess state, which action is possible?
  • Which of the following records is NOT among those to which Entity Types are applied?
  • What is the minimum role required for creating a policy acknowledgement campaign?
  • Which of the following is NOT a parent table for GRC: Risk Management tables?
  • In RAM, which assessment type is a valid option to enable?
  • Which role can move the control to the 'Monitor' state manually?
  • Which table links Policy Profiles to Policy Types?
  • Which destination is used for approved policies?
  • Which of the following is a typical example of an entity in the GRC framework (facility-related)?
  • Where does one go to configure the Regulatory Change Management impact assessment template?
  • Which option best describes the relationship between a facility and an entity in the GRC model?
  • GRC Options in Interactive Filters are available through which feature?
  • Which state does an approved audit engagement with no remaining open tasks move to?
  • Which feature of classic risk scoring is frequently configured by customers?
  • What does RAM stand for in ServiceNow IRM context?
  • Which GRC application is used to determine the areas where the organization is most vulnerable or exposed?
  • Which statement describes using a baseline template in consolidated attestations?
  • Why would a company need to comply with the General Data Protection Regulation?
  • Policies can be automatically published after which of the following occurs?
  • Controls are moved to which state from the attestation phase?
  • Which external component enables ServiceNow to ingest data from other systems?
  • Which table stores the explicit mapping between statements and citations?
  • Which table extends the Content (sn_grc_content) table to store citations?
  • Which mapping capability in the Classic UI relates specific Entities to each other within an Entity Class?
  • The Calculated Risk Score adjustments are driven by which factor besides the Inherent and Residual risk scores?
  • By default, who is assigned to complete control attestations in the baseline?
  • Which table is explicitly mentioned as part of a many-to-many relationship with Policy and Control Objective in ServiceNow GRC?
  • What does RAM stand for in this context?
  • Which of the following is NOT a parent table for GRC: Risk Management tables?
  • Which of the following is NOT a UCF term?
  • Which table extends from the Content Table?
  • Which table stores the many-to-many relationship between GRC profiles and their types?
  • Which table stores the links from the Entity Type to Risk Statement?
  • Which of the following is a valid mapping capability in Classic UI for relating Entities?
  • Where does a policy get published to when it is approved?
  • Which Script include can be modified to change how the compliance scores roll up?
  • Runbooks connect Security Incident Response Task and Knowledge Article.
  • In RAM, one valid method to identify controls is from the control library.
  • Which table stores the links from Policy to Control Objective?
  • Which filter navigation syntax displays the table in list view within a separate browser tab?
  • The Risk Scoring values are entered on the Risk Statement. What records inherits the values from the Risk Statement?
  • Santa Clara Facility and Boston Facility are examples of which concept in the GRC model?
  • If the audit engagement is approved and there are no remaining open tasks or issues, it automatically moves into which state?
  • Control Objectives are not active until the parent policy is in which state?
  • Which statement best describes an organization’s approach to a GRC deployment?
  • What table, along with the Policy table, is linked to the Control Objective table by a many-to-many relationship?
  • The 'Add to Update Set' utility is available for download via:
  • What does ALE stand for in risk management?
  • When calculating compliance scores, what is true about the weighting of Controls?
  • Which destination serves as the repository for knowledge articles after approval?
  • What is the primary purpose of Entity Classes in GRC?
  • What rule ensures that every time you create an Entity from a specific table, the Class of the Entity is set according to the rule?
  • Which option best describes the relationship between Control Objective and Policy in ServiceNow GRC?
  • In addition to Audit Manager, which role should be assigned to allow management of the audit process?
  • Which use-case for SLAs in this context is valid?
  • Which of the following is the correct syntax to display the default form view of the Risk table in the Content Frame?
  • What GRC module would you access in order to update Entity Types?
  • What is a primary table for the GRC Advanced Risk application scope?
  • Automatic policy publication is triggered by which condition?
  • Which of the following is true about the UCF-to-ServiceNow mapping for imports?
  • Which option best describes a typical initial stage for an organization adopting ServiceNow GRC?
  • Which of the following is a plausible trigger for automatic creation of an issue in GRC workflows?
  • Which option correctly identifies a commonly used baseline data element for Entity filters?
  • What is the repository for all identified risks?
  • Which of the following statements is true about how Risk Statements relate to Entity Types?
  • What should you do when risk thresholds in the Risk Criteria Matrix do not align with company needs?
  • To use User Reported Phishing v2 in Flow Designer, what must occur?
  • Which action is necessary to implement a second layer of policy approvals?
  • Which of the following records is most likely to be an Entity in the GRC data model?
  • Which option is a typical example of a record type that can be extended by risk-related tables in the GRC model?
  • Which GRC application would you use to manage internal or external consultancy processes that aim to prove the effectiveness of controls?
  • Which syntax opens the risk form in the Content Frame?
  • Which statement is true of a Risk Response task?
  • Which of the following describes how the risk form URL is used in the Content Frame?
  • Which role can you grant to external audit team members?
  • Which of the following statements best describes the Document extension set?
  • Which table stores the links from Policy to Control Objective in a RAM context?
  • What is the minimum role required to approve a Policy?
  • Which of the following would be considered an example of an Entity Type in the described data model?
  • Which audit module task focuses on testing controls to verify their effectiveness?
  • Which factor, when modified, directly affects the overall compliance score calculation?
  • Which of the following is a valid use of Entity Types and Entities in risk management?
  • Which role is required to create a risk assessment methodology (RAM)?
  • What happens when you assign an Entity Type to a Risk Statement?
  • Common controls from UCF are imported into which ServiceNow table?
  • What does SLE stand for in risk management?
  • Which of the following best describes the relationship of Risk Statement within the GRC data model?
  • Which two components are used to calculate the inherent risk score?
  • In this risk-management model, what must be true for a control objective and a risk statement to be automatically linked?
  • Which state represents formal attestation of controls?
  • Which term best describes the rule that automatically assigns the class when creating a new Entity?
  • Which of the following is true about the content model's relationship to risk definitions?
  • What is the function of the sn_compliance_policy table?
  • Which of the following is NOT typically an Audit module task?
  • Creating Entities in ServiceNow is easier as customers can leverage existing data used in other applications. Which of the following is a baseline table commonly used to build an Entity Type?
  • Which item is displayed as an extra related list when advanced planning is used?
  • In the context of risk scoring, which item is commonly configured by customers?
  • Which table extends from the Content Table?
  • Which of the following is NOT a primary parent table for GRC applications?
  • Which of the following is a risk record table in ServiceNow IRM?
  • What table is populated if a regulatory change is determined to be applicable?
  • Which item is NOT an extra related list shown with advanced planning?
  • Which option describes the correct mapping for Authority Documents in policy and compliance tracking?
  • Which option accurately describes the owner notification when a duplicate control is created automatically after manual creation?
  • Configuration Compliance is used to continuously monitor controls.
  • Which table stores the risk_definition profile type mapping?
  • Which of the following statements is true about the GRC Profiles application scope?
  • Entity Types generate entitlements based on which scope?
  • Which baseline criterion triggers notifications for audit tasks when the task is reassigned?
  • Which statement about the Calculated Risk Score is true?
  • An Entity in the system can belong to one or more of which categories?
  • A relationship between a registered risk and a control will be automatically generated when the control objective and risk statement have the same what?
  • What is the effect on risk scores when mitigating controls are in place?
  • What does UCF stand for in this content?
  • Controls are generated from a Control Objective when what is applied to it?
  • What condition must exist to edit the factor guidance of a published RAM?
  • Which table stores the link from Entity Types to Control Objectives?
  • As GRC maturity increases, which of the following is NOT expected?
  • Which role should be given to external auditors to view published policies and controls?
  • Which of the following is a valid table name that stores risk definitions in ServiceNow's content model?
  • Which is not used to source control data for a customer's control framework?
  • Which statement correctly describes the risk management lifecycle process?
  • What term describes the level of risk remaining after control measures are applied?
  • Which statement best describes Annualized Loss Expectancy in relation to risk score methodologies?
  • Control indicators may be triggered or scheduled in which state?
  • The Single Loss Expectancy is $1,000,000 and the Annual Rate of Occurrence is 20%. What is the Annualized Loss Expectancy?
  • In a GRC implementation, which role is appropriate to be directly involved?
  • Which policy lifecycle state is included in the ServiceNow baseline?
  • Which table is a primary example from the GRC Advanced Risk scope?
  • Which capability enables integration of Advanced Audit with PPM?
  • GRC Options in Interactive Filters are only available through which feature?
  • What is a key outcome of higher GRC maturity?
  • To have entities and controls created automatically after associating a control objective and configuration test, what must be true?
  • Which scheduled job is responsible for generating GRC profiles, thereby affecting the population of Entity records?
  • Which table extends the Content (sn_grc_content) table to store policy statements?
  • In ServiceNow Integrated Risk Management, which feature is used to track the completion of specific tasks?
  • Which role has the capability to create Policies?
  • Which of the following is true about creating a RAM in terms of role?
  • For Control records, who can modify the Control in the Draft state?
  • Entity scoping is used for what?
  • What are key prerequisites for a control test task to be generated?
  • Which data source is not used to source control data for a customer's control framework?
  • In classic risk assessment, indicator failure factor represents the impact on which score?
  • If the audit engagement is approved and there are remaining open tasks or issues, it automatically moves into which state?
  • What happens when you assign an Entity Type to a Control Objective?
  • Which table stores the link from Entity Types to Policies?
  • Which of the following is NOT a driver for customers to get the GRC suite of applications?
  • Which of the following relationship sets is a valid example of a many-to-many relationship in the data model?
  • What is a risk register?
  • The Tablename.config displays which content?
  • Entity Types use Entity Filters to generate entitlements based on which of the following?
  • Which content types can be ingested into ServiceNow via UCF integration?
  • Which GRC application would you use to prove the effectiveness of controls through consultancy processes?
  • Where are 80% of new customers within the GRC maturity model?
  • How can you obtain the SOX content pack for ServiceNow?
  • In the quantitative risk method, what is the risk likelihood called?
  • Which of the following is a typical first step when evaluating SOX content packs for ServiceNow?
  • Which baseline criterion triggers notifications for audit tasks when they expire?
  • What is the result of SLE × ARO in the risk scoring formula?
  • Which term describes risk after actions are taken?
  • EMEA Data Centers are an example of which data model concept?
  • In ServiceNow IRM, in which policy state can reviewers either send the policy back to draft or forward it by requesting approval?
  • What would you leverage in order to provide users with an alternate user experience to view policies, create policy exceptions, and search for controls?
  • In which state is the Policy once all approvals are received?
  • Which audit module task is typically used to gather information by interviewing a person?
  • All of the following are PARENT tables which exist within the GRC Entities application scope EXCEPT.
  • Which module houses the Regulatory Change Management impact assessment methodologies?
  • If you create a control manually and later decide to create them automatically, what will be the result?
  • All of the following are tables which exist within the GRC Profiles application scope EXCEPT:
  • Which statement best describes Entity Class Rules?
  • Configuration Compliance is used to do what in ServiceNow IRM?
  • Which table stored the links from Entity to Entity Types?
  • On rejection, which state does the engagement revert to?
  • To accommodate a customer's unique policy approvals process, which method is recommended?
  • Annualized Loss Expectancy is a feature of which risk score method?
  • After migrating to advanced risk assessment, which related list was added to risk statement and entity records?
  • Which of the following records is not associated with a lifecycle focus in GRC models?
  • Which of the following records does not have a lifecycle?
  • Which table stores a compliance policy?
  • Which data sources feed into the Calculated Risk Score along with inherent and residual risk scores?
  • Which of the following statements is true about control identification options for RAM?
  • What is the condition that must exist to edit the risk scoring logic of a published RAM?
  • Which table stores policy statements?
  • If the engagement is rejected, it automatically moves back to the Fieldwork state.
  • Which of the following is NOT displayed as an extra related list on the engagement record when advanced planning is selected?
  • There is a direct relationship between Entity Class and Entity Type when:
  • The Citation table is a child table of which parent?
  • The compliance score calculation may be modified by changing which control factor?
  • To complete the integration registry form for policy exceptions, what additional information must be provided beyond the registry entry name?
  • What are the four values leveraged for the Inherent and Residual Risk Score Types?
  • Which of the following is not a trigger for issue creation?
  • Which of the following is a commonly configured choice list on the Control Objective Table form?
  • In the Classic UI, which feature is used to build relationships between Entity Classes?
  • Which of the following is a valid state for a control record?
  • Which term describes risk before any actions are taken?
  • Which statement best describes the relationship Runbooks have with components?
  • Which table stores the links from Control Objective to Citation?
  • Which equation correctly expresses the Risk Scoring formula?
  • Which collection of tables extend the Document table?
  • Which concept is illustrated by Santa Clara Facility in the GRC data model?
  • What table extends from Document Table?
  • Which RAM-related term is used to describe a method for risk assessment?
  • Which statement about the Risk Store characteristics is true?
  • In addition to Audit Manager, which role should be assigned to enable other GRC functions related to audit?
  • Which ServiceNow role can manually move a Control record into the Monitor state?
  • Which role is directly involved in GRC implementations?
  • Who can move a Policy record from Review into the next state?
  • Which option correctly identifies the RAM assessment type enabled by default for RAM configurations?
  • The overall goal of Entity Classes is to:
  • Why would you create Entity classes?
  • Which regulation is listed as a possible healthcare entity scoping regulation?
  • Which ServiceNow table is used to store the Control Objective derived from the Unified Compliance Framework (UCF)?
  • An Observation can also be commonly known as what during an audit?
  • Which statement is true about RAM assessment context options?
  • Setting up entity classes is required when using which GRC feature?
  • Which of the following should be directly involved in GRC implementations?
  • Which action moves a policy from Review state back to Draft?
  • Which of the following is NOT commonly leveraged in Entity filters?
  • Which of the following extends from items?
  • Which of the following is a correct characteristic of the GRC Profiles scope tables?
  • Which table stores the links from Policy to Profiles?
  • Which of the following best describes obtaining added content packs for compliance?
  • The Acknowledgement Instance table extends from which table?
  • Which role is primarily responsible for reviewing risk responses in risk management?
  • The content table sn_grcs_content is a parent table of which of the following?
  • Which property controls score calculation by weighting controls?
  • Which statement best describes the role of Finding in audit terminology as presented?
  • Which statement describes the role of the Citation table?
  • Which statement best describes the relationship between advanced planning and engagement records?
  • Which role is not part of ServiceNow GRC?
  • Which table stores regulatory citations?
  • When the property Migrate to Advanced Risk Assessments is true, which forms are impacted?
  • Which scenario best describes an organization recently acquired with some bad audit findings using ServiceNow GRC to help restart their process?
  • Which property name indicates migration to advanced risk assessments?
  • Which statement is true about the new related list introduced after migration?
  • Which table stores the imported UCF control objective in ServiceNow?
  • Which RAM assessment types can be enabled when configuring a RAM?
  • Entity scoping is dynamic; what happens as new records meet criteria?
  • Which role reviews the risk response and moves the Risk record into the Monitor state at the appropriate time?
  • The SOX content pack includes a series of policies, control, risks. How are all of these components linked together?
  • Which audit module task is used to walk through the process to understand how it is implemented?
  • How does GRC: Policy and Compliance Management track compliance to Authority Documents?
  • Which statement best describes the purpose of Entity Classes?
  • If a control objective has been related to a risk statement and scoped with the same entity type, what can we expect to occur?
  • Which record is not required when configuring an RSS feed integration with a provider?
  • Which option best lists the entities included when configuring an assessment scheduler for RAM?
  • In policy workflow, which state indicates that a policy is awaiting approval before progress?
  • Which of the following is NOT part of the GRC Profiles scope according to the provided material?
  • In the risk data model, which of the following could represent a risk statement?
  • Which state does an approved audit engagement with ongoing tasks transition to?
  • Which of the following best describes the function of an Entity Type in relation to a Risk Statement?
  • Controls are put in place to ensure adherence to policies and regulations. When are they also helpful?
  • Control Failure Factor represents the impact of Control Failures on which score?
  • Which related list name is used to display aggregated risk data after migration?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy