ServiceNow CIS-SIR Certification Exam Sample Questions

CIS-SIR Dumps PDF, Security Incident Response Implementation Specialist Dumps, download CIS-Security Incident Response free Dumps, ServiceNow Security Incident Response Implementation Specialist exam questions, free online CIS-Security Incident Response exam questionsYou have to pass the CIS-SIR exam to receive the certification from ServiceNow. To increase the effectiveness of your study and make you familiar with the actual exam pattern, we have prepared this ServiceNow Security Incident Response Implementation Specialist sample questions. Our Sample ServiceNow Certified Implementation Specialist - Security Incident Response Practice Exam will give you more insight about both the type and the difficulty level of the questions on the ServiceNow CIS-Security Incident Response exam.

However, we are strongly recommending practice with our Premium ServiceNow Certified Implementation Specialist - Security Incident Response (CIS-SIR) Practice Exam to achieve the best score in your actual ServiceNow CIS-SIR Exam. The premium practice exam questions are more comprehensive, exam oriented, scenario-based and exact match of ServiceNow Certified Implementation Specialist - Security Incident Response exam questions.

ServiceNow Security Incident Response Implementation Specialist Sample Questions:

01. A consultant compares two customers who both run Security Incident Response. On one instance the Severity calculator group offers a priority calculator that takes the incident's observables into account, and on the other that calculator is simply not there. Nobody on the second instance has deactivated or deleted a calculator.
Which three statements should the consultant give the second customer?
(Choose three.)
a) Both calculators are provisioned in the Severity calculator group on every instance regardless of pricing tier, and the missing one needs its Active check box selected.
b) Set priority with category and services is the calculator provided at the Starter Security Operations pricing tier.
c) The observable-driven calculator appears as soon as the new Risk Score Calculator property is set to true.
d) Set priority with observables needs the Advanced tier together with the Threat Feeds plugin.
e) Which risk calculator the base system provides depends on the organization's Security Operations pricing tier.
 
02. A customer has activated the new Risk Score Calculator and wants phishing incidents scored by one model and confidential data exposure incidents scored by another. An administrator opens the Rules Engine in the Security Incident Response Workspace and looks for a way to add a second risk score rule.
What should the administrator report back to the customer?
a) The predefined rule can be duplicated, and the copy edited for the second category.
b) The base system provides a single risk score rule, which can be customized and enabled but can neither be created nor deleted.
c) The predefined rule can be deleted and rebuilt from scratch, once the activation property is set back to false.
d) A second risk score rule can be created and given its own criteria, so each category is scored on its own terms.
 
03. A monitoring tool's service account authenticates to the instance and writes rows into the Security Incident Import sn_si_incident_import table, and the rows themselves are well formed, but no security incident is ever produced from them.
Which role is the service account missing?
a) sn_si.ingestion_profile_admin, which creates and manages the profiles for the Splunk, Splunk ES and Azure Sentinel integrations
b) sn_si.basic, the role that creates and updates incidents, requests and tasks
c) sn_si.integration_user, through which external tools provide and update security incident records
d) sn_si.knowledge_admin, the Security Incident Knowledge Administrator role carried by the SOC's knowledge team
 
04. A security administrator builds a new security incident calculator group beside the base-system groups. Its calculators match the incidents the administrator expects, but the administrator needs this group to be evaluated ahead of the Severity group.
Which setting determines the sequence in which calculator groups are evaluated?
a) The Calculate Severity related link on the security incident
b) The Active check box on each of the group's calculators
c) The Order field on each calculator inside the group
d) The Order field on the calculator group record
 
05. A security administrator opening Security Incident Calculator Groups in the base system finds a group named User criticality, and inside it a calculator called Get user criticality.
What does that calculator do?
a) It elevates the Risk score, Business Impact and Priority of any incident that is found to touch a business-critical asset.
b) It changes a user's business criticality to 1 - Critical when that user's Department field is set to Finance.
c) It elevates the Risk score, Business Impact and Priority when the criticality of the incident's business service becomes most or somewhat critical.
d) It adds the user to the post incident review list for a security incident.
 
06. A security manager is preparing the half-yearly reviews of the analysts who work the incident queue, and wants a base-system dashboard showing how many security incidents each of them closed and how long each of them took, rather than how the queue as a whole is moving.
Which dashboard should the manager open?
a) The Security Incident Management dashboard, whose widgets include New Security Incidents, Open Security Incidents and New Security Incidents by Priority
b) The Security Incident Explorer dashboard, which groups security incidents by category, subcategory, location, priority and business impact
c) The CISO dashboard, the executive view a security leadership team opens when it is asked about the organization as a whole
d) The Security Operations Efficiency dashboard, whose metrics cover both the overall efficiency and the individual performance of the SOC team
 
07. A SOC works a large intrusion as a parent security incident with two child incidents beneath it. On one of the children, an analyst has a response task in Work In Progress and is part way through it.
At the end of the shift the SOC manager closes the parent record. No one else opens the child incident, and no analyst touches the task. When the analyst returns to it, the response task is in the Canceled state.
What accounts for the canceled response task?
a) Closing the parent security incident canceled the response tasks belonging to its child incident.
b) Closure automatically cancels an incident's active workflows, playbook activities and flows.
c) Advanced Work Assignment pulled the task back when the parent incident closed.
d) Bulk closure was used on the parent, and it closes the active tasks, playbooks, child incidents and assessments still pending.
 
08. An administrator has revised several weight values on an instance that uses the classic risk score configuration. Security incidents scored under the earlier weights must be brought into line with the revised ones.
Which two actions reach the whole set of risk score weight records in one step?
(Choose two.)
a) Clear All Risk Scores on the Risk Score Weights form
b) Recalculate Score on the new Risk Score Calculator Rule
c) Calculate Severity on one security incident record
d) Update All Risk Scores on the Risk Score Weights form
 
09. An administrator who holds the security administrator role is asked why a security tag that several records carried last week is no longer on any of them. Opening the records shows the tag gone, the audit history shows no user removing it, and the tag and its group are both still active and unchanged.
What accounts for the tag disappearing?
a) The tags are rewritten in the background each time the incident's affected services and impacted CIs related lists are refreshed by an event.
b) Clearing Allow multi-selection on the group leaves a record with only one of that group's tags and drops any others it was carrying.
c) A security tag rule applied the tag, and rules take their tags off automatically once the conditions stop matching.
d) A tag group enforcing restricted access, through its read and write roles, hides the tag from users lacking them.
 
10. An instance has been locked down so that Security Incident Response is closed to the platform administrator, with the application's administration held elsewhere. To demonstrate the lockdown to an auditor, an IT system administrator impersonates the user who holds that application admin role and works through the application.
What does the impersonating administrator find?
a) The features that role grants, including security incidents and profile information, are out of reach, and the modules in the navigation bar are restricted as well.
b) Everything that role grants is available, because the base system also assigns the administrator the security administrator role.
c) Security incidents open as usual, although the password of the user being impersonated cannot be changed.
d) The modules stay in the navigation bar, security incidents and profile information open as usual, and each record shows its fields or its related lists.

Answers:

Question: 01
Answer: b, d, e
Question: 02
Answer: b
Question: 03
Answer: c
Question: 04
Answer: d
Question: 05
Answer: b
Question: 06
Answer: d
Question: 07
Answer: a
Question: 08
Answer: a, d
Question: 09
Answer: c
Question: 10
Answer: a

If you find any errors or typos in ServiceNow Certified Implementation Specialist - Security Incident Response (CIS-SIR) sample question-answers or online ServiceNow CIS-Security Incident Response practice exam, please report them to us on feedback@processexam.com

Your rating: None Rating: 4.8 / 5 (82 votes)