Questions Flashcards

1
Q
Which of the following tables exist within the GRC: Profiles application scope? (Choose three.)
A. Document
B. Policy
C. Risk
D. Content
E. Indicator
A

A,D,E
https://docs.servicenow.com/bundle/madrid-governance-risk-compliance/page/product/grc-policy-and-compliance/concept/profiles-policy-compliance.html

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are some characteristics of the ServiceNow Store? (Choose four.)
A. Some applications are certified by ServiceNow
B. All applications are certified by ServiceNow
C. Applications may be developed by ServiceNow Technology Partners
D. It houses both paid and free applications and integrations
E. Applications are built om the ServiceNow platform
F. Applications are certified by other developers

A

BCDE
https://www.servicenow.co.jp/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/data-sheet/ds-servicenow-store.pdf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q
Which role is not part of ServiceNow GRC?
A. Risk User
B. Risk Developer
C. Risk Manager
D. Risk Reader
A

B is correct, should be risk admin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which of the following statements is true of a Risk Response task?

A. Only one Risk Response task can be related to a Risk at a time
B. Only users with the risk_manager role or higher can be assigned to a Risk Response task
C. The risk admin role is required to assign the Risk Response task
D. The Risk Response task is automatically progressed through the states using a worflow

A

Risk managers can assign risk response tasks. D is correct

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q
What table, along with the Policy table, is linked to the Control Objective table by a many-to-many
relationship?
A. Entity Class
B. Citation
C. Authority Documents
D. Risk Framework
A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q
Why would you create Entity classes?
A. To show relationships between tables or objects you are tracking that doesn’t otherwise exist
anywhere in ServiceNow
B. To be assigned to risk statements, which generate risks for every Entity listed in the Entity Class
C. To be assigned to Control Objectives, which generate Controls for every Entity listed in the Entity class
D. To show relationships between Entities and Policies and map them directory to Citations
A

A. “Create entity classes to show relationships between tables or objects you are tracking
that don’t otherwise exist anywhere in ServiceNow.” -From the book. pg. 98

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

TheTablename.config:
A. Displays the configuration list view of the table in the browser tab
B. Displays the table in list view within the Content Frame
C. Displays the table in list view within a separate browser tab
D. Displays the configuration list view of the table in the Content Frame

A

D
https://docs.servicenow.com/bundle/orlando-platform-user-interface/page/administer/navigation-and-ui/task/t_NavigateDirectlyToATable.html

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
Which of the following extends fromitems?
A. Citation
B. Controls
C. Issue
D. Policy
A

B. Controls and Risks extend sn_grc_item

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What happens when you assign an Entity Type to a Risk Statement?
A. An assessment will be automatically generated to test each Entity listed in the Entity Type
B. A risk assessment is created automatically for every Entity listed in the Entity Type
C. A risk is automatically generated for every Entity listed in the Entity Type
D. The Entity is now going to present a risk score and controls are going to be tied to it

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
There is a direct relationship between Entity Class and Entity Type when:
A. They have the same Entity Types
B. There is no direct relationship
C. They have the same Entities
D. They leverage the same reporting
A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
Which filter navigation syntax displays the table in list view within a separate browser tab?
A. Tablename_LIST
B. Tablename.list
C. Tablename.LIST
D. Tablename.List
A

c

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Jim is an Audit Manager. In addition to Audit Manager, which roles should be assigned to ensure he can
manage the audit process as well as other GRC functions related to audit? (Choose two.)
A. sn_grc.manager
B. sn_audit.user
C. sn_grc.user
D. sn_grc.reader
E. sn_grc.developer

A

Strange question… if he has audit manager, he has audit user automatically.
If he gets sn_grc.manager, he gets sn_grc user automatically. I think the best answer is
what’s here, AB.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
What table extends from DocumentTable?
A. Risk
B. Risk Framework
C. Risk Response Task
D. Risk Statement
A

b

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q
Which of the following are scoped applications related to the Risk and Compliance applications? (Choose
four.)
A. GRC: GRC Profiles
B. GRC: Attestation Design
C. GRC: UCF Compliance
D. GRC: Policy and Compliance
E. GRC: Performance Analytics
F. GRC: Risk
Management
A

A,D,E,F

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q
Which tables extend the Content (sn_grc_content) table? (Choose two.)
A. sn_compliance_citati
on
B. sn_grc_issue
C. sn_compliance_policy_statement
D. sn_risk_risk
A

A C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q
All of the following are PARENT tables which exist within the GRC Entities application scope EXCEPT.
A. Item
B. Document
C. Content
D. Indicator
A

“GRC Entities” scope/app doesn’t exist. GRC: Profiles does, and all 4 choices belong to this scope.
However, Indicator is a child table as it extends Base Indicator. Document, Item and Content all don’t extenany tables so D is the answer.

17
Q

Which table stored the links from Entity to Entity Types?
A. [sn_compliance_m2m_profile_profile_type]
B. [sn_risk_m2m_risk_profile]
C. [sn_compliance_m2m_policy_profile]
D. [sn_grc_m2m_profile_profile_type]

A

D

18
Q
Where does a policy get published to when it is approved?
A. Knowledge Summit
B. ServiceNow 
C. Authoritative Records
D. Knowledge Base
A

D

19
Q
What GRC module would you access in order to update Entity Types?
A. Risk > Entities
B. Scoping > Profiles
C. Scoping > Entity Types
D. CMDB
A

C
Entity types exists under the scoping module under both the risk
and policy and compliance applications in the filter nav

20
Q

The ServiceNow Platform requires which external components in order to ingest data from other systems?
A. The platform includes an SDK template that allows developers to enhance it using Java
B. A messaging bus needs to be developed
C. The platform allows XML to be ingested, and it required developers to leverage XSLT to map it
properly
D. The platform has Integration Service that allow users and developers to ingest data from a
variety of sources

A

D

21
Q

You are working with your customer to determine necessary audit management workflow configurations.
What should they know about the approval process for audit engagements? (Choose three.)

A. If the engagement is approved and there are remaining open tasks or issues, it automatically moves
into the Follow Up state.
B. If the engagement is approved and there are no remaining open tasks or issues, it automatically moves
into the Closed state.
C. If the engagement is rejected, it automatically moves back to the Fieldwork state.
D. If the engagement is approved and there are remaining open tasks or issues, it automatically moves
into the Fieldwork state.
E. If the engagement is rejected, it automatically moves into the Scope state.

A

ABC

22
Q
Which GRC application would you use to manage internal or external consultancy processes that aim to
prove the effectiveness of controls?
A. Audit Management
B. Risk Management
C. Vendor Risk Management
D. Policy and Compliance Management
A

A

23
Q
What are the Risk Scoring methods available in ServiceNow? (Choose two.)
A. Quantitative
B. Qualitative
C. Inherent
D. Residual
E. Calculated
A

A B

24
Q

The Risk thresholds in the Risk Criteria Matrix (default values) do not line up with company needs. What
should you do?
A. Configure the Risk Criteria in ServiceNow
B. Identify Risk that will benefit from the default values
C. Demonstrate Risk scoring scenarios using the default values
D. Use the default values to determine new company approach

A

A

25
Q
The Citation table is a child table of which parent?
A. Content
B. Authority Document
C. Item
D. Document
A

B
This is technically correct I think. Authority documents have many citations. However
its important to note Citation EXTENDS Content and not Authority Document

26
Q

Entity Table name

A

sn_grc_profile