Which three steps can be performed by using the Configure Module Objects pages? (Choose three.)
A. Choose display (or hide) configurable options for: results, events, consequences and treatments.
B. Set "object-perspective" association.
C. Create object data import templates.
D. Edit the assessment activity question and guidance text for all assessment types.
E. View assessment response details for all assessment types.
You are advising your client on design and configuration related to how access incident results will be viewed and managed. The client has provided a list of business requirements: Incident results can be viewed by Department Groups of investigators receive assigned incidents based on Department Must ensure systematically that no incident is unassigned to an investigator
Which three must be configured to support these requirements? (Choose three.)
A. Worklist assignment Result Investigator should be set to specific users.
B. Custom perspective for Department linked to the Results object with Required set to "No"
C. Custom perspective for Department linked to the Results object with Required set to "Yes"
D. Investigators are assigned job roles with custom Department perspective data roles attached. Other incident users receive job roles which only allow viewing of incidents.
E. Investigators are assigned job roles with custom Department perspective data roles attached for managing incidents. Other incident users are assigned job roles with custom Department perspective data roles attached for viewing only.
F. Worklist assignment Result Investigator should be set to "All Eligible Users"
Your client has configured separate roles for control assessor and control assessment reviewer. The control assessor has submitted his or her assessment. The control assessor realizes later that he or she has forgotten to attach a critical test evidence document to the assessment and needs to attach it now. How can this be accomplished?
A. The assessor can request the reviewer to attach the document during the review.
B. On the Assessment tab in the Control definition, the assessor can select the assessment and click the Complete Assessment button. He or she can attach the document and resubmit the assessment.
C. The assessor can request the reviewer to reject the assessment. After the assessment is rejected, the assessor can then attach the document and resubmit the assessment.
D. On the Manage Assessments page, the assessor can select the assessment and click the Reopen button. He or she can then attach the document and resubmit the assessment.
During an assessment, an issue was created. Your job as the Issue Manager is to review the issues and
validate them. If it is determined that they are not valid issues, you need to close them. You have found an
issue that is not valid and with Status: Open and State: Reported.
Identify the correct step to close this issue.
A. On the Manage Issues page, highlight the issue and click the Close button.
B. The assessment associated to the issue must be completed before closing the issue. Only then can you close the issue.
C. After you have completed the remediation plan, click the Close button on the Remediation Plan page.
D. Ensure that the issue status is In Edit, and then from the Actions menu, select Close Issue.
During implementation, you created a risk object and successfully mapped it to a control object. The
client's Risk Owner is able to access the risk but not the control.
Why did this happen?
A. The Risk Administrator needs to run the synchronize jobs to populate the mapping.
B. The Risk Owner account is inactive.
C. The Risk Owner role does not have the right privileges.
D. The risk and control objects are inactive and need to be made active.
You have two segregation of duties requirements:
1) a user can access either the supplier creation pages or the invoice pages, but not both.
2) a user can access either the invoice creation pages or the payment creation pages, but not both.
How must these requirements be met in Advanced Access Controls?
A. Construct one model with three condition filters where the Function Name Equals "Create Supplier", "Create Invoice" and "Create Payment"
B. Construct two models, and create controls based on the models: "Create Supplier and Create Invoice", "Create Invoice and Create Payment"
C. Construct three controls, and create controls based on the models: "Create Supplier and Create Invoice", "Create Invoice and Create Payment", "Create Supplier and Create Payment"
D. Construct one model: "Create Supplier and Create Invoice and Create Payment"
E. Construct one entitlement: "Create Supplier and Create Invoice and Create Payment"
At the last step of initiating assessments, the assessment manager sees who the assessment participants are (to complete, review, and approve the assessments). If the assessment manager wants to change the participant, who completes the assessment, what should he or she do?
A. Modify the perspective hierarchy in the last step of initiating assessments.
B. Modify the participant list in the last step of initiating assessments.
C. Request the administrator to change the Perspective in Data Security Policy for the Control Manager's job role.
D. It is not possible to change the participants after Data Security Policies are assigned.
E. Request the administrator to assign Data Security Policies with correct perspectives to the Assessor's job role.
How do you associate a risk to a control?
A. On the Related Controls tab of risk definition, add the control.
B. To associate a control to a risk, the control needs to be in the Review state.
C. In the related object section of process definition, add the control to the risk.
D. On the Related Objects tab of control definition, add the risk.
E. The only way to create risk-control associations is through data import.
A user has created and submitted a new control and the state of the control is "In Review." The user expected that the control state would change to "Approved."
Why is the control not in the "Approved" state?
A. This user is not a Control Approver; therefore, the status will be "In Review."
B. The Control Reviewer role has been assigned to some users.
C. New controls must always be reviewed, irrespective of security configuration.
D. The Control Approver role has been assigned to some users.
Which three objects can be related to issues when creating an issue on the Manage Issues page? (Choose three.)
A. Test Plans
B. Assessments
C. Processes
D. Perspectives
E. Risks
F. Controls