Which three steps can be performed by using the Configure Module Objects pages? (Choose three.)
A. Choose display (or hide) configurable options for: results, events, consequences and treatments.
B. Set "object-perspective" association.
C. Create object data import templates.
D. Edit the assessment activity question and guidance text for all assessment types.
E. View assessment response details for all assessment types.
A Control Manager has changed the status of an issue to "In Remediation" and has submitted it. What will be the state of the Issue if there is no issue validator, reviewer, or approver configured?
A. In Review
B. Active
C. Reported
D. Approved
E. In Edit
Select three fields that are required to create an impromptu assessment. (Choose three.)
A. Due Date
B. Template
C. Name
D. Reviewer
E. Perspectives
F. Activity
Which three tasks should be completed before starting the Financial Reporting Compliance implementation? (Choose three.)
A. Migrate the organization's existing risk and control matrix into Financial Reporting Compliance.
B. Complete control review and assessment for one period/cycle with the actual business owners.
C. Create a project plan with objectives, goals, and exit criteria.
D. Identify Financial Reporting Compliance users for everyday use, administration, and sustained use.
E. Plan to go-live with a simple scope and later expand the solution to include additional business units/ organizations/compliance frameworks.
When validating imported data, the control manager at your client has identified an incorrect Risk- Control mapping; that is, Control A was mapped incorrectly to Risk B instead of Risk.
What needs to be done to fix the mapping?
A. Option A
B. Option B
C. Option C
D. Option D
You have two segregation of duties requirements:
1) a user can access either the supplier creation pages or the invoice pages, but not both.
2) a user can access either the invoice creation pages or the payment creation pages, but not both.
How must these requirements be met in Advanced Access Controls?
A. Construct one model with three condition filters where the Function Name Equals "Create Supplier", "Create Invoice" and "Create Payment"
B. Construct two models, and create controls based on the models: "Create Supplier and Create Invoice", "Create Invoice and Create Payment"
C. Construct three controls, and create controls based on the models: "Create Supplier and Create Invoice", "Create Invoice and Create Payment", "Create Supplier and Create Payment"
D. Construct one model: "Create Supplier and Create Invoice and Create Payment"
E. Construct one entitlement: "Create Supplier and Create Invoice and Create Payment"
You want to identify Controls with the most Incidents, with the condition that the identified Controls should
have 80% of all Incidents. To do this, you have imported a custom object that contains the number of
incidents associated with each control, and have added that object to a transaction model.
Which pattern filter must you now apply?
A. Anomaly Detection
B. Mean
C. Pareto
D. Absolute Deviation
E. Clustering
You are remediating access incidents in Advanced Access Controls (AAC), and have just completed the
remediation of a segregation of duties conflict for users in Fusion Security by removing the conflicting
access from the users.
What status do you set for the incident in AAC?
A. Resolved
B. Remediation
C. Remedy
D. Authorized
E. Accepted
Which part of the security structure cannot be created or viewed from the Security Console, when configuring security for Financial Reporting Compliance?
A. Composite Duty Role
B. Job Role Perspective Policy
C. Data Security Policy
D. Functional Security Policy
The GRC Business owner responsible for reviewing and investigating access incidents related to the "Order to Cash" perspective does not see any worklists for the generated results. You have validated that:
1.
Other business owners are able to view their assigned worklists without any problem
2.
Incidents have been generated for the controls related to Order to Cash
3.
The business owner's assigned roles contain the correct functional privileges and data access to the correct perspective values
What is the reason the business owner cannot see any worklists for the generated incidents?
A. The Result Management Perspective Assignment has not been linked.
B. The underlying model is not linked to Order to Cash.
C. The business owner was recently assigned the role and the worklist needs to be refreshed.
D. Worklist assignment does not include the business owner.
E. The Control Perspectives are not linked to the control.