Which role is not part of ServiceNow GRC?
A. Risk User
B. Risk Developer
C. Risk Manager
D. Risk Reader
Which of the following statements is true of a Risk Response task?
A. Only one Risk Response task can be related to a Risk at a time
B. Only users with the risk_manager role or higher can be assigned to a Risk Response task
C. The risk admin role is required to assign the Risk Response task
D. The Risk Response task is automatically progressed through the states using a worflow
Which of the following extends from items?
A. Citation
B. Controls
C. Issue
D. Policy
The ServiceNow Platform requires which external components in order to ingest data from other systems?
A. The platform includes an SDK template that allows developers to enhance it using Java
B. A messaging bus needs to be developed
C. The platform allows XML to be ingested, and it required developers to leverage XSLT to map it properly
D. The platform has Integration Service that allow users and developers to ingest data from a variety of sources
The Risk Scoring values are entered on the Risk Statement. What records inherits the values from the Risk Statement?
A. Risk Criteria Matrix
B. Risk Framework
C. Registered Risk
D. Risk Response Issue
Which of the following statements correctly describe the risk management lifecycle process?
A. Access, Identify and Plan, Control, Review
B. Control, Review, Assess, Identify and Plan
C. Identify and Plan, Assess, Control, Review
D. Identify and Plan, Review, Assess, Control
When calculating compliance scores, what is true about the weighting of Controls? (Choose two.)
A. Controls are not weighted equally by default
B. The weight cannot be changed
C. The default value is 10
D. The weight of the Control is set when the Control is created
Which role(s) has the capability to create Policies? Choose two.)
A. Compliance Manager
B. Compliance admin
C. Compliance User
D. Risk Manager
What type of customers may you encounter? (Choose three.)
A. Organization recently acquired and had some bad audit findings (using ServiceNow GRC to help restart their process)
B. Organization with little to nothing in place already (implementing one or more core ServiceNow GRC applications)
C. Organization undergoing a full GRC transformation (implementing all three core ServiceNow GRC applications at once or in a phased approach)
D. Organization implementing ServiceNow GRC to help ease their Customer Service organization (using other tools to manage other processes)
E. Organization implementing ServiceNow GRC to help ease their Help Desk organization (using other tools to manage other processes)
Control indicators may be triggered or scheduled in which state?
A. Retired
B. Monitor
C. Review
D. Attest
E. Draft