CIS-RC Sample Questions & Answers
Policy and compliance record life cycles tie with risk and advanced risk configuration for the heaviest weight, next to scoping entities by type and class, GRC terminology and framework basics, integrations and other platform capabilities, and audit management.
Launch the full CIS-RC simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Policy and Compliance · Policy Architecture
A global retailer is setting up its Policy and Compliance module. They have a parent 'Code of Conduct' policy that applies to all employees worldwide. They also have regional 'Acceptable Use' policies for North America, Europe, and Asia, which contain specific clauses relevant to local regulations. What is the best practice for structuring these policies in ServiceNow?
Show answer & explanation
Correct answer: B
Using the parent/child policy relationship is the designed best practice for this scenario. It allows for a clear hierarchy, separate ownership and review cycles for the regional child policies, and the ability to link common controls from the parent down to the children. This structure is scalable and easy to navigate.
- Question 2Intermediate
Implementation Planning · Risk and Compliance Personas, Groups and Roles
A GRC implementation requires a new role for junior compliance analysts. This role should allow users to view Policies, Control Objectives, and Controls, and to create evidence requests. However, they should NOT be able to approve policy exceptions or move a control into the 'Attest' state. Which base GRC role would be the most appropriate starting point to clone and modify for this purpose?
Show answer & explanation
Correct answer: D
The sn_compliance.user role provides the correct baseline of permissions. It allows users to interact with compliance records, such as responding to requests and creating evidence, but does not grant high-level administrative or managerial permissions like approving exceptions or changing control states. It is the ideal starting point to clone for a junior analyst role.
- Question 3Intermediate
Entity Framework · Entity Type Approach
A hospital system is using ServiceNow GRC to manage HIPAA compliance. They need to generate controls for every department that handles Protected Health Information (PHI). They have a CMDB, but the concept of a 'department handling PHI' is a business construct, not a specific CI class. The list of these 30 departments is maintained by the compliance team. Which approach should be used to define these departments as Entities?
Show answer & explanation
Correct answer: C
The Entity Type approach is ideal for this scenario. It is designed for creating a manually curated collection of entities that may not be easily grouped by a simple filter condition. Since the list of 30 departments is small and maintained by a specific team, an Entity Type provides a direct and simple way to group them for GRC purposes.
- Question 4Beginner
Entity Framework · Entity Generation
The scheduled job
GRC Profile Generationis responsible for which of the following actions?Show answer & explanation
Correct answer: C
This scheduled job runs periodically to evaluate the filter conditions on all active Entity Classes. It creates new Entity (Profile) records for source records that now match the filter, retires Entities whose source records no longer match, and updates existing Entities if their source data has changed.
- Question 5BeginnerSelect 2
Risk and Advanced Risk · Risk Response
Which two of the following are valid response options for a risk identified during an assessment? (Select TWO)
Show answer & explanation
Correct answers: A, D
Accept is a standard risk response strategy where the organization acknowledges the risk and decides not to take any action to reduce it, often because the cost of mitigation outweighs the potential loss.
Mitigate is a common risk response strategy that involves implementing controls or countermeasures to reduce the likelihood or impact of the risk.
- Question 6Intermediate
Audit Management · Audit Execution
An internal audit team is conducting a review of access controls. They need to test a single control, 'Quarterly User Access Review', against 50 different application entities. What is the most efficient way for the audit manager to structure this work in the Audit Management application?
Show answer & explanation
Correct answer: B
This is the designed and most efficient process. A single Audit Engagement can scope multiple entities. The system can then automatically generate individual control test tasks for the 'Quarterly User Access Review' control for each of the 50 application entities, allowing for parallel execution and centralized tracking within one engagement.
- Question 7Advanced
Entity Framework · Entity Architecture
Case Study:
Company Background: GlobalLogix is a multinational logistics company with operations in North America (NA), Europe (EU), and Asia-Pacific (APAC). Each region operates as a semi-autonomous business unit. The company is publicly traded in the US and must comply with SOX. The EU operations must also comply with GDPR.
Current Situation: GlobalLogix is implementing ServiceNow GRC to centralize its compliance efforts. They have a single global CMDB. The IT department is organized globally, but certain applications and servers are dedicated to specific regions. The compliance team is structured with a global lead and regional compliance managers.
Requirements:
- SOX controls must be applied to all financial systems globally.
- GDPR controls must be applied ONLY to systems processing data for EU citizens.
- Regional compliance managers should only see and manage controls and issues for their respective regions.
- A consolidated, global view of compliance posture must be available to the global lead.
Architectural Challenge: The implementation team needs to design the Entity Framework to meet these requirements efficiently. Which design represents the BEST approach?
APPROACH A: Single Level Entity Classes [Entity Class: NA Systems] -> Filters on location=NA [Entity Class: EU Systems] -> Filters on location=EU [Entity Class: APAC Systems] -> Filters on location=APAC [Entity Class: Financial Systems] -> Filters on app_function=Finance APPROACH B: Hierarchical Entity Types [Entity Type: GlobalLogix] |-- [Entity Type: NA Region] |-- [Entity Type: EU Region] |-- [Entity Type: APAC Region] Manually add systems to each type. APPROACH C: Hierarchical Entity Classes [Entity Class: Global Systems (Parent)] -> No filter |-- [Entity Class: NA Systems (Child)] -> Filters on location=NA |-- [Entity Class: EU Systems (Child)] -> Filters on location=EU |-- [Entity Class: APAC Systems (Child)] -> Filters on location=APAC Another separate class for Financial Systems.Show answer & explanation
Correct answer: A
This hybrid approach is the most robust. The hierarchical Entity Classes for regions allow for both regional-specific control scoping and global roll-up reporting. A separate, flat Entity Class for financial systems provides a clear, dynamic group for applying SOX controls globally. Security can then be managed effectively using User Groups (e.g., 'EU Compliance Managers') assigned as owners to the regional entities, combined with ACLs to enforce visibility, satisfying all requirements.
- Question 8Beginner
GRC Overview · Key Terminology
What is the primary purpose of the 'Content' table [sn_grc_content] within the GRC: Profiles application scope?
Show answer & explanation
Correct answer: A
The Content table [sn_grc_content] is a core component used by GRC content packs and regulatory intelligence integrations. It serves as a repository for the definitions and text of external standards, regulations, and frameworks. Records from this table are then used to create or update Authority Documents, Citations, and Control Objectives within ServiceNow.
- Question 9Intermediate
Common Elements and Extended Capabilities · Integrations
A compliance team uses a third-party system to track regulatory updates. When a new regulation is published, they want to automatically import it into ServiceNow as an Authority Document and its individual articles as Citations. Which ServiceNow capability is best suited for this recurring, automated integration?
Show answer & explanation
Correct answer: A
IntegrationHub is the platform's strategic tool for building reusable, code-less/low-code integrations. By using a REST step (if the third-party system has an API) or building a custom Spoke, the compliance team can create a robust, scheduled data flow to automatically pull regulatory data and map it to the Authority Document and Citation tables. This is the recommended approach for automated, recurring integrations.
- Question 10Intermediate
Policy and Compliance · Policy Lifecycle Management
True or False: Once a Policy has been moved to the 'Published' state, it cannot be reverted to 'Draft' for further edits. A new version of the policy must be created.
Show answer & explanation
Correct answer: B
False. A user with the appropriate permissions (typically sn_compliance.manager or sn_compliance.admin) can use the 'Recall' UI action to move a 'Published' policy back to the 'Review' state, and from there it can be moved back to 'Draft' for edits. While creating a new version is a best practice for significant changes, the system does allow for recalling a published policy.
Ready for the real thing?
The full CIS-RC simulator has every exam-style question, timed mode, and instant scoring.