CIS-VR Sample Questions

CIS-VR Sample Questions & Answers

Core applications for container security tie with pulling in vulnerability data for the top share, alongside workspace tools for managing it all, automating exceptions and workflow responses, and dashboards for tracking performance.

Launch the full CIS-VR simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Getting Data into Vulnerability Response · Scanner Integration Setup

    True or False: By default, the ServiceNow Vulnerability Response integration with Tenable.io only imports vulnerabilities that have been detected within the last 90 days.

    Show answer & explanation

    Correct answer: A

    This is true. The 'Vulnerability Import since' property for the Tenable.io integration is set to 90 days by default. This is a configurable setting designed to prevent the import of a massive amount of historical, potentially irrelevant vulnerability data on the first run. Administrators can and often should adjust this value based on their specific requirements.

  2. Question 2Advanced

    Tools to Manage Vulnerability Response · Risk Calculators

    An organization's risk calculation model needs to be updated. The new model requires that any vulnerability on a CI that is part of a 'PCI Compliant' business service automatically has its risk score increased by 20 points, in addition to the standard CVSS-based calculation. Which component of Vulnerability Response should be customized to implement this requirement?

    Show answer & explanation

    Correct answer: B

    Vulnerability Calculator Groups contain one or more Vulnerability Calculators that define how the risk score is calculated. To add custom logic, such as increasing the score based on a CI's relationship to a business service, you would typically clone the default calculator and modify its script. This script can query related records (like the Business Service) and adjust the score accordingly. This modified calculator is then made active within the group.

  3. Question 3Intermediate

    Automating Vulnerability Response · Change Management Integration

    A hospital is using ServiceNow VR to manage vulnerabilities on medical devices. When a high-severity vulnerability is confirmed on a device, a standard change request must be created and linked to the Vulnerability Group for patching. Which ServiceNow feature is best suited to automate the creation of this change request when the Vulnerability Group's state is moved to 'Awaiting Change'?

    Show answer & explanation

    Correct answer: C

    Flow Designer is ServiceNow's modern, low-code solution for process automation. It is the ideal tool for this scenario. A flow can be configured with a trigger that runs whenever a Vulnerability Group record is updated and its 'State' field changes to 'Awaiting Change'. The flow can then use the 'Create Record' action to generate a new change request, populating its fields with data from the vulnerability group.

  4. Question 4Intermediate

    Vulnerability Response Dashboards and Reports · Performance Analytics and Metrics

    A SecOps manager wants to analyze the Mean Time to Remediate (MTTR) for vulnerabilities, but wants to see the data trended over time and broken down by the CI's operating system. What Performance Analytics component allows for filtering the indicator data by operating system?

    Show answer & explanation

    Correct answer: C

    In Performance Analytics, a Breakdown is used to group or filter indicator scores for more detailed analysis. To see MTTR (the Indicator) by operating system, you would create a Breakdown based on the 'Operating System' field of the Configuration Item table. This allows users to view the overall MTTR score and then drill down to see the scores for Windows, Linux, etc., individually.

  5. Question 5Advanced

    Vulnerability Response Applications and Modules · Application and Container Vulnerability Response

    When implementing Application Vulnerability Response (AVR), a developer needs to understand how ServiceNow uniquely identifies an application vulnerability finding. Which combination of fields is typically used to create a unique key for an Application Vulnerable Item (AVI)?

    Show answer & explanation

    Correct answer: A

    For Application Vulnerable Items (AVIs), ServiceNow needs to distinguish the same vulnerability (e.g., a specific CWE) across different codebases. The unique key is typically a combination of the specific vulnerability identifier (from the scanner), the application or repository being scanned, and the specific branch where the vulnerability was found. This allows for tracking the same SQL injection flaw in the 'main' branch and a 'feature' branch as two distinct AVIs.

  6. Question 6Intermediate

    Getting Data into Vulnerability Response · Vulnerable Items and CI Matching

    A company is setting up its CI matching criteria. They want to ensure that if a match is found using the 'FQDN' lookup rule, the system stops processing and does not attempt to match using the 'NetBIOS' or 'IP Address' rules for that same Discovered Item. Which configuration on the CI Lookup Rules achieves this?

    Show answer & explanation

    Correct answer: A

    CI Lookup Rules are processed in ascending order. By setting the 'Order' field of the most reliable rule (FQDN) to a lower number (e.g., 100) than the other rules (e.g., NetBIOS at 200, IP at 300), you ensure it runs first. The matching process stops as soon as a successful match is found. Therefore, if the FQDN rule succeeds, the subsequent, less reliable rules will not be executed for that Discovered Item.

  7. Question 7Intermediate

    Tools to Manage Vulnerability Response · Classification and Assignment Rules

    A Vulnerability Analyst notices that many Vulnerable Items for a specific CVE are being assigned to a generic IT support group instead of the specialized server patching team. The analyst confirms the affected CIs have the correct 'Support group' field populated. What is the most likely cause of this misassignment?

    Show answer & explanation

    Correct answer: B

    Assignment rules are executed in order, from the lowest 'Order' number to the highest. A common issue is having a generic, catch-all rule (e.g., 'Assign all Windows vulnerabilities to IT Support') with a low order number. This rule matches the VITs before a more specific rule (e.g., 'Assign vulnerabilities on servers with Support Group X to Team Y') gets a chance to run. The solution is to ensure specific rules have a lower order number than generic ones.

  8. Question 8Intermediate

    Automating Vulnerability Response · Workflow Automation and Integration

    A security team has configured a Flow Designer action to automatically isolate a host using their EDR solution when a critical vulnerability is detected. The flow fails with an authentication error. The REST API call works from a separate tool using the same credentials. Within the ServiceNow flow, where should the administrator check and correct the credentials used for this integration?

    Show answer & explanation

    Correct answer: C

    The best practice for managing credentials for integrations in Flow Designer and IntegrationHub is to use Connection & Credential Aliases. The alias separates the flow logic from the specific endpoint and credentials. The administrator needs to navigate to the alias used by the EDR spoke, and verify or update the associated Credential record. This approach allows for secure storage of credentials and easy updates without modifying the flow itself.

  9. Question 9Advanced

    Tools to Manage Vulnerability Response · Implementation Strategy

    Case Study

    A multinational corporation, GlobalCorp, has just completed its initial implementation of ServiceNow Vulnerability Response. They have integrated Qualys for infrastructure scanning and Veracode for application scanning. The CMDB is populated by ServiceNow Discovery but has known data quality issues, with many servers lacking a value for the 'Support group' and 'Managed by' fields. The security team is overwhelmed with the volume of newly created Vulnerable Items (VITs).

    The Head of Security Operations has outlined three primary objectives:

    1. Ensure all new critical VITs are assigned to the correct remediation team within 4 hours.
    2. Reduce the noise by automatically closing low-risk vulnerabilities on development systems.
    3. Provide a clear way for application owners to request exceptions for vulnerabilities that cannot be immediately fixed.

    Given the state of the CMDB and the stated objectives, which of the following represents the most effective strategy to implement first?

    flowchart TD subgraph Qualys_Data A[Scanner Results] --> B{CI Matching} end subgraph CMDB C[Server CIs] -- Has Support Group? --> D{Yes/No} end subgraph Veracode_Data E[App Scan Results] --> F{AVI Creation} end B --> G[VIT Creation] D -->|No| H[Unassigned VITs] D -->|Yes| I[Assigned VITs]
    Show answer & explanation

    Correct answer: B

    This strategy directly addresses all three objectives with practical, immediate steps. 1) The default assignment rule ensures critical VITs don't remain unassigned, meeting the 4-hour goal by routing them for manual triage while CMDB issues are fixed. 2) The auto-close rule immediately reduces noise, allowing the team to focus on higher-risk items. 3) Activating the exception workflow provides the required process for application owners. This pragmatic approach provides immediate value while the longer-term CMDB cleanup occurs in parallel.

  10. Question 10IntermediateSelect 2

    Vulnerability Response Applications and Modules · Personas and Roles

    The sn_vul.vulnerability_analyst role is considered a primary operational role in Vulnerability Response. Which of the following tasks can a user with ONLY this role perform? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

Ready for the real thing?

The full CIS-VR simulator has every exam-style question, timed mode, and instant scoring.

Go to the CIS-VR simulator →