Exit demo CIS-SIR Certified Implementation Specialist - Security Incident Response PDF format · free preview

ServiceNow CIS-SIR - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/cis-sir.html

Question 1
Multiple choice

What specific role is required in order to use the REST API Explorer?

A.

admin

B.

sn_si.admin

C.

rest_api_explorer

D.

security_admin

Question 2
Single choice

The Risk Score is calculated by combining all the weights using.

A.

an arithmetic mean

B.

addition

C.

the Risk Score script include

D.

a geometric mean

Question 3
Single choice

When a record is created in the Security Incident Phishing Email table what is triggered to create a Security Incident?

A.

Ingestion Rule

B.

Transform flow

C.

Transform workflow

D.

Duplication Rule

Question 4
Single choice

Which one of the following reasons best describes why roles for Security Incident Response (SIR) begin with "sn_si"?

A.

Because SIR is a scoped application, roles and script includes will begin with the sn_si prefix

B.

Because the Security Incident Response application uses a Secure Identity token

C.

Because ServiceNow checks the instance for a Secure Identity when logging on to this scoped application

D.

Because ServiceNow tracks license use against the Security Incident Response Application

Question 5
Single choice

Which ServiceNow automation capability extends Flow Designer to integrate business processes with other systems?

A.

Workflow

B.

Orchestration

C.

Subflows

D.

Integration Hub

Question 6
Single choice

What is the first step when creating a security Playbook?

A.

Set the Response Task's state

B.

Create a Flow

C.

Create a Runbook

D.

Create a Knowledge Article

Question 7
Single choice

Which one of the following users is automatically added to the Request Assessments list?

A.

Any user that adds a worknote to the ticket

B.

The analyst assigned to the ticket

C.

Any user who has Response Tasks on the incident

D.

The Affected User on the incident

Question 8
Single choice

Which improvement opportunity can be found baseline which can contribute towards process maturity and strengthen costumer's overall security posture?

A.

Post-Incident Review

B.

Fast Eradication

C.

Incident Containment

D.

Incident Analysis

Question 9
Multiple choice

Incident severity is influenced by the business value of the affected asset.

Which of the following are asset types that can be affected by an incident? (Choose two.)

A.

Business Service

B.

Configuration Item

C.

Calculator Group

D.

Severity Calculator

Question 10
Multiple choice

For Customers who don't use 3rd-party systems, what ways can security incidents be created? (Choose three.)

A.

Security Service Catalog

B.

Security Incident Form

C.

Inbound Email Parsing Rules

D.

Leveraging an Integration

E.

Alert Management

Showing 10 of 60 questions · Unlock the full set