[Full-Version] 2025 New Preparation Guide of ServiceNow CIS-VR Exam [Q36-Q56]

Share

[Full-Version] 2025 New Preparation Guide of ServiceNow CIS-VR Exam

CIS-VR Practice Exam - 62 Unique Questions


ServiceNow CIS-VR Certification Exam is an essential credential for individuals who are responsible for managing vulnerability response processes within their organizations. By earning this certification, individuals demonstrate their expertise in vulnerability identification, prioritization, remediation, and reporting, and are recognized by employers as valuable assets to their teams.

 

NEW QUESTION # 36
What must Vulnerability Exceptions be supplied by default?

  • A. Requirement Actions for the exception
  • B. A manual approval authority for the exception
  • C. Integrations with GRC to handle the exception
  • D. A reason for the exception

Answer: D


NEW QUESTION # 37
What Business Rule creates a Configuration Item from a Vulnerable Item record?

  • A. Create CI from Vulnerable item Details
  • B. Create CI from Closed Item Details
  • C. Determine CI from Network Details
  • D. Create CI from Vulnerable Group Details

Answer: C

Explanation:
Determine CI from Network Details exists on sn_vul_vulnerable_item table which run on insert and update with the condition "Configuration item is empty", "IP address is not empty" OR "DNS name is not empty" OR
"NETBIOS name is not empty".


NEW QUESTION # 38
When an approval is rejected for a Vulnerable Item exception, what happens to the State field for that record?

  • A. It is set to 'In Review'
  • B. It is set to 'New'
  • C. It reverts to 'Analysis'
  • D. It will be set back to its previous value

Answer: A


NEW QUESTION # 39
What do Vulnerability Exceptions require?

  • A. A GRC integration
  • B. An Exception Workflow
  • C. An Approval by default
  • D. A Filter Group

Answer: B

Explanation:
https://docs.servicenow.com/bundle/vancouver-security-management/page/product/vulnerability-response/task/add-exception-approver.html


NEW QUESTION # 40
Where can you find information related to the Common Vulnerabilities and Exposures (CVE)?

  • A. NIST
  • B. Qualys
  • C. Tenable
  • D. MITRE

Answer: A

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-security-management/page/product/vulnerability- response/concept/c_VulnerabilityResponse.html


NEW QUESTION # 41
What role Is required to view the Vulnerability Overview Dashboard?

  • A. sn_vuI.vulnerability.read
  • B. sn_vul.vulnerability.wnte
  • C. sn_vuI.manager
  • D. sn_vul.ciso

Answer: A

Explanation:
sn_vul.vulnerability_read in the Roles table assigned to a user gives access to the Vulnerability Overview Dashboard


NEW QUESTION # 42
Select the three components of a Fitter Condition: Choose 3 answers

  • A. Operator
  • B. Sum
  • C. Value
  • D. Field

Answer: A,C,D

Explanation:
https://docs.servicenow.com/bundle/vancouver-mobile/page/administer/tablet-mobile-ui/reference/filter-condition-attributes.html


NEW QUESTION # 43
This functionality provides a simple way to build criteria once, which can be reused in other platform areas.

  • A. Filte Group
  • B. Filters
  • C. Conditions
  • D. Favorites

Answer: A

Explanation:
"Create and use filter groups to locate records from any table on your instance. For example, you can create a group of all computers by the same manufacturer. You can also filter configuration items (CIs) that have similar vulnerabilities or that fall within a particular subnet IP address range." https://docs.servicenow.com/bundle/washingtondc-security-management/page/product/security-operations-common/task/create-filter-group.html


NEW QUESTION # 44
To ensure that Vulnerabilities are processed correctly, you can define a Service Level Agreement (SLA) for Vulnerability Response. To achieve this you would:

  • A. Log in as a system admin, and using the globally scoped baseline SLA Modules
  • B. Have the role of Vulnerability admin, but only in the Vulnerability Scope
  • C. Make sure you have at least the sn_vul.vulnerability_write role and using the baseline SLA Application Modules
  • D. Create a custom workflow to monitor the time between States

Answer: B

Explanation:
https://docs.servicenow.com/bundle/vancouver-security-management/page/product/vulnerability-response/task/t_CreateVulnSLA.html


NEW QUESTION # 45
This functionality provides a simple way to build criteria once, which can be reused in other platform areas.

  • A. Filte Group
  • B. Filters
  • C. Conditions
  • D. Favorites

Answer: A

Explanation:
"Create and use filter groups to locate records from any table on your instance. For example, you can create a group of all computers by the same manufacturer. You can also filter configuration items (CIs) that have similar vulnerabilities or that fall within a particular subnet IP address range."https://docs.servicenow.com/bundle/washingtondc-security-management/page/product/security-operation


NEW QUESTION # 46
A list of software weaknesses is known as:

  • A. Common Vulnerability and Exposure (CVE)
  • B. National Institute of Science and Technology (NIST)
  • C. National Vulnerability Database (NVD)
  • D. Common Weaknesses Enumeration (CWE)

Answer: D


NEW QUESTION # 47
When an approval is rejected for a Vulnerable Item exception, what happens to the State field for that record?

  • A. It is set to 'New'
  • B. It reverts to 'Analysis'
  • C. It is set to 'In Review'
  • D. It will be set back to its previous value

Answer: D

Explanation:
https://docs.servicenow.com/en-US/bundle/vancouver-security-management/page/product/vulnerability-response


NEW QUESTION # 48
What system property allows for the auto creation of Vulnerability Groups based on the Vulnerable Item's Vulnerability?

  • A. sn_vul.autocreate_vul_group_item
  • B. sn_vul.autocreate_vul_filter_group
  • C. sn_vul.autocreate_vul_approval_group
  • D. sn_vul.autocreate_vul_centric_group

Answer: B


NEW QUESTION # 49
After closing the Vulnerable Item (VI), it is recommended to:

  • A. The VI remains active and in place until the Scanner rescans and closes the VI.
  • B. Compare the Vulnerability with subsequent scans.
  • C. Mark the CI as exempt from the Vulnerability if the vulnerability was remediated.
  • D. Update the values in the Vulnerability Score Indicator (VSl) based on the criticality of the Vulnerability.

Answer: D


NEW QUESTION # 50
If fixing a Vulnerable Item outweighs the benefits, the correct course of action is:

  • A. Add the Cl to the Vulnerability Scanners exclusions Related List
  • B. Mark the CI inactive in the CMDB and notify the CI owner
  • C. Record the accepted risk and Close/Defer the Vulnerable Item
  • D. Deprioritize the Vulnerable item Records (VlT) to push them further down the list so it can be ignored

Answer: B


NEW QUESTION # 51
If a customer expects to ingest 2 million vulnerabilities during it's initial load, which instance size should you recommend?

  • A. L
  • B. XL
  • C. Ultra
  • D. XXL

Answer: B


NEW QUESTION # 52
The components Installed with Vulnerability Response Include:

  • A. Business Rules, Roles, Workflows
  • B. Ul Pages. Business Rules, Vulnerability Scanners
  • C. Tables, Scheduled Jobs, Security Operations Common
  • D. Properties, Client Scripts, Wizards

Answer: C

Explanation:
https://docs.servicenow.com/bundle/vancouver-security-management/page/product/vulnerability-response/reference/installed-with-vr.html


NEW QUESTION # 53
Which one of the following record types can be considered the intersection of Vulnerability source information and CMDB CI records?

  • A. Vulnerability Task
  • B. CMDB_CI_Vuln
  • C. Vulnerability
  • D. Vulnerable Item (VI)

Answer: C


NEW QUESTION # 54
Which of the following best describes the Vulnerable item State Approval Workflow?

  • A. It is read-only, you can only change the Assignment Group members for the approval
  • B. It exists in the Security Operations Common scope so it can be modified by any Security Operations Admin
  • C. It runs against the [sn_vul_change_approval] table
  • D. It can only be modified by System Adminstrators

Answer: D


NEW QUESTION # 55
A list of software weaknesses is known as:

  • A. Common Vulnerability and Exposure (CVE)
  • B. National Institute of Science and Technology (NIST)
  • C. National Vulnerability Database (NVD)
  • D. Common Weaknesses Enumeration (CWE)

Answer: D

Explanation:
Explanation
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-security-management/page/product/vulnerability- response/concept/c_VulnerabilityResponse.html


NEW QUESTION # 56
......

Latest Questions CIS-VR Guide to Prepare Free Practice Tests: https://www.prepawayexam.com/ServiceNow/braindumps.CIS-VR.ete.file.html

Reliable CIS-VR Dumps Questions Available as Web-Based Practice Test Engine: https://drive.google.com/open?id=1-h9G6IrzrXfHgJ-UdhddF0oRHFZdp7eS