ServiceNow CIS-RCI Exam
Certified Implementation Specialist - Risk and Compliance (Page 4 )

Updated On: 19-Jan-2026

Within the Policy Acknowledgement module, what table does the Acknowledgement Instance table extend from?

  1. Task
  2. Policy Acknowledgement
  3. Does not extend from a table
  4. Policy
  5. Document

Answer(s): C



For advanced risk assessment, risk response can be handled in the following ways:
(Choose two.)

  1. Create multiple risk response tasks
  2. Skipped entirely based on attributes defined in the RAM
  3. Must create a mitigation response task
  4. Must create at least one risk response task

Answer(s): A,B



Which of the following is not used to source control data for a customer’s control framework?

  1. ServiceNow Product documentation
  2. Customer’s existing controls
  3. An external regulatory content provider
  4. ServiceNow content packs and accelerators

Answer(s): A



What assessment types can be enabled when configuring a risk assessment methodology (RAM)? (Choose three.)

  1. Operational Risk Assessment
  2. Application Risk Assessment
  3. Residual Assessment
  4. Inherent Assessment
  5. Control Assessment
  6. Project Risk Assessment

Answer(s): C,D,E



How does GRC: Policy and Compliance Management track compliance to Authority Documents?

  1. Citations are mapped to entity-scoped controls, which are tested as compliant or non-compliant.
  2. Authority Documents are mapped to individual policies, which are either marked compliant or non-compliant.
  3. Authority Documents are mapped to control objectives and compliance is checked when controls are tested as compliant or non-compliant.
  4. Citations are mapped to control objectives, and compliance is checked when controls are tested as compliant or non-compliant.

Answer(s): D



Viewing page 4 of 35
Viewing questions 16 - 20 out of 278 questions



Post your Comments and Discuss ServiceNow CIS-RCI exam prep with other Community members:

Join the CIS-RCI Discussion