Free ServiceNow® CIS-SIR Exam Questions (page: 3)

What are two of the audiences identified that will need reports and insight into Security Incident Response reports? (Choose two.)

  1. Analysts
  2. Vulnerability Managers
  3. Chief Information Security Officer (CISO)
  4. Problem Managers

Answer(s): A,B


Reference:

https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource- center/data-sheet/ds-security-operations.pdf



What three steps enable you to include a new playbook in the Selected Playbook choice list? (Choose three.)

  1. Add the TLP: GREEN tag to the playbooks that you want to include in the Selected Playbook choice list
  2. Navigate to the sys_hub_flow.list table
  3. Search for the new playbook you have created using Flow Designer
  4. Add the sir_playbook tag to the playbooks that you want to include in the Selected Playbook choice list
  5. Navigate to the sys_playbook_flow.list table

Answer(s): B,C,D


Reference:

https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/concept/sir-new-ui-add-playbook.html



Which improvement opportunity can be found baseline which can contribute towards process maturity and strengthen costumer’s overall security posture?

  1. Post-Incident Review
  2. Fast Eradication
  3. Incident Containment
  4. Incident Analysis

Answer(s): D



What is the fastest way for security incident administrators to remove unwanted widgets from the Security Incident Catalog?

  1. Clicking the X on the top right corner
  2. Talking to the system administrator
  3. Can't be removed
  4. Through the Catalog Definition record

Answer(s): D



Select the one capability that retrieves a list of running processes on a CI from a host or endpoint.

  1. Get Network Statistics
  2. Isolate Host
  3. Get Running Processes
  4. Publish Watchlist
  5. Block Action
  6. Sightings Search

Answer(s): C


Reference:

https://docs.servicenow.com/bundle/quebec-security-management/page/product/security- operations-common/concept/get-running-processes-capability.html






Post your Comments and Discuss ServiceNow® CIS-SIR exam prep with other Community members:

CIS-SIR Exam Discussions & Posts