Free ServiceNow® CIS-SIR Exam Questions (page: 4)

Which Table would be commonly used for Security Incident Response?

  1. sysapproval_approver
  2. sec_ops_incident
  3. cmdb_rel_ci
  4. sn_si_incident

Answer(s): D


Reference:

https://docs.servicenow.com/bundle/quebec-security-management/page/product/security-incident- response/reference/installed-with-sir.html



There are several methods in which security incidents can be raised, which broadly fit into one of these categories:        . (Choose two.)

  1. Integrations
  2. Manually created
  3. Automatically created
  4. Email parsing

Answer(s): B,C


Reference:

https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/concept/si-creation.html



What is the first step when creating a security Playbook?

  1. Set the Response Task's state
  2. Create a Flow
  3. Create a Runbook
  4. Create a Knowledge Article

Answer(s): B



To configure Security Incident Escalations, you need the following role(s):       .

  1. sn_si.admin
  2. sn_si.admin or sn_si.manager
  3. sn_si.admin or sn_si.ciso
  4. sn_si.manager or sn_si.analyst

Answer(s): A


Reference:

https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/task/escalate-security-incident.html



Which of the following are potential benefits for utilizing Security Incident assignment automation? (Choose two.)

  1. Decreased Time to Containment
  2. Increased Mean Time to Remediation
  3. Decreased Time to Ingestion
  4. Increased resolution process consistency

Answer(s): B,D






Post your Comments and Discuss ServiceNow® CIS-SIR exam prep with other Community members:

CIS-SIR Exam Discussions & Posts