CIS-TPRM: Certified Implementation Specialist - Third-party Risk Management
Free Practice Exam Questions (page: 5)
Updated On: 10-Jan-2026

How does ServiceNow help companies manage third parties without emails and spreadsheets?

  1. Third-party Platform
  2. Primary Third-party
  3. Third-party Manager Workspace
  4. Third-party Portal

Answer(s): C

Explanation:

The Third-party Manager Workspace in ServiceNow centralizes third-party risk management activities, allowing companies to manage vendors, assessments, and tasks without relying on emails and spreadsheets. It provides a unified interface for tracking and collaborating on third-party risks.



What is the definition of 'Risk Management'?

  1. Process to identify, assess, and respond to risks, threats and vulnerabilities that could compromise the business
  2. The process of conforming to standards, policies, and remediation of audit findings
  3. The elimination of vulnerable surface area in an enterprise environment
  4. Policies/Standards/Procedures established to ensure an organization is aligned with corporate strategy and expectations are clearly defined

Answer(s): A

Explanation:

Risk management is the process of identifying, assessing, and responding to risks, threats, and vulnerabilities that could negatively impact a business. It focuses on understanding potential risks and implementing strategies to mitigate or manage them effectively.



What application provides the ability to define multiple levels of approvals based on business rule definitions?

  1. Risk Approver Configuration
  2. Approval Configurator
  3. Approver Levels
  4. TPRM Approvals

Answer(s): D

Explanation:

TPRM Approvals in ServiceNow allows organizations to define and manage multiple levels of approvals for third-party risk processes based on configurable business rules, ensuring that risk decisions follow the proper governance workflow.



Which table stores the third-party records?

  1. Company [core_company]
  2. Department [cmn_department]
  3. User [sys_user]
  4. Vendor [sn_vdr_vendor]

Answer(s): D

Explanation:

The Vendor [sn_vdr_vendor] table in ServiceNow stores all third-party (vendor) records, including details such as vendor name, type, and associated risk information, serving as the central repository for third-party management.



When the GRC: Policy and Compliance Management application is installed, what GRC related list displays on the Third-party Risk Issue record?

  1. Policies
  2. Policy Exceptions
  3. Configuration baseline
  4. Citations

Answer(s): A

Explanation:

When the GRC: Policy and Compliance Management application is installed, the Policies related list appears on the Third-party Risk Issue record. This allows linking relevant policies to a third-party risk issue for compliance tracking and management.



Viewing page 5 of 13
Viewing questions 21 - 25 out of 60 questions



Post your Comments and Discuss ServiceNow® CIS-TPRM exam prep with other Community members:

CIS-TPRM Exam Discussions & Posts