ServiceNow CIS-VRM Exam
Certified Implementation Specialist - Vendor Risk Management (Page 3 )

Updated On: 26-Jan-2026

Which of the following is an objective of Vendor Risk Management? (Choose two.)

  1. To help vendors improve their security posture and preparedness
  2. To assess and manage the risk from interactions with vendors and third parties
  3. To help negotiate the best possible price for a product or service from the vendor
  4. To verify that vendors have adequate measures and processes in place to ensure profitability of vendor

Answer(s): A,B


Reference:

https://reciprocity.com/resources/what-is-a-vendor-risk-management- program/#:~:text=A%20vendor%20risk%20management%20framework,across%20the%20organizati on's%20supplier%20base



During the Generating Observations phase of the Vendor Risk Assessment, what action might be taken by the Risk Assessor?

  1. Create issues from the assessment if necessary
  2. Update the vendor risk score
  3. Email the vendor
  4. Answer questions the vendor forgot to answer

Answer(s): A



For each questionnaire template/assessment metric type, how many vendor risk areas can be

designated?

  1. One
  2. As many as desired
  3. None
  4. Two

Answer(s): B



To what type of assessment record can a vendor contact respond?

  1. Vendor tiering assessment
  2. Vendor risk assessment
  3. Customer assessment
  4. External monitoring assessment

Answer(s): B


Reference:

https://www.smartsheet.com/content/vendor-assessment-evaluation



What are individual questions within a questionnaire or document request referred to as?

  1. Metrics
  2. Ratings
  3. Templates
  4. Tiers

Answer(s): D



Viewing page 3 of 13
Viewing questions 11 - 15 out of 60 questions



Post your Comments and Discuss ServiceNow CIS-VRM exam prep with other Community members:

Join the CIS-VRM Discussion