Skip to main content

CIS-SIR Real Exam Questions

Certified Implementation Specialist - Security Incident Response

60 questions available · Page 1 of 6

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Joe is on the SIR Team and needs to be able to configure Territories and Skills.

What role does he need?

  1. A

    Security Basic

  2. B

    Manager

  3. C

    Security Analyst

  4. D

    Security Admin

Show answer and explanation

Correct answer: D

Explanation

References:
https://docs.servicenow.com/bundle/quebec-security-management/page/product/security-incident-response/reference/installed-with-sir.html

Question 2 Single choice

Using the KB articles for Playbooks tasks also gives you which of these advantages?

  1. A

    Automated activities to run scans and enrich Security Incidents with real time data

  2. B

    Automated activities to resolve security Incidents through patching

  3. C

    Improved visibility to threats and vulnerabilities

  4. D

    Enhanced ability to create and present concise, descriptive tasks

Show answer and explanation

Correct answer: C

Question 3 Single choice

What is the name of the Inbound Action that validates whether an inbound email should be processed as a phishing email for URP v2?

  1. A

    User Reporting Phishing (for Forwarded emails)

  2. B

    Scan email for threats

  3. C

    User Reporting Phishing (for New emails)

  4. D

    Create Phishing Email

Show answer and explanation

Correct answer: A

Question 4 Single choice

This type of integration workflow helps retrieve a list of active network connections from a host or endpoint, so it can be used to enrich incidents during investigation.

  1. A

    Security Incident Response ?Get Running Services

  2. B

    Security Incident Response ?Get Network Statistics

  3. C

    Security Operations Integration ?Sightings Search

  4. D

    Security Operations Integration ?Block Request

Show answer and explanation

Correct answer: B

Explanation

References:
https://docs.servicenow.com/bundle/quebec-security-management/page/product/security-incident-response/concept/cj-sir-capfmw-about.html

Question 5 Single choice

What does a flow require?

  1. A

    Security orchestration flows

  2. B

    Runbooks

  3. C

    CAB orders

  4. D

    A trigger

Show answer and explanation

Correct answer: D

Question 6 Single choice

Which ServiceNow automation capability extends Flow Designer to integrate business processes with other systems?

  1. A

    Workflow

  2. B

    Orchestration

  3. C

    Subflows

  4. D

    Integration Hub

Show answer and explanation

Correct answer: D

Explanation

References:
https://docs.servicenow.com/bundle/quebec-servicenow-platform/page/administer/flow-designer/concept/flow-designer.html

Question 7 Single choice

Which one of the following users is automatically added to the Request Assessments list?

  1. A

    Any user that adds a worknote to the ticket

  2. B

    The analyst assigned to the ticket

  3. C

    Any user who has Response Tasks on the incident

  4. D

    The Affected User on the incident

Show answer and explanation

Correct answer: C

Question 8 Single choice

Which of the following fields is used to identify an Event that is to be used for Security purposes?

  1. A

    IT

  2. B

    Classification

  3. C

    Security

  4. D

    CI

Show answer and explanation

Correct answer: B

Explanation

References:
https://docs.servicenow.com/bundle/paris-it-operations-management/page/product/event-management/task/t_EMManageEvent.html

Question 9 Multiple choice

What are two of the audiences identified that will need reports and insight into Security Incident Response reports? (Choose two.)

  1. A

    Analysts

  2. B

    Vulnerability Managers

  3. C

    Chief Information Security Officer (CISO)

  4. D

    Problem Managers

Show answer and explanation

Correct answers: A, B

Explanation

References:
https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/resource-center/data-sheet/ds-security-operations.pdf

Question 10 Single choice

Knowledge articles that describe steps an analyst needs to follow to complete Security incident tasks might be associated to those tasks through which of the following?

  1. A

    Work Instruction Playbook

  2. B

    Flow

  3. C

    Workflow

  4. D

    Runbook

  5. E

    Flow Designer

Show answer and explanation

Correct answer: D

Explanation

References:
https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident-response/task/perform-addtl-tasks-on-si.html