[Jan-2022] The Best Certified Implementation Specialist CIS-SIR Professional Exam Questions [Q24-Q41]

Share

[Jan-2022] The Best Certified Implementation Specialist CIS-SIR Professional Exam Questions

Try 100% Updated CIS-SIR Exam Questions [2022]


Understanding useful and specialized parts of ServiceNow Certified Implementation Specialist - Security Incident Response Exam

The accompanying will be examined in SERVICENOW CIS-SIR dumps:

  • Understanding Threat Intelligence
  • Explore How to Create Security Incidents
  • Miter ATT&CK Framework

Exam Topics for ServiceNow Certified Implementation Specialist - Security Incident Response Exam

The accompanying will be examined in SERVICENOW CIS-SIR exam dumps:

  • Security Incident Automation
  • Security Incident Response Overview
  • Security Incident and Threat Intelligence Integrations
  • Security Incident Creation and Threat Intelligence
  • Risk Calculations and Post Incident Response
  • Security Incident Response Management

 

NEW QUESTION 24
Using the KB articles for Playbooks tasks also gives you which of these advantages?

  • A. Improved visibility to threats and vulnerabilities
  • B. Automated activities to run scans and enrich Security Incidents with real time data
  • C. Automated activities to resolve security Incidents through patching
  • D. Enhanced ability to create and present concise, descriptive tasks

Answer: A

 

NEW QUESTION 25
What is the first step when creating a security Playbook?

  • A. Create a Flow
  • B. Set the Response Task's state
  • C. Create a Knowledge Article
  • D. Create a Runbook

Answer: A

 

NEW QUESTION 26
Incident severity is influenced by the business value of the affected asset.
Which of the following are asset types that can be affected by an incident? (Choose two.)

  • A. Business Service
  • B. Configuration Item
  • C. Calculator Group
  • D. Severity Calculator

Answer: A,B

 

NEW QUESTION 27
Flow Triggers can be based on what? (Choose three.)

  • A. Record changes
  • B. Record views
  • C. Record inserts
  • D. Schedules
  • E. Subflows

Answer: A,D,E

 

NEW QUESTION 28
Which of the following tag classifications are provided baseline? (Choose three.)

  • A. Escalation Level
  • B. Traffic Light Protocol
  • C. IoC Type
  • D. Cyber Kill Chain Step
  • E. Enrichment whitelist/blacklist
  • F. Severity
  • G. Block from Sharing

Answer: B,C,E

 

NEW QUESTION 29
What factor, if any, limits the ability to close SIR records?

  • A. Opened related INC records
  • B. All post-incident review question:ers have to be completed first
  • C. Nothing, SIR records could be closed at any time
  • D. Best practice dictates that SIR records should be set to 'Resolved' never to 'Closed'

Answer: A

 

NEW QUESTION 30
What parts of the Security Incident Response lifecycle is responsible for limiting the impact of a security incident?

  • A. Preparation and Identification
  • B. Detection & Analysis
  • C. Post Incident Activity
  • D. Containment, Eradication, and Recovery

Answer: D

Explanation:
Explanation/Reference: https://searchsecurity.techtarget.com/definition/incident-response

 

NEW QUESTION 31
Which of the following tag classifications are provided baseline? (Choose three.)

  • A. Escalation Level
  • B. Traffic Light Protocol
  • C. IoC Type
  • D. Cyber Kill Chain Step
  • E. Enrichment whitelist/blacklist
  • F. Severity
  • G. Block from Sharing

Answer: B,C,E

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security- operations-common/task/create-class-group-and-tags.html

 

NEW QUESTION 32
The severity field of the security incident is influenced by what?

  • A. The time taken to resolve the security incident
  • B. The impact, urgency and priority of the incident
  • C. The business value of the affected asset
  • D. The cost of the response to the security breach

Answer: C

 

NEW QUESTION 33
Which of the following are potential benefits for utilizing Security Incident assignment automation? (Choose two.)

  • A. Decreased Time to Containment
  • B. Increased resolution process consistency
  • C. Increased Mean Time to Remediation
  • D. Decreased Time to Ingestion

Answer: B,C

 

NEW QUESTION 34
Joe is on the SIR Team and needs to be able to configure Territories and Skills. What role does he need?

  • A. Security Analyst
  • B. Security Basic
  • C. Manager
  • D. Security Admin

Answer: D

 

NEW QUESTION 35
What specific role is required in order to use the REST API Explorer?

  • A. security_admin
  • B. admin
  • C. sn_si.admin
  • D. rest_api_explorer

Answer: B,D

 

NEW QUESTION 36
A flow consists of one or more actions and a what?

  • A. Change formatter
  • B. Trigger
  • C. NIST Ready State
  • D. Catalog Designer

Answer: B

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/quebec-servicenow-platform/page/administer/flow- designer/concept/flows.html

 

NEW QUESTION 37
If the customer's email server currently has an account setup to report suspicious emails, then what happens next?

  • A. the customer should set up a rule to forward these mails onto the ServiceNow platform
  • B. an integration added to Exchange keeps the ServiceNow platform in sync
  • C. the ServiceNow platform ensures that parsing and analysis takes place on their mail server
  • D. the customer's systems are already handling suspicious emails

Answer: A

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/concept/urp-about.html

 

NEW QUESTION 38
Which of the following is an action provided by the Security Incident Response application?

  • A. Create Record on Security Incident state V1
  • B. Look Up Record on Security Incident state V1
  • C. Create Outage state V1
  • D. Create Response Task set Incident state V1

Answer: B

 

NEW QUESTION 39
What is the name of the Inbound Action that validates whether an inbound email should be processed as a phishing email for URP v2?

  • A. User Reporting Phishing (for New emails)
  • B. User Reporting Phishing (for Forwarded emails)
  • C. Create Phishing Email
  • D. Scan email for threats

Answer: B

 

NEW QUESTION 40
The EmailUserReportedPhishing script include processes inbound emails and creates a record in which table?

  • A. sn_si_phishing_email
  • B. ar_sn_si_phishing_email
  • C. sn_si_phishing_email_header
  • D. sn_si_incident

Answer: B

 

NEW QUESTION 41
......


ServiceNow CIS-SIR Exam Syllabus Topics:

TopicDetails
Topic 1
  • Security Incident Calculator Groups and Risk Scores
  • Security Incident Creation and Threat Intelligence
Topic 2
  • Understanding Customer Goals and Meeting Customer Expectations
  • Security Incident Response Overview
Topic 3
  • Managing Pre-Built Integrations
  • Understanding Threat Intelligence
Topic 4
  • Security Incident Response Management
  • Definition of Escalation Paths
Topic 5
  • Security Incident Automation using Flows and Workflows
  • Explore How to Create Security Incidents
Topic 6
  • Security Incident and Threat Intelligence Integrations
  • Understand Major Security Incident Management
Topic 7
  • Risk Calculations and Post Incident Response
  • Introducing Security IncidentResponse
Topic 8
  • Automate Security Incident Response Overview
  • Security Analyst Workspace (New UI)
Topic 9
  • Standard Automated Assignment Options
  • Process Definitions and Selection

 

CIS-SIR Exam Questions Get Updated [2022] with Correct Answers: https://www.prepawaypdf.com/ServiceNow/CIS-SIR-practice-exam-dumps.html