[Dec-2021] CIS-SIR Exam Dumps Pass with Updated 2021 Certified Implementation Specialist - Security Incident Response Exam [Q19-Q44]

Share

[Dec-2021] CIS-SIR Exam Dumps Pass with Updated 2021 Certified Implementation Specialist - Security Incident Response Exam

Free CIS-SIR Exam Dumps to Pass Exam Easily


Salary of ServiceNow Certified Implementation Specialist - Security Incident Response Exam certified professionals

The salary of ServiceNow Certified Implementation Specialist - Security Incident Response Exam certified professionals varies from $88K to $107K depending on the years of experience.


Exam Topics for ServiceNow Certified Implementation Specialist - Security Incident Response Exam

The accompanying will be examined in SERVICENOW CIS-SIR exam dumps:

  • Security Incident Response Management
  • Risk Calculations and Post Incident Response
  • Security Incident and Threat Intelligence Integrations

 

NEW QUESTION 19
What parts of the Security Incident Response lifecycle is responsible for limiting the impact of a security incident?

  • A. Post Incident Activity
  • B. Preparation and Identification
  • C. Detection & Analysis
  • D. Containment, Eradication, and Recovery

Answer: D

Explanation:
Explanation/Reference: https://searchsecurity.techtarget.com/definition/incident-response

 

NEW QUESTION 20
What is the key to a successful implementation?

  • A. Sell customer the most expensive package
  • B. Building custom integrations
  • C. Understanding the customer's goals and objectives
  • D. Implementing everything that we offer

Answer: C

 

NEW QUESTION 21
What field is used to distinguish Security events from other IT events?

  • A. Description
  • B. Classification
  • C. Type
  • D. Source

Answer: B

 

NEW QUESTION 22
What factor, if any, limits the ability to close SIR records?

  • A. Nothing, SIR records could be closed at any time
  • B. Opened related INC records
  • C. All post-incident review question:ers have to be completed first
  • D. Best practice dictates that SIR records should be set to 'Resolved' never to 'Closed'

Answer: B

 

NEW QUESTION 23
The Risk Score is calculated by combining all the weights using.

  • A. an arithmetic mean
  • B. addition
  • C. a geometric mean
  • D. the Risk Score script include

Answer: A

 

NEW QUESTION 24
If the customer's email server currently has an account setup to report suspicious emails, then what happens next?

  • A. the ServiceNow platform ensures that parsing and analysis takes place on their mail server
  • B. the customer's systems are already handling suspicious emails
  • C. the customer should set up a rule to forward these mails onto the ServiceNow platform
  • D. an integration added to Exchange keeps the ServiceNow platform in sync

Answer: C

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/concept/urp-about.html

 

NEW QUESTION 25
A flow consists of. (Choose two.)

  • A. Actors
  • B. Scripts
  • C. Actions
  • D. Processes
  • E. Triggers

Answer: C,E

 

NEW QUESTION 26
Knowledge articles that describe steps an analyst needs to follow to complete Security incident tasks might be associated to those tasks through which of the following?

  • A. Flow
  • B. Flow Designer
  • C. Workflow
  • D. Runbook
  • E. Work Instruction Playbook

Answer: D

 

NEW QUESTION 27
A pre-planned response process contains which sequence of events?

  • A. Organize, Prepare, Prioritize, Contain
  • B. Organize, Verify, Prioritize, Contain
  • C. Organize, Detect, Prioritize, Contain
  • D. Organize, Analyze, Prioritize, Contain

Answer: D

 

NEW QUESTION 28
Select the one capability that retrieves a list of running processes on a CI from a host or endpoint.

  • A. Block Action
  • B. Publish Watchlist
  • C. Sightings Search
  • D. Get Network Statistics
  • E. Isolate Host
  • F. Get Running Processes

Answer: F

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/quebec-security-management/page/product/security- operations-common/concept/get-running-processes-capability.html

 

NEW QUESTION 29
A Post Incident Review can contain which of the following? (Choose three.)

  • A. Key incident fields
  • B. Performance Analytics reports
  • C. Attachments associated with the security incident
  • D. Post incident question:naires
  • E. An audit trail

Answer: A,D,E

 

NEW QUESTION 30
How do you select which process definition to use?

  • A. By selecting the desired process within the Process Definition module
  • B. By setting the process definition record to Active
  • C. By setting the Script Include record to Active
  • D. By selecting the desired process within the Process Selection module

Answer: D

 

NEW QUESTION 31
When a service desk agent uses the Create Security Incident UI action from a regular incident, what occurs?

  • A. A security incident is raised on their behalf and displayed to the service desk agent
  • B. A security incident is raised on their behalf but only a notification is displayed
  • C. The service desk agent is redirected to the Security Incident Catalog to complete the record producer
  • D. The incident is marked resolved with an automatic security resolution code

Answer: D

 

NEW QUESTION 32
What is the purpose of Calculator Groups as opposed to Calculators?

  • A. To provide metadata about the calculators
  • B. To set the condition for all calculators to run
  • C. To allow the agent to select which calculator they want to execute
  • D. To ensure one at maximum will run per group

Answer: B

 

NEW QUESTION 33
If the customer's email server currently has an account setup to report suspicious emails, then what happens next?

  • A. the ServiceNow platform ensures that parsing and analysis takes place on their mail server
  • B. the customer's systems are already handling suspicious emails
  • C. the customer should set up a rule to forward these mails onto the ServiceNow platform
  • D. an integration added to Exchange keeps the ServiceNow platform in sync

Answer: C

 

NEW QUESTION 34
Which one of the following reasons best describes why roles for Security Incident Response (SIR) begin with "sn_si"?

  • A. Because the Security Incident Response application uses a Secure Identity token
  • B. Because SIR is a scoped application, roles and script includes will begin with the sn_si prefix
  • C. Because ServiceNow tracks license use against the Security Incident Response Application
  • D. Because ServiceNow checks the instance for a Secure Identity when logging on to this scoped application

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 35
If a desired pre-built integration cannot be found in the platform, what should be your next step to find a certified integration?

  • A. Look for one in the ServiceNow Store
  • B. Download one from ServiceNow Share
  • C. Build your own through the REST API Explorer
  • D. Ask for assistance in the community page

Answer: A

 

NEW QUESTION 36
The following term is used to describe any observable occurrence:.

  • A. Event
  • B. Ticket
  • C. Alert
  • D. Incident
  • E. Log

Answer: A

 

NEW QUESTION 37
What makes a playbook appear for a Security Incident if using Flow Designer?

  • A. Trigger set to conditions that match the security incident
  • B. Runbook property set to true
  • C. Actions defined to create tasks
  • D. Service Criticality set to High

Answer: A

 

NEW QUESTION 38
Which one of the following reasons best describes why roles for Security Incident Response (SIR) begin with
"sn_si"?

  • A. Because the Security Incident Response application uses a Secure Identity token
  • B. Because SIR is a scoped application, roles and script includes will begin with the sn_si prefix
  • C. Because ServiceNow tracks license use against the Security Incident Response Application
  • D. Because ServiceNow checks the instance for a Secure Identity when logging on to this scoped application

Answer: A

 

NEW QUESTION 39
The severity field of the security incident is influenced by what?

  • A. The time taken to resolve the security incident
  • B. The business value of the affected asset
  • C. The cost of the response to the security breach
  • D. The impact, urgency and priority of the incident

Answer: B

 

NEW QUESTION 40
How do you select which process definition to use?

  • A. By selecting the desired process within the Process Definition module
  • B. By setting the process definition record to Active
  • C. By setting the Script Include record to Active
  • D. By selecting the desired process within the Process Selection module

Answer: D

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/reference/setup-assistant-reference.html

 

NEW QUESTION 41
Which of the following process definitions are not provided baseline?

  • A. SAN Stateful
  • B. NIST Open
  • C. NIST Stateful
  • D. SANS Open

Answer: B

 

NEW QUESTION 42
What is the name of the Inbound Action that validates whether an inbound email should be processed as a phishing email for URP v2?

  • A. Scan email for threats
  • B. User Reporting Phishing (for Forwarded emails)
  • C. Create Phishing Email
  • D. User Reporting Phishing (for New emails)

Answer: B

 

NEW QUESTION 43
What three steps enable you to include a new playbook in the Selected Playbook choice list? (Choose three.)

  • A. Search for the new playbook you have created using Flow Designer
  • B. Navigate to the sys_playbook_flow.list table
  • C. Add the TLP: GREEN tag to the playbooks that you want to include in the Selected Playbook choice list
  • D. Navigate to the sys_hub_flow.list table
  • E. Add the sir_playbook tag to the playbooks that you want to include in the Selected Playbook choice list

Answer: A,D,E

 

NEW QUESTION 44
......

CIS-SIR Exam Dumps, CIS-SIR Practice Test Questions: https://www.practicevce.com/ServiceNow/CIS-SIR-practice-exam-dumps.html