Weekend Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the ServiceNow CIS-Security Incident Response CIS-SIR Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CIS-SIR Premium Access

View all detail and faqs for the CIS-SIR exam


537 Students Passed

88% Average Score

91% Same Questions
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Why is it important that the Platform (System) Administrator and the Security Incident administrator role be separated? (Choose three.)

Options:

A.

Access to security incident data may need to be restricted

B.

Allow SIR Teams to control assignment of security roles

C.

Clear separation of duty

D.

Reduce the number of incidents assigned to the Platform Admin

E.

Preserve the security image in the company

Questions # 2:

How do you select which process definition to use?

Options:

A.

By selecting the desired process within the Process Definition module

B.

By selecting the desired process within the Process Selection module

C.

By setting the process definition record to Active

D.

By setting the Script Include record to Active

Questions # 3:

What plugin must be activated to see the New Security Analyst UI?

Options:

A.

Security Analyst UI Plugin

B.

Security Incident Response UI plugin

C.

Security Operations UI plugin

D.

Security Agent UI Plugin

Questions # 4:

What is calculated as an arithmetic mean taking into consideration different values in the CI, Security Incident, and User records?

Options:

A.

Priority

B.

Business Impact

C.

Severity

D.

Risk Score

Questions # 5:

The benefits of improved Security Incident Response are expressed.

Options:

A.

as desirable outcomes with clear, measurable Key Performance Indicators

B.

differently depending upon 3 stages: Process Improvement, Process Design, and Post Go-Live

C.

as a series of states with consistent, clear metrics

D.

as a value on a scale of 1-10 based on specific outcomes

Questions # 6:

Which of the following State Flows are provided for Security Incidents? (Choose three.)

Options:

A.

NIST Open

B.

SANS Open

C.

NIST Stateful

D.

SANS Stateful

Questions # 7:

Chief factors when configuring auto-assignment of Security Incidents are.

Options:

A.

Agent group membership, Agent location and time zone

B.

Security incident priority, CI Location and agent time zone

C.

Agent skills, System Schedules and agent location

D.

Agent location, Agent skills and agent time zone

Questions # 8:

Select the one capability that restricts connections from one CI to other devices.

Options:

A.

Isolate Host

B.

Sightings Search

C.

Block Action

D.

Get Running Processes

E.

Get Network Statistics

F.

Publish Watchlist

Questions # 9:

What are two of the audiences identified that will need reports and insight into Security Incident Response reports? (Choose two.)

Options:

A.

Analysts

B.

Vulnerability Managers

C.

Chief Information Security Officer (CISO)

D.

Problem Managers

Questions # 10:

Which of the following process definitions are not provided baseline?

Options:

A.

NIST Open

B.

SAN Stateful

C.

NIST Stateful

D.

SANS Open

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.