Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ServiceNow CIS-Security Incident Response CIS-SIR Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CIS-SIR Premium Access

View all detail and faqs for the CIS-SIR exam


839 Students Passed

89% Average Score

91% Same Questions
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Why should discussions focus with the end in mind?

Options:

A.

To understand desired outcomes

B.

To understand current posture

C.

To understand customer’s process

D.

To understand required tools

Questions # 12:

Security tag used when a piece of information requires support to be effectively acted upon, yet carries risks to privacy, reputation, or operations if shared outside of the organizations involved.

Options:

A.

TLP:GREEN

B.

TLP:AMBER

C.

TLP:RED

D.

TLP:WHITE

Questions # 13:

Incident severity is influenced by the business value of the affected asset.

Which of the following are asset types that can be affected by an incident? (Choose two.)

Options:

A.

Business Service

B.

Configuration Item

C.

Calculator Group

D.

Severity Calculator

Questions # 14:

What is the fastest way for security incident administrators to remove unwanted widgets from the Security Incident Catalog?

Options:

A.

Clicking the X on the top right corner

B.

Talking to the system administrator

C.

Can't be removed

D.

Through the Catalog Definition record

Questions # 15:

This type of integration workflow helps retrieve a list of active network connections from a host or endpoint, so it can be used to enrich incidents during investigation.

Options:

A.

Security Incident Response – Get Running Services

B.

Security Incident Response – Get Network Statistics

C.

Security Operations Integration – Sightings Search

D.

Security Operations Integration – Block Request

Questions # 16:

What field is used to distinguish Security events from other IT events?

Options:

A.

Type

B.

Source

C.

Classification

D.

Description

Questions # 17:

For Customers who don't use 3rd-party systems, what ways can security incidents be created? (Choose three.)

Options:

A.

Security Service Catalog

B.

Security Incident Form

C.

Inbound Email Parsing Rules

D.

Leveraging an Integration

E.

Alert Management

Questions # 18:

Joe is on the SIR Team and needs to be able to configure Territories and Skills. What role does he need?

Options:

A.

Security Basic

B.

Manager

C.

Security Analyst

D.

Security Admin

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.