ServiceNow CIS-SIR Cert Guide PDF 100% Cover Real Exam Questions [Q25-Q40]

Share

ServiceNow CIS-SIR Cert Guide PDF 100% Cover Real Exam Questions

Pass CIS-SIR Exam - Real Questions & Answers


Understanding useful and specialized parts of ServiceNow Certified Implementation Specialist - Security Incident Response Exam

The accompanying will be examined in SERVICENOW CIS-SIR dumps:

  • Understanding Threat Intelligence
  • Explore How to Create Security Incidents
  • Miter ATT&CK Framework

Exam Topics for ServiceNow Certified Implementation Specialist - Security Incident Response Exam

The accompanying will be examined in SERVICENOW CIS-SIR exam dumps:

  • Security Incident and Threat Intelligence Integrations
  • Risk Calculations and Post Incident Response
  • Security Incident Response Management
  • Security Incident Response Overview
  • Security Incident Creation and Threat Intelligence
  • Security Incident Automation

ServiceNow CIS-SIR Exam Syllabus Topics:

TopicDetails
Topic 1
  • Understanding Customer Goals and Meeting Customer Expectations
  • Security Incident Response Overview
Topic 2
  • Managing Pre-Built Integrations
  • Understanding Threat Intelligence
Topic 3
  • Security Incident Calculator Groups and Risk Scores
  • Security Incident Creation and Threat Intelligence
Topic 4
  • Risk Calculations and Post Incident Response
  • Introducing Security IncidentResponse
Topic 5
  • Security Incident Response Management
  • Definition of Escalation Paths
Topic 6
  • Automate Security Incident Response Overview
  • Security Analyst Workspace (New UI)
Topic 7
  • Security Incident Automation using Flows and Workflows
  • Explore How to Create Security Incidents
Topic 8
  • Security Incident and Threat Intelligence Integrations
  • Understand Major Security Incident Management
Topic 9
  • Standard Automated Assignment Options
  • Process Definitions and Selection

 

NEW QUESTION 25
Knowledge articles that describe steps an analyst needs to follow to complete Security incident tasks might be associated to those tasks through which of the following?

  • A. Flow
  • B. Workflow
  • C. Flow Designer
  • D. Runbook
  • E. Work Instruction Playbook

Answer: D

 

NEW QUESTION 26
A Post Incident Review can contain which of the following? (Choose three.)

  • A. Attachments associated with the security incident
  • B. Key incident fields
  • C. Post incident question:naires
  • D. Performance Analytics reports
  • E. An audit trail

Answer: B,C,E

 

NEW QUESTION 27
What makes a playbook appear for a Security Incident if using Flow Designer?

  • A. Trigger set to conditions that match the security incident
  • B. Actions defined to create tasks
  • C. Runbook property set to true
  • D. Service Criticality set to High

Answer: A

 

NEW QUESTION 28
Which of the following State Flows are provided for Security Incidents? (Choose three.)

  • A. SANS Stateful
  • B. NIST Stateful
  • C. NIST Open
  • D. SANS Open

Answer: A,B,C

 

NEW QUESTION 29
Select the one capability that retrieves a list of running processes on a CI from a host or endpoint.

  • A. Publish Watchlist
  • B. Get Running Processes
  • C. Sightings Search
  • D. Get Network Statistics
  • E. Block Action
  • F. Isolate Host

Answer: B

 

NEW QUESTION 30
What parts of the Security Incident Response lifecycle is responsible for limiting the impact of a security incident?

  • A. Post Incident Activity
  • B. Detection & Analysis
  • C. Preparation and Identification
  • D. Containment, Eradication, and Recovery

Answer: D

Explanation:
Explanation/Reference: https://searchsecurity.techtarget.com/definition/incident-response

 

NEW QUESTION 31
A flow consists of. (Choose two.)

  • A. Scripts
  • B. Triggers
  • C. Actions
  • D. Processes
  • E. Actors

Answer: B,C

 

NEW QUESTION 32
Incident severity is influenced by the business value of the affected asset.
Which of the following are asset types that can be affected by an incident? (Choose two.)

  • A. Business Service
  • B. Calculator Group
  • C. Configuration Item
  • D. Severity Calculator

Answer: A,C

 

NEW QUESTION 33
Which of the following fields is used to identify an Event that is to be used for Security purposes?

  • A. Security
  • B. CI
  • C. Classification
  • D. IT

Answer: C

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-it-operations-management/page/product/event- management/task/t_EMManageEvent.html

 

NEW QUESTION 34
Which one of the following reasons best describes why roles for Security Incident Response (SIR) begin with
"sn_si"?

  • A. Because SIR is a scoped application, roles and script includes will begin with the sn_si prefix
  • B. Because the Security Incident Response application uses a Secure Identity token
  • C. Because ServiceNow checks the instance for a Secure Identity when logging on to this scoped application
  • D. Because ServiceNow tracks license use against the Security Incident Response Application

Answer: B

 

NEW QUESTION 35
What is the name of the Inbound Action that validates whether an inbound email should be processed as a phishing email for URP v2?

  • A. Create Phishing Email
  • B. User Reporting Phishing (for Forwarded emails)
  • C. User Reporting Phishing (for New emails)
  • D. Scan email for threats

Answer: B

 

NEW QUESTION 36
What is the key to a successful implementation?

  • A. Sell customer the most expensive package
  • B. Implementing everything that we offer
  • C. Building custom integrations
  • D. Understanding the customer's goals and objectives

Answer: D

 

NEW QUESTION 37
Select the one capability that restricts connections from one CI to other devices.

  • A. Get Running Processes
  • B. Publish Watchlist
  • C. Sightings Search
  • D. Get Network Statistics
  • E. Block Action
  • F. Isolate Host

Answer: F

 

NEW QUESTION 38
Joe is on the SIR Team and needs to be able to configure Territories and Skills. What role does he need?

  • A. Security Analyst
  • B. Security Admin
  • C. Manager
  • D. Security Basic

Answer: B

 

NEW QUESTION 39
What three steps enable you to include a new playbook in the Selected Playbook choice list? (Choose three.)

  • A. Navigate to the sys_playbook_flow.list table
  • B. Search for the new playbook you have created using Flow Designer
  • C. Add the sir_playbook tag to the playbooks that you want to include in the Selected Playbook choice list
  • D. Navigate to the sys_hub_flow.list table
  • E. Add the TLP: GREEN tag to the playbooks that you want to include in the Selected Playbook choice list

Answer: B,C,D

 

NEW QUESTION 40
......

100% Free CIS-SIR Daily Practice Exam With 62 Questions: https://www.newpassleader.com/ServiceNow/CIS-SIR-exam-preparation-materials.html