
ServiceNow CIS-SIR Cert Guide PDF 100% Cover Real Exam Questions
Pass CIS-SIR Exam - Real Questions & Answers
Understanding useful and specialized parts of ServiceNow Certified Implementation Specialist - Security Incident Response Exam
The accompanying will be examined in SERVICENOW CIS-SIR dumps:
- Understanding Threat Intelligence
- Explore How to Create Security Incidents
- Miter ATT&CK Framework
Exam Topics for ServiceNow Certified Implementation Specialist - Security Incident Response Exam
The accompanying will be examined in SERVICENOW CIS-SIR exam dumps:
- Security Incident and Threat Intelligence Integrations
- Risk Calculations and Post Incident Response
- Security Incident Response Management
- Security Incident Response Overview
- Security Incident Creation and Threat Intelligence
- Security Incident Automation
ServiceNow CIS-SIR Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
NEW QUESTION 25
Knowledge articles that describe steps an analyst needs to follow to complete Security incident tasks might be associated to those tasks through which of the following?
- A. Flow
- B. Workflow
- C. Flow Designer
- D. Runbook
- E. Work Instruction Playbook
Answer: D
NEW QUESTION 26
A Post Incident Review can contain which of the following? (Choose three.)
- A. Attachments associated with the security incident
- B. Key incident fields
- C. Post incident question:naires
- D. Performance Analytics reports
- E. An audit trail
Answer: B,C,E
NEW QUESTION 27
What makes a playbook appear for a Security Incident if using Flow Designer?
- A. Trigger set to conditions that match the security incident
- B. Actions defined to create tasks
- C. Runbook property set to true
- D. Service Criticality set to High
Answer: A
NEW QUESTION 28
Which of the following State Flows are provided for Security Incidents? (Choose three.)
- A. SANS Stateful
- B. NIST Stateful
- C. NIST Open
- D. SANS Open
Answer: A,B,C
NEW QUESTION 29
Select the one capability that retrieves a list of running processes on a CI from a host or endpoint.
- A. Publish Watchlist
- B. Get Running Processes
- C. Sightings Search
- D. Get Network Statistics
- E. Block Action
- F. Isolate Host
Answer: B
NEW QUESTION 30
What parts of the Security Incident Response lifecycle is responsible for limiting the impact of a security incident?
- A. Post Incident Activity
- B. Detection & Analysis
- C. Preparation and Identification
- D. Containment, Eradication, and Recovery
Answer: D
Explanation:
Explanation/Reference: https://searchsecurity.techtarget.com/definition/incident-response
NEW QUESTION 31
A flow consists of. (Choose two.)
- A. Scripts
- B. Triggers
- C. Actions
- D. Processes
- E. Actors
Answer: B,C
NEW QUESTION 32
Incident severity is influenced by the business value of the affected asset.
Which of the following are asset types that can be affected by an incident? (Choose two.)
- A. Business Service
- B. Calculator Group
- C. Configuration Item
- D. Severity Calculator
Answer: A,C
NEW QUESTION 33
Which of the following fields is used to identify an Event that is to be used for Security purposes?
- A. Security
- B. CI
- C. Classification
- D. IT
Answer: C
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-it-operations-management/page/product/event- management/task/t_EMManageEvent.html
NEW QUESTION 34
Which one of the following reasons best describes why roles for Security Incident Response (SIR) begin with
"sn_si"?
- A. Because SIR is a scoped application, roles and script includes will begin with the sn_si prefix
- B. Because the Security Incident Response application uses a Secure Identity token
- C. Because ServiceNow checks the instance for a Secure Identity when logging on to this scoped application
- D. Because ServiceNow tracks license use against the Security Incident Response Application
Answer: B
NEW QUESTION 35
What is the name of the Inbound Action that validates whether an inbound email should be processed as a phishing email for URP v2?
- A. Create Phishing Email
- B. User Reporting Phishing (for Forwarded emails)
- C. User Reporting Phishing (for New emails)
- D. Scan email for threats
Answer: B
NEW QUESTION 36
What is the key to a successful implementation?
- A. Sell customer the most expensive package
- B. Implementing everything that we offer
- C. Building custom integrations
- D. Understanding the customer's goals and objectives
Answer: D
NEW QUESTION 37
Select the one capability that restricts connections from one CI to other devices.
- A. Get Running Processes
- B. Publish Watchlist
- C. Sightings Search
- D. Get Network Statistics
- E. Block Action
- F. Isolate Host
Answer: F
NEW QUESTION 38
Joe is on the SIR Team and needs to be able to configure Territories and Skills. What role does he need?
- A. Security Analyst
- B. Security Admin
- C. Manager
- D. Security Basic
Answer: B
NEW QUESTION 39
What three steps enable you to include a new playbook in the Selected Playbook choice list? (Choose three.)
- A. Navigate to the sys_playbook_flow.list table
- B. Search for the new playbook you have created using Flow Designer
- C. Add the sir_playbook tag to the playbooks that you want to include in the Selected Playbook choice list
- D. Navigate to the sys_hub_flow.list table
- E. Add the TLP: GREEN tag to the playbooks that you want to include in the Selected Playbook choice list
Answer: B,C,D
NEW QUESTION 40
......
100% Free CIS-SIR Daily Practice Exam With 62 Questions: https://www.newpassleader.com/ServiceNow/CIS-SIR-exam-preparation-materials.html