[Oct 30, 2021] CIS-SIR PDF Dumps is essential on your CIS-SIR Exam Questions Certain Success!
CIS-SIR PDF Questions - Perfect Prospect To Go With CIS-SIR Practice Exam
NEW QUESTION 13
A flow consists of one or more actions and a what?
- A. NIST Ready State
- B. Change formatter
- C. Trigger
- D. Catalog Designer
Answer: C
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/quebec-servicenow-platform/page/administer/flow- designer/concept/flows.html
NEW QUESTION 14
What parts of the Security Incident Response lifecycle is responsible for limiting the impact of a security incident?
- A. Preparation and Identification
- B. Detection & Analysis
- C. Containment, Eradication, and Recovery
- D. Post Incident Activity
Answer: C
NEW QUESTION 15
The Risk Score is calculated by combining all the weights using __________.
- A. a geometric mean
- B. an arithmetic mean
- C. addition
- D. the Risk Score script include
Answer: B
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/reference/setup-assistant-reference.html
NEW QUESTION 16
If a desired pre-built integration cannot be found in the platform, what should be your next step to find a certified integration?
- A. Build your own through the REST API Explorer
- B. Look for one in the ServiceNow Store
- C. Download one from ServiceNow Share
- D. Ask for assistance in the community page
Answer: B
NEW QUESTION 17
Which improvement opportunity can be found baseline which can contribute towards process maturity and strengthen costumer's overall security posture?
- A. Incident Analysis
- B. Incident Containment
- C. Post-Incident Review
- D. Fast Eradication
Answer: A
NEW QUESTION 18
Chief factors when configuring auto-assignment of Security Incidents are.
- A. Security incident priority, CI Location and agent time zone
- B. Agent location, Agent skills and agent time zone
- C. Agent group membership, Agent location and time zone
- D. Agent skills, System Schedules and agent location
Answer: B
NEW QUESTION 19
Which of the following process definitions are not provided baseline?
- A. NIST Stateful
- B. SAN Stateful
- C. SANS Open
- D. NIST Open
Answer: D
NEW QUESTION 20
What role(s) are required to add new items to the Security Incident Catalog?
- A. requires the sn_si.admin role
- B. requires the admin role
- C. requires both sn_si.write and catalog_admin roles
- D. requires the sn_si.catalog role
Answer: B
NEW QUESTION 21
Which of the following State Flows are provided for Security Incidents? (Choose three.)
- A. NIST Stateful
- B. SANS Stateful
- C. SANS Open
- D. NIST Open
Answer: A,B,D
NEW QUESTION 22
Which Table would be commonly used for Security Incident Response?
- A. sysapproval_approver
- B. sn_si_incident
- C. sec_ops_incident
- D. cmdb_rel_ci
Answer: B
NEW QUESTION 23
What is the fastest way for security incident administrators to remove unwanted widgets from the Security Incident Catalog?
- A. Talking to the system administrator
- B. Can't be removed
- C. Through the Catalog Definition record
- D. Clicking the X on the top right corner
Answer: C
NEW QUESTION 24
There are several methods in which security incidents can be raised, which broadly fit into one of these categories: __________. (Choose two.)
- A. Automatically created
- B. Email parsing
- C. Integrations
- D. Manually created
Answer: A,D
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/concept/si-creation.html
NEW QUESTION 25
Select the one capability that retrieves a list of running processes on a CI from a host or endpoint.
- A. Get Running Processes
- B. Block Action
- C. Get Network Statistics
- D. Publish Watchlist
- E. Sightings Search
- F. Isolate Host
Answer: A
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/quebec-security-management/page/product/security- operations-common/concept/get-running-processes-capability.html
NEW QUESTION 26
In order to see the Actions in Flow Designer for Security Incident, what plugin must be activated?
- A. Security Incident Spoke
- B. Performance Analytics for Security Incident Response
- C. Security Spoke
- D. Security Operations Spoke
Answer: D
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response-orchestration/concept/sir-flows-and-templates.html
NEW QUESTION 27
Incident severity is influenced by the business value of the affected asset.
Which of the following are asset types that can be affected by an incident? (Choose two.)
- A. Configuration Item
- B. Calculator Group
- C. Business Service
- D. Severity Calculator
Answer: A,C
NEW QUESTION 28
Which one of the following reasons best describes why roles for Security Incident Response (SIR) begin with
"sn_si"?
- A. Because the Security Incident Response application uses a Secure Identity token
- B. Because ServiceNow checks the instance for a Secure Identity when logging on to this scoped application
- C. Because SIR is a scoped application, roles and script includes will begin with the sn_si prefix
- D. Because ServiceNow tracks license use against the Security Incident Response Application
Answer: A
NEW QUESTION 29
Security tag used when a piece of information requires support to be effectively acted upon, yet carries risks to privacy, reputation, or operations if shared outside of the organizations involved.
- A. TLP:AMBER
- B. TLP:RED
- C. TLP:WHITE
- D. TLP:GREEN
Answer: A
Explanation:
Explanation
Table Description automatically generated
NEW QUESTION 30
The severity field of the security incident is influenced by what?
- A. The cost of the response to the security breach
- B. The business value of the affected asset
- C. The time taken to resolve the security incident
- D. The impact, urgency and priority of the incident
Answer: B
NEW QUESTION 31
Which one of the following users is automatically added to the Request Assessments list?
- A. The Affected User on the incident
- B. Any user that adds a worknote to the ticket
- C. The analyst assigned to the ticket
- D. Any user who has Response Tasks on the incident
Answer: D
NEW QUESTION 32
What three steps enable you to include a new playbook in the Selected Playbook choice list? (Choose three.)
- A. Add the TLP: GREEN tag to the playbooks that you want to include in the Selected Playbook choice list
- B. Add the sir_playbook tag to the playbooks that you want to include in the Selected Playbook choice list
- C. Navigate to the sys_playbook_flow.list table
- D. Search for the new playbook you have created using Flow Designer
- E. Navigate to the sys_hub_flow.list table
Answer: B,D,E
NEW QUESTION 33
Which of the following tag classifications are provided baseline? (Choose three.)
- A. Severity
- B. Block from Sharing
- C. Traffic Light Protocol
- D. IoC Type
- E. Enrichment whitelist/blacklist
- F. Cyber Kill Chain Step
- G. Escalation Level
Answer: C,D,E
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security- operations-common/task/create-class-group-and-tags.html
NEW QUESTION 34
Joe is on the SIR Team and needs to be able to configure Territories and Skills.
What role does he need?
- A. Security Analyst
- B. Security Admin
- C. Manager
- D. Security Basic
Answer: B
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/quebec-security-management/page/product/security- incident-response/reference/installed-with-sir.html
NEW QUESTION 35
Which of the following tag classifications are provided baseline? (Choose three.)
- A. Severity
- B. Block from Sharing
- C. Traffic Light Protocol
- D. IoC Type
- E. Enrichment whitelist/blacklist
- F. Cyber Kill Chain Step
- G. Escalation Level
Answer: C,D,E
NEW QUESTION 36
......
CIS-SIR Exam with Accurate Certified Implementation Specialist - Security Incident Response Exam PDF Questions: https://www.vceprep.com/CIS-SIR-latest-vce-prep.html