CIS-DISCO Sample Questions & Answers
Designing discovery patterns ties with configuring and troubleshooting discovery itself for the heaviest weight, while sorting CIs into classes and cleaning up the configuration database, plus planning a rollout, make up the rest.
Launch the full CIS-DISCO simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Discovery Configuration · Discovery Process Flow
While analyzing the ECC Queue, an administrator notices a 'No credentials would authenticate' error. In which phase of the Discovery PCIE cycle did this error occur, and what is the immediate consequence for the CI?
Show answer & explanation
Correct answer: A
The 'No credentials would authenticate' error occurs during the Classification phase. After Shazzam (Port Scan) identifies open ports, Discovery attempts to log in using configured credentials to determine the device type (Classification). If authentication fails, the process halts for that IP, meaning Identification and Exploration never run, so no CI is created or updated.
- Question 2Intermediate
Discovery Pattern Design · Syntax
An implementation specialist needs to parse a version string from a raw data variable in Pattern Designer. The raw string format is
App_Name-v12.4.5-Build2024. The requirement is to extract12.4.5into theversionvariable. Which Regular Expression (Regex) correctly captures this value?Show answer & explanation
Correct answer: A
The regex
v(\d+\.\d+\.\d+)looks for the literal character 'v' followed by a capture group(...). Inside the group,\d+matches one or more digits, and\.matches a literal dot. This pattern\d+\.\d+\.\d+strictly matches the version format '12.4.5' found immediately after 'v'. - Question 3Advanced
Configuration Management Database · CMDB Identification and Reconciliation
You are configuring the CMDB Identification and Reconciliation Engine (IRE). You have a requirement where CIs discovered by 'ServiceNow Discovery' should always overwrite attributes set by 'Manual Entry', but 'SCCM' imports should only update the 'Operating System' attribute if it is empty. Which feature should you configure to enforce these rules?
Show answer & explanation
Correct answer: C
Reconciliation Definitions (specifically Data Source Precedence rules) are used to define the priority of different discovery sources. You can configure rules at the table level (Discovery > Manual) or attribute level (SCCM can only update Operating System if null/lower priority) to control which source is authoritative for CI data.
- Question 4Beginner
Discovery Configuration · Discovery Setup
A customer wants to run a quick discovery on a specific high-priority server to troubleshoot a configuration change. They do not want to create a formal Discovery Schedule. What is the most appropriate method to achieve this, and what input is required?
Show answer & explanation
Correct answer: D
'Quick Discovery' is a feature designed exactly for this purpose. It allows an administrator to run discovery on a single IP address immediately without configuring a full schedule. The user must specify the Target IP address and the MID Server to use for the check.
- Question 5IntermediateSelect 3
Discovery Engagement Readiness · Planning
In the context of Discovery Engagement Readiness, which THREE factors are critical when sizing and planning the deployment of MID Servers? (Select THREE)
Show answer & explanation
Correct answers: A, C, E
The volume of data (number of CIs) and how often you need to scan them determines the load, which dictates how many MID Servers or clusters are needed.
MID Servers should be placed close (network-wise) to the targets to reduce latency and bandwidth usage, especially for large discoveries.
MID Server performance is directly tied to the number of threads it can run and the memory allocated to the Java Virtual Machine (JVM). Heavy loads require tuning these parameters.
- Question 6Advanced
Discovery Configuration · Discovery Troubleshooting
Case Study: TechCorp Inc.
TechCorp is implementing ServiceNow Discovery. They have a strict security policy that prohibits the use of 'Domain Admin' accounts. They have provided a 'Service Account' with specific WMI and SSH permissions. During the initial 'Port Scan' phase, Shazzam successfully identifies open ports 135 and 22 on the targets. However, the discovery log shows the process halting at the Classification phase with authentication failures.
Upon reviewing the credentials table, the administrator sees the service account is configured correctly. What is the most likely cause of this failure given the security constraints?
Show answer & explanation
Correct answer: B
For Windows Discovery using WMI, if the MID Server service is running as 'LocalSystem', it cannot impersonate domain credentials effectively for WMI queries in many secure environments. The MID Server service itself should often be configured to run as a specific service account that has the necessary network rights, or configured specifically to allow credential impersonation. However, the most common issue in non-Domain Admin scenarios is the MID Server service account configuration or lack of 'Log on as a service' rights for the credential being used.
Ready for the real thing?
The full CIS-DISCO simulator has every exam-style question, timed mode, and instant scoring.