CIS-TPRM Sample Questions

CIS-TPRM Sample Questions & Answers

Setting up due-diligence requests, tiering and risk assessments carries the most weight, next to the overall process, configuring portfolios and contacts with risk scoring, the third-party portal, approval workflows, and links to other GRC apps.

Launch the full CIS-TPRM simulator →

Free CIS-TPRM Sample Questions with Answers

Real questions from the Certified Implementation Specialist - Third-party Risk Management practice test — answers and explanations included. Showing 6 of 12 free samples.

  1. Question 1Beginner

    Third-party Risk Management Fundamentals and Third-party Risk Management Review · Technical Details

    In ServiceNow GRC, risks that are registered within an organization and applied to third parties are typically captured as which type of record?

    Show answer & explanation

    Correct answer: C

    In the ServiceNow GRC architecture, registered risks are captured as Risk Statements. These statements can be applied to various entities, including third parties, to track and evaluate specific risk exposures consistently across the enterprise.

  2. Question 2Intermediate

    Third-party Risk Management Fundamentals and Third-party Risk Management Review · About Third-party Risk Management

    A client wants to ensure that external vendors can log in, complete questionnaires, and manage their own contacts. Which ServiceNow feature is specifically designed for this purpose, and should not be confused with customer support portals?

    Show answer & explanation

    Correct answer: C

    The Third-party Portal is the dedicated interface within the TPRM application for external vendors. It allows them to securely respond to assessments, manage issues, and update their contacts. It is distinct from the Customer Service Portal, which is used for external customer support queries.

  3. Question 3Beginner

    Third-party Risk Management Fundamentals and Third-party Risk Management Review · Third-party Risk Management Process

    Review the following TPRM process flow:

    flowchart LR A[Onboarding] --> B[Tiering] B --> C[Assessment] C --> D[Issue Management] D --> E[Monitoring]

    During which phase of this lifecycle does the platform typically utilize an Inherent Risk Questionnaire (IRQ)?

    Show answer & explanation

    Correct answer: B

    The Inherent Risk Questionnaire (IRQ) is utilized during the Tiering phase. It is typically sent to an internal business owner to assess the inherent risk of engaging with the third party. The responses dictate the third party's Rank Tier, which subsequently drives the type and rigor of the due diligence and risk assessment required in the next phase.

  4. Question 4Intermediate

    Third-party Risk Management Fundamentals and Third-party Risk Management Review · About Third-party Risk Management

    How does the TPRM application integrate third-party risk with broader ServiceNow GRC operations?

    Show answer & explanation

    Correct answer: C

    TPRM operates within the broader ServiceNow GRC suite. This integration allows organizations to link specific third-party risks to overarching enterprise Risk Statements and monitor compliance against centralized Control Objectives. This ensures that third-party risk is treated as a component of the overall enterprise risk posture.

  5. Question 5Intermediate

    Third-party Risk Management Fundamentals and Third-party Risk Management Review · Technical Details

    The core table used to store third-party organizational records in the ServiceNow TPRM application is: _____

    Show answer & explanation

    Correct answer: B

    The core_third_party table is the primary table that stores the organizational records for third parties. It extends the base core_company table to add TPRM-specific fields and capabilities without impacting other applications.

  6. Question 6Beginner

    Third-party Risk Management Fundamentals and Third-party Risk Management Review · Technical Details

    True or False: In ServiceNow TPRM, third-party risk assessments can be used to monitor the compliance of specific GRC Controls associated with a third party.

    Show answer & explanation

    Correct answer: A

    True. ServiceNow TPRM is tightly integrated with the broader GRC suite. When a third party responds to an assessment, those responses can be mapped to automatically update the compliance status of specific GRC Controls applied to that vendor. This eliminates manual evidence gathering and ensures continuous compliance monitoring.

Ready for the real thing?

The full CIS-TPRM simulator has every exam-style question, timed mode, and instant scoring.