CIS-VRM Sample Questions

CIS-VRM Sample Questions & Answers

Assessment basics, tiering and risk scoring take the biggest share, next to a general grounding in the process itself, setting up portfolios and contact records, the vendor-facing portal, approval chains, and ties to other GRC capabilities.

Launch the full CIS-VRM simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Supporting Processes · Third-party Risk Issues Approval

    A TPRM manager has a requirement that any 'High' severity issue generated from an assessment for a 'Tier 1' third party must be approved by the Director of Compliance before it can be moved to the 'Awaiting Implementation' state. What is the most appropriate tool in ServiceNow to automate this specific approval requirement?

    Show answer & explanation

    Correct answer: D

    Flow Designer is the modern and recommended approach for creating complex, conditional approval workflows. A flow can be triggered when an issue is created or updated. It can then use 'If' logic to check if the issue's severity is 'High' and the related third party's tier is 'Tier 1'. If both conditions are met, it can use the 'Ask for Approval' action to route the request to the specified user or group.

  2. Question 2Advanced

    Application Relationships · Monitor Risk and Control Compliance

    A healthcare organization uses ServiceNow TPRM to manage suppliers of critical medical software. After an assessment, a high-risk issue related to HIPAA compliance is identified. The risk team needs to formally track this risk and link it to a specific HIPAA control. Which is the best practice for handling this within the GRC and TPRM applications?

    Show answer & explanation

    Correct answer: B

    The standard ServiceNow GRC process is to elevate a vendor risk issue into a formal Risk record in the Risk Register. This allows for comprehensive risk assessment, scoring, and treatment planning. The Risk record can then be directly associated with the specific Control Objective (e.g., a specific HIPAA control from the UCF), creating a clear audit trail from the assessment finding to the compliance framework.

  3. Question 3Intermediate

    Core Configuration · Third-party Portfolio Configuration

    A TPRM administrator is importing a large number of third-party records from a legacy system. The import set contains a 'Country' column. The administrator needs to ensure that the imported string for the country is correctly mapped to the corresponding core_country reference field on the Company table. Which feature of the import process should be used to accomplish this?

    Show answer & explanation

    Correct answer: D

    When mapping a source field containing a display value (like a country name) to a target reference field, the correct approach is to use a standard Field Map and specify the 'Referenced value field name'. By setting this to 'name', you instruct the Transform Map to look up records in the referenced table (core_country) where the 'name' field matches the incoming source value, and then populate the target field with the sys_id of the found record.

  4. Question 4Beginner

    Assessment Configuration · Third-party IRQ (Tiering) and Due Diligence Configuration

    What is the primary function of an Inherent Risk Questionnaire (IRQ) in the ServiceNow Third-party Risk Management process?

    Show answer & explanation

    Correct answer: B

    The IRQ is an internal-facing questionnaire. Its primary purpose is for the business owner or relationship manager to provide information about the nature of the engagement with the third party (e.g., what data they will access, how they will connect). The answers are then used to calculate an inherent risk score and automatically determine the third party's tier, which in turn drives the level of due diligence required.

  5. Question 5Intermediate

    Assessment Configuration · Assessment Lifecycle

    A user with the sn_vdr_risk_asmt.vendor_assessor role reports that they are unable to see the 'Generate Observations' UI action on a Third-party Risk Assessment record that is in the 'Responses Received' state. What is the most likely reason for this issue?

    stateDiagram-v2 [*] --> Submitted Submitted --> "Responses Received" : vendor responds "Responses Received" --> "Generating Observations" : assessor action "Generating Observations" --> Finalizing : system process Finalizing --> Closed
    Show answer & explanation

    Correct answer: B

    While the sn_vdr_risk_asmt.vendor_assessor role provides the necessary permissions to perform the action, the 'Generate Observations' UI action has a condition that requires the logged-in user to be the individual specified in the 'Assigned to' field of that specific assessment record. This ensures that only the designated assessor can advance the assessment.

  6. Question 6Advanced

    Fundamentals and Review · About Third-party Risk Management

    Case Study: FinCorp, a large investment bank, is implementing ServiceNow TPRM. They have over 5,000 third parties, ranging from large technology providers to small independent contractors. The Chief Risk Officer (CRO) has mandated a new, highly structured governance process.

    Current Situation: Third-party onboarding is manual and inconsistent. Risk assessments are performed using spreadsheets and are not standardized. There is no central repository of third-party information, leading to duplicate efforts and a lack of visibility into overall risk exposure. The process for managing identified issues is ad-hoc, with no formal tracking or approval.

    Requirements:

    1. A centralized, authoritative source for all third-party data.
    2. An automated, risk-based tiering system to categorize all 5,000 third parties based on their inherent risk.
    3. A streamlined assessment process where the type and depth of the questionnaire are determined by the third party's tier.
    4. A formal, multi-level approval workflow for any 'High' or 'Critical' risk issues identified, requiring sign-off from the business owner, the risk team, and the CISO.
    5. A dedicated portal for third parties to respond to assessments and manage their information.

    Which ServiceNow feature is LEAST relevant to meeting the CRO's mandated requirements?

    Show answer & explanation

    Correct answer: C

    While SAM Pro can be a valuable related application for managing software vendors, it is not a core component for meeting the specified requirements of centralized data, risk-based tiering, automated assessments, issue approval workflows, and a vendor portal. The other options directly address the CRO's mandates using core TPRM functionality.

  7. Question 7Beginner

    Portal Configuration · Third-party Portal Configuration

    A TPRM administrator wants to provide third-party contacts with the ability to ask questions and get help directly within the Third-party Portal. Which feature should be enabled and configured to provide this functionality?

    Show answer & explanation

    Correct answer: D

    The ServiceNow Virtual Agent can be configured and exposed on the Third-party Portal to provide a conversational interface for third parties. It can be designed to answer frequently asked questions, guide users through processes, or create cases for the internal TPRM team if the issue cannot be resolved automatically.

  8. Question 8BeginnerSelect 2

    Assessment Configuration · Assessment Lifecycle

    Which of the following are valid states in the default lifecycle of a Third-party Risk Assessment? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    The default assessment lifecycle includes several key states. 'Submitted to Third Party' indicates the assessment is with the external contact for completion. 'Finalizing with Third Party' is a state where the internal team reviews the submitted responses and may ask for clarification before closing the assessment. 'Pending Approval' and 'Awaiting Implementation' are typically states for Issues, not the assessment itself.

  9. Question 9Advanced

    Application Relationships · Other Application Relationships

    A company has integrated ServiceNow TPRM with a third-party risk intelligence provider that continuously monitors for security incidents. An alert is received indicating a critical data breach at a 'Tier 1' third party. Which ServiceNow application should this alert be routed to for immediate investigation and response, while also linking it back to the third party's risk profile?

    Show answer & explanation

    Correct answer: C

    For security-related events like data breaches, the best practice is to route the alert to the Security Incident Response (SIR) application within ServiceNow Security Operations. A security incident can be created, which allows for a formal, structured investigation by the security team. The security incident can then be linked to the third party's company record and a corresponding GRC Issue can be created to track the risk impact within the TPRM application.

  10. Question 10Beginner

    Fundamentals and Review · Technical Details

    True or False: The sn_vdr_risk.vendor_admin role allows a user to configure all aspects of the Third-party Risk Management application, including creating questionnaire templates and modifying risk scoring calculations.

    Show answer & explanation

    Correct answer: B

    False. The sn_vdr_risk.vendor_admin role has limited administrative capabilities, primarily focused on managing vendor records and contacts. The role required to configure core application settings like questionnaire templates, risk scoring, and tiering rules is sn_vdr_risk_asmt.vendor_risk_manager.

Ready for the real thing?

The full CIS-VRM simulator has every exam-style question, timed mode, and instant scoring.