[2022] New CIS-SIR exam dumps Use Updated ServiceNow Exam [Q37-Q62]

Share

[2022] New CIS-SIR exam dumps Use Updated ServiceNow Exam

Verified CIS-SIR Dumps Q&As - CIS-SIR Test Engine with Correct Answers


Salary of ServiceNow Certified Implementation Specialist - Security Incident Response Exam certified professionals

The salary of ServiceNow Certified Implementation Specialist - Security Incident Response Exam certified professionals varies from $88K to $107K depending on the years of experience.


For more info about ServiceNow Certified Implementation Specialist - Security Incident Response Exam

CIS-SIR Certification

 

NEW QUESTION 37
This type of integration workflow helps retrieve a list of active network connections from a host or endpoint, so it can be used to enrich incidents during investigation.

  • A. Security Operations Integration - Sightings Search
  • B. Security Incident Response - Get Network Statistics
  • C. Security Incident Response - Get Running Services
  • D. Security Operations Integration - Block Request

Answer: B

 

NEW QUESTION 38
When a record is created in the Security Incident Phishing Email table what is triggered to create a Security Incident?

  • A. Transform workflow
  • B. Ingestion Rule
  • C. Duplication Rule
  • D. Transform flow

Answer: B

 

NEW QUESTION 39
There are several methods in which security incidents can be raised, which broadly fit into one of these categories:. (Choose two.)

  • A. Integrations
  • B. Email parsing
  • C. Manually created
  • D. Automatically created

Answer: C,D

 

NEW QUESTION 40
If a desired pre-built integration cannot be found in the platform, what should be your next step to find a certified integration?

  • A. Look for one in the ServiceNow Store
  • B. Download one from ServiceNow Share
  • C. Build your own through the REST API Explorer
  • D. Ask for assistance in the community page

Answer: A

 

NEW QUESTION 41
When a service desk agent uses the Create Security Incident UI action from a regular incident, what occurs?

  • A. A security incident is raised on their behalf and displayed to the service desk agent
  • B. A security incident is raised on their behalf but only a notification is displayed
  • C. The service desk agent is redirected to the Security Incident Catalog to complete the record producer
  • D. The incident is marked resolved with an automatic security resolution code

Answer: D

 

NEW QUESTION 42
To configure Security Incident Escalations, you need the following role(s):.

  • A. sn_si.admin or sn_si.ciso
  • B. sn_si.manager or sn_si.analyst
  • C. sn_si.admin
  • D. sn_si.admin or sn_si.manager

Answer: C

 

NEW QUESTION 43
What is the key to a successful implementation?

  • A. Sell customer the most expensive package
  • B. Building custom integrations
  • C. Understanding the customer's goals and objectives
  • D. Implementing everything that we offer

Answer: C

 

NEW QUESTION 44
A pre-planned response process contains which sequence of events?

  • A. Organize, Prepare, Prioritize, Contain
  • B. Organize, Verify, Prioritize, Contain
  • C. Organize, Detect, Prioritize, Contain
  • D. Organize, Analyze, Prioritize, Contain

Answer: D

 

NEW QUESTION 45
Chief factors when configuring auto-assignment of Security Incidents are.

  • A. Security incident priority, CI Location and agent time zone
  • B. Agent location, Agent skills and agent time zone
  • C. Agent group membership, Agent location and time zone
  • D. Agent skills, System Schedules and agent location

Answer: B

 

NEW QUESTION 46
Which of the following State Flows are provided for Security Incidents? (Choose three.)

  • A. NIST Open
  • B. NIST Stateful
  • C. SANS Stateful
  • D. SANS Open

Answer: A,B,C

 

NEW QUESTION 47
A flow consists of one or more actions and a what?

  • A. Catalog Designer
  • B. NIST Ready State
  • C. Change formatter
  • D. Trigger

Answer: D

 

NEW QUESTION 48
Which one of the following reasons best describes why roles for Security Incident Response (SIR) begin with "sn_si"?

  • A. Because the Security Incident Response application uses a Secure Identity token
  • B. Because SIR is a scoped application, roles and script includes will begin with the sn_si prefix
  • C. Because ServiceNow tracks license use against the Security Incident Response Application
  • D. Because ServiceNow checks the instance for a Secure Identity when logging on to this scoped application

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 49
What parts of the Security Incident Response lifecycle is responsible for limiting the impact of a security incident?

  • A. Post Incident Activity
  • B. Preparation and Identification
  • C. Detection & Analysis
  • D. Containment, Eradication, and Recovery

Answer: D

 

NEW QUESTION 50
Knowledge articles that describe steps an analyst needs to follow to complete Security incident tasks might be associated to those tasks through which of the following?

  • A. Flow
  • B. Flow Designer
  • C. Workflow
  • D. Runbook
  • E. Work Instruction Playbook

Answer: D

 

NEW QUESTION 51
A Post Incident Review can contain which of the following? (Choose three.)

  • A. Key incident fields
  • B. Performance Analytics reports
  • C. Attachments associated with the security incident
  • D. Post incident question:naires
  • E. An audit trail

Answer: A,D,E

 

NEW QUESTION 52
What is the first step when creating a security Playbook?

  • A. Create a Runbook
  • B. Set the Response Task's state
  • C. Create a Knowledge Article
  • D. Create a Flow

Answer: D

 

NEW QUESTION 53
Which Table would be commonly used for Security Incident Response?

  • A. sec_ops_incident
  • B. sn_si_incident
  • C. sysapproval_approver
  • D. cmdb_rel_ci

Answer: B

 

NEW QUESTION 54
David is on the Network team and has been assigned a security incident response task.
What role does he need to be able to view and work the task?

  • A. Read
  • B. External
  • C. Security Basic
  • D. Security Analyst

Answer: D

 

NEW QUESTION 55
What is the purpose of Calculator Groups as opposed to Calculators?

  • A. To provide metadata about the calculators
  • B. To set the condition for all calculators to run
  • C. To allow the agent to select which calculator they want to execute
  • D. To ensure one at maximum will run per group

Answer: B

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/reference/setup-assistant-reference.html

 

NEW QUESTION 56
What does a flow require?

  • A. Security orchestration flows
  • B. Runbooks
  • C. CAB orders
  • D. A trigger

Answer: D

 

NEW QUESTION 57
Which of the following is an action provided by the Security Incident Response application?

  • A. Create Record on Security Incident state V1
  • B. Look Up Record on Security Incident state V1
  • C. Create Outage state V1
  • D. Create Response Task set Incident state V1

Answer: B

 

NEW QUESTION 58
What three steps enable you to include a new playbook in the Selected Playbook choice list? (Choose three.)

  • A. Search for the new playbook you have created using Flow Designer
  • B. Navigate to the sys_playbook_flow.list table
  • C. Add the TLP: GREEN tag to the playbooks that you want to include in the Selected Playbook choice list
  • D. Navigate to the sys_hub_flow.list table
  • E. Add the sir_playbook tag to the playbooks that you want to include in the Selected Playbook choice list

Answer: A,D,E

 

NEW QUESTION 59
What parts of the Security Incident Response lifecycle is responsible for limiting the impact of a security incident?

  • A. Post Incident Activity
  • B. Preparation and Identification
  • C. Detection & Analysis
  • D. Containment, Eradication, and Recovery

Answer: D

Explanation:
Explanation/Reference: https://searchsecurity.techtarget.com/definition/incident-response

 

NEW QUESTION 60
Flow Triggers can be based on what? (Choose three.)

  • A. Record views
  • B. Record changes
  • C. Subflows
  • D. Record inserts
  • E. Schedules

Answer: B,C,E

 

NEW QUESTION 61
When the Security Phishing Email record is created what types of observables are stored in the record?
(Choose three.)

  • A. Hashes and/or file names found in the EML attachment
  • B. Type of Ingestion Rule used to identify this email as a phishing attempt
  • C. IP addresses from the header
  • D. Who reported the phishing attempt
  • E. URLs, domains, or IP addresses appearing in the body
  • F. State of the phishing email

Answer: A,C,E

 

NEW QUESTION 62
......

Pass Your CIS-SIR Dumps as PDF Updated on 2022 With 62 Questions: https://prep4tests.pass4sures.top/Certified-Implementation-Specialist/CIS-SIR-testking-braindumps.html