[Dec 14, 2025] Free Vulnerability Response Implementation CIS-VR Official Cert Guide PDF Download [Q18-Q33]

Share

[Dec 14, 2025] Free Vulnerability Response Implementation CIS-VR Official Cert Guide PDF Download

ServiceNow CIS-VR Official Cert Guide PDF

NEW QUESTION # 18
Where can you find Information related to the Common Vulnerabilities and Exposures (CVE)?

  • A. Qualys
  • B. Tenable
  • C. NIST
  • D. MITRE

Answer: D

Explanation:
https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures


NEW QUESTION # 19
In ServiceNow, which plugin needs to be added to enable Vulnerability Integration with Qualys, Tenable, or Rapid7?

  • A. Trusted Security Circles
  • B. Threat Intelligence
  • C. Vulnerability Response
  • D. Security Incident Response

Answer: C

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-release-notes/page/release-notes/security-operations/ secops-vuln-resp-rn.html


NEW QUESTION # 20
SLAs are used to ensure VUL are processed in a timely matter. Which field is used to determine the expected timeframe for remediating a VIT?

  • A. Updated
  • B. Remediation target
  • C. Closed
  • D. Remediation status

Answer: B

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-security-management/page/product/vulnerability- response/concept/time-to-remediate-rules.html


NEW QUESTION # 21
What do Vulnerability Exceptions require?

  • A. A GRC integration
  • B. A Filter Group
  • C. An Exception Workflow
  • D. An Approval by default

Answer: D


NEW QUESTION # 22
A list of software weaknesses is known as:

  • A. Common Weaknesses Enumeration (CWE)
  • B. National Vulnerability Database (NVD)
  • C. Common Vulnerability and Exposure (CVE)
  • D. National Institute of Science and Technology (NIST)

Answer: A

Explanation:
Explanation
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-security-management/page/product/vulnerability- response/concept/c_VulnerabilityResponse.html


NEW QUESTION # 23
Which statement about patching is most correct?

  • A. Patch management and Vulnerability Response are interchangeable terms
  • B. As long as you are patching actively. Vulnerability Response isn't necessary
  • C. Mature organizations abandon patching
  • D. Patching is one of many responses to a Vulnerability

Answer: D


NEW QUESTION # 24
Which of the following best describes a Vulnerability Group?

  • A. Groups VIs using a Filter against Vulnerable Item Fields
  • B. A Filter defining a sub-set of CIs to be treated as a group
  • C. The User Group assigned to resolving the Vulnerable Item
  • D. Must have a corresponding filter group

Answer: D

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-security-management/page/product/vulnerability- response/concept/vulnerability-groups.html


NEW QUESTION # 25
The three levels of users you will likely encounter that will need access to data displayed in the Vulnerability Response dashboard are: Choose 3 answers

  • A. CIO/CISO
  • B. Fulfillers
  • C. Customers
  • D. Security Analysts

Answer: D


NEW QUESTION # 26
To get useful reporting regarding the most vulnerable CI's, which statement applies?

  • A. Your CI population must be huge.
  • B. You must purchase a separate PA module.
  • C. You must have good KPi's defined.
  • D. Your CMDB must be up to date and useful.

Answer: A


NEW QUESTION # 27
To facilitate the remediation of a Vulnerable Item what type of Item is most commonly used?

  • A. Create a Problem
  • B. Create a KB article
  • C. Create a Security Incident
  • D. Create a Change

Answer: D


NEW QUESTION # 28
If fixing a Vulnerable Item outweighs the benefits, the correct course of action is:

  • A. Record the accepted risk and Close/Defer the Vulnerable Item
  • B. Deprioritize the Vulnerable Item Records (VIT) to push them further down the list so it can be ignored
  • C. Add the CI to the Vulnerability Scanner's exclusions Related List
  • D. Mark the CI inactive in the CMDB and notify the CI owner

Answer: A

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-security-management/page/product/vulnerability- response/concept/c_IndivVulnItemMgmt.html


NEW QUESTION # 29
What is the minimum role required to create and change Service Level Agreements for Vulnerability Response groups?

  • A. sla_manager
  • B. admin
  • C. sn_vul.admin
  • D. sn_vul.vulnerability_write

Answer: C

Explanation:
https://docs.servicenow.com/bundle/washingtondc-security-management/page/product/vulnerability-response/task/t_CreateVulnSLA.html


NEW QUESTION # 30
To ensure that Vulnerabilities are processed correctly, you can define a Service Level Agreement (SLA) for Vulnerability Response. To achieve this you would:

  • A. Create a custom workflow to monitor the time between States
  • B. Have the role of Vulnerability admin, but only in the Vulnerability Scope
  • C. Log in as a system admin, and using the globally scoped baseline SLA Modules
  • D. Make sure you have at least the sn_vul.vulnerability_write role and using the baseline SLA Application Modules

Answer: B

Explanation:
https://docs.servicenow.com/bundle/vancouver-security-management/page/product/vulnerability-response/task/t_CreateVulnSLA.html


NEW QUESTION # 31
Where can you find Information related to the Common Vulnerabilities and Exposures (CVE)?

  • A. Qualys
  • B. Tenable
  • C. NIST
  • D. MITRE

Answer: D


NEW QUESTION # 32
Where in the platform can you create Filter Groups?

  • A. Security Operations > Groups > Filter Groups
  • B. Security Operations > Administration > Filter Groups
  • C. Vulnerability > Groups > Filter Groups
  • D. Vulnerability > Administration > Filter Groups

Answer: A

Explanation:
https://docs.servicenow.com/en-US/bundle/vancouver-security-management/page/product/security-operations-common/task/create-filter-group.html


NEW QUESTION # 33
......

Free CIS-VR Exam Dumps to Improve Exam Score: https://examcollection.vcetorrent.com/CIS-VR-valid-vce-torrent.html