
[Dec 14, 2025] Free Vulnerability Response Implementation CIS-VR Official Cert Guide PDF Download
ServiceNow CIS-VR Official Cert Guide PDF
NEW QUESTION # 18
Where can you find Information related to the Common Vulnerabilities and Exposures (CVE)?
- A. Qualys
- B. Tenable
- C. NIST
- D. MITRE
Answer: D
Explanation:
https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures
NEW QUESTION # 19
In ServiceNow, which plugin needs to be added to enable Vulnerability Integration with Qualys, Tenable, or Rapid7?
- A. Trusted Security Circles
- B. Threat Intelligence
- C. Vulnerability Response
- D. Security Incident Response
Answer: C
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-release-notes/page/release-notes/security-operations/ secops-vuln-resp-rn.html
NEW QUESTION # 20
SLAs are used to ensure VUL are processed in a timely matter. Which field is used to determine the expected timeframe for remediating a VIT?
- A. Updated
- B. Remediation target
- C. Closed
- D. Remediation status
Answer: B
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-security-management/page/product/vulnerability- response/concept/time-to-remediate-rules.html
NEW QUESTION # 21
What do Vulnerability Exceptions require?
- A. A GRC integration
- B. A Filter Group
- C. An Exception Workflow
- D. An Approval by default
Answer: D
NEW QUESTION # 22
A list of software weaknesses is known as:
- A. Common Weaknesses Enumeration (CWE)
- B. National Vulnerability Database (NVD)
- C. Common Vulnerability and Exposure (CVE)
- D. National Institute of Science and Technology (NIST)
Answer: A
Explanation:
Explanation
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-security-management/page/product/vulnerability- response/concept/c_VulnerabilityResponse.html
NEW QUESTION # 23
Which statement about patching is most correct?
- A. Patch management and Vulnerability Response are interchangeable terms
- B. As long as you are patching actively. Vulnerability Response isn't necessary
- C. Mature organizations abandon patching
- D. Patching is one of many responses to a Vulnerability
Answer: D
NEW QUESTION # 24
Which of the following best describes a Vulnerability Group?
- A. Groups VIs using a Filter against Vulnerable Item Fields
- B. A Filter defining a sub-set of CIs to be treated as a group
- C. The User Group assigned to resolving the Vulnerable Item
- D. Must have a corresponding filter group
Answer: D
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-security-management/page/product/vulnerability- response/concept/vulnerability-groups.html
NEW QUESTION # 25
The three levels of users you will likely encounter that will need access to data displayed in the Vulnerability Response dashboard are: Choose 3 answers
- A. CIO/CISO
- B. Fulfillers
- C. Customers
- D. Security Analysts
Answer: D
NEW QUESTION # 26
To get useful reporting regarding the most vulnerable CI's, which statement applies?
- A. Your CI population must be huge.
- B. You must purchase a separate PA module.
- C. You must have good KPi's defined.
- D. Your CMDB must be up to date and useful.
Answer: A
NEW QUESTION # 27
To facilitate the remediation of a Vulnerable Item what type of Item is most commonly used?
- A. Create a Problem
- B. Create a KB article
- C. Create a Security Incident
- D. Create a Change
Answer: D
NEW QUESTION # 28
If fixing a Vulnerable Item outweighs the benefits, the correct course of action is:
- A. Record the accepted risk and Close/Defer the Vulnerable Item
- B. Deprioritize the Vulnerable Item Records (VIT) to push them further down the list so it can be ignored
- C. Add the CI to the Vulnerability Scanner's exclusions Related List
- D. Mark the CI inactive in the CMDB and notify the CI owner
Answer: A
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/orlando-security-management/page/product/vulnerability- response/concept/c_IndivVulnItemMgmt.html
NEW QUESTION # 29
What is the minimum role required to create and change Service Level Agreements for Vulnerability Response groups?
- A. sla_manager
- B. admin
- C. sn_vul.admin
- D. sn_vul.vulnerability_write
Answer: C
Explanation:
https://docs.servicenow.com/bundle/washingtondc-security-management/page/product/vulnerability-response/task/t_CreateVulnSLA.html
NEW QUESTION # 30
To ensure that Vulnerabilities are processed correctly, you can define a Service Level Agreement (SLA) for Vulnerability Response. To achieve this you would:
- A. Create a custom workflow to monitor the time between States
- B. Have the role of Vulnerability admin, but only in the Vulnerability Scope
- C. Log in as a system admin, and using the globally scoped baseline SLA Modules
- D. Make sure you have at least the sn_vul.vulnerability_write role and using the baseline SLA Application Modules
Answer: B
Explanation:
https://docs.servicenow.com/bundle/vancouver-security-management/page/product/vulnerability-response/task/t_CreateVulnSLA.html
NEW QUESTION # 31
Where can you find Information related to the Common Vulnerabilities and Exposures (CVE)?
- A. Qualys
- B. Tenable
- C. NIST
- D. MITRE
Answer: D
NEW QUESTION # 32
Where in the platform can you create Filter Groups?
- A. Security Operations > Groups > Filter Groups
- B. Security Operations > Administration > Filter Groups
- C. Vulnerability > Groups > Filter Groups
- D. Vulnerability > Administration > Filter Groups
Answer: A
Explanation:
https://docs.servicenow.com/en-US/bundle/vancouver-security-management/page/product/security-operations-common/task/create-filter-group.html
NEW QUESTION # 33
......
Free CIS-VR Exam Dumps to Improve Exam Score: https://examcollection.vcetorrent.com/CIS-VR-valid-vce-torrent.html