CIS-RC — ServiceNow Certified Implementation Specialist – Risk and Compliance
ServiceNow

ServiceNow Certified Implementation Specialist – Risk and Compliance (CIS-RC) Practice Questions

★★★★☆ 4.1 137 verified reviews
160 questions
2026-06-21 updated
✓ Online quiz simulator

Domain coverage

  • GRC Overview (12%)
  • Implementation Planning (5%)
  • Entity Framework (20%)
  • Policy and Compliance (25%)
  • Risk and Advanced Risk (25%)
  • Common Elements & Extended Capabilities (8%)
  • Audit and Advanced Audit (5%)

Sample Questions (16 of 160 shown)

Q1
Which filter navigation syntax displays the table in list view within a separate browser tab?
  1. Tablename_LIST
  2. Tablename.list
  3. Tablename.LIST
  4. Tablename.List
✓ Correct Answer: C
The correct answer is C. Tablename.LIST is correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q2
Which GRC tables serve as primary parent tables for the GRC applications? (Choose three.)
  1. Content
  2. Item
  3. Asset
  4. Task
  5. Document
✓ Correct Answer: A, B, E
The correct answer is ABE. Content and Item and Document are correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q3
Annualized Loss Expectancy is a feature of which risk score method?
  1. Residual
  2. Quantitative
  3. Qualitative
  4. Inherent
✓ Correct Answer: B
The correct answer is B. Quantitative is correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q4
What are some of the features of scoped applications for GRC? (Choose three.)
  1. Requires an entitlement for all environments
  2. All components have a namespace prefix for identification
  3. Provides access to all global data
  4. Ability to view all components from the sys_metadata table
  5. Ability to restrict access to available data
✓ Correct Answer: A, B, E
The correct answer is ABE. these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q5
Which of the following tables exist within the GRC: Profiles application scope? (Choose three.)
  1. sn_grc_profile_type
  2. sn_grc_indicator
  3. sn_grc_compliance_policy_statement
  4. sn_grc_risk_definition
  5. sn_grc_profile_class
✓ Correct Answer: A, B, E
The correct answer is ABE. sn_grc_profile_type and sn_grc_indicator and sn_grc_profile_class are correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q6
An external audit team needs to view all of your published policies and controls? Which role can you give the team members?
  1. sn_audit_manager
  2. sn_compliance_user
  3. sn_audit.external_auditor
  4. sn_risk_user
✓ Correct Answer: C
The correct answer is C. sn_audit.external_auditor is correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q7
Which feature of classic risk scoring is frequently configured by customers?
  1. Annualized Loss Expectancy
  2. Risk Criteria Matrix
  3. Control Failure Factor
  4. Indicator Failure Factor
✓ Correct Answer: B
The correct answer is B. Risk Criteria Matrix is correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q8
Which of the following are scoped applications related to the Risk and Compliance applications? (Choose four.)
  1. GRC: GRC Profiles
  2. GRC: Attestation Design
  3. GRC: UCF Compliance
  4. GRC: Policy and Compliance
  5. GRC: Performance Analytics
  6. GRC: Risk Management
✓ Correct Answer: A, C, D, F
The correct answer is ACDF. GRC: GRC Profiles and GRC: UCF Compliance and GRC: Policy and Compliance and GRC: Risk Management are correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q9
The Single Loss Expectancy is $1.000.000 and the Annual Rate of Occurrence is 20%. What is the Annualized Loss Expectancy?
  1. $1,000,000
  2. $200,000
  3. $2,000,000
  4. $10,000
✓ Correct Answer: B
The correct answer is B. $200,000 is correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q10
What are key prerequisites for a control test task to be generated?
  1. Engagement is Scope
  2. Risks have associated assessments
  3. Entity being scoped has associated controls with test plans
  4. Controls have a set frequency
  5. Entity being scoped has associated risks
✓ Correct Answer: C
The correct answer is C. Entity being scoped has associated controls with test plans is correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q11
Who should be directly involved in GRC implementations? (Choose three.)
  1. Board of directors
  2. Chief Executive
  3. ServiceNow platform experts
  4. HR analysts
  5. Risk and compliance experts
  6. CMDB process owner
✓ Correct Answer: C, E, F
The correct answer is CEF. ServiceNow platform experts and Risk and compliance experts and CMDB process owner are correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q12
Which Script include can be modified to change how the compliance scores roll up?
  1. ScoreRollUp
  2. ComplianceUtils
  3. ComplianceScoreCalculator
  4. AssessmentStrategy
✓ Correct Answer: C
The correct answer is C. ComplianceScoreCalculator is correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q13
What is the minimum role required to approve a Policy?
  1. sn_grc admin
  2. sn_compliance manager
  3. sn_compliance user
  4. sn_grc user
✓ Correct Answer: C
The correct answer is C. sn_compliance user is correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q14
Which roles can move the control to the ‘Monitor’ state manually? (Choose two.)
  1. Compliance Reader
  2. Risk User
  3. Audit User
  4. System Administrator
  5. Compliance Manager
✓ Correct Answer: D, E
The correct answer is DE. System Administrator and Compliance Manager are correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q15
All of the following are tables which exist within the GRC Profiles application scope EXCEPT:
  1. sn_grc_profile
  2. sn_grc_item
  3. sn_grc_profile_type
  4. sn_grc_risk
✓ Correct Answer: D
The correct answer is D. sn_grc_risk is correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.
Q16
Which of the following tables are included in the GRC: Policy and Compliance Management scoped application? (Choose three.)
  1. sn_compliance_risk
  2. sn_compliance_policy
  3. sn_grc_item
  4. sn_compliance_policy_statement
  5. sn_grc_m2m_audience_user
  6. sn_grc_entity_type G. sn_compliance_citation
✓ Correct Answer: B, D, G
The correct answer is BDG. sn_compliance_policy and sn_compliance_policy_statement are correct because these concepts relate to GRC positioning, terminology, and technical overview of the GRC framework.

You've viewed 3 of 160 questions. Start the free practice exam to answer all questions with instant feedback.

Exam overview

Built for risk and compliance managers, GRC leads, and IRM implementers, the ServiceNow Certified Implementation Specialist – Risk and Compliance (CIS-RC) credential certifies your ability to implement and operate the Integrated Risk Management (IRM) application on the Now Platform. Scheduled and delivered through ServiceNow University via Pearson VUE (registration executed inside Now Learning via SSO), the exam voucher costs $450 USD with no publicly disclosed passing score, 45 scored questions in 130 minutes, and no partial credit on multiple-select items.

Before purchasing the voucher, candidates must complete the GRC: Integrated Risk Management (IRM) Fundamentals course and the GRC: Integrated Risk Management (IRM) Implementation course on Now Learning — finishing the Implementation course explicitly unlocks the voucher acquisition field in your portal. ServiceNow also recommends holding the CSA credential, completing the baseline Welcome to ServiceNow and Platform Implementation courses, and having at least six months of hands-on GRC/IRM deployment experience across a minimum of two full implementation lifecycles.

The CIS-RC blueprint is organized into seven weighted domains, with the heaviest emphasis on Policy and Compliance (25%) and Risk and Advanced Risk (25%), which together account for half the exam score. The remaining weight splits across Entity Framework (20%), GRC Overview (12%), Common Elements and Extended Capabilities (8%), Implementation Planning (5%), and Audit and Advanced Audit (5%). Because the exam uses multiple-select items with no partial credit, scenario questions on the Compliance Hierarchy (Authority Documents → Citations → Policies → Control Objectives), Advanced Risk Assessment (ARA) with Risk Assessment Methodologies (RAM), and Inherent, Residual, and Calculated Risk computations are heavily tested.

For candidates preparing for the CIS-RC exam, our practice materials cover all seven weighted domains in the same proportions as the real test, with online practice questions, detailed answer explanations, and a downloadable PDF that mirrors the single-select and multiple-select format you will see on exam day.

Official Exam Domains & Weighting

To successfully pass the CIS-RC exam, candidates must master the following core domains:
  • Domain 1: GRC Overview (12%)
Covers GRC positioning, scope, architectural mapping, and business frameworks, plus the relationships between Scoped Applications (Profiles, Risk, Compliance) and the Global tier.
  • Domain 2: Implementation Planning (5%)
Tests use cases, architectural baseline scoping, implementation team sizing, and platform Personas, Groups, and granular Security Roles such as Admin, Manager, and User.
  • Domain 3: Entity Framework (20%)
Validates Entity Scoping Strategies including the difference between Entity Types and Entity Classes, Entity Generation Engines, Filter Conditions, and Entity structural lifecycles.
  • Domain 4: Policy and Compliance (25%)
Focuses on the Compliance Hierarchy with rigid linkages between Authority Documents, Citations, Policies, and Control Objectives, the Control Lifecycle States (Draft, Attest, Review, Monitor), Attestation configuration, and Compliance Supporting Workflows including Evidence Collection automation, Attestation templates, and Policy Acknowledgment tracking.
  • Domain 5: Risk and Advanced Risk (25%)
Covers Risk Statement mapping to active Operational Risks, Advanced Risk Assessment (ARA) with Risk Assessment Methodologies (RAM), Assessment Factors (Manual vs. Automated), and scoring matrices, Risk Calculation engines handling Inherent, Residual, and Calculated Risk, and Risk Response mechanisms such as Accept, Mitigate, Transfer, and Avoid.
  • Domain 6: Common Elements & Extended Capabilities (8%)
Tests continuous monitoring via GRC Indicators, the Issues Management Engine with Issue tracking, lifecycle statuses, Remediation Tasks, and Exception rules, plus Regulatory Change Management (RCM) workflows and native Content Packs.
  • Domain 7: Audit and Advanced Audit (5%)
Validates the Audit Lifecycle Management with Audit Plans, Audit Engagements, Audit Tasks, and Workpapers, plus Evidence Management frameworks for seamless control validation with auditors.

What Our Customers Say 137 verified reviews

4.1 ★★★★☆ Based on 137 reviews
★★★★★★
Used the CIS-RC test bank for two weeks before my exam date. Felt very prepared going in and the results showed.
— Luke M.
★★★★★★
I scored 890 on the CIS-RC exam. Went through about 80% of this question bank and it was more than enough to pass.
— Levi C.
★★★★★★
Quick shipping? LOL jk — instant access was great. Started studying CIS-RC questions right after purchase, no delays.
— Colton W.
★★★★★★
I studied for CIS-RC with this bank and passed comfortably. The questions are well-organized and the UI is clean.
— Lauren C.
★★★★★
Passed CIS-RC with 912/1000. The practice questions cover the exam objectives thoroughly and the explanations are clear.
— Ella M.
★★★★★★
I liked that the CIS-RC questions update regularly. Felt current and aligned with what I actually saw on the test.
— Dylan P.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

No. If you Pass, your final terminal UI will simply read Pass with zero supplementary score strings or section breakdowns. ServiceNow treats a passing attempt as a binary verification of competence. However, if you Fail, you will receive a diagnostic breakdown displaying your exact percentage performance across all 7 blueprint domains to guide your remediation study plan.

All immediate results delivered on-screen at test submission are preliminary and flagged as conditional. ServiceNow's security and credentialing team subjects all testing logs to a background audit check, flagging biometric discrepancies, sudden disconnects, or anomalous progression times. Your formal credential and Credly badge sync to your account within 24 to 48 hours once verified.

You do not need to sit for the full 45-question proctored exam ever again, provided you complete your Delta Exam cycles. Every time ServiceNow releases a major platform update, a micro, non-proctored, open-book Delta test of 5-10 questions appears inside Now Learning. Failing to pass these within the designated multi-month window will cause your mainline certification to expire immediately.

Vastly. With modern releases, ServiceNow has made Advanced Risk Assessment (ARA) the cornerstone of the Risk domain. You must thoroughly study the laboratory configurations for RAMs (Risk Assessment Methodologies), assessment factors (Manual vs. Automated), and calculation equations for Inherent, Residual, and Calculated Risk. Shallow conceptual knowledge will result in failing this domain — the exam presents scenario questions that require you to trace the full scoring matrix from a RAM through to the risk response decision.

The mock exam scenarios target the same ARA mechanics the real exam tests — RAM configuration, assessment factor selection (Manual vs. Automated), the Inherent/Residual/Calculated Risk computation chain, and the Accept/Mitigate/Transfer/Avoid response linkage. Each scenario presents a risk assessment setup, asks which calculation outcome applies, and walks through the full scoring matrix step by step in the answer explanation.

The PDF download is most useful when you want to trace the Compliance Hierarchy offline — Authority Documents linking to Citations, Citations to Policies, Policies to Control Objectives, through the Control Lifecycle States (Draft, Attest, Review, Monitor). The mock exam scenarios cover the same hierarchy linkages in interactive format for timed practice, while the PDF lets you study the rigid four-layer structure on paper during commutes or in environments without stable internet.

You must complete the GRC: Integrated Risk Management (IRM) Fundamentals and the GRC: Integrated Risk Management (IRM) Implementation courses on Now Learning — the Implementation course is what unlocks the voucher acquisition field. ServiceNow also recommends holding the CSA credential, completing the baseline Welcome to ServiceNow, ServiceNow Platform Implementation, and Now Create Methodologies courses, and having at least six months of hands-on GRC/IRM deployment experience across a minimum of two full implementation lifecycles.