Pass CIS-SIR Exam in First Attempt Guaranteed 2021 Dumps! [Q17-Q40]

Share

Pass CIS-SIR Exam in First Attempt Guaranteed 2021 Dumps!

CIS-SIR Dumps Full Questions - Exam Study Guide

NEW QUESTION 17
This type of integration workflow helps retrieve a list of active network connections from a host or endpoint, so it can be used to enrich incidents during investigation.

  • A. Security Incident Response - Get Running Services
  • B. Security Incident Response - Get Network Statistics
  • C. Security Operations Integration - Block Request
  • D. Security Operations Integration - Sightings Search

Answer: B

 

NEW QUESTION 18
What parts of the Security Incident Response lifecycle is responsible for limiting the impact of a security incident?

  • A. Preparation and Identification
  • B. Detection & Analysis
  • C. Containment, Eradication, and Recovery
  • D. Post Incident Activity

Answer: C

Explanation:
Explanation/Reference: https://searchsecurity.techtarget.com/definition/incident-response

 

NEW QUESTION 19
For Customers who don't use 3rd-party systems, what ways can security incidents be created? (Choose three.)

  • A. Security Incident Form
  • B. Inbound Email Parsing Rules
  • C. Security Service Catalog
  • D. Alert Management
  • E. Leveraging an Integration

Answer: A,B,C

 

NEW QUESTION 20
What are two of the audiences identified that will need reports and insight into Security Incident Response reports? (Choose two.)

  • A. Vulnerability Managers
  • B. Problem Managers
  • C. Chief Information Security Officer (CISO)
  • D. Analysts

Answer: A,D

 

NEW QUESTION 21
How do you select which process definition to use?

  • A. By setting the Script Include record to Active
  • B. By selecting the desired process within the Process Selection module
  • C. By setting the process definition record to Active
  • D. By selecting the desired process within the Process Definition module

Answer: B

 

NEW QUESTION 22
The benefits of improved Security Incident Response are expressed __________.

  • A. differently depending upon 3 stages: Process Improvement, Process Design, and Post Go-Live
  • B. as a value on a scale of 1-10 based on specific outcomes
  • C. as a series of states with consistent, clear metrics
  • D. as desirable outcomes with clear, measurable Key Performance Indicators

Answer: C

 

NEW QUESTION 23
The following term is used to describe any observable occurrence:.

  • A. Alert
  • B. Log
  • C. Incident
  • D. Ticket
  • E. Event

Answer: E

 

NEW QUESTION 24
The following term is used to describe any observable occurrence: __________.

  • A. Alert
  • B. Log
  • C. Incident
  • D. Ticket
  • E. Event

Answer: E

 

NEW QUESTION 25
Why should discussions focus with the end in mind?

  • A. To understand current posture
  • B. To understand required tools
  • C. To understand customer's process
  • D. To understand desired outcomes

Answer: D

 

NEW QUESTION 26
To configure Security Incident Escalations, you need the following role(s):.

  • A. sn_si.admin or sn_si.manager
  • B. sn_si.admin or sn_si.ciso
  • C. sn_si.admin
  • D. sn_si.manager or sn_si.analyst

Answer: C

 

NEW QUESTION 27
If the customer's email server currently has an account setup to report suspicious emails, then what happens next?

  • A. an integration added to Exchange keeps the ServiceNow platform in sync
  • B. the ServiceNow platform ensures that parsing and analysis takes place on their mail server
  • C. the customer's systems are already handling suspicious emails
  • D. the customer should set up a rule to forward these mails onto the ServiceNow platform

Answer: D

 

NEW QUESTION 28
What role(s) are required to add new items to the Security Incident Catalog?

  • A. requires the sn_si.admin role
  • B. requires the admin role
  • C. requires both sn_si.write and catalog_admin roles
  • D. requires the sn_si.catalog role

Answer: B

 

NEW QUESTION 29
The Risk Score is calculated by combining all the weights using __________.

  • A. a geometric mean
  • B. an arithmetic mean
  • C. addition
  • D. the Risk Score script include

Answer: B

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/reference/setup-assistant-reference.html

 

NEW QUESTION 30
Which improvement opportunity can be found baseline which can contribute towards process maturity and strengthen costumer's overall security posture?

  • A. Incident Analysis
  • B. Incident Containment
  • C. Post-Incident Review
  • D. Fast Eradication

Answer: A

 

NEW QUESTION 31
What does a flow require?

  • A. A trigger
  • B. Security orchestration flows
  • C. Runbooks
  • D. CAB orders

Answer: A

 

NEW QUESTION 32
Which one of the following users is automatically added to the Request Assessments list?

  • A. The Affected User on the incident
  • B. Any user that adds a worknote to the ticket
  • C. The analyst assigned to the ticket
  • D. Any user who has Response Tasks on the incident

Answer: D

 

NEW QUESTION 33
A Post Incident Review can contain which of the following? (Choose three.)

  • A. Attachments associated with the security incident
  • B. An audit trail
  • C. Performance Analytics reports
  • D. Key incident fields
  • E. Post incident question:naires

Answer: B,D,E

 

NEW QUESTION 34
Which Table would be commonly used for Security Incident Response?

  • A. sysapproval_approver
  • B. sn_si_incident
  • C. sec_ops_incident
  • D. cmdb_rel_ci

Answer: B

Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/quebec-security-management/page/product/security- incident-response/reference/installed-with-sir.html

 

NEW QUESTION 35
Which of the following State Flows are provided for Security Incidents? (Choose three.)

  • A. NIST Stateful
  • B. SANS Stateful
  • C. SANS Open
  • D. NIST Open

Answer: A,B,D

 

NEW QUESTION 36
What is the key to a successful implementation?

  • A. Building custom integrations
  • B. Implementing everything that we offer
  • C. Understanding the customer's goals and objectives
  • D. Sell customer the most expensive package

Answer: C

 

NEW QUESTION 37
What is the name of the Inbound Action that validates whether an inbound email should be processed as a phishing email for URP v2?

  • A. Create Phishing Email
  • B. User Reporting Phishing (for Forwarded emails)
  • C. Scan email for threats
  • D. User Reporting Phishing (for New emails)

Answer: B

 

NEW QUESTION 38
What field is used to distinguish Security events from other IT events?

  • A. Source
  • B. Classification
  • C. Type
  • D. Description

Answer: B

 

NEW QUESTION 39
Joe is on the SIR Team and needs to be able to configure Territories and Skills. What role does he need?

  • A. Security Analyst
  • B. Security Admin
  • C. Manager
  • D. Security Basic

Answer: B

 

NEW QUESTION 40
......

Certified Implementation Specialist  Free Certification Exam Material from SureTorrent with 62 Questions: https://www.suretorrent.com/CIS-SIR-exam-guide-torrent.html