
Pass CIS-SIR Exam in First Attempt Guaranteed 2021 Dumps!
CIS-SIR Dumps Full Questions - Exam Study Guide
NEW QUESTION 17
This type of integration workflow helps retrieve a list of active network connections from a host or endpoint, so it can be used to enrich incidents during investigation.
- A. Security Incident Response - Get Running Services
- B. Security Incident Response - Get Network Statistics
- C. Security Operations Integration - Block Request
- D. Security Operations Integration - Sightings Search
Answer: B
NEW QUESTION 18
What parts of the Security Incident Response lifecycle is responsible for limiting the impact of a security incident?
- A. Preparation and Identification
- B. Detection & Analysis
- C. Containment, Eradication, and Recovery
- D. Post Incident Activity
Answer: C
Explanation:
Explanation/Reference: https://searchsecurity.techtarget.com/definition/incident-response
NEW QUESTION 19
For Customers who don't use 3rd-party systems, what ways can security incidents be created? (Choose three.)
- A. Security Incident Form
- B. Inbound Email Parsing Rules
- C. Security Service Catalog
- D. Alert Management
- E. Leveraging an Integration
Answer: A,B,C
NEW QUESTION 20
What are two of the audiences identified that will need reports and insight into Security Incident Response reports? (Choose two.)
- A. Vulnerability Managers
- B. Problem Managers
- C. Chief Information Security Officer (CISO)
- D. Analysts
Answer: A,D
NEW QUESTION 21
How do you select which process definition to use?
- A. By setting the Script Include record to Active
- B. By selecting the desired process within the Process Selection module
- C. By setting the process definition record to Active
- D. By selecting the desired process within the Process Definition module
Answer: B
NEW QUESTION 22
The benefits of improved Security Incident Response are expressed __________.
- A. differently depending upon 3 stages: Process Improvement, Process Design, and Post Go-Live
- B. as a value on a scale of 1-10 based on specific outcomes
- C. as a series of states with consistent, clear metrics
- D. as desirable outcomes with clear, measurable Key Performance Indicators
Answer: C
NEW QUESTION 23
The following term is used to describe any observable occurrence:.
- A. Alert
- B. Log
- C. Incident
- D. Ticket
- E. Event
Answer: E
NEW QUESTION 24
The following term is used to describe any observable occurrence: __________.
- A. Alert
- B. Log
- C. Incident
- D. Ticket
- E. Event
Answer: E
NEW QUESTION 25
Why should discussions focus with the end in mind?
- A. To understand current posture
- B. To understand required tools
- C. To understand customer's process
- D. To understand desired outcomes
Answer: D
NEW QUESTION 26
To configure Security Incident Escalations, you need the following role(s):.
- A. sn_si.admin or sn_si.manager
- B. sn_si.admin or sn_si.ciso
- C. sn_si.admin
- D. sn_si.manager or sn_si.analyst
Answer: C
NEW QUESTION 27
If the customer's email server currently has an account setup to report suspicious emails, then what happens next?
- A. an integration added to Exchange keeps the ServiceNow platform in sync
- B. the ServiceNow platform ensures that parsing and analysis takes place on their mail server
- C. the customer's systems are already handling suspicious emails
- D. the customer should set up a rule to forward these mails onto the ServiceNow platform
Answer: D
NEW QUESTION 28
What role(s) are required to add new items to the Security Incident Catalog?
- A. requires the sn_si.admin role
- B. requires the admin role
- C. requires both sn_si.write and catalog_admin roles
- D. requires the sn_si.catalog role
Answer: B
NEW QUESTION 29
The Risk Score is calculated by combining all the weights using __________.
- A. a geometric mean
- B. an arithmetic mean
- C. addition
- D. the Risk Score script include
Answer: B
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident- response/reference/setup-assistant-reference.html
NEW QUESTION 30
Which improvement opportunity can be found baseline which can contribute towards process maturity and strengthen costumer's overall security posture?
- A. Incident Analysis
- B. Incident Containment
- C. Post-Incident Review
- D. Fast Eradication
Answer: A
NEW QUESTION 31
What does a flow require?
- A. A trigger
- B. Security orchestration flows
- C. Runbooks
- D. CAB orders
Answer: A
NEW QUESTION 32
Which one of the following users is automatically added to the Request Assessments list?
- A. The Affected User on the incident
- B. Any user that adds a worknote to the ticket
- C. The analyst assigned to the ticket
- D. Any user who has Response Tasks on the incident
Answer: D
NEW QUESTION 33
A Post Incident Review can contain which of the following? (Choose three.)
- A. Attachments associated with the security incident
- B. An audit trail
- C. Performance Analytics reports
- D. Key incident fields
- E. Post incident question:naires
Answer: B,D,E
NEW QUESTION 34
Which Table would be commonly used for Security Incident Response?
- A. sysapproval_approver
- B. sn_si_incident
- C. sec_ops_incident
- D. cmdb_rel_ci
Answer: B
Explanation:
Explanation/Reference: https://docs.servicenow.com/bundle/quebec-security-management/page/product/security- incident-response/reference/installed-with-sir.html
NEW QUESTION 35
Which of the following State Flows are provided for Security Incidents? (Choose three.)
- A. NIST Stateful
- B. SANS Stateful
- C. SANS Open
- D. NIST Open
Answer: A,B,D
NEW QUESTION 36
What is the key to a successful implementation?
- A. Building custom integrations
- B. Implementing everything that we offer
- C. Understanding the customer's goals and objectives
- D. Sell customer the most expensive package
Answer: C
NEW QUESTION 37
What is the name of the Inbound Action that validates whether an inbound email should be processed as a phishing email for URP v2?
- A. Create Phishing Email
- B. User Reporting Phishing (for Forwarded emails)
- C. Scan email for threats
- D. User Reporting Phishing (for New emails)
Answer: B
NEW QUESTION 38
What field is used to distinguish Security events from other IT events?
- A. Source
- B. Classification
- C. Type
- D. Description
Answer: B
NEW QUESTION 39
Joe is on the SIR Team and needs to be able to configure Territories and Skills. What role does he need?
- A. Security Analyst
- B. Security Admin
- C. Manager
- D. Security Basic
Answer: B
NEW QUESTION 40
......
Certified Implementation Specialist Free Certification Exam Material from SureTorrent with 62 Questions: https://www.suretorrent.com/CIS-SIR-exam-guide-torrent.html