ServiceNow
CIS-SIR
Q1:
Which of the following fields is used to identify an Event that is to be used for Security purposes?
○
A
IT○
B
Classification○
C
Security○
D
CI
ServiceNow
CIS-SIR
Q2:
David is on the Network team and has been assigned a security incident response task. What role does he need to be able to view and work the task?
○
A
Security Analyst○
B
Security Basic○
C
External○
D
Read
ServiceNow
CIS-SIR
Q3:
Which of the following tag classifications are provided baseline? (Choose three.)
☐
A
Traffic Light Protocol☐
B
Block from Sharing☐
C
IoC Type☐
D
Severity☐
E
Cyber Kill Chain Step☐
F
Escalation Level☐
G
Enrichment whitelist/blacklist
ServiceNow
CIS-SIR
Q4:
Which of the following process definitions are not provided baseline?
○
A
NIST Open○
B
SAN Stateful○
C
NIST Stateful○
D
SANS Open
ServiceNow
CIS-SIR
Q5:
The EmailUserReportedPhishing script include processes inbound emails and creates a record in which table?
○
A
ar_sn_si_phishing_email○
B
sn_si_incident○
C
sn_si_phishing_email_header○
D
sn_si_phishing_email