Questions for the CIS-SIR were updated on : Dec 01 ,2025
Security tag used when a piece of information requires support to be effectively acted upon, yet
carries risks to privacy, reputation, or operations if shared outside of the organizations involved.
A. TLP:GREEN
B. TLP:AMBER
C. TLP:RED
D. TLP:WHITE
B

A Post Incident Review can contain which of the following? (Choose three.)
ABD
Which one of the following reasons best describes why roles for Security Incident Response (SIR)
begin with "sn_si"?
B
Which of the following is an action provided by the Security Incident Response application?
D
What specific role is required in order to use the REST API Explorer?
AC
Reference: https://developer.servicenow.com/dev.do#!/learn/learning-plans/orlando/
technology_partner_program/app_store_learnv2_rest_orlando_introduction_to_the_rest_api_explo
rer
What field is used to distinguish Security events from other IT events?
C
Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-incident-response/concept/c_ScIncdUseAlrts.html
Which of the following fields is used to identify an Event that is to be used for Security purposes?
B
Reference: https://docs.servicenow.com/bundle/paris-it-operations-management/page/product/event-management/task/t_EMManageEvent.html
When a service desk agent uses the Create Security Incident UI action from a regular incident, what
occurs?
A
David is on the Network team and has been assigned a security incident response task. What role
does he need to be able to view and work the task?
A
Which of the following tag classifications are provided baseline? (Choose three.)
ACG
Reference: https://docs.servicenow.com/bundle/paris-security-management/page/product/security-operations-common/task/create-class-group-and-tags.html
Which of the following process definitions are not provided baseline?
A
A flow consists of
. (Choose two.)
BE
Reference: https://docs.servicenow.com/bundle/paris-servicenow-platform/page/administer/flow-designer/concept/flows.html
The EmailUserReportedPhishing script include processes inbound emails and creates a record in
which table?
A
Using the KB articles for Playbooks tasks also gives you which of these advantages?
C
Why is it important that the Platform (System) Administrator and the Security Incident administrator
role be separated? (Choose three.)
BCD