ServiceNow CSA Exam Questions

Questions for the CSA were updated on : Dec 12 ,2025

Page 1 out of 34. Viewing questions 1-15 out of 500

Question 1

What encryption feature is included in ServiceNow by default?

  • A. Data in use
  • B. Data in transit
  • C. Data at rest
Answer:

B

User Votes:
A
50%
B
50%
C
50%

Explanation:
By default, ServiceNow encrypts data in transit using industry-standard Transport Layer Security (TLS)
protocols. This ensures that any data transmitted between the client and the ServiceNow platform,
or between ServiceNow and integrated systems, is encrypted and protected from interception or
tampering.
While ServiceNow also offers options for data at rest encryption and customer-managed encryption
keys, these features often require additional configuration or subscription services. Encryption of
data in use (while data is being processed in memory) is a more advanced concept and not provided
by default.
Thus, encryption of data in transit is the baseline encryption feature included automatically in all
ServiceNow instances.
Reference:
ServiceNow Security Operations Documentation, Encryption section
ServiceNow Trust and Compliance Documentation
ServiceNow System Administrator Study Guide, Security Chapter
ServiceNow Docs: Security and Encryption

Discussions
vote your answer:
A
B
C
0 / 1000

Question 2

An Administrator wants to display a reminder message to any user submitting an incident. Which
feature does this?

  • A. Client Script
  • B. Business Rule
  • C. Policy
  • D. Data Policy
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
To display reminder messages or alerts to users as they interact with forms in ServiceNow, Client
Scripts are used. Specifically, an onSubmit Client Script can be configured to display a message or
perform validation just before the form is submitted by the user. This script runs on the client
(browser) and can prevent submission or prompt the user with informational messages.
Business Rules execute on the server and cannot directly interact with the user interface in real-time.
Policies and Data Policies enforce data consistency but do not provide user messages or reminders
during form submission.
Therefore, the Client Script is the correct mechanism to display a reminder message dynamically as
the incident is submitted.
Reference:
ServiceNow System Administrator Study Guide, Client Scripts section
ServiceNow Docs: Client Scripts - onSubmit
ServiceNow Docs: Data Policy Overview

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

Which components are the responsibility according to the Shared Responsibility Model?
Choose 2 answers

  • A. Backup and restore
  • B. Media disposal and destruction
  • C. Authentication and authorization
  • D. Infrastructure management
  • E. Data encryption at rest
Answer:

B,D

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

Explanation:
The Shared Responsibility Model in ServiceNow clearly delineates responsibilities between the cloud
service provider (ServiceNow) and the customer. ServiceNow manages the infrastructure, including
the physical data centers, networking, hardware, and media disposal and destruction, ensuring
proper security of the underlying platform. Hence, Media disposal and destruction and Infrastructure
management fall under the provider’s responsibility.
The customer is responsible for their data, including backup and restore, access management
(authentication and authorization), and encryption configuration on their data. While ServiceNow
provides encryption capabilities, the customer must configure and manage encryption keys and
access controls.
This model is critical for maintaining security and compliance in cloud environments and is explicitly
detailed in ServiceNow’s official documentation and cloud security best practices.
Reference:
ServiceNow Trust and Security Documentation, Shared Responsibility Model section
ServiceNow System Administrator Study Guide, Cloud Security Chapter
ServiceNow Docs: Shared Responsibility Model

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 4

Which statement correctly describes the differences between a Client Script and a Business Rule?

  • A. A Client Script executes on the server and a Business Rule executes on the client
  • B. A Client Script executes before a record is loaded and a Business Rule executes after a record is loaded
  • C. A Client Script executes on the client and a Business Rule executes on the server
  • D. A Client Script executes before a record is loaded and a Business Rule executes after a record is updated
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
The fundamental difference between a Client Script and a Business Rule in ServiceNow lies in where
they execute and when. A Client Script runs on the client side — that is, in the user's browser — and
is primarily used to control UI behavior, validate data before submission, and enhance user
interaction with forms. Client Scripts can run at different stages (onLoad, onChange, onSubmit), but
they always execute within the browser environment.
A Business Rule, on the other hand, runs on the server side and executes when records are inserted,
updated, deleted, or queried in the database. Business Rules are used for enforcing data integrity,
automating server-side logic, and integrating with other systems. They can be set to run before or
after a database action (before insert, after update, etc.).
Therefore, the correct statement is that Client Scripts execute on the client and Business Rules
execute on the server.
Reference:
ServiceNow System Administrator Study Guide, Client Scripts and Business Rules chapter
ServiceNow Docs: Client Scripts
ServiceNow Docs: Business Rules

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

An Administrator wants to review all the users having privileged access to identify users that no
longer need this level of access. Which Security Center feature can help fulfill this requirement?

  • A. Security hardening
  • B. Security posture console
  • C. Security scanner
  • D. Customer actions
Answer:

D

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
The Customer Actions feature in the Security Center allows administrators to take targeted actions
such as reviewing privileged user access and managing accounts that might pose a risk. It is
specifically designed to enable organizations to identify and remediate risks associated with user
privileges, such as excessive access rights or orphaned privileged accounts. This feature aggregates
risk data and prompts action items, allowing administrators to review, approve, or revoke privileged
access based on current organizational policies.
While Security Hardening focuses on platform configurations and the Security Posture Console
provides an overview of security metrics and trends, Customer Actions is the practical tool for
directly managing and reviewing privileged access to ensure least privilege principles are enforced.
Reference:
ServiceNow Security Operations Product Documentation, Security Center > Customer Actions
ServiceNow System Administrator Study Guide, Security Operations Chapter
ServiceNow Docs: Customer Actions

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

Which Security Center feature helps resolve platform-related security issues and misconfigurations?

  • A. Security scanner
  • B. Best practices
  • C. Security hardening
  • D. Customer actions
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Explanation:
The Security Hardening feature in the ServiceNow Security Operations Security Center is specifically
designed to help identify, resolve, and mitigate platform-related security issues and
misconfigurations. Security hardening provides prescriptive guidance on improving your platform’s
security posture by addressing vulnerabilities and ensuring compliance with security best practices. It
includes automated checks and recommendations related to system configurations, access controls,
and other settings that, if left unchecked, could expose the system to threats.
The Security Center’s Security Hardening dashboard aggregates these findings and allows
administrators to track remediation progress effectively. Unlike the Security Scanner, which focuses
more on vulnerability scanning of integrated systems, or Customer Actions, which involves manual
customer intervention for specific issues, Security Hardening is the proactive tool ServiceNow
provides to manage platform security risks internally.
Reference:
ServiceNow System Administrator Study Guide, Security Operations Chapter
ServiceNow Product Documentation, Security Operations > Security Center > Security Hardening
ServiceNow Docs: Security Hardening

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

Which one of the following is true for a table with the "Allow configuration" Application Access
option selected?

  • A. Out of scope applications can create Business Rules for the table
  • B. Only the in scope applications scripts can create Business Rules for the table
  • C. Out of scope applications can add new tables to the scoped application
  • D. Any user with the application's user role can modify the application's scripts
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

Which of the following methods prints a message on a blue background to the top of the current
form by default?

  • A. g_form.addlnfoMsg()
  • B. g_form.addlnfoMessage()
  • C. g_form.showFieldMsg()
  • D. g_form.showFieldMessage()
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 9

When evaluating Access Controls, ServiceNow searches and evaluates:

  • A. From the most generic match to the most specific match
  • B. From the most specific match to the most generic match
  • C. Only for matches on the current field
  • D. Only for matches on the current table
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

Which one of the following is true for a Script Include with a Protection Policy value of Protected?

  • A. The Protection Policy is applied only if the application is downloaded from the ServiceNow App Store
  • B. Any user with the protected_edit role can see and edit the Script include
  • C. The Protection policy option can only be enabled by a user with the admin role
  • D. The Protection Policy is applied only if the glide.app.apply.protection system property value is true
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11

Which objects can you use in a Scheduled Script Execution (Scheduled Job) script?

  • A. GlideUser and GlideRecord
  • B. GlideSystem and GlideRecord
  • C. GlideSystem and current
  • D. GlideRecord and current
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

Which are reasons an application could be developed on the ServiceNow platform?
Choose 3 answers

  • A. It squires low-level programming libraries.
  • B. It needs workflow to manage processes.
  • C. It requires reporting capabilities.
  • D. It uses forms extensively to interact with data.
  • E. it uses multimedia features.
Answer:

A,C,D

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 13

Which one of the following is the fastest way to create and configure a Record Producer?

  • A. use the Record Producer module then add and configure all variables manually
  • B. Open the table in the Table record and select the Add to Service Catalog Related Link
  • C. Create a Catalog Category, open the category, and select the Add New Record Producer button
  • D. Open the table's form, right-click on the form header, and select the Create Record Producer menu item
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%

Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

In a privately-scoped application, which methods are used for logging messages in server-side
scripts?
Choose 2 answers

  • A. gs.debug()
  • B. gs.message()
  • C. gs.logError()
  • D. gs.error()
  • E. gs.log()
Answer:

C,D

User Votes:
A
50%
B
50%
C
50%
D
50%
E
50%

Discussions
vote your answer:
A
B
C
D
E
0 / 1000

Question 15

What is the GlideForm Client-side scripting object?

  • B. sn.form
  • C. gs.form
  • D. g_form
Answer:

D

User Votes:
B
50%
C
50%
D
50%

Discussions
vote your answer:
B
C
D
0 / 1000
To page 2