Skip to content

Automating Vulnerability Response Questions

Practice questions for Automating Vulnerability Response topic in Certified Implementation Specialist - Vulnerability Response. 40 questions covering this domain.

40 questions8 easy22 medium10 hard
Q1
easy

Which documented mechanism is used when a finding or remediation task cannot be remediated immediately and needs approved deferral?

Q2
medium

Which automation stops matching detections from being converted into vulnerable items during ingestion?

Q3
medium

Which approval-rule capabilities are documented for exception management?

Q4
medium

If a false positive request is approved, how is the record closed?

Q5
easy

A scanner reports an issue on a decommissioned CI that is not actually vulnerable. How does ServiceNow classify that request type?

Q6
medium

A team member raises a false positive request from an open remediation task. What state change is documented at request time?

Q7
medium

What happens immediately after an exception request is raised from a vulnerable item or remediation task?

Q8
medium

What happens if a false positive request is not approved?

Q9
hard

How does an approved exception rule differ from a one-off approved exception request?

Q10
hard

Which pair names the documented bases for auto-closing stale detections?

Q11
medium

What is the documented outcome when an exception request is not approved?

Q12
easy

Which documented feature is used when a valid finding cannot be remediated right away and needs approval to defer work?

Q13
medium

Which automation can prevent matching detections from turning into vulnerable items during ingestion?

Q14
hard

What extra automation occurs when an exception rule, not just a one-off exception, is approved?

Q15
medium

In a time-bound false positive case, who sets the end date according to the official behavior?

Q16
medium

If a false positive request is denied, what happens next to the record?

Q17
easy

A scanner flags a condition on a device that has already been decommissioned, so there is no real vulnerability. What is the documented classification...

Q18
hard

Which optional behavior can be enabled for auto-close stale detections?

Q19
hard

Which pair names the primary bases ServiceNow documents for auto-closing stale detections?

Q20
medium

What happens when an exception request is submitted from a vulnerable item or remediation task?

Sign in to see all 40 questions

Create a free account to browse all questions — completely free during our launch phase.