PE PowerExams Prepare. Practice. Pass.
CIS-RC · Domain 7 of 7

Audit Management Implementation

About 5% of the CIS-RC exam — see all 7 domains.

5%
of the exam
15
practice questions
7
domains total

Audit Management plans and executes internal/external audits leveraging the same scoped entities and controls.

Key objects:

  • Engagement — the audit project/scope (advanced planning lets you scope by entities, risks, controls).
  • Audit Plan / Audit Universe — what could be audited and the planned schedule.
  • Audit tasks / fieldwork — execution steps and working papers / evidence.
  • Findings / Issues — results of testing, routed to remediation.
  • Risk-based auditing — audits draw on the risk register and control test results so audit, risk, and compliance reuse the same data.

Exam gotcha: Audit reuses GRC controls, profiles/entities, and indicators — it does not maintain a separate parallel control universe.


Sample questions from this domain

Three of the 15 in this domain, with the reasoning. The full set is in the question bank.

Question 1 · easy

What is the primary purpose of Audit Management in ServiceNow GRC?

  • A. To replace the risk register
  • B. To plan, scope, execute, and report on internal audit engagements
  • C. To configure the CMDB
  • D. To store authority documents only

Why: Audit Management plans, scopes, executes, and reports on audit engagements. It does not merely store authority documents, replace the risk register, or configure the CMDB.

Question 2 · medium

In Audit Management, what is an engagement?

  • A. A type of authority document
  • B. A risk statement
  • C. A profile type
  • D. A defined audit project with scope, schedule, and tasks to evaluate controls/areas

Why: An engagement is a defined audit project with scope, schedule, and tasks. It is not an authority document, a risk statement, or a profile type.

Question 3 · medium

How does Audit Management leverage the shared GRC framework when scoping an engagement?

  • A. It can scope to entities/profiles and reference existing controls and risks rather than recreating them
  • B. It cannot reference profiles
  • C. It only works on incidents
  • D. It must create entirely new controls unrelated to Policy and Compliance

Why: Audit engagements can scope to entities/profiles and reuse existing controls and risks. They do not require recreating controls, can reference profiles, and are not limited to incidents.