PE PowerExams Prepare. Practice. Pass.
CIS-RC · Domain 2 of 7

Implementation Planning

About 10% of the CIS-RC exam — see all 7 domains.

10%
of the exam
30
practice questions
7
domains total

Covers how to scope and deliver an IRM implementation: requirements gathering, identifying which applications (Policy & Compliance, Risk, Audit, Advanced Risk, Vendor Risk) the customer needs, phasing, data sources (CMDB, HR, vendor data) feeding profiles/entities, plugin activation, and roles.

Common roles: GRC Admin, GRC Manager, Risk Manager, Compliance Manager, Audit Manager, plus reader/user roles. Match the role to the application and least-privilege principle.

Now Create / best practices: scope narrowly first, use out-of-box content packs, design the profile/entity model early (it drives everything downstream), and plan integrations (CMDB, identity, ticketing) and reporting (Performance Analytics) up front.


Sample questions from this domain

Three of the 30 in this domain, with the reasoning. The full set is in the question bank.

Question 1 · easy

During GRC implementation planning, what is the recommended first step before configuring entities and profiles?

  • A. Build every risk statement in production
  • B. Define the organization's GRC scope, objectives, and stakeholders
  • C. Delete the out-of-box roles
  • D. Immediately import all available content packs

Why: Successful implementations begin by defining scope, objectives, and stakeholders so configuration aligns to business needs. Importing all content, building directly in production, or deleting baseline roles are premature and risky actions.

Question 2 · medium

Which ServiceNow role is typically required to perform GRC administration and configuration tasks?

  • A. catalog_admin
  • B. knowledge_admin
  • C. sn_grc.admin
  • D. itil

Why: The sn_grc.admin role grants administrative access to the GRC framework for configuration. itil, catalog_admin, and knowledge_admin govern other applications (incident/request, service catalog, knowledge) and do not provide GRC administration.

Question 3 · medium

Which activities belong in the planning/design phase of a GRC implementation? (Choose two)

  • A. Configuring the email server for a different application
  • B. Upgrading unrelated hardware
  • C. Defining the entity types and profile types to be used
  • D. Identifying authority documents and frameworks in scope
  • E. Closing all production incidents

Why: Planning should identify which authority documents/frameworks are in scope and define the entity types and profile types that structure the data model. Closing incidents, configuring unrelated email, and hardware upgrades are not GRC design activities.