Back to all practice tests
CIS Risk & Compliance GRC/IRM - ServiceNow GRC Certification Practice Test
GRC

CIS Risk & Compliance GRC/IRM - ServiceNow Practice Test 2026

GRC/IRM is one of the widest exams in the catalog. Policy, risk, compliance, entities, indicators, assessments, and issue management all show up. This 300-question bank is built for people who want reps before they sit a broad exam.

4.0
300 questions
Lifetime access
$9.99 $99.99 90% off
Start practicing now

What's included

15-question preview

15 Free Preview Questions

Answer 5 questions free. Enter your email to continue through question 15. The full course has 300 questions on Udemy.

Question 1 of 15
Free
0 correct so far
1.In the Audit Workspace an Auditor creates an Evidence Request task and assigns it to a First Line user. When the First Line user opens the task to respond which action are they strictly required to take to move the workflow forward
  • ACreate a new Control Test
  • BAttach a file or link to a record and submit the task for approval
  • CManually close the Audit Engagement
  • DMark the related Control as Compliant
Show full explanation
Correct Answer

B - Attach a file or link to a record and submit the task for approval

Source

ServiceNow Zurich Documentation - Audit Evidence Requests

Expert Explanation

Evidence Request tasks are assigned to First Line users so they can provide proof of control effectiveness. The user attaches files (documents, screenshots, exports) or links to existing ServiceNow records, then submits the task back for auditor review. This attachment-and-submit pattern ensures evidence is formally captured and routed through the approval chain.

Why the Others Are Wrong

Creating Control Tests (A) is a separate compliance activity. Closing an Audit Engagement (C) is reserved for Audit leadership. Marking a Control as Compliant (D) results from auditor evaluation of test results, not from evidence submission.

Memory Tip

Think "Evidence = Attach + Submit." The First Line user is like a witness in court - they provide evidence, they do not render the verdict.

Real-World Example

An IT administrator receives an Evidence Request to prove that quarterly access reviews were completed. They attach the exported access review report from their IAM tool and submit the task. The auditor then reviews the attachment and approves or rejects it.

Choose an answer and submit to continue.
Questions 6-15 are ready.

Looking for a different certification-

Browse all 18 practice tests →

Not sure which cert? See the full certification guide →