Back to all practice tests
CIS Security Incident Response - ServiceNow SIR Certification Practice Test
SIR

CIS Security Incident Response - ServiceNow Practice Test 2026

SIR is workflow-heavy and easy to overthink. These 281 questions stay close to intake, response tasks, playbooks, enrichment, and handoffs. The goal is to make the platform logic feel familiar before exam day.

5.0 (17 reviews)
281 questions
Lifetime access
$9.99 $99.99 90% off
Start practicing now

What's included

15-question preview

15 Free Preview Questions

Answer 5 questions free. Enter your email to continue through question 15. The full course has 281 questions on Udemy.

Question 1 of 15
Free
0 correct so far
1.When configuring a Security Tag what does the "Enrichment whitelist/blacklist" classification control-
  • AWhether the tag can be seen by external users.
  • BWhether Observables associated with the tagged incident are automatically sent for Threat Intelligence enrichment.
  • CWhich analysts are allowed to remove the tag.
  • DThe color of the tag in the UI.
Show full explanation
Correct Answer

B - Whether Observables associated with the tagged incident are automatically sent for Threat Intelligence enrichment.

Source

ServiceNow Zurich Documentation - Security Tags

Expert Explanation

Security Tags can be classified to control enrichment behavior. When a tag carries an enrichment blacklist classification, any Observables attached to that tagged security incident will be skipped during automatic Threat Intelligence enrichment. This is critical for sensitive cases where you do not want hashes or IPs sent to external threat feeds.

Why the Others Are Wrong

A confuses tag classification with user access controls. C confuses it with role-based permissions. D confuses it with UI styling, which is a separate tag property.

Memory Tip

Think "Enrichment whitelist/blacklist" literally: it whitelists or blacklists observables from being enriched. The name tells you exactly what it does.

Real-World Example

Your SOC is investigating an insider threat. You tag the incident "Insider - Sensitive" with an enrichment blacklist classification so that file hashes from the case are never sent to VirusTotal or other external services, preventing data leakage about the investigation.

Choose an answer and submit to continue.
Questions 6-15 are ready.

Looking for a different certification-

Browse all 18 practice tests →

Not sure which cert? See the full certification guide →