Back to all practice tests
CIS Third-Party Risk Mgmt - ServiceNow TPRM Certification Practice Test New
TPRM

CIS Third-Party Risk Mgmt - ServiceNow Practice Test 2026

TPRM is still new, which makes good practice material hard to find. This bank covers vendor assessments, engagements, portal workflows, issues, and risk handling. It already gives you 100+ questions and will keep growing as the cert matures.

4.5
180 questions
Lifetime access
$9.99 $99.99 90% off
Start practicing now

What's included

15-question preview

15 Free Preview Questions

Answer 5 questions free. Enter your email to continue through question 15. The full course has 180 questions on Udemy.

Question 1 of 15
Free
0 correct so far
1.When the GRC: Policy and Compliance Management application is installed, what GRC related list displays on the Third-party Risk Issue record-
  • APolicies
  • BPolicy Exceptions
  • CConfiguration baseline
  • DCitations
Show full explanation
Correct Answer

B - Policy Exceptions

Source

ServiceNow Zurich Documentation

Expert Explanation

Installing the GRC: Policy and Compliance Management application extends the Third-party Risk Issue record with a Policy Exceptions related list. This integration allows organizations to track situations where a vendor issue triggers a formal exception to an internal policy. The linkage ensures that risk and compliance teams share visibility into how vendor shortcomings affect policy adherence.

Why the Others Are Wrong

Policies (A) exist in GRC but are not added as a related list to vendor risk issues. Configuration baselines (C) belong to CMDB security hardening, not GRC risk records. Citations (D) relate to audit evidence tracking and do not surface on the Third-party Risk Issue form.

Memory Tip

Think of it this way: a vendor issue can break your policy, so you need a Policy Exception right there on the issue record to document the deviation.

Real-World Example

A cloud hosting vendor fails to encrypt data at rest, violating your organization's data protection policy. The risk analyst opens the Third-party Risk Issue, then creates a Policy Exception directly from the related list to formally document the temporary deviation while the vendor remediates.

Choose an answer and submit to continue.
Questions 6-15 are ready.

Looking for a different certification-

Browse all 18 practice tests →

Not sure which cert? See the full certification guide →