Back to all practice tests
CIS Vulnerability Response - ServiceNow VR Certification Practice Test
VR

CIS Vulnerability Response - ServiceNow Practice Test 2026

VR questions are usually about prioritization and workflow, not raw scanner jargon. This 213-question bank covers remediation, exceptions, groups, integrations, and response logic. The explanations help separate similar-looking answers.

5.0 (20 reviews)
213 questions
Lifetime access
$9.99 $99.99 90% off
Start practicing now

What's included

15-question preview

15 Free Preview Questions

Answer 5 questions free. Enter your email to continue through question 15. The full course has 213 questions on Udemy.

Question 1 of 15
Free
0 correct so far
1.To facilitate "Exception Management", a user requests an exception for a Vulnerability. If the Risk Score of the item is below a certain threshold, the system can be configured to:
  • AReject the request immediately.
  • BAuto-approve the exception without human intervention.
  • CEscalate to the CISO.
  • DCreate a Problem record.
Show full explanation
Correct Answer

B - Auto-approve the exception without human intervention.

Source

ServiceNow Zurich Documentation - Exception Management

Expert Explanation

Vulnerability Response Exception Management allows organizations to define risk thresholds that determine the approval path. When a vulnerability item has a risk score below the configured threshold, the system can automatically approve the exception, bypassing the manual approval process. This reduces administrative overhead while maintaining governance for higher-risk items.

Why the Others Are Wrong

Option A (Reject immediately) goes against the purpose of exception management, which is to allow acceptable risk. Option C (Escalate to CISO) is the opposite of what you want for low-risk items. Option D (Create a Problem record) belongs to ITSM processes, not to the exception approval workflow.

Memory Tip

Think of it like a fast lane at airport security: low-risk travelers get through automatically, while higher-risk ones go through extra screening. Low risk score = auto-approved, no human needed.

Real-World Example

Your scanner flags a vulnerability on a test server that scores a 1.2 out of 100 on risk. Instead of bothering the security manager for approval, the system auto-approves the exception because 1.2 is well below the threshold of 25 you configured. The security team can focus on the items that truly matter.

Choose an answer and submit to continue.
Questions 6-15 are ready.

Looking for a different certification-

Browse all 18 practice tests →

Not sure which cert? See the full certification guide →