Service Now Vulnerability
Response Implementor
Exam with complete
solution
Denning [Date] [Course title]
,NVD - Correct Answers: National Vulnerability Database
CVE - Correct Answers: Common Vulnerability and Exposures
CWE - Correct Answers: Common Weakness Enumeration
CPE - Correct Answers: Common Platform Enumeration
Third-Party Vulnerable Entries - Correct Answers: Dictionary of vulns or scan checks based on scanning
vendors (Qualys, Tenable, Veracode)
What data does a VIT contain? - Correct Answers: Tasks, Attachments, Work Notes, Approvals,
Vulnerability Details
VR + CMDB allows for the following activities in a single system of record? - Correct Answers:
Remediation, Configuration Management/Business Impact, Security Incident Response, Problem
Management, Change Management, Orchestrations (Manual response), SLAs
IT Remediation Workspace - Correct Answers: Shows all vulnerabilities/RT assigned to me or to a group I
belong to
Remediation Overview - Correct Answers: Dashboard reporting of all vulns/RT assigned to me or to
groups I belong to
Vulnerability Manager Workspace - Correct Answers: Breakdown of all vulnerabilities (admin view)
Approver Overview - Correct Answers: view of all Exception and FP requests in a dashboard
VR Roles: Vulnerability Admin - Correct Answers: complete access to the VR application, Configure VR
and rules, Installs all 3rd-party integrations, assigns all VR personas and roles
, VR Roles: Remediation Owner - Correct Answers: view and update VI's and RT's, view all vulnerabilities
and solutions, write access to Notes on the solution record
VR Roles: CI Manager - Correct Answers: Manages unmatched CIs not in CMDB, Updates discovered
items
VR Roles: Exception Approver - Correct Answers: approves exceptions, deferrals, and closures of VI's and
RT's
AVR Roles: Security Champion - Correct Answers: Liaisons between the development group and security
managers
AVR Roles: App-Sec Manager - Correct Answers: ID and prioritization of vulns, configure integrations,
work with security champion and developer to remediate vulns
AVR Roles: Developer - Correct Answers: contributor to development of an application, make changes to
application to remediate vulns
VR Properties: sn_vul.popup - Correct Answers: customization when creating a problem change or
security incident in VIT form
VR Properties: sn_vul.vulnerable_item.approval_required - Correct Answers: Determines whether an
approval process is required to move a vuln item into a terminal state
VR Properties: sn_vul.email_to - Correct Answers: specifies the inbox to be used by vulnerability tools (in
Security Support Common Scope)
VR Properties: sys_properties.list - Correct Answers: complete list of system properties
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller NETEXPERT. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $11.49. You're not tied to anything after your purchase.