ServiceNow Certified Implementation Specialist – Risk and Compliance — Question 129
For a particular risk assessment methodology (RAM), the control effectiveness score is calculated based on an individual assessment of controls. What are options for control identification? (Choose three.)
Answer options
- A. Controls are identified from library and ad-hoc
- B. Controls are identified from indicator results
- C. Controls are identified from library
- D. Controls are identified ad-hoc
- E. Controls are identified from related issues
Correct answer: A, C, D
Explanation
The correct options A, C, and D indicate that controls can be identified from both a predefined library and through ad-hoc means. Option B is incorrect because indicator results are not a primary source for control identification, and option E is not relevant as it refers to issues rather than control identification methods.