exam questions

Exam CIS-SIR All Questions

View all questions & answers for the CIS-SIR exam

Exam CIS-SIR topic 1 question 10 discussion

Actual exam question from ServiceNow's CIS-SIR
Question #: 10
Topic #: 1
[All CIS-SIR Questions]

Select the one capability that retrieves a list of running processes on a CI from a host or endpoint.

  • A. Get Network Statistics
  • B. Isolate Host
  • C. Get Running Processes
  • D. Publish Watchlist
  • E. Block Action
  • F. Sightings Search
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MarlyB
1 month, 1 week ago
Selected Answer: C
https://www.servicenow.com/docs/bundle/yokohama-security-management/page/product/security-operations-integrations/concept/secops-integration-get-running-processes-workflow.html The Security Operations - Get Running Processes flow is a high-level flow independent of integrations. It retrieves a list of running processes on a configuration item (CI) from a host. Use it to fulfill an integration, such as Carbon Black, or for a Windows-based security incident.
upvoted 1 times
...
NokoNice
6 months, 2 weeks ago
Selected Answer: C
https://www.servicenow.com/docs/bundle/xanadu-security-management/page/product/security-operations-common/concept/get-running-processes-capability.html
upvoted 1 times
...
sephereth
11 months, 2 weeks ago
Selected Answer: C
The Get Running Processes capability retrieves a list of running processes on a CI from a host or endpoint in ServiceNow. This capability is useful for security incident response teams to identify malicious processes running on a host or endpoint and to take appropriate action.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...