About the Exam

The CIS-TPRM exam is ServiceNow's certification for Certified Implementation Specialist - Third-Party Risk Management. It is intended for ServiceNow implementation specialists who work with third-party risk management in GRC workflows. Passing the proctored exam demonstrates knowledge and skills to identify, assess, and mitigate third-party risk across the vendor lifecycle.

Exam Topics

  • Assessment Configuration33%
  • Third-party Risk Management Fundamentals23%
  • Core Configuration20%
  • Third-party Due Diligence24%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated December 5, 2025 at 4:46 PM

Topic filter
Retired questions
Question sort

QuestionQ1

Assessment Configuration

Which type of record is each question in an assessment?

  • A GRC Task[sn_grc_task]
  • B Assessment Metric [asmt_metric]
  • C Task [task]
  • D Assessment Instance [asmt_assessment_instance]
Explanation

In ServiceNow Assessments, each non-scripted assessment metric defines a questionnaire question. Assessment Metric records are stored in the asmt_metric table.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Assessment Configuration

A Third-party Risk Manager needs to run a report that displays due Third-party Assessments. On which table should this report be run?

  • A [sn_vdr_risk_assessment]
  • B [sn_vdr_risk_asmt_task]
  • C [sn_vdr_risk_asmt_assessment]
  • D [sn_vdr_risk_asmt_issue]
Explanation

ServiceNow stores external third-party risk assessments in the sn_vdr_risk_asmt_assessment table. The task and issue tables store follow-up work and identified issues rather than the assessment records themselves.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Assessment Configuration

By default, when are reminder notifications for outstanding assessments sent to the third-party contact?

Choose two
  • A 14 day after due date
  • B 30 days prior to due date
  • C 3 days prior to due date
  • D 7 days prior to due date
Explanation

ServiceNow Third-party Risk Management sends the default pending-assessment reminders to the third-party contact at 30 days before the due date and again at 7 days before the due date.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Third-party Due Diligence

Which types of requests may an employee make when selecting the Request third-party risk due diligence option?

Choose four
  • A Duplicate an engagement
  • B Cancel an engagement
  • C Offboard an engagement with due diligence
  • D Reassess an existing engagement for contract renewal
  • E Reassess an existing engagement
  • F Onboard a new engagement
Explanation

ServiceNow Third-party Risk Management supports due-diligence requests to onboard a new engagement, reassess an existing engagement, reassess an engagement for contract renewal, and offboard an engagement with due diligence. It also supports offboarding without due diligence, which is not among the choices. Duplicating or canceling an engagement is not a due-diligence request type.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Assessment Configuration

Which actions could affect the third party's Risk Assessment rating?

Choose three
  • A Answering one or more questions incorrectly
  • B Leaving answers blank
  • C Omitting documentation
  • D Spelling errors
  • E Reassigning a questionnaire to a contact
Explanation

A third-party assessment rating is derived from the scores and ratings of questionnaires and document requests, weighted by risk area. Incorrect questionnaire responses and omitted requested documentation can therefore affect the rating. Reassigning a questionnaire can change the contact authorized to complete it and consequently the responses that determine its score.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

That's the end of the preview

It's free

100% of the questions are free for all users.
No strings attached.

Topics covered
Assessment ConfigurationThird-party Risk Management FundamentalsCore ConfigurationThird-party Due Diligence
Know a question that should be here? Contribute to this exam
Back home