Wednesday, 26 February 2014

GRC AC 10.0 Certification Exam Questions and Answers - part-1



These questions and answers are collected from web and friends who is preparing for GRC 10.0 certification exam to help people who is preparing for GRC certification. 

1. Your customer has created a custom transaction code ZFB10N by copying transaction FB10
and  implementing a user exit.
How can you incorporate the customer enhancement into the global rule set so that it will be
available for Risk Analysis?


A. Update security permissions in all relevant authorization objects, maintain the custom program
name in all relevant functions, and generate the access rules
B. Update all relevant functions with ZFB10N, maintain the permission values for all relevant
authorization objects, and generate the access rules
C. Update all relevant functions with ZFB10N, maintain the permission values in the relevant
access risk, and generate the global rule set
D. Update the relevant access risk with ZFB10N, maintain access rules in all relevant functions,
and generate the global rule set
Answer: B

2. Which of the following objects can you maintain in the "Maintain Paths" work area of MSMP workflow configuration? (Choose three)
A. Paths
B. Path versions
C. Rules for path mappings
D. Stage notification settings
E. Stages
Answer: A,D,E

3. Which configuration parameters determine the content of the log generated by the SPM Log
Synch job? (Choose three)?

A. Enable Risk Change log (1002)
B. Enable Authorization Logging (1100)
C. Retrieve System log (4004)
D. Retrieve OS Command log (4006)
E. Retrieve Audit log (4005)
Answer: C,D,E

4. Your customer wants to eliminate false positives from their risk analysis results.
How must you configure Access Control to include organizational value checks when performing a
risk analysis? (Choose two)?


A. Configure organization rules for each relevant function
B. Update the functions that contain each relevant action by activating the fields for the required
permissions and maintaining a value for each specific organization
C. Configure organization rules for each relevant risk
D. Update the functions that contain each relevant action by activating the fields for the required
permissions
E. Configure organization level system parameters to incorporate all organization levels for each
relevant risk

Answer: C,D

5. What do you mitigate using Access Control?
A. Roles
B. Users
C. Risks
D. Functions
Answer: C

6. Your customer wants a manager to fulfill both MSMP workflow agent purposes.
How do you configure this?


A. Maintain the manager agent twice, once for each purpose, using the same agent ID
B. Maintain the manager agent once and assign both purposes to it without using an agent ID
C. Maintain the manager agent twice, once for each purpose, using different agent IDs
D. Maintain the manager agent once and assign both purposes to it using the same agent ID
Answer: C

7. You have identified some risks that need to be defined as cross-system risks. How do you
configure your system to enable cross-system risk analysis?

A. 1. Set the analysis scope of the function to cross-system
2. Create cross-system type connectors
3. Assign the corresponding connectors to the appropriate connector group

4. Generate rules

B. 1. Set the analysis scope of the risk to cross-system
2. Create cross-system type connectors
3. Assign the corresponding connectors to the appropriate connector group
4. Generate rules


C. 1. Set the analysis scope of the risk to cross-system
2. Create a cross-system type connector group
3. Assign the corresponding connectors to the connector group
4. Generate rules


D. 1. Set the analysis scope of the function to cross-system
2. Create a cross-system type connector group
3. Assign the corresponding connectors to the connector group
4. Generate rules
Answer: D

8. What does assigning the Logical Group (SOD-LOG) type to a connector group allow you to do?
A. Run a cross-system analysis
B. Use the connector group for transports to the target system
C. Monitor the target system
D. Use the connector group as a business role management landscape
Answer: D

9. Who approves the review of the periodic segregation of duties?
A. Mitigation monitors
B. Role owners
C. Mitigation approvers
D. Risk owners
Answer: D

10. How are lines and columns linked in a BRFplus initiator decision table?
A. A column to a column through a logical OR
B. A column to a line through a logical OR
C. A column to a column through a logical AND
D. A line to a line through a logical AND
Answer: C
 

Click here for GRC AC 10.0 Certification Exam Questions and Answers - part-2

Please do share if you like this post :)

No comments:

Post a Comment

Note: only a member of this blog may post a comment.