Which filter can be used to identify expense reports that contain suspicious expense type combinations, such as, a report for a single trip that contains taxi, car rental, and mileage expenses?
A. Inclusive function filter grouped by the "Expense Report Information" object's "Report Number" where the "Expense Type" has an "Equals" condition for values that include taxi, car, mileage.
B. Inclusive function filter grouped by the "Expense Report Information" object's "Report Number" where the "Expense Type" has an "In" condition for values that include taxi, car, mileage.
C. Inclusive function filter grouped by the "Expense Report Information" object's "Person" where the "Expense Type" has an "In" condition for values that include taxi, car, mileage.
D. Inclusive function filter grouped by the "Expense Report Information" object's "Report Number" where the "Expense Type" has an "In" condition for values that include taxi, car, mileage.
E. Inclusive function filter grouped by the "Expense Report Information" object's "Person" where the "Expense Type" has an "In" condition for values that include taxi, car, mileage.
Which two steps are required to set up two levels of approval for new controls, which are added after the initial import? (Choose two.)
A. On the Controls tab of the Import template, set the control state to NEW for each control record.
B. Identify the organizations or business units for which users will perform review or approval.
C. Identify users who will perform control review and approval.
D. Identify the other roles to be provided for control managers.
You are designing data for data import. The customer decided that they want to secure controls based on
their company organization.
Which three worksheets of the import template are required to accomplish this requirement? (Choose
three.)
A. Perspective Items
B. Controls
C. Control Test Plans
D. Perspective-Control
You are configuring security and you do not want the risks to go through the review and approve process each time they are updated. How will you meet this requirement?
A. Add the Risk Reviewer Composite duty role to the person who creates the risks so he or she would be able to review them before saving the record.
B. Use only the Risk Approver Composite duty role in the configurations so the risks will not go through the review process.
C. Ensure that only the upper management is given the Risk Reviewer Composite duty role so they could review the risks that they want to review.
D. Ensure that no user has been assigned a job role that includes the Risk Reviewer Composite or Risk Approver Composite Duty Role.
Which statement related to Advanced Access Controls is true?
A. If helps enforce segregation of duties.
B. If helps perform risk analysis and evaluation.
C. It analyzes transaction records.
D. It documents risks and controls.
During implementation, you created a risk object and successfully mapped it to a control object. The
client's Risk Owner is able to access the risk but not the control.
Why did this happen?
A. The Risk Administrator needs to run the synchronize jobs to populate the mapping.
B. The Risk Owner account is inactive.
C. The Risk Owner role does not have the right privileges.
D. The risk and control objects are inactive and need to be made active.
You have completed the data import process with no errors. You created process, risks, controls, and one perspective. Controls were related to perspectives. You have provided the customer with the Control Manager security role. When the customer logs in to Financials Risk Compliance (FRC), the customer cannot see any controls. Which step was missed during the import process?
A. Data security policies for Controls were not created.
B. The Controls were not related to any risk objects.
C. The parent process was never approved.
D. The Control Method was not set to a valid value.
You are remediating access incidents in Advanced Access Controls (AAC), and have just completed the
remediation of a segregation of duties conflict for users in Fusion Security by removing the conflicting
access from the users.
What status do you set for the incident in AAC?
A. Resolved
B. Remediation
C. Remedy
D. Authorized
E. Accepted
Your client needs to perform Design Review and Certification assessment for all their controls. Identify two options that show how this requirement can be met. (Choose two.)
A. Option A
B. Option B
C. Option C
D. Option D
E. Option E
The GRC Business owner responsible for reviewing and investigating access incidents related to the "Order to Cash" perspective does not see any worklists for the generated results. You have validated that:
1.
Other business owners are able to view their assigned worklists without any problem
2.
Incidents have been generated for the controls related to Order to Cash
3.
The business owner's assigned roles contain the correct functional privileges and data access to the correct perspective values
What is the reason the business owner cannot see any worklists for the generated incidents?
A. The Result Management Perspective Assignment has not been linked.
B. The underlying model is not linked to Order to Cash.
C. The business owner was recently assigned the role and the worklist needs to be refreshed.
D. Worklist assignment does not include the business owner.
E. The Control Perspectives are not linked to the control.