After generating an XML file export of Advanced Controls perspectives, you receive a message that the
export job has been generated.
What are the three steps you need to perform in order to download and review the formatted export file?
(Choose three.)
A. Open with an XML editor, such as Excel.
B. Navigate to Monitor Jobs and click the message link for the export job.
C. Click the Item Results link.
D. Click the Export File button.
E. Open with an HTML editor.
Your client has configured separate roles for control assessor and control assessment reviewer. The control assessor has submitted his or her assessment. The control assessor realizes later that he or she has forgotten to attach a critical test evidence document to the assessment and needs to attach it now. How can this be accomplished?
A. The assessor can request the reviewer to attach the document during the review.
B. On the Assessment tab in the Control definition, the assessor can select the assessment and click the Complete Assessment button. He or she can attach the document and resubmit the assessment.
C. The assessor can request the reviewer to reject the assessment. After the assessment is rejected, the assessor can then attach the document and resubmit the assessment.
D. On the Manage Assessments page, the assessor can select the assessment and click the Reopen button. He or she can then attach the document and resubmit the assessment.
During an assessment, an issue was created. Your job as the Issue Manager is to review the issues and
validate them. If it is determined that they are not valid issues, you need to close them. You have found an
issue that is not valid and with Status: Open and State: Reported.
Identify the correct step to close this issue.
A. On the Manage Issues page, highlight the issue and click the Close button.
B. The assessment associated to the issue must be completed before closing the issue. Only then can you close the issue.
C. After you have completed the remediation plan, click the Close button on the Remediation Plan page.
D. Ensure that the issue status is In Edit, and then from the Actions menu, select Close Issue.
Your client has three operating units.
What are two ways in which you can exclude an operating unit where there are not enough personnel to
allow segregation of duties? (Choose two.)
A. In a model, create a new condition logic filter, select the operating unit attribute, select the operating unit value, and then perform an exclusion though the advanced options check box.
B. Navigate to the Create Access Global Condition page and create a new condition logic filter, select the operating unit attribute, select the operating unit value, and then perform an exclusion though the advanced options check box.
C. Navigate to the Create Access Global Condition page and create a new condition logic filter, select the within same operating unit attribute, select the value yes, and then perform your exclusion though the advanced options check box.
D. In a model, create a new condition logic filter, select the within same operating unit attribute, select the value yes, and then perform your exclusion though the advanced options check box.
E. In a model, create a new condition logic filter, select the operating unit attribute and select the operating unit value.
Which two options can be assigned to a duty role? (Choose two.)
A. Functional Security Policy
B. Abstract Role
C. Data Security Policy
D. Job Role
You have created a risk definition R100 and have created a new control C100 for this risk. No user has been assigned the Risk or Control reviewer and approver roles. What will be the state of R100 and C100 after submitting?
A. Both R100 and C100 will be in the "In Review" state.
B. Both R100 and C100 will be in the "Awaiting Approval" state.
C. Both R100 and C100 will be in the "Approved" state.
D. Both R100 and C100 will be in the "New" state.
You are remediating access incidents in Advanced Access Controls (AAC), and have just completed the
remediation of a segregation of duties conflict for users in Fusion Security by removing the conflicting
access from the users.
What status do you set for the incident in AAC?
A. Resolved
B. Remediation
C. Remedy
D. Authorized
E. Accepted
Which three statements are true about the purpose of perspectives? (Choose three.)
A. Perspectives can be used to define user privileges.
B. Perspectives can be used for categorizing Financial Reporting Compliance objects.
C. Perspectives can be used to represent regional hierarchies.
D. Perspectives are used to enable data security on Financial Reporting Compliance objects.
E. Perspectives enable functional security in Financial Reporting Compliance.
Your client has asked you to define a transaction model to identify duplicate invoices based on Invoice
Numbers and Invoice Amounts.
Which two standard filters can be combined to accomplish this? (Choose two.)
A. The "Payables Invoice" object's "Supplier ID" does not equal itself.
B. The "Payables Invoice" object's "Invoice ID" is similar to the "Payables Invoice" object's "Invoice Number".
C. The "Payables Invoice" object's "Invoice Amount" is equal to itself.
D. The "Payables Invoice" object's "Invoice Number" is equal to the "Payables Invoice" object's "Invoice ID."
E. The "Payables Invoice" object's "Invoice Number" is equal to itself.
The GRC Business owner responsible for reviewing and investigating access incidents related to the "Order to Cash" perspective does not see any worklists for the generated results. You have validated that:
1.
Other business owners are able to view their assigned worklists without any problem
2.
Incidents have been generated for the controls related to Order to Cash
3.
The business owner's assigned roles contain the correct functional privileges and data access to the correct perspective values
What is the reason the business owner cannot see any worklists for the generated incidents?
A. The Result Management Perspective Assignment has not been linked.
B. The underlying model is not linked to Order to Cash.
C. The business owner was recently assigned the role and the worklist needs to be refreshed.
D. Worklist assignment does not include the business owner.
E. The Control Perspectives are not linked to the control.