Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A project expense line is cost associated with a specific source, except for:
According to theProject Expense Linesdocument, a project expense line is cost associated with a specific source, such as fixed assets, resource, or software. The program field on the project expense line form is not a source of cost, but a reference to the program that the project belongs to. Therefore, the correct answer is B. Program. The other options are not correct, as they are sources of cost for a project expense line.
What are the default project template configuration records available in the Template Config module?
Choose 3 answers
the default project template configuration records available in the Template Config module are Project task, Project, and Project template. These records define the fields and values that are copied from the template to the project when a project is created from a template. The other options are incorrect because:
B .Project subtask: Project subtask is not a valid record in the Template Config module, as it is a child of the Project task record2.
D .Task: Task is not a valid record in the Template Config module, as it is a parent of the Project task record3.
1:12: https://docs.servicenow.com/bundle/vancouver-it-business-management/page/product/project-management/reference/r_ProjectTaskTable.html3: https://docs.servicenow.com/bundle/vancouver-platform-administration/page/administer/table-administration/concept/c_TableHierarchy.html
What determines the resource schedule if the Schedules related list and Schedule field are both empty?
What is the formula for Committed Utilization?
If a user creates a new demand from the demand workbench, what state will the system save the record in?
According to theUsing the Demand Workbenchdocument, if a user creates a new demand from the demand workbench, the system saves the record in the qualified state and displays it on the bubble chart. The other options are not correct, as they are not the default state for a new demand created from the demand workbench. The approved state is the final state for a demand that has passed all the assessments. The open state is the initial state for a demand that is created from the Service Catalog. The draft state is the state for a demand that is created from the Demand form.
112 questions covering all exam domains, starting from $20
Exam domains verified against: Official ServiceNow CIS-SPM exam guide, last checked September 2026.
Covers security management concepts and principles, organizational structures and roles in security, and security policies, standards, and procedures. Focus on establishing governance frameworks and defining security roles within organizations.
Addresses risk management, risk assessment methodologies, threat modeling and vulnerability assessment, and risk mitigation strategies. Focuses on identifying and managing organizational risks through systematic assessment and response planning.
Covers information and asset classification, data security controls, privacy protection measures, and intellectual property protection. Emphasizes safeguarding organizational assets and maintaining appropriate control over sensitive information.
Covers security models and design principles, system and application security, and cryptography and key management. Focuses on designing secure systems and implementing technical controls to protect information and systems.
Covers network architecture and design, secure communication protocols, wireless network security, and network attacks and defenses. Addresses securing data transmission and protecting network infrastructure from threats.
Covers authentication methods and technologies, authorization and access control models, and identity management lifecycle. Focuses on ensuring only authorized users access appropriate resources and maintaining identity governance.
Focuses on security monitoring and analytics, incident response and management, forensics and investigations, and patch and vulnerability management. Emphasizes detecting, responding to, and investigating security incidents while maintaining system updates.
Addresses securing the software development lifecycle, application security testing, code review and secure coding practices, and third-party software management. Focuses on building security into applications from design through deployment.
Covers security audit principles and methodologies, penetration testing techniques, and security metrics and reporting. Focuses on evaluating security posture through systematic assessment and reporting on security effectiveness.
Covers privacy principles and regulations, privacy impact assessments, data protection techniques, and privacy by design concepts. Emphasizes protecting personal information and integrating privacy considerations into organizational processes.
Common questions about the exam itself