How do you populate the Control Method field with a new custom value, such as a third-party application'?
A. Enter the new value directly in the Control method field.
B. Use Lookup Meaning of the new lookup value.
C. Use Lookup Code of the new lookup value.
D. Use Lookup Type of the new lookup value.
Which two steps are required to set up two levels of approval for new controls, which are added after the initial import? (Choose two.)
A. On the Controls tab of the Import template, set the control state to NEW for each control record.
B. Identify the organizations or business units for which users will perform review or approval.
C. Identify users who will perform control review and approval.
D. Identify the other roles to be provided for control managers.
A Control Manager has changed the status of an issue to "In Remediation" and has submitted it. What will be the state of the Issue if there is no issue validator, reviewer, or approver configured?
A. In Review
B. Active
C. Reported
D. Approved
E. In Edit
How do you add values to a Risk Type list of values?
A. Populate the Import template with the new values in the Issue Severity column on the Controls tab.
B. Add the lookup codes to the GRC_RISK_TYPE Lookup Type.
C. Because you cannot add new values, update one of the existing lookup codes to what the client wants it to be.
D. Add the lookup codes to the GRCM_RISK_TYPE Lookup Type.
E. Use the default lookup codes because there is no way to update the existing ones.
An assessor is trying to complete an operational assessment on a control for manual AP Invoice entry and
is reviewing Prior Results.
Which statement is true about viewing Prior Results for this control?
A. He or she will be able to review results of all prior assessments of all types for this control.
B. He or she will be able to review results of all prior Audit tests and operational assessments for this control.
C. He or she will be able to review only results of prior operational assessments for this control.
D. He or she will be able to review results of all prior operational assessments for all controls.
E. He or she will be able to review results of all prior assessments of all types for all controls.
You have completed the data import process with no errors. You created process, risks, controls, and one perspective. Controls were related to perspectives. You have provided the customer with the Control Manager security role. When the customer logs in to Financials Risk Compliance (FRC), the customer cannot see any controls. Which step was missed during the import process?
A. Data security policies for Controls were not created.
B. The Controls were not related to any risk objects.
C. The parent process was never approved.
D. The Control Method was not set to a valid value.
You have created a risk definition R100 and have created a new control C100 for this risk. No user has been assigned the Risk or Control reviewer and approver roles. What will be the state of R100 and C100 after submitting?
A. Both R100 and C100 will be in the "In Review" state.
B. Both R100 and C100 will be in the "Awaiting Approval" state.
C. Both R100 and C100 will be in the "Approved" state.
D. Both R100 and C100 will be in the "New" state.
You are helping your client identify and define their controls. You have determined that your client requires two perspectives: Business Units and Regulatory Standards. The controls are going to be secured by the business unit, and you want to ensure that when the client defines new controls, it is mandatory to assign a Business Units perspective to the control. You are going to set the "Required" field to "yes" for the Control-Business Units association. Where do you do this in the product?
A. The Create Control screen
B. The Manage Object Perspectives screen
C. The Import template
D. The Create Perspectives screen
E. The Manage Module Perspectives screen
You are remediating access incidents in Advanced Access Controls (AAC), and have just completed the
remediation of a segregation of duties conflict for users in Fusion Security by removing the conflicting
access from the users.
What status do you set for the incident in AAC?
A. Resolved
B. Remediation
C. Remedy
D. Authorized
E. Accepted
You have defined an initial Perspective Hierarchy for your client in the Advanced Controls module. After refining their business requirements, your client wants to expand the existing hierarchy to include 150 perspective items in various levels. For efficient processing, you decide to use the GRC data migration feature to import the new items. Which three are valid processing steps required to define the export file? (Choose three.)
A. Navigate to Risk Management Tools > Setup and Administration > Data Migration, and select Advanced Controls.
B. Generate Template as Without Data.
C. Navigate to Manage Module Perspectives.
D. Generate Template as Without Data ?Perspectives Only.
E. Click the Create Import Template button.