Practice CIS-HR Security And Data Protection questions with full explanations on every answer.
Start practicing
Security And Data Protection — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
When configuring 'HR Security Profiles', what is the purpose of the 'Apply to' field?
2Which THREE of the following are primary methods for enforcing data protection within the HR Service Delivery application?
3A user in the HR department reports they cannot see records in the 'HR Tasks' list, despite having the 'hr_task_reader' role. What is the most likely cause?
4An HR Administrator needs to configure data masking for the 'SSN' field in the HR Profile (sn_hr_core_profile) table. Which feature should be used to ensure the data is masked for all users except those with the 'hr_admin' role?
5Which role is required to modify HR security configurations in a scoped application without having full system admin access?
6You need to restrict access to a specific HR Case so that only members of the 'Payroll' assignment group can view it. Which security mechanism should you configure?
7You are configuring Delegated Development for an HR team member. You want to grant them permissions to create and modify HR Service Portal widgets, but you must prevent them from modifying the underlying HR security ACLs. Which scope role should be assigned to the developer?
8An HR administrator needs to restrict access to sensitive employee medical records so that only the HR Benefits team can view them, even though other HR staff have the 'sn_hr_core.case_reader' role. Which security mechanism should be implemented?
9Where do you go to view the HR Security Profiles assigned to a specific user?
10What role is required for a user to manage 'HR Criteria' records?
11Which of the following is true regarding 'HR Scoped Roles'?
12You need to ensure that 'Payroll' employees cannot see 'Employee Relations' cases. What is the standard ServiceNow best practice for this?
13If a user has both the 'hr_admin' and 'sn_hr_core.admin' roles, which role takes precedence for HR data security?
14An organization requires that HR case data be encrypted at rest. What platform feature must be enabled?
15To ensure that HR case 'Work Notes' are hidden from the employee portal, what should you configure?
16When configuring 'Delegated Developer', what privilege allows a user to modify 'HR Service' definitions?
17Which module contains the 'HR Security' configuration settings?
18You need to allow HR managers to view sensitive employee information only while they are on the corporate VPN. What security tool is best suited for this?
19If an HR table has a 'Read' ACL for the 'hr_admin' role, and you want to grant a new group 'HR_Auditors' access, what should you do?
20Who can modify HR Security Profiles?
21What is the purpose of the 'HR Criteria' 'Display' field?
22Which feature enables the 'HR Scoped App' to hide its tables from non-HR users?
23If an HR Case is assigned to a 'Group', how does the 'HR Security Profile' ensure only the assigned group members can see it?
24What is the impact of checking 'Enforce HR Security' on a table in the 'HR Scoped App'?
25When using 'HR Criteria', which attribute can be used to restrict access based on the user's location?
26Which ServiceNow feature identifies sensitive HR data fields for protection?
27If a user has the 'sn_hr_core.case_writer' role, what can they do?
28In a multi-scoped environment, how do you allow an HR role to access a global 'cmdb_ci' table?
29What is the purpose of the 'Delegated Developer' role?
30When setting up 'HR Criteria', can you use both roles and conditions?
31What is the benefit of using 'HR Criteria' instead of hard-coded ACL scripts?
32What is the role of the 'HR Service' definition in data security?
33When an HR service is restricted by 'HR Criteria', what happens when a user attempts to open a case they don't have access to via the portal?
34Which 'HR Security Profile' setting defines whether the profile is active?
35Which table holds the 'HR Profile' data?
36How can you audit access to HR cases?
37Which role is necessary to perform 'HR Case' deletions?
38If a user is assigned to multiple 'HR Security Profiles', how does the system determine the final access level?
39What is the function of the 'Restricted Caller Access' (RCA) records?
40You need to ensure that HR case attachments are encrypted. What is the correct approach?
41What is the primary way to define which HR users can access the 'HR Service Portal'?
42If a field has 'Encryption' applied, how does the system handle searching for that data?
43Which THREE of the following are components of an HR Security Profile?
44Which TWO factors must be configured when setting up a new 'Delegated Developer' for HR?
45Which THREE of the following are types of HR Criteria?
46Which TWO of the following are true about 'HR Scoped Roles'?
47Which TWO of the following are valid ways to secure sensitive HR data on the platform?
48Which TWO of the following can be used to restrict access to an HR Case?
49Which THREE of the following are considered 'Sensitive HR Data' categories?
50Which THREE of the following are necessary to test if your HR security configuration is working correctly?
51Which TWO of the following are true about 'HR Criteria'?
52Which THREE of the following are benefits of using 'Scoped Applications' for HR?
53Which TWO of the following tools allow you to perform a security audit on HR records?
54Which THREE of the following are required to successfully implement 'Field Level Encryption'?
55Which TWO of the following are examples of 'HR Scoped Roles'?
56Which THREE of the following are security controls that can be applied to HR attachments?
57Which TWO of the following are true regarding 'HR Security Profiles' and 'Assignment Groups'?
58Which THREE of the following are valid ways to prevent data leakage in HR?
59An HR administrator is configuring HR Criteria to restrict access to a specific Knowledge Base article. When applying this criteria, the system checks the HR Profile of the logged-in user. Which security component is responsible for enforcing this record-level visibility in the HR Service Delivery module?
60You need to grant a partner HR team the ability to modify HR Case records, but you must prevent them from seeing the 'Salary' field on the HR Profile. How should you implement this requirement using the principle of least privilege?
61An HR department requires that only users with the 'sn_hr_core.admin' role can modify HR Services. Which security mechanism must be configured to ensure this role restriction is enforced during the service definition process?
62When utilizing the 'HR Service Delivery' module, you notice that sensitive employee data is being logged in the application logs. Which ServiceNow feature should be used to mask this data automatically without modifying the business logic?
63A customer is using 'Scoped HR' and needs to allow an HR Admin to modify scripts while ensuring they cannot access other system tables. Which role should be assigned to the HR Admin to permit these actions within the HR scope?
64A user needs access to HR case data, but only for cases belonging to their specific department. Which security model should be used to restrict this data access dynamically?
65You are auditing your instance and find that unauthorized users are able to read HR Profile records. After verifying that no ACLs are broken, what is the next most likely source of this data exposure?
66Which THREE of the following are primary components of the HR Service Delivery data protection strategy when handling PII?
67Which TWO statements are true regarding the use of the 'sn_hr_core.delegated_developer' role?
68Which THREE of the following are valid ways to secure HR data within a ServiceNow instance?
The Security And Data Protection domain covers the key concepts tested in this area of the CIS-HR exam blueprint published by ServiceNow. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CIS-HR domains — no account required.
The Courseiva CIS-HR question bank contains 68 questions in the Security And Data Protection domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security And Data Protection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included