Question 6

An organization has a list of companies with which they no longer wish to do business. The list is not stored in their ERP Could but is stored in a file.
Whichtransaction model will identify payments made to these companies?
  • Question 7

    An assessor is trying to complete an operational assessment on a control for manual AP Invoice entry and is reviewing Prior Results.
    Which statement is true about viewing Prior Results for this control?
  • Question 8

    The GRC Business owner responsible for reviewing and investigating access incidents related to the "Order to Cash" perspective does not see any worklists for the generated results. You have validated that:
    1. Other business owners are able to view their assigned worklists without any problem
    2. Incidents have been generated for the controls related to Order to Cash
    3. The business owner's assigned roles contain the correct functional privileges and data access to the correct perspective values What is the reason the business owner cannot see any worklists for the generated incidents?
  • Question 9

    A user has created and submitted a new control and the state of the control is "In Review." The user expected that the control state would change to "Approved." Why is the control not in the "Approved" state?
  • Question 10

    You havecreated security roles for the Procure-to-Pay (P2P) Control Manager for the EMEA region in your client's organization. But, there are two problems with his or her security configuration.
    Problem 1: This person should not receive notifications to complete control assessments, but currently he or she does.
    Problem 2: Also, although he or she has access to controls associated with EMEA, he or she is unable to access controls created for individual regions within EMEA.
    You have given him or her the following job role:
    * EMEA P2P Control Manager Job Role
    * Seeded Control Manager Duty Composite
    * Seeded Control Certification Assessor Duty Composite
    * EMEA P2P Control Manager Data Security Policy
    * Seeded Control Manager Data Security Policy
    * Perspective filter where Region Perspective "equals" EMEA
    * Perspective filter where Process Perspective "equals" P2P
    Which two actions need to be taken to correct the problems? (Choose two.)