logo
其他专业级🔒 安全

ServiceNow Certified Implementation Specialist - Security Incident Response (CIS-SIR)

ServiceNow Security Operations certification covering security incident lifecycle, threat intelligence feeds, observables and IOC matching, vulnerability response, scanner integrations, playbooks, and SOC workspace operations. 60 questions, 90 minutes, 70% to pass, $250 exam fee.

$250
Exam Fee
60
Questions
90m
Exam Duration
70/100
Passing Score
MEMBERSHIP

JR Academy Membership

Unlock all certifications, courses & tools at a fraction of the cost

  • All certification exam prep included
  • Course discounts up to 50%
  • AI tools & Chrome extensions
  • Priority 1-on-1 coaching
View Membership Plans

What this certification covers

This page is structured for quick scanning first: exam format, fit, prep time, and the actual study scope.

Certification Overview

ServiceNow Certified Implementation Specialist - Security Incident Response (CIS-SIR) is for people implementing ServiceNow Security Operations in real SOC workflows. The exam is built around how alerts become security incidents, how analysts investigate and contain them, how threat intelligence is matched, and how vulnerability data from tools like Qualys or Tenable is pushed into remediation work. This is one of the more operational specialist exams in the ServiceNow stack. You need enough security background to understand why the workflow exists, not just where the fields are.

Exam Domains

  • Security Incident Response: incident creation, categorization, prioritization, investigation, containment, eradication, recovery, and post-incident review
  • Threat Intelligence: feeds, STIX/TAXII, observables, IOC matching, sightings, and lookups
  • Vulnerability Response: scanner integrations, vulnerable items, prioritization, remediation tasks, exceptions, and CMDB linkage
  • SecOps Configuration: SOC workspace, playbooks, classifications, SLAs, and integration setup
  • Reporting and Dashboards: security posture visibility, response metrics, and operational reporting

Who Is This For

This certification fits SecOps consultants, SOC analysts, security engineers, vulnerability management teams, and ServiceNow practitioners moving into security operations work.

You will work with

Security Incident ResponseVulnerability ResponseThreat IntelligenceIOCObservablesSTIXTAXIIPlaybooksSIEM IntegrationQualys IntegrationTenable IntegrationCVSSRemediation TasksSOC WorkspaceSecurity Posture DashboardMITRE ATT&CK

After preparation

  • Earn the ServiceNow CIS-SIR certification
  • Set up and run security incident workflows in the ServiceNow SecOps model
  • Link threat intelligence and scanner data to incidents and remediation work
  • Configure playbooks, response SLAs, and SOC-facing operational views

Exam details

Exam Code
CIS-SIR
Provider
其他认证机构
Duration
90 minutes
Question Count
60 questions
Passing Score
70/100
Validity
3 years
Exam Fee
$250 USD
Question Types
Single choice, Multiple select
Languages
English
Official Page

Who should take it

Good fit

  • ServiceNow SecOps consultants implementing SIR and Vulnerability Response
  • Security engineers moving incident response workflows into the ServiceNow platform
  • SOC analysts using ServiceNow Security Operations day to day
  • CSA-certified professionals with a security background who want to specialize in SecOps

Before you start

  • CSA is recommended before taking CIS-SIR
  • You should know basic incident response and vulnerability management concepts
  • Familiarity with SIEM tools and scanner outputs is useful
  • Hands-on exposure to Security Operations in ServiceNow will help a lot
  • Basic understanding of frameworks such as NIST IR and MITRE ATT&CK is expected

Study preparation

With hands-on AWS

8-10 weeks

From scratch

12-16 weeks

Daily pace

1-2 hours/day

Learning path preview

3 chapters
1
CIS-SIR Exam Overview & Study Guide
45 min
2
Core Concepts
279 min
3
Final Review & Hands-on Exam Practice
60 min

Certification comparison

ServiceNow CIS-SIRCCDAKCCFA
Provider其他其他其他
Level专业级助理级专业级
Fee$250$150$300
Duration90 min90 min90 min
Question count606060
Validity3 yrs2 yrs3 yrs

Study tips and common mistakes

💡

60 题 90 分钟,平均每题 2 分钟,合理分配时间

💡

及格分 70/100,不确定的题先标记跳过,回头再做

💡

排除法非常有用 — 先排掉明显错误的选项,剩下的再分析

💡

多选题会告诉你选几个,仔细看题目要求

⚠️

没有读完所有选项就选答案 — 题目经常有"最佳"答案和"正确但不最佳"的干扰项

⚠️

备考只刷题不理解原理 — 考试场景题需要理解底层概念

⚠️

忽略时间管理 — 在难题上卡太久,导致后面简单题没时间做

FAQ

Frequently Asked Questions

If you plan to take ServiceNow CIS-SIR, start with real practice.

113+ questions, chapter-by-chapter learning, mock exams, wrong-question review, and AI tutor support live in the exam page.

Go to exam prep

From $39 · 2 free chapters

Related certifications