You have built a transaction model to identify possible duplicate charges between invoicing and expense credit cards. The model logic already includes two standard filters that identify amounts and suppliers that are the same or similar, as shown:

Which additional date filter will further refine the set of duplicate charges found?
A. The "Payables Invoice" object's "Invoice Date" attribute is greater than the "Expense Report Credit Card Transaction" object's "Transaction Date" attribute.
B. The "Expense Report Credit Card Transaction" object's "Last Updated Date" attribute is greater than the "Relative Value" of 3 months.
C. The "Expense Report Credit Card Transaction" object's "Transaction Date" attribute is not blank.
D. The "Payables Invoice" object's "Invoice Date" attribute is similar to the "Expense Report Credit Card Transaction" object's "Transaction Date" attribute within +/- 10 days.
Which two would need to happen in order for Advanced Access Controls (AAC) to automatically assign a status of "Closed" to an access incident? (Choose two.)
A. The incident is resolved in Fusion Cloud and a subsequent evaluation of controls finds that the incident no longer exists.
B. A global condition was added that resolves the conflict and a subsequent evaluation of controls finds that the incident no longer exists.
C. A user sets the State of the incident to "Remediate".
D. The incident is resolved using simulation in AAC and a subsequent evaluation of controls finds that the incident no longer exists.
E. A user sets the Status of the incident to "Resolved".
The internal auditor advised the Control Owner of North America to perform assessment for two P2P
controls.
Which three steps can the Control Owner perform to kick-off assessments for only those two controls?
(Choose three.)
A. Initiate a planned assessment that includes all controls assigned to perspective P2P.
B. Perform impromptu assessments for the two controls.
C. Enable impromptu assessments during configuration of module objects.
D. Initiate a planned assessment and include the two controls as part of the same assessment.
E. Initiate two planned assessments, one for each control.
An assessor is trying to complete an operational assessment on a control for manual AP Invoice entry and
is reviewing Prior Results.
Which statement is true about viewing Prior Results for this control?
A. He or she will be able to review results of all prior assessments of all types for this control.
B. He or she will be able to review results of all prior Audit tests and operational assessments for this control.
C. He or she will be able to review only results of prior operational assessments for this control.
D. He or she will be able to review results of all prior operational assessments for all controls.
E. He or she will be able to review results of all prior assessments of all types for all controls.
You have created security roles for the Procure-to-Pay (P2P) Control Manager for the EMEA region in your client's organization. But, there are two problems with his or her security configuration. Problem 1: This person should not receive notifications to complete control assessments, but currently he or she does. Problem 2: Also, although he or she has access to controls associated with EMEA, he or she is unable to access controls created for individual regions within EMEA. You have given him or her the following job role: EMEA P2P Control Manager Job Role Seeded Control Manager Duty Composite Seeded Control Certification Assessor Duty Composite EMEA P2P Control Manager Data Security Policy Seeded Control Manager Data Security Policy Perspective filter where Region Perspective “equals” EMEA Perspective filter where Process Perspective “equals” P2P
Which two actions need to be taken to correct the problems? (Choose two.)
A. Remove Control Certification Assessor Composite from the EMEA P2P Control Manager job role.
B. Create EMEA P2P Control Certification Assessor Data Security Policy striped by both EMEA and P2P perspectives and assign to the job role.
C. Add to the EMEA P2P Control Manager Data Security Policy the seeded Control Certification Assessor Data Security Policy.
D. While defining data security policy, set the perspective value to EMEA including all child nodes of the EMEA region.
You have two segregation of duties requirements:
1) a user can access either the supplier creation pages or the invoice pages, but not both.
2) a user can access either the invoice creation pages or the payment creation pages, but not both.
How must these requirements be met in Advanced Access Controls?
A. Construct one model with three condition filters where the Function Name Equals "Create Supplier", "Create Invoice" and "Create Payment"
B. Construct two models, and create controls based on the models: "Create Supplier and Create Invoice", "Create Invoice and Create Payment"
C. Construct three controls, and create controls based on the models: "Create Supplier and Create Invoice", "Create Invoice and Create Payment", "Create Supplier and Create Payment"
D. Construct one model: "Create Supplier and Create Invoice and Create Payment"
E. Construct one entitlement: "Create Supplier and Create Invoice and Create Payment"
You want to identify Controls with the most Incidents, with the condition that the identified Controls should
have 80% of all Incidents. To do this, you have imported a custom object that contains the number of
incidents associated with each control, and have added that object to a transaction model.
Which pattern filter must you now apply?
A. Anomaly Detection
B. Mean
C. Pareto
D. Absolute Deviation
E. Clustering
Your client needs to perform Design Review and Certification assessment for all their controls. Identify two options that show how this requirement can be met. (Choose two.)

A. Option A
B. Option B
C. Option C
D. Option D
E. Option E
A user has created and submitted a new control and the state of the control is "In Review." The user expected that the control state would change to "Approved."
Why is the control not in the "Approved" state?
A. This user is not a Control Approver; therefore, the status will be "In Review."
B. The Control Reviewer role has been assigned to some users.
C. New controls must always be reviewed, irrespective of security configuration.
D. The Control Approver role has been assigned to some users.
Which three objects can be related to issues when creating an issue on the Manage Issues page? (Choose three.)
A. Test Plans
B. Assessments
C. Processes
D. Perspectives
E. Risks
F. Controls