ServiceNow · Free Practice Questions · Last reviewed May 2026
54real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
11% of exam · 6 sample questions below
A company is integrating ServiceNow with an external ticketing system using a custom REST API. The integration should push updates from ServiceNow to the external system when a change request is approved. Which ServiceNow feature is best suited for this?
REST API Explorer
Business Rule with outbound REST call
A Business Rule executes server-side on the change_request table after approval, and its outbound REST message call pushes the update immediately. This event-driven trigger satisfies the requirement to notify the external system at the moment of approval, without polling.
Access Control List (ACL)
Scheduled Job
Which TWO actions should a developer take when designing an inbound email integration in ServiceNow to ensure proper data mapping? (Choose two.)
Set up an ACL to allow the email user to write to the target table
Ensure the email includes an attachment with the data
Configure the inbound email action to trigger on the appropriate table
The inbound action must be associated with the table where records will be created or updated.
Create a connection to the external email server
Use the email parsing script to extract fields from the email body
Scripts can parse structured data (e.g., JSON) from the email body.
A developer is creating a REST API integration that retrieves data from an external system and updates ServiceNow records. Which THREE considerations are critical for handling authentication securely? (Choose three.)
Enable credential monitoring in the Security Operations Center
Configure the external system to authenticate ServiceNow requests
Store credentials in the ServiceNow Credential Store instead of scripts
The Credential Store encrypts and manages secrets, reducing exposure.
Use OAuth2.0 with refresh tokens for long-lived access
Refresh tokens allow secure renewal without storing long-lived secrets.
Ensure the REST endpoint uses HTTPS
HTTPS encrypts data in transit, preventing interception.
A large enterprise uses ServiceNow as its ITSM platform. They have an existing LDAP directory that contains user accounts and group memberships. They want to synchronize user accounts from LDAP into the ServiceNow user table (sys_user) and automatically assign roles based on group membership. The LDAP server supports both user and group synchronization. The administrator has configured an LDAP server record and a user import transform map. After running the LDAP user import, all users are created but none have roles assigned. The LDAP group import transform map is configured to load groups into the sys_user_group table and members into the member list. The administrator verified that the LDAP group import runs successfully and populates groups with members. However, the expected roles are still missing. What is the most likely cause and solution?
The LDAP group import is not correctly associating users to groups. Solution: check the member attribute mapping in the group import transform map.
The administrator did not configure role-to-group mapping in the LDAP server record. Solution: define the mapping in the 'Role' related list on the LDAP server configuration.
LDAP group imports populate sys_user_group and member lists, but roles are only assigned when role-to-group mapping exists on the LDAP server record's Role related list. Without that mapping, group membership never translates into sys_user_has_role entries, leaving imported users roleless.
The LDAP user import is not populating the 'group' field on the user record. Solution: add a field mapping to copy the group DN.
The LDAP user import transform map does not have a coalesce field set, causing duplicate users. Solution: set coalesce on the user ID field.
A company has a ServiceNow instance integrated with a third-party ticket management system. The integration runs every hour via a scheduled job that calls a REST API to fetch new tickets and create incidents in ServiceNow. The administrator notices that some incidents are being created as duplicates. Investigation reveals that the third-party system sometimes returns the same ticket in multiple API calls due to caching. The scheduled job does not check for existing incidents before creating new ones. The administrator needs to modify the integration to prevent duplicate incidents without relying on the third-party system to change its behavior. Which action should the administrator take?
Add a check in the integration script to query the incident table for an existing incident with the same external ticket ID before creating a new one.
Querying the incident table by external ticket ID before insertion creates an idempotency check, so repeated tickets from the third-party cache are detected and skipped. This prevents duplicates without requiring any change to the third-party system's behaviour.
Modify the integration to only create incidents if the ticket status is 'New'.
Increase the scheduled job interval to run every 2 hours.
Add a post-processing script that deletes duplicate incidents after each run.
Drag and drop the steps to configure a Business Rule in ServiceNow into the correct order.
Step 1: Navigate to the Business Rules module. Step 2: Click the New button. Step 3: Select the table and enter a name. Step 4: Set the conditions for when the rule runs. Step 5: Write the script. Step 6: Click Submit.
This is the correct order because you must first navigate to the Business Rules module, create a new rule, define its table and name, set the conditions that trigger it, write the script logic, and finally save it.
Step 1: Navigate to the Business Rules module. Step 2: Click the New button. Step 3: Write the script. Step 4: Set the conditions. Step 5: Select the table and enter a name. Step 6: Click Submit.
Step 1: Navigate to the Business Rules module. Step 2: Click the New button. Step 3: Set the conditions. Step 4: Select the table and enter a name. Step 5: Write the script. Step 6: Click Submit.
Step 1: Navigate to the Business Rules module. Step 2: Click the New button. Step 3: Select the table and enter a name. Step 4: Write the script. Step 5: Set the conditions. Step 6: Click Submit.
Want more Integrating and managing application data practice?
Practice this domain11% of exam · 6 sample questions below
An administrator wants to enable inbound email integration to automatically create incidents from emails sent to support@company.com. What is the first step in configuring this?
Enable the Email Integration plugin.
Configure an email account (mailbox) to receive emails.
Inbound email integration requires a receiving mailbox before any rule or notification can process messages. Creating and configuring the email account that accepts mail at support@company.com is therefore the prerequisite first step; subsequent steps map incoming messages to incident records.
Create an inbound email action.
Create an ACL to allow email processing.
A ServiceNow instance is being integrated with an external HR system using a SOAP message. The SOAP call is failing intermittently. The developer notices that the XML payload contains special characters like '&' and '<'. What is the best practice to handle these characters in SOAP messages?
Wrap the payload in a CDATA section.
Encode the entire payload in Base64.
Use URL encoding for the payload.
Escape the characters using XML entities (e.g., & for &).
XML reserves '&' and '<' as markup delimiters, so raw occurrences break parsing and cause intermittent SOAP faults. Replacing them with entities such as & and < keeps the payload well-formed, satisfying the requirement to transmit special characters reliably within the SOAP envelope.
A company wants to allow their customers to submit requests via email. The email should create a new record in the 'Request' table. Which component should be used to define the mapping of email fields to the ServiceNow table fields?
Inbound Email Action
Inbound email actions define conditions and scripts to map email fields to table fields.
Email Account
Inbound Email Script
Email Notification
A developer is building a REST API endpoint in ServiceNow to return data from the 'incident' table. The API should only return incidents assigned to the caller. Which method should be used to filter the records based on the caller's user ID?
Use the 'sysparm_display_value' parameter.
Use the 'sysparm_query' parameter with an encoded query.
sysparm_query allows filtering using encoded queries.
Use the 'sysparm_limit' parameter to limit results.
Use the 'sysparm_fields' parameter to specify fields.
Which THREE of the following are valid components of the ServiceNow IntegrationHub?
Action steps
Action steps are individual steps within a spoke action.
Spoke actions
Spoke actions are part of IntegrationHub.
REST Message
Data Source
Flow triggers
Flow triggers are used to start flows in IntegrationHub.
A global company is using ServiceNow for IT Service Management. They have an external asset management system that needs to update asset records in ServiceNow in real-time. The integration is implemented using REST API calls from the external system to ServiceNow. Recently, the integration started failing intermittently with HTTP 429 (Too Many Requests) errors. The external system is sending a high volume of update requests (up to 1000 per minute) to the /api/now/table/alm_asset endpoint. The administrator noticed that the instance performance is degraded during peak times. The company wants to resolve the 429 errors while ensuring data is updated as quickly as possible, but without overloading the instance. Which course of action should the administrator take?
Increase the API rate limit in the instance's system properties.
Reduce the number of requests from the external system to 500 per minute.
Implement a queue-based integration using Flow Designer to process updates asynchronously with a controlled rate.
Queuing allows decoupling and rate control, preventing 429 errors.
Switch the authentication method from basic to OAuth to reduce overhead.
Want more Platform Features and Integration practice?
Practice this domainA developer needs to create a new table in ServiceNow to track project milestones. The table should have a reference field to the Project table and a date field for the milestone date. Which data type should be used for the reference field?
GlideRecord
Integer
String
Reference
The Reference data type stores a sys_id pointing to a record on another table, creating the relational link to the Project table. A plain string or choice field cannot enforce that relationship or resolve the referenced record.
During development, a developer creates a new application module and adds a table 'x_abc_incident' with a reference field to the 'sys_user' table. The developer wants to ensure that when a user is deleted, all related incident records are also deleted. What database constraint should be configured on the reference field?
Cascade delete
Cascade delete is a database constraint on the reference field that automatically removes dependent incident records when the referenced sys_user record is deleted. This directly enforces the required behaviour at the database level, preventing orphaned x_abc_incident rows without custom business rules.
No action
Restrict delete
Set null on delete
A company has a custom table 'u_training_course' with a reference field to 'sys_user' named 'u_instructor'. The requirement is that only users with the 'instructor' role can be selected in this field. Which approach should be used to enforce this?
Create a business rule on the table to check the role and reject invalid selections
Add a reference qualifier on the field to filter users with the 'instructor' role
A reference qualifier applies a filter condition to the reference field's lookup query, restricting selectable records to users holding the 'instructor' role. This enforces the constraint at data entry without altering roles or writing business rules.
Use a client script to validate the selection before form submission
Configure an ACL on the reference field to restrict write access
A developer needs to import data from a CSV file into a custom table. Which ServiceNow module should be used for this task?
Scheduled Jobs
Update Sets
Import Sets
Import Sets load external CSV data into a staging table, where transform maps then coerce records into the target custom table. This staging-then-transform mechanism satisfies the stem's requirement to import CSV data into a custom table, unlike direct table imports or update sets.
Data Source
Which TWO statements about Database Views in ServiceNow are correct?
Database Views improve write performance by reducing the number of tables.
Database Views are stored as separate physical tables.
Database Views allow direct updates to the underlying tables through the view.
Database Views can be used to join multiple tables for reporting purposes.
Correct, they are used for reporting across tables.
Database Views can include fields from parent and child tables.
Views can include fields from related tables.
Which THREE conditions must be met for a user to successfully see a record in a ServiceNow list view?
The user has write permission on the table.
The user has read permission on the table via an ACL.
Read ACL is necessary to view records.
The user has configured a personalized list view for the table.
The user has a role that grants access to the table, if role-based access is configured.
Roles are often required for access.
The record is not excluded by a condition in the application's default filter.
Default filters can hide records from list views.
Want more Working with Data practice?
Practice this domain11% of exam · 6 sample questions below
A company needs to automatically update the 'Assignment group' field on the Change Request table to 'Change Management' when the 'Category' field is set to 'Network'. Which type of business rule should be used?
Display business rule
Async business rule
After business rule
Before business rule
A before business rule runs prior to the database operation, so setting the Assignment group there updates the same record being saved. After rules require a second update, and display rules cannot modify data. Before therefore satisfies the requirement to set the field automatically on insert or update.
A developer creates a business rule on the Incident table that executes a GlideRecord query to update related records. The rule runs on 'after' update and queries the Problem table to set a field. However, the update is not being committed. What is the most likely reason?
The developer forgot to use gr.insert() instead of gr.update().
The GlideRecord query requires an explicit gr.updateMultiple() or gr.commit() to persist changes.
When updating multiple records, gr.updateMultiple() is needed to commit all changes at once.
After business rules cannot update other tables.
The query returns more than 100 records, causing a governor limit.
A company has a business rule on the Task table that runs on 'before' insert. The rule uses current.gotoField('short_description') and current.setValue('short_description', 'Default'). The rule is ordered to run at 500. However, a second business rule on the same table with order 100 also sets the short_description. What will be the final value of short_description?
'Default'
The rule with order 500 runs last and sets the value to 'Default'.
Both values will be concatenated
The value set by the rule at order 100
The field will be empty because gotoField() clears it
Which TWO of the following are valid ways to trigger a business rule? (Choose two.)
Form load
Insert
Insert is a database operation that fires a business rule before or after a new record is written to the table. This satisfies the question's requirement for a valid business rule trigger, since rules execute on record operations rather than on scheduled or manual invocation.
Timer event
Update
Update is a database operation that fires a business rule before or after an existing record is modified. This satisfies the question's requirement for a valid business rule trigger, since rules execute on record operations rather than on scheduled or manual invocation.
Inbound email receipt
Which THREE of the following are best practices when writing business rules? (Choose three.)
Set the Order field to control execution sequence
Order ensures business rules run in the desired sequence.
Use condition scripts to keep scripts clean
Condition scripts improve maintainability.
Use gs.sleep() to wait for other processes
Avoid long-running synchronous business rules
Long-running synchronous rules can cause timeouts and poor performance.
Use GlideAggregate for updating records
Which TWO statements are true about using GlideAggregate in business rules?
GlideAggregate allows adding non-aggregated fields to the result set using addField().
GlideAggregate can be used to perform SQL-like GROUP BY operations.
GlideAggregate is designed to perform grouping and aggregate functions like count, sum, min, max.
GlideAggregate can be used inside a business rule to compute values.
Business rules can use GlideAggregate to query and aggregate data from the database.
GlideAggregate automatically orders the results by the aggregated field.
GlideAggregate can only be used in client scripts.
Want more Automating application logic with business rules and scripts practice?
Practice this domain11% of exam · 6 sample questions below
A developer is creating a custom application in ServiceNow Studio and wants to ensure that the application can be easily installed in other instances without conflicts. Which approach should the developer follow?
Develop the application in global scope and manually copy components to target instances.
Use the 'Application' module in the navigator to create a new application without scope.
Create the application with a unique scope prefix in Studio and export as a scoped application.
A unique scope prefix isolates the application's artefacts, preventing naming collisions with other applications during installation. Exporting as a scoped application packages those artefacts with their scope metadata, so target instances recognise and protect them. This directly satisfies the stem's requirement that the application install elsewhere without conflicts.
Create the application in the global scope and use update sets for distribution.
A developer needs to add a new table to an existing scoped application in ServiceNow Studio. What is the correct sequence of steps?
Open Studio, select the application, click 'Create Application File', choose 'Table', and define the table.
ServiceNow Studio centralises application development, so opening Studio, selecting the target scoped application, then using 'Create Application File' to add a Table creates the record within that application's scope. This sequence ensures the new table is correctly captured in the application's update set.
Navigate to 'Tables' module, create a new table, and then assign it to the application.
Open Studio, select the application, navigate to 'System Definition' > 'Tables' and create the table.
Open Studio, go to 'Application Files', click 'New', select 'Table' and configure.
A developer wants to use ServiceNow Studio to create a client script that runs when a form loads and sets a field value based on the current user's department. Which type of client script should be used?
onLoad client script
An onLoad client script fires when the form loads, allowing the script to query the current user's department and set the field value immediately. This matches the stem's requirement that the script run on form load.
onChange client script
onSubmit client script
onCellEdit client script
A developer is using ServiceNow Studio to deploy a custom application to a production instance. Which THREE actions are recommended best practices for deployment?
Use update sets to move the application to production.
Publish the application to the ServiceNow Store for deployment.
Test the application thoroughly in a sub-production instance before deployment.
Testing in a non-production environment is critical.
Export the application as a scoped application archive (.snc) file.
Scoped applications are distributed as .snc files.
Ensure all application dependencies are included in the export.
Dependencies must be bundled to avoid missing components.
A developer notices that the business rule does not set the assignment group as expected when a new record is created with state 0. What is the most likely issue?
The script has a syntax error.
The assignment_group value is not a valid sys_id of a group.
An invalid group sys_id causes the assignment_group write to fail silently, so the field stays empty despite the rule firing on insert. The stem's constraint is that the rule runs but the group is not set, which points to reference validation rejecting a malformed sys_id rather than a condition or ordering fault.
The business rule runs after the record is saved, so updates are ignored.
The business rule condition is incorrect.
Which TWO statements are true about using ServiceNow Studio for application development?
Studio provides a guided interface to create application files such as tables, business rules, and client scripts.
Studio is designed to streamline creation of application artifacts.
Studio requires a separate HI (High-Impact) instance to develop applications.
When creating a new application in Studio, a new scope is automatically generated without user input.
Studio can only be used by users with the admin role.
Studio allows integration with source control systems like Git for version management.
Studio supports source control integration for managing application versions.
Want more Application development using ServiceNow Studio practice?
Practice this domain11% of exam · 6 sample questions below
A developer is creating a custom table for tracking hardware assets. The table must have fields for asset tag, serial number, and purchase date. The developer wants to ensure that the asset tag is automatically generated using a prefix followed by an incrementing number. Which approach should the developer use?
Use a calculated value that dot-walks to a number table
Set the default value of the asset tag field to 'AST-' + sys_id
Create a business rule that calculates the asset tag using a script that increments a counter
A business rule runs server-side on insert, letting a script query the current maximum and generate the next prefixed, incrementing asset tag before the record saves. This guarantees uniqueness and automatic generation, which a client-side default or UI policy cannot reliably enforce.
Configure a dictionary override on the asset tag field to auto-generate
An organization has a custom table 'u_incident_task' that extends 'task'. They need to allow users to create records in this table from the 'Incidents' module. The 'u_incident_task' table should appear as a related list on the incident form. However, the related list is not showing the 'New' button. What is the most likely cause?
There is no reference field on 'u_incident_task' pointing to the incident table
A related list's New button requires a reference field on the child table pointing back to the parent. Without that reference from u_incident_task to the incident table, ServiceNow cannot establish the relationship, so the New button is suppressed on the incident form.
The table is in a different application scope
The table does not extend 'incident'
The user does not have the required role
A developer is working with a custom table 'u_project_task' that has a reference field 'u_project' pointing to the 'project' table. The developer wants to create a new field 'u_category' that lists values from a choice list, but the list should be filtered based on the value of 'u_project.u_type'. Which field type should be used?
Choice field with a dependent choice list
A dependent choice list filters its available options dynamically from another field's value. Referencing u_project.u_type lets u_category display only the qualifying choices, satisfying the requirement for a filtered list tied to the parent project's type.
Choice field with a static choice list
Calculated value using a script
Reference field to a table of categories
A company has a custom table 'u_employee' with fields: 'first_name', 'last_name', 'department'. They want to create a unique index on the combination of 'last_name' and 'department' to prevent duplicate entries. Where should this index be defined?
In the table schema map
In the table's dictionary record via the Indexes related list
Defining the index on the table's dictionary record via the Indexes related list enforces uniqueness at the database level, satisfying the requirement to prevent duplicate last_name and department combinations. A unique index on those two columns blocks any insert or update producing a duplicate pair, regardless of how records are created.
In the dictionary entry for each field
In the sys_dictionary table directly
A developer is creating a custom table 'u_project_risk' to track risks associated with projects. The table must: (1) Automatically set the 'state' field to 'Open' when a new record is created. (2) Prevent deletion of records if the state is 'Closed'. (3) Display a warning message when a user changes the state from 'In Progress' to 'Closed'. Which THREE approaches should the developer use?
Set a default value for the 'state' field to 'Open'
Default value sets initial state.
Create a before business rule to check state on update
Create a client script that shows a warning on state change
An onChange client script can show a message.
Create a business rule that aborts the delete operation on condition state='Closed'
A before delete business rule can abort.
Define a reference qualifier on the 'project' field
A developer implemented the client script shown in the exhibit to auto-populate the assigned-to field based on the task type. However, when the task type is changed, the assigned-to field is not updated. The server-side script 'TaskTypeAjax' is correctly defined and returns a valid sys_id. What is the most likely reason for the failure?
The client script does not check if oldValue is different from newValue
The Script Include 'TaskTypeAjax' is not client-callable
Client scripts can only invoke Script Includes whose client_callable property is true. Without it, the GlideAjax call to TaskTypeAjax fails silently, so the returned sys_id never reaches the onChange handler and assigned-to stays unchanged despite the server-side logic being valid.
The client script returns on isLoading, preventing execution
A UI policy is overriding the assigned-to field
Want more Creating and customizing tables and data practice?
Practice this domain11% of exam · 6 sample questions below
A ServiceNow developer is designing a portal for end users to submit requests. The requirements state that users should be able to track the status of their requests and receive notifications when the status changes. Which combination of ServiceNow features best meets these requirements?
Service Portal and Access Controls (ACLs)
Service Portal and Catalog Client Scripts
Service Portal and Notifications
Service Portal provides the end-user interface for submitting and tracking requests via widgets and record pages, while Notifications deliver automatic alerts when record status changes. Together they satisfy both stated requirements: self-service status tracking and event-driven status-change alerts, without custom development.
Service Portal and UI Policies
A developer is troubleshooting a Service Portal widget that loads slowly. The widget uses a server script that queries a large table without any filters. Which design change would most improve performance?
Add client-side caching using $scope
Load the widget using ng-if instead of ng-show
Create a custom table with only required fields
Add a filter condition in the GlideRecord query
An unfiltered GlideRecord performs a full table scan, so adding a filter condition lets the database return only matching rows, cutting query time. This directly satisfies the stem's constraint of a large table queried without filters.
A developer is designing a custom application with a table that stores sensitive employee data. The requirement is that only managers can view records where they are the manager of the employee. Which two configurations are needed to implement this requirement?
Use a UI Policy to set fields to read-only or invisible for non-managers
Create an ACL with a condition script that checks if the logged-in user is the manager of the record's employee
ACLs control read access based on conditions.
Create a new view that excludes sensitive fields
Create a Business Rule that deletes records if the user is not the manager
Use a Client Script to hide fields if the user is not the manager
A developer created a UI Script and a Client Script as shown. Both scripts set urgency and impact to '1' when priority is '1'. However, when the priority is changed to '1' on an existing record, the urgency and impact fields do not update. What is the most likely cause?
The UI Script is not being called because it is not associated with any form or event
Client Scripts require an explicit form association and event trigger to execute; without one, changing priority never invokes the script, so urgency and impact stay unchanged. The UI Script alone cannot drive that on-change behaviour, explaining why the fields fail to update.
The priority field is not a choice field, so onChange does not fire
The Client Script function name is incorrect; it should be 'onChangePriority'
The g_form API is deprecated and no longer works
Drag and drop the steps to create a new Update Set in ServiceNow into the correct order.
Navigate to Local Update Sets, then Click New, then Provide name and description, then Set state to In Progress, then Submit
This is the correct order because you first navigate to the correct module, create a new record, fill in required details, change the state to In Progress to capture changes, and finally submit to save.
Navigate to Local Update Sets, then Click New, then Set state to In Progress, then Provide name and description, then Submit
Click New, then Navigate to Local Update Sets, then Provide name and description, then Set state to In Progress, then Submit
Navigate to Local Update Sets, then Click New, then Provide name and description, then Submit, then Set state to In Progress
When designing a custom portal page, the developer notices that the page layout breaks on mobile devices. What is the most efficient approach to ensure responsiveness?
Add a media query for each device
Implement Bootstrap grid classes
Bootstrap's mobile-first grid classes apply responsive breakpoints directly to the markup, so columns reflow at each viewport width without bespoke CSS. This satisfies the stem's efficiency constraint: the developer adds predefined classes rather than authoring custom media queries, quickly restoring the layout across mobile devices.
Use fixed pixel widths
Use a single-column layout
Want more Designing interfaces and user experiences practice?
Practice this domain11% of exam · 6 sample questions below
A company has a custom table 'u_asset' with a reference field 'u_location' pointing to 'cmn_location'. When a user changes the location on an asset record, the system must automatically update the location on all related 'u_asset_software' records. Which approach should the developer use?
Create a Client Script that runs on load to update related records.
Create an ACL to automatically propagate changes.
Create a Business Rule that runs on update of the 'u_asset' table and updates related records.
A Business Rule running on update of u_asset executes server-side whenever the record is saved, letting it query and update all related u_asset_software records in one transaction. This satisfies the requirement to propagate the changed location automatically to every related record.
Create a UI Policy that sets the location field on related records.
A developer is creating a catalog item that requires a user to upload a file. Which variable type should be used?
Attachment
The Attachment variable type renders a file upload control on the catalog item, storing the submitted file as an attachment record linked to the request. This directly satisfies the requirement that a user upload a file, unlike string or reference types.
Multi Line Text
Single Line Text
Checkbox
A company has a custom table 'u_incident_task' that extends 'task'. The developer wants to add a field 'u_approval' that is a reference to 'sysapproval_approver'. Which method is the correct way to create this field?
Create a 'List' field type and set the table to sysapproval_approver.
Create a 'Reference' field and set the reference table to 'sysapproval_approver'.
A Reference field type stores a sys_id pointing to a record in another table, so setting its reference table to sysapproval_approver links each u_incident_task record to the appropriate approval record. This matches the requirement for a field referencing sysapproval_approver.
Create a 'Reference' field and set the table to 'task' and the reference field to 'sysapproval_approver'.
Create a 'Choice' field and populate it with sysapproval_approver values.
A developer needs to create a service catalog variable that allows the user to select multiple values from a predefined list. Which variable type should be used?
Single Line Text
Radio Button
Select Box
Multiple Choice (Checkbox)
Multiple Choice (Checkbox) renders a predefined list of choices with checkboxes, letting the user select several values and storing them as a comma-separated set. A standard Choice variable permits only one selection, so it cannot satisfy the multi-select requirement.
Which THREE of the following are true about ACLs (Access Control Lists)? (Choose three.)
ACLs can include conditions that must be met for access.
ACLs evaluate condition statements, such as field values or role checks, before granting access to a record or operation. This conditional evaluation is a defining characteristic, satisfying the question's requirement to identify genuine ACL capabilities rather than misconceptions.
ACLs are evaluated on the client side.
ACLs are only applicable to system tables.
ACLs can control read and write access to records.
ACLs grant or deny read, write, create and delete operations on records, so they directly govern read and write access. This operation-level control is a core ACL characteristic, satisfying the question's requirement to identify true statements about what ACLs can do.
ACLs can be scoped to a specific application.
ACLs can be configured against a specific application scope, restricting their enforcement to that application's tables and records. This scoping capability is a genuine ACL feature, satisfying the question's requirement to identify accurate characteristics rather than common misconceptions.
Which TWO of the following are types of UI Policies? (Choose two.)
On change
On change UI Policies run when a specified field's value changes on the form, applying mandatory, read-only or visible actions dynamically. This is one of the two UI Policy types, alongside on load, and satisfies the stem's requirement to identify a valid UI Policy type.
On load
On load UI Policies execute when the form loads, applying their actions immediately regardless of user interaction. This is one of the two UI Policy types, alongside on change, and satisfies the stem's requirement to identify a valid UI Policy type.
On submit
On delete
On query
Want more Core Application Development practice?
Practice this domain11% of exam · 6 sample questions below
A developer is asked to add a custom button to the Service Portal form for the 'incident' table. The button should trigger a client script that displays a confirmation dialog before submitting the form. Which approach should the developer use?
Create a UI Policy on the incident table with a client script that shows the button conditionally.
Create an Access Control Rule (ACL) on the incident table and attach a client script.
Create a Business Rule on the incident table that injects a button via server-side code.
Create a UI Action on the incident table with a client script and set the 'Show insert' condition.
Correct. UI Actions allow adding custom buttons to forms and attaching client scripts. By setting the 'Show insert' condition appropriately, the button can be displayed on the form and execute a client script that shows a confirmation dialog before submission.
A Service Portal widget is failing to update a reference field on a form after a user selects a value from a reference picker. The developer reviews the widget's client controller and sees the following code snippet: $scope.c.data.selectedItem = value; The server script expects 'selectedItem' to be a sys_id string, but it is receiving an object. What is the most likely cause?
The server script expects the parameter in a different scope variable, like $scope.c.data.item.
The $scope.c.data assignment is incorrect; it should be $scope.data.
The client controller is not allowed to set $scope.c variables.
The reference field returns an object with 'value' and 'display' properties; the code should extract the sys_id.
Service Portal reference pickers bind the full GlideRecord-style object, not the sys_id, so assigning it directly stores an object the server script cannot parse. Extracting value (the sys_id) before assignment satisfies the stem's constraint that the server expects a sys_id string.
When configuring a Service Portal page, a developer wants to ensure that a specific widget appears only to users with the 'itil' role. Which approach should be used?
Pass a role check from the server script to the client controller via widget options.
Write an Access Control Rule (ACL) on the widget's table to restrict access.
Set the 'Roles' property on the widget instance within the page designer.
Widget instances expose a Roles property in the page designer that gates rendering by role. Setting it to 'itil' means the widget's server-side rendering is skipped for users lacking that role, hiding it without custom scripting.
Create a UI Policy on the portal table that hides the widget based on user roles.
A developer is designing a custom form in the standard UI (UI16) and needs to add a message that displays only when the 'state' field is 'Closed'. Which feature should be used to achieve this without custom scripting?
Create a UI Policy that adds a message when the condition state=Closed is true.
A UI Policy evaluates the state=Closed condition client-side and can display a message via its "Add message" action, requiring no scripting. This satisfies the stem's constraint of showing the message only when state equals Closed, while remaining within the standard UI16 form's declarative configuration.
Create a form section and set its condition via the 'Conditional' property.
Write a Client Script that shows a message when state changes to Closed.
Use a UI Macro with a condition that checks the state field.
A Service Portal widget is not updating data on the page after the user clicks a button that calls a server-side function. The client controller uses $scope.server.get() to call the server. The server script updates a global variable in glideRecord and returns it. However, the widget view does not reflect the change. What is the most likely issue?
The widget template is not bound to the correct scope variable.
The client controller should use $scope.server.update() instead of $scope.server.get().
The client controller is not handling the promise returned by $scope.server.get(); the scope update should be inside the success callback.
The promise returned by $scope.server.get() resolves asynchronously, so assigning the response to $scope outside its success callback leaves the view bound to stale data. Placing the scope update inside the callback ensures the widget re-renders once the server response arrives, satisfying the requirement that the page reflect the change.
The server script is not allowed to modify data from a widget server script.
Which THREE of the following are correct statements about Service Portal client controllers?
They can use AngularJS services like $http and $timeout.
Service Portal client controllers run as AngularJS controllers within the browser, so Angular's built-in $http and $timeout services remain injectable and usable for asynchronous calls and deferred execution. This satisfies the stem's requirement for a correct statement about client controller capabilities.
They run on the server and are called via server-side includes.
They must define a $scope variable explicitly to bind data to the template.
They can call the server using $scope.server.get() or $scope.server.post().
Service Portal exposes $scope.server.get() and $scope.server.post() as wrappers that invoke server-side scripts from the client controller, returning promises. This satisfies the stem's requirement for a correct statement, since these methods are the supported mechanism for client-to-server communication in widgets.
They are AngularJS controllers that handle client-side logic.
Service Portal client controllers are AngularJS controllers instantiated per widget, handling client-side logic such as scope binding and event handling. This satisfies the stem's requirement for a correct statement, since the framework is built on AngularJS and controllers govern the widget's browser-side behaviour.
Want more User Interface Development practice?
Practice this domainThe SNOW-CAD exam has 60 questions and must be completed in 90 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 9 domains: Integrating and managing application data, Platform Features and Integration, Working with Data, Automating application logic with business rules and scripts, Application development using ServiceNow Studio, Creating and customizing tables and data, Designing interfaces and user experiences, Core Application Development, User Interface Development. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ServiceNow SNOW-CAD exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.