Courseiva

CISA ITIL Priority Levels Practice Question

An IS auditor is reviewing the ITIL incident management process. Which THREE are the correct priority levels and their typical definitions?

⚠ Common exam trap

Watch out — candidates often confuse P2 with low impact or normal service hours, but ITIL defines P2 as high impact requiring urgent response, not low impact, and P4 is never critical impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

P1: Critical impact, immediate response required.

Option A is correct because P1 is the highest priority level in ITIL incident management, reserved for critical impact incidents (e.g., major outages affecting the whole organization) that demand immediate response and often major incident procedures. Option D is correct because P2 represents high-impact incidents requiring an urgent response, typically affecting a significant user group or critical business function but not as catastrophically as P1. Option E is correct because P3 denotes moderate impact incidents handled with a standard response time under normal service desk workflows. Option B is incorrect because P4 is the lowest priority (low impact, minor issue), not a critical-impact level requiring senior management escalation. Option C is incorrect because P2 is not defined as low impact resolved within normal service hours; that description better fits P4 or P3, whereas P2 requires urgent attention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    P1: Critical impact, immediate response required.

    Why this is correct

    P1 denotes the highest priority, reserved for incidents causing critical business impact or major service outage, demanding immediate response and continuous effort until resolution. This matches the ITIL priority matrix, where priority derives from impact and urgency, so P1 definitions must reflect severe disruption requiring escalation.

  • ✗

    P4: Critical impact, requires escalation to senior management.

    Why it's wrong here

    ITIL priority levels run P1 highest to P4 lowest, so P4 denotes minimal impact and routine handling, not critical impact with senior-management escalation — that describes P1. It is tempting because the P-numbering looks like a severity ranking where higher numbers mean worse, but priority and impact scales both descend from P1.

  • ✗

    P2: Low impact, can be resolved within normal service hours.

    Why it's wrong here

    P2 denotes high impact with significant service degradation, not low impact resolvable within normal hours — that is P4. It is tempting because the scale descends from P1, so a mid-number feels minor, but P2 typically demands urgent attention and workarounds, often outside standard hours.

  • ✓

    P2: High impact, requires urgent response.

    Why this is correct

    P2 denotes high impact with an urgent response requirement, matching ITIL's priority matrix where priority derives from impact multiplied by urgency. This satisfies the stem's demand for a correct priority level and its typical definition, distinguishing it from P1 (critical) and P3 (medium), which carry different response expectations.

  • ✓

    P3: Moderate impact, standard response time.

    Why this is correct

    P3 denotes moderate impact with standard response time, sitting below P1 and P2 severity. This matches the stem's requested priority definition, confirming the tiering scheme distinguishes impact and urgency so resources are allocated proportionately across incident levels.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.