Courseiva

ITIL 4 Foundation (ITIL4F) — Questions 151–225

805 questions total · 11pages · All types, answers revealed

Page 2

Page 3 of 11

Page 4
151
MCQhard

During a service review, a customer states that the service 'works well' but they are not achieving the expected business benefits. According to ITIL 4, this indicates a shortfall in which aspect of the service?

A.Utility
B.Warranty
C.Risk
D.Cost
AnswerA

Utility concerns the functionality offered by a service and whether it enables the customer's required outcomes — "fit for purpose". The customer confirms the service performs ("works well") yet business benefits are absent, so the shortfall lies in utility's outcome contribution, not warranty's assurance of availability, capacity, security or continuity.

Why this answer

Utility in ITIL 4 refers to the functionality offered by a service to meet a specific need—the 'what it does' that enables desired business outcomes. When the customer says the service 'works well' but fails to deliver expected business benefits, the shortfall is in utility, because the service's features or capabilities are not aligned with or sufficient to achieve the intended outcomes. This is distinct from warranty, which covers availability, capacity, continuity, and security—the 'how it is delivered'.

Exam trap

The trap here is that candidates confuse 'works well' (which implies good warranty) with overall service success, and incorrectly assume the problem must be warranty-related, when ITIL 4 explicitly separates utility (fitness for purpose) from warranty (fitness for use).

How to eliminate wrong answers

Option B (Warranty) is wrong because warranty ensures the service is available, reliable, and secure when needed; the customer already stated the service 'works well', so warranty is not the issue. Option C (Risk) is wrong because risk is an inherent uncertainty that could affect outcomes, but the question explicitly describes a gap in achieving expected benefits, not a risk event or mitigation failure. Option D (Cost) is wrong because cost relates to the financial resources consumed by the service; the customer's complaint is about missing business benefits, not about the service being too expensive or over budget.

152
MCQhard

A service provider develops a new software feature that works flawlessly (output) but fails to increase user productivity (outcome). Which statement is correct?

A.The output is poor, but the outcome is good
B.The output is good, but the outcome is poor
C.Neither output nor outcome is satisfactory
D.Both output and outcome are satisfactory
AnswerB

This option is correct. The 'output' refers to the tangible deliverable, which is the new software feature itself. Since the feature 'works,' the output is considered good or satisfactory, meeting its technical specifications. However, the 'outcome' represents the actual benefit or result achieved for the stakeholders, such as increased productivity. If the working feature fails to deliver this desired benefit, then the outcome is poor, despite the functionality of the output.

Why this answer

In ITIL 4, an output is a tangible deliverable (e.g., a software feature), while an outcome is the actual result or value achieved for the business (e.g., increased user productivity). The question states the feature works flawlessly (good output) but fails to increase productivity (poor outcome). Therefore, option B is correct because it accurately distinguishes between a technically successful output and a failed business outcome.

Exam trap

The trap here is confusing technical perfection (output) with business value (outcome), leading candidates to assume a flawless feature automatically delivers good outcomes, which ITIL 4 explicitly separates.

How to eliminate wrong answers

Option A is wrong because it claims the output is poor when the feature works flawlessly, and the outcome is good when productivity did not increase. Option C is wrong because it states neither output nor outcome is satisfactory, but the output is explicitly described as flawless. Option D is wrong because it claims both are satisfactory, but the outcome (increased productivity) was not achieved.

153
MCQhard

An IT team develops a new mobile app that reduces customer response time from 4 hours to 30 minutes. Which statement best distinguishes the output from the outcome?

A.The app is the output; faster response time is the outcome
B.Both are outcomes because they improve customer satisfaction
C.Both are outputs because they are tangible deliverables
D.Faster response time is the output; the app is the outcome
AnswerA

The mobile app itself is a tangible deliverable, directly produced by the IT team's development activity, making it an output. The faster response time, however, represents the benefit or change experienced by customers (stakeholders) as a result of using that app. This improved efficiency and customer experience is the desired outcome, demonstrating the value derived from the output.

Why this answer

The output is the tangible deliverable (the mobile app), while the outcome is the measurable business result (reduced customer response time from 4 hours to 30 minutes). In ITIL 4, outputs are what the organization produces, and outcomes are the value realized by stakeholders. Here, the app itself does not create value until it is used to achieve faster response times.

Exam trap

The trap here is that candidates confuse tangible deliverables with measurable results, often misidentifying a business improvement as an output because it seems like a direct product of the project.

How to eliminate wrong answers

Option B is wrong because both are not outcomes; the app is a tangible output, and only the faster response time is the outcome that delivers value to customers. Option C is wrong because the faster response time is not a tangible deliverable but a measurable result, so it cannot be classified as an output. Option D is wrong because it reverses the definitions: the app is the output, and the faster response time is the outcome.

154
MCQmedium

A company is implementing a new ticketing system. The project team decides to use a large rollout after months of development, but later discovers many issues that could have been caught early. Which principle was NOT followed?

A.Focus on value
B.Optimise and automate
C.Progress iteratively with feedback
D.Keep it simple and practical
AnswerC

The company's use of a big-bang approach directly violated the 'Progress iteratively with feedback' principle. This principle advocates for breaking down work into smaller, manageable iterations, allowing for continuous learning, adaptation, and course correction based on stakeholder feedback at each stage. A big-bang deployment bypasses these crucial feedback loops, significantly increasing the risk of encountering unforeseen issues late in the process, leading to widespread failure when the entire system is launched simultaneously.

Why this answer

'Progress iteratively with feedback' advises against big-bang approaches and encourages timeboxed iterations with continuous feedback. The team ignored this by not iterating.

155
MCQeasy

Which ITIL 4 guiding principle emphasizes breaking down silos and making information visible to all relevant parties?

A.Think and work holistically
B.Collaborate and promote visibility
C.Keep it simple and practical
D.Focus on value
AnswerB

Collaborate and promote visibility directly addresses siloed working by mandating shared information across teams and stakeholders. It satisfies the stem's requirement to break down silos and make information visible, since the principle explicitly pairs cross-team collaboration with transparent, accessible communication, ensuring relevant parties can act on the same data.

Why this answer

The 'Collaborate and promote visibility' guiding principle directly addresses breaking down organizational silos and ensuring that information, work in progress, and constraints are visible to all relevant stakeholders. This principle reduces rework, improves trust, and enables faster decision-making by making data accessible across teams, which is a core tenet of ITIL 4's service value system.

Exam trap

Candidates often confuse 'Collaborate and promote visibility' with 'Think and work holistically' because both involve cross-team coordination, but the former specifically targets information transparency and breaking down silos, while the latter is about understanding end-to-end system interactions.

How to eliminate wrong answers

Option A is wrong because 'Think and work holistically' focuses on understanding how all parts of the organization interact as a whole, not specifically on breaking down silos or making information visible. Option C is wrong because 'Keep it simple and practical' emphasizes eliminating unnecessary complexity and focusing on outcomes, not on cross-team visibility or collaboration. Option D is wrong because 'Focus on value' directs efforts toward delivering outcomes that matter to stakeholders, but it does not inherently address the structural or informational barriers between teams.

156
MCQeasy

Which practice involves the use of an improvement register?

A.Problem Management
B.Change Enablement
C.Continual Improvement
D.Service Level Management
AnswerC

The Continual Improvement practice is dedicated to aligning an organization's practices and services with changing business needs through the ongoing identification and improvement of all elements involved in the management of products and services. A central component of this practice is the Improvement Register, which serves as a structured database to capture, track, and manage all identified improvement opportunities from across the organization, ensuring they are prioritized, actioned, and reviewed for effectiveness. This register is crucial for maintaining visibility and driving the improvement lifecycle.

Why this answer

The Continual Improvement practice is responsible for identifying and managing improvement opportunities across all ITIL practices. The improvement register is a key tool used to log, track, and prioritize these improvement initiatives, ensuring they are systematically reviewed and acted upon.

Exam trap

The trap here is that candidates often confuse the improvement register with the service improvement plan (SIP) used in Service Level Management, but the SIP is a specific document for a single service, whereas the improvement register is a cross-practice repository for all improvement ideas.

How to eliminate wrong answers

Option A is wrong because Problem Management uses a problem record, not an improvement register, to manage the lifecycle of underlying causes of incidents. Option B is wrong because Change Enablement uses a change record and a change schedule to manage changes, not an improvement register. Option D is wrong because Service Level Management uses a service level agreement (SLA) and service improvement plan (SIP), but the improvement register is specifically a tool of the Continual Improvement practice, not Service Level Management.

157
Multi-Selecthard

Which TWO statements correctly describe the relationship between Service Level Management and other practices?

Select 2 answers
A.SLAs are used to manage supplier performance
B.SLAs are agreements between internal IT teams
C.SLAs define the detailed steps of the incident handling process
D.OLAs support the achievement of SLAs
E.SLAs provide targets for Incident Management
AnswersD, E

Operational Level Agreements (OLAs) are internal agreements between different departments or teams within the same service provider organization. Their primary purpose is to define the specific responsibilities, activities, and performance targets that each internal group must meet to collectively ensure the successful delivery of services and, consequently, the achievement of the customer-facing Service Level Agreements (SLAs). Without robust OLAs, internal coordination can falter, jeopardizing SLA compliance.

Why this answer

Option D is correct because Operational Level Agreements (OLAs) are internal agreements between teams within the same organization that underpin and support the delivery of the customer-facing SLA targets. Option E is correct because SLAs establish measurable service targets (such as availability, response, and resolution times) that Incident Management uses to prioritize and resolve incidents in line with agreed commitments. Option A is not correct because supplier performance is managed through contracts and Underpinning Contracts (UCs), not SLAs, which are agreements with customers.

Option B is not correct because agreements between internal IT teams are OLAs, not SLAs, which are customer-facing. Option C is not correct because the detailed steps of incident handling are defined in incident management procedures and work instructions, not in SLAs, which specify targets rather than process steps.

Exam trap

ITIL4F often tests the definitions and relationships between SLAs, OLAs, and other practices, so candidates might confuse SLAs with OLAs or think SLAs define processes rather than targets.

158
MCQeasy

What is the PRIMARY purpose of the 'Improve' value chain activity in the ITIL 4 service value chain?

A.To coordinate the planning of resources
B.To obtain or build service components
C.To drive continual improvement of services and practices
D.To ensure agreed service levels are delivered
AnswerC

The 'Improve' value chain activity is specifically designed to ensure the continual improvement of products, services, and practices across all value chain activities and the four dimensions of service management. Its primary purpose is to identify and manage improvement opportunities, translating them into actionable initiatives to enhance value delivery and optimize organizational performance. This activity drives the ongoing enhancement cycle, making it the correct answer for its direct focus on improvement.

Why this answer

The 'Improve' value chain activity is specifically defined in ITIL 4 to drive continual improvement of services, practices, and all elements of the service value system. It ensures that feedback, metrics, and lessons learned are systematically used to enhance performance and value delivery. This aligns directly with the ITIL guiding principle of 'Continual Improvement' and the Plan-Do-Check-Act (PDCA) cycle.

Exam trap

The trap here is that candidates confuse 'Improve' with operational activities like resource planning or service delivery, because they think 'improvement' is just fixing broken services, but ITIL 4 specifically assigns proactive, systematic improvement to this distinct value chain activity.

How to eliminate wrong answers

Option A is wrong because coordinating the planning of resources is the primary purpose of the 'Plan' value chain activity, not 'Improve'. Option B is wrong because obtaining or building service components is the primary purpose of the 'Obtain/Build' value chain activity. Option D is wrong because ensuring agreed service levels are delivered is the primary purpose of the 'Deliver and Support' value chain activity, which focuses on service operations and meeting service level agreements (SLAs).

159
MCQeasy

Which ITIL 4 guiding principle recommends that you do not create unnecessary processes or documentation that do not add value?

A.Focus on value
B.Optimise and automate
C.Progress iteratively with feedback
D.Keep it simple and practical
AnswerD

The "Keep it simple and practical" guiding principle directly advises organizations to use the minimum number of steps necessary to achieve a desired outcome, eliminating anything that does not add value. It explicitly states that if a process, service, action, or metric provides no value or produces no useful outcome, it should be removed. This principle directly addresses the avoidance of unnecessary complexity and bureaucracy, advocating for straightforward, pragmatic solutions that are easy to understand and implement.

Why this answer

The 'Keep it simple and practical' guiding principle emphasizes minimizing complexity by only creating processes, documentation, or steps that directly contribute to value delivery. In ITIL 4, this means avoiding unnecessary overhead like excessive approval workflows or verbose runbooks that do not improve service outcomes. The correct answer is D because it directly addresses the removal of non-value-adding activities.

Exam trap

The trap here is that candidates confuse 'Focus on value' (which is about outcomes) with the specific directive to cut unnecessary complexity, leading them to pick A instead of D.

How to eliminate wrong answers

Option A is wrong because 'Focus on value' prioritizes delivering outcomes that customers perceive as valuable, but it does not specifically target the elimination of unnecessary processes or documentation. Option B is wrong because 'Optimise and automate' focuses on improving efficiency through technology and streamlining, but it assumes the process itself is already necessary and value-adding. Option C is wrong because 'Progress iteratively with feedback' advocates for incremental improvements and continuous learning, not the direct removal of non-value-adding artifacts.

160
MCQeasy

Which ITIL 4 term describes the functionality offered by a product or service to meet a particular need?

A.Outcome
B.Utility
C.Output
D.Warranty
AnswerB

Utility directly describes the functionality offered by a service, defining what the service *does* and whether it is 'fit for purpose.' It addresses the specific requirements of the consumer, enabling them to perform tasks or achieve desired objectives. This term precisely captures the inherent capabilities and features that allow a service to support a consumer's performance or remove constraints.

Why this answer

Utility is the ITIL 4 term that defines the functionality offered by a product or service to meet a particular need. It directly addresses what the service does for the user—its core capability to solve a problem or enable an outcome. In ITIL 4, utility is often described as 'fit for purpose,' distinguishing it from warranty, which covers 'fit for use.'

Exam trap

The trap here is confusing 'utility' with 'outcome'—candidates often think the functionality directly produces the outcome, but utility is the enabler, while the outcome is the actual result experienced by the user.

How to eliminate wrong answers

Option A is wrong because an outcome is the result achieved by a stakeholder through the use of a service, not the functionality itself. Option C is wrong because an output is a tangible or intangible deliverable produced by an activity (e.g., a report or a processed transaction), not the service's capability to meet a need. Option D is wrong because warranty describes the assurance that a service will meet agreed requirements (availability, capacity, continuity, security), not the functionality it provides.

161
MCQmedium

A user requests a new laptop for a new employee. According to ITIL 4, how should this request be classified?

A.Problem
B.Service request
C.Emergency change
D.Incident
AnswerB

A Service Request is a formal request from a user for something standard that is part of normal service delivery, such as information, advice, a standard change, or access to a service. Provisioning a new laptop for a new employee is a classic example of a pre-defined, low-risk, and often automated service request, following established procedures for fulfillment.

Why this answer

The request for a new laptop for a new employee is a pre-defined, standardized request for a service or service component, which ITIL 4 classifies as a Service Request. This is because it follows an established procedure (e.g., ordering, provisioning, and configuring hardware) and does not involve restoring an unexpected outage or fixing a failure. The ITIL 4 Service Request Practice specifically covers such routine, low-risk, and low-cost requests that are part of normal service delivery.

Exam trap

The trap here is that candidates confuse a 'Standard Change' with a 'Service Request,' but ITIL 4 explicitly separates them: a Service Request is for requesting something (e.g., a laptop), while a Standard Change is a pre-approved change to an existing service (e.g., modifying a configuration), and the question's phrasing ('requests a new laptop') clearly fits the Service Request definition.

How to eliminate wrong answers

Option A is wrong because a Problem is the root cause of one or more Incidents, not a routine request for a new asset; a new laptop request has no underlying failure or unknown cause to diagnose. Option C is wrong because an Emergency Change is a high-risk, urgent change (e.g., applying a critical security patch to stop an active breach) that must be implemented as soon as possible, whereas provisioning a laptop follows a standard, pre-approved change model with no urgency or risk of service disruption. Option D is wrong because an Incident is an unplanned interruption or reduction in quality of an IT service (e.g., a laptop that won't boot), not a planned request for a new resource that is part of normal operations.

162
MCQeasy

What is the definition of 'utility' in ITIL 4?

A.The functionality offered by a service to meet a specific need
B.The cost incurred by the service consumer
C.The risks removed from the consumer by using the service
D.The assurance that a service will perform as agreed
AnswerA

In ITIL 4, utility is precisely defined as the functionality provided by a service to address a particular requirement or achieve a specific outcome for the consumer. It describes whether a service is "fit for purpose," meaning it possesses the necessary features and performance capabilities to support the consumer's objectives. This concept focuses on the tangible value derived from the service's core functions, enabling the consumer to perform tasks or achieve goals effectively.

Why this answer

In ITIL 4, 'utility' is defined as the functionality offered by a service to meet a specific need. It represents the 'what' of the service—the features and capabilities that enable the service to deliver the desired outcome, such as processing a transaction or providing access to data. This is distinct from 'warranty,' which covers how the service is delivered reliably.

Exam trap

The trap here is that candidates often confuse 'utility' with 'warranty' or 'value,' especially when options mention risk removal or assurance, which are related but distinct concepts in ITIL 4's service definition.

How to eliminate wrong answers

Option B is wrong because cost incurred by the service consumer is not part of utility; it relates to the service's value proposition and is considered separately in cost-benefit analysis. Option C is wrong because risks removed from the consumer are a potential benefit of using the service, but utility specifically refers to the functionality that enables risk reduction, not the risk removal itself. Option D is wrong because assurance that a service will perform as agreed is the definition of 'warranty' in ITIL 4, not utility.

163
Matchingmedium

Match each ITIL 4 practice to its primary purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Restore normal service operation as quickly as possible

Prevent incidents and minimize impact of those that cannot be prevented

Ensure changes are assessed, approved, and implemented in a controlled manner

Handle pre-defined, user-initiated service requests

Provide a single point of contact for users and customers

Why these pairings

The correct matches are: Incident Management restores service after incidents; Problem Management identifies root causes; Change Enablement controls changes; and Service Request Management handles user requests. Common confusions involve swapping Incident and Problem Management or mistaking Change Enablement for Incident Management.

164
Multi-Selecteasy

Which THREE are ITIL 4 guiding principles?

Select 3 answers
A.Manage risk
B.Focus on value
C.Keep it simple and practical
D.Optimise and automate
E.Ensure security
AnswersB, C, D

"Focus on value" is indeed one of the seven ITIL 4 guiding principles, emphasizing that all activities performed by the organization should directly or indirectly create value for its stakeholders, including customers, users, and the organization itself. This principle encourages understanding the customer's perspective and ensuring that every service management effort contributes to tangible outcomes and perceived benefits. Value can encompass financial, experiential, or strategic benefits.

Why this answer

The ITIL 4 guiding principles are universal recommendations that guide an organization in all circumstances, and among the listed options, 'Focus on value' (B) is correct because it directs every activity toward creating value for stakeholders, which is the core purpose of service management. 'Keep it simple and practical' (C) is correct because ITIL 4 explicitly recommends using the minimum number of steps needed to accomplish an objective and eliminating anything that does not add value. 'Optimise and automate' (D) is correct because it is a named guiding principle that advises organizations to optimize human effort and use technology to automate where it makes sense. The remaining options do not belong: 'Manage risk' (A) is a general management practice concern rather than a guiding principle, and 'Ensure security' (E) is likewise a practice/objective area, not one of the seven ITIL 4 guiding principles.

Exam trap

The trap here is that candidates often confuse the ITIL 4 guiding principles with the ITIL practices or concepts, such as 'risk management' or 'security', because these are heavily emphasised in other parts of the syllabus, but they are not among the seven defined principles.

165
MCQmedium

An IT service desk analyst receives a call from a user who cannot access the CRM system. The user says this happened after a recent password change. What should the analyst do FIRST, according to ITIL 4?

A.Log an incident record and attempt to resolve the access issue
B.Direct the user to fill out a service request form for password assistance
C.Submit a change request to reverse the password change
D.Create a problem record to investigate why the password change caused the issue
AnswerA

The user's inability to access services due to a password issue constitutes an unplanned interruption to a service, which is the definition of an incident in ITIL 4. The primary objective of incident management is to restore normal service operation as quickly as possible, minimizing business impact. Logging the incident ensures it is properly tracked, prioritized, and managed through to resolution, aligning with ITIL's incident management practice.

Why this answer

According to ITIL 4, the analyst's first action should be to log an incident record and attempt to resolve the access issue. This aligns with the incident management practice, which prioritizes restoring normal service operation as quickly as possible. The user's inability to access the CRM system after a password change is a clear incident (an unplanned interruption or reduction in quality of an IT service), and the analyst should immediately capture the details and work toward a resolution, such as resetting the password or verifying account synchronization with the identity provider (e.g., Active Directory or LDAP).

Exam trap

The trap here is that candidates confuse incident management with problem management or change management, mistakenly thinking that a password change issue automatically warrants a problem investigation or a formal change reversal, when ITIL 4 mandates that restoring service (incident management) is the immediate priority.

How to eliminate wrong answers

Option B is wrong because directing the user to fill out a service request form for password assistance treats the issue as a standard service request (a pre-defined, low-risk request for a service), but the user is already experiencing an active service outage, which requires incident management to restore service quickly, not a separate request process. Option C is wrong because submitting a change request to reverse the password change is premature and bypasses the incident management process; the analyst should first attempt to resolve the incident (e.g., by resetting the password or checking account lockout policies) rather than initiating a formal change, which would delay restoration of service. Option D is wrong because creating a problem record to investigate why the password change caused the issue is a reactive step that should only occur after the incident is resolved; problem management focuses on identifying the root cause of incidents to prevent recurrence, not on immediate service restoration.

166
MCQhard

Refer to the exhibit. The monthly report shows that the availability target was met but the response time target was not. What should the service provider do to improve response time?

A.Close the incident as it is resolved and focus on other issues
B.Increase the response time target to 99%
C.Adjust the availability target to 99.95%
D.Analyze the incident from March 15 to identify the root cause of slow transactions
AnswerD

Analyzing the incident from March 15 to identify the root cause of slow transactions aligns directly with ITIL's Problem Management practice. This proactive approach seeks to understand the underlying issues causing performance degradation, rather than just resolving symptoms. By identifying the root cause, the organization can implement permanent solutions, prevent recurrence of slow transactions, and improve overall service quality and user satisfaction.

Why this answer

The incident from March 15 is the only event where response time degraded (slow transactions), and analyzing its root cause is the proper ITIL problem management practice. Simply closing the incident (A) ignores the underlying issue, while adjusting targets (B, C) does not fix the actual performance problem. Root cause analysis (D) enables the service provider to identify and resolve the specific technical bottleneck, such as database contention or network latency, that caused the slow response.

Exam trap

The trap here is that candidates confuse adjusting service level targets (a reactive, non-solution) with performing root cause analysis (the correct ITIL problem management action), thinking that changing a metric can fix a performance issue.

How to eliminate wrong answers

Option A is wrong because closing the incident without resolving the root cause of slow transactions means the response time target will continue to be missed; ITIL requires problem management to prevent recurrence. Option B is wrong because increasing the response time target to 99% does not improve actual performance—it merely lowers the bar, which violates the principle of continual improvement and does not address the underlying technical issue. Option C is wrong because adjusting the availability target to 99.95% is irrelevant to response time; availability measures uptime, not transaction speed, and changing it does not fix slow queries or application delays.

167
MCQhard

A user submits a request to reset their password. The service desk handles this by following a pre-approved standard procedure. According to ITIL 4, this is classified as:

A.A service request
B.A change request
C.An incident
D.A problem
AnswerA

A service request is a formal request from a user for something that is a normal part of service delivery, typically pre-defined and pre-approved. A password reset is a classic example, as it is a common, routine action with a known procedure and expected outcome, often fulfilled through self-service or standard operating procedures. It falls squarely under the scope of standard service offerings.

Why this answer

A password reset is a standard, pre-approved request for a service action that does not involve a change to the service's risk profile or a deviation from normal operations. ITIL 4 defines a service request as a formal request from a user for something to be provided – for example, information, advice, or a standard change. Since the service desk follows a pre-approved procedure without requiring additional authorization, this fits the service request category exactly.

Exam trap

The trap here is that candidates confuse a 'standard change' with a 'service request' because both are pre-approved, but ITIL 4 reserves 'standard change' for modifications to services or infrastructure, while 'service request' is for user-initiated requests for information, advice, or access.

How to eliminate wrong answers

Option B is wrong because a change request involves a modification to a service or configuration item that requires assessment and authorization (e.g., via a change advisory board), whereas a password reset is a pre-approved standard activity with no risk of service disruption. Option C is wrong because an incident is an unplanned interruption or reduction in quality of an IT service, but a password reset is a planned, routine request that does not indicate a service failure. Option D is wrong because a problem is the underlying cause of one or more incidents, not a user-initiated request for a standard action like a password reset.

168
MCQeasy

A user contacts the service desk because they cannot access a shared drive. The agent gathers information, identifies a known workaround, and restores the user's access. The user asks how the agent knew what to do so quickly. Which practice is MOST directly responsible for providing the documented workaround the agent used?

A.Service Configuration Management
B.Service Desk
C.Service Request Management
D.Knowledge Management
AnswerD

Knowledge Management maintains the body of information that supports all practices, including known errors, workarounds, and resolution steps. The agent could quickly apply the workaround because Knowledge Management had captured and made it available. This practice ensures that useful information is created, shared, and kept current across the organization.

Why this answer

Knowledge Management is the practice that creates, maintains, and shares information such as known errors and workarounds. The agent restored access quickly because the workaround had already been documented and made available. The Service Desk delivers the support, and Service Configuration Management records configuration items, but neither supplies the resolution knowledge used here.

Exam trap

The trap here is crediting the Service Desk for the workaround simply because the agent delivered it, rather than recognizing Knowledge Management as the source of the content.

169
MCQmedium

A change request that is low risk and follows a pre-approved procedure is classified as which type of change?

A.Standard change
B.Emergency change
C.Normal change
D.Service request
AnswerA

A standard change is a low-risk, pre-authorized change that is well-understood, fully documented, and often implemented as a service request. These changes follow a defined procedure, do not require additional authorization each time they are implemented, and are typically initiated to deliver a new or changed service feature or to resolve a common issue. Their pre-approval streamlines the change process for routine activities, ensuring efficiency while maintaining control and predictability within the service environment.

Why this answer

A Standard change is the correct classification because it is pre-approved, low-risk, and follows a documented, repeatable procedure. ITIL 4 defines a Standard change as one that is fully authorized in advance, requires no additional approval, and is executed through a defined workflow, such as a routine server patch or password reset.

Exam trap

The trap here is that candidates often confuse a Standard change with a Service request, but ITIL 4 distinguishes them by the fact that a Service request is for something pre-defined and not a change to a service (e.g., 'reset password'), whereas a Standard change is a pre-approved change to a service (e.g., 'apply patch').

How to eliminate wrong answers

Option B is wrong because an Emergency change is used for urgent, high-risk situations (e.g., a critical security vulnerability) that require expedited approval, not for low-risk, pre-approved procedures. Option C is wrong because a Normal change follows a full lifecycle of assessment and approval by a Change Authority (e.g., CAB), which is not needed for low-risk, pre-approved work. Option D is wrong because a Service request is a formal request for something pre-defined (e.g., access to an application), not a change to an IT service; while it may be low-risk, it is not a change to a service's configuration or state.

170
Multi-Selectmedium

Which THREE of the following are elements of value co-creation according to ITIL 4?

Select 3 answers
A.The consumer actively participates in the service relationship
B.The provider and consumer work together to create value
C.The provider delivers outputs without consumer involvement
D.The consumer uses the provider's resources to achieve outcomes
E.Value is delivered by the provider to the consumer
AnswersA, B, D

Value co-creation requires the consumer to actively participate in the service relationship rather than passively receive output. This satisfies the stem's focus on co-creation elements, since value emerges through interaction between provider and consumer, not from the provider alone.

Why this answer

According to ITIL 4, value co-creation requires active collaboration between provider and consumer rather than one-way delivery. Option A is correct because the consumer must actively participate in the service relationship, contributing inputs, feedback, and engagement that shape the service. Option B is correct because value is co-created when the provider and consumer work together, combining their respective resources and capabilities.

Option D is correct because the consumer applies the provider's resources (such as people, information, and technology) to achieve its own desired outcomes, which is the essence of value realization. Option C is incorrect because delivering outputs without consumer involvement contradicts the co-creation principle, which demands participation. Option E is incorrect because value is not simply delivered by the provider to the consumer; it emerges through joint interaction and the consumer's use of the service.

Exam trap

The trap here is that candidates often confuse 'value delivery' (a one-way provider-to-consumer model) with 'value co-creation' (a bidirectional partnership), leading them to select option E as correct when it is actually a misconception from older service management paradigms.

171
MCQhard

A software vendor provides a cloud-based CRM. The service contract includes uptime guarantees and response times for support. Which aspect of service value is primarily addressed by these contractual terms?

A.Output
B.Outcome
C.Utility
D.Warranty
AnswerD

Warranty provides assurance that a product or service will meet agreed requirements, describing 'how' the service performs. This includes aspects such as availability, capacity, security, and continuity. When a software vendor provides a cloud-based CRM, they are implicitly or explicitly guaranteeing these non-functional requirements, ensuring the service is 'fit for use' and operates reliably according to specified service levels.

Why this answer

The contractual terms specifying uptime guarantees and response times directly address the 'Warranty' aspect of service value. Warranty ensures that a service will be available, secure, and perform consistently as agreed, which is exactly what uptime SLAs and support response times define. In contrast, 'Utility' covers the functionality or 'fit for purpose' of the CRM, not its availability or support commitments.

Exam trap

The trap here is that candidates confuse 'Utility' (what the service does) with 'Warranty' (how well it is delivered), leading them to pick Utility because they think uptime is a feature of the service, when in fact it is a guarantee of performance.

How to eliminate wrong answers

Option A is wrong because 'Output' is not a dimension of service management in ITIL 4; it refers to the tangible deliverables of a process, not contractual guarantees. Option B is wrong because 'Outcome' describes the business result enabled by the service (e.g., increased sales efficiency), not the uptime or response time promises. Option C is wrong because 'Utility' defines what the service does (its functionality), such as CRM features like contact management or reporting, not the assurance of availability or support responsiveness.

172
MCQmedium

A service provider is designing a new service. Which dimension addresses the contracts and sourcing strategy?

A.Information and Technology
B.Organizations and People
C.Partners and Suppliers
D.Value Streams and Processes
AnswerC

This option is correct because the Partners and Suppliers dimension explicitly addresses the relationships an organization has with other organizations that are involved in the design, development, delivery, support, and improvement of services. When designing a new service, a service provider frequently needs to consider external collaborations, contracts, and the entire supply chain to acquire necessary components, expertise, or capabilities, making this dimension highly relevant.

Why this answer

The Partners and Suppliers dimension of the ITIL 4 four dimensions model specifically addresses the organization's relationships with external parties, including contracts, agreements, and sourcing strategies. When designing a new service, this dimension ensures that the service provider considers how external vendors, suppliers, and partners will contribute to the service delivery, including the contractual terms and the strategic approach to sourcing (e.g., insourcing vs. outsourcing).

Exam trap

The trap here is that candidates often confuse the Partners and Suppliers dimension with the Information and Technology dimension, mistakenly thinking that contracts and sourcing are purely technical or data-related, when in fact they are about external relationships and governance.

How to eliminate wrong answers

Option A is wrong because the Information and Technology dimension focuses on the information assets, technology architecture, and the systems required to support the service, not on contracts or sourcing strategy. Option B is wrong because the Organizations and People dimension deals with the internal organizational structure, roles, responsibilities, and culture of the service provider, not external contracts or sourcing decisions. Option D is wrong because the Value Streams and Processes dimension covers the workflows, activities, and procedures needed to deliver the service, but does not address the contractual or sourcing relationships with external parties.

173
MCQmedium

An IT department is planning to introduce a new monitoring tool. They want to ensure the tool is effective before full rollout. Which service value chain activity should they perform first?

A.Improve
B.Obtain/Build
C.Design and Transition
D.Plan
AnswerD

The 'Plan' value chain activity establishes a shared understanding of the vision, current status, and improvement direction for all four dimensions of service management and all products and services across the organization. Introducing a new monitoring tool necessitates this foundational planning to define its purpose, scope, resource requirements, and how it aligns with overall organizational strategy. This initial activity sets the stage for all subsequent actions, ensuring alignment and effective resource allocation.

Why this answer

The Plan activity is the correct first step because it ensures the monitoring tool's objectives, scope, and success criteria are defined before any development or deployment begins. Without a clear plan, the IT department risks selecting or building a tool that does not align with business needs or service requirements, leading to wasted effort and ineffective monitoring.

Exam trap

The trap here is that candidates often jump to 'Design and Transition' because they think of the tool's deployment lifecycle, but ITIL 4 emphasizes that planning must precede any design or build activity to ensure alignment with value and strategy.

How to eliminate wrong answers

Option A (Improve) is wrong because improvement activities occur after the tool is in use, based on feedback and performance data, not before selection. Option B (Obtain/Build) is wrong because acquiring or developing the tool should only happen after planning defines what is needed. Option C (Design and Transition) is wrong because design and transition activities follow planning; they assume the tool's requirements and architecture are already established.

174
MCQeasy

An IT team decides to reduce the number of steps in a change approval process to speed up delivery. Which guiding principle are they applying?

A.Progress iteratively with feedback
B.Optimise and automate
C.Start where you are
D.Keep it simple and practical
AnswerD

The 'Keep it simple and practical' principle advocates for eliminating anything that does not contribute to value creation, focusing on the minimum necessary steps to achieve the desired outcome. Reducing the number of steps in a change process directly aligns with this by removing unnecessary complexity, bureaucracy, and waste, ensuring the process remains efficient, effective, and easy to understand and execute for all stakeholders.

Why this answer

By reducing the number of steps in a change approval process, the team is eliminating unnecessary complexity and bureaucracy. This directly aligns with the 'Keep it simple and practical' guiding principle, which advocates for minimizing process overhead to achieve outcomes efficiently. The focus is on streamlining the workflow itself, not on automation or iterative feedback.

Exam trap

The trap here is that candidates often confuse 'reducing steps' with 'automation' (Option B), but the question explicitly states they are reducing the number of steps, not automating the existing ones, which is a key distinction in ITIL 4's guidance on simplification before automation.

How to eliminate wrong answers

Option A is wrong because 'Progress iteratively with feedback' focuses on delivering value in small increments and using feedback to adjust, not on simplifying an existing process by removing steps. Option B is wrong because 'Optimise and automate' would apply if the team were using technology to speed up the existing steps (e.g., automated approvals), but here they are removing steps entirely, which is simplification before optimization. Option C is wrong because 'Start where you are' means understanding the current state before making changes, but the question describes the action taken (reducing steps), not the initial assessment phase.

175
MCQeasy

Which ITIL 4 practice is responsible for maintaining the CMDB and ensuring configuration items are accurate?

A.Service Desk
B.IT Asset Management
C.Service Configuration Management
D.Change Enablement
AnswerC

Service Configuration Management is the ITIL practice specifically tasked with ensuring that accurate and reliable information about the configuration of services and the Configuration Items (CIs) that support them is available when and where needed. This practice defines, identifies, controls, records, reports, and verifies all CIs and their relationships within the Configuration Management Database (CMDB). Its core function is to maintain the integrity and accuracy of configuration data throughout the entire service lifecycle, making it directly responsible for the CMDB.

Why this answer

Service Configuration Management (C) is the ITIL 4 practice responsible for maintaining the Configuration Management Database (CMDB) and ensuring that Configuration Items (CIs) are accurate, up-to-date, and under controlled management. This practice focuses on defining, recording, and controlling CIs and their relationships, directly supporting the integrity of the CMDB.

Exam trap

The trap here is that candidates confuse IT Asset Management (B) with Service Configuration Management because both deal with tracking items, but IT Asset Management focuses on financial lifecycle and ownership, not the detailed configuration relationships and CMDB accuracy that Service Configuration Management owns.

How to eliminate wrong answers

Option A is wrong because the Service Desk practice handles incident and service request management, not the maintenance of the CMDB or CI accuracy. Option B is wrong because IT Asset Management focuses on the financial and lifecycle management of assets (e.g., procurement, depreciation), not the detailed configuration records and relationships stored in the CMDB. Option D is wrong because Change Enablement controls the process for approving and implementing changes, but it relies on the CMDB for impact analysis and does not itself maintain CI data.

176
Multi-Selectmedium

Which TWO of the following are true regarding the 'Optimise and automate' principle?

Select 2 answers
A.Automation can free up people for more complex tasks
B.Human intervention should be minimized where possible
C.Only technical activities should be automated
D.All manual steps should be automated immediately
E.Automation should be applied before optimization
AnswersA, B

This statement is correct and aligns perfectly with the ITIL guiding principle of "Optimize and automate." By automating repetitive, low-value, or high-volume tasks, organizations can significantly reduce the burden of mundane operational activities on their workforce. This strategic liberation of human resources enables skilled personnel to concentrate on more complex problem-solving, strategic initiatives, innovation, and tasks requiring critical thinking or complex decision-making, thereby increasing overall organizational value and efficiency.

Why this answer

Automation, when applied after optimization, reduces manual effort for repetitive tasks, freeing people to focus on complex, value-adding activities like problem-solving and innovation. This aligns with the ITIL 4 guiding principle 'Optimise and automate,' which emphasizes that automation should be applied to optimized processes to maximize efficiency and human potential.

Exam trap

The trap here is that candidates often assume automation is always beneficial and should be applied immediately, but ITIL 4 stresses that optimization must precede automation to avoid amplifying existing inefficiencies.

177
MCQhard

A project team is developing a new mobile banking app. They decide to reuse an existing authentication module and focus on adding new features. Which ITIL 4 guiding principle is being applied?

A.Collaborate and promote visibility
B.Progress iteratively with feedback
C.Focus on value
D.Start where you are
AnswerD

The 'Start where you are' guiding principle mandates that organizations assess their current state and leverage existing services, processes, tools, and people whenever possible, rather than starting from scratch. For a new mobile banking app, this means identifying and reusing existing components, APIs, security protocols, or even development methodologies already present within the organization. This approach avoids unnecessary duplication of effort, accelerates development, and leverages prior investments, directly promoting the strategic reuse of assets.

Why this answer

The team is reusing an existing authentication module rather than building a new one from scratch. This directly applies the 'Start where you are' guiding principle, which recommends leveraging existing services, processes, and capabilities to avoid unnecessary rework and reduce risk. By starting with what already works, the team can focus effort on new features, maximizing efficiency.

Exam trap

The trap here is that candidates may confuse 'Start where you are' with 'Focus on value' because both involve efficiency, but the key distinction is that 'Start where you are' specifically addresses leveraging existing assets, while 'Focus on value' is about ensuring all activities deliver measurable outcomes to stakeholders.

How to eliminate wrong answers

Option A is wrong because 'Collaborate and promote visibility' focuses on cross-team communication and transparency, not on reusing existing components. Option B is wrong because 'Progress iteratively with feedback' emphasizes incremental delivery and continuous improvement, not the reuse of an existing module. Option C is wrong because 'Focus on value' prioritizes outcomes for stakeholders, but the specific action of reusing an existing component is a direct application of 'Start where you are', not a value-focused decision.

178
MCQmedium

A company's IT department has separate teams for network, servers, and applications that rarely communicate. Which ITIL 4 guiding principle would best address this issue?

A.Focus on value
B.Collaborate and promote visibility
C.Think and work holistically
D.Optimize and automate
AnswerB

The "Collaborate and promote visibility" principle directly addresses the challenge of separate teams and communication silos by advocating for cross-functional cooperation and transparent information sharing. It encourages working together across boundaries, fostering mutual understanding, and ensuring all relevant parties have a clear view of activities and progress. This principle explicitly targets the breakdown of departmental barriers and the improvement of shared context necessary for effective service delivery.

Why this answer

The 'Collaborate and promote visibility' guiding principle directly addresses the lack of communication and siloed operations between network, server, and application teams. By promoting visibility into each team's work and fostering collaboration, the IT department can break down barriers, reduce conflicts (e.g., firewall rules blocking application ports), and improve overall service delivery.

Exam trap

The trap here is that candidates may choose 'Think and work holistically' because it sounds like it addresses silos, but ITIL 4 specifically separates holistic thinking (understanding the whole system) from collaboration and visibility (the active sharing and teamwork needed to break down silos).

How to eliminate wrong answers

Option A is wrong because 'Focus on value' emphasizes delivering outcomes to customers, not resolving internal team silos or communication gaps. Option C is wrong because 'Think and work holistically' focuses on understanding the entire service system end-to-end, but it does not specifically prescribe the collaborative behavior and transparency needed to fix isolated teams. Option D is wrong because 'Optimize and automate' targets efficiency gains through process improvement and automation, which is premature when the fundamental issue is a lack of cross-team coordination and visibility.

179
MCQeasy

What is the PRIMARY purpose of the ITIL 4 concept 'service management'?

A.To enable value co-creation through services
B.To ensure compliance with regulations
C.To reduce costs of IT operations
D.To manage IT infrastructure and applications
AnswerA

ITIL 4 defines service management as a set of specialized organizational capabilities for enabling value for customers in the form of services. The primary purpose is to facilitate value co-creation, where organizations collaborate with consumers to realize desired outcomes. This involves understanding stakeholder needs and designing, delivering, and improving services that provide utility and warranty, ultimately contributing to mutual value.

Why this answer

The primary purpose of 'service management' in ITIL 4 is to enable value co-creation through services. This is achieved by organizing and managing resources, activities, and processes to deliver outcomes that customers value, while balancing the provider's constraints. ITIL 4 defines service management as a set of specialized organizational capabilities for providing value to customers in the form of services, directly linking it to the Service Value System (SVS) and the guiding principles.

Exam trap

The trap here is that candidates confuse the operational goal of 'managing IT' (Option D) with the strategic purpose of service management, which is explicitly defined in ITIL 4 as enabling value co-creation through services, not just running technology.

How to eliminate wrong answers

Option B is wrong because ensuring compliance with regulations is a specific governance or risk management activity, not the overarching purpose of service management; ITIL 4 treats compliance as one outcome within the broader goal of value co-creation. Option C is wrong because reducing costs of IT operations is a potential benefit or objective of service management, but not its primary purpose; focusing solely on cost reduction ignores value delivery and customer outcomes. Option D is wrong because managing IT infrastructure and applications is a tactical or operational activity (part of service management practices like Service Desk or Technical Management), not the primary purpose; ITIL 4 emphasizes that infrastructure management serves to enable services that co-create value.

180
MCQhard

An organization has implemented a new customer relationship management (CRM) system. Users are now able to access customer data 50% faster, leading to increased sales. Which of the following describes the output vs. outcome in this scenario?

A.Output: faster data access; Outcome: the CRM system
B.Output: the CRM system; Outcome: faster data access and increased sales
C.Output: the CRM system; Outcome: revenue from the project
D.Output: increased sales; Outcome: the CRM system
AnswerB

This option correctly identifies the output and outcome. The "CRM system" is the tangible output, representing the specific product or service component delivered by the organization's activities. "Faster data access and increased sales" are the desired outcomes, which are the benefits realized by the organization and its customers as a result of utilizing the CRM system. This alignment demonstrates a clear understanding of how delivered outputs enable the achievement of valuable business outcomes, central to the ITIL 4 value co-creation model.

Why this answer

In ITIL 4, an output is a tangible deliverable (the CRM system), while an outcome is the result achieved for stakeholders (faster data access and increased sales). The question explicitly states that users access data 50% faster and sales increased, which are the outcomes enabled by the CRM system output.

Exam trap

The trap here is that candidates confuse the tangible deliverable (output) with the resulting business benefit (outcome), often misidentifying 'faster data access' as an output because it sounds like a technical feature, when in ITIL 4 it is a measurable outcome of using the CRM system.

How to eliminate wrong answers

Option A is wrong because it incorrectly labels 'faster data access' as the output and 'the CRM system' as the outcome, reversing the ITIL 4 definitions: the CRM system is the tangible output, and faster data access is a measurable outcome. Option C is wrong because it states the outcome is 'revenue from the project,' which is too narrow; the scenario includes both faster data access and increased sales, and revenue is a financial result, not the primary outcome described. Option D is wrong because it claims 'increased sales' is the output and 'the CRM system' is the outcome, which again reverses definitions: increased sales is a business outcome, not a deliverable, and the CRM system is the output.

181
MCQeasy

Which ITIL 4 guiding principle is being applied when a team decides to review what is already working before redesigning a process?

A.Progress iteratively with feedback
B.Focus on value
C.Start where you are
D.Keep it simple and practical
AnswerC

This principle advises against discarding existing resources or processes without first assessing their current utility and potential for reuse. It encourages a thorough examination of the current state, including services, processes, people, partners, and technology, to identify what can be leveraged or improved rather than initiating new efforts from scratch. This approach promotes efficiency and avoids unnecessary waste by building upon established foundations.

Why this answer

The 'Start where you are' guiding principle emphasizes leveraging existing services, processes, and capabilities before creating new ones. By reviewing what is already working, the team avoids reinventing the wheel and builds on proven practices, which aligns directly with this principle.

Exam trap

The trap here is that candidates confuse 'Start where you are' with 'Progress iteratively with feedback,' because both involve incremental steps, but the former specifically mandates an initial assessment of existing assets before any change.

How to eliminate wrong answers

Option A is wrong because 'Progress iteratively with feedback' focuses on making incremental improvements based on continuous feedback, not on assessing the current state before redesign. Option B is wrong because 'Focus on value' directs all activities toward delivering value to stakeholders, but does not specifically address the step of reviewing existing work. Option D is wrong because 'Keep it simple and practical' advocates for minimizing complexity and unnecessary steps, but does not inherently involve analyzing what already functions well.

182
Multi-Selecthard

Which THREE of the following are activities of the Problem Management practice?

Select 3 answers
A.Problem identification
B.Root cause analysis
C.Managing changes
D.Managing known errors
E.Monitoring services for events
AnswersA, B, D

Problem identification is a foundational activity within Problem Management, initiating the process by detecting and logging potential or actual problems. This involves analyzing incident trends, reviewing service desk data, and receiving direct input from various stakeholders to proactively identify recurring issues or single, high-impact events that warrant deeper investigation. The goal is to move beyond mere symptom treatment to understand underlying causes.

Why this answer

Problem identification (A) is a core Problem Management activity because the practice must detect and log problems, often from recurring incidents or major incidents, so they can be investigated. Root cause analysis (B) is central to Problem Management, which seeks to determine the underlying cause of incidents and problems to prevent recurrence. Managing known errors (D) is also a Problem Management responsibility, as known errors are problems with a documented root cause and workaround that must be recorded, maintained, and made available to support teams.

Managing changes (C) belongs to Change Enablement, which authorizes and schedules changes, not Problem Management. Monitoring services for events (E) is an activity of Service Desk or Monitoring and Event Management, since it focuses on detecting and correlating events rather than investigating problem root causes.

Exam trap

ITIL4F often tests the boundary between Problem Management and other practices, tricking candidates into selecting activities that belong to Change Enablement or Monitoring and Event Management.

183
Multi-Selectmedium

Which TWO of the following scenarios best illustrate the 'Think and work holistically' principle?

Select 2 answers
A.Focusing only on incident resolution speed
B.Engaging all relevant departments when planning a new service
C.Optimizing a single process without considering other processes
D.Updating a database without assessing the impact on related applications
E.Identifying how a change in the network affects the entire service chain
AnswersB, E

Engaging all relevant departments, such as development, operations, security, finance, and business units, during the planning phase of a new service exemplifies a truly holistic approach. This comprehensive stakeholder involvement ensures that the service is designed with a full understanding of its requirements, dependencies, potential impacts, and value streams across the entire organization, fostering proactive, cross-functional collaboration from inception to deliver integrated value.

Why this answer

'Think and work holistically' requires considering the entire service value chain, not just individual components. Engaging all relevant departments when planning a new service ensures that dependencies, resource constraints, and downstream impacts are identified early, preventing siloed decisions that could disrupt other services or create bottlenecks. This aligns with the ITIL guiding principle of viewing the organization as an interconnected system.

Exam trap

The trap here is that candidates often mistake 'holistic' for simply involving more people or processes, but the principle specifically requires understanding and managing the interdependencies and end-to-end impacts across the entire service value chain, not just adding stakeholders without systemic analysis.

184
MCQhard

An IT service provider is designing a new service. They want to ensure that the service will deliver value to customers by achieving desired outcomes without requiring them to manage specific costs and risks. Which key concept of ITIL 4 does this best describe?

A.Service
B.Utility
C.Outcome
D.Warranty
AnswerA

A service is defined in ITIL 4 as a means of enabling value co-creation by facilitating outcomes customers want, without them managing specific costs and risks. This matches the stem's description precisely, making it the correct concept.

Why this answer

The scenario describes a service designed to deliver desired outcomes while shielding customers from managing specific costs and risks. This directly aligns with the ITIL 4 definition of a service, which is a means of enabling value co-creation by facilitating outcomes customers want to achieve, without the customer having to manage the associated costs and risks. Options like utility, outcome, or warranty are components of value but do not capture the full concept of a service as a delivery mechanism that abstracts away cost and risk management.

Exam trap

The trap here is that candidates often confuse 'utility' (the functionality) with the full service definition, forgetting that a service must also include the abstraction of costs and risks, which is a key differentiator in ITIL 4.

How to eliminate wrong answers

Option B (Utility) is wrong because utility refers to the functionality offered by a product or service to meet a specific need, not the abstraction of costs and risks. Option C (Outcome) is wrong because an outcome is a result for a stakeholder enabled by one or more outputs, not the mechanism that delivers value while managing costs and risks. Option D (Warranty) is wrong because warranty focuses on the assurance that a product or service will meet agreed requirements (availability, capacity, continuity, security), not on achieving desired outcomes without customer cost/risk management.

185
MCQmedium

Which of the following is a key difference between Incident Management and Problem Management?

A.Incident Management deals with unplanned interruptions; Problem Management deals with root causes
B.Incident Management requires a change request; Problem Management does not
C.Incident Management is proactive; Problem Management is reactive
D.Incident Management is only for major incidents
AnswerA

Incident Management's primary objective is to restore normal service operation as quickly as possible following an unplanned interruption or reduction in service quality. It focuses on the immediate impact and resolution of service disruptions. In contrast, Problem Management aims to reduce the likelihood and impact of incidents by identifying and eliminating their underlying root causes, often preventing future occurrences of similar issues.

Why this answer

Incident Management focuses on restoring normal service operation as quickly as possible after an unplanned interruption or service degradation, minimizing business impact. Problem Management, in contrast, seeks to identify and eliminate the root cause of incidents to prevent recurrence. This fundamental distinction in purpose—restoration versus root cause analysis—is the key difference tested in the ITIL 4 Foundation exam.

Exam trap

The trap here is confusing the reactive nature of Incident Management with the proactive aspect of Problem Management, leading candidates to incorrectly reverse the roles (Option C), when in fact Incident Management is always reactive and Problem Management includes both reactive and proactive elements.

How to eliminate wrong answers

Option B is wrong because Incident Management does not inherently require a change request; while a workaround or fix may eventually lead to a change, the incident process itself focuses on swift restoration, not mandatory RFCs. Option C is wrong because Incident Management is reactive (responding to disruptions), while Problem Management includes both reactive (analyzing past incidents) and proactive (preventing future incidents) activities. Option D is wrong because Incident Management handles all incidents, not just major ones; major incidents follow a separate, more urgent procedure, but the practice covers every unplanned interruption.

186
Multi-Selecteasy

Which TWO are key activities of Capacity and Performance Management?

Select 2 answers
A.Defining service level targets
B.Managing the IT service desk staffing levels
C.Forecasting future demand for services
D.Managing service availability
E.Monitoring current service performance
AnswersC, E

Forecasting future demand for services is a critical activity within capacity and performance management, specifically for proactive capacity planning. By analyzing historical trends, business plans, and anticipated growth, organizations can predict future resource requirements for IT services and their underlying components. This foresight enables the timely acquisition, provisioning, or scaling of infrastructure and applications, ensuring that sufficient capacity is available to meet evolving business needs without costly over-provisioning or detrimental under-provisioning.

Why this answer

Option C (Forecasting future demand for services) is correct because Capacity and Performance Management must anticipate future workload and resource requirements so that services continue to meet agreed performance targets as demand grows. Option E (Monitoring current service performance) is correct because it provides the baseline data on utilization, throughput, and response times needed to compare actual performance against targets and to feed accurate forecasting. Together, these activities form the core iterative cycle of measuring present performance and predicting future capacity needs.

Option A (Defining service level targets) belongs primarily to Service Level Management, which negotiates and agrees SLAs rather than performing capacity analysis. Option B (Managing the IT service desk staffing levels) is a workforce/resource management activity, not a capacity management activity for IT services. Option D (Managing service availability) is the domain of Availability Management, which focuses on uptime and reliability rather than capacity and performance.

Exam trap

ITIL4F often tests the confusion between related practices — candidates mistakenly assign SLA definition to Capacity Management when it actually belongs to Service Level Management, or confuse availability with capacity.

187
Multi-Selecthard

Which TWO statements about the relationship between IT Asset Management and Service Configuration Management are correct?

Select 2 answers
A.Asset management maintains the configuration baseline
B.All assets are considered CIs, and all CIs are assets
C.Configuration management provides information about relationships between assets
D.Configuration management provides the CMDB that includes details of IT assets
E.Asset management focuses on the lifecycle of CIs
AnswersC, D

Configuration management is fundamentally concerned with understanding how different components of an IT service relate to each other to ensure service integrity and operational efficiency. By defining and tracking Configuration Items (CIs) and their interdependencies within the Configuration Management System (CMS), it provides crucial insights into how changes to one asset (represented as a CI) might impact others. This relational information is vital for effective incident, problem, and change management, ensuring service stability and reliability.

Why this answer

Option C is correct because Service Configuration Management maintains the CMDB and its relationship records, so it can show how assets/CIs depend on or connect to one another (e.g., an application running on a server, or a server hosted on a hypervisor). Option D is correct because the CMDB is the configuration management repository that holds CI attributes and can include detailed information about IT assets, linking asset data to configuration data. Option A is not correct because configuration management, not asset management, establishes and maintains the configuration baseline.

Option B is not correct because the relationship is not universally bidirectional: assets are not always managed as CIs, and CIs are not always financial/physical assets. Option E is not correct because asset management focuses on the asset lifecycle (procurement, deployment, maintenance, disposal), while configuration management focuses on CIs and their relationships.

Exam trap

ITIL4F often tests the misconception that all assets are CIs and vice versa; candidates must remember that the two practices have different scopes and that configuration management adds relationship data.

188
MCQmedium

Which ITIL 4 practice is responsible for ensuring that services deliver the agreed level of availability?

A.Service Level Management
B.Capacity and Performance Management
C.IT Asset Management
D.Availability Management
AnswerD

This ITIL practice is specifically responsible for ensuring that services and components are able to perform their agreed function when required, meeting established availability targets. It encompasses designing for resilience, implementing redundancy, proactive monitoring, and establishing recovery mechanisms to maximize service uptime and minimize downtime. Its core purpose is to guarantee the continuous operational capability of services and their underlying components.

Why this answer

Availability Management is the ITIL 4 practice specifically tasked with ensuring that IT services deliver the agreed level of availability to meet business requirements. It involves planning, measuring, and improving the availability of services, components, and supporting infrastructure, directly aligning with the question's focus on delivering agreed availability levels.

Exam trap

The trap here is that candidates often confuse Service Level Management (which defines the availability target in the SLA) with Availability Management (which is the practice that actually ensures that target is met through technical design and operational controls).

How to eliminate wrong answers

Option A is wrong because Service Level Management focuses on defining, negotiating, and monitoring service level agreements (SLAs) and targets, not on the technical assurance of availability itself. Option B is wrong because Capacity and Performance Management deals with ensuring services have sufficient resources to meet performance and demand requirements, not specifically with availability metrics like uptime or downtime. Option C is wrong because IT Asset Management is concerned with tracking and managing the lifecycle of IT assets (hardware, software) for financial and inventory purposes, not with the operational delivery of service availability.

189
MCQmedium

What is the primary focus of Problem Management in ITIL 4?

A.Managing service requests from users
B.Restoring service as quickly as possible
C.Implementing changes to IT infrastructure
D.Finding underlying causes of incidents
AnswerD

Finding underlying causes of incidents is the central purpose of Problem Management. This ITIL practice focuses on identifying the root causes of actual or potential incidents, analyzing trends, and developing permanent solutions to prevent recurrence. By moving beyond temporary fixes, Problem Management aims to eliminate known errors and improve the long-term stability and reliability of IT services, thereby reducing the overall number and impact of future incidents.

Why this answer

Problem Management in ITIL 4 focuses on identifying and analyzing the underlying causes of incidents to prevent recurrence or minimize their impact. Option D is correct because this practice aims to diagnose root causes, not just restore service or handle requests, aligning with the ITIL 4 guiding principle of 'Focus on Value' by reducing future disruptions.

Exam trap

The trap here is that candidates confuse the reactive, fast-restore focus of Incident Management (Option B) with the proactive, root-cause analysis focus of Problem Management, leading them to select the wrong answer when the question explicitly asks for the 'primary focus' of Problem Management.

How to eliminate wrong answers

Option A is wrong because managing service requests is the domain of Service Desk and Request Fulfillment, not Problem Management, which deals with incidents and their root causes. Option B is wrong because restoring service as quickly as possible is the primary goal of Incident Management, which prioritizes speed over root cause analysis. Option C is wrong because implementing changes to IT infrastructure is the responsibility of Change Enablement, not Problem Management, though Problem Management may identify the need for changes.

190
MCQeasy

What is the purpose of the Monitoring and Event Management practice?

A.To restore service after an incident
B.To manage the lifecycle of assets
C.To plan and manage capacity
D.To detect events and classify them to enable appropriate response
AnswerD

This statement accurately defines the primary purpose of the Monitoring and Event Management practice. It involves systematically observing services and service components, recording changes of state identified as events, and then classifying these events. This classification is crucial for determining the appropriate response, whether it's an informational alert, a warning requiring further investigation, or an an indicator of an incident that needs immediate action.

Why this answer

The Monitoring and Event Management practice is specifically designed to observe IT services and infrastructure, detect events (e.g., SNMP traps, syslog messages, performance threshold crossings), and classify them (e.g., informational, warning, exception) so that the appropriate response—such as automated remediation, alerting, or incident creation—can be triggered. This aligns with ITIL 4's definition of the practice as ensuring that events are systematically identified and acted upon to maintain service availability and performance.

Exam trap

The trap here is that candidates confuse Monitoring and Event Management with Incident Management, because both involve reacting to problems, but the former is purely about detection and classification, while the latter handles the actual restoration of service.

How to eliminate wrong answers

Option A is wrong because restoring service after an incident is the purpose of the Incident Management practice, not Monitoring and Event Management, which focuses on detection and classification rather than recovery actions. Option B is wrong because managing the lifecycle of assets (e.g., hardware, software licenses) is the domain of the IT Asset Management practice, which tracks financial and contractual aspects, not real-time event detection. Option C is wrong because planning and managing capacity is the responsibility of the Capacity and Performance Management practice, which deals with forecasting resource demands and ensuring performance meets agreed levels, not the detection and classification of operational events.

191
Multi-Selectmedium

Which TWO of the following are components of the ITIL 4 Service Value System?

Select 2 answers
A.Service desk
B.Configuration management
C.Service value chain
D.Service level agreements
E.Guiding principles
AnswersC, E

The service value chain is a core component of the ITIL 4 Service Value System, representing an operational model that outlines the key activities required to respond to demand and facilitate value co-creation through the creation and management of products and services. It provides a flexible, interconnected set of activities that an organization performs to deliver value, integrating various practices and resources. This component is central to how an organization transforms inputs into outputs.

Why this answer

The ITIL 4 Service Value System (SVS) is a structured framework that includes the service value chain and guiding principles as core components. The service value chain (C) is a set of interconnected activities that an organization performs to deliver value, while guiding principles (E) are universal recommendations that guide decision-making. Both are explicitly defined as components of the SVS in the ITIL 4 Foundation syllabus.

Exam trap

The trap here is that candidates confuse operational elements like the service desk or SLAs with the high-level structural components of the SVS, leading them to select familiar-sounding options that are actually parts of practices or functions, not the SVS itself.

192
MCQmedium

An IT team monitors server CPU usage and receives an alert that usage has exceeded 90%. According to ITIL 4, what type of event is this?

A.Warning event
B.Incident
C.Informational event
D.Exception event
AnswerA

A warning event, as defined by ITIL 4, indicates that a predefined threshold has been met or exceeded, signaling a potential degradation of service or an impending incident. In this scenario, high server CPU usage reaching a critical level triggers such an event, prompting IT staff to investigate and take proactive measures. The primary objective of a warning event is to enable intervention before the situation escalates into an actual service disruption, thereby maintaining service quality and availability.

Why this answer

In ITIL 4, a warning event occurs when a threshold is reached that indicates a potential future issue, such as server CPU usage exceeding 90%. This alert signals that the service is still operational but may degrade if the trend continues, prompting proactive monitoring or escalation.

Exam trap

The trap here is that candidates confuse a warning event with an incident, failing to recognize that ITIL 4 distinguishes between a potential issue (warning) and an actual service disruption (incident).

How to eliminate wrong answers

Option B is wrong because an incident is an unplanned interruption or reduction in quality of an IT service, whereas a CPU usage alert above 90% does not yet indicate service degradation or outage. Option C is wrong because an informational event is a routine notification (e.g., normal CPU usage at 50%) that requires no action, not a threshold breach. Option D is wrong because ITIL 4 does not define an 'exception event'; this is a common misnomer that conflates warning events with error conditions.

193
MCQeasy

What is the definition of 'warranty' in ITIL 4?

A.The value created by the service
B.The cost of using the service
C.The assurance that a service will perform as agreed
D.The functionality offered by a service to meet a specific need
AnswerC

Warranty, in ITIL 4, precisely defines the assurance that a service will consistently meet its agreed-upon specifications and requirements, thereby confirming its 'fitness for use.' This critical aspect ensures the service performs reliably without undue interruption or degradation, providing confidence to the consumer. Specifically, warranty addresses key performance indicators related to availability, capacity, continuity, and security, guaranteeing the service's operational integrity.

Why this answer

In ITIL 4, 'warranty' is defined as the assurance that a service will meet its agreed-upon performance requirements, covering aspects like availability, capacity, continuity, and security. Option C correctly captures this by stating 'the assurance that a service will perform as agreed,' which aligns with the ITIL 4 definition that warranty focuses on the service's reliability and fitness for use under defined conditions.

Exam trap

The trap here is that candidates often confuse 'warranty' with 'utility,' mistakenly selecting Option D because they think warranty is about what the service does (functionality), rather than the assurance of how it will perform under agreed conditions.

How to eliminate wrong answers

Option A is wrong because it describes 'utility,' which is the value created by the service through functionality that meets a specific need, not warranty. Option B is wrong because it refers to 'cost' or 'price,' which is a separate financial consideration and not part of the warranty definition in ITIL 4. Option D is wrong because it defines 'utility' again—the functionality offered by a service to meet a specific need—whereas warranty is about the assurance of performance, not the features themselves.

194
MCQmedium

A service desk analyst handles a password reset request. According to ITIL 4, this should be classified as:

A.A service request
B.An incident
C.A change request
D.A problem
AnswerA

A password reset is a classic example of a service request in ITIL 4. Service requests are standard, pre-defined, and often automated requests for information, advice, or access to a service, or for a standard change. They are typically low-risk, frequently occurring, and have a known resolution path, making them distinct from incidents or changes. Users expect a quick and predictable fulfillment process for such common requests.

Why this answer

A password reset is a standard, pre-approved request for information or access that follows a defined procedure, which aligns with ITIL 4's definition of a service request. It does not involve restoring a failed service (incident), altering a configuration (change), or investigating an underlying cause (problem).

Exam trap

The trap here is that candidates confuse a service request with an incident because both involve user-reported issues, but ITIL 4 strictly defines a service request as a pre-approved, low-risk action (like a password reset) versus an incident as an unplanned service disruption.

How to eliminate wrong answers

Option B is wrong because an incident is an unplanned interruption or reduction in quality of an IT service, not a routine administrative action like a password reset. Option C is wrong because a change request involves adding, modifying, or removing a configuration item (e.g., deploying a new server), which a password reset does not alter any infrastructure. Option D is wrong because a problem is the root cause of one or more incidents, requiring analysis and a permanent fix, whereas a password reset is a one-off operational task.

195
MCQmedium

An IT manager is reviewing the processes for handling user requests for new software. The manager notices that the existing process is working well, so only minor adjustments are made. Which ITIL 4 guiding principle is being applied?

A.Focus on value
B.Optimize and automate
C.Keep it simple and practical
D.Start where you are
AnswerD

The "Start where you are" guiding principle explicitly advises against starting from scratch without first considering what is already available and functional within the organization or its ecosystem. It encourages organizations to assess existing services, processes, people, partners, and tools to determine if they can be leveraged, adapted, or improved upon, making only the necessary changes to achieve the desired state. This approach minimizes waste, accelerates progress, and builds upon proven capabilities, directly aligning with the idea of reusing existing processes rather than reinventing the wheel.

Why this answer

The IT manager is building upon the existing process rather than redesigning it from scratch, which directly aligns with the ITIL 4 guiding principle 'Start where you are.' This principle emphasizes that before making changes, you should first understand the current state and leverage what already works well, as demonstrated by the manager's decision to make only minor adjustments to a process that is already functioning effectively.

Exam trap

The trap here is that candidates often confuse 'Start where you are' with 'Keep it simple and practical' because both involve avoiding unnecessary complexity, but the key distinction is that 'Start where you are' specifically focuses on leveraging the current state rather than simplifying a new design.

How to eliminate wrong answers

Option A is wrong because 'Focus on value' is about ensuring that every activity delivers value to stakeholders, not about leveraging existing processes; the scenario does not describe a value assessment or value stream mapping. Option B is wrong because 'Optimize and automate' involves streamlining workflows and implementing automation to reduce waste, but the manager is not optimizing or automating the process—they are making minor adjustments to a working process. Option C is wrong because 'Keep it simple and practical' advocates for minimizing complexity and avoiding over-engineering, but the scenario does not indicate any complexity reduction or simplification; the manager is simply retaining the current process with minor tweaks.

196
MCQmedium

Which ITIL 4 practice is responsible for managing the complete lifecycle of all IT assets, including financial and contractual aspects?

A.Service Configuration Management
B.IT Asset Management
C.Service Portfolio Management
D.Supplier Management
AnswerB

IT Asset Management covers the full lifecycle of IT assets, including financial, contractual and inventory detail, tracking cost, ownership and compliance. It satisfies the stem's requirement for managing financial and contractual aspects, unlike practices such as Service Configuration Management, which focuses on configuration items and their relationships rather than commercial data.

Why this answer

IT Asset Management (ITAM) is the ITIL 4 practice responsible for managing the complete lifecycle of all IT assets, including financial and contractual aspects. It covers planning, acquisition, deployment, maintenance, and disposal, ensuring cost optimization and compliance with vendor contracts. This aligns directly with the question's emphasis on lifecycle management plus financial and contractual oversight.

Exam trap

The trap here is that candidates confuse Service Configuration Management with IT Asset Management because both involve inventories, but ITAM uniquely handles financial and contractual data, whereas Configuration Management focuses on service relationships and control.

How to eliminate wrong answers

Option A (Service Configuration Management) is wrong because it focuses on managing configuration items (CIs) and their relationships within the service model, not on financial or contractual aspects of assets. Option C (Service Portfolio Management) is wrong because it manages the entire portfolio of services from idea to retirement, not the lifecycle of physical or digital IT assets with financial tracking. Option D (Supplier Management) is wrong because it oversees supplier relationships and performance, not the internal lifecycle and financial management of IT assets themselves.

197
MCQhard

An IT department implements a new monitoring tool that generates alerts for every minor performance fluctuation, causing the service desk to be overwhelmed. Which ITIL 4 guiding principle is being violated?

A.Start where you are
B.Focus on value
C.Progress iteratively with feedback
D.Keep it simple and practical
AnswerD

The 'Keep it simple and practical' guiding principle advises against unnecessary complexity and encourages delivering the minimum necessary to achieve the objective. A monitoring tool that generates an overwhelming number of alerts, many of which are likely non-actionable or redundant, directly violates this principle. Such over-alerting introduces significant complexity, makes the system impractical to use effectively, and obscures critical information, thereby failing to provide a simple, practical, and useful output for the IT department.

Why this answer

(Keep it simple and practical) is correct because the monitoring tool is generating alerts for every minor performance fluctuation, which adds unnecessary complexity and noise. This violates the principle of minimizing complexity to achieve outcomes efficiently; a practical approach would filter alerts to only those requiring action, preventing the service desk from being overwhelmed.

Exam trap

The trap here is that candidates confuse 'Start where you are' (Option A) with the need to assess current monitoring capabilities, when the real violation is the failure to simplify alerting thresholds to avoid overwhelming the service desk.

How to eliminate wrong answers

Option A is wrong because 'Start where you are' focuses on leveraging existing processes and tools before introducing new ones, not on the volume or relevance of alerts generated. Option B is wrong because 'Focus on value' emphasizes delivering outcomes that matter to stakeholders, but the issue here is not about misidentifying value—it's about excessive alerting that hinders value delivery. Option C is wrong because 'Progress iteratively with feedback' advocates for incremental improvements and incorporating feedback, but the core problem is the lack of simplicity in alert design, not the absence of iterative cycles or feedback loops.

198
MCQhard

An IT service provider guarantees 99.9% availability for a critical application. This guarantee is an example of which ITIL 4 concept?

A.Warranty
B.Utility
C.Risk
D.Output
AnswerA

Warranty is the assurance that a service meets agreed requirements, covering availability, capacity, continuity and security. The 99.9% availability guarantee is precisely this assurance, distinguishing it from utility, which describes the functionality the service provides to support the consumer's outcomes.

Why this answer

A 99.9% availability guarantee defines the service's fitness for use in terms of reliability and performance, which aligns directly with the ITIL 4 concept of 'Warranty'. Warranty ensures that the service will meet agreed-upon conditions such as availability, capacity, continuity, and security, making it the correct choice for this scenario.

Exam trap

The trap here is that candidates confuse 'Warranty' (fitness for use, including availability guarantees) with 'Utility' (fitness for purpose, or what the service does), leading them to incorrectly select Utility when the question explicitly states a performance guarantee.

How to eliminate wrong answers

Option B is wrong because Utility refers to the functionality of the service—'what the service does'—such as processing transactions or storing data, not the guaranteed uptime percentage. Option C is wrong because Risk is a potential event that could cause harm or loss, not a guarantee of service performance; the 99.9% availability is a warranty condition, not a risk assessment. Option D is wrong because Output is a tangible or intangible deliverable produced by a process (e.g., a report or a code module), not a measure of service reliability or availability.

199
MCQeasy

An IT department is redesigning its change management process. The current process has many approval steps causing delays. According to the guiding principle 'Keep it simple and practical', what should they do?

A.Outsource the process to a vendor
B.Add more approval steps to ensure quality
C.Remove steps that do not add value
D.Automate all approvals regardless of value
AnswerC

This action directly aligns with the ITIL 4 Guiding Principles of "Focus on value" and "Keep it simple and practical." By systematically identifying and eliminating redundant, unnecessary, or non-value-adding activities within the change management process, an organization can significantly streamline workflows, reduce cycle times, and optimize resource utilization. This simplification enhances efficiency, improves responsiveness, and ensures that every remaining step contributes directly to desired outcomes.

Why this answer

The guiding principle 'Keep it simple and practical' emphasizes eliminating unnecessary complexity. In change management, approval steps that do not add value (e.g., redundant sign-offs for low-risk changes) cause delays without improving quality. By removing such steps, the process becomes more efficient while still maintaining appropriate controls.

Exam trap

The trap here is that candidates may confuse 'automation' with 'simplification,' assuming that automating all approvals (Option D) is inherently good, but ITIL4F stresses that automation should only be applied to value-adding steps, not to all steps indiscriminately.

How to eliminate wrong answers

Option A is wrong because outsourcing the process does not inherently simplify it; it may introduce new complexities like vendor management and contractual overhead, violating the principle of keeping things simple and practical. Option B is wrong because adding more approval steps directly contradicts the principle by increasing complexity and delays, which is the opposite of what the redesign aims to achieve. Option D is wrong because automating all approvals regardless of value can automate waste, locking in inefficiencies and potentially bypassing necessary human judgment for high-risk changes, which is not practical or simple.

200
MCQmedium

Which practice is responsible for negotiating, agreeing, and monitoring service level targets?

A.Service Configuration Management
B.Incident Management
C.Service Level Management
D.Availability Management
AnswerC

Service Level Management is the dedicated practice responsible for setting clear, business-based targets for service performance and ensuring that the organization meets those targets. This practice explicitly involves negotiating and agreeing upon service level agreements (SLAs) with customers, which define the expected quality, availability, and other performance metrics of a service. It also continuously monitors, reports on, and reviews service performance against these agreed-upon levels to ensure customer satisfaction.

Why this answer

Service Level Management (SLM) is the ITIL practice specifically tasked with negotiating, agreeing, and monitoring service level targets. It defines, documents, and manages Service Level Agreements (SLAs) and Operational Level Agreements (OLAs) to ensure that the delivered service meets agreed performance metrics. This practice is the single point of accountability for service level achievement and continuous improvement against those targets.

Exam trap

The trap here is that candidates often confuse Availability Management with Service Level Management because both deal with performance metrics, but Availability Management only covers one specific dimension (uptime) while SLM covers the full spectrum of service targets including response times, throughput, and business outcomes.

How to eliminate wrong answers

Option A is wrong because Service Configuration Management is responsible for maintaining the Configuration Management Database (CMDB) and controlling changes to configuration items (CIs), not for negotiating or monitoring service level targets. Option B is wrong because Incident Management focuses on restoring normal service operation as quickly as possible after an incident, minimizing adverse impact on business operations, not on negotiating or monitoring service level targets. Option D is wrong because Availability Management is concerned with ensuring that IT services meet current and future availability requirements of the business, which is a subset of service level targets but does not encompass the full negotiation, agreement, and monitoring of all service level targets.

201
MCQmedium

A service desk receives multiple calls about a recurring network issue. According to ITIL 4, what is the FIRST step the team should take?

A.Raise a problem record
B.Create a service request
C.Log each call as an incident
D.Submit a change request
AnswerC

Logging each call as an incident is the correct initial action because an incident is defined as an unplanned interruption to a service or a reduction in the quality of a service. Each user call reporting a network issue signifies a service disruption that requires immediate attention and tracking. This ensures proper incident management processes are followed, service level agreements are monitored, and provides crucial data for subsequent problem identification and resolution.

Why this answer

In ITIL 4, an incident is defined as an unplanned interruption to a service or a reduction in the quality of a service. Since the service desk is receiving multiple calls about a recurring network issue, each call represents a user experiencing an unplanned interruption or degradation. The first step is to log each call as an incident to capture the details, restore service as quickly as possible, and then later analyze the recurring nature to potentially raise a problem record.

Logging incidents is the immediate action to manage the current impact.

Exam trap

ITIL4F often tests the distinction between incident and problem management, and candidates may incorrectly jump to raising a problem record first when they see 'recurring' in the scenario, forgetting that incidents must be logged initially to capture impact and restore service.

How to eliminate wrong answers

Option A is wrong because a problem record is typically raised after incidents have been logged and a recurring or underlying cause is identified; it is not the first step when calls are still coming in. Option B is wrong because a service request is for standard, pre-approved user requests (e.g., password reset, software installation), not for unplanned network issues. Option D is wrong because a change request is for modifying infrastructure or services, which would come after problem analysis and approval, not as an initial response to incidents.

202
Multi-Selecthard

Which THREE of the following are purposes of the ITIL 4 Service Value System?

Select 3 answers
A.To provide a holistic model for service management
B.To replace all existing management systems
C.To enable value co-creation for stakeholders
D.To facilitate continual improvement at all levels
E.To define organizational structures
AnswersA, C, D

The ITIL Service Value System (SVS) is designed to provide a comprehensive and integrated framework for service management, encompassing all organizational components and activities required to create value. It ensures that guiding principles, governance, the service value chain, practices, and continual improvement all work together cohesively. This holistic approach moves beyond isolated processes to a unified system, optimizing overall service delivery and value realization.

Why this answer

The ITIL 4 Service Value System (SVS) is designed to provide a holistic, end-to-end model for service management, integrating all components (guiding principles, governance, service value chain, practices, and continual improvement) to enable value co-creation. It does not replace existing management systems but rather aligns and coordinates them within a unified framework.

Exam trap

The trap here is that candidates often mistake the SVS as a replacement for all other management systems (Option B) or confuse its purpose with defining organizational structures (Option E), when in fact the SVS is an overarching model that integrates and coordinates existing systems and focuses on value co-creation and continual improvement.

203
MCQmedium

Which of the following is a key activity of Service Level Management?

A.Resolving incidents within agreed times
B.Installing new software
C.Managing supplier contracts
D.Negotiating and agreeing SLAs
AnswerD

Negotiating and agreeing Service Level Agreements (SLAs) is a fundamental and defining activity of the Service Level Management practice. This involves establishing clear, measurable targets for service performance, availability, capacity, and other critical aspects, ensuring they align with customer expectations and business requirements. By formalizing these agreements, Service Level Management sets the baseline for monitoring, reporting, and continual improvement of service delivery, directly linking IT services to business outcomes.

Why this answer

Service Level Management involves negotiating, agreeing, and monitoring SLAs, as well as reporting on service performance.

204
MCQhard

An IT team implements a new monitoring tool that reduces incident detection time but requires staff to learn a new interface, causing temporary productivity loss. Which ITIL 4 dimension is MOST overlooked in this scenario?

A.Partners and Suppliers
B.Information and Technology
C.Value Streams and Processes
D.Organisations and People
AnswerD

This dimension encompasses the organizational structure, culture, roles, responsibilities, and the required skills and competencies of all personnel involved in service management. The described issue, where the IT team experiences a skill gap and temporary productivity loss after implementing a new tool, directly highlights a failure to adequately prepare and enable the people within the organization for the change, making this the primary dimension affected.

Why this answer

The scenario describes a technology change (new monitoring tool) that directly impacts staff productivity due to the need to learn a new interface. This is a classic failure to consider the 'Organisations and People' dimension, which addresses culture, skills, and change management. The temporary productivity loss is a people-related risk, not a technology or process flaw.

Exam trap

The trap here is that candidates see 'new monitoring tool' and immediately think 'Information and Technology' (Option B), but the question explicitly highlights the temporary productivity loss due to learning, which is a people-centric issue, not a technology deficiency.

How to eliminate wrong answers

Option A is wrong because Partners and Suppliers are not mentioned; the tool is implemented internally, not outsourced or dependent on external vendors. Option B is wrong because Information and Technology focuses on the tool itself and data, but the core issue is the human adaptation cost, not the tool's functionality or data quality. Option C is wrong because Value Streams and Processes would be relevant if the monitoring workflow or procedures were disrupted, but the problem is specifically the learning curve for staff, not the process design.

205
MCQmedium

A user calls the service desk to report that they cannot access a shared folder. The analyst resolves the issue by resetting the folder permissions. Which practice is being performed?

A.Incident Management
B.Change Enablement
C.Service Request Management
D.Problem Management
AnswerA

Incident Management's primary purpose is to minimize the negative impact of incidents by restoring normal service operation as quickly as possible. An unplanned disruption, such as a user being unable to access a critical service, directly aligns with the ITIL definition of an incident. The immediate action taken by the service desk to resolve this access issue is a core activity within the Incident Management practice, aiming for swift resolution and service restoration.

Why this answer

Incident Management is correct because the user experienced an unplanned interruption to an IT service (inability to access a shared folder), and the service desk's immediate action to restore access by resetting permissions is the core of incident resolution. The focus is on restoring normal service operation as quickly as possible, not on identifying the root cause or managing a planned change. Resetting permissions is a standard incident resolution technique when access is broken unexpectedly.

Exam trap

ITIL4F often tests the distinction between Incident Management and Service Request Management: candidates may incorrectly choose Service Request Management because the user 'requested' access, but the key is that access was previously working and now is not, making it an unplanned incident.

How to eliminate wrong answers

Option B is wrong because Change Enablement (formerly Change Management) governs modifications to IT services through formal change requests, assessment, and authorization; resetting permissions to fix an unplanned outage is an incident resolution action, not a planned change. Option C is wrong because Service Request Management handles predefined, user-initiated requests such as password resets or software installations, not unexpected failures or degradation of service. Option D is wrong because Problem Management focuses on finding the root cause of recurring incidents and implementing permanent fixes; here the analyst only restored access, without investigating why the permissions were incorrect.

206
MCQmedium

An IT team is reviewing a recurring incident pattern. They decide to find the root cause to prevent future occurrences. Which practice are they applying?

A.Incident Management
B.Service Desk
C.Problem Management
D.Change Enablement
AnswerC

This ITIL practice is precisely designed to reduce the likelihood and impact of incidents by identifying and resolving their underlying causes, known as problems. It proactively analyzes recurring incident patterns, trends, and historical data to diagnose root causes, develop effective workarounds, and recommend permanent solutions. Its goal is to prevent future incidents, thereby enhancing service stability and reliability.

Why this answer

Problem Management (C) is the correct practice because it focuses on identifying the root cause of recurring incidents to prevent future occurrences. The IT team's decision to analyze a recurring incident pattern and find its root cause aligns directly with the proactive and reactive activities of Problem Management, which aims to minimize the impact of incidents and prevent them from happening again.

Exam trap

The trap here is that candidates confuse the 'restoration of service' focus of Incident Management with the 'root cause analysis and prevention' focus of Problem Management, especially when the question mentions a 'recurring incident pattern' which might seem like an incident handling task.

How to eliminate wrong answers

Option A is wrong because Incident Management is focused on restoring normal service operation as quickly as possible after an incident, not on finding the root cause of recurring patterns. Option B is wrong because the Service Desk is the single point of contact for users reporting incidents and service requests, and it does not perform root cause analysis or proactive problem resolution. Option D is wrong because Change Enablement manages the lifecycle of all changes to IT services, ensuring standardized methods and procedures are used, but it does not investigate the root cause of incidents.

207
Multi-Selecthard

Which THREE of the following are key activities of the Service Level Management practice?

Select 3 answers
A.Managing supplier contracts
B.Conducting service reviews with customers
C.Negotiating and agreeing service level targets
D.Monitoring and reporting service performance against SLAs
E.Resolving incidents at first contact
AnswersB, C, D

Conducting service reviews with customers is a fundamental activity of Service Level Management, providing a structured forum to discuss service performance, customer satisfaction, and any changes in business requirements. These regular reviews are crucial for ensuring that the agreed service level agreements (SLAs) remain relevant and continue to align with customer needs and business objectives, fostering a collaborative relationship and identifying opportunities for continual improvement.

Why this answer

Service Level Management (SLM) is the ITIL practice that sets, monitors, and reviews service levels, so option B (conducting service reviews with customers) is correct because SLM regularly reviews achieved performance with customers to confirm services meet their needs and to identify improvement actions. Option C (negotiating and agreeing service level targets) is correct because SLM is responsible for negotiating and agreeing SLAs, SLTs, and OLAs with customers and internal teams, ensuring targets are realistic and aligned to business requirements. Option D (monitoring and reporting service performance against SLAs) is correct because SLM continuously measures and reports service performance against agreed SLAs, producing reports and dashboards that feed into service reviews.

Option A (managing supplier contracts) belongs to Supplier Management, which handles supplier relationships, contracts, and performance, not SLM. Option E (resolving incidents at first contact) is an Incident Management activity focused on restoring service quickly, not on setting or reviewing service levels.

Exam trap

ITIL4F often tests the boundary between practices — candidates pick 'managing supplier contracts' or 'resolving incidents' because they sound service-related, missing that those belong to Supplier Management and Incident Management respectively, not SLM.

208
MCQhard

A company is implementing a new payroll system. The project team has focused on selecting the right technology and designing efficient processes. However, they have not involved the HR department in defining the service outcomes. Which ITIL 4 dimension is being ignored?

A.Organizations and People
B.Information and Technology
C.Partners and Suppliers
D.Value Streams and Processes
AnswerA

Implementing a new payroll system profoundly impacts employees, managers, HR, and finance departments, necessitating significant changes in roles, responsibilities, and daily workflows. This dimension focuses on ensuring the organization has the right culture, structure, and capabilities, alongside effective communication and training strategies, to successfully adopt and operate the new system. Effective change management, stakeholder engagement, and clear definition of new roles are critical components addressed by this dimension for project success.

Why this answer

The project team focused on technology and processes but neglected the 'Organizations and People' dimension by not involving the HR department in defining service outcomes. ITIL 4 emphasizes that all four dimensions must be balanced; ignoring the people and organizational aspects, such as stakeholder engagement and culture, leads to misaligned services that fail to deliver value, regardless of how efficient the technology or processes are.

Exam trap

The trap here is that candidates often assume 'Information and Technology' is the ignored dimension because the question mentions 'technology,' but the key is that the team already focused on technology and processes, leaving out the people and organizational aspects.

How to eliminate wrong answers

Option B is wrong because 'Information and Technology' is not being ignored; the team explicitly focused on selecting the right technology and designing efficient processes, so this dimension is addressed. Option C is wrong because 'Partners and Suppliers' is irrelevant here; the scenario does not mention any external vendors or third-party dependencies, so this dimension is not the one being overlooked. Option D is wrong because 'Value Streams and Processes' is not being ignored; the team designed efficient processes, which directly covers this dimension, but they failed to consider the people and organizational aspects.

209
Multi-Selecteasy

Which THREE are roles in the service relationship according to ITIL 4?

Select 3 answers
A.Customer
B.Supplier
C.Sponsor
D.Manager
E.User
AnswersA, C, E

The Customer is a key consumer role in the service relationship, representing the organizational entity or individual that defines service requirements and is accountable for the service's value realization. They authorize the service and are typically responsible for its financial aspects, ensuring it aligns with broader organizational objectives and strategic needs. This role focuses on the overall agreement and outcome.

Why this answer

In ITIL 4, the service relationship model defines three core roles: the customer, the sponsor, and the user. The customer is the role that defines the requirements for a service and takes responsibility for the outcomes of service consumption. This role is essential for establishing the service relationship and ensuring that the service meets agreed needs.

Exam trap

The trap here is that candidates often confuse 'supplier' or 'manager' with the official ITIL 4 roles, because in real-world organizations these titles are common, but ITIL 4 specifically limits the service relationship roles to customer, sponsor, and user.

210
MCQmedium

A financial services firm is adopting ITIL 4. The CIO asks the ITSM manager to explain how the Service Value System (SVS) enables the organization to co-create value with customers, not just deliver IT outputs. The manager needs to describe how the SVS components interact when a new digital service is introduced. Which statement accurately describes how the SVS operates?

A.The SVS focuses exclusively on the service value chain activities, while guiding principles and practices are optional additions that can be ignored if the organization is mature.
B.The SVS replaces the need for governance by allowing self-organizing teams to make all decisions about service delivery without oversight.
C.The SVS takes inputs in the form of demand and opportunities from internal and external sources, and uses opportunities to create value through the service value chain and practices.
D.The SVS is a sequential process where governance, service value chain, and practices are executed in strict order, starting with governance and ending with continual improvement.
AnswerC

The SVS explicitly receives demand and opportunities as inputs from stakeholders and the external environment. Opportunities represent options to add value or improve services, while demand represents the need for products and services. The SVS transforms these inputs through the service value chain and practices into value for the organization, its customers, and other stakeholders, enabling true co-creation.

Why this answer

The Service Value System takes demand and opportunities as inputs and transforms them into value through the interconnected components of guiding principles, governance, service value chain, practices, and continual improvement. This holistic system enables co-creation of value with customers and stakeholders, ensuring that IT services align with business outcomes rather than merely producing outputs.

Exam trap

The trap here is assuming the SVS is a linear process that starts with governance and ends with continual improvement, when in fact its components interact dynamically and continually.

211
Multi-Selectmedium

Which TWO of the following are correct statements about value co-creation according to ITIL 4?

Select 2 answers
A.Value is created solely by the service provider and delivered to the consumer.
B.Value is always monetary.
C.Value co-creation only occurs in formal contracts.
D.The provider contributes resources such as infrastructure and expertise.
E.The consumer always contributes resources such as information or effort.
AnswersD, E

This statement is correct. Service providers contribute a variety of resources and capabilities, such as technological infrastructure, specialized knowledge, skilled personnel, and intellectual property, to enable the service consumer to achieve their desired outcomes. These contributions form the essential foundation of the service offering, allowing consumers to leverage these assets effectively.

Why this answer

Option D is correct because in ITIL 4 value co-creation, the service provider brings its own resources—such as infrastructure, tools, technology, and expertise—into the service relationship, and these provider resources are essential inputs to the creation of value. Option E is correct because the consumer is not a passive recipient; the consumer also contributes resources such as information, time, effort, and other assets, and value emerges only through the interaction and integration of both parties' resources. Together, D and E reflect the ITIL 4 principle that value is co-created through the combined contributions of provider and consumer rather than produced unilaterally.

Option A is incorrect because it describes the outdated, one-directional view of value creation, whereas ITIL 4 explicitly rejects the idea that the provider alone creates and delivers value. Option B is incorrect because value in ITIL 4 is not limited to money; it can include outcomes such as improved performance, reduced risk, compliance, and user experience. Option C is incorrect because value co-creation can occur in many forms of service relationship, not only formal contracts, and ITIL 4 does not restrict co-creation to contractual arrangements.

Exam trap

ITIL4F often tests the misconception that value is created solely by the provider, tricking candidates into selecting options that ignore the consumer's role in value co-creation.

212
Multi-Selecthard

Which FOUR of the following are considered external factors in PESTLE that can affect the Four Dimensions?

Select 4 answers
A.Economic recession
B.New technology trends
C.Legal data protection regulations
D.Organisational culture
E.Political trade sanctions
AnswersA, B, C, E

An economic recession represents a significant external factor because it originates from broad macroeconomic conditions, such as declining GDP, increased unemployment, and reduced consumer spending, which are entirely beyond an organization's direct control. These conditions directly impact market demand for products and services, influence investment capital availability, and can necessitate strategic adjustments to an organization's financial planning and operational capacity. Consequently, an organization must adapt its service management practices to navigate the challenges posed by a contracting economy.

Why this answer

The PESTLE framework covers Political, Economic, Social, Technological, Legal, and Environmental external influences, so Economic recession (A) is correct because macroeconomic downturns directly affect demand, budgets, and the viability of services across the Four Dimensions. New technology trends (B) are correct as the Technological element, since emerging platforms, tooling, and automation shift how services are designed, delivered, and supported. Legal data protection regulations (C) are correct as the Legal element, because statutes such as GDPR impose binding compliance obligations on processes, people, partners, and technology.

Political trade sanctions (E) are correct as the Political element, since government actions like embargoes and export controls restrict markets, suppliers, and cross-border operations. Organisational culture (D) is not an external PESTLE factor; it is an internal influence within the organisation's own Four Dimensions, so it does not belong in this list.

Exam trap

The trap here is that candidates confuse internal factors (like organisational culture, which is part of the 'Organizations and People' dimension) with external PESTLE factors. It's crucial to remember that PESTLE specifically analyzes the *macro-environmental* external factors, not internal organizational characteristics or internal technology development initiatives.

213
MCQmedium

A service improvement team is working on reducing incident resolution time. They decide to form a cross-functional team that includes developers, operations, and support staff. Which guiding principle are they applying?

A.Collaborate and promote visibility
B.Progress iteratively with feedback
C.Think and work holistically
D.Start where you are
AnswerA

The "Collaborate and promote visibility" guiding principle is directly applicable here because reducing incident resolution time typically requires input and cooperation from multiple teams, such as the service desk, technical support, and development. This principle emphasizes breaking down organizational silos, fostering cross-functional teamwork, and ensuring all relevant stakeholders share information and progress openly. Such collective effort and transparency are crucial for identifying root causes, implementing effective solutions, and tracking improvements across the entire service value chain.

Why this answer

The cross-functional team including developers, operations, and support staff directly applies the 'Collaborate and promote visibility' guiding principle. By breaking down silos and sharing knowledge across roles, the team gains a complete view of the incident lifecycle, enabling faster root cause analysis and resolution. This principle emphasizes that collaboration and transparency are essential for effective service improvement, especially when reducing incident resolution time.

Exam trap

The trap here is that candidates confuse 'Think and work holistically' with cross-functional teamwork, but the holistic principle is about understanding the entire service system, whereas 'Collaborate and promote visibility' specifically addresses the act of forming a diverse team to improve communication and transparency.

How to eliminate wrong answers

Option B is wrong because 'Progress iteratively with feedback' focuses on making incremental improvements and using feedback loops, not on assembling a cross-functional team. Option C is wrong because 'Think and work holistically' addresses end-to-end service management and interdependencies, but the specific action of forming a cross-functional team is a direct expression of collaboration and visibility, not holistic thinking alone. Option D is wrong because 'Start where you are' means leveraging existing processes and measurements rather than forming new team structures; it does not prescribe cross-functional collaboration.

214
MCQmedium

Which dimension ensures that the right skills and competencies are available to deliver a service?

A.Organisations and People
B.Value Streams and Processes
C.Information and Technology
D.Partners and Suppliers
AnswerA

The 'Organisations and People' dimension specifically addresses the human element of service management, encompassing the organizational structure, culture, roles, responsibilities, and the necessary skills and competencies of all personnel. It ensures that individuals possess the required expertise, are adequately trained, and are motivated to perform service management activities effectively. This dimension is crucial for fostering a culture of collaboration, continuous learning, and aligning human capabilities with organizational goals to deliver value.

Why this answer

The Organisations and People dimension ensures that the right skills, competencies, and roles are available to deliver and support IT services. This includes defining clear responsibilities, training staff, and fostering a culture that aligns with service management objectives. Without proper attention to this dimension, even the best technology and processes will fail due to a lack of skilled personnel.

Exam trap

The trap here is that candidates often confuse 'Organisations and People' with 'Partners and Suppliers' because both involve human resources, but the former is strictly internal while the latter covers external vendors and contractors.

How to eliminate wrong answers

Option B (Value Streams and Processes) is wrong because it focuses on the sequence of activities and workflows required to create and deliver value, not on the human competencies or staffing. Option C (Information and Technology) is wrong because it deals with the data, applications, and infrastructure needed to support services, not the skills of the people using them. Option D (Partners and Suppliers) is wrong because it addresses external relationships and contracts with third parties, not the internal workforce's capabilities.

215
MCQmedium

An IT manager is reviewing the service value chain to identify where to add new monitoring tools. Which value chain activity would be most directly affected?

A.Design & transition
B.Improve
C.Deliver & support
D.Plan
AnswerC

The 'Deliver & support' activity is precisely where services are delivered and supported according to agreed specifications and expectations, making it the most direct source for identifying operational issues. This activity encompasses incident management, problem management, and service request fulfillment, meaning it is where service failures, performance degradation, and user-reported issues are first encountered, logged, and managed. An IT manager reviewing this activity would directly observe the symptoms and causes of service problems.

Why this answer

Monitoring tools are directly used during the 'Deliver & support' activity to observe the operational state of live services, detect incidents, and trigger responses. This activity manages the day-to-day running of services, where real-time monitoring is essential for maintaining availability and performance. Adding new monitoring tools here enhances the ability to detect and resolve issues as they occur.

Exam trap

The trap here is that candidates confuse 'Improve' with monitoring because monitoring data is used for improvements, but the direct operational act of monitoring belongs to 'Deliver & support'.

How to eliminate wrong answers

Option A is wrong because 'Design & transition' focuses on creating and deploying new or changed services, not on the operational monitoring of live services. Option B is wrong because 'Improve' is about analyzing performance data and planning continual improvements, not the direct operational use of monitoring tools. Option D is wrong because 'Plan' involves defining strategy, policies, and objectives, not the hands-on monitoring of running services.

216
MCQhard

An IT team is redesigning a process. They decide to review what already works well before making changes. Which ITIL 4 guiding principle are they applying?

A.Focus on value
B.Keep it simple
C.Start where you are
D.Progress iteratively
AnswerC

The "Start where you are" guiding principle explicitly advises against discarding existing resources and starting from scratch without first considering what is already available. When an IT team is redesigning a process, reviewing the current state is a direct application of this principle, as it involves understanding the baseline, identifying what works well, and recognizing what needs improvement, thereby leveraging existing foundations rather than reinventing solutions.

Why this answer

The guiding principle 'Start where you are' means using existing capabilities and services as a basis for improvement. Option C is correct. Option A (Focus on value) is about delivering value.

Option B (Keep it simple) is about simplicity. Option D (Progress iteratively) is about incremental improvements.

217
Multi-Selectmedium

Which TWO of the following are key metrics used by a service desk?

Select 2 answers
A.Mean Time Between Failures (MTBF)
B.Return on Investment (ROI)
C.Customer Satisfaction (CSAT)
D.Capacity Utilization
E.First Contact Resolution (FCR)
AnswersC, E

Customer Satisfaction (CSAT) is a pivotal metric for any service, directly measuring how satisfied customers are with a service or specific interaction, such as with the service desk. It typically involves direct feedback from users, often through surveys, providing invaluable insight into their perception of service quality, responsiveness, and overall value. High CSAT scores indicate that the service is meeting or exceeding customer expectations, making it a fundamental indicator of service success and customer-centricity.

Why this answer

Customer Satisfaction (CSAT) is a key metric for a service desk because it directly measures the user's perception of the quality and effectiveness of the support they received. ITIL 4 defines CSAT as a critical indicator of service value and customer experience, often collected via post-interaction surveys. First Contact Resolution (FCR) is equally vital as it tracks the percentage of incidents resolved during the first interaction, reducing downtime and operational costs.

Exam trap

The trap here is that candidates confuse infrastructure reliability metrics (MTBF) or financial metrics (ROI) with service desk performance indicators, but ITIL 4 explicitly defines CSAT and FCR as key service desk metrics in the Service Desk practice.

218
MCQeasy

What is the purpose of the Service Desk practice?

A.To monitor and control IT events
B.To manage the lifecycle of all IT assets
C.To negotiate service level agreements
D.To provide a single point of contact for users
AnswerD

The fundamental purpose of the Service Desk practice is to establish and maintain a single point of contact (SPOC) between the service provider and its users. This crucial role ensures that users have a consistent, accessible, and reliable channel for all IT-related inquiries, incident reporting, service requests, and information needs, thereby streamlining communication and enhancing user experience and satisfaction.

Why this answer

The Service Desk practice provides a single point of contact (SPOC) for users to report incidents, submit service requests, and receive updates. This ensures that all user interactions are logged, tracked, and managed consistently, aligning with the ITIL 4 guiding principle of 'Focus on Value' by reducing user confusion and improving resolution times.

Exam trap

The trap here is that candidates often confuse the Service Desk with other operational practices like Event Management or Asset Management, because all involve handling IT-related data, but the Service Desk is uniquely focused on being the user-facing single point of contact.

How to eliminate wrong answers

Option A is wrong because monitoring and controlling IT events is the purpose of the Event Management practice, not the Service Desk. Option B is wrong because managing the lifecycle of all IT assets is the purpose of the IT Asset Management practice, which focuses on tracking hardware, software, and licenses from acquisition to disposal. Option C is wrong because negotiating service level agreements is the purpose of the Service Level Management practice, which defines and reviews SLAs, not the Service Desk.

219
MCQhard

An organization implements a new monitoring tool that automatically detects and classifies events. A high-priority event triggers an alert. According to ITIL 4, what type of event is this?

A.Exception event
B.Informational event
C.Warning event
D.Normal event
AnswerA

An exception event signifies an abnormal situation where a service or component is operating outside its established baseline or expected parameters, often indicating a failure or a critical degradation. These events trigger immediate investigation and resolution efforts to prevent service disruption or restore normal operations, aligning with the core purpose of event management to detect and respond to deviations.

Why this answer

In ITIL 4, an exception event indicates that something has occurred that deviates from normal operation, often requiring immediate attention. A high-priority alert triggered by a monitoring tool automatically detecting and classifying events fits this definition, as it signals a significant anomaly that may impact services.

Exam trap

The trap here is that candidates confuse 'warning' with 'exception' because both involve alerts, but ITIL 4 distinguishes them by the required response—warnings are proactive notifications of potential issues, while exceptions are reactive alerts of actual failures requiring immediate action.

How to eliminate wrong answers

Option B is wrong because an informational event is a routine notification (e.g., a log entry confirming a scheduled task completed) that does not require action, not a high-priority alert. Option C is wrong because a warning event signals a potential future issue (e.g., disk usage exceeding 80%) but does not yet require immediate escalation, unlike a high-priority alert. Option D is wrong because a normal event is a standard operational occurrence (e.g., a user logging in) that is expected and does not trigger alerts.

220
MCQhard

A service consumer transfers costs and risks to the provider by using a service. Which of the following is an example of a risk that is removed from the consumer?

A.The risk of employee errors in using the service
B.The cost of purchasing and maintaining servers
C.The risk of data loss due to the consumer's internal processes
D.The provider's hardware failure causing service outage
AnswerD

This option perfectly illustrates a risk transferred from the consumer to the provider. When a consumer utilizes a service, they rely on the provider's infrastructure and operational capabilities. The risk associated with the provider's own hardware failing and subsequently causing a service outage is entirely borne by the provider, who is responsible for maintaining availability and resolving such incidents according to agreed service levels. The consumer pays for the service's outcome, not the direct management of infrastructure risks.

Why this answer

It describes a risk that is transferred from the consumer to the provider when using a service. The provider's hardware failure causing a service outage is a risk that the consumer no longer bears; instead, the provider is responsible for managing and mitigating this risk through redundancy, SLAs, and incident management processes. This aligns with the ITIL 4 concept of utility and warranty, where warranty ensures the service is available when needed, shifting operational risks to the provider.

Exam trap

The trap here is that candidates often confuse cost transfer (Option B) with risk transfer, or mistakenly think that all operational risks (like employee errors or data loss from internal processes) are automatically assumed by the provider, when in fact only risks explicitly covered by the service warranty and SLA are transferred.

How to eliminate wrong answers

Option A is wrong because employee errors in using the service remain the consumer's responsibility, as the consumer controls user training and access management; the provider does not assume this risk. Option B is wrong because the cost of purchasing and maintaining servers is a financial cost, not a risk; while costs are transferred, the question specifically asks for a risk, and this option confuses cost with risk. Option C is wrong because the risk of data loss due to the consumer's internal processes (e.g., poor backup practices or user mistakes) stays with the consumer, as the provider cannot control the consumer's internal operations or data handling procedures.

221
MCQmedium

A service desk team notices that many incidents are related to password issues. They decide to implement a self-service password reset tool. Which ITIL guiding principle is being applied?

A.Collaborate and promote visibility
B.Keep it simple and practical
C.Optimise and automate
D.Progress iteratively with feedback
AnswerC

Automating password resets removes repetitive manual effort from the service desk, streamlining the workflow so agents focus on higher-value work. This embodies Optimise and automate, which urges organisations to use technology to eliminate waste rather than simply doing the same manual task faster.

Why this answer

Implementing a self-service password reset tool automates a repetitive manual process (password reset requests), which directly aligns with the ITIL guiding principle 'Optimise and automate'. The team is not just making the process simpler; they are replacing human intervention with technology to reduce incident volume and improve efficiency.

Exam trap

The trap here is that candidates confuse 'automation' with 'simplification', leading them to choose 'Keep it simple and practical' (Option B) when the core action is actually replacing human effort with technology, not just reducing steps.

How to eliminate wrong answers

Option A is wrong because 'Collaborate and promote visibility' focuses on involving stakeholders and making work transparent, not on replacing a manual process with technology. Option B is wrong because 'Keep it simple and practical' emphasizes reducing complexity, but the team is not simplifying an existing process; they are automating it entirely. Option D is wrong because 'Progress iteratively with feedback' advocates for incremental improvements with continuous feedback, but the scenario describes a single implementation decision, not an iterative cycle.

222
Multi-Selectmedium

Which TWO statements about Problem Management are correct?

Select 2 answers
A.It includes root cause analysis to identify the underlying cause of incidents
B.It is responsible for implementing permanent fixes for recurring incidents
C.It focuses on recording and tracking individual incidents
D.It is responsible for restoring normal service operation
E.It is responsible for maintaining the known error database
AnswersA, E

Problem management fundamentally includes root cause analysis (RCA) as a core activity to systematically investigate and identify the underlying causes of incidents. This analytical process goes beyond merely restoring service, aiming to understand why incidents occur. By uncovering the true source of issues, problem management enables the development of effective solutions that prevent future recurrences, thereby improving service stability and reliability.

Why this answer

Option A is correct because Problem Management's core purpose is to perform root cause analysis (RCA) to determine the underlying cause of one or more incidents, preventing recurrence rather than just resolving symptoms. Option E is correct because Problem Management owns and maintains the Known Error Database (KEDB), which stores details of problems and their root causes along with documented workarounds, typically populated once a problem is diagnosed. Option B is not correct as stated because implementing permanent fixes is a change/implementation activity (Change Management/technical teams) that Problem Management triggers via an RFC, not something it directly performs.

Option C is incorrect because recording and tracking individual incidents is the responsibility of Incident Management, not Problem Management. Option D is incorrect because restoring normal service operation as quickly as possible is the primary objective of Incident Management.

Exam trap

ITIL4F often tests the distinction between Incident and Problem Management, and candidates frequently select 'restoring normal service operation' or 'recording incidents' as Problem Management responsibilities when those belong to Incident Management.

223
Multi-Selectmedium

Which TWO of the following are examples of triggers that initiate the ITIL 4 Service Value System?

Select 2 answers
A.Risk
B.Opportunity
C.Budget
D.Compliance
E.Demand
AnswersB, E

An opportunity serves as a significant trigger by presenting a potential for improvement, innovation, or the creation of new value for stakeholders. Recognizing an unmet market need, a technological advancement, or a chance to enhance efficiency can initiate the development of new services, features, or processes. These opportunities drive strategic initiatives aimed at capitalizing on potential benefits and expanding the organization's capabilities or market reach.

Why this answer

(Opportunity) is correct because the ITIL 4 Service Value System (SVS) is triggered by opportunities to create value for stakeholders, such as new market demands or technological advancements. Option E (Demand) is correct because demand for services—whether from internal or external customers—initiates the SVS to respond with value co-creation. Both are explicit triggers defined in ITIL 4 Foundation, representing the starting points for the service value chain activities.

Exam trap

The trap here is that candidates confuse inputs or constraints (like risk, budget, or compliance) with triggers, but ITIL 4 explicitly defines only demand and opportunity as the initiating factors for the Service Value System.

224
MCQmedium

An IT team is redesigning their incident management process. They decide to review existing documentation and current workflows before making any changes. Which ITIL 4 guiding principle are they applying?

A.Optimize and automate
B.Start where you are
C.Focus on value
D.Keep it simple and practical
AnswerB

The "Start where you are" guiding principle mandates that an organization should not discard existing resources or processes without first understanding their current state and value. For an IT team redesigning incident management, this means assessing the current process, identifying what works, what doesn't, and what can be reused or improved, rather than attempting to build an entirely new process from a blank slate. This foundational assessment prevents wasted effort and ensures continuity.

Why this answer

The guiding principle 'Start where you are' emphasizes using existing documentation, workflows, and processes as a baseline before making changes. By reviewing current incident management documentation and workflows, the team ensures they understand the current state, avoiding unnecessary rework and leveraging what already works. This aligns with ITIL 4's recommendation to assess and build upon existing practices rather than starting from scratch.

Exam trap

The trap here is that candidates confuse 'Start where you are' with 'Focus on value' or 'Keep it simple and practical,' because all three involve analysis, but only 'Start where you are' specifically requires reviewing existing documentation and workflows as the first step.

How to eliminate wrong answers

Option A is wrong because 'Optimize and automate' focuses on improving efficiency through automation and streamlining, not on reviewing existing documentation before changes. Option C is wrong because 'Focus on value' prioritizes delivering outcomes that matter to stakeholders, not the initial assessment of current workflows. Option D is wrong because 'Keep it simple and practical' advocates for minimal complexity in solutions, but does not specifically address the step of reviewing existing documentation before redesign.

225
Multi-Selecthard

Which THREE of the following are benefits of applying the 'Progress iteratively with feedback' principle?

Select 3 answers
A.More predictable delivery deadlines
B.Reduced need for collaboration
C.Reduced risk of large-scale failures
D.Early identification of issues and improvements
E.Greater flexibility to adapt to changes
AnswersC, D, E

By delivering value in small, manageable increments, the risk associated with large-scale failures is significantly mitigated. Each iteration allows for early detection of defects or misalignments with requirements, confining potential issues to a smaller scope. This approach prevents minor problems from escalating into catastrophic project failures, as corrections can be made frequently and with less overall impact.

Why this answer

The 'Progress iteratively with feedback' principle breaks work into smaller, manageable increments, allowing teams to detect and correct issues early. This iterative approach prevents the accumulation of errors that could lead to large-scale failures, as each increment is validated before proceeding, reducing the overall risk.

Exam trap

The trap here is that candidates may confuse 'iterative progress' with 'predictable deadlines' (Option A), not realizing that feedback-driven iterations can change scope and timelines, while the principle actually increases collaboration (Option B) rather than reducing it.

Page 2

Page 3 of 11

Page 4

All pages