Courseiva
ITIL Management Practices →mediumMultiple Choice

ITIL4F ITIL Management Practices Practice Question

An IT service desk analyst receives a call from a user who cannot access the CRM system. The user says this happened after a recent password change. What should the analyst do FIRST, according to ITIL 4?

⚠ Common exam trap

Test-takers frequently confuse incident management with problem management or change management, mistakenly thinking that a password change issue automatically warrants a problem investigation or a formal change reversal, when ITIL 4 mandates that restoring service (incident management) is the immediate priority.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log an incident record and attempt to resolve the access issue

According to ITIL 4, the analyst's first action should be to log an incident record and attempt to resolve the access issue. This aligns with the incident management practice, which prioritizes restoring normal service operation as quickly as possible. The user's inability to access the CRM system after a password change is a clear incident (an unplanned interruption or reduction in quality of an IT service), and the analyst should immediately capture the details and work toward a resolution, such as resetting the password or verifying account synchronization with the identity provider (e.g., Active Directory or LDAP).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Log an incident record and attempt to resolve the access issue

    Why this is correct

    The user's inability to access services due to a password issue constitutes an unplanned interruption to a service, which is the definition of an incident in ITIL 4. The primary objective of incident management is to restore normal service operation as quickly as possible, minimizing business impact. Logging the incident ensures it is properly tracked, prioritized, and managed through to resolution, aligning with ITIL's incident management practice.

  • ✗

    Direct the user to fill out a service request form for password assistance

    Why it's wrong here

    A service request is for a user to obtain a pre-defined, pre-approved service offering, such as requesting a new software installation or a standard password reset when there isn't an existing access issue. In this scenario, the user is experiencing an unplanned interruption to their access, which constitutes an incident, not a routine service request. Directing them to a form for a service request would delay the restoration of service and miscategorize the event.

  • ✗

    Submit a change request to reverse the password change

    Why it's wrong here

    While reversing a recent password change might be a potential resolution action, submitting a change request is not the immediate first step. A change request is typically for adding, modifying, or removing anything that could have a direct or indirect effect on services. The immediate priority is to restore service, which falls under incident management. The resolution of an incident might involve a change, but the initial action is to log the incident and diagnose the cause of the access failure.

  • ✗

    Create a problem record to investigate why the password change caused the issue

    Why it's wrong here

    Creating a problem record is premature and misprioritizes the immediate need. A problem is the cause, or potential cause, of one or more incidents. While there might be an underlying problem, such as a faulty password synchronization process, the immediate focus of the service desk is incident resolution—getting the user back to work. Problem management investigates root causes to prevent future incidents, but it is a distinct practice from incident management, which focuses on restoring service quickly.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 805 original ITIL4F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ITIL4F practice question is part of Courseiva's free PeopleCert certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4F exam.