Courseiva

CCNA ITIL Management Practices Questions

75 of 301 questions · Page 1/5 · ITIL Management Practices · Answers revealed

1
MCQmedium

An organization wants to ensure that its IT services meet the agreed performance levels. Which practice is primarily responsible for negotiating and monitoring these targets?

A.Availability Management
B.Supplier Management
C.Service Level Management
D.Capacity and Performance Management
AnswerC

Service Level Management negotiates, agrees, and monitors the service level agreements that define agreed performance targets. It is the practice accountable for measuring delivery against those commitments, satisfying the stem's requirement to meet agreed performance levels.

Why this answer

Service Level Management (SLM) is the ITIL practice responsible for negotiating, agreeing, and documenting service level targets (SLTs) in Service Level Agreements (SLAs), and then monitoring and reporting on actual performance against those targets. This ensures IT services consistently meet the agreed performance levels by establishing clear expectations and providing a framework for continuous improvement.

Exam trap

The trap here is that candidates often confuse Capacity and Performance Management (which monitors performance metrics) with Service Level Management (which negotiates and owns the targets), leading them to select D instead of C.

How to eliminate wrong answers

Option A is wrong because Availability Management focuses specifically on ensuring IT services are available when needed, managing risks to availability, and reporting on availability metrics, but it does not negotiate or monitor the broader set of performance targets (e.g., response times, throughput) that SLM handles. Option B is wrong because Supplier Management manages relationships with external suppliers, negotiating contracts and monitoring supplier performance, but it does not directly negotiate or monitor the end-to-end service performance targets for internal IT services. Option D is wrong because Capacity and Performance Management ensures that IT services have sufficient capacity to meet current and future demand and monitors performance metrics, but it does not negotiate SLTs or own the SLA process; it provides input to SLM.

2
MCQmedium

An IT team wants to prioritize incidents based on business impact and urgency. Which ITIL practice provides the framework for classifying and handling incidents?

A.Problem Management
B.Service Desk
C.Event Management
D.Incident Management
AnswerD

Incident Management is the ITIL practice responsible for minimizing the negative impact of incidents by restoring normal service operation as quickly as possible. A core component of this practice involves the classification and prioritization of incidents, typically based on their urgency and impact on business operations. This ensures that critical incidents affecting business value are addressed with appropriate speed and resources.

Why this answer

Incident Management (D) is the correct ITIL practice because it provides the specific framework for classifying, prioritizing, and handling incidents based on business impact and urgency. This practice defines the lifecycle from detection through resolution, including categorization and prioritization matrices that directly address the scenario's requirement.

Exam trap

The trap here is that candidates confuse the Service Desk (a function) with Incident Management (a practice), or mistakenly think Problem Management handles individual incidents, when in fact Incident Management is the correct practice for classification and handling.

How to eliminate wrong answers

Option A is wrong because Problem Management focuses on identifying and eliminating the root causes of incidents to prevent recurrence, not on classifying and handling individual incidents as they occur. Option B is wrong because the Service Desk is a functional team that provides a single point of contact for users, but it does not define the framework for incident classification and handling—it executes the Incident Management process. Option C is wrong because Event Management monitors and responds to IT events (e.g., alerts, notifications) but does not provide the structured classification and handling framework for incidents; incidents are a subset of events that require the Incident Management practice.

3
MCQhard

Which of the following BEST describes the difference between an incident and a service request?

A.Incidents require a workaround; service requests do not
B.Incidents are always resolved within 24 hours; service requests have no time limit
C.Incidents are unplanned disruptions; service requests are routine, pre-approved requests
D.Incidents are handled by the service desk; service requests are handled by change enablement
AnswerC

The axis is cause versus intent: incidents arise from unplanned disruption or degradation, whereas service requests are routine, pre-approved user asks handled through a defined workflow. This distinction drives separate logging, prioritisation and escalation paths.

Why this answer

The ITIL 4 definition clearly distinguishes incidents as unplanned interruptions or reductions in service quality, while service requests are pre-defined, standardized, and pre-approved requests from users for information, advice, or access. This aligns with the ITIL 4 Foundation syllabus, which separates the two based on the nature of the trigger—unplanned vs. planned—not on resolution time, workaround necessity, or assignment team.

Exam trap

The trap here is that candidates confuse the operational handling (e.g., who resolves it or time limits) with the fundamental definitional difference, leading them to pick options that describe common practices rather than the ITIL 4 core distinction between unplanned and planned activities.

How to eliminate wrong answers

Option A is wrong because workarounds are not a defining characteristic of incidents; many incidents are resolved without a workaround, and service requests can also have workarounds if the standard procedure fails. Option B is wrong because ITIL 4 does not mandate a 24-hour resolution time for incidents; service level targets vary by organization and are defined in SLAs, not by ITIL. Option D is wrong because both incidents and service requests are typically handled by the service desk as the single point of contact; change enablement handles changes, not service requests or incidents directly.

4
MCQhard

An IT department is considering replacing a critical server. According to ITIL 4, which type of change should be used if the replacement involves a new, untested model and requires a full risk assessment?

A.Standard change
B.Service request
C.Normal change
D.Emergency change
AnswerC

A normal change is any change that is not standard or emergency, requiring a full assessment, authorization, and scheduling process. This type of change typically involves a structured workflow, including planning, risk and impact analysis, approval by a change authority (such as a Change Advisory Board or CAB), and careful coordination. Replacing a critical server, given its potential impact and the need for careful planning and approval, perfectly aligns with the characteristics and rigor of a normal change.

Why this answer

A normal change is used for changes that are not pre-authorized and require a full risk assessment and approval process. Since the server replacement involves a new, untested model, it carries significant risk and cannot be classified as a standard change (which is pre-approved and low-risk) or an emergency change (which is for urgent, unplanned changes). A service request is for routine user requests, not infrastructure changes.

Therefore, a normal change is the correct choice.

Exam trap

ITIL4F often tests the misconception that any planned change can be a standard change if it follows a procedure, but standard changes must be pre-approved and low-risk; a new, untested server replacement requires a full risk assessment, making it a normal change.

How to eliminate wrong answers

Option A is wrong because a standard change is a pre-authorized, low-risk change that follows a defined procedure, and replacing a critical server with an untested model does not meet these criteria. Option B is wrong because a service request is a user-initiated request for something like password resets or software installation, not a major infrastructure change. Option D is wrong because an emergency change is reserved for urgent situations that require immediate action to resolve an incident or security issue, and this planned replacement does not qualify.

5
MCQeasy

Which ITIL 4 practice involves the 7-step improvement model?

A.Incident Management
B.Continual Improvement
C.Problem Management
D.Change Enablement
AnswerB

Continual Improvement is the ITIL 4 practice explicitly dedicated to aligning an organization's practices and services with changing business needs through ongoing, iterative improvement. It directly utilizes the ITIL Continual Improvement Model, which is a seven-step framework guiding all improvement initiatives from defining the vision to sustaining momentum. This model provides a structured approach for identifying, planning, implementing, and reviewing improvements across the entire service value system.

Why this answer

The Continual Improvement practice in ITIL 4 is directly associated with the 7-step improvement model, which provides a structured approach to identifying, defining, and implementing improvements. This practice ensures that services continually align with business needs.

Exam trap

ITIL 4 Foundation often tests the association of the 7-step improvement model with the Continual Improvement practice, but candidates may confuse it with Problem Management due to the focus on root cause analysis.

How to eliminate wrong answers

Option A is wrong because Incident Management focuses on restoring normal service operation quickly, not on the 7-step improvement model. Option C is wrong because Problem Management aims to identify root causes of incidents, not to drive continual improvement. Option D is wrong because Change Enablement manages changes to services, not the improvement process itself.

6
MCQhard

A service desk agent resolves a password reset request after verifying the user's identity. According to ITIL 4, which metrics would be most appropriate to measure the performance of this interaction?

A.Change success rate and backout success
B.Mean Time to Repair (MTTR) and uptime
C.Number of problems and known errors
D.First Contact Resolution (FCR) and Customer Satisfaction (CSAT)
AnswerD

First Contact Resolution (FCR) is a crucial service desk metric that measures the percentage of requests or incidents resolved entirely during the initial interaction, directly reflecting efficiency and user convenience. Customer Satisfaction (CSAT) gauges how pleased users are with the service received, often collected immediately after resolution. For a password reset, successfully resolving it on the first contact and ensuring the user is satisfied are primary indicators of effective service desk performance and value delivery.

Why this answer

For a password reset request resolved at the service desk, the most appropriate metrics are First Contact Resolution (FCR) and Customer Satisfaction (CSAT). FCR measures the percentage of incidents resolved on the first contact without escalation, which directly applies to a password reset. CSAT measures the user's satisfaction with the interaction, providing feedback on the service quality.

Exam trap

ITIL4F often tests the confusion between incident metrics (FCR, CSAT) and other ITIL practices like change management (change success rate) or problem management (known errors), so candidates must match the metric to the practice.

How to eliminate wrong answers

Option A is wrong because change success rate and backout success are metrics for change management, not incident resolution. Option B is wrong because MTTR and uptime are availability and repair metrics, typically used for infrastructure or major incidents, not for individual service desk interactions. Option C is wrong because number of problems and known errors are problem management metrics, not incident resolution metrics.

7
Multi-Selectmedium

Which THREE actions are part of Supplier Management?

Select 3 answers
A.Setting SLA targets for internal teams
B.Providing training to supplier staff
C.Managing supplier contracts
D.Monitoring supplier performance
E.Evaluating and selecting suppliers
AnswersC, D, E

Managing supplier contracts is a fundamental and integral activity within the Supplier Management practice. This involves the entire lifecycle of contracts, from negotiation and establishment to ongoing administration, amendment, and eventual termination. Effective contract management ensures that terms, conditions, and service expectations are clearly defined, legally binding, and consistently met by external providers, safeguarding the organization's interests and service delivery.

Why this answer

Supplier Management in ITIL/IT service management covers the activities needed to manage the suppliers that deliver products and services to the organization. Option C is correct because managing supplier contracts — including negotiation, maintenance, renewal, and compliance with agreed terms — is a core supplier management activity. Option D is correct because monitoring supplier performance against agreed SLAs, KPIs, and service levels ensures suppliers meet their contractual obligations and supports continual improvement.

Option E is correct because evaluating and selecting suppliers is part of the sourcing and supplier strategy process, ensuring the right suppliers are chosen before contracts are established. Option A is not part of supplier management because setting SLA targets for internal teams concerns internal service level management, not external suppliers. Option B is not a standard supplier management action; while training may occasionally be arranged, providing training to supplier staff is the supplier's own responsibility and is not one of the core supplier management processes.

Exam trap

ITIL4F often tests the confusion between Supplier Management and Service Level Management, where candidates incorrectly include internal SLA setting as part of Supplier Management.

8
Multi-Selecthard

Which TWO statements correctly describe the difference between Incident Management and Problem Management? (Choose two.)

Select 2 answers
A.Incident management aims to eliminate the root cause of disruptions.
B.Problem management investigates the underlying cause of one or more incidents.
C.Problem management is responsible for logging all service interruptions.
D.Incident management may use a workaround to restore service quickly.
E.Problem management only focuses on known errors after incidents are resolved.
AnswersB, D

Problem management is specifically designed to identify and investigate the underlying causes of incidents, often performing root cause analysis (RCA). By understanding why incidents occur, problem management aims to prevent their recurrence and minimize future service disruptions. This proactive and reactive approach contributes significantly to long-term service stability and improvement.

Why this answer

Option B is correct because Problem Management is the practice that performs root cause analysis (RCA) to determine why one or more incidents occurred, typically producing a known error record when the underlying fault is identified. Option D is correct because Incident Management prioritizes restoring normal service as quickly as possible, and a documented workaround is a legitimate means to achieve that restoration even when the root cause is not yet known. Option A is wrong because eliminating the root cause is the goal of Problem Management, not Incident Management, which focuses on service restoration.

Option C is wrong because logging all service interruptions is an Incident Management activity (incident logging/recording), not a Problem Management responsibility. Option E is wrong because Problem Management is not limited to known errors after resolution; it also performs proactive problem management and reactive investigation of open incidents to identify root causes and workarounds.

Exam trap

The trap here is confusing the reactive, service-restoration focus of Incident Management with the proactive, root-cause-analysis focus of Problem Management, leading candidates to incorrectly assign 'eliminate root cause' to Incident Management or 'log all interruptions' to Problem Management.

9
Multi-Selecthard

Which THREE of the following are components of the Service Value System (SVS) according to ITIL 4?

Select 3 answers
A.Service Value Chain
B.Outcomes
C.Governance
D.Value Streams
E.Guiding Principles
AnswersA, C, E

One of the five SVS components.

Why this answer

The Service Value Chain is a core component of the ITIL 4 Service Value System (SVS). It provides an operating model for the creation, delivery, and continual improvement of services through six key activities: plan, improve, engage, design & transition, obtain/build, and deliver & support.

Exam trap

The trap here is that candidates often confuse 'Value Streams' with the 'Service Value Chain' as a component of the SVS, but ITIL 4 explicitly defines the Service Value Chain as the structural component, while value streams are derived from it and are not listed as a separate SVS component.

10
MCQmedium

A configuration baseline is used primarily in which practice?

A.Service Configuration Management
B.IT Asset Management
C.Deployment Management
D.Change Enablement
AnswerA

Service Configuration Management is the practice responsible for ensuring that accurate and reliable information about the configuration of services and the Configuration Items (CIs) that support them is available when and where it is needed. A configuration baseline, representing an approved configuration of a service or product at a specific point in time, is a critical output and input for this practice. It provides a known, good state for recovery, change validation, and audit purposes, directly aligning with the core objectives of managing configuration information throughout its lifecycle.

Why this answer

A configuration baseline is primarily used in Service Configuration Management because it defines a known, approved state of one or more configuration items (CIs) against which changes and deviations are measured. This practice ensures that the configuration data is accurate and that baselines are recorded in the Configuration Management Database (CMDB) to support release, change, and incident management processes.

Exam trap

The trap here is that candidates confuse the 'use' of a baseline (e.g., in Deployment Management to roll back a release) with the 'primary practice' that defines and maintains it, which is Service Configuration Management.

How to eliminate wrong answers

Option B is wrong because IT Asset Management focuses on the financial and lifecycle management of assets (e.g., procurement, depreciation, disposal), not on establishing technical baselines of CIs. Option C is wrong because Deployment Management handles the movement of new or changed hardware, software, or documentation into live environments, but it uses baselines created by Service Configuration Management rather than defining them itself. Option D is wrong because Change Enablement controls the lifecycle of changes (request, assessment, approval, implementation), but it relies on configuration baselines to assess impact and authorize changes, not to create or maintain them.

11
MCQmedium

A change that is low risk, pre-approved, and follows a defined procedure is classified as which type of change?

A.Standard change
B.Service request
C.Normal change
D.Emergency change
AnswerA

Standard changes are pre-authorised, low-risk changes with a documented procedure, so they bypass the normal change advisory board review. This matches the stem's three constraints exactly: low risk, pre-approved, and following a defined procedure. Emergency changes need urgent approval, while normal changes require full assessment and authorisation.

Why this answer

Standard changes are pre-approved, low risk, and follow a defined procedure. Option A is correct. Normal changes require authorization.

Emergency changes are for urgent issues and require urgent authorization.

12
MCQhard

A Configuration Management Database (CMDB) is maintained by which practice?

A.Monitoring and Event Management
B.Service Desk
C.Service Configuration Management
D.IT Asset Management
AnswerC

Service Configuration Management is the dedicated practice responsible for ensuring that accurate and reliable information about the configuration of services and the CIs that support them is available when and where needed. This includes planning, identifying, controlling, recording, reporting, and verifying all configuration items and their relationships. The CMDB is the central repository for this critical information, and its integrity and maintenance are direct responsibilities of this practice.

Why this answer

The Configuration Management Database (CMDB) is the central repository for storing and managing configuration records (CIs) and their relationships. This is the core responsibility of the Service Configuration Management practice, which ensures that accurate and reliable information about CIs is available to support other service management processes.

Exam trap

The trap here is that candidates confuse IT Asset Management with Service Configuration Management because both deal with tracking IT resources, but ITAM focuses on financial lifecycle and ownership (e.g., cost, contract, depreciation) while Service Configuration Management focuses on technical relationships and configuration control (e.g., CI dependencies, versioning).

How to eliminate wrong answers

Option A is wrong because Monitoring and Event Management focuses on detecting and reacting to events (e.g., SNMP traps, syslog messages) and does not maintain a CMDB; it may consume CI data but does not own it. Option B is wrong because the Service Desk is the single point of contact for users and handles incidents and service requests, but it does not maintain the CMDB; it may use CMDB data for context but is not responsible for its accuracy or updates. Option D is wrong because IT Asset Management (ITAM) manages the lifecycle of financial assets (e.g., procurement, depreciation, disposal) and typically uses an Asset Management Database (AMDB) that is separate from the CMDB; while CIs and assets may overlap, the CMDB is specifically for configuration items and their relationships, not financial tracking.

13
MCQeasy

What type of change is pre-authorized and follows a low-risk, standardized procedure?

A.Normal change
B.Service request
C.Emergency change
D.Standard change
AnswerD

A standard change is pre-authorised through an established, documented procedure with known low risk, so it proceeds without individual assessment or authorisation each time. This matches the stem's requirement for a pre-authorised, low-risk, standardised change type.

Why this answer

D is correct because a Standard change is pre-authorized by default and follows a low-risk, standardized procedure, such as applying a routine security patch or provisioning a new user account. This aligns with ITIL 4's definition of a Standard change as one that is well-understood, fully documented, and can be implemented without requiring additional approval each time.

Exam trap

The trap here is that candidates often confuse a Service request (Option B) with a Standard change because both are pre-defined and low-risk, but ITIL 4 explicitly categorizes Service requests as separate from changes, focusing on user-initiated requests like password resets rather than infrastructure modifications.

How to eliminate wrong answers

Option A is wrong because a Normal change requires formal approval from a Change Authority (e.g., CAB) and follows a non-standardized, risk-assessed procedure, not a pre-authorized low-risk one. Option B is wrong because a Service request is a formal request for something (e.g., access, information) that follows a predefined workflow, but it is not a type of change; ITIL distinguishes service requests from change types. Option C is wrong because an Emergency change is used for urgent, high-risk situations (e.g., critical security vulnerability patch) and must be authorized urgently, often via an emergency CAB, not pre-authorized as low-risk.

14
MCQhard

An IT team is investigating recurring network outages. They identify the root cause as a faulty switch and record the issue as a known error with a workaround. Which ITIL 4 practice is being applied?

A.Supplier Management
B.Service Desk
C.Problem Management
D.Incident Management
AnswerC

Problem Management is the ITIL practice dedicated to reducing the likelihood and impact of incidents by identifying and resolving their underlying causes. Investigating recurring network outages directly aligns with its objectives, which include performing root cause analysis, managing known errors, and implementing permanent solutions. This proactive approach aims to prevent future incidents and improve overall service stability, making it the correct practice for this scenario.

Why this answer

Problem management is the ITIL 4 practice responsible for managing the lifecycle of problems, including identifying root causes, recording known errors, and documenting workarounds. Investigating recurring outages, finding a faulty switch as the root cause, and logging a known error with a workaround are textbook problem management activities. Incident management would only restore service, not investigate the underlying cause.

Exam trap

ITIL4F often tests the boundary between incident management (restore service fast) and problem management (find root cause and log known errors); candidates who see 'recurring outages' and jump to incident management fall into the trap.

How to eliminate wrong answers

Option A is wrong because supplier management deals with managing third-party relationships and performance, not with root cause analysis of internal network faults. Option B is wrong because the service desk is the entry point for user contact and incident logging, not the practice that performs root cause investigation and known error documentation. Option D is wrong because incident management focuses on restoring normal service operation as quickly as possible; it does not own root cause analysis or the known error database, which belong to problem management.

15
MCQhard

After a major incident, the Problem Management team identifies a known error and documents a workaround. According to ITIL 4, which practice is responsible for ensuring the workaround is implemented to restore service?

A.Change Enablement
B.Incident Management
C.Problem Management
D.Service Request Management
AnswerB

Incident Management is the practice responsible for minimizing the negative impact of incidents by restoring normal service operation as quickly as possible. Its core objective is rapid service restoration, which frequently involves applying pre-identified workarounds or temporary fixes to mitigate the immediate disruption. Therefore, applying a workaround to restore service after a major incident is a direct and critical function of Incident Management, ensuring business continuity.

Why this answer

In ITIL 4, Incident Management is the practice responsible for restoring normal service operation as quickly as possible, and applying a documented workaround is a standard incident resolution technique. Problem Management identifies the root cause and documents the known error and workaround, but it is Incident Management that executes the workaround to restore service. Change Enablement and Service Request Management do not own service restoration during an active incident.

Exam trap

ITIL4F often tests the boundary between Problem Management (owns the known error and workaround documentation) and Incident Management (executes the workaround to restore service), so candidates must not assign execution to Problem Management.

How to eliminate wrong answers

Option A is wrong because Change Enablement authorizes and schedules changes; applying a workaround to restore service is not a change request process, and invoking change control during an incident would delay restoration. Option C is wrong because Problem Management owns root-cause analysis and known-error documentation, but it does not directly restore service — that is the incident team's job. Option D is wrong because Service Request Management handles standard, pre-approved user requests (e.g., password resets, access provisioning), not incident restoration.

16
MCQhard

A user requests new software to be installed on their company laptop. The installation is pre-approved and follows a standard procedure. According to ITIL 4, this request should be categorized as:

A.A problem
B.An incident
C.An emergency change
D.A service request
AnswerD

A service request is a formal request from a user for something that is a normal part of service delivery, often pre-approved and following a standard procedure. This includes requests for information, standard changes, or access to a service. A user asking for new software, especially if it's a standard, approved application, perfectly fits this definition as it's a routine, expected action that initiates a defined fulfillment workflow.

Why this answer

D is correct because a service request in ITIL 4 is defined as a formal request from a user for something to be provided – for example, information, advice, access to a service, or a pre-approved standard change. Since the software installation is pre-approved and follows a standard procedure, it fits the definition of a service request, not an incident or problem.

Exam trap

The trap here is that candidates often confuse a 'service request' with a 'standard change' or think any request for a change is a 'change request', but ITIL 4 explicitly categorizes pre-approved, user-initiated requests for standard items as service requests, not changes.

How to eliminate wrong answers

Option A is wrong because a problem is the root cause of one or more incidents, not a request for a standard, pre-approved installation. Option B is wrong because an incident is an unplanned interruption or reduction in quality of an IT service, whereas this is a planned, pre-approved request. Option C is wrong because an emergency change is a change that must be implemented as soon as possible to resolve a major incident or security threat, not a routine, pre-approved software installation.

17
MCQeasy

What is the ITIL 4 Continual Improvement Model?

A.A 7-step process for improvement
B.A 3-step process for problem management
C.A 5-step process for incident handling
D.A 4-step process for change authorization
AnswerA

The Continual Improvement Model structures improvement into seven sequential steps, from vision and current state through to action and evaluation. This iterative sequence satisfies the stem's definition, embedding improvement as a routine activity across the service value chain rather than a one-off project.

Why this answer

The ITIL 4 Continual Improvement Model is a structured 7-step process designed to guide organizations in identifying, planning, and implementing improvements to services and practices. It ensures that improvement efforts are aligned with business objectives and are measurable, following steps from 'What is the vision?' to 'Did we get there?'.

Exam trap

The trap here is that candidates often confuse the Continual Improvement Model's 7 steps with other ITIL 4 practice processes (like the 5-step incident management or 3-step problem management), leading them to select a wrong option based on a familiar number of steps.

How to eliminate wrong answers

Option B is wrong because problem management in ITIL 4 uses a separate 3-step model (identify, control, and resolve) or the 5-step problem management practice, not the Continual Improvement Model. Option C is wrong because incident handling follows a distinct 5-step process (identify, log, categorize, prioritize, resolve/close) and is not the Continual Improvement Model. Option D is wrong because change authorization is part of the change enablement practice, which involves a 4-step workflow (request, assess, authorize, implement) but is not the Continual Improvement Model.

18
MCQhard

Which of the following scenarios BEST illustrates the difference between an incident and a service request?

A.A user reports a system crash (service request) and requests a software upgrade (incident)
B.A user requests a password reset (service request) and later reports that the email system is down (incident)
C.A user requests a new laptop (incident) and reports a printer jam (service request)
D.A user requests access to a database (incident) and reports a network outage (incident)
AnswerB

This option correctly differentiates between an incident and a service request according to ITIL 4 principles. A password reset is a common, pre-defined user request for a standard service, accurately categorized as a service request. Reporting that the email system is down, however, signifies an unplanned interruption to a critical service, which is precisely what defines an an incident requiring prompt resolution to restore functionality.

Why this answer

A password reset is a routine, pre-approved service request fulfilled through the service catalogue, while an email system outage is an unplanned interruption of service and therefore an incident. Option B correctly pairs a service request with an incident, illustrating the distinction ITIL 4 draws between planned request fulfillment and incident resolution. This is the only option where both labels are applied correctly.

Exam trap

ITIL4F often tests the incident vs. service request distinction by presenting scenarios where the labels are swapped, tricking candidates who scan for keywords like 'crash' or 'outage' without verifying which term is applied to which event.

How to eliminate wrong answers

Option A is wrong because a system crash is an unplanned interruption (incident), not a service request, and a software upgrade request is a planned service request, not an incident — the labels are reversed. Option C is wrong because a new laptop request is a service request, not an incident, and a printer jam is a service disruption (incident), not a service request — again reversed. Option D is wrong because a database access request is a service request, not an incident, even though the network outage is correctly labeled as an incident.

19
Multi-Selectmedium

Which TWO of the following are key metrics for the Service Desk practice?

Select 2 answers
A.Mean Time Between Failures (MTBF)
B.First Call Resolution (FCR)
C.Recovery Time Objective (RTO)
D.Customer Satisfaction Score (CSAT)
E.Mean Time to Restore Service (MTTR)
AnswersB, D

First Call Resolution measures the percentage of user contacts resolved at first contact without escalation or callback, directly reflecting Service Desk effectiveness. It satisfies the stem's requirement for a key Service Desk metric, alongside measures such as average handling time and user satisfaction.

Why this answer

First Call Resolution (FCR) (option B) is a core Service Desk metric because it measures the percentage of user incidents or requests resolved during the initial contact without escalation or callback, directly reflecting the desk's efficiency and effectiveness. Customer Satisfaction Score (CSAT) (option D) is equally essential, as it captures user perception of the support experience and is a standard KPI for evaluating Service Desk quality and service experience. By contrast, Mean Time Between Failures (MTBF) (option A) is a reliability metric for components or systems, not a Service Desk performance measure.

Recovery Time Objective (RTO) (option C) is a continuity and availability target for restoring services after disruption, owned by continuity/availability management rather than the Service Desk. Mean Time to Restore Service (MTTR) (option E) measures how quickly a service is restored after failure, which is an incident and availability management metric rather than a primary Service Desk KPI.

Exam trap

The trap here is that candidates confuse operational metrics like MTTR (which is for Incident Management) with Service Desk-specific metrics, or they mistakenly think MTBF (a reliability metric) applies to the Service Desk's daily performance rather than to infrastructure components.

20
MCQeasy

What is the purpose of the 'shift-left' strategy in a service desk?

A.To enable users to resolve issues themselves via a portal
B.To resolve more incidents at the first point of contact without escalation
C.To increase system availability by reducing downtime
D.To automate incident resolution using artificial intelligence
AnswerB

The shift-left strategy aims to empower the lowest possible support tier, typically the service desk or first-line support, to resolve a higher percentage of incidents and service requests. By providing these teams with enhanced knowledge, tools, and training, issues are addressed at the initial point of contact. This reduces the need for costly and time-consuming escalations to specialized second or third-line support, improving efficiency and customer satisfaction.

Why this answer

Shift-left strategy in a service desk aims to resolve incidents at the earliest possible point, typically the first point of contact (e.g., service desk agent or self-service portal), thereby minimizing escalations. The correct answer is B because it directly captures this purpose: resolving more incidents at the first point of contact without escalation. Option A describes self-service, which is a method of shift-left but not its overall purpose.

Option C is related to availability management, and option D is about automation, which are not the primary purpose of shift-left.

21
MCQmedium

Which of the following is the correct distinction between Incident Management and Problem Management?

A.Incident Management restores service; Problem Management finds root causes
B.Incident Management finds root causes; Problem Management restores service
C.Incident Management handles change requests; Problem Management manages incidents
D.Incident Management is reactive; Problem Management is always proactive
AnswerA

Incident Management's primary objective is to restore normal service operation as quickly as possible, minimizing business impact. Conversely, Problem Management focuses on identifying and understanding the root causes of incidents to prevent their recurrence or minimize their impact. This clear division ensures both immediate recovery and long-term service stability by addressing symptoms and underlying issues respectively.

Why this answer

Incident Management focuses on restoring service as quickly as possible, while Problem Management focuses on identifying root causes to prevent recurrence. Option A is correct. Option B is incorrect because it reverses the roles.

Option C is incorrect because Incident Management does not handle change requests; that is Change Enablement. Option D is incorrect because Problem Management can be both reactive and proactive, not always proactive.

22
Multi-Selectmedium

Which TWO of the following are activities of the Problem Management practice according to ITIL 4?

Select 2 answers
A.Fulfilling service requests
B.Restoring service by applying a workaround
C.Authorizing changes
D.Performing root cause analysis
E.Identifying and logging problems
AnswersD, E

Root cause analysis is a core Problem Management activity: it identifies why an incident occurred and what underlying error or cause must be removed to prevent recurrence, feeding problem control and error control within the ITIL 4 practice.

Why this answer

Option D (Performing root cause analysis) is correct because Problem Management's core purpose is to reduce the likelihood and impact of incidents by identifying their actual and potential causes, which is exactly what root cause analysis accomplishes. Option E (Identifying and logging problems) is correct because Problem Management owns the problem record lifecycle, and detecting and recording problems (often from incident trends or major incidents) is a foundational activity of the practice. Option A (Fulfilling service requests) belongs to Service Request Management, which handles user-initiated requests rather than investigating causes.

Option B (Restoring service by applying a workaround) is an Incident Management activity, since incident management focuses on restoring service quickly, while Problem Management may later investigate the underlying cause. Option C (Authorizing changes) is performed by Change Enablement, which assesses and authorizes changes, not by Problem Management.

Exam trap

The trap here is that candidates confuse the reactive restoration activities of Incident Management (like applying workarounds) with the proactive diagnostic activities of Problem Management, leading them to select Option B instead of D or E.

23
Multi-Selectmedium

Which TWO are components of the ITIL 4 Service Value System?

Select 2 answers
A.Governance
B.Incident Management
C.Service desk
D.Guiding principles
E.Service portfolio
AnswersA, D

Governance is a fundamental component of the ITIL 4 Service Value System (SVS), providing the means by which an organization is directed and controlled. It encompasses the framework of policies, roles, and responsibilities that ensure the organization's strategy is implemented effectively and that objectives are achieved. This component ensures accountability and decision-making authority are clearly defined, aligning service management activities with overall business goals and regulatory requirements.

Why this answer

The ITIL 4 Service Value System (SVS) consists of five components: guiding principles, governance, the service value chain, practices, and continual improvement. Option A (Governance) is correct because governance is one of the five core components of the SVS, describing how an organization is directed and controlled through policies, rules, and decision-making structures. Option D (Guiding principles) is correct because the guiding principles are another core SVS component, providing recommendations that guide an organization in all circumstances.

Option B (Incident Management) is incorrect because incident management is a management practice within ITIL 4, not a component of the SVS itself. Option C (Service desk) is incorrect because the service desk is a specific practice (part of the practices component), not a standalone SVS component. Option E (Service portfolio) is incorrect because the service portfolio is a management tool/artifact associated with the service portfolio management practice, not one of the five SVS components.

Exam trap

The trap here is that candidates confuse ITIL management practices (like Incident Management) or operational functions (like Service Desk) with the high-level structural components of the SVS, which are limited to the five specific elements defined in ITIL 4 Foundation.

24
MCQeasy

What is the primary focus of the Service Desk practice?

A.Monitoring and managing events
B.Providing a single point of contact for users
C.Ensuring services meet agreed capacity levels
D.Managing the lifecycle of all IT assets
AnswerB

This is the correct answer as the Service Desk practice is explicitly designed to be the single point of contact (SPOC) between the service provider and its users. Its primary function is to handle all user interactions, including incidents, service requests, and inquiries, ensuring efficient communication and coordination. By centralizing these interactions, the Service Desk facilitates prompt resolution and maintains user satisfaction, acting as the crucial interface for all service-related matters.

Why this answer

The Service Desk practice is defined in ITIL 4 as the entry point and single point of contact for users seeking support, reporting incidents, or requesting services. Its primary focus is on capturing, managing, and resolving user interactions, not on technical infrastructure monitoring or asset lifecycle management.

Exam trap

PeopleCert often tests the distinction between user-facing practices (Service Desk) and infrastructure-focused practices (Event Management, Capacity Management, Asset Management), leading candidates to confuse the Service Desk's role with operational monitoring or asset tracking.

How to eliminate wrong answers

Option A is wrong because monitoring and managing events is the primary focus of the ITIL Event Management practice, which deals with detecting and responding to alerts from infrastructure components, not user-facing interactions. Option C is wrong because ensuring services meet agreed capacity levels is the responsibility of the Capacity and Performance Management practice, which involves monitoring resource utilization and planning for future demand. Option D is wrong because managing the lifecycle of all IT assets is the domain of the IT Asset Management practice, which tracks hardware, software, and other assets from acquisition to disposal.

25
MCQhard

A service provider uses a third-party data center. They want to ensure the data center's availability meets their requirements. Which document should they use to define these requirements?

A.Operational Level Agreement (OLA)
B.Underpinning Contract (UC)
C.Service Level Agreement (SLA)
D.Service Improvement Plan (SIP)
AnswerB

An Underpinning Contract (UC) is a formal agreement between the service provider and a third-party supplier, such as a data centre operator, that specifies required availability levels, performance targets, and remedies for non-compliance. This document directly satisfies the stem’s constraint of defining measurable availability requirements for an externally hosted facility, ensuring the provider can enforce service levels contractually rather than relying on informal expectations.

Why this answer

An Underpinning Contract (UC) is the agreement between the service provider and an external third-party supplier that defines the services and targets the supplier must meet to support the provider's SLAs. Since the data center is a third party, the UC is the correct document to define availability requirements for that supplier.

Exam trap

The trap is confusing SLA, OLA, and UC — candidates pick SLA because it sounds most formal, but the exam specifically tests that third-party supplier agreements are UCs, internal agreements are OLAs, and customer agreements are SLAs.

How to eliminate wrong answers

Option A is wrong because an Operational Level Agreement (OLA) is an internal agreement between teams within the same organization (for example, between the network team and the service desk), not with an external supplier. Option C is wrong because a Service Level Agreement (SLA) is between the service provider and the customer, defining the service levels the customer receives — it does not govern the third-party data center. Option D is wrong because a Service Improvement Plan (SIP) is a document created to address ongoing service improvement after a review, not a contractual instrument for defining supplier requirements.

26
MCQeasy

Which ITIL 4 practice is responsible for managing the lifecycle of IT assets from acquisition to disposal?

A.IT Asset Management
B.Supplier Management
C.Change Enablement
D.Service Configuration Management
AnswerA

IT Asset Management governs the full lifecycle of IT assets, covering acquisition, deployment, maintenance, and disposal. This directly satisfies the stem's requirement for cradle-to-grave accountability, tracking financial, contractual, and inventory data across each asset's life. No other ITIL 4 practice owns end-to-end asset lifecycle responsibility.

Why this answer

IT Asset Management (ITAM) is the ITIL 4 practice that governs the entire lifecycle of IT assets, including acquisition, deployment, maintenance, and disposal. It ensures that assets are tracked, accounted for, and managed to maximize value and minimize risk. The other practices focus on different areas: Supplier Management handles vendor relationships, Change Enablement controls changes, and Service Configuration Management manages configuration items and their relationships.

Exam trap

ITIL4F often tests the distinction between IT Asset Management and Service Configuration Management, as both deal with assets but ITAM focuses on the financial and lifecycle aspects while Service Configuration Management focuses on relationships and service delivery.

How to eliminate wrong answers

Option B is wrong because Supplier Management focuses on managing suppliers and their performance, not the lifecycle of IT assets. Option C is wrong because Change Enablement is responsible for controlling changes to IT services, not asset lifecycle. Option D is wrong because Service Configuration Management manages configuration items (CIs) and their relationships, but does not specifically cover the financial and lifecycle aspects of IT assets from acquisition to disposal.

27
MCQhard

An organization wants to ensure that its IT services are available according to agreed levels. Which practice is PRIMARILY responsible for negotiating and monitoring these levels?

A.IT Asset Management
B.Availability Management
C.Service Level Management
D.Monitoring and Event Management
AnswerC

Service Level Management (SLM) is the practice of setting clear, business-focused targets for service performance, including availability, and then monitoring and reporting against those targets. It involves negotiating Service Level Agreements (SLAs) with customers, ensuring that services meet agreed expectations, and managing customer perceptions of service quality. This practice directly ensures that IT services achieve agreed availability levels from the customer's perspective by formalizing commitments.

Why this answer

Service Level Management (SLM) is the ITIL practice responsible for negotiating, agreeing, and documenting service level targets with customers, and then monitoring and reporting on actual service performance against those targets. It ensures that IT services are delivered at the agreed levels by managing service level agreements (SLAs), operational level agreements (OLAs), and underpinning contracts.

Exam trap

The trap here is that candidates often confuse Availability Management (which handles the technical design and measurement of availability) with Service Level Management (which owns the contractual negotiation and reporting of service levels), leading them to pick B instead of C.

How to eliminate wrong answers

Option A is wrong because IT Asset Management focuses on the lifecycle management of IT assets (hardware, software, licenses) and does not handle negotiation or monitoring of service levels. Option B is wrong because Availability Management is a technical practice that ensures services meet availability targets, but it does not negotiate service levels; it provides input to SLM. Option D is wrong because Monitoring and Event Management detects and manages events and alerts, but it does not negotiate or define service level targets; it supports SLM by providing raw performance data.

28
MCQmedium

Which practice is responsible for ensuring that a service can meet current and future capacity demands?

A.Capacity and Performance Management
B.Monitoring and Event Management
C.IT Asset Management
D.Availability Management
AnswerA

This practice is precisely responsible for ensuring that services and service components can meet current and future performance and demand requirements in a cost-effective way. It involves understanding the demand for services, monitoring the performance and utilization of resources, and planning for necessary adjustments or investments to maintain agreed service levels. By proactively managing resources, it prevents performance bottlenecks and ensures the service remains capable of handling expected workloads.

Why this answer

Capacity and Performance Management is the ITIL 4 practice whose purpose is to ensure that services achieve the agreed and expected performance, and that they satisfy current and future demand in a cost-effective way. It covers both the sizing of resources (capacity) and the responsiveness of services (performance), including forecasting future demand. The other practices address monitoring, asset tracking, or availability, not capacity forecasting.

Exam trap

ITIL4F often tests the boundary between Capacity and Performance Management and Availability Management, so candidates who see 'meet demand' and think 'availability' pick the wrong practice — the key discriminator is that capacity is about sufficient resources for demand, while availability is about uptime and resilience.

How to eliminate wrong answers

Option B is wrong because Monitoring and Event Management observes the state of services and records/reports selected changes of state as events — it detects capacity issues but does not plan or provision for current and future demand. Option C is wrong because IT Asset Management tracks the lifecycle, location, and financial value of assets; it may inform capacity data but is not accountable for meeting demand. Option D is wrong because Availability Management ensures services meet agreed availability targets (uptime, reliability, resilience) — it is related but distinct from ensuring sufficient capacity to meet demand.

29
MCQhard

During a major incident, a temporary workaround is implemented to restore service. Which ITIL 4 practice is responsible for documenting this workaround and managing it until a permanent solution is available?

A.Service Level Management
B.Problem Management
C.Change Enablement
D.Incident Management
AnswerB

Problem Management is the ITIL practice responsible for reducing the likelihood and impact of incidents by identifying and resolving their root causes. When a temporary workaround is implemented during a major incident, Problem Management formally documents this solution, often within a Known Error Record, making it accessible for future incident resolution. This practice ensures that temporary fixes are tracked and systematically addressed for permanent resolution, preventing recurrence.

Why this answer

Problem Management is responsible for documenting workarounds and managing known errors until a permanent solution is implemented. Incident Management focuses on restoring service quickly, often using workarounds, but Problem Management owns the workaround documentation and root cause resolution.

Exam trap

ITIL4F often tests the confusion between Incident Management and Problem Management; candidates may think Incident Management documents workarounds, but Problem Management is responsible for managing workarounds and known errors.

How to eliminate wrong answers

Option A is wrong because Service Level Management defines and monitors service level agreements, but does not document workarounds. Option C is wrong because Change Enablement manages changes to IT services, including the implementation of permanent solutions, but does not own the documentation of workarounds. Option D is wrong because Incident Management uses workarounds to restore service, but it does not manage the documentation and lifecycle of workarounds; that is the role of Problem Management.

30
MCQhard

An organization wants to improve its service desk's efficiency by resolving more issues at the first point of contact. Which concept does this describe?

A.Continual improvement
B.Standard change
C.Service level management
D.Shift-left
AnswerD

Shift-left moves resolution capability closer to the point of contact, empowering first-line staff or self-service so issues are fixed without escalation. This directly satisfies the stem's constraint of resolving more issues at first contact, improving Service Desk efficiency.

Why this answer

Shift-left is the correct concept because it refers to moving problem resolution activities earlier in the service lifecycle, specifically to the first point of contact (e.g., service desk). By empowering the service desk with better tools, knowledge, and automation, more incidents can be resolved without escalation, directly improving efficiency and first-contact resolution rates.

Exam trap

The trap here is that candidates often confuse shift-left with continual improvement, but shift-left is a specific operational tactic for moving work to earlier support tiers, not a general improvement philosophy.

How to eliminate wrong answers

Option A is wrong because continual improvement is a broader, ongoing practice of aligning services with changing business needs, not specifically about resolving more issues at the first point of contact. Option B is wrong because a standard change is a pre-approved, low-risk change that follows a defined procedure, not a strategy for improving first-contact resolution. Option C is wrong because service level management focuses on defining, agreeing, and monitoring service level targets (e.g., response times), not on the operational tactic of resolving issues at the first point of contact.

31
MCQmedium

An organization wants to improve first-level resolution rate. Which practice is most directly involved?

A.Service Level Management
B.Service Desk
C.Problem Management
D.Incident Management
AnswerB

The Service Desk owns first-line incident logging, triage and resolution, so shifting resolution left directly raises the first-level resolution rate. Its documented purpose includes resolving incidents at first contact where possible, making it the practice the metric measures, unlike Incident Management, which spans all support tiers.

Why this answer

The Service Desk practice is directly responsible for handling incidents and service requests at the first point of contact. Improving the first-level resolution rate means enabling service desk agents to resolve more issues without escalation, which is the core function of this practice.

Exam trap

The trap here is that candidates often confuse Incident Management (which handles the process of managing incidents) with the Service Desk (which is the functional team that executes first-level resolution), leading them to select Incident Management instead of Service Desk.

How to eliminate wrong answers

Option A is wrong because Service Level Management focuses on defining, negotiating, and monitoring service level agreements (SLAs), not on directly resolving incidents at the first level. Option C is wrong because Problem Management aims to identify and manage the root causes of incidents to prevent recurrence, not to increase the percentage of incidents resolved at first contact. Option D is wrong because Incident Management manages the lifecycle of all incidents but does not specifically target improving the first-level resolution rate; that is a key performance indicator for the Service Desk practice.

32
Multi-Selecteasy

Which THREE are types of changes in Change Enablement?

Select 3 answers
A.Normal
B.Urgent
C.Emergency
D.Standard
E.Minor
AnswersA, C, D

Normal changes are non-pre-approved changes that must follow a full, structured change process, including assessment, authorization, and scheduling, to ensure minimal risk and impact. These changes typically require a change authority's approval based on a thorough evaluation of their potential effects on services and infrastructure. They are scheduled and implemented according to a defined change calendar, balancing speed with stability. This category encompasses most significant service improvements or infrastructure modifications.

Why this answer

In Change Enablement (ITIL 4), changes are classified into exactly three types: Standard, Normal, and Emergency. Option A (Normal) is correct because normal changes follow the full change control process, including assessment, authorization, and scheduling by the Change Authority. Option C (Emergency) is correct because emergency changes must be implemented as quickly as possible to resolve an incident or security issue, often with expedited or retrospective authorization.

Option D (Standard) is correct because standard changes are pre-authorized, low-risk, routine changes with a documented procedure or work instruction. Option B (Urgent) is not a defined change type — urgency is an attribute that may trigger an emergency change, not a category itself. Option E (Minor) is not a change type either; minor refers to low impact/risk scope, which typically maps to a standard or normal change rather than a distinct classification.

Exam trap

ITIL4F often tests the distinction between change types and other change-related terms like urgency, impact, or scope, causing candidates to select plausible-sounding but non-canonical options such as 'urgent' or 'minor'.

33
MCQeasy

Which ITIL 4 practice involves negotiating, agreeing, and monitoring service level agreements (SLAs)?

A.Service Level Management
B.Availability Management
C.Supplier Management
D.Service Desk
AnswerA

The Service Level Management practice is central to defining, negotiating, agreeing, and monitoring service level agreements (SLAs) with customers. It ensures that services consistently meet agreed-upon performance targets and customer expectations. This practice involves regular reviews of service performance against these agreements, driving improvement initiatives where necessary to maintain value.

Why this answer

Service Level Management is the ITIL 4 practice responsible for negotiating, agreeing, and monitoring Service Level Agreements (SLAs). It ensures that the agreed service levels are documented, tracked, and reported, aligning IT services with business expectations. This practice directly manages the lifecycle of SLAs, including their creation, review, and improvement.

Exam trap

The trap here is that candidates confuse the operational role of the Service Desk (handling incidents) with the strategic role of Service Level Management (negotiating and monitoring SLAs), leading them to select Service Desk because they think it 'manages' SLAs through daily interactions.

How to eliminate wrong answers

Option B (Availability Management) is wrong because it focuses on ensuring that IT services meet agreed availability targets, not on negotiating or monitoring SLAs; it uses metrics like uptime percentages and MTBF. Option C (Supplier Management) is wrong because it manages relationships with external suppliers and their contracts, not the SLAs with internal or external customers. Option D (Service Desk) is wrong because it is the single point of contact for incident and service requests, handling operational communication, not the strategic negotiation or monitoring of SLAs.

34
MCQmedium

A change request to replace a server with a newer model is assessed as low risk and follows a defined procedure. Which type of change should this be classified as in ITIL 4?

A.Service request
B.Emergency change
C.Normal change
D.Standard change
AnswerD

A standard change is pre-authorised, low-risk, and follows a documented procedure, so it bypasses full change advisory board review. The stem's low-risk assessment plus defined procedure matches this classification exactly, making it the correct ITIL 4 change type.

Why this answer

A standard change is a pre-approved, low-risk change that follows a defined procedure, such as replacing a server with a newer model according to a vendor's lifecycle plan. This classification allows the change to be implemented without requiring additional authorization from the change authority, as long as it adheres to the established procedure. The key differentiator is that the risk is assessed as low and the procedure is well-documented and repeatable.

Exam trap

The trap here is that candidates often confuse a standard change with a normal change because they think any infrastructure replacement requires formal approval, but ITIL 4 specifically classifies low-risk, procedure-driven changes as standard to streamline operations.

How to eliminate wrong answers

Option A is wrong because a service request is a formal request from a user for something to be provided – for example, a request for information or access – not a change to an infrastructure component like a server replacement. Option B is wrong because an emergency change must be implemented as soon as possible to resolve an incident or security vulnerability, whereas this change is assessed as low risk and follows a planned procedure, not an urgent response. Option C is wrong because a normal change requires approval from the change authority before implementation, but this change is pre-approved due to its low risk and defined procedure, making it a standard change instead.

35
MCQhard

Which ITIL 4 practice involves managing the lifecycle of all IT assets, including financial and contractual components?

A.Service Configuration Management
B.Capacity and Performance Management
C.Supplier Management
D.IT Asset Management
AnswerD

IT Asset Management (ITAM) is the practice responsible for planning, acquiring, deploying, managing, and disposing of IT assets throughout their entire lifecycle. This comprehensive approach includes managing financial, contractual, and inventory aspects to maximize value, control costs, and mitigate risks associated with IT assets. ITAM ensures that assets are effectively utilized, maintained, and retired in alignment with organizational objectives and regulatory requirements, directly addressing the management of an asset's full lifecycle.

Why this answer

IT Asset Management covers the full lifecycle of assets, including financial and contractual aspects.

36
Multi-Selectmedium

Which TWO of the following are types of change in ITIL 4?

Select 2 answers
A.Urgent change
B.Normal change
C.Routine change
D.Planned change
E.Standard change
AnswersB, E

Normal changes are the most common type of change, requiring full assessment, authorization, and scheduling. They follow a defined process, which typically includes peer review, impact analysis, risk assessment, and formal approval, often by a Change Advisory Board (CAB), before implementation. This structured approach is crucial for managing significant service modifications, new deployments, or complex updates that are not pre-approved or driven by an immediate emergency, ensuring thorough risk mitigation.

Why this answer

In ITIL 4, changes are categorized by how they are authorized and scheduled, and the two recognized types among the options are the normal change (B) and the standard change (E). A normal change (B) is correct because it is a change that must be assessed, authorized, and scheduled through the change control practice, typically following a defined workflow such as the change advisory board (CAB) review. A standard change (E) is correct because it is a pre-authorized, low-risk, routine change with a documented procedure that does not require additional authorization each time it is implemented.

The other options do not belong: urgent change (A) and planned change (D) are not ITIL 4 change types but rather descriptors or legacy terms, and routine change (C) is not an ITIL 4 category — routine work is handled as standard changes or service requests, not as a separate change type.

Exam trap

The trap is picking plausible-sounding synonyms like 'urgent,' 'routine,' or 'planned' instead of the exact ITIL 4 terminology: standard, normal, and emergency.

37
MCQmedium

An e-commerce company defines an SLA that its website will be available 99.9% of the time. Which practice is primarily responsible for negotiating and monitoring this agreement?

A.Supplier Management
B.Monitoring and Event Management
C.Service Level Management
D.Availability Management
AnswerC

Service Level Management is the dedicated practice responsible for setting clear, business-focused targets for service performance and ensuring that the organization meets these agreed-upon levels. It involves defining, documenting, agreeing, monitoring, analyzing, and reviewing service level agreements (SLAs) with customers, ensuring that services are delivered according to expectations and value is co-created. This practice directly addresses the negotiation and definition of customer-facing service commitments.

Why this answer

Service Level Management (SLM) is the ITIL 4 practice responsible for negotiating, agreeing, and monitoring service level agreements (SLAs) with customers. It ensures that services are delivered according to the agreed targets, such as the 99.9% availability SLA. SLM also manages the ongoing relationship with customers regarding service performance.

Exam trap

ITIL4F often tests the confusion between Service Level Management and Availability Management, where candidates might think Availability Management owns the SLA because it deals with availability targets.

How to eliminate wrong answers

Option A is wrong because Supplier Management focuses on managing suppliers and their performance, not on negotiating SLAs with customers. Option B is wrong because Monitoring and Event Management is about observing services and responding to events, not about negotiating or monitoring SLAs. Option D is wrong because Availability Management focuses on ensuring services are available as needed, but it does not own the SLA negotiation or monitoring process.

38
MCQeasy

What is the role of the Service Desk in ITIL 4?

A.Authorizing and scheduling changes
B.Identifying root causes of incidents
C.Single point of contact for users reporting incidents and requests
D.Monitoring and reporting on service levels
AnswerC

The Service Desk serves as the crucial single point of contact (SPOC) between the service provider and its users. This central role ensures that users have one clear channel for reporting incidents, making service requests, and seeking information, thereby streamlining communication and improving user experience. By acting as the SPOC, the Service Desk facilitates efficient logging, initial assessment, and routing of all user interactions to the appropriate support teams or practices.

Why this answer

In ITIL 4, the Service Desk is the single point of contact (SPOC) between the service provider and its users, handling incident reports, service requests, and general communication. It owns the 'engage' and 'incident management' practice entry points, ensuring users have one consistent channel rather than contacting multiple technical teams. This role is foundational to the Service Desk practice within ITIL 4's Service Value System.

Exam trap

ITIL4F often tests the confusion between the Service Desk's SPOC role and the responsibilities of Problem Management (root cause) or Change Enablement (authorization), so candidates must map each activity to its correct practice.

How to eliminate wrong answers

Option A is wrong because authorizing and scheduling changes is the responsibility of Change Enablement (change authority), not the Service Desk. Option B is wrong because identifying root causes of incidents is the domain of Problem Management, which performs root cause analysis; the Service Desk only logs and escalates. Option D is wrong because monitoring and reporting on service levels is performed by Service Level Management and Continual Improvement practices, not the Service Desk.

39
Multi-Selectmedium

Which TWO activities are part of the problem identification phase of Problem Management?

Select 2 answers
A.Organizing workarounds into known-error records
B.Trend analysis of incident records
C.Root cause analysis
D.Analyzing incident data for patterns
E.Implementing a known error
AnswersB, D

Trend analysis of incident records is a crucial activity for problem identification, as it involves systematically reviewing historical incident data to detect recurring patterns or increasing frequencies of specific incident types over time. By observing these trends, IT teams can proactively identify emerging problems that might otherwise go unnoticed, signaling a need for deeper investigation into an underlying cause. This proactive approach helps prevent future service disruptions.

Why this answer

Problem identification involves proactively identifying potential problems. The correct activities are trend analysis of incident records (option B) and analyzing incident data for patterns (option D). These help detect recurring issues.

Option A (organizing workarounds into known-error records) is part of error control, not identification. Option C (root cause analysis) is part of problem control. Option E (implementing a known error) is also error control.

40
MCQmedium

An IT team is reviewing the configuration baseline of a service to understand what has changed since the last release. Which practice is primarily involved?

A.Service Configuration Management
B.Change Enablement
C.Deployment Management
D.Release Management
AnswerA

Service Configuration Management is the practice of ensuring that accurate and reliable information about the configuration of services and the CIs that support them is available when and where it is needed. This includes managing configuration baselines, which are snapshots of a configuration at a specific point in time, used for comparison, restoration, and as a known good state. Reviewing these baselines is a core activity within this practice to maintain service integrity and control.

Why this answer

The configuration baseline is a snapshot of the service's configuration at a specific point in time, used as a reference for comparison. Service Configuration Management (SCM) is the practice responsible for maintaining configuration baselines and tracking all changes to Configuration Items (CIs) within the Configuration Management Database (CMDB). Therefore, when the team needs to understand what has changed since the last release, SCM is the primary practice involved, as it provides the historical records and comparison capabilities.

Exam trap

The trap here is that candidates often confuse 'tracking changes' with Change Enablement, but Change Enablement manages the process of approving changes, while Service Configuration Management is the practice that actually records and compares the configuration states.

How to eliminate wrong answers

Option B (Change Enablement) is wrong because Change Enablement focuses on controlling the lifecycle of changes (e.g., assessing risk, approving, and scheduling changes), not on maintaining or comparing configuration baselines. Option C (Deployment Management) is wrong because Deployment Management deals with moving new or changed components to production environments, not with tracking the historical state of configuration items. Option D (Release Management) is wrong because Release Management oversees the planning, scheduling, and controlling of releases into production, but it does not maintain the configuration baseline records; it consumes them from SCM.

41
MCQeasy

Which of the following is a key activity in the Problem Management practice?

A.Authorizing and scheduling emergency changes
B.Fulfilling a password reset request from a user
C.Restoring service as quickly as possible using a workaround
D.Documenting known errors and workarounds in the Known Error Database
AnswerD

Documenting known errors and workarounds in the Known Error Database is a critical activity within the Error Control phase of Problem Management. Once a problem's root cause has been identified and a temporary solution developed, recording this information allows for quicker incident resolution in the future and prevents recurrence. This database serves as a vital knowledge base, enabling efficient incident diagnosis and providing interim solutions until a permanent fix is implemented.

Why this answer

A key activity in Problem Management is documenting known errors and workarounds in the Known Error Database (KEDB). Problem Management focuses on identifying root causes of incidents and managing workarounds and known errors to reduce their impact. The KEDB is a central repository that helps the Service Desk resolve incidents faster by applying documented workarounds.

Exam trap

ITIL4F often tests the confusion between Incident Management and Problem Management — candidates must remember that Incident Management restores service (often via workarounds), while Problem Management identifies root causes and documents known errors in the KEDB.

How to eliminate wrong answers

Option A is wrong because authorizing and scheduling emergency changes is a key activity of Change Enablement, not Problem Management. Option B is wrong because fulfilling a password reset request is a service request handled by the Service Desk or Request Management, not Problem Management. Option C is wrong because restoring service as quickly as possible using a workaround is the primary goal of Incident Management, not Problem Management — Problem Management focuses on root cause and prevention.

42
MCQmedium

An IT manager wants to ensure that a service meets its agreed availability targets. Which practice should they use?

A.Capacity and Performance Management
B.Availability Management
C.IT Asset Management
D.Service Level Management
AnswerB

Availability Management is the ITIL practice dedicated to ensuring that services and their components are available when needed, for the agreed period, and at the agreed level of performance. This involves proactive planning, design, implementation, measurement, and improvement of service availability to meet defined targets and business requirements. Its core objective is to minimize service interruptions and ensure continuous access for users.

Why this answer

Availability Management is the ITIL practice responsible for ensuring that IT services meet their defined availability targets. This practice involves monitoring, measuring, and reporting on service uptime, as well as planning and implementing improvements to prevent outages. The IT manager should use Availability Management to directly track and manage agreed availability levels, such as 99.9% uptime, and to coordinate with other practices to address failures.

Exam trap

The trap here is that candidates often confuse Service Level Management (which defines and reports on SLAs) with Availability Management (which actually measures and ensures the technical availability), leading them to pick D instead of B.

How to eliminate wrong answers

Option A is wrong because Capacity and Performance Management focuses on ensuring that IT resources (e.g., CPU, memory, bandwidth) are sufficient to meet current and future demand, not on tracking or achieving availability targets like uptime percentages. Option C is wrong because IT Asset Management deals with the lifecycle management of hardware and software assets (e.g., tracking licenses, warranties, and inventory), not with monitoring or improving service availability. Option D is wrong because Service Level Management is responsible for negotiating, documenting, and reviewing Service Level Agreements (SLAs), but the actual monitoring and assurance of availability targets is performed by Availability Management; Service Level Management relies on Availability Management data to verify compliance.

43
MCQhard

An organization is implementing a new IT service management tool. According to ITIL 4, which practice would be primarily responsible for ensuring that the tool's performance meets the agreed demand?

A.Service Configuration Management
B.Capacity and Performance Management
C.Monitoring and Event Management
D.Availability Management
AnswerB

Capacity and Performance Management is the ITIL practice specifically designed to ensure that services and service components are able to meet agreed performance targets and demand, both current and future. It involves understanding the current capacity and performance of resources, forecasting future demand, and planning for necessary adjustments to maintain optimal service delivery and user experience. This practice proactively balances the cost of capacity with the need for performance and availability.

Why this answer

Capacity and Performance Management is the ITIL 4 practice that ensures services, including supporting tools, meet current and future demand in a cost-effective manner. It involves sizing, monitoring, and optimizing resources to meet performance requirements as defined in service level agreements. Since the question asks about ensuring the tool's performance meets agreed demand, this practice is directly responsible.

It works by forecasting demand, planning capacity, and managing performance to prevent bottlenecks.

Exam trap

ITIL4F often tests the confusion between Capacity and Performance Management and Availability Management, as both deal with service performance, but the key differentiator is that Capacity focuses on meeting demand, while Availability focuses on uptime.

How to eliminate wrong answers

Option A is wrong because Service Configuration Management focuses on maintaining accurate configuration records of configuration items (CIs) and their relationships, not on performance or demand management. Option C is wrong because Monitoring and Event Management is about observing services and components, recording and reporting events, and triggering actions; it does not own the responsibility for ensuring performance meets demand. Option D is wrong because Availability Management ensures services are available when needed, meeting availability targets, but it does not primarily handle performance relative to demand; that is the domain of Capacity and Performance Management.

44
MCQhard

An organization notices that the CMDB contains outdated information about several configuration items. Which ITIL 4 practice is primarily responsible for maintaining accurate CI data?

A.Service Configuration Management
B.Deployment Management
C.IT Asset Management
D.Change Enablement
AnswerA

Service Configuration Management is the ITIL practice specifically responsible for ensuring that accurate and reliable information about the configuration of services and their supporting configuration items (CIs) is available. This practice establishes and maintains the Configuration Management Database (CMDB), defining configuration baselines and managing the lifecycle of CIs to reflect their current state. Therefore, addressing outdated information in the CMDB falls directly under its purview, as it governs the integrity and accuracy of configuration data.

Why this answer

Service Configuration Management is the ITIL 4 practice responsible for maintaining accurate and reliable information about configuration items (CIs) throughout their lifecycle. It ensures the CMDB reflects the current state of CIs, including relationships and attributes, by controlling updates through defined processes and audits. Outdated CI data directly indicates a failure in this practice's core function of configuration control and status accounting.

Exam trap

The trap here is that candidates confuse IT Asset Management (which tracks financial and contractual data) with Service Configuration Management (which tracks technical configuration data), leading them to choose Option C even though the CMDB's accuracy is a configuration management responsibility, not an asset management one.

How to eliminate wrong answers

Option B is wrong because Deployment Management focuses on moving new or changed hardware, software, or services into production environments, not on maintaining ongoing CI data accuracy in the CMDB. Option C is wrong because IT Asset Management manages the financial, contractual, and lifecycle aspects of assets (e.g., procurement, depreciation, disposal), but it does not own the technical configuration records or their accuracy in the CMDB. Option D is wrong because Change Enablement controls the approval and implementation of changes to services and CIs, but it does not perform the ongoing maintenance or verification of CI data accuracy; it relies on Service Configuration Management to provide reliable CI information.

45
MCQeasy

Which type of change follows a pre-defined, low-risk procedure and is pre-approved?

A.Service request
B.Normal change
C.Standard change
D.Emergency change
AnswerC

A standard change is a pre-authorized change that is low-risk, well-understood, and has a documented procedure for implementation. These changes are typically routine, frequently performed, and do not require additional authorization each time they are executed, as the risk has been assessed and approved beforehand. This classification perfectly aligns with following a pre-defined, low-risk procedure, making it efficient for common modifications.

Why this answer

A standard change is a pre-defined, low-risk change that follows a specific procedure and is pre-approved by change management. It does not require a new change request each time because its risk profile and implementation steps are already documented and authorized. This aligns with ITIL 4's definition of a standard change as a change that is well-understood, fully documented, and can be implemented without additional approval.

Exam trap

The trap here is that candidates often confuse 'standard change' with 'service request' because both can follow a pre-defined procedure, but ITIL 4 explicitly separates them: a service request is for standard services (e.g., password reset), while a standard change is for low-risk technical changes (e.g., applying a tested patch).

How to eliminate wrong answers

Option A is wrong because a service request is a formal request from a user for something to be provided – such as access, information, or a standard service – and while it may follow a pre-defined procedure, it is not a type of change; it is a separate category in ITIL 4. Option B is wrong because a normal change is any change that is not standard or emergency; it requires a full assessment and approval through the change advisory board (CAB) and does not have pre-approval. Option D is wrong because an emergency change is a change that must be implemented as soon as possible to resolve an incident or critical issue; it follows an expedited process but is not pre-approved and carries higher risk.

46
MCQmedium

Which of the following is an example of an emergency change?

A.Updating the service desk knowledge base with new articles
B.Applying a critical security patch to a production server to fix a vulnerability
C.A request to install a new software version for all users next month
D.A password reset for a user
AnswerB

Applying a critical security patch to a production server to fix a vulnerability is a prime example of an emergency change. Such a situation involves an immediate, severe threat to the security, availability, or integrity of a live service, demanding urgent action to prevent significant business impact or data compromise. The critical nature of the vulnerability necessitates an expedited assessment and authorization process, bypassing the typical, longer change schedule to mitigate the risk as quickly as possible.

Why this answer

An emergency change is defined in ITIL 4 as a change that must be implemented as soon as possible, often to resolve a major incident or address a critical security vulnerability. Applying a critical security patch to a production server to fix a vulnerability fits this definition because it is urgent, unplanned, and necessary to prevent or mitigate a significant risk. The other options are either routine changes, service requests, or planned changes with future dates.

Exam trap

ITIL4F often tests the distinction between emergency changes, normal changes, and service requests, and candidates may mistakenly classify any urgent-sounding task (like a password reset) as an emergency change, when it is actually a service request.

How to eliminate wrong answers

Option A is wrong because updating the service desk knowledge base is a routine, low-risk administrative task that follows a standard change model, not an emergency. Option C is wrong because it describes a planned change with a future implementation date (next month), which would go through normal change control, not emergency procedures. Option D is wrong because a password reset is a service request, not a change; it is handled through request management, not change enablement.

47
MCQmedium

An IT team is reviewing the number of incidents resolved on first contact. Which metric is being measured?

A.Customer Satisfaction Score (CSAT)
B.First Contact Resolution (FCR)
C.Service Level Agreement (SLA) compliance
D.Mean Time to Resolve (MTTR)
AnswerB

First Contact Resolution (FCR) is a crucial service desk metric that quantifies the percentage of incidents or service requests that are fully resolved during the customer's initial interaction with the service provider. This means the issue is completely addressed without requiring further follow-up, escalation, or transfer to another support agent. FCR directly measures the efficiency and effectiveness of the initial support, indicating the team's ability to resolve issues promptly at the first point of contact. A high FCR rate significantly enhances customer satisfaction and reduces operational costs.

Why this answer

First Contact Resolution (FCR) is the metric that specifically measures the percentage of incidents resolved during the initial interaction with the service desk, without requiring escalation or follow-up. The question directly describes this scenario, making B the correct choice.

Exam trap

The trap here is that candidates often confuse FCR with MTTR, assuming that resolving an incident quickly on first contact is the same as measuring the time to resolve, but FCR is a ratio metric, not a time-based one.

How to eliminate wrong answers

Option A is wrong because Customer Satisfaction Score (CSAT) measures overall customer happiness with a service or interaction, not the specific count of incidents resolved on first contact. Option C is wrong because Service Level Agreement (SLA) compliance measures whether response or resolution times meet contractual targets, not the first-contact resolution rate. Option D is wrong because Mean Time to Resolve (MTTR) calculates the average time taken to fully resolve an incident, not the proportion resolved on first contact.

48
Multi-Selecthard

Which THREE of the following are activities of Service Level Management?

Select 3 answers
A.Managing supplier contracts
B.Reporting service performance
C.Monitoring service performance against SLAs
D.Negotiating and agreeing SLAs
E.Defining service metrics
AnswersB, C, D

Reporting service performance is a critical activity within Service Level Management, ensuring transparency and accountability. This involves systematically collecting, analyzing, and presenting data on how well services are meeting their agreed-upon targets to relevant stakeholders, including customers and internal management. Regular performance reports highlight achievements, identify deviations, and provide insights necessary for continuous service improvement and informed decision-making regarding service levels.

Why this answer

Service Level Management involves negotiating SLAs, monitoring service performance, and reporting results. Defining service metrics is part of service design, not a direct activity of SLA management.

49
MCQhard

An organization has implemented a change to update the firewall rules. The change was pre-authorized and followed a predefined procedure. What type of change is this?

A.Standard change
B.Normal change
C.Service request
D.Emergency change
AnswerA

A standard change is a low-risk, pre-authorized change that follows a well-established, documented procedure. Updating a firewall rule, if it's a routine, templated modification (e.g., opening a specific port for a new application following a pre-approved template), perfectly aligns with this definition. Such changes are implemented without needing additional authorization each time, enabling efficient and consistent delivery of common infrastructure modifications.

Why this answer

In ITIL 4, a standard change is a pre-approved, low-risk change that follows a defined procedure. Option A is correct. Option B (normal change) requires authorization through the change advisory board.

Option C (emergency change) is for urgent issues. Option D (service request) is for routine service requests, not changes.

50
MCQmedium

An event monitoring system detects that a server's disk usage has reached 85%. Which type of event is this?

A.Exception event
B.Critical event
C.Warning event
D.Informational event
AnswerC

A warning event is correctly identified when a predefined threshold, such as 85% disk usage, has been exceeded, indicating a potential issue that could escalate if not addressed. This type of event serves as an early alert, prompting investigation or proactive action to prevent a more severe incident, without necessarily signifying an immediate failure or critical impact. It allows for timely intervention before service quality is significantly affected.

Why this answer

An event that indicates a threshold has been reached and may require attention or monitoring is classified as a Warning event in ITIL 4. Here, 85% disk usage exceeds typical warning thresholds (e.g., 80%), suggesting potential future risk if usage continues to grow, but does not yet constitute a critical failure. ITIL 4 defines Warning events as those that signify a situation that is not normal but not yet critical, often prompting proactive review or preventive action.

Exam trap

The trap is that candidates may assume any threshold-based alert is 'informational,' but ITIL 4 distinguishes informational events as purely awareness without action, whereas warning events indicate a potential problem that should be monitored or addressed.

How to eliminate wrong answers

Option A is wrong because an exception event indicates an abnormal or unexpected occurrence that deviates from standard operations, such as a service outage or hardware failure, not a routine threshold alert. Option B is wrong because a critical event signifies a situation that requires immediate intervention to prevent service disruption, such as disk usage at 95% or 100%, not 85%. Option C is wrong because a warning event typically alerts that a threshold is approaching a critical level and may require attention soon, but 85% is often considered a standard informational threshold in many monitoring systems, not a warning.

51
MCQmedium

A service provider has a large number of standard, low-risk changes that are requested frequently, such as resetting a password or adding a user to a distribution list. The change manager wants to reduce the administrative burden on the Change Control practice while maintaining an acceptable level of risk. Which approach BEST fits ITIL 4 guidance?

A.Use a pre-authorized standard change model with defined triggers, so these changes can be implemented without individual CAB review.
B.Delegate approval of these changes to the service desk, allowing agents to authorize any change they believe is low risk.
C.Route all changes through the full Change Control practice, including the Change Advisory Board (CAB), to ensure consistent risk assessment.
D.Reclassify all of these changes as incidents so that they can be handled by the Incident Management practice instead.
AnswerA

Standard changes are pre-authorized, low-risk, and well-understood, so they can be implemented using a documented procedure without seeking further authorization each time. This reduces the burden on Change Control while preserving control, because the risk has already been assessed and the model defines exactly when and how the change may proceed.

Why this answer

Standard changes are low-risk, repeatable, and pre-authorized, so they can be implemented through a documented procedure without a CAB decision each time. Defining such a model lets the Change Control practice focus attention on normal and emergency changes, which carry more risk. The other approaches either add unnecessary control, misuse Incident Management, or remove control entirely.

Exam trap

The trap here is assuming that all changes must go through the CAB, when ITIL 4 explicitly recognizes pre-authorized standard changes that bypass individual review.

52
MCQmedium

Which practice includes the 'ITIL continual improvement model' with seven steps?

A.Continual Improvement
B.Change Enablement
C.Service Level Management
D.Problem Management
AnswerA

The Continual Improvement practice explicitly encompasses the ITIL continual improvement model, which provides a structured approach for organizations to improve their services, products, and practices. This model, consisting of seven steps, guides improvement initiatives from "What is the vision?" to "Did we get there?" and "How do we keep the momentum going?". It is central to fostering an organizational culture of ongoing enhancement and value co-creation.

Why this answer

The ITIL continual improvement model is a structured seven-step process (What is the vision?, Where are we now?, Where do we want to be?, How do we get there?, Take action, Did we get there?, How do we keep the momentum going?) that is explicitly defined within the Continual Improvement practice. This practice is the owner of the model, providing the framework for identifying and executing improvements across all other ITIL practices.

Exam trap

The trap here is that candidates confuse the 'continual improvement model' with a generic improvement concept and incorrectly associate it with Problem Management (which also investigates root causes) or Change Enablement (which also involves steps), but only the Continual Improvement practice formally owns and defines the seven-step model.

How to eliminate wrong answers

Option B is wrong because Change Enablement manages the lifecycle of changes (standard, normal, emergency) and does not include the seven-step continual improvement model; its focus is on risk assessment and authorization of changes. Option C is wrong because Service Level Management deals with negotiating, agreeing, and monitoring service level agreements (SLAs) and does not own the seven-step improvement model; it may use the model but does not define it. Option D is wrong because Problem Management focuses on identifying the root cause of incidents and preventing recurrence through known error records and workarounds, not on the seven-step continual improvement model.

53
MCQmedium

An organization wants to track the lifecycle of its servers, including acquisition, maintenance, and disposal. Which practice should they use?

A.Supplier Management
B.Capacity and Performance Management
C.IT Asset Management
D.Service Configuration Management
AnswerC

IT Asset Management is the practice of planning, acquiring, deploying, managing, and retiring IT assets, including servers, throughout their entire lifecycle. This comprehensive approach encompasses tracking financial aspects like depreciation, contractual details, physical location, and operational status from procurement through to disposal. It directly addresses the organization's need to understand and manage the full journey and value of its servers.

Why this answer

IT Asset Management (ITAM) is the correct practice because it is specifically designed to manage the complete lifecycle of IT assets, including servers, from acquisition through maintenance to disposal. ITAM tracks financial value, contractual agreements (e.g., warranties, leases), and physical status, ensuring compliance and cost optimization across the entire lifecycle.

Exam trap

The trap here is confusing Service Configuration Management (which tracks configuration items and their relationships) with IT Asset Management (which tracks the financial and lifecycle aspects of assets), leading candidates to pick D because they think 'tracking lifecycle' means tracking configuration changes.

How to eliminate wrong answers

Option A is wrong because Supplier Management focuses on managing relationships and contracts with external vendors, not on tracking the internal lifecycle of assets like servers. Option B is wrong because Capacity and Performance Management deals with ensuring current and future performance and capacity demands are met, not with lifecycle tracking of individual hardware assets. Option D is wrong because Service Configuration Management (now part of Service Configuration Management in ITIL 4) manages the configuration items (CIs) and their relationships within the service model, but it does not handle financial tracking, procurement, or disposal processes that are core to asset lifecycle management.

54
MCQhard

A user requests a new laptop because their current one is slow. The request is for a standard configuration. How should this be handled?

A.As a change request
B.As a service request
C.As an incident
D.As a problem
AnswerB

A service request represents a formal request from a user for something that is a normal part of service delivery, typically a pre-defined and pre-approved offering from the service catalog. Requesting a new laptop, especially when it's a standard model provided by the organization, falls squarely into this category. These requests are usually low-risk, frequently occurring, and follow established workflows for fulfillment, often with automated or semi-automated processes.

Why this answer

A standard laptop request is a pre-approved, low-risk service request handled through the service request fulfillment process, not the change enablement process. Service requests are user-initiated requests for information, advice, or a standard change, and they follow a defined workflow with approval and fulfillment steps. Because the configuration is standard, it does not require assessment by a change advisory board.

Exam trap

ITIL4F often tests the confusion between incidents and service requests, especially when a user reports a symptom (slow laptop) that sounds like a fault but is actually a request for a new standard item.

How to eliminate wrong answers

Option A is wrong because a change request is for modifying a service or infrastructure component that is not a pre-approved standard change; a standard laptop is already authorized. Option C is wrong because an incident is an unplanned interruption or degradation of a service, whereas the user's slow laptop is a request for a new asset, not a service outage. Option D is wrong because a problem is the underlying cause of one or more incidents, and no incident has been logged for a service failure.

55
MCQmedium

What is the relationship between a Configuration Management Database (CMDB) and IT Asset Management?

A.IT Asset Management provides financial data for CIs in the CMDB
B.The CMDB replaces IT Asset Management
C.They are the same practice
D.IT Asset Management is a subset of Service Configuration Management
AnswerA

IT Asset Management (ITAM) is responsible for tracking the financial and contractual aspects of IT assets throughout their lifecycle, including acquisition cost, depreciation, warranty information, and end-of-life dates. This crucial financial and lifecycle data is then integrated with Configuration Items (CIs) within the Configuration Management Database (CMDB). This integration enriches the CMDB's technical view with vital business context, enabling better decision-making regarding asset utilization and investment.

Why this answer

IT Asset Management (ITAM) is a broader practice that tracks the financial, contractual, and lifecycle aspects of assets, while the CMDB focuses on configuration items (CIs) and their relationships to support service delivery. In ITIL 4, ITAM feeds financial and ownership data—such as cost, depreciation, and license status—into the CMDB so that CIs have complete lifecycle context. This integration ensures that configuration records reflect both technical and financial attributes, supporting better decision-making across service value streams.

Exam trap

ITIL4F often tests the misconception that CMDB and ITAM are interchangeable or that one subsumes the other, when in fact they are complementary practices with distinct but overlapping responsibilities.

How to eliminate wrong answers

Option B is wrong because the CMDB does not replace ITAM; the two practices serve complementary purposes—CMDB manages configuration relationships while ITAM manages asset lifecycle and financial data. Option C is wrong because ITIL 4 treats Service Configuration Management and IT Asset Management as distinct practices with different scopes, even though they overlap. Option D is wrong because ITAM is not a subset of Service Configuration Management; rather, ITAM is a separate practice that provides financial and contractual data that enriches the CMDB.

56
MCQeasy

A retail company is experiencing frequent service outages during peak hours due to insufficient capacity. The IT team wants to implement a practice that ensures the service provider has the capacity to meet agreed service level targets cost-effectively and in a timely manner. Which ITIL management practice should they use?

A.Monitoring and event management
B.Capacity and performance management
C.Availability management
D.Service level management and availability management
AnswerB

Capacity and availability management is the best answer because it addresses capacity, which is the core requirement of the question. Note that the exact ITIL 4 practice name is Capacity and performance management, but among the options, this is the most appropriate.

Why this answer

In ITIL 4, the practice that ensures the service provider has sufficient capacity to meet agreed service level targets cost-effectively and in a timely manner is Capacity and performance management. Option B represents this practice. Option A (Monitoring and event management) focuses on detecting events, not capacity planning.

Option C (Availability management) focuses on availability, not capacity. Option D (Service level management and availability management) covers service levels and availability but not capacity. Therefore, B is correct.

57
Multi-Selectmedium

Which TWO of the following are key activities of Problem Management?

Select 2 answers
A.Conducting root cause analysis
B.Authorizing changes to resolve incidents
C.Restoring normal service as quickly as possible
D.Managing service requests from users
E.Identifying problems from incidents
AnswersA, E

Root cause analysis (RCA) is a fundamental activity within problem management, specifically falling under the 'problem control' phase. Its purpose is to systematically investigate and determine the underlying causes of one or more incidents, preventing their recurrence. By identifying the true origin of issues, problem management can develop effective workarounds and permanent solutions, thereby reducing the impact and frequency of future service disruptions. This proactive approach is crucial for improving service stability and reliability.

Why this answer

Problem management includes problem identification and root cause analysis (problem control). Restoring service is incident management, and managing changes is change enablement.

58
Multi-Selecteasy

Which TWO of the following are types of events in the Monitoring and Event Management practice?

Select 2 answers
A.Known error
B.Standard change
C.Warning event
D.Service request
E.Informational event
AnswersC, E

A warning event signals that a threshold is approaching or has been breached, prompting investigation before a full exception occurs. It satisfies the stem by being one of the recognised event types, alongside informational and exception events.

Why this answer

In the Monitoring and Event Management practice, events are classified by their significance and required response, and two recognized event types are the warning event (C) and the informational event (E). A warning event (C) is correct because it signals that a component or service is approaching a threshold or condition that may require attention before it becomes a breach, such as high CPU or low disk space. An informational event (E) is correct because it simply records a normal, expected occurrence—like a device coming online or a job completing—that requires no action.

The other options do not belong: a known error (A) is a problem record whose root cause is documented, a standard change (B) is a pre-authorized low-risk change, and a service request (D) is a user-initiated request handled by the Service Request Management practice—none of these are event types in Monitoring and Event Management.

Exam trap

ITIL4F often tests the confusion between event types (informational, warning, exception) and other ITIL concepts like known errors, standard changes, and service requests, which belong to different practices.

59
MCQhard

An organization identifies that a recurring incident is due to a known error in a software component. According to ITIL 4, which practice is responsible for managing the known error?

A.Service Level Management
B.Incident Management
C.Change Enablement
D.Problem Management
AnswerD

Problem Management is the correct practice as it specifically focuses on reducing the likelihood and impact of incidents by identifying actual and potential causes of incidents, and managing workarounds and known errors. When an organization identifies a recurring incident and determines its root cause, it becomes a "known error." Problem Management's "Error Control" activity is precisely responsible for managing these known errors throughout their lifecycle, ensuring that the underlying cause is addressed and future incidents are prevented or minimized.

Why this answer

Problem Management because ITIL 4 assigns the responsibility for managing known errors to the Problem Management practice. A known error is a problem that has been analyzed and has a documented root cause and a potential workaround, and Problem Management is the practice that owns the known error database (KEDB) and coordinates the lifecycle of known errors until a permanent fix is implemented via Change Enablement.

Exam trap

The trap here is that candidates confuse Incident Management's use of the KEDB with ownership of known errors, but ITIL 4 explicitly assigns the known error lifecycle to Problem Management, not to the practice that merely consumes the data.

How to eliminate wrong answers

Option A is wrong because Service Level Management is responsible for negotiating, agreeing, and monitoring service level agreements (SLAs), not for managing technical defects like known errors. Option B is wrong because Incident Management focuses on restoring normal service operation as quickly as possible for individual incidents, but it does not own the long-term analysis or documentation of known errors; it may use the KEDB but does not manage it. Option C is wrong because Change Enablement controls the lifecycle of changes (e.g., deploying a fix), but it does not perform the root cause analysis or maintain the known error record; it is a downstream practice that implements solutions identified by Problem Management.

60
MCQmedium

Which ITIL 4 practice involves classifying events as informational, warning, or exception?

A.Problem Management
B.Service Desk
C.Incident Management
D.Monitoring and Event Management
AnswerD

Monitoring and Event Management is the ITIL 4 practice specifically designed to systematically observe services and service components, recording and reporting selected changes of state identified as events. A fundamental activity within this practice is the classification of these events into meaningful categories, such as informational (no action needed), warning (potential issue), or exception (requires action), to enable appropriate automated or manual responses.

Why this answer

The Monitoring and Event Management practice is specifically responsible for monitoring IT services and categorizing events into three types: informational (routine notifications), warning (conditions that may require attention), and exception (significant deviations requiring immediate action). This classification enables appropriate responses based on the event's severity and impact on service availability.

Exam trap

The trap here is that candidates confuse the event classification step with Incident Management, but ITIL 4 explicitly assigns the classification of events (informational, warning, exception) to the Monitoring and Event Management practice, not to the incident lifecycle.

How to eliminate wrong answers

Option A is wrong because Problem Management focuses on identifying the root cause of incidents and preventing recurrence, not on classifying real-time events into informational, warning, or exception categories. Option B is wrong because the Service Desk acts as the single point of contact for users reporting incidents or service requests, and does not perform event classification or monitoring. Option C is wrong because Incident Management handles the lifecycle of unplanned interruptions or service reductions, but event classification occurs before an incident is declared, as part of the monitoring and detection process.

61
MCQmedium

Which ITIL practice involves negotiating, agreeing, and monitoring service level targets?

A.Incident Management
B.Supplier Management
C.Service Level Management
D.Service Desk
AnswerC

Service Level Management is the practice of setting clear business-based targets for service performance, and ensuring that delivery of services is properly assessed, monitored, and managed against these targets. This practice explicitly involves negotiating service level agreements (SLAs) with customers to define measurable service outcomes, agreeing upon these targets, and then continuously monitoring and reporting on actual service performance against the agreed levels to ensure value co-creation and customer satisfaction.

Why this answer

Service Level Management (SLM) is the ITIL practice responsible for negotiating, agreeing, and monitoring service level targets. It ensures that IT services meet the agreed-upon levels of performance and availability as documented in Service Level Agreements (SLAs). SLM is a core practice in ITIL 4 and directly aligns with the question's description.

Exam trap

The trap is confusing Service Level Management with Incident Management or Service Desk—candidates may pick Incident Management because it deals with service issues, but the key differentiator is that SLM negotiates and monitors targets, while Incident Management resolves disruptions.

How to eliminate wrong answers

Option A is wrong because Incident Management focuses on restoring normal service operation as quickly as possible after an incident, not on negotiating or monitoring service level targets. Option B is wrong because Supplier Management handles relationships with external suppliers and ensuring they meet contractual obligations, not the overall service level targets with customers. Option D is wrong because the Service Desk is the single point of contact for users to report issues and request services, but it does not negotiate or monitor SLAs—that is the role of SLM.

62
MCQeasy

What is the role of the Service Desk according to ITIL 4?

A.To manage changes
B.To negotiate SLAs
C.To be the single point of contact for users
D.To perform root cause analysis
AnswerC

The Service Desk serves as the crucial single point of contact (SPOC) between the service provider and its users. This means users have one consistent channel for logging incidents, requesting services, and making inquiries, streamlining communication and improving user experience. By centralizing these interactions, the Service Desk ensures efficient routing, tracking, and resolution of all user-initiated contacts, embodying its core ITIL 4 purpose.

Why this answer

In ITIL 4, the Service Desk is defined as the single point of contact (SPOC) between the service provider and users. It handles incidents, service requests, and communication, ensuring users have one place to go for support. This SPOC role is the foundational definition of the Service Desk in ITIL.

Exam trap

ITIL4F often tests the precise ITIL definition of the Service Desk as the single point of contact — candidates may confuse it with Change Management, SLM, or Problem Management responsibilities.

How to eliminate wrong answers

Option A is wrong because managing changes is the responsibility of Change Enablement (formerly Change Management), not the Service Desk. Option B is wrong because negotiating SLAs is typically the role of Service Level Management, not the Service Desk. Option C is correct — the Service Desk is the SPOC for users.

Option D is wrong because root cause analysis is part of Problem Management, not the Service Desk's core role.

63
Multi-Selecthard

Which THREE of the following are key activities of the Problem Management practice?

Select 3 answers
A.Problem identification
B.Error control
C.Change authorization
D.Problem control
E.Incident resolution
AnswersA, B, D

Problem identification is a foundational activity in Problem Management, focusing on detecting and logging potential problems. This often involves analyzing incident trends, reviewing monitoring alerts, or receiving direct reports from users and technical staff to proactively identify recurring issues and their root causes.

Why this answer

Problem identification (A) is a core Problem Management activity because it detects and logs problems — often by analyzing incident trends and recurring patterns — so their root causes can be investigated. Error control (B) is correct because it covers managing known errors throughout their lifecycle, including recording them in the known error database, assessing workarounds, and tracking them until a permanent fix is implemented. Problem control (D) is correct because it is the activity of investigating and analyzing problems to determine root causes and identify permanent solutions.

Change authorization (C) belongs to Change Enablement (change control), which assesses and authorizes changes, not to Problem Management. Incident resolution (E) belongs to Incident Management, whose goal is to restore service quickly, whereas Problem Management focuses on eliminating the underlying causes of incidents.

Exam trap

The trap here is that candidates confuse the activities of Incident Management (like Incident Resolution) with Problem Management, or mistake Change Authorization as part of Problem Management, when it strictly belongs to Change Enablement.

64
Multi-Selectmedium

Which TWO of the following are components of the Service Value System (SVS)?

Select 2 answers
A.Service desk
B.Service level agreements
C.Configuration management database
D.Service value chain
E.Guiding principles
AnswersD, E

The Service Value Chain (SVC) is a core operational model within the ITIL Service Value System, outlining the six key activities an organization undertakes to create value. It describes how demand is translated into value through a sequence of interconnected steps: Plan, Engage, Design & Transition, Obtain/Build, Deliver & Support, and Improve. The SVC is central to understanding how an organization delivers services and manages its value streams.

Why this answer

The Service Value System (SVS) is a core component of ITIL 4 that describes how all components and activities of an organization work together as a system to enable value creation. The Service Value Chain (Option D) is a central element of the SVS, providing an operating model for the creation, delivery, and continuous improvement of services. Guiding Principles (Option E) are also a key component of the SVS, providing universal recommendations that guide an organization in all its work.

Exam trap

The trap here is that candidates often confuse operational components (like Service Desk, SLAs, or CMDB) with the high-level, abstract building blocks of the Service Value System, leading them to select concrete tools or documents instead of the correct conceptual components.

65
MCQhard

An IT department has a CMDB. Which practice is primarily responsible for ensuring that configuration data is accurate and up to date?

A.Monitoring and Event Management
B.IT Asset Management
C.Service Configuration Management
D.Service Desk
AnswerC

Service Configuration Management is the practice specifically responsible for planning, identifying, controlling, recording, reporting, and verifying all configuration items (CIs) and their relationships. Its core purpose is to ensure that accurate and reliable information about the services and their supporting components is available in the Configuration Management Database (CMDB) throughout their lifecycle.

Why this answer

Service Configuration Management (C) is the practice responsible for maintaining accurate and up-to-date configuration data in the CMDB. It ensures that all Configuration Items (CIs) are identified, controlled, and their attributes and relationships are recorded and verified through regular audits and reconciliation processes, directly supporting the integrity of the CMDB.

Exam trap

The trap here is that candidates often confuse IT Asset Management (ITAM) with Service Configuration Management, but ITAM focuses on financial lifecycle and inventory, while Service Configuration Management owns the logical relationships and technical attributes of CIs in the CMDB.

How to eliminate wrong answers

Option A is wrong because Monitoring and Event Management focuses on detecting and reacting to events and alerts from IT infrastructure, not on maintaining the accuracy of configuration data in a CMDB. Option B is wrong because IT Asset Management manages the lifecycle, financial value, and contractual aspects of assets, but it does not own the detailed configuration records or relationships between CIs in the CMDB. Option D is wrong because the Service Desk handles incident and service request tickets, and while it may update CI statuses as part of incident resolution, it is not primarily responsible for ensuring the ongoing accuracy and currency of configuration data.

66
MCQeasy

Which practice involves the use of an improvement register?

A.Problem Management
B.Change Enablement
C.Continual Improvement
D.Service Level Management
AnswerC

The Continual Improvement practice is dedicated to aligning an organization's practices and services with changing business needs through the ongoing identification and improvement of all elements involved in the management of products and services. A central component of this practice is the Improvement Register, which serves as a structured database to capture, track, and manage all identified improvement opportunities from across the organization, ensuring they are prioritized, actioned, and reviewed for effectiveness. This register is crucial for maintaining visibility and driving the improvement lifecycle.

Why this answer

The Continual Improvement practice is responsible for identifying and managing improvement opportunities across all ITIL practices. The improvement register is a key tool used to log, track, and prioritize these improvement initiatives, ensuring they are systematically reviewed and acted upon.

Exam trap

The trap here is that candidates often confuse the improvement register with the service improvement plan (SIP) used in Service Level Management, but the SIP is a specific document for a single service, whereas the improvement register is a cross-practice repository for all improvement ideas.

How to eliminate wrong answers

Option A is wrong because Problem Management uses a problem record, not an improvement register, to manage the lifecycle of underlying causes of incidents. Option B is wrong because Change Enablement uses a change record and a change schedule to manage changes, not an improvement register. Option D is wrong because Service Level Management uses a service level agreement (SLA) and service improvement plan (SIP), but the improvement register is specifically a tool of the Continual Improvement practice, not Service Level Management.

67
Multi-Selecthard

Which TWO statements correctly describe the relationship between Service Level Management and other practices?

Select 2 answers
A.SLAs are used to manage supplier performance
B.SLAs are agreements between internal IT teams
C.SLAs define the detailed steps of the incident handling process
D.OLAs support the achievement of SLAs
E.SLAs provide targets for Incident Management
AnswersD, E

Operational Level Agreements (OLAs) are internal agreements between different departments or teams within the same service provider organization. Their primary purpose is to define the specific responsibilities, activities, and performance targets that each internal group must meet to collectively ensure the successful delivery of services and, consequently, the achievement of the customer-facing Service Level Agreements (SLAs). Without robust OLAs, internal coordination can falter, jeopardizing SLA compliance.

Why this answer

Option D is correct because Operational Level Agreements (OLAs) are internal agreements between teams within the same organization that underpin and support the delivery of the customer-facing SLA targets. Option E is correct because SLAs establish measurable service targets (such as availability, response, and resolution times) that Incident Management uses to prioritize and resolve incidents in line with agreed commitments. Option A is not correct because supplier performance is managed through contracts and Underpinning Contracts (UCs), not SLAs, which are agreements with customers.

Option B is not correct because agreements between internal IT teams are OLAs, not SLAs, which are customer-facing. Option C is not correct because the detailed steps of incident handling are defined in incident management procedures and work instructions, not in SLAs, which specify targets rather than process steps.

Exam trap

ITIL4F often tests the definitions and relationships between SLAs, OLAs, and other practices, so candidates might confuse SLAs with OLAs or think SLAs define processes rather than targets.

68
MCQmedium

A user requests a new laptop for a new employee. According to ITIL 4, how should this request be classified?

A.Problem
B.Service request
C.Emergency change
D.Incident
AnswerB

A Service Request is a formal request from a user for something standard that is part of normal service delivery, such as information, advice, a standard change, or access to a service. Provisioning a new laptop for a new employee is a classic example of a pre-defined, low-risk, and often automated service request, following established procedures for fulfillment.

Why this answer

The request for a new laptop for a new employee is a pre-defined, standardized request for a service or service component, which ITIL 4 classifies as a Service Request. This is because it follows an established procedure (e.g., ordering, provisioning, and configuring hardware) and does not involve restoring an unexpected outage or fixing a failure. The ITIL 4 Service Request Practice specifically covers such routine, low-risk, and low-cost requests that are part of normal service delivery.

Exam trap

The trap here is that candidates confuse a 'Standard Change' with a 'Service Request,' but ITIL 4 explicitly separates them: a Service Request is for requesting something (e.g., a laptop), while a Standard Change is a pre-approved change to an existing service (e.g., modifying a configuration), and the question's phrasing ('requests a new laptop') clearly fits the Service Request definition.

How to eliminate wrong answers

Option A is wrong because a Problem is the root cause of one or more Incidents, not a routine request for a new asset; a new laptop request has no underlying failure or unknown cause to diagnose. Option C is wrong because an Emergency Change is a high-risk, urgent change (e.g., applying a critical security patch to stop an active breach) that must be implemented as soon as possible, whereas provisioning a laptop follows a standard, pre-approved change model with no urgency or risk of service disruption. Option D is wrong because an Incident is an unplanned interruption or reduction in quality of an IT service (e.g., a laptop that won't boot), not a planned request for a new resource that is part of normal operations.

69
MCQmedium

An IT service desk analyst receives a call from a user who cannot access the CRM system. The user says this happened after a recent password change. What should the analyst do FIRST, according to ITIL 4?

A.Log an incident record and attempt to resolve the access issue
B.Direct the user to fill out a service request form for password assistance
C.Submit a change request to reverse the password change
D.Create a problem record to investigate why the password change caused the issue
AnswerA

The user's inability to access services due to a password issue constitutes an unplanned interruption to a service, which is the definition of an incident in ITIL 4. The primary objective of incident management is to restore normal service operation as quickly as possible, minimizing business impact. Logging the incident ensures it is properly tracked, prioritized, and managed through to resolution, aligning with ITIL's incident management practice.

Why this answer

According to ITIL 4, the analyst's first action should be to log an incident record and attempt to resolve the access issue. This aligns with the incident management practice, which prioritizes restoring normal service operation as quickly as possible. The user's inability to access the CRM system after a password change is a clear incident (an unplanned interruption or reduction in quality of an IT service), and the analyst should immediately capture the details and work toward a resolution, such as resetting the password or verifying account synchronization with the identity provider (e.g., Active Directory or LDAP).

Exam trap

The trap here is that candidates confuse incident management with problem management or change management, mistakenly thinking that a password change issue automatically warrants a problem investigation or a formal change reversal, when ITIL 4 mandates that restoring service (incident management) is the immediate priority.

How to eliminate wrong answers

Option B is wrong because directing the user to fill out a service request form for password assistance treats the issue as a standard service request (a pre-defined, low-risk request for a service), but the user is already experiencing an active service outage, which requires incident management to restore service quickly, not a separate request process. Option C is wrong because submitting a change request to reverse the password change is premature and bypasses the incident management process; the analyst should first attempt to resolve the incident (e.g., by resetting the password or checking account lockout policies) rather than initiating a formal change, which would delay restoration of service. Option D is wrong because creating a problem record to investigate why the password change caused the issue is a reactive step that should only occur after the incident is resolved; problem management focuses on identifying the root cause of incidents to prevent recurrence, not on immediate service restoration.

70
MCQhard

Refer to the exhibit. The monthly report shows that the availability target was met but the response time target was not. What should the service provider do to improve response time?

A.Close the incident as it is resolved and focus on other issues
B.Increase the response time target to 99%
C.Adjust the availability target to 99.95%
D.Analyze the incident from March 15 to identify the root cause of slow transactions
AnswerD

Analyzing the incident from March 15 to identify the root cause of slow transactions aligns directly with ITIL's Problem Management practice. This proactive approach seeks to understand the underlying issues causing performance degradation, rather than just resolving symptoms. By identifying the root cause, the organization can implement permanent solutions, prevent recurrence of slow transactions, and improve overall service quality and user satisfaction.

Why this answer

The incident from March 15 is the only event where response time degraded (slow transactions), and analyzing its root cause is the proper ITIL problem management practice. Simply closing the incident (A) ignores the underlying issue, while adjusting targets (B, C) does not fix the actual performance problem. Root cause analysis (D) enables the service provider to identify and resolve the specific technical bottleneck, such as database contention or network latency, that caused the slow response.

Exam trap

The trap here is that candidates confuse adjusting service level targets (a reactive, non-solution) with performing root cause analysis (the correct ITIL problem management action), thinking that changing a metric can fix a performance issue.

How to eliminate wrong answers

Option A is wrong because closing the incident without resolving the root cause of slow transactions means the response time target will continue to be missed; ITIL requires problem management to prevent recurrence. Option B is wrong because increasing the response time target to 99% does not improve actual performance—it merely lowers the bar, which violates the principle of continual improvement and does not address the underlying technical issue. Option C is wrong because adjusting the availability target to 99.95% is irrelevant to response time; availability measures uptime, not transaction speed, and changing it does not fix slow queries or application delays.

71
MCQeasy

A user contacts the service desk because they cannot access a shared drive. The agent gathers information, identifies a known workaround, and restores the user's access. The user asks how the agent knew what to do so quickly. Which practice is MOST directly responsible for providing the documented workaround the agent used?

A.Service Configuration Management
B.Service Desk
C.Service Request Management
D.Knowledge Management
AnswerD

Knowledge Management maintains the body of information that supports all practices, including known errors, workarounds, and resolution steps. The agent could quickly apply the workaround because Knowledge Management had captured and made it available. This practice ensures that useful information is created, shared, and kept current across the organization.

Why this answer

Knowledge Management is the practice that creates, maintains, and shares information such as known errors and workarounds. The agent restored access quickly because the workaround had already been documented and made available. The Service Desk delivers the support, and Service Configuration Management records configuration items, but neither supplies the resolution knowledge used here.

Exam trap

The trap here is crediting the Service Desk for the workaround simply because the agent delivered it, rather than recognizing Knowledge Management as the source of the content.

72
MCQmedium

A change request that is low risk and follows a pre-approved procedure is classified as which type of change?

A.Standard change
B.Emergency change
C.Normal change
D.Service request
AnswerA

A standard change is a low-risk, pre-authorized change that is well-understood, fully documented, and often implemented as a service request. These changes follow a defined procedure, do not require additional authorization each time they are implemented, and are typically initiated to deliver a new or changed service feature or to resolve a common issue. Their pre-approval streamlines the change process for routine activities, ensuring efficiency while maintaining control and predictability within the service environment.

Why this answer

A Standard change is the correct classification because it is pre-approved, low-risk, and follows a documented, repeatable procedure. ITIL 4 defines a Standard change as one that is fully authorized in advance, requires no additional approval, and is executed through a defined workflow, such as a routine server patch or password reset.

Exam trap

The trap here is that candidates often confuse a Standard change with a Service request, but ITIL 4 distinguishes them by the fact that a Service request is for something pre-defined and not a change to a service (e.g., 'reset password'), whereas a Standard change is a pre-approved change to a service (e.g., 'apply patch').

How to eliminate wrong answers

Option B is wrong because an Emergency change is used for urgent, high-risk situations (e.g., a critical security vulnerability) that require expedited approval, not for low-risk, pre-approved procedures. Option C is wrong because a Normal change follows a full lifecycle of assessment and approval by a Change Authority (e.g., CAB), which is not needed for low-risk, pre-approved work. Option D is wrong because a Service request is a formal request for something pre-defined (e.g., access to an application), not a change to an IT service; while it may be low-risk, it is not a change to a service's configuration or state.

73
MCQeasy

Which ITIL 4 practice is responsible for maintaining the CMDB and ensuring configuration items are accurate?

A.Service Desk
B.IT Asset Management
C.Service Configuration Management
D.Change Enablement
AnswerC

Service Configuration Management is the ITIL practice specifically tasked with ensuring that accurate and reliable information about the configuration of services and the Configuration Items (CIs) that support them is available when and where needed. This practice defines, identifies, controls, records, reports, and verifies all CIs and their relationships within the Configuration Management Database (CMDB). Its core function is to maintain the integrity and accuracy of configuration data throughout the entire service lifecycle, making it directly responsible for the CMDB.

Why this answer

Service Configuration Management (C) is the ITIL 4 practice responsible for maintaining the Configuration Management Database (CMDB) and ensuring that Configuration Items (CIs) are accurate, up-to-date, and under controlled management. This practice focuses on defining, recording, and controlling CIs and their relationships, directly supporting the integrity of the CMDB.

Exam trap

The trap here is that candidates confuse IT Asset Management (B) with Service Configuration Management because both deal with tracking items, but IT Asset Management focuses on financial lifecycle and ownership, not the detailed configuration relationships and CMDB accuracy that Service Configuration Management owns.

How to eliminate wrong answers

Option A is wrong because the Service Desk practice handles incident and service request management, not the maintenance of the CMDB or CI accuracy. Option B is wrong because IT Asset Management focuses on the financial and lifecycle management of assets (e.g., procurement, depreciation), not the detailed configuration records and relationships stored in the CMDB. Option D is wrong because Change Enablement controls the process for approving and implementing changes, but it relies on the CMDB for impact analysis and does not itself maintain CI data.

74
Multi-Selecthard

Which THREE of the following are activities of the Problem Management practice?

Select 3 answers
A.Problem identification
B.Root cause analysis
C.Managing changes
D.Managing known errors
E.Monitoring services for events
AnswersA, B, D

Problem identification is a foundational activity within Problem Management, initiating the process by detecting and logging potential or actual problems. This involves analyzing incident trends, reviewing service desk data, and receiving direct input from various stakeholders to proactively identify recurring issues or single, high-impact events that warrant deeper investigation. The goal is to move beyond mere symptom treatment to understand underlying causes.

Why this answer

Problem identification (A) is a core Problem Management activity because the practice must detect and log problems, often from recurring incidents or major incidents, so they can be investigated. Root cause analysis (B) is central to Problem Management, which seeks to determine the underlying cause of incidents and problems to prevent recurrence. Managing known errors (D) is also a Problem Management responsibility, as known errors are problems with a documented root cause and workaround that must be recorded, maintained, and made available to support teams.

Managing changes (C) belongs to Change Enablement, which authorizes and schedules changes, not Problem Management. Monitoring services for events (E) is an activity of Service Desk or Monitoring and Event Management, since it focuses on detecting and correlating events rather than investigating problem root causes.

Exam trap

ITIL4F often tests the boundary between Problem Management and other practices, tricking candidates into selecting activities that belong to Change Enablement or Monitoring and Event Management.

75
MCQmedium

Which of the following is a key difference between Incident Management and Problem Management?

A.Incident Management deals with unplanned interruptions; Problem Management deals with root causes
B.Incident Management requires a change request; Problem Management does not
C.Incident Management is proactive; Problem Management is reactive
D.Incident Management is only for major incidents
AnswerA

Incident Management's primary objective is to restore normal service operation as quickly as possible following an unplanned interruption or reduction in service quality. It focuses on the immediate impact and resolution of service disruptions. In contrast, Problem Management aims to reduce the likelihood and impact of incidents by identifying and eliminating their underlying root causes, often preventing future occurrences of similar issues.

Why this answer

Incident Management focuses on restoring normal service operation as quickly as possible after an unplanned interruption or service degradation, minimizing business impact. Problem Management, in contrast, seeks to identify and eliminate the root cause of incidents to prevent recurrence. This fundamental distinction in purpose—restoration versus root cause analysis—is the key difference tested in the ITIL 4 Foundation exam.

Exam trap

The trap here is confusing the reactive nature of Incident Management with the proactive aspect of Problem Management, leading candidates to incorrectly reverse the roles (Option C), when in fact Incident Management is always reactive and Problem Management includes both reactive and proactive elements.

How to eliminate wrong answers

Option B is wrong because Incident Management does not inherently require a change request; while a workaround or fix may eventually lead to a change, the incident process itself focuses on swift restoration, not mandatory RFCs. Option C is wrong because Incident Management is reactive (responding to disruptions), while Problem Management includes both reactive (analyzing past incidents) and proactive (preventing future incidents) activities. Option D is wrong because Incident Management handles all incidents, not just major ones; major incidents follow a separate, more urgent procedure, but the practice covers every unplanned interruption.

Page 1 of 5 · 301 questions totalNext →

Ready to test yourself?

Try a timed practice session using only ITIL Management Practices questions.