Courseiva

CCNA ITIL Management Practices Questions

75 of 260 questions · Page 1/4 · ITIL Management Practices · Answers revealed

1
MCQmedium

An organization wants to ensure that its IT services meet the agreed performance levels. Which practice is primarily responsible for negotiating and monitoring these targets?

A.Availability Management
B.Supplier Management
C.Service Level Management
D.Capacity and Performance Management
AnswerC

Service Level Management handles SLAs and monitoring of service levels.

Why this answer

Service Level Management (SLM) is the ITIL practice responsible for negotiating, agreeing, and documenting service level targets (SLTs) in Service Level Agreements (SLAs), and then monitoring and reporting on actual performance against those targets. This ensures IT services consistently meet the agreed performance levels by establishing clear expectations and providing a framework for continuous improvement.

Exam trap

The trap here is that candidates often confuse Capacity and Performance Management (which monitors performance metrics) with Service Level Management (which negotiates and owns the targets), leading them to select D instead of C.

How to eliminate wrong answers

Option A is wrong because Availability Management focuses specifically on ensuring IT services are available when needed, managing risks to availability, and reporting on availability metrics, but it does not negotiate or monitor the broader set of performance targets (e.g., response times, throughput) that SLM handles. Option B is wrong because Supplier Management manages relationships with external suppliers, negotiating contracts and monitoring supplier performance, but it does not directly negotiate or monitor the end-to-end service performance targets for internal IT services. Option D is wrong because Capacity and Performance Management ensures that IT services have sufficient capacity to meet current and future demand and monitors performance metrics, but it does not negotiate SLTs or own the SLA process; it provides input to SLM.

2
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To manage the lifecycle of all changes to IT services
B.To negotiate and agree on service level targets
C.To find the root cause of incidents and prevent recurrence
D.To restore normal service operation as quickly as possible and minimize business impact
AnswerD

This is the precise and primary purpose of the Incident Management practice according to ITIL 4. Its objective is to ensure that any unplanned interruption or reduction in the quality of an IT service is resolved swiftly, restoring functionality to an agreed-upon service level. By focusing on rapid restoration, Incident Management minimizes the negative impact on business operations, user productivity, and overall service value.

Why this answer

Incident Management aims to restore normal service operation as quickly as possible and minimize the adverse impact on business operations.

3
Multi-Selectmedium

Which TWO of the following are components of the ITIL 4 Service Value System?

Select 2 answers
A.Service Catalogue
B.Known Error Database
C.Configuration Baseline
D.Service Value Chain
E.Guiding Principles
AnswersD, E

The Service Value Chain is a central element of the SVS.

Why this answer

The SVS includes: Guiding Principles, Governance, Service Value Chain, Practices, and Continual Improvement. Service Catalogue and Known Error Database are not components.

4
MCQhard

Which of the following BEST describes the difference between an incident and a service request?

A.Incidents require a workaround; service requests do not
B.Incidents are always resolved within 24 hours; service requests have no time limit
C.Incidents are unplanned disruptions; service requests are routine, pre-approved requests
D.Incidents are handled by the service desk; service requests are handled by change enablement
AnswerC

Why this answer

The ITIL 4 definition clearly distinguishes incidents as unplanned interruptions or reductions in service quality, while service requests are pre-defined, standardized, and pre-approved requests from users for information, advice, or access. This aligns with the ITIL 4 Foundation syllabus, which separates the two based on the nature of the trigger—unplanned vs. planned—not on resolution time, workaround necessity, or assignment team.

Exam trap

The trap here is that candidates confuse the operational handling (e.g., who resolves it or time limits) with the fundamental definitional difference, leading them to pick options that describe common practices rather than the ITIL 4 core distinction between unplanned and planned activities.

How to eliminate wrong answers

Option A is wrong because workarounds are not a defining characteristic of incidents; many incidents are resolved without a workaround, and service requests can also have workarounds if the standard procedure fails. Option B is wrong because ITIL 4 does not mandate a 24-hour resolution time for incidents; service level targets vary by organization and are defined in SLAs, not by ITIL. Option D is wrong because both incidents and service requests are typically handled by the service desk as the single point of contact; change enablement handles changes, not service requests or incidents directly.

5
Multi-Selecthard

Which THREE of the following are components of the ITIL 4 Service Value System (SVS)?

Select 3 answers
A.Practices
B.Continual improvement
C.Outcomes
D.Guiding principles
E.Service value chain activities
AnswersA, B, D

Practices are a component of the SVS.

Why this answer

'Practices' are a core component of the ITIL 4 Service Value System (SVS). The SVS is defined by the ITIL 4 framework to include the Guiding Principles, Governance, Service Value Chain, Practices, and Continual Improvement. Practices are sets of organizational resources designed for performing work or accomplishing an objective, replacing the ITIL v3 'processes' concept.

Exam trap

The trap here is that candidates confuse the 'Service Value Chain activities' (the six specific activity blocks within the chain) with the 'Service Value Chain' itself as a component of the SVS, leading them to incorrectly select Option E.

6
MCQhard

An IT department is considering replacing a critical server. According to ITIL 4, which type of change should be used if the replacement involves a new, untested model and requires a full risk assessment?

A.Standard change
B.Service request
C.Normal change
D.Emergency change
AnswerC

A normal change is any change that is not standard or emergency, requiring a full assessment, authorization, and scheduling process. This type of change typically involves a structured workflow, including planning, risk and impact analysis, approval by a change authority (such as a Change Advisory Board or CAB), and careful coordination. Replacing a critical server, given its potential impact and the need for careful planning and approval, perfectly aligns with the characteristics and rigor of a normal change.

Why this answer

A normal change is a change that is not pre-approved (like standard changes) and not urgent (like emergency changes). It requires a full risk assessment and authorization by a change authority before implementation. Therefore, for a replacement involving a new, untested model, a normal change is appropriate.

Option A (Standard change) is pre-approved and low risk, not suitable for untested models. Option B (Service request) is for predefined service requests, not changes. Option D (Emergency change) is for urgent situations that cannot wait for normal authorization, which does not apply here.

7
MCQeasy

Which ITIL 4 practice involves the 7-step improvement model?

A.Incident Management
B.Continual Improvement
C.Problem Management
D.Change Enablement
AnswerB

Continual Improvement is the ITIL 4 practice explicitly dedicated to aligning an organization's practices and services with changing business needs through ongoing, iterative improvement. It directly utilizes the ITIL Continual Improvement Model, which is a seven-step framework guiding all improvement initiatives from defining the vision to sustaining momentum. This model provides a structured approach for identifying, planning, implementing, and reviewing improvements across the entire service value system.

Why this answer

The Continual Improvement practice uses the 7-step improvement model.

8
MCQhard

A service desk agent resolves a password reset request after verifying the user's identity. According to ITIL 4, which metrics would be most appropriate to measure the performance of this interaction?

A.Change success rate and backout success
B.Mean Time to Repair (MTTR) and uptime
C.Number of problems and known errors
D.First Contact Resolution (FCR) and Customer Satisfaction (CSAT)
AnswerD

First Contact Resolution (FCR) is a crucial service desk metric that measures the percentage of requests or incidents resolved entirely during the initial interaction, directly reflecting efficiency and user convenience. Customer Satisfaction (CSAT) gauges how pleased users are with the service received, often collected immediately after resolution. For a password reset, successfully resolving it on the first contact and ensuring the user is satisfied are primary indicators of effective service desk performance and value delivery.

Why this answer

First Contact Resolution (FCR) and Customer Satisfaction (CSAT) are key service desk metrics.

9
Multi-Selectmedium

Which THREE actions are part of Supplier Management?

Select 3 answers
A.Setting SLA targets for internal teams
B.Providing training to supplier staff
C.Managing supplier contracts
D.Monitoring supplier performance
E.Evaluating and selecting suppliers
AnswersC, D, E

Managing supplier contracts is a fundamental and integral activity within the Supplier Management practice. This involves the entire lifecycle of contracts, from negotiation and establishment to ongoing administration, amendment, and eventual termination. Effective contract management ensures that terms, conditions, and service expectations are clearly defined, legally binding, and consistently met by external providers, safeguarding the organization's interests and service delivery.

Why this answer

Supplier management includes evaluating and selecting suppliers, managing contracts, and monitoring performance. Options C, D, and E are core activities. Option A (setting SLA targets for internal teams) belongs to Service Level Management, not Supplier Management.

Option B (providing training to supplier staff) is not a typical supplier management activity; training is usually the supplier's own responsibility.

10
Multi-Selecthard

Which THREE of the following are components of the Service Value System (SVS) according to ITIL 4?

Select 3 answers
A.Service Value Chain
B.Outcomes
C.Governance
D.Value Streams
E.Guiding Principles
AnswersA, C, E

One of the five SVS components.

Why this answer

The Service Value Chain is a core component of the ITIL 4 Service Value System (SVS). It provides an operating model for the creation, delivery, and continual improvement of services through six key activities: plan, improve, engage, design & transition, obtain/build, and deliver & support.

Exam trap

The trap here is that candidates often confuse 'Value Streams' with the 'Service Value Chain' as a component of the SVS, but ITIL 4 explicitly defines the Service Value Chain as the structural component, while value streams are derived from it and are not listed as a separate SVS component.

11
MCQmedium

A change that is low risk, pre-approved, and follows a defined procedure is classified as which type of change?

A.Standard change
B.Service request
C.Normal change
D.Emergency change
AnswerA

Standard changes are pre-approved and low risk.

Why this answer

Standard changes are pre-approved, low risk, and follow a defined procedure. Option A is correct. Normal changes require authorization.

Emergency changes are for urgent issues and require urgent authorization.

12
MCQeasy

What type of change is pre-authorized and follows a low-risk, standardized procedure?

A.Normal change
B.Service request
C.Emergency change
D.Standard change
AnswerD

Standard changes are pre-authorized and have a low risk.

Why this answer

D is correct because a Standard change is pre-authorized by default and follows a low-risk, standardized procedure, such as applying a routine security patch or provisioning a new user account. This aligns with ITIL 4's definition of a Standard change as one that is well-understood, fully documented, and can be implemented without requiring additional approval each time.

Exam trap

The trap here is that candidates often confuse a Service request (Option B) with a Standard change because both are pre-defined and low-risk, but ITIL 4 explicitly categorizes Service requests as separate from changes, focusing on user-initiated requests like password resets rather than infrastructure modifications.

How to eliminate wrong answers

Option A is wrong because a Normal change requires formal approval from a Change Authority (e.g., CAB) and follows a non-standardized, risk-assessed procedure, not a pre-authorized low-risk one. Option B is wrong because a Service request is a formal request for something (e.g., access, information) that follows a predefined workflow, but it is not a type of change; ITIL distinguishes service requests from change types. Option C is wrong because an Emergency change is used for urgent, high-risk situations (e.g., critical security vulnerability patch) and must be authorized urgently, often via an emergency CAB, not pre-authorized as low-risk.

13
MCQeasy

What is the purpose of a Service Level Agreement (SLA)?

A.To list all services provided by the service desk
B.To define the internal support targets between IT teams
C.To document agreed service targets between the service provider and the customer
D.To define the terms and conditions with external suppliers
AnswerC

The core purpose of a Service Level Agreement (SLA) is to formally document the mutually agreed-upon service targets and responsibilities between a service provider and its customer. This includes critical metrics such as availability, performance thresholds, incident response times, and problem resolution targets, establishing clear expectations and providing a basis for measuring service quality and accountability from the customer's perspective.

Why this answer

A Service Level Agreement (SLA) is a documented agreement between a service provider and a customer that defines the level of service expected, including agreed service targets. Option A is incorrect because listing all services is more typical of a service catalog. Option B is incorrect because it describes an Operational Level Agreement (OLA), which defines internal support targets between IT teams.

Option D is incorrect because it describes an Underpinning Contract (UC), which defines terms and conditions with external suppliers.

14
MCQhard

An IT team is investigating recurring network outages. They identify the root cause as a faulty switch and record the issue as a known error with a workaround. Which ITIL 4 practice is being applied?

A.Supplier Management
B.Service Desk
C.Problem Management
D.Incident Management
AnswerC

Problem Management is the ITIL practice dedicated to reducing the likelihood and impact of incidents by identifying and resolving their underlying causes. Investigating recurring network outages directly aligns with its objectives, which include performing root cause analysis, managing known errors, and implementing permanent solutions. This proactive approach aims to prevent future incidents and improve overall service stability, making it the correct practice for this scenario.

Why this answer

Problem Management includes three phases: problem identification, problem control (root cause analysis), and error control (known errors, workarounds). The scenario describes error control, which is part of Problem Management. Incident Management focuses on restoring service quickly, not root cause analysis.

Service Desk handles user communication and initial support, not deep investigation. Supplier Management deals with vendor relationships, not internal root cause analysis. Therefore, option C (Problem Management) is correct.

15
MCQhard

After a major incident, the Problem Management team identifies a known error and documents a workaround. According to ITIL 4, which practice is responsible for ensuring the workaround is implemented to restore service?

A.Change Enablement
B.Incident Management
C.Problem Management
D.Service Request Management
AnswerB

Incident Management is the practice responsible for minimizing the negative impact of incidents by restoring normal service operation as quickly as possible. Its core objective is rapid service restoration, which frequently involves applying pre-identified workarounds or temporary fixes to mitigate the immediate disruption. Therefore, applying a workaround to restore service after a major incident is a direct and critical function of Incident Management, ensuring business continuity.

Why this answer

Incident Management is responsible for restoring service using workarounds; Problem Management identifies the workaround but does not execute it.

16
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To manage the lifecycle of all changes
B.To find the root cause of incidents
C.To ensure that service levels are met
D.To restore normal service operation as quickly as possible
AnswerD

This is indeed the primary purpose of the Incident Management practice. Its core objective is to minimize the negative impact of incidents by restoring normal service operation as quickly as possible, thereby ensuring business continuity and maintaining user productivity. This involves rapid diagnosis, workaround implementation, and resolution to return services to their agreed-upon functional state.

Why this answer

The primary purpose of Incident Management is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations.

17
MCQhard

Which of the following scenarios BEST illustrates the difference between an incident and a service request?

A.A user reports a system crash (service request) and requests a software upgrade (incident)
B.A user requests a password reset (service request) and later reports that the email system is down (incident)
C.A user requests a new laptop (incident) and reports a printer jam (service request)
D.A user requests access to a database (incident) and reports a network outage (incident)
AnswerB

This option correctly differentiates between an incident and a service request according to ITIL 4 principles. A password reset is a common, pre-defined user request for a standard service, accurately categorized as a service request. Reporting that the email system is down, however, signifies an unplanned interruption to a critical service, which is precisely what defines an an incident requiring prompt resolution to restore functionality.

Why this answer

Ly illustrates the difference: a password reset is a pre-approved, routine service request, while an email system outage is an unplanned incident that disrupts service. Option A incorrectly reverses the categories (system crash is an incident, not a service request; software upgrade is typically a request, not an incident). Option C labels both as the wrong type (new laptop is a service request, printer jam is an incident).

Option D classifies both as incidents, but database access is a service request.

18
Multi-Selectmedium

Which TWO of the following are key metrics for the Service Desk practice?

Select 2 answers
A.Mean Time Between Failures (MTBF)
B.First Call Resolution (FCR)
C.Recovery Time Objective (RTO)
D.Customer Satisfaction Score (CSAT)
E.Mean Time to Restore Service (MTTR)
AnswersB, D

FCR measures the percentage of issues resolved on the first call.

Why this answer

First Call Resolution (FCR) is a key metric for the Service Desk practice because it measures the percentage of incidents resolved during the first interaction with the user, without the need for escalation or follow-up. A high FCR directly indicates the efficiency and effectiveness of the Service Desk in resolving issues promptly, reducing user downtime and operational costs. This metric is critical for assessing the quality of first-level support and the knowledge base's adequacy.

Exam trap

The trap here is that candidates confuse operational metrics like MTTR (which is for Incident Management) with Service Desk-specific metrics, or they mistakenly think MTBF (a reliability metric) applies to the Service Desk's daily performance rather than to infrastructure components.

19
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. What should they do FIRST?

A.Log the incident with relevant details
B.Search for a known error in the known error database
C.Escalate to the problem management team
D.Reset users' passwords
AnswerA

Logging the incident is the foundational first step in the Incident Management practice. It ensures that the service disruption is formally recorded, assigned a unique identifier, and tracked through its entire lifecycle. Capturing relevant details like user contact, symptoms, and impact is crucial for effective diagnosis, communication, and eventual resolution, aligning with the practice's objective of restoring normal service operation as quickly as possible.

Why this answer

The first step in incident management is to log the incident, capturing key details, before proceeding with investigation or escalation.

20
MCQeasy

What is the purpose of the 'shift-left' strategy in a service desk?

A.To enable users to resolve issues themselves via a portal
B.To resolve more incidents at the first point of contact without escalation
C.To increase system availability by reducing downtime
D.To automate incident resolution using artificial intelligence
AnswerB

The shift-left strategy aims to empower the lowest possible support tier, typically the service desk or first-line support, to resolve a higher percentage of incidents and service requests. By providing these teams with enhanced knowledge, tools, and training, issues are addressed at the initial point of contact. This reduces the need for costly and time-consuming escalations to specialized second or third-line support, improving efficiency and customer satisfaction.

Why this answer

Shift-left strategy in a service desk aims to resolve incidents at the earliest possible point, typically the first point of contact (e.g., service desk agent or self-service portal), thereby minimizing escalations. The correct answer is B because it directly captures this purpose: resolving more incidents at the first point of contact without escalation. Option A describes self-service, which is a method of shift-left but not its overall purpose.

Option C is related to availability management, and option D is about automation, which are not the primary purpose of shift-left.

21
MCQmedium

Which of the following is the correct distinction between Incident Management and Problem Management?

A.Incident Management restores service; Problem Management finds root causes
B.Incident Management finds root causes; Problem Management restores service
C.Incident Management handles change requests; Problem Management manages incidents
D.Incident Management is reactive; Problem Management is always proactive
AnswerA

Incident Management's primary objective is to restore normal service operation as quickly as possible, minimizing business impact. Conversely, Problem Management focuses on identifying and understanding the root causes of incidents to prevent their recurrence or minimize their impact. This clear division ensures both immediate recovery and long-term service stability by addressing symptoms and underlying issues respectively.

Why this answer

Incident Management focuses on restoring service as quickly as possible, while Problem Management focuses on identifying root causes to prevent recurrence. Option A is correct. Option B is incorrect because it reverses the roles.

Option C is incorrect because Incident Management does not handle change requests; that is Change Enablement. Option D is incorrect because Problem Management can be both reactive and proactive, not always proactive.

22
Multi-Selectmedium

Which TWO of the following are activities of the Problem Management practice according to ITIL 4?

Select 2 answers
A.Fulfilling service requests
B.Restoring service by applying a workaround
C.Authorizing changes
D.Performing root cause analysis
E.Identifying and logging problems
AnswersD, E

Root cause analysis is part of problem control.

Why this answer

Performing root cause analysis (RCA) is a core activity of Problem Management, which aims to identify the underlying cause of incidents to prevent recurrence. ITIL 4 defines Problem Management as focusing on diagnosing the root cause of problems and initiating actions to eliminate or minimize future incidents.

Exam trap

The trap here is that candidates confuse the reactive restoration activities of Incident Management (like applying workarounds) with the proactive diagnostic activities of Problem Management, leading them to select Option B instead of D or E.

23
MCQeasy

What is the primary focus of the Service Desk practice?

A.Monitoring and managing events
B.Providing a single point of contact for users
C.Ensuring services meet agreed capacity levels
D.Managing the lifecycle of all IT assets
AnswerB

This is the correct answer as the Service Desk practice is explicitly designed to be the single point of contact (SPOC) between the service provider and its users. Its primary function is to handle all user interactions, including incidents, service requests, and inquiries, ensuring efficient communication and coordination. By centralizing these interactions, the Service Desk facilitates prompt resolution and maintains user satisfaction, acting as the crucial interface for all service-related matters.

Why this answer

The Service Desk practice is defined in ITIL 4 as the entry point and single point of contact for users seeking support, reporting incidents, or requesting services. Its primary focus is on capturing, managing, and resolving user interactions, not on technical infrastructure monitoring or asset lifecycle management.

Exam trap

PeopleCert often tests the distinction between user-facing practices (Service Desk) and infrastructure-focused practices (Event Management, Capacity Management, Asset Management), leading candidates to confuse the Service Desk's role with operational monitoring or asset tracking.

How to eliminate wrong answers

Option A is wrong because monitoring and managing events is the primary focus of the ITIL Event Management practice, which deals with detecting and responding to alerts from infrastructure components, not user-facing interactions. Option C is wrong because ensuring services meet agreed capacity levels is the responsibility of the Capacity and Performance Management practice, which involves monitoring resource utilization and planning for future demand. Option D is wrong because managing the lifecycle of all IT assets is the domain of the IT Asset Management practice, which tracks hardware, software, and other assets from acquisition to disposal.

24
MCQhard

A service provider uses a third-party data center. They want to ensure the data center's availability meets their requirements. Which document should they use to define these requirements?

A.Operational Level Agreement (OLA)
B.Underpinning Contract (UC)
C.Service Level Agreement (SLA)
D.Service Improvement Plan (SIP)
AnswerB

An Underpinning Contract (UC) is a formal agreement between the service provider and a third-party supplier, such as a data centre operator, that specifies required availability levels, performance targets, and remedies for non-compliance. This document directly satisfies the stem’s constraint of defining measurable availability requirements for an externally hosted facility, ensuring the provider can enforce service levels contractually rather than relying on informal expectations.

Why this answer

An Underpinning Contract (UC) is a formal contract between a service provider and an external supplier, such as a third-party data center, that defines the requirements and responsibilities, including availability targets. Option B is correct. Option A (OLA) is incorrect because an Operational Level Agreement is an internal agreement between departments within the same organization.

Option C (SLA) is incorrect because a Service Level Agreement is between the service provider and its customers, not with external suppliers. Option D (SIP) is incorrect because a Service Improvement Plan is used to plan improvements, not to define initial requirements.

25
MCQeasy

Which ITIL 4 practice is responsible for managing the lifecycle of IT assets from acquisition to disposal?

A.IT Asset Management
B.Supplier Management
C.Change Enablement
D.Service Configuration Management
AnswerA

IT Asset Management manages the complete lifecycle of assets.

Why this answer

IT Asset Management manages the lifecycle of IT assets, including financial aspects. Option A is correct. Service Configuration Management manages configuration items and their relationships.

Change Enablement handles changes. Supplier Management manages suppliers.

26
MCQhard

An organization wants to ensure that its IT services are available according to agreed levels. Which practice is PRIMARILY responsible for negotiating and monitoring these levels?

A.IT Asset Management
B.Availability Management
C.Service Level Management
D.Monitoring and Event Management
AnswerC

Service Level Management (SLM) is the practice of setting clear, business-focused targets for service performance, including availability, and then monitoring and reporting against those targets. It involves negotiating Service Level Agreements (SLAs) with customers, ensuring that services meet agreed expectations, and managing customer perceptions of service quality. This practice directly ensures that IT services achieve agreed availability levels from the customer's perspective by formalizing commitments.

Why this answer

Service Level Management (SLM) is the ITIL practice responsible for negotiating, agreeing, and documenting service level targets with customers, and then monitoring and reporting on actual service performance against those targets. It ensures that IT services are delivered at the agreed levels by managing service level agreements (SLAs), operational level agreements (OLAs), and underpinning contracts.

Exam trap

The trap here is that candidates often confuse Availability Management (which handles the technical design and measurement of availability) with Service Level Management (which owns the contractual negotiation and reporting of service levels), leading them to pick B instead of C.

How to eliminate wrong answers

Option A is wrong because IT Asset Management focuses on the lifecycle management of IT assets (hardware, software, licenses) and does not handle negotiation or monitoring of service levels. Option B is wrong because Availability Management is a technical practice that ensures services meet availability targets, but it does not negotiate service levels; it provides input to SLM. Option D is wrong because Monitoring and Event Management detects and manages events and alerts, but it does not negotiate or define service level targets; it supports SLM by providing raw performance data.

27
MCQmedium

Which practice is responsible for ensuring that a service can meet current and future capacity demands?

A.Capacity and Performance Management
B.Monitoring and Event Management
C.IT Asset Management
D.Availability Management
AnswerA

This practice is precisely responsible for ensuring that services and service components can meet current and future performance and demand requirements in a cost-effective way. It involves understanding the demand for services, monitoring the performance and utilization of resources, and planning for necessary adjustments or investments to maintain agreed service levels. By proactively managing resources, it prevents performance bottlenecks and ensures the service remains capable of handling expected workloads.

Why this answer

Capacity and Performance Management ensures that services have the necessary resources to meet agreed performance and demand levels.

28
MCQhard

During a major incident, a temporary workaround is implemented to restore service. Which ITIL 4 practice is responsible for documenting this workaround and managing it until a permanent solution is available?

A.Service Level Management
B.Problem Management
C.Change Enablement
D.Incident Management
AnswerB

Problem Management is the ITIL practice responsible for reducing the likelihood and impact of incidents by identifying and resolving their root causes. When a temporary workaround is implemented during a major incident, Problem Management formally documents this solution, often within a Known Error Record, making it accessible for future incident resolution. This practice ensures that temporary fixes are tracked and systematically addressed for permanent resolution, preventing recurrence.

Why this answer

Problem Management includes the error control phase, which manages known errors and workarounds. Incident Management resolves incidents but does not formally manage workarounds for known errors. Change Enablement and Service Level Management are not responsible for workarounds.

29
MCQhard

An organization wants to improve its service desk's efficiency by resolving more issues at the first point of contact. Which concept does this describe?

A.Continual improvement
B.Standard change
C.Service level management
D.Shift-left
AnswerD

Correct: Shift-left aims to resolve issues at the first contact.

Why this answer

Shift-left is the correct concept because it refers to moving problem resolution activities earlier in the service lifecycle, specifically to the first point of contact (e.g., service desk). By empowering the service desk with better tools, knowledge, and automation, more incidents can be resolved without escalation, directly improving efficiency and first-contact resolution rates.

Exam trap

The trap here is that candidates often confuse shift-left with continual improvement, but shift-left is a specific operational tactic for moving work to earlier support tiers, not a general improvement philosophy.

How to eliminate wrong answers

Option A is wrong because continual improvement is a broader, ongoing practice of aligning services with changing business needs, not specifically about resolving more issues at the first point of contact. Option B is wrong because a standard change is a pre-approved, low-risk change that follows a defined procedure, not a strategy for improving first-contact resolution. Option C is wrong because service level management focuses on defining, agreeing, and monitoring service level targets (e.g., response times), not on the operational tactic of resolving issues at the first point of contact.

30
MCQmedium

An organization wants to improve first-level resolution rate. Which practice is most directly involved?

A.Service Level Management
B.Service Desk
C.Problem Management
D.Incident Management
AnswerB

The service desk handles initial user contact and first-level resolution.

Why this answer

The Service Desk practice is directly responsible for handling incidents and service requests at the first point of contact. Improving the first-level resolution rate means enabling service desk agents to resolve more issues without escalation, which is the core function of this practice.

Exam trap

The trap here is that candidates often confuse Incident Management (which handles the process of managing incidents) with the Service Desk (which is the functional team that executes first-level resolution), leading them to select Incident Management instead of Service Desk.

How to eliminate wrong answers

Option A is wrong because Service Level Management focuses on defining, negotiating, and monitoring service level agreements (SLAs), not on directly resolving incidents at the first level. Option C is wrong because Problem Management aims to identify and manage the root causes of incidents to prevent recurrence, not to increase the percentage of incidents resolved at first contact. Option D is wrong because Incident Management manages the lifecycle of all incidents but does not specifically target improving the first-level resolution rate; that is a key performance indicator for the Service Desk practice.

31
Multi-Selecteasy

Which THREE are types of changes in Change Enablement?

Select 3 answers
A.Normal
B.Urgent
C.Emergency
D.Standard
E.Minor
AnswersA, C, D

Normal changes are non-pre-approved changes that must follow a full, structured change process, including assessment, authorization, and scheduling, to ensure minimal risk and impact. These changes typically require a change authority's approval based on a thorough evaluation of their potential effects on services and infrastructure. They are scheduled and implemented according to a defined change calendar, balancing speed with stability. This category encompasses most significant service improvements or infrastructure modifications.

Why this answer

ITIL 4 defines three change types: Normal (assessed and authorized via change advisory board), Emergency (urgent, expedited), and Standard (pre-approved, low risk). Options A, C, and D are correct. Option B (Urgent) is not an official type; Emergency is.

Option E (Minor) is not a separate type.

32
MCQeasy

Which ITIL 4 practice involves negotiating, agreeing, and monitoring service level agreements (SLAs)?

A.Service Level Management
B.Availability Management
C.Supplier Management
D.Service Desk
AnswerA

The Service Level Management practice is central to defining, negotiating, agreeing, and monitoring service level agreements (SLAs) with customers. It ensures that services consistently meet agreed-upon performance targets and customer expectations. This practice involves regular reviews of service performance against these agreements, driving improvement initiatives where necessary to maintain value.

Why this answer

Service Level Management is the ITIL 4 practice responsible for negotiating, agreeing, and monitoring Service Level Agreements (SLAs). It ensures that the agreed service levels are documented, tracked, and reported, aligning IT services with business expectations. This practice directly manages the lifecycle of SLAs, including their creation, review, and improvement.

Exam trap

The trap here is that candidates confuse the operational role of the Service Desk (handling incidents) with the strategic role of Service Level Management (negotiating and monitoring SLAs), leading them to select Service Desk because they think it 'manages' SLAs through daily interactions.

How to eliminate wrong answers

Option B (Availability Management) is wrong because it focuses on ensuring that IT services meet agreed availability targets, not on negotiating or monitoring SLAs; it uses metrics like uptime percentages and MTBF. Option C (Supplier Management) is wrong because it manages relationships with external suppliers and their contracts, not the SLAs with internal or external customers. Option D (Service Desk) is wrong because it is the single point of contact for incident and service requests, handling operational communication, not the strategic negotiation or monitoring of SLAs.

33
MCQmedium

A change request to replace a server with a newer model is assessed as low risk and follows a defined procedure. Which type of change should this be classified as in ITIL 4?

A.Service request
B.Emergency change
C.Normal change
D.Standard change
AnswerD

Standard changes are low risk, pre-approved, and follow a procedure.

Why this answer

A standard change is a pre-approved, low-risk change that follows a defined procedure, such as replacing a server with a newer model according to a vendor's lifecycle plan. This classification allows the change to be implemented without requiring additional authorization from the change authority, as long as it adheres to the established procedure. The key differentiator is that the risk is assessed as low and the procedure is well-documented and repeatable.

Exam trap

The trap here is that candidates often confuse a standard change with a normal change because they think any infrastructure replacement requires formal approval, but ITIL 4 specifically classifies low-risk, procedure-driven changes as standard to streamline operations.

How to eliminate wrong answers

Option A is wrong because a service request is a formal request from a user for something to be provided – for example, a request for information or access – not a change to an infrastructure component like a server replacement. Option B is wrong because an emergency change must be implemented as soon as possible to resolve an incident or security vulnerability, whereas this change is assessed as low risk and follows a planned procedure, not an urgent response. Option C is wrong because a normal change requires approval from the change authority before implementation, but this change is pre-approved due to its low risk and defined procedure, making it a standard change instead.

34
MCQhard

Which ITIL 4 practice involves managing the lifecycle of all IT assets, including financial and contractual components?

A.Service Configuration Management
B.Capacity and Performance Management
C.Supplier Management
D.IT Asset Management
AnswerD

IT Asset Management (ITAM) is the practice responsible for planning, acquiring, deploying, managing, and disposing of IT assets throughout their entire lifecycle. This comprehensive approach includes managing financial, contractual, and inventory aspects to maximize value, control costs, and mitigate risks associated with IT assets. ITAM ensures that assets are effectively utilized, maintained, and retired in alignment with organizational objectives and regulatory requirements, directly addressing the management of an asset's full lifecycle.

Why this answer

IT Asset Management covers the full lifecycle of assets, including financial and contractual aspects.

35
Multi-Selectmedium

Which TWO of the following are types of change in ITIL 4?

Select 2 answers
A.Urgent change
B.Normal change
C.Routine change
D.Planned change
E.Standard change
AnswersB, E

Normal changes are the most common type of change, requiring full assessment, authorization, and scheduling. They follow a defined process, which typically includes peer review, impact analysis, risk assessment, and formal approval, often by a Change Advisory Board (CAB), before implementation. This structured approach is crucial for managing significant service modifications, new deployments, or complex updates that are not pre-approved or driven by an immediate emergency, ensuring thorough risk mitigation.

Why this answer

The three change types are standard, normal, and emergency.

36
MCQmedium

An e-commerce company defines an SLA that its website will be available 99.9% of the time. Which practice is primarily responsible for negotiating and monitoring this agreement?

A.Supplier Management
B.Monitoring and Event Management
C.Service Level Management
D.Availability Management
AnswerC

Service Level Management is the dedicated practice responsible for setting clear, business-focused targets for service performance and ensuring that the organization meets these agreed-upon levels. It involves defining, documenting, agreeing, monitoring, analyzing, and reviewing service level agreements (SLAs) with customers, ensuring that services are delivered according to expectations and value is co-created. This practice directly addresses the negotiation and definition of customer-facing service commitments.

Why this answer

Service Level Management negotiates, agrees, and monitors SLAs with customers.

37
MCQeasy

What is the role of the Service Desk in ITIL 4?

A.Authorizing and scheduling changes
B.Identifying root causes of incidents
C.Single point of contact for users reporting incidents and requests
D.Monitoring and reporting on service levels
AnswerC

The Service Desk serves as the crucial single point of contact (SPOC) between the service provider and its users. This central role ensures that users have one clear channel for reporting incidents, making service requests, and seeking information, thereby streamlining communication and improving user experience. By acting as the SPOC, the Service Desk facilitates efficient logging, initial assessment, and routing of all user interactions to the appropriate support teams or practices.

Why this answer

The Service Desk acts as a single point of contact (SPOC) for users, handling incidents and service requests. Option A is incorrect because authorizing and scheduling changes is the role of Change Enablement. Option B is incorrect because identifying root causes of incidents is part of Problem Management.

Option D is incorrect because monitoring and reporting on service levels is part of Service Level Management. Option C correctly identifies the Service Desk as the single point of contact.

38
Multi-Selectmedium

Which TWO activities are part of the problem identification phase of Problem Management?

Select 2 answers
A.Organizing workarounds into known-error records
B.Trend analysis of incident records
C.Root cause analysis
D.Analyzing incident data for patterns
E.Implementing a known error
AnswersB, D

Trend analysis of incident records is a crucial activity for problem identification, as it involves systematically reviewing historical incident data to detect recurring patterns or increasing frequencies of specific incident types over time. By observing these trends, IT teams can proactively identify emerging problems that might otherwise go unnoticed, signaling a need for deeper investigation into an underlying cause. This proactive approach helps prevent future service disruptions.

Why this answer

Problem identification involves proactively identifying potential problems. The correct activities are trend analysis of incident records (option B) and analyzing incident data for patterns (option D). These help detect recurring issues.

Option A (organizing workarounds into known-error records) is part of error control, not identification. Option C (root cause analysis) is part of problem control. Option E (implementing a known error) is also error control.

39
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. What should they do FIRST?

A.Submit an emergency change to fix the system
B.Raise a problem record to investigate the root cause
C.Log an incident record and attempt to restore service
D.Inform the users that it is a known issue
AnswerC

Logging an incident record and attempting to restore service is the correct immediate action, aligning with the primary objective of ITIL's Incident Management practice. An incident is defined as an unplanned interruption to a service or a reduction in the quality of a service. The service desk's role is to capture this event, track it, and initiate steps to restore service functionality to users as quickly as possible, minimizing business impact.

Why this answer

The first step is to log the incident to initiate the Incident Management process and restore service.

40
MCQeasy

Which of the following is a key activity in the Problem Management practice?

A.Authorizing and scheduling emergency changes
B.Fulfilling a password reset request from a user
C.Restoring service as quickly as possible using a workaround
D.Documenting known errors and workarounds in the Known Error Database
AnswerD

Documenting known errors and workarounds in the Known Error Database is a critical activity within the Error Control phase of Problem Management. Once a problem's root cause has been identified and a temporary solution developed, recording this information allows for quicker incident resolution in the future and prevents recurrence. This database serves as a vital knowledge base, enabling efficient incident diagnosis and providing interim solutions until a permanent fix is implemented.

Why this answer

Problem Management includes error control, which involves documenting known errors and workarounds in the Known Error Database (KEDB). Therefore, option D is correct. Option A pertains to Change Enablement.

Option B is a Service Request. Option C describes Incident Management.

41
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To handle pre-defined, pre-approved service requests from users
B.To identify the root cause of incidents and prevent recurrence
C.To restore normal service operation as quickly as possible and minimize the adverse impact on business operations
D.To assess, authorize, and schedule changes to the IT infrastructure
AnswerC

Restoring normal service operation as quickly as possible directly satisfies the Incident Management practice’s primary constraint of minimising business disruption, as defined in the ITIL 4 service value system. This objective prioritises speed of recovery over root-cause analysis, which distinguishes it from the Problem Management practice’s focus on permanent resolution.

Why this answer

Incident Management aims to restore normal service operation as quickly as possible and minimize the adverse impact on business operations, ensuring that agreed levels of service quality are maintained. Therefore, Option C is correct. Option A describes Service Request Management.

Option B describes Problem Management. Option D describes Change Enablement.

42
MCQhard

An organization is implementing a new IT service management tool. According to ITIL 4, which practice would be primarily responsible for ensuring that the tool's performance meets the agreed demand?

A.Service Configuration Management
B.Capacity and Performance Management
C.Monitoring and Event Management
D.Availability Management
AnswerB

Capacity and Performance Management is the ITIL practice specifically designed to ensure that services and service components are able to meet agreed performance targets and demand, both current and future. It involves understanding the current capacity and performance of resources, forecasting future demand, and planning for necessary adjustments to maintain optimal service delivery and user experience. This practice proactively balances the cost of capacity with the need for performance and availability.

Why this answer

Capacity and Performance Management ensures that services perform at the required level to meet demand. Availability Management focuses on uptime, not performance.

43
MCQeasy

Which type of change follows a pre-defined, low-risk procedure and is pre-approved?

A.Service request
B.Normal change
C.Standard change
D.Emergency change
AnswerC

A standard change is a pre-authorized change that is low-risk, well-understood, and has a documented procedure for implementation. These changes are typically routine, frequently performed, and do not require additional authorization each time they are executed, as the risk has been assessed and approved beforehand. This classification perfectly aligns with following a pre-defined, low-risk procedure, making it efficient for common modifications.

Why this answer

A standard change is a pre-defined, low-risk change that follows a specific procedure and is pre-approved by change management. It does not require a new change request each time because its risk profile and implementation steps are already documented and authorized. This aligns with ITIL 4's definition of a standard change as a change that is well-understood, fully documented, and can be implemented without additional approval.

Exam trap

The trap here is that candidates often confuse 'standard change' with 'service request' because both can follow a pre-defined procedure, but ITIL 4 explicitly separates them: a service request is for standard services (e.g., password reset), while a standard change is for low-risk technical changes (e.g., applying a tested patch).

How to eliminate wrong answers

Option A is wrong because a service request is a formal request from a user for something to be provided – such as access, information, or a standard service – and while it may follow a pre-defined procedure, it is not a type of change; it is a separate category in ITIL 4. Option B is wrong because a normal change is any change that is not standard or emergency; it requires a full assessment and approval through the change advisory board (CAB) and does not have pre-approval. Option D is wrong because an emergency change is a change that must be implemented as soon as possible to resolve an incident or critical issue; it follows an expedited process but is not pre-approved and carries higher risk.

44
Multi-Selecteasy

Which TWO of the following are components of the ITIL 4 Service Value System?

Select 2 answers
A.Service level agreements (SLAs)
B.Guiding principles
C.Outputs
D.Governance
E.Service desk
AnswersB, D

Guiding principles are a key component of the SVS.

Why this answer

The ITIL 4 SVS includes guiding principles, governance, service value chain, practices, and continual improvement. Outputs and SLAs are not components of the SVS.

45
MCQmedium

Which of the following is an example of an emergency change?

A.Updating the service desk knowledge base with new articles
B.Applying a critical security patch to a production server to fix a vulnerability
C.A request to install a new software version for all users next month
D.A password reset for a user
AnswerB

Applying a critical security patch to a production server to fix a vulnerability is a prime example of an emergency change. Such a situation involves an immediate, severe threat to the security, availability, or integrity of a live service, demanding urgent action to prevent significant business impact or data compromise. The critical nature of the vulnerability necessitates an expedited assessment and authorization process, bypassing the typical, longer change schedule to mitigate the risk as quickly as possible.

Why this answer

Emergency changes are for urgent situations like security patches; they follow a faster authorization process.

46
Multi-Selecthard

Which THREE of the following are activities of Service Level Management?

Select 3 answers
A.Managing supplier contracts
B.Reporting service performance
C.Monitoring service performance against SLAs
D.Negotiating and agreeing SLAs
E.Defining service metrics
AnswersB, C, D

Reporting service performance is a critical activity within Service Level Management, ensuring transparency and accountability. This involves systematically collecting, analyzing, and presenting data on how well services are meeting their agreed-upon targets to relevant stakeholders, including customers and internal management. Regular performance reports highlight achievements, identify deviations, and provide insights necessary for continuous service improvement and informed decision-making regarding service levels.

Why this answer

Service Level Management involves negotiating SLAs, monitoring service performance, and reporting results. Defining service metrics is part of service design, not a direct activity of SLA management.

47
MCQhard

Which of the following is an example of an 'exception' event as defined in Monitoring and Event Management?

A.A disk is nearing capacity
B.A server's CPU usage exceeds 95% and requires immediate attention
C.A user logs into the system
D.A backup job completes successfully
AnswerB

A server's CPU usage exceeding 95% and requiring immediate attention is a clear example of an exception event. This critical threshold signifies an abnormal and potentially service-impacting situation that demands urgent, often reactive, intervention to prevent performance degradation or system failure. It represents a severe deviation from expected operational norms that cannot be ignored without significant consequences for service delivery.

Why this answer

Exception events indicate that something is outside normal operation and requires immediate action. Option B, where server CPU usage exceeds 95% and requires immediate attention, is an example of an exception event. Option A (disk nearing capacity) is typically a warning.

Option C (user login) is informational. Option D (backup completion) is informational.

48
MCQhard

An organization has implemented a change to update the firewall rules. The change was pre-authorized and followed a predefined procedure. What type of change is this?

A.Standard change
B.Normal change
C.Service request
D.Emergency change
AnswerA

A standard change is a low-risk, pre-authorized change that follows a well-established, documented procedure. Updating a firewall rule, if it's a routine, templated modification (e.g., opening a specific port for a new application following a pre-approved template), perfectly aligns with this definition. Such changes are implemented without needing additional authorization each time, enabling efficient and consistent delivery of common infrastructure modifications.

Why this answer

In ITIL 4, a standard change is a pre-approved, low-risk change that follows a defined procedure. Option A is correct. Option B (normal change) requires authorization through the change advisory board.

Option C (emergency change) is for urgent issues. Option D (service request) is for routine service requests, not changes.

49
MCQeasy

What is the PRIMARY purpose of the Problem Management practice?

A.To restore normal service operation as quickly as possible
B.To handle service requests from users efficiently
C.To manage the lifecycle of all IT assets
D.To eliminate or reduce the impact of incidents by identifying root causes
AnswerD

Problem management's primary purpose is indeed to eliminate or reduce the likelihood and impact of incidents by identifying and resolving their underlying root causes. This involves both reactive analysis of existing incidents and proactive trend analysis to prevent future occurrences, often leading to the creation of known errors and permanent solutions or effective workarounds.

Why this answer

Problem management aims to identify the root causes of incidents and prevent recurrence or reduce impact. Restoring service is the purpose of incident management.

50
MCQmedium

An organization wants to track the lifecycle of its servers, including acquisition, maintenance, and disposal. Which practice should they use?

A.Supplier Management
B.Capacity and Performance Management
C.IT Asset Management
D.Service Configuration Management
AnswerC

IT Asset Management is the practice of planning, acquiring, deploying, managing, and retiring IT assets, including servers, throughout their entire lifecycle. This comprehensive approach encompasses tracking financial aspects like depreciation, contractual details, physical location, and operational status from procurement through to disposal. It directly addresses the organization's need to understand and manage the full journey and value of its servers.

Why this answer

IT Asset Management (ITAM) is the correct practice because it is specifically designed to manage the complete lifecycle of IT assets, including servers, from acquisition through maintenance to disposal. ITAM tracks financial value, contractual agreements (e.g., warranties, leases), and physical status, ensuring compliance and cost optimization across the entire lifecycle.

Exam trap

The trap here is confusing Service Configuration Management (which tracks configuration items and their relationships) with IT Asset Management (which tracks the financial and lifecycle aspects of assets), leading candidates to pick D because they think 'tracking lifecycle' means tracking configuration changes.

How to eliminate wrong answers

Option A is wrong because Supplier Management focuses on managing relationships and contracts with external vendors, not on tracking the internal lifecycle of assets like servers. Option B is wrong because Capacity and Performance Management deals with ensuring current and future performance and capacity demands are met, not with lifecycle tracking of individual hardware assets. Option D is wrong because Service Configuration Management (now part of Service Configuration Management in ITIL 4) manages the configuration items (CIs) and their relationships within the service model, but it does not handle financial tracking, procurement, or disposal processes that are core to asset lifecycle management.

51
MCQhard

A user requests a new laptop because their current one is slow. The request is for a standard configuration. How should this be handled?

A.As a change request
B.As a service request
C.As an incident
D.As a problem
AnswerB

A service request represents a formal request from a user for something that is a normal part of service delivery, typically a pre-defined and pre-approved offering from the service catalog. Requesting a new laptop, especially when it's a standard model provided by the organization, falls squarely into this category. These requests are usually low-risk, frequently occurring, and follow established workflows for fulfillment, often with automated or semi-automated processes.

Why this answer

A request for a standard configuration item, such as a new laptop with a standard configuration, is a service request because it is pre-approved and follows a defined procedure. Option B is correct. Option A (change request) is incorrect because a change request is required for deviations from standard or for changes that may need approval, not for standard requests.

Option C (incident) is incorrect because an incident is an unplanned interruption or reduction in quality of an IT service. Option D (problem) is incorrect because a problem is the cause of one or more incidents.

52
MCQmedium

What is the relationship between a Configuration Management Database (CMDB) and IT Asset Management?

A.IT Asset Management provides financial data for CIs in the CMDB
B.The CMDB replaces IT Asset Management
C.They are the same practice
D.IT Asset Management is a subset of Service Configuration Management
AnswerA

IT Asset Management (ITAM) is responsible for tracking the financial and contractual aspects of IT assets throughout their lifecycle, including acquisition cost, depreciation, warranty information, and end-of-life dates. This crucial financial and lifecycle data is then integrated with Configuration Items (CIs) within the Configuration Management Database (CMDB). This integration enriches the CMDB's technical view with vital business context, enabling better decision-making regarding asset utilization and investment.

Why this answer

IT Asset Management manages the lifecycle of assets (financial and contractual), while the CMDB records configuration items (CIs) and their relationships. They are complementary, with the CMDB often containing asset information but not replacing asset management.

53
MCQeasy

A retail company is experiencing frequent service outages during peak hours due to insufficient capacity. The IT team wants to implement a practice that ensures the service provider has the capacity to meet agreed service level targets cost-effectively and in a timely manner. Which ITIL management practice should they use?

A.Monitoring and event management
B.Capacity and performance management
C.Availability management
D.Service level management and availability management
AnswerB

Capacity and availability management is the best answer because it addresses capacity, which is the core requirement of the question. Note that the exact ITIL 4 practice name is Capacity and performance management, but among the options, this is the most appropriate.

Why this answer

In ITIL 4, the practice that ensures the service provider has sufficient capacity to meet agreed service level targets cost-effectively and in a timely manner is Capacity and performance management. Option B represents this practice. Option A (Monitoring and event management) focuses on detecting events, not capacity planning.

Option C (Availability management) focuses on availability, not capacity. Option D (Service level management and availability management) covers service levels and availability but not capacity. Therefore, B is correct.

54
Multi-Selectmedium

Which TWO of the following are key activities of Problem Management?

Select 2 answers
A.Conducting root cause analysis
B.Authorizing changes to resolve incidents
C.Restoring normal service as quickly as possible
D.Managing service requests from users
E.Identifying problems from incidents
AnswersA, E

Root cause analysis (RCA) is a fundamental activity within problem management, specifically falling under the 'problem control' phase. Its purpose is to systematically investigate and determine the underlying causes of one or more incidents, preventing their recurrence. By identifying the true origin of issues, problem management can develop effective workarounds and permanent solutions, thereby reducing the impact and frequency of future service disruptions. This proactive approach is crucial for improving service stability and reliability.

Why this answer

Problem management includes problem identification and root cause analysis (problem control). Restoring service is incident management, and managing changes is change enablement.

55
Multi-Selecteasy

Which TWO of the following are types of events in the Monitoring and Event Management practice?

Select 2 answers
A.Known error
B.Standard change
C.Warning event
D.Service request
E.Informational event
AnswersC, E

Warning events indicate a threshold is approaching.

Why this answer

Events are classified into three types: informational, warning, and exception. Options C (Warning event) and E (Informational event) are correct types. Option A (Known error) is a type of problem, not an event.

Option B (Standard change) is a type of change request. Option D (Service request) is a type of request, not an event.

56
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To restore normal service operation as quickly as possible and minimize business impact
B.To manage the lifecycle of all changes to IT services
C.To find the root cause of incidents and prevent recurrence
D.To handle service requests from users in a standardized way
AnswerA

Incident Management's core objective is to minimize disruption to business operations by restoring affected services to their agreed-upon operational state as swiftly as possible. This practice focuses on the immediate impact of unplanned interruptions or reductions in service quality, aiming for quick fixes or workarounds to ensure continuity rather than deep root cause analysis. Its success is measured by how rapidly normal service is resumed and the extent to which business productivity is preserved.

Why this answer

The primary purpose is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations.

57
MCQmedium

Which ITIL 4 practice involves classifying events as informational, warning, or exception?

A.Problem Management
B.Service Desk
C.Incident Management
D.Monitoring and Event Management
AnswerD

Monitoring and Event Management is the ITIL 4 practice specifically designed to systematically observe services and service components, recording and reporting selected changes of state identified as events. A fundamental activity within this practice is the classification of these events into meaningful categories, such as informational (no action needed), warning (potential issue), or exception (requires action), to enable appropriate automated or manual responses.

Why this answer

The Monitoring and Event Management practice is specifically responsible for monitoring IT services and categorizing events into three types: informational (routine notifications), warning (conditions that may require attention), and exception (significant deviations requiring immediate action). This classification enables appropriate responses based on the event's severity and impact on service availability.

Exam trap

The trap here is that candidates confuse the event classification step with Incident Management, but ITIL 4 explicitly assigns the classification of events (informational, warning, exception) to the Monitoring and Event Management practice, not to the incident lifecycle.

How to eliminate wrong answers

Option A is wrong because Problem Management focuses on identifying the root cause of incidents and preventing recurrence, not on classifying real-time events into informational, warning, or exception categories. Option B is wrong because the Service Desk acts as the single point of contact for users reporting incidents or service requests, and does not perform event classification or monitoring. Option C is wrong because Incident Management handles the lifecycle of unplanned interruptions or service reductions, but event classification occurs before an incident is declared, as part of the monitoring and detection process.

58
MCQmedium

Which ITIL practice involves negotiating, agreeing, and monitoring service level targets?

A.Incident Management
B.Supplier Management
C.Service Level Management
D.Service Desk
AnswerC

Service Level Management is the practice of setting clear business-based targets for service performance, and ensuring that delivery of services is properly assessed, monitored, and managed against these targets. This practice explicitly involves negotiating service level agreements (SLAs) with customers to define measurable service outcomes, agreeing upon these targets, and then continuously monitoring and reporting on actual service performance against the agreed levels to ensure value co-creation and customer satisfaction.

Why this answer

Service Level Management is responsible for SLAs and ensuring services meet agreed targets.

59
MCQeasy

What is the role of the Service Desk according to ITIL 4?

A.To manage changes
B.To negotiate SLAs
C.To be the single point of contact for users
D.To perform root cause analysis
AnswerC

The Service Desk serves as the crucial single point of contact (SPOC) between the service provider and its users. This means users have one consistent channel for logging incidents, requesting services, and making inquiries, streamlining communication and improving user experience. By centralizing these interactions, the Service Desk ensures efficient routing, tracking, and resolution of all user-initiated contacts, embodying its core ITIL 4 purpose.

Why this answer

The Service Desk is the single point of contact (SPOC) for users to report issues and request services.

60
MCQhard

A user requests a new laptop for a new employee. According to ITIL 4, how should this request be classified?

A.As an incident because the user lacks a laptop to work
B.As a problem because it may have been caused by a previous incident
C.As a normal change because it requires authorization
D.As a service request because it is a standard request from a user
AnswerD

Service requests handle predefined, routine requests like new equipment.

Why this answer

In ITIL 4, a service request is a standardized, pre-defined request from a user for something that does not involve a failure or a change to the service's risk profile. Requesting a new laptop for a new employee is a standard, low-risk, pre-approved request that follows an established procedure, making it a service request, not an incident or a change.

Exam trap

The trap here is confusing a user's need (lack of a laptop) with an incident, when ITIL 4 explicitly defines incidents as service-affecting failures, not as unmet user needs that are fulfilled via standard service requests.

How to eliminate wrong answers

Option A is wrong because an incident is defined as an unplanned interruption or reduction in quality of a service; lacking a laptop for a new employee is not a service failure or degradation. Option B is wrong because a problem is the root cause of one or more incidents, and this request is not caused by a previous incident. Option C is wrong because a normal change requires formal authorization and risk assessment, whereas a service request for a new laptop is typically pre-approved and follows a standard procedure without requiring a full change authorization process.

61
Multi-Selectmedium

Which TWO of the following are components of the Service Value System (SVS)?

Select 2 answers
A.Service desk
B.Service level agreements
C.Configuration management database
D.Service value chain
E.Guiding principles
AnswersD, E

The Service Value Chain (SVC) is a core operational model within the ITIL Service Value System, outlining the six key activities an organization undertakes to create value. It describes how demand is translated into value through a sequence of interconnected steps: Plan, Engage, Design & Transition, Obtain/Build, Deliver & Support, and Improve. The SVC is central to understanding how an organization delivers services and manages its value streams.

Why this answer

The Service Value System (SVS) is a core component of ITIL 4 that describes how all components and activities of an organization work together as a system to enable value creation. The Service Value Chain (Option D) is a central element of the SVS, providing an operating model for the creation, delivery, and continuous improvement of services. Guiding Principles (Option E) are also a key component of the SVS, providing universal recommendations that guide an organization in all its work.

Exam trap

The trap here is that candidates often confuse operational components (like Service Desk, SLAs, or CMDB) with the high-level, abstract building blocks of the Service Value System, leading them to select concrete tools or documents instead of the correct conceptual components.

62
Multi-Selecthard

Which TWO statements correctly describe the relationship between Service Level Management and other practices?

Select 2 answers
A.SLAs are used to manage supplier performance
B.SLAs are agreements between internal IT teams
C.SLAs define the detailed steps of the incident handling process
D.OLAs support the achievement of SLAs
E.SLAs provide targets for Incident Management
AnswersD, E

Operational Level Agreements (OLAs) are internal agreements between different departments or teams within the same service provider organization. Their primary purpose is to define the specific responsibilities, activities, and performance targets that each internal group must meet to collectively ensure the successful delivery of services and, consequently, the achievement of the customer-facing Service Level Agreements (SLAs). Without robust OLAs, internal coordination can falter, jeopardizing SLA compliance.

Why this answer

Options D and E are correct. D is correct because Operational Level Agreements (OLAs) are internal agreements between IT teams that support the achievement of Service Level Agreements (SLAs). E is correct because SLAs define the targets that Incident Management must meet, such as response times and resolution times.

Option A is incorrect because supplier performance is managed through Underpinning Contracts (UCs) with suppliers, not SLAs. Option B is incorrect because SLAs are agreements between the service provider and the customer, not between internal IT teams. Option C is incorrect because SLAs specify service level targets, not the detailed steps of the incident handling process.

63
MCQhard

A user requests a new laptop for a new employee. According to ITIL 4, how should this request be classified?

A.Problem, because it may indicate a recurring issue
B.Incident, because the user has a need
C.Service request, because it is a pre-defined and pre-approved request
D.Change request, because it involves procuring hardware
AnswerC

A Service Request is a formal request from a user for something standard that is part of normal service delivery, often pre-defined, pre-approved, and fulfilled through a standard process. Providing a new laptop for a new employee is a classic example of a standard, repeatable service offering that fits within established workflows and policies. This type of request is typically handled efficiently through automated or semi-automated fulfillment processes.

Why this answer

New laptop provisioning is a standard, pre-approved request, thus a service request.

64
MCQmedium

Which metric is MOST appropriate for measuring the effectiveness of the Incident Management practice?

A.Percentage of SLAs met
B.Number of known errors
C.Mean Time to Restore Service (MTTR)
D.First Call Resolution (FCR) rate
AnswerC

Mean Time to Restore Service (MTTR) is the most appropriate metric for measuring the effectiveness of service restoration. It quantifies the average time taken from the start of an incident to the full restoration of the affected service to its normal operational state. MTTR directly reflects the efficiency of the incident management process, encompassing detection, diagnosis, repair, and verification, thereby providing a clear indicator of how quickly an organization can recover from service disruptions.

Why this answer

Mean Time to Restore Service (MTTR) directly measures how quickly service is restored, making it the most appropriate metric for Incident Management effectiveness. First Call Resolution (FCR) is for Service Desk. SLA compliance is for Service Level Management.

Number of known errors is for Problem Management.

65
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To handle predefined, pre-approved service requests
B.To restore normal service operation as quickly as possible and minimize business impact
C.To manage and control changes to IT services
D.To find the root cause of incidents and prevent recurrence
AnswerB

This is the correct definition of Incident Management's purpose.

Why this answer

The primary purpose of Incident Management is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations. This practice focuses on resolving incidents—unplanned interruptions or reductions in quality of an IT service—rather than handling predefined requests, managing changes, or performing root cause analysis. The ITIL 4 Foundation explicitly defines this as the core objective, ensuring that service availability and quality are restored within agreed service level targets.

Exam trap

The ITIL Foundation exam often tests the distinction between Incident Management and Problem Management, trapping candidates who confuse the reactive, restoration-focused nature of Incident Management with the proactive, root-cause-elimination focus of Problem Management.

How to eliminate wrong answers

Option A is wrong because handling predefined, pre-approved service requests is the purpose of the Service Request Management practice, not Incident Management; incidents are unplanned, whereas service requests are standard, low-risk user demands. Option C is wrong because managing and controlling changes to IT services is the domain of Change Enablement, which focuses on assessing, authorizing, and implementing changes with minimal risk, not on restoring service after an unplanned interruption. Option D is wrong because finding the root cause of incidents and preventing recurrence is the objective of Problem Management, which conducts root cause analysis and implements permanent fixes, whereas Incident Management is solely concerned with swift restoration without necessarily identifying the underlying cause.

66
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To identify the root cause of incidents
B.To handle pre-approved service requests
C.To monitor and manage events across the infrastructure
D.To restore normal service operation as quickly as possible
AnswerD

Core purpose of incident management.

Why this answer

The primary purpose of incident management is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations. Option D is correct. Option A (identify root cause) is problem management.

Option B (handle pre-approved service requests) is service request management. Option C (monitor and manage events) is monitoring and event management.

67
Multi-Selecthard

Which THREE of the following are activities of the Problem Management practice?

Select 3 answers
A.Problem identification
B.Root cause analysis
C.Managing changes
D.Managing known errors
E.Monitoring services for events
AnswersA, B, D

Problem identification is a foundational activity within Problem Management, initiating the process by detecting and logging potential or actual problems. This involves analyzing incident trends, reviewing service desk data, and receiving direct input from various stakeholders to proactively identify recurring issues or single, high-impact events that warrant deeper investigation. The goal is to move beyond mere symptom treatment to understand underlying causes.

Why this answer

Problem Management includes problem identification, root cause analysis (problem control), and managing known errors (error control). Monitoring services is part of Monitoring and Event Management. Managing changes is part of Change Enablement.

68
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To find the root cause of incidents
B.To monitor and manage events
C.To restore normal service operation as quickly as possible
D.To manage service requests
AnswerC

This is the fundamental purpose of the Incident Management practice within ITIL 4. Its objective is to minimize the negative impact of incidents by restoring normal service operation as swiftly as possible. This involves rapid diagnosis, workaround implementation, and resolution to ensure business continuity and maintain agreed service levels, thereby reducing disruption to users and the organization.

Why this answer

Incident management aims to restore normal service operation as quickly as possible and minimize adverse impact.

69
Multi-Selecteasy

Which TWO are key activities of Capacity and Performance Management?

Select 2 answers
A.Defining service level targets
B.Managing the IT service desk staffing levels
C.Forecasting future demand for services
D.Managing service availability
E.Monitoring current service performance
AnswersC, E

Forecasting future demand for services is a critical activity within capacity and performance management, specifically for proactive capacity planning. By analyzing historical trends, business plans, and anticipated growth, organizations can predict future resource requirements for IT services and their underlying components. This foresight enables the timely acquisition, provisioning, or scaling of infrastructure and applications, ensuring that sufficient capacity is available to meet evolving business needs without costly over-provisioning or detrimental under-provisioning.

Why this answer

Capacity and Performance Management focuses on ensuring that services meet agreed capacity and performance targets. Key activities include monitoring current service performance (Option E) to identify trends and issues, and forecasting future demand (Option C) to plan for capacity needs. Option A (defining service level targets) is part of Service Level Management.

Option B (managing IT service desk staffing levels) is part of the Service Desk practice. Option D (managing service availability) is part of Availability Management.

70
Multi-Selecthard

Which TWO statements about the relationship between IT Asset Management and Service Configuration Management are correct?

Select 2 answers
A.Asset management maintains the configuration baseline
B.All assets are considered CIs, and all CIs are assets
C.Configuration management provides information about relationships between assets
D.Configuration management provides the CMDB that includes details of IT assets
E.Asset management focuses on the lifecycle of CIs
AnswersC, D

Configuration management is fundamentally concerned with understanding how different components of an IT service relate to each other to ensure service integrity and operational efficiency. By defining and tracking Configuration Items (CIs) and their interdependencies within the Configuration Management System (CMS), it provides crucial insights into how changes to one asset (represented as a CI) might impact others. This relational information is vital for effective incident, problem, and change management, ensuring service stability and reliability.

Why this answer

Configuration management provides information about relationships between CIs, which helps understand dependencies. Option D is correct: Configuration management provides the CMDB that includes details of IT assets (CIs). Option A is incorrect because configuration management maintains the configuration baseline, not asset management.

Option B is incorrect because not all assets are CIs and not all CIs are assets; they are separate but overlapping concepts. Option E is incorrect because asset management focuses on the entire lifecycle of assets, not just CIs.

71
MCQmedium

What is the primary focus of Problem Management in ITIL 4?

A.Managing service requests from users
B.Restoring service as quickly as possible
C.Implementing changes to IT infrastructure
D.Finding underlying causes of incidents
AnswerD

Finding underlying causes of incidents is the central purpose of Problem Management. This ITIL practice focuses on identifying the root causes of actual or potential incidents, analyzing trends, and developing permanent solutions to prevent recurrence. By moving beyond temporary fixes, Problem Management aims to eliminate known errors and improve the long-term stability and reliability of IT services, thereby reducing the overall number and impact of future incidents.

Why this answer

Problem Management in ITIL 4 focuses on identifying and analyzing the underlying causes of incidents to prevent recurrence or minimize their impact. Option D is correct because this practice aims to diagnose root causes, not just restore service or handle requests, aligning with the ITIL 4 guiding principle of 'Focus on Value' by reducing future disruptions.

Exam trap

The trap here is that candidates confuse the reactive, fast-restore focus of Incident Management (Option B) with the proactive, root-cause analysis focus of Problem Management, leading them to select the wrong answer when the question explicitly asks for the 'primary focus' of Problem Management.

How to eliminate wrong answers

Option A is wrong because managing service requests is the domain of Service Desk and Request Fulfillment, not Problem Management, which deals with incidents and their root causes. Option B is wrong because restoring service as quickly as possible is the primary goal of Incident Management, which prioritizes speed over root cause analysis. Option C is wrong because implementing changes to IT infrastructure is the responsibility of Change Enablement, not Problem Management, though Problem Management may identify the need for changes.

72
MCQmedium

Which ITIL 4 practice is responsible for managing the complete lifecycle of all IT assets, including financial and contractual aspects?

A.Service Configuration Management
B.IT Asset Management
C.Service Portfolio Management
D.Supplier Management
AnswerB

IT Asset Management manages the lifecycle of assets, including financial and contractual aspects.

Why this answer

IT Asset Management (ITAM) is the ITIL 4 practice responsible for managing the complete lifecycle of all IT assets, including financial and contractual aspects. It covers planning, acquisition, deployment, maintenance, and disposal, ensuring cost optimization and compliance with vendor contracts. This aligns directly with the question's emphasis on lifecycle management plus financial and contractual oversight.

Exam trap

The trap here is that candidates confuse Service Configuration Management with IT Asset Management because both involve inventories, but ITAM uniquely handles financial and contractual data, whereas Configuration Management focuses on service relationships and control.

How to eliminate wrong answers

Option A (Service Configuration Management) is wrong because it focuses on managing configuration items (CIs) and their relationships within the service model, not on financial or contractual aspects of assets. Option C (Service Portfolio Management) is wrong because it manages the entire portfolio of services from idea to retirement, not the lifecycle of physical or digital IT assets with financial tracking. Option D (Supplier Management) is wrong because it oversees supplier relationships and performance, not the internal lifecycle and financial management of IT assets themselves.

73
MCQmedium

Which of the following is a key activity of Service Level Management?

A.Resolving incidents within agreed times
B.Installing new software
C.Managing supplier contracts
D.Negotiating and agreeing SLAs
AnswerD

Negotiating and agreeing Service Level Agreements (SLAs) is a fundamental and defining activity of the Service Level Management practice. This involves establishing clear, measurable targets for service performance, availability, capacity, and other critical aspects, ensuring they align with customer expectations and business requirements. By formalizing these agreements, Service Level Management sets the baseline for monitoring, reporting, and continual improvement of service delivery, directly linking IT services to business outcomes.

Why this answer

Service Level Management involves negotiating, agreeing, and monitoring SLAs, as well as reporting on service performance.

74
MCQmedium

A user calls the service desk to report that they cannot access a shared folder. The analyst resolves the issue by resetting the folder permissions. Which practice is being performed?

A.Incident Management
B.Change Enablement
C.Service Request Management
D.Problem Management
AnswerA

Incident Management's primary purpose is to minimize the negative impact of incidents by restoring normal service operation as quickly as possible. An unplanned disruption, such as a user being unable to access a critical service, directly aligns with the ITIL definition of an incident. The immediate action taken by the service desk to resolve this access issue is a core activity within the Incident Management practice, aiming for swift resolution and service restoration.

Why this answer

Resetting permissions for an unplanned access issue is restoring a failed service, which is Incident Management.

75
Multi-Selecthard

Which THREE of the following are key activities of the Service Level Management practice?

Select 3 answers
A.Managing supplier contracts
B.Conducting service reviews with customers
C.Negotiating and agreeing service level targets
D.Monitoring and reporting service performance against SLAs
E.Resolving incidents at first contact
AnswersB, C, D

Conducting service reviews with customers is a fundamental activity of Service Level Management, providing a structured forum to discuss service performance, customer satisfaction, and any changes in business requirements. These regular reviews are crucial for ensuring that the agreed service level agreements (SLAs) remain relevant and continue to align with customer needs and business objectives, fostering a collaborative relationship and identifying opportunities for continual improvement.

Why this answer

Service Level Management includes negotiating and agreeing service level targets (option C), monitoring and reporting service performance against SLAs (option D), and conducting service reviews with customers (option B). These are key activities. Option A is incorrect because managing supplier contracts falls under Supplier Management.

Option E is incorrect because resolving incidents at first contact is an activity of Incident Management, not Service Level Management.

Page 1 of 4 · 260 questions totalNext →

Ready to test yourself?

Try a timed practice session using only ITIL Management Practices questions.