Courseiva

CCNA ITIL Management Practices Questions

75 of 301 questions · Page 2/5 · ITIL Management Practices · Answers revealed

76
Multi-Selecteasy

Which TWO are key activities of Capacity and Performance Management?

Select 2 answers
A.Defining service level targets
B.Managing the IT service desk staffing levels
C.Forecasting future demand for services
D.Managing service availability
E.Monitoring current service performance
AnswersC, E

Forecasting future demand for services is a critical activity within capacity and performance management, specifically for proactive capacity planning. By analyzing historical trends, business plans, and anticipated growth, organizations can predict future resource requirements for IT services and their underlying components. This foresight enables the timely acquisition, provisioning, or scaling of infrastructure and applications, ensuring that sufficient capacity is available to meet evolving business needs without costly over-provisioning or detrimental under-provisioning.

Why this answer

Option C (Forecasting future demand for services) is correct because Capacity and Performance Management must anticipate future workload and resource requirements so that services continue to meet agreed performance targets as demand grows. Option E (Monitoring current service performance) is correct because it provides the baseline data on utilization, throughput, and response times needed to compare actual performance against targets and to feed accurate forecasting. Together, these activities form the core iterative cycle of measuring present performance and predicting future capacity needs.

Option A (Defining service level targets) belongs primarily to Service Level Management, which negotiates and agrees SLAs rather than performing capacity analysis. Option B (Managing the IT service desk staffing levels) is a workforce/resource management activity, not a capacity management activity for IT services. Option D (Managing service availability) is the domain of Availability Management, which focuses on uptime and reliability rather than capacity and performance.

Exam trap

ITIL4F often tests the confusion between related practices — candidates mistakenly assign SLA definition to Capacity Management when it actually belongs to Service Level Management, or confuse availability with capacity.

77
Multi-Selecthard

Which TWO statements about the relationship between IT Asset Management and Service Configuration Management are correct?

Select 2 answers
A.Asset management maintains the configuration baseline
B.All assets are considered CIs, and all CIs are assets
C.Configuration management provides information about relationships between assets
D.Configuration management provides the CMDB that includes details of IT assets
E.Asset management focuses on the lifecycle of CIs
AnswersC, D

Configuration management is fundamentally concerned with understanding how different components of an IT service relate to each other to ensure service integrity and operational efficiency. By defining and tracking Configuration Items (CIs) and their interdependencies within the Configuration Management System (CMS), it provides crucial insights into how changes to one asset (represented as a CI) might impact others. This relational information is vital for effective incident, problem, and change management, ensuring service stability and reliability.

Why this answer

Option C is correct because Service Configuration Management maintains the CMDB and its relationship records, so it can show how assets/CIs depend on or connect to one another (e.g., an application running on a server, or a server hosted on a hypervisor). Option D is correct because the CMDB is the configuration management repository that holds CI attributes and can include detailed information about IT assets, linking asset data to configuration data. Option A is not correct because configuration management, not asset management, establishes and maintains the configuration baseline.

Option B is not correct because the relationship is not universally bidirectional: assets are not always managed as CIs, and CIs are not always financial/physical assets. Option E is not correct because asset management focuses on the asset lifecycle (procurement, deployment, maintenance, disposal), while configuration management focuses on CIs and their relationships.

Exam trap

ITIL4F often tests the misconception that all assets are CIs and vice versa; candidates must remember that the two practices have different scopes and that configuration management adds relationship data.

78
MCQmedium

Which ITIL 4 practice is responsible for ensuring that services deliver the agreed level of availability?

A.Service Level Management
B.Capacity and Performance Management
C.IT Asset Management
D.Availability Management
AnswerD

This ITIL practice is specifically responsible for ensuring that services and components are able to perform their agreed function when required, meeting established availability targets. It encompasses designing for resilience, implementing redundancy, proactive monitoring, and establishing recovery mechanisms to maximize service uptime and minimize downtime. Its core purpose is to guarantee the continuous operational capability of services and their underlying components.

Why this answer

Availability Management is the ITIL 4 practice specifically tasked with ensuring that IT services deliver the agreed level of availability to meet business requirements. It involves planning, measuring, and improving the availability of services, components, and supporting infrastructure, directly aligning with the question's focus on delivering agreed availability levels.

Exam trap

The trap here is that candidates often confuse Service Level Management (which defines the availability target in the SLA) with Availability Management (which is the practice that actually ensures that target is met through technical design and operational controls).

How to eliminate wrong answers

Option A is wrong because Service Level Management focuses on defining, negotiating, and monitoring service level agreements (SLAs) and targets, not on the technical assurance of availability itself. Option B is wrong because Capacity and Performance Management deals with ensuring services have sufficient resources to meet performance and demand requirements, not specifically with availability metrics like uptime or downtime. Option C is wrong because IT Asset Management is concerned with tracking and managing the lifecycle of IT assets (hardware, software) for financial and inventory purposes, not with the operational delivery of service availability.

79
MCQmedium

What is the primary focus of Problem Management in ITIL 4?

A.Managing service requests from users
B.Restoring service as quickly as possible
C.Implementing changes to IT infrastructure
D.Finding underlying causes of incidents
AnswerD

Finding underlying causes of incidents is the central purpose of Problem Management. This ITIL practice focuses on identifying the root causes of actual or potential incidents, analyzing trends, and developing permanent solutions to prevent recurrence. By moving beyond temporary fixes, Problem Management aims to eliminate known errors and improve the long-term stability and reliability of IT services, thereby reducing the overall number and impact of future incidents.

Why this answer

Problem Management in ITIL 4 focuses on identifying and analyzing the underlying causes of incidents to prevent recurrence or minimize their impact. Option D is correct because this practice aims to diagnose root causes, not just restore service or handle requests, aligning with the ITIL 4 guiding principle of 'Focus on Value' by reducing future disruptions.

Exam trap

The trap here is that candidates confuse the reactive, fast-restore focus of Incident Management (Option B) with the proactive, root-cause analysis focus of Problem Management, leading them to select the wrong answer when the question explicitly asks for the 'primary focus' of Problem Management.

How to eliminate wrong answers

Option A is wrong because managing service requests is the domain of Service Desk and Request Fulfillment, not Problem Management, which deals with incidents and their root causes. Option B is wrong because restoring service as quickly as possible is the primary goal of Incident Management, which prioritizes speed over root cause analysis. Option C is wrong because implementing changes to IT infrastructure is the responsibility of Change Enablement, not Problem Management, though Problem Management may identify the need for changes.

80
MCQeasy

What is the purpose of the Monitoring and Event Management practice?

A.To restore service after an incident
B.To manage the lifecycle of assets
C.To plan and manage capacity
D.To detect events and classify them to enable appropriate response
AnswerD

This statement accurately defines the primary purpose of the Monitoring and Event Management practice. It involves systematically observing services and service components, recording changes of state identified as events, and then classifying these events. This classification is crucial for determining the appropriate response, whether it's an informational alert, a warning requiring further investigation, or an an indicator of an incident that needs immediate action.

Why this answer

The Monitoring and Event Management practice is specifically designed to observe IT services and infrastructure, detect events (e.g., SNMP traps, syslog messages, performance threshold crossings), and classify them (e.g., informational, warning, exception) so that the appropriate response—such as automated remediation, alerting, or incident creation—can be triggered. This aligns with ITIL 4's definition of the practice as ensuring that events are systematically identified and acted upon to maintain service availability and performance.

Exam trap

The trap here is that candidates confuse Monitoring and Event Management with Incident Management, because both involve reacting to problems, but the former is purely about detection and classification, while the latter handles the actual restoration of service.

How to eliminate wrong answers

Option A is wrong because restoring service after an incident is the purpose of the Incident Management practice, not Monitoring and Event Management, which focuses on detection and classification rather than recovery actions. Option B is wrong because managing the lifecycle of assets (e.g., hardware, software licenses) is the domain of the IT Asset Management practice, which tracks financial and contractual aspects, not real-time event detection. Option C is wrong because planning and managing capacity is the responsibility of the Capacity and Performance Management practice, which deals with forecasting resource demands and ensuring performance meets agreed levels, not the detection and classification of operational events.

81
MCQmedium

An IT team monitors server CPU usage and receives an alert that usage has exceeded 90%. According to ITIL 4, what type of event is this?

A.Warning event
B.Incident
C.Informational event
D.Exception event
AnswerA

A warning event, as defined by ITIL 4, indicates that a predefined threshold has been met or exceeded, signaling a potential degradation of service or an impending incident. In this scenario, high server CPU usage reaching a critical level triggers such an event, prompting IT staff to investigate and take proactive measures. The primary objective of a warning event is to enable intervention before the situation escalates into an actual service disruption, thereby maintaining service quality and availability.

Why this answer

In ITIL 4, a warning event occurs when a threshold is reached that indicates a potential future issue, such as server CPU usage exceeding 90%. This alert signals that the service is still operational but may degrade if the trend continues, prompting proactive monitoring or escalation.

Exam trap

The trap here is that candidates confuse a warning event with an incident, failing to recognize that ITIL 4 distinguishes between a potential issue (warning) and an actual service disruption (incident).

How to eliminate wrong answers

Option B is wrong because an incident is an unplanned interruption or reduction in quality of an IT service, whereas a CPU usage alert above 90% does not yet indicate service degradation or outage. Option C is wrong because an informational event is a routine notification (e.g., normal CPU usage at 50%) that requires no action, not a threshold breach. Option D is wrong because ITIL 4 does not define an 'exception event'; this is a common misnomer that conflates warning events with error conditions.

82
MCQmedium

A service desk analyst handles a password reset request. According to ITIL 4, this should be classified as:

A.A service request
B.An incident
C.A change request
D.A problem
AnswerA

A password reset is a classic example of a service request in ITIL 4. Service requests are standard, pre-defined, and often automated requests for information, advice, or access to a service, or for a standard change. They are typically low-risk, frequently occurring, and have a known resolution path, making them distinct from incidents or changes. Users expect a quick and predictable fulfillment process for such common requests.

Why this answer

A password reset is a standard, pre-approved request for information or access that follows a defined procedure, which aligns with ITIL 4's definition of a service request. It does not involve restoring a failed service (incident), altering a configuration (change), or investigating an underlying cause (problem).

Exam trap

The trap here is that candidates confuse a service request with an incident because both involve user-reported issues, but ITIL 4 strictly defines a service request as a pre-approved, low-risk action (like a password reset) versus an incident as an unplanned service disruption.

How to eliminate wrong answers

Option B is wrong because an incident is an unplanned interruption or reduction in quality of an IT service, not a routine administrative action like a password reset. Option C is wrong because a change request involves adding, modifying, or removing a configuration item (e.g., deploying a new server), which a password reset does not alter any infrastructure. Option D is wrong because a problem is the root cause of one or more incidents, requiring analysis and a permanent fix, whereas a password reset is a one-off operational task.

83
MCQmedium

Which ITIL 4 practice is responsible for managing the complete lifecycle of all IT assets, including financial and contractual aspects?

A.Service Configuration Management
B.IT Asset Management
C.Service Portfolio Management
D.Supplier Management
AnswerB

IT Asset Management covers the full lifecycle of IT assets, including financial, contractual and inventory detail, tracking cost, ownership and compliance. It satisfies the stem's requirement for managing financial and contractual aspects, unlike practices such as Service Configuration Management, which focuses on configuration items and their relationships rather than commercial data.

Why this answer

IT Asset Management (ITAM) is the ITIL 4 practice responsible for managing the complete lifecycle of all IT assets, including financial and contractual aspects. It covers planning, acquisition, deployment, maintenance, and disposal, ensuring cost optimization and compliance with vendor contracts. This aligns directly with the question's emphasis on lifecycle management plus financial and contractual oversight.

Exam trap

The trap here is that candidates confuse Service Configuration Management with IT Asset Management because both involve inventories, but ITAM uniquely handles financial and contractual data, whereas Configuration Management focuses on service relationships and control.

How to eliminate wrong answers

Option A (Service Configuration Management) is wrong because it focuses on managing configuration items (CIs) and their relationships within the service model, not on financial or contractual aspects of assets. Option C (Service Portfolio Management) is wrong because it manages the entire portfolio of services from idea to retirement, not the lifecycle of physical or digital IT assets with financial tracking. Option D (Supplier Management) is wrong because it oversees supplier relationships and performance, not the internal lifecycle and financial management of IT assets themselves.

84
MCQmedium

Which practice is responsible for negotiating, agreeing, and monitoring service level targets?

A.Service Configuration Management
B.Incident Management
C.Service Level Management
D.Availability Management
AnswerC

Service Level Management is the dedicated practice responsible for setting clear, business-based targets for service performance and ensuring that the organization meets those targets. This practice explicitly involves negotiating and agreeing upon service level agreements (SLAs) with customers, which define the expected quality, availability, and other performance metrics of a service. It also continuously monitors, reports on, and reviews service performance against these agreed-upon levels to ensure customer satisfaction.

Why this answer

Service Level Management (SLM) is the ITIL practice specifically tasked with negotiating, agreeing, and monitoring service level targets. It defines, documents, and manages Service Level Agreements (SLAs) and Operational Level Agreements (OLAs) to ensure that the delivered service meets agreed performance metrics. This practice is the single point of accountability for service level achievement and continuous improvement against those targets.

Exam trap

The trap here is that candidates often confuse Availability Management with Service Level Management because both deal with performance metrics, but Availability Management only covers one specific dimension (uptime) while SLM covers the full spectrum of service targets including response times, throughput, and business outcomes.

How to eliminate wrong answers

Option A is wrong because Service Configuration Management is responsible for maintaining the Configuration Management Database (CMDB) and controlling changes to configuration items (CIs), not for negotiating or monitoring service level targets. Option B is wrong because Incident Management focuses on restoring normal service operation as quickly as possible after an incident, minimizing adverse impact on business operations, not on negotiating or monitoring service level targets. Option D is wrong because Availability Management is concerned with ensuring that IT services meet current and future availability requirements of the business, which is a subset of service level targets but does not encompass the full negotiation, agreement, and monitoring of all service level targets.

85
MCQmedium

Which of the following is a key activity of Service Level Management?

A.Resolving incidents within agreed times
B.Installing new software
C.Managing supplier contracts
D.Negotiating and agreeing SLAs
AnswerD

Negotiating and agreeing Service Level Agreements (SLAs) is a fundamental and defining activity of the Service Level Management practice. This involves establishing clear, measurable targets for service performance, availability, capacity, and other critical aspects, ensuring they align with customer expectations and business requirements. By formalizing these agreements, Service Level Management sets the baseline for monitoring, reporting, and continual improvement of service delivery, directly linking IT services to business outcomes.

Why this answer

Service Level Management involves negotiating, agreeing, and monitoring SLAs, as well as reporting on service performance.

86
MCQmedium

A user calls the service desk to report that they cannot access a shared folder. The analyst resolves the issue by resetting the folder permissions. Which practice is being performed?

A.Incident Management
B.Change Enablement
C.Service Request Management
D.Problem Management
AnswerA

Incident Management's primary purpose is to minimize the negative impact of incidents by restoring normal service operation as quickly as possible. An unplanned disruption, such as a user being unable to access a critical service, directly aligns with the ITIL definition of an incident. The immediate action taken by the service desk to resolve this access issue is a core activity within the Incident Management practice, aiming for swift resolution and service restoration.

Why this answer

Incident Management is correct because the user experienced an unplanned interruption to an IT service (inability to access a shared folder), and the service desk's immediate action to restore access by resetting permissions is the core of incident resolution. The focus is on restoring normal service operation as quickly as possible, not on identifying the root cause or managing a planned change. Resetting permissions is a standard incident resolution technique when access is broken unexpectedly.

Exam trap

ITIL4F often tests the distinction between Incident Management and Service Request Management: candidates may incorrectly choose Service Request Management because the user 'requested' access, but the key is that access was previously working and now is not, making it an unplanned incident.

How to eliminate wrong answers

Option B is wrong because Change Enablement (formerly Change Management) governs modifications to IT services through formal change requests, assessment, and authorization; resetting permissions to fix an unplanned outage is an incident resolution action, not a planned change. Option C is wrong because Service Request Management handles predefined, user-initiated requests such as password resets or software installations, not unexpected failures or degradation of service. Option D is wrong because Problem Management focuses on finding the root cause of recurring incidents and implementing permanent fixes; here the analyst only restored access, without investigating why the permissions were incorrect.

87
Multi-Selecthard

Which THREE of the following are key activities of the Service Level Management practice?

Select 3 answers
A.Managing supplier contracts
B.Conducting service reviews with customers
C.Negotiating and agreeing service level targets
D.Monitoring and reporting service performance against SLAs
E.Resolving incidents at first contact
AnswersB, C, D

Conducting service reviews with customers is a fundamental activity of Service Level Management, providing a structured forum to discuss service performance, customer satisfaction, and any changes in business requirements. These regular reviews are crucial for ensuring that the agreed service level agreements (SLAs) remain relevant and continue to align with customer needs and business objectives, fostering a collaborative relationship and identifying opportunities for continual improvement.

Why this answer

Service Level Management (SLM) is the ITIL practice that sets, monitors, and reviews service levels, so option B (conducting service reviews with customers) is correct because SLM regularly reviews achieved performance with customers to confirm services meet their needs and to identify improvement actions. Option C (negotiating and agreeing service level targets) is correct because SLM is responsible for negotiating and agreeing SLAs, SLTs, and OLAs with customers and internal teams, ensuring targets are realistic and aligned to business requirements. Option D (monitoring and reporting service performance against SLAs) is correct because SLM continuously measures and reports service performance against agreed SLAs, producing reports and dashboards that feed into service reviews.

Option A (managing supplier contracts) belongs to Supplier Management, which handles supplier relationships, contracts, and performance, not SLM. Option E (resolving incidents at first contact) is an Incident Management activity focused on restoring service quickly, not on setting or reviewing service levels.

Exam trap

ITIL4F often tests the boundary between practices — candidates pick 'managing supplier contracts' or 'resolving incidents' because they sound service-related, missing that those belong to Supplier Management and Incident Management respectively, not SLM.

88
MCQhard

An IT team is redesigning a process. They decide to review what already works well before making changes. Which ITIL 4 guiding principle are they applying?

A.Focus on value
B.Keep it simple
C.Start where you are
D.Progress iteratively
AnswerC

The "Start where you are" guiding principle explicitly advises against discarding existing resources and starting from scratch without first considering what is already available. When an IT team is redesigning a process, reviewing the current state is a direct application of this principle, as it involves understanding the baseline, identifying what works well, and recognizing what needs improvement, thereby leveraging existing foundations rather than reinventing solutions.

Why this answer

The guiding principle 'Start where you are' means using existing capabilities and services as a basis for improvement. Option C is correct. Option A (Focus on value) is about delivering value.

Option B (Keep it simple) is about simplicity. Option D (Progress iteratively) is about incremental improvements.

89
Multi-Selectmedium

Which TWO of the following are key metrics used by a service desk?

Select 2 answers
A.Mean Time Between Failures (MTBF)
B.Return on Investment (ROI)
C.Customer Satisfaction (CSAT)
D.Capacity Utilization
E.First Contact Resolution (FCR)
AnswersC, E

Customer Satisfaction (CSAT) is a pivotal metric for any service, directly measuring how satisfied customers are with a service or specific interaction, such as with the service desk. It typically involves direct feedback from users, often through surveys, providing invaluable insight into their perception of service quality, responsiveness, and overall value. High CSAT scores indicate that the service is meeting or exceeding customer expectations, making it a fundamental indicator of service success and customer-centricity.

Why this answer

Customer Satisfaction (CSAT) is a key metric for a service desk because it directly measures the user's perception of the quality and effectiveness of the support they received. ITIL 4 defines CSAT as a critical indicator of service value and customer experience, often collected via post-interaction surveys. First Contact Resolution (FCR) is equally vital as it tracks the percentage of incidents resolved during the first interaction, reducing downtime and operational costs.

Exam trap

The trap here is that candidates confuse infrastructure reliability metrics (MTBF) or financial metrics (ROI) with service desk performance indicators, but ITIL 4 explicitly defines CSAT and FCR as key service desk metrics in the Service Desk practice.

90
MCQeasy

What is the purpose of the Service Desk practice?

A.To monitor and control IT events
B.To manage the lifecycle of all IT assets
C.To negotiate service level agreements
D.To provide a single point of contact for users
AnswerD

The fundamental purpose of the Service Desk practice is to establish and maintain a single point of contact (SPOC) between the service provider and its users. This crucial role ensures that users have a consistent, accessible, and reliable channel for all IT-related inquiries, incident reporting, service requests, and information needs, thereby streamlining communication and enhancing user experience and satisfaction.

Why this answer

The Service Desk practice provides a single point of contact (SPOC) for users to report incidents, submit service requests, and receive updates. This ensures that all user interactions are logged, tracked, and managed consistently, aligning with the ITIL 4 guiding principle of 'Focus on Value' by reducing user confusion and improving resolution times.

Exam trap

The trap here is that candidates often confuse the Service Desk with other operational practices like Event Management or Asset Management, because all involve handling IT-related data, but the Service Desk is uniquely focused on being the user-facing single point of contact.

How to eliminate wrong answers

Option A is wrong because monitoring and controlling IT events is the purpose of the Event Management practice, not the Service Desk. Option B is wrong because managing the lifecycle of all IT assets is the purpose of the IT Asset Management practice, which focuses on tracking hardware, software, and licenses from acquisition to disposal. Option C is wrong because negotiating service level agreements is the purpose of the Service Level Management practice, which defines and reviews SLAs, not the Service Desk.

91
MCQhard

An organization implements a new monitoring tool that automatically detects and classifies events. A high-priority event triggers an alert. According to ITIL 4, what type of event is this?

A.Exception event
B.Informational event
C.Warning event
D.Normal event
AnswerA

An exception event signifies an abnormal situation where a service or component is operating outside its established baseline or expected parameters, often indicating a failure or a critical degradation. These events trigger immediate investigation and resolution efforts to prevent service disruption or restore normal operations, aligning with the core purpose of event management to detect and respond to deviations.

Why this answer

In ITIL 4, an exception event indicates that something has occurred that deviates from normal operation, often requiring immediate attention. A high-priority alert triggered by a monitoring tool automatically detecting and classifying events fits this definition, as it signals a significant anomaly that may impact services.

Exam trap

The trap here is that candidates confuse 'warning' with 'exception' because both involve alerts, but ITIL 4 distinguishes them by the required response—warnings are proactive notifications of potential issues, while exceptions are reactive alerts of actual failures requiring immediate action.

How to eliminate wrong answers

Option B is wrong because an informational event is a routine notification (e.g., a log entry confirming a scheduled task completed) that does not require action, not a high-priority alert. Option C is wrong because a warning event signals a potential future issue (e.g., disk usage exceeding 80%) but does not yet require immediate escalation, unlike a high-priority alert. Option D is wrong because a normal event is a standard operational occurrence (e.g., a user logging in) that is expected and does not trigger alerts.

92
Multi-Selectmedium

Which TWO statements about Problem Management are correct?

Select 2 answers
A.It includes root cause analysis to identify the underlying cause of incidents
B.It is responsible for implementing permanent fixes for recurring incidents
C.It focuses on recording and tracking individual incidents
D.It is responsible for restoring normal service operation
E.It is responsible for maintaining the known error database
AnswersA, E

Problem management fundamentally includes root cause analysis (RCA) as a core activity to systematically investigate and identify the underlying causes of incidents. This analytical process goes beyond merely restoring service, aiming to understand why incidents occur. By uncovering the true source of issues, problem management enables the development of effective solutions that prevent future recurrences, thereby improving service stability and reliability.

Why this answer

Option A is correct because Problem Management's core purpose is to perform root cause analysis (RCA) to determine the underlying cause of one or more incidents, preventing recurrence rather than just resolving symptoms. Option E is correct because Problem Management owns and maintains the Known Error Database (KEDB), which stores details of problems and their root causes along with documented workarounds, typically populated once a problem is diagnosed. Option B is not correct as stated because implementing permanent fixes is a change/implementation activity (Change Management/technical teams) that Problem Management triggers via an RFC, not something it directly performs.

Option C is incorrect because recording and tracking individual incidents is the responsibility of Incident Management, not Problem Management. Option D is incorrect because restoring normal service operation as quickly as possible is the primary objective of Incident Management.

Exam trap

ITIL4F often tests the distinction between Incident and Problem Management, and candidates frequently select 'restoring normal service operation' or 'recording incidents' as Problem Management responsibilities when those belong to Incident Management.

93
Multi-Selectmedium

Which TWO of the following are phases of the Continual Improvement Model in ITIL 4?

Select 2 answers
A.Escalate to management
B.Take action
C.Where are we now?
D.Perform root cause analysis
E.Define the problem statement
AnswersB, C

The 'Take action' phase is the fifth step in the ITIL 4 Continual Improvement Model, directly following the 'How do we get there?' phase. In this critical stage, the planned improvements and solutions are implemented, executed, and put into operation. This involves making the necessary changes to services, products, or practices, ensuring the designed improvements are actively deployed and integrated.

Why this answer

In ITIL 4, the Continual Improvement Model consists of seven steps, and option B ("Take action") is one of them — it is the step where the improvement plan is executed, making it a correct phase. Option C ("Where are we now?") is also a correct phase; it is the first step of the model, used to establish the current baseline before deciding where the organization wants to be. The remaining options are not phases of the ITIL 4 Continual Improvement Model: "Escalate to management" (A) is an incident management activity, "Perform root cause analysis" (D) belongs to problem management, and "Define the problem statement" (E) is a general problem-solving technique rather than a named step in the model.

Exam trap

The trap here is that candidates confuse common problem-solving steps (like root cause analysis or escalation) with the specific, named phases of the ITIL 4 Continual Improvement Model, leading them to select options that are not part of the official model.

94
Multi-Selecthard

Which THREE of the following are characteristics of a service request?

Select 3 answers
A.Unplanned
B.Low risk
C.Pre-approved
D.Require approval from the Change Advisory Board
E.Predefined and standardized
AnswersB, C, E

Service requests are characterized by their low inherent risk because they involve well-established, routine procedures with predictable outcomes. The potential for negative impact on IT services, users, or the business is minimal, as these requests typically concern standard offerings and have been thoroughly vetted. This low-risk profile allows for streamlined processing and often automated fulfillment without extensive scrutiny.

Why this answer

Option B (Low risk) is correct because service requests are routine, well-understood interactions that carry minimal risk to the environment, unlike changes that may disrupt services. Option C (Pre-approved) is correct because service requests are typically pre-authorized within the service catalog, allowing fulfillment teams to act without seeking separate change approval. Option E (Predefined and standardized) is correct because service requests follow documented, repeatable procedures and are offered as standardized catalog items, ensuring consistent delivery.

Option A (Unplanned) does not belong because service requests are planned, expected interactions initiated by users through normal channels, not unplanned events. Option D (Require approval from the Change Advisory Board) does not belong because CAB approval is associated with normal changes, whereas service requests are pre-approved and do not require CAB review.

Exam trap

ITIL4F often tests the confusion between service requests and changes; candidates may incorrectly think service requests require CAB approval or are unplanned.

95
MCQeasy

What is the PRIMARY purpose of the Service Desk practice in ITIL 4?

A.To manage the lifecycle of all IT assets
B.To capture and manage all service requests and incidents
C.To analyze root causes of recurring incidents
D.To monitor the performance of IT services
AnswerB

The Service Desk serves as the crucial Single Point of Contact (SPOC) between the service provider and its users, primarily responsible for handling all user interactions. Its core purpose is to capture, log, categorize, prioritize, and manage both incidents (unplanned interruptions to a service) and service requests (a formal request from a user for something standard). This ensures prompt restoration of normal service operation and efficient fulfillment of user needs.

Why this answer

The Service Desk practice in ITIL 4 serves as the single point of contact between the service provider and users. Its primary purpose is to capture, manage, and progress all service requests and incidents, ensuring they are logged, categorized, prioritized, and routed to the appropriate resolution teams. This aligns with the ITIL 4 definition that the Service Desk is the entry point for all user interactions, not a specialized technical function.

Exam trap

The trap here is that candidates confuse the Service Desk's role as a communication hub with the specialized practices of Problem Management (root cause analysis) or Monitoring and Event Management (performance tracking), leading them to select options that describe those separate ITIL practices.

How to eliminate wrong answers

Option A is wrong because managing the lifecycle of all IT assets is the primary purpose of the IT Asset Management (ITAM) practice, not the Service Desk. Option C is wrong because analyzing root causes of recurring incidents is the responsibility of the Problem Management practice, which uses techniques like 5 Whys or Kepner-Tregoe analysis. Option D is wrong because monitoring the performance of IT services is the core function of the Monitoring and Event Management practice, which uses tools like SNMP traps or synthetic transactions to track service health.

96
MCQmedium

An organization monitors IT systems and detects an event indicating that a disk is 80% full. According to ITIL 4, what type of event is this?

A.Informational event
B.Warning event
C.Exception event
D.Error event
AnswerB

A warning event indicates a condition that is deviating from normal operational parameters but has not yet caused a service disruption or degradation. It serves as an early alert, signaling a potential future problem if left unaddressed, such as a disk approaching full capacity or high CPU utilization. Proactive intervention based on a warning event can prevent an actual incident, making it a critical classification for effective event management. The detection of an event that requires attention but isn't yet an incident aligns perfectly with a warning.

Why this answer

In ITIL 4, a warning event is an event that indicates a threshold has been reached or a condition that could lead to an incident if not addressed. A disk being 80% full is a typical example of a warning event because it signals a potential issue that requires attention but is not yet a failure. It is not an error or exception because the system is still operational.

Exam trap

ITIL4F often tests the distinction between warning and exception events, causing candidates to misclassify threshold-based alerts as exceptions when they are actually warnings.

How to eliminate wrong answers

Option A is wrong because an informational event is a normal operational event that does not require action, such as a user logging in or a backup completing successfully; an 80% full disk is not merely informational as it may require proactive action. Option C is wrong because an exception event indicates that a service or component is operating outside normal parameters, often resulting in a breach of service level or a failure; an 80% full disk is a threshold warning, not an exception. Option D is wrong because an error event indicates a failure or fault that has occurred, such as a disk full error or a service crash; at 80% full, no error has occurred yet.

97
MCQmedium

During a major incident, a workaround is applied by the service desk. Later, Problem Management identifies the root cause and implements a permanent fix through a normal change. Which sequence of practices is being followed?

A.Service Request Management → Incident Management → Change Enablement
B.Problem Management → Incident Management → Change Enablement
C.Change Enablement → Incident Management → Problem Management
D.Incident Management → Problem Management → Change Enablement
AnswerD

This sequence accurately reflects the ITIL 4 approach to managing service disruptions and their underlying causes. Incident Management prioritizes restoring service functionality, often via a workaround, during a major incident. Subsequently, Problem Management investigates the root cause to prevent recurrence. Finally, if a permanent solution requires a modification to a service or component, Change Enablement ensures that this change is planned, approved, and implemented in a controlled manner.

Why this answer

Incident Management restores service, Problem Management finds root cause, and Change Enablement implements the permanent fix.

98
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. What should the analyst do FIRST?

A.Search the known error database for a workaround
B.Inform the user that a problem has been raised
C.Escalate the call to Level 2 support
D.Log the incident in the ITSM tool
AnswerD

Logging the incident in the ITSM tool is the foundational first step in the incident management process. This action creates a formal record of the service interruption, enabling tracking, prioritization, and communication throughout its lifecycle until resolution. Proper logging ensures accountability, facilitates adherence to service level agreements, and provides valuable data for future analysis and problem identification.

Why this answer

The first action for any incident, including a CRM system outage, is to log the incident in the ITSM tool. This ensures a formal record is created with details such as user impact, timestamp, and symptoms, which is the foundation for all subsequent incident management activities per ITIL 4. Without logging, there is no auditable trail or basis for prioritization, escalation, or problem management.

Exam trap

The trap here is that candidates often confuse the urgency of restoring service with the procedural necessity of logging, leading them to jump to escalation or workaround steps before creating the formal record.

How to eliminate wrong answers

Option A is wrong because searching the known error database for a workaround is a secondary step that occurs after the incident is logged and categorized, not the first action. Option B is wrong because informing the user that a problem has been raised is premature and incorrect; a problem is only raised after multiple related incidents are analyzed, and the analyst should first log the incident and provide initial communication. Option C is wrong because escalating to Level 2 support should only happen after the incident is logged, assessed, and determined to be beyond the analyst's capability to resolve; skipping logging violates the incident management process.

99
MCQeasy

Which ITIL 4 practice has the PRIMARY purpose of restoring normal service operation as quickly as possible and minimizing the adverse impact on business operations?

A.Problem Management
B.Service Request Management
C.Incident Management
D.Change Enablement
AnswerC

Incident Management is the correct practice because its primary purpose is to minimize the negative impact of incidents by restoring normal service operation as quickly as possible. An incident is defined as an unplanned interruption to a service or a reduction in the quality of a service. This practice focuses on rapid diagnosis, workaround implementation, and resolution to ensure business continuity and user productivity are maintained.

Why this answer

Incident Management's primary purpose in ITIL 4 is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations, making it the correct answer. It focuses on the 'here and now' — diagnosing and resolving the immediate disruption rather than investigating underlying causes. This urgency-driven practice is distinct from Problem Management, which seeks root causes.

Exam trap

ITIL4F often tests the boundary between Incident and Problem Management, and candidates frequently select Problem Management because they conflate 'fixing the issue permanently' with 'restoring service quickly.'

How to eliminate wrong answers

Option A is wrong because Problem Management focuses on identifying the root cause of incidents and managing workarounds and known errors, not on rapid restoration of service. Option B is wrong because Service Request Management handles routine user requests (e.g., password resets, software installs) rather than unplanned disruptions. Option D is wrong because Change Enablement authorizes and schedules changes to IT services, ensuring risk is assessed — it does not restore service during an outage.

100
MCQhard

A user requests new software that is already pre-approved in the service catalogue. The service desk team handles this request following a defined, automated workflow. According to ITIL 4, what type of record should be created?

A.Problem record
B.Normal change record
C.Service request record
D.Incident record
AnswerC

A service request record is the appropriate choice for a user requesting new software that is already pre-approved, as it represents a formal request for a standard, pre-defined service offering. These requests typically follow established, automated workflows and do not require additional assessment or authorization beyond the initial submission. ITIL 4 emphasizes that service requests are low-risk, frequently occurring events, making this the ideal mechanism for fulfilling such a pre-approved software provision.

Why this answer

A service request record should be created for a user request for pre-approved software that follows a defined workflow. In ITIL 4, service requests are a normal part of service delivery, handled through the service request management practice, and are distinct from incidents and changes. Since the software is pre-approved and the workflow is automated, it qualifies as a service request.

Exam trap

ITIL4F often tests the confusion between service requests and incidents or changes, where candidates may incorrectly choose incident or change record for a routine request, especially when the request is pre-approved.

How to eliminate wrong answers

Option A is wrong because a problem record is created to investigate the root cause of one or more incidents, not for a routine service request. Option B is wrong because a normal change record is required for changes that need assessment and authorization; pre-approved software in the service catalogue does not require a change record. Option D is wrong because an incident record is for unplanned interruptions or degradations of service, not for requesting new software.

101
MCQmedium

Which of the following describes a key difference between Incident Management and Problem Management in ITIL 4?

A.Incident Management aims to restore normal service as soon as possible; Problem Management aims to prevent incidents from happening or recurring
B.Incident Management is reactive; Problem Management is always proactive
C.Incident Management is only for major incidents; Problem Management is for minor issues
D.Incident Management always resolves the root cause; Problem Management only applies workarounds
AnswerA

Incident Management's primary objective is the swift restoration of normal service operation, minimizing business impact and returning users to productivity as quickly as possible. In contrast, Problem Management focuses on identifying and understanding the underlying causes of incidents, aiming to prevent their recurrence or to mitigate their impact if they cannot be entirely avoided. This clear distinction highlights their different but complementary roles in maintaining service stability and quality.

Why this answer

Incident Management focuses on restoring normal service operation as quickly as possible to minimize business impact, while Problem Management seeks to identify and eliminate the underlying root causes of incidents to prevent recurrence or reduce their impact. This distinction is fundamental in ITIL 4: Incident Management is about speed of recovery, Problem Management about long-term stability.

Exam trap

The trap here is confusing the reactive nature of Incident Management with the misconception that Problem Management is always proactive, when in fact Problem Management includes both reactive and proactive activities.

How to eliminate wrong answers

Option B is wrong because Problem Management can be both proactive (identifying potential causes before incidents occur) and reactive (analyzing incidents that have already happened), so it is not 'always proactive'. Option C is wrong because Incident Management handles all incidents, not just major ones, and Problem Management addresses both major and minor underlying issues. Option D is wrong because Incident Management does not resolve root causes—it restores service via workarounds or fixes—while Problem Management may apply workarounds as a temporary measure while seeking a permanent root cause resolution.

102
MCQeasy

What is the primary role of a service desk?

A.To negotiate SLAs with customers
B.To act as a single point of contact (SPOC) for users
C.To manage the lifecycle of all IT assets
D.To perform root cause analysis
AnswerB

The primary role of the Service Desk is to function as the single point of contact (SPOC) between the service provider and its users. This ensures that users have one consistent and recognizable channel for all service-related interactions, including requesting services, reporting incidents, and seeking information. By centralizing communication, the Service Desk streamlines support, improves user experience, and facilitates efficient incident resolution and service request fulfillment.

Why this answer

The primary role of a service desk is to act as a single point of contact (SPOC) for users, ensuring all incidents, service requests, and inquiries are logged, tracked, and resolved or escalated efficiently. This aligns with ITIL 4's guiding principle of 'focus on value' by providing a clear, accessible entry point for users to interact with IT services.

Exam trap

The trap here is that candidates often confuse the service desk's operational SPOC role with other ITIL practices like service level management (SLA negotiation), IT asset management (lifecycle tracking), or problem management (root cause analysis), leading them to select a plausible but incorrect option.

How to eliminate wrong answers

Option A is wrong because negotiating SLAs is a strategic activity performed by service level management, not the service desk, which focuses on operational incident and request handling. Option C is wrong because managing the lifecycle of IT assets is the responsibility of IT asset management (ITAM), which tracks hardware and software from acquisition to disposal, not the service desk's daily support role. Option D is wrong because root cause analysis is a key activity of problem management, which investigates underlying causes of incidents after they occur, whereas the service desk handles initial incident logging and resolution.

103
Drag & Dropmedium

Drag and drop the steps of the availability management process into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Availability management begins with defining requirements, then designing, monitoring, analyzing, and improving.

104
MCQmedium

A service desk analyst receives a call from a user requesting a new laptop because their current one is slow. According to ITIL 4, how should this request be classified?

A.Incident, because the user is experiencing a slow laptop
B.Change request, because a new laptop requires changes to the asset register
C.Service request, because the user is asking for a new device, which is a standard request
D.Problem, because the slow performance may be a recurring issue
AnswerC

A service request is a formal request from a user for something standard that is part of normal service delivery, such as a request for information, advice, a standard change, or access to a service. Requesting a new device, especially when it aligns with predefined organizational policies for hardware provision (e.g., for new hires or scheduled refreshes), perfectly fits this definition. These requests are typically low-risk, frequently occurring, and often have established, sometimes automated, fulfillment procedures.

Why this answer

According to ITIL 4, a service request is a formal request from a user for something to be provided – for example, a new laptop. This is a standard, pre-approved change that follows a defined procedure, not an unplanned interruption or a failure. The user is not reporting an incident (the laptop is slow but still operational) or a problem; they are asking for a new asset as part of normal service delivery.

Exam trap

The trap here is that candidates confuse a user's request for a new device with an incident or problem because the current device is slow, but ITIL 4 clearly separates service requests (standard, pre-approved asks) from incidents (service interruptions) and problems (root cause analysis).

How to eliminate wrong answers

Option A is wrong because an incident is an unplanned interruption or reduction in quality of an IT service; a slow laptop that is still usable is not necessarily a service interruption, and the user is explicitly requesting a new device, not reporting a failure. Option B is wrong because a change request is for a modification to a service or configuration item that is not pre-approved; a new laptop from a standard catalog is a pre-approved service request, not a change requiring formal change management. Option D is wrong because a problem is the root cause of one or more incidents; the user's request is for a new device, not an investigation into why the laptop is slow, and there is no evidence of a recurring underlying cause.

105
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. According to ITIL 4, what should the analyst do FIRST?

A.Log the incident and categorize it
B.Reboot the server immediately
C.Inform the change manager about a potential emergency change
D.Start a problem investigation to find the root cause
AnswerA

Logging the incident is the foundational first step in the Incident Management practice, ensuring that all service disruptions are formally recorded and tracked. Categorization, which includes assigning impact and urgency, allows for proper prioritization and routing to the appropriate support teams. This systematic approach is crucial for effective incident resolution, service restoration, and subsequent analysis of service performance.

Why this answer

According to ITIL 4, the first action for a service desk analyst when receiving a user-reported outage is to log the incident and categorize it. This ensures the incident is formally recorded, prioritized, and routed to the appropriate support team for resolution. Skipping this step would violate the incident management process, which mandates logging as the initial activity to maintain an accurate audit trail and enable proper escalation.

Exam trap

The trap here is that candidates may confuse incident management with problem management or change management, and incorrectly assume that immediate technical action (like rebooting) or root cause analysis is the first priority, rather than following the prescribed process of logging and categorization.

How to eliminate wrong answers

Option B is wrong because rebooting the server immediately bypasses the required logging and categorization step, and could disrupt other services or mask the root cause without proper authorization. Option C is wrong because informing the change manager about a potential emergency change is premature; the incident must first be logged and assessed to determine if a change is actually needed. Option D is wrong because starting a problem investigation to find the root cause is a problem management activity that occurs after the incident is resolved, not the first step in incident management.

106
MCQhard

During a major incident, the IT team implements a workaround to restore service. Later, they discover the root cause and submit a permanent fix as an emergency change. Which ITIL 4 practices are primarily involved in this sequence?

A.Incident Management, Problem Management, and Change Enablement
B.Incident Management and Problem Management only
C.Problem Management and Change Enablement only
D.Incident Management and Change Enablement only
AnswerA

Incident Management is crucial for detecting and managing the major incident, focusing on restoring service as quickly as possible. Problem Management then identifies the underlying cause and develops a workaround to mitigate the incident's impact. Finally, if implementing this workaround requires any modification to the live environment, even temporarily, Change Enablement ensures the change is properly assessed, authorized, and managed to minimize risk and prevent further disruption.

Why this answer

The sequence involves Incident Management (restoring service via workaround), Problem Management (finding root cause and submitting permanent fix), and Change Enablement (emergency change to implement the fix). All three practices are involved.

Exam trap

The trap is forgetting that Change Enablement is involved even for emergency changes, or assuming that Problem Management alone handles the fix without formal change control.

How to eliminate wrong answers

Option B is wrong because it omits Change Enablement, which is necessary for the emergency change. Option C is wrong because it omits Incident Management, which handled the initial workaround. Option D is wrong because it omits Problem Management, which identified the root cause and proposed the fix.

107
MCQmedium

An organization wants to improve its first call resolution rate. Which practice is most directly responsible for this metric?

A.Incident Management
B.Problem Management
C.Change Enablement
D.Service Desk
AnswerD

The Service Desk serves as the single point of contact between the service provider and its users, handling incidents, service requests, and providing information. A primary objective of the Service Desk is to resolve as many incidents and service requests as possible during the user's initial contact, directly contributing to enhanced user satisfaction and operational efficiency. First Call Resolution (FCR) is a critical and fundamental metric for evaluating the effectiveness and efficiency of Service Desk operations, as it directly quantifies their ability to resolve issues without escalation.

Why this answer

The Service Desk is the single point of contact between the service provider and users, and it is directly responsible for handling user incidents and service requests on first contact. First call resolution (FCR) measures the percentage of incidents resolved during the initial interaction without escalation or callback, which is a core Service Desk responsibility. While Incident Management oversees the overall incident lifecycle, the Service Desk practice is the one that actually resolves incidents at the first point of contact, making it the most directly accountable for FCR.

Exam trap

ITIL4F often tests the distinction between the Service Desk practice and Incident Management, as candidates may confuse the broader incident lifecycle with the specific first-contact resolution responsibility.

How to eliminate wrong answers

Option A is wrong because Incident Management is a broader practice that focuses on managing the lifecycle of all incidents to restore normal service operation, but it does not directly own the first-contact resolution metric—that is delegated to the Service Desk. Option B is wrong because Problem Management aims to identify root causes of recurring incidents and prevent future occurrences, which affects resolution times and volume but not the immediate first-call resolution rate. Option C is wrong because Change Enablement governs changes to services, ensuring risks are assessed and authorized; it has no direct role in resolving user incidents on first contact.

108
MCQhard

Which of the following BEST distinguishes an incident from a problem in ITIL 4?

A.Incidents are unplanned service disruptions, while problems are the root causes of incidents
B.Incidents are always reported by users, while problems are identified by technical staff
C.Incidents have a defined resolution time in the SLA, while problems do not
D.Incidents are managed by the service desk, while problems are managed by problem management
AnswerA

This option correctly distinguishes incidents from problems based on their fundamental nature. An incident represents an unplanned interruption to a service or a reduction in its quality, directly impacting users. Conversely, a problem is defined as the cause, or potential cause, of one or more incidents, focusing on the underlying issue rather than the immediate disruption.

Why this answer

In ITIL 4, an incident is defined as an unplanned interruption or reduction in quality of an IT service, while a problem is the underlying cause of one or more incidents. Option A correctly captures this distinction: incidents are the visible disruptions, and problems are the root causes that need to be identified and resolved to prevent recurrence.

Exam trap

The trap here is that candidates confuse the roles or reporting sources (options B and D) or SLA applicability (option C) with the fundamental definitional difference, which is that an incident is the symptom and a problem is the cause.

How to eliminate wrong answers

Option B is wrong because incidents can be identified by technical staff through monitoring tools (e.g., SNMP traps, synthetic transactions) and are not exclusively reported by users; problems can also be reported by users or identified proactively. Option C is wrong because both incidents and problems can have defined resolution times in SLAs (e.g., a problem may have a target for root cause analysis completion), and the presence or absence of an SLA target does not distinguish the two concepts. Option D is wrong because while the service desk typically handles incident logging and initial support, problem management is a separate process that may involve the service desk in coordination, but the distinction is not about who manages them—it is about the nature of the work (restoring service vs. finding root cause).

109
MCQeasy

Which practice involves the use of a service catalogue for predefined offerings?

A.Service Request Management
B.Change Enablement
C.Problem Management
D.Incident Management
AnswerA

Service Request Management is the practice of supporting the agreed quality of a service by handling all pre-defined, user-initiated requests. These requests are typically standardized, often automated, and are prominently featured in a service catalogue, which acts as the primary interface for users to browse and order available services and their associated requests. The catalogue provides clear descriptions, fulfillment times, and costs, making it integral to the efficient processing of service requests.

Why this answer

Service Request Management is the practice that involves the use of a service catalogue for predefined offerings. The service catalogue lists available services and service requests, enabling users to request standard services efficiently. This practice ensures that requests are handled consistently and in a user-friendly manner.

Exam trap

The trap is confusing Service Request Management with Incident Management or Change Enablement, as all involve handling user interactions but serve different purposes.

How to eliminate wrong answers

Option B is wrong because Change Enablement focuses on managing changes to IT services, not on service requests. Option C is wrong because Problem Management aims to identify and manage the root causes of incidents, not to fulfill service requests. Option D is wrong because Incident Management focuses on restoring normal service operation as quickly as possible, not on predefined service offerings.

110
MCQeasy

Which of the following is a key metric for measuring the performance of the Service Desk?

A.Number of changes implemented
B.First Call Resolution (FCR)
C.Mean Time to Restore Service (MTTR)
D.Percentage of projects on time
AnswerB

First Call Resolution (FCR) is a critical Service Desk metric that quantifies the percentage of incidents or service requests resolved completely during the initial contact with the user, without requiring further escalation or follow-up. A high FCR rate directly indicates the Service Desk's efficiency and the competence of its agents, significantly enhancing customer satisfaction by minimizing disruption and reducing the need for multiple interactions. It is a primary indicator of the Service Desk's ability to provide immediate value and effective front-line support.

Why this answer

First Call Resolution (FCR) is a key metric for the Service Desk because it directly measures the percentage of incidents resolved during the first contact with the user, without the need for escalation or a callback. A high FCR indicates an efficient and knowledgeable Service Desk, reducing user downtime and operational costs. This metric is central to ITIL's focus on delivering value and minimizing disruption to business activities.

Exam trap

The trap here is that candidates often confuse FCR with MTTR, assuming both measure speed of resolution, but MTTR applies to the entire incident lifecycle and technical restoration, while FCR specifically measures the Service Desk's ability to resolve at first touch without escalation.

How to eliminate wrong answers

Option A is wrong because the number of changes implemented is a metric for Change Enablement, not the Service Desk, which focuses on incident and request management. Option C is wrong because Mean Time to Restore Service (MTTR) is a metric for Incident Management and technical resolution teams, measuring the time to fix a service after a failure, not the Service Desk's first-contact performance. Option D is wrong because the percentage of projects on time is a metric for Project Management or Portfolio Management, not the operational, reactive nature of the Service Desk.

111
MCQeasy

What is the PRIMARY purpose of the Service Desk practice?

A.To manage the lifecycle of all incidents
B.To monitor and manage IT services proactively
C.To analyze root causes of incidents
D.To provide a single point of contact for users
AnswerD

The primary purpose of the Service Desk practice is to establish and maintain a single point of contact (SPOC) between the service provider and its users. This ensures that users have one consistent, identifiable channel for all service-related interactions, including logging incidents, requesting services, making inquiries, and receiving communication. This centralized approach streamlines user experience and facilitates efficient communication flow within the service organization.

Why this answer

The Service Desk provides a single point of contact for users to report issues, ask questions, and request services.

112
MCQhard

Refer to the exhibit. A change order to patch a security vulnerability on WebServer01 has been approved. The IT manager is the change authority. During implementation, it is discovered that the patch requires a reboot, which will cause an outage for the OrderApp application. What is the MOST appropriate action?

A.Inform the IT manager and ask for a decision on whether to proceed.
B.Escalate to the change advisory board (CAB) for a new approval.
C.Proceed with the change as planned, since the change is already approved.
D.Cancel the change and request a new one with updated information.
AnswerA

When new information, such as an unexpected mandatory reboot causing an outage, emerges after a change has been approved but before its implementation, the designated change authority must be informed. The IT manager, acting as the change authority, is empowered to re-evaluate the change's risk, impact, and schedule based on this updated information. This ensures that decisions are made with the most current data, aligning with ITIL's principle of 'Progress Iteratively with Feedback' and maintaining service stability.

Why this answer

The change order was approved based on the original scope, which did not include a reboot. The discovery that a reboot is required introduces a new risk (application outage) that was not assessed during the initial approval. The IT manager, as the change authority, must be informed and make a decision on whether to proceed with the change under the new circumstances, in line with the ITIL 4 'change enablement' practice of managing risk and ensuring authorized decisions.

Exam trap

The trap here is that candidates assume a change approval is final and irrevocable, but ITIL 4 requires that any new risk discovered during implementation must be communicated to the change authority for a fresh decision, not blindly executed or automatically escalated to a CAB.

How to eliminate wrong answers

Option B is wrong because the change advisory board (CAB) is typically used for higher-risk or standard changes, not for an operational decision on an already-approved change where the change authority (IT manager) is already identified and available. Option C is wrong because proceeding without informing the change authority of the newly discovered outage risk violates the principle of risk-based decision-making and could lead to unauthorized service disruption. Option D is wrong because canceling the change outright is premature; the change authority should first be consulted to decide if the change can proceed with the new risk or if it should be re-planned.

113
Multi-Selecthard

Which THREE of the following are key activities of Service Configuration Management?

Select 3 answers
A.Identifying and documenting configuration items (CIs)
B.Authorizing and scheduling changes to CIs
C.Maintaining the configuration management database (CMDB)
D.Verifying and auditing configuration records against actual state
E.Defining service level targets with customers
AnswersA, C, D

Identifying and documenting CIs is a core activity of Service Configuration Management.

Why this answer

Identifying and documenting configuration items (CIs) is a foundational activity of Service Configuration Management. It ensures that all components of the IT infrastructure, including hardware, software, and documentation, are uniquely identified and recorded in the configuration management database (CMDB) to support control and traceability.

Exam trap

The trap here is confusing the activities of Service Configuration Management with those of Change Management or Service Level Management, as ITIL 4F often tests the precise boundaries between practices by listing overlapping but distinct responsibilities.

114
MCQeasy

Which practice involves the Single Point of Contact (SPOC) for users?

A.Problem Management
B.Service Desk
C.Incident Management
D.Service Level Management
AnswerB

The Service Desk is explicitly defined in ITIL 4 as the single point of contact (SPOC) between the service provider and its users. Its primary function is to handle all user interactions, including logging incidents, fulfilling service requests, and providing information. By centralizing communication, the Service Desk ensures a consistent and efficient channel for users to engage with IT services, facilitating value co-creation.

Why this answer

The Service Desk practice is explicitly defined in ITIL 4 as the single point of contact (SPOC) between the service provider and all users. Its primary purpose is to capture, manage, and resolve service requests and incidents, ensuring users have a consistent entry point for all interactions with IT services.

Exam trap

PeopleCert often tests the distinction between a practice (Incident Management) and the function that implements the SPOC (Service Desk), causing candidates to confuse the process with the operational point of contact.

How to eliminate wrong answers

Option A is wrong because Problem Management focuses on identifying the root cause of incidents and preventing recurrence, not on providing a single point of contact for users. Option C is wrong because Incident Management is the process of restoring normal service operation after an incident, but it does not itself act as the SPOC; the Service Desk is the function that handles the initial contact and triage. Option D is wrong because Service Level Management is responsible for negotiating, agreeing, and monitoring service level agreements (SLAs), not for providing a direct user-facing contact point.

115
MCQhard

An IT manager wants to improve first-level resolution rates by empowering the service desk to resolve more incidents without escalation. Which ITIL 4 concept is being applied?

A.Continual Improvement
B.Shift-left
C.Service Desk
D.Omnichannel
AnswerB

Shift-left is a strategic approach aimed at moving incident resolution and service request fulfillment to the earliest possible point of contact, typically the Service Desk or self-service channels. By empowering first-level support with more knowledge, tools, and authority, or by enabling users with self-service, it directly increases the percentage of issues resolved at the initial interaction. This strategy is precisely designed to improve first-level resolution rates by reducing escalations to higher support tiers.

Why this answer

The scenario describes moving incident resolution tasks from higher-level support tiers to the service desk, which is the essence of 'shift-left' in ITIL 4. By empowering the service desk with better tools, knowledge, and authority, incidents are resolved earlier in the support chain, improving first-level resolution rates and reducing escalation costs. This directly applies the shift-left principle, not just a general improvement or channel strategy.

Exam trap

The trap here is that candidates confuse 'shift-left' with 'Continual Improvement' because both involve making processes better, but shift-left is specifically about moving work earlier in the support lifecycle, not just any improvement.

How to eliminate wrong answers

Option A is wrong because Continual Improvement is a broader, ongoing cycle of evaluating and enhancing all IT services and practices, not a specific technique to empower the service desk for first-level resolution. Option C is wrong because Service Desk is a functional team or tool, not a concept or practice; the question asks which ITIL 4 concept is being applied, not which team is involved. Option D is wrong because Omnichannel refers to integrating multiple communication channels (e.g., chat, email, phone) for a seamless customer experience, not to shifting resolution responsibilities to lower tiers.

116
MCQeasy

What is the difference between utility and warranty in ITIL 4?

A.Utility is about cost; warranty is about quality
B.Utility is for customers; warranty is for users
C.Utility is about functionality; warranty is about performance and availability
D.Utility is provided by the service provider; warranty is provided by the customer
AnswerC

Utility precisely describes the functionality a service provides, addressing what the service does and whether it is 'fit for purpose' in supporting customer outcomes. Warranty, conversely, focuses on the non-functional aspects, ensuring the service is 'fit for use' through guaranteed levels of performance, availability, capacity, and security. This distinction highlights that a service must not only do what is needed but also do it reliably and consistently.

Why this answer

Utility is 'fit for purpose' (does it do what it should?), while warranty is 'fit for use' (is it available, secure, etc.?).

117
MCQmedium

A service desk analyst resolves a user's issue by following a script. Which metric is most appropriate to measure the analyst's performance?

A.Customer Satisfaction (CSAT)
B.Mean Time to Resolve (MTTR)
C.Number of incidents logged
D.First Call Resolution (FCR)
AnswerD

First Call Resolution (FCR) is a critical Key Performance Indicator (KPI) that measures the percentage of incidents or service requests fully resolved during the user's initial contact with the service desk. When a service desk analyst successfully resolves a user's issue completely during the first interaction, without needing further follow-up or escalation, this directly exemplifies and contributes to a high FCR rate. It reflects the efficiency and effectiveness of the service desk at the point of initial contact.

Why this answer

First Call Resolution (FCR) is the most appropriate metric because it directly measures whether the analyst resolved the issue during the initial contact without escalation or follow-up. Following a script to resolve a user's issue on the first call demonstrates effective adherence to standardized procedures and minimizes customer effort, which is the core purpose of FCR in ITIL 4.

Exam trap

The trap here is that candidates often confuse FCR with MTTR, thinking that resolving quickly is the same as resolving on the first call, but MTTR can be low even if the issue requires multiple contacts, whereas FCR specifically measures one-and-done resolution.

How to eliminate wrong answers

Option A is wrong because Customer Satisfaction (CSAT) measures overall user happiness with the service experience, not the specific performance of resolving an issue by following a script; a user could be satisfied even if the issue was not resolved on the first call. Option B is wrong because Mean Time to Resolve (MTTR) measures the average time from incident logging to resolution, which can be influenced by factors like queue time and complexity, not the efficiency of following a script on the first contact. Option C is wrong because the number of incidents logged is a volume metric that reflects workload, not the quality or effectiveness of the analyst's resolution performance when using a script.

118
MCQmedium

Which change type is pre-authorized and follows a defined procedure?

A.Emergency change
B.Service change
C.Normal change
D.Standard change
AnswerD

Standard changes are pre-authorized, low-risk changes that are frequently implemented and follow a well-documented, repeatable procedure. Because their risks are understood and managed, they do not require individual assessment and approval each time they are performed. This pre-authorization allows for efficient execution, aligning perfectly with the description of a change that is pre-authorized and follows a defined process.

Why this answer

Standard changes are pre-authorized and follow a defined, low-risk procedure, such as applying a routine security patch or provisioning a new user account. They do not require additional approval because the risk is well-understood and the implementation steps are documented in a standard operating procedure (SOP). This aligns with ITIL 4's definition of a standard change as a change that is fully documented, low risk, and can be implemented without a formal change advisory board (CAB) meeting.

Exam trap

The trap here is that candidates confuse 'pre-authorized' with 'no change record needed'—standard changes still require a change record for tracking, but they skip the approval step because the procedure is already approved.

How to eliminate wrong answers

Option A is wrong because an emergency change is not pre-authorized; it requires urgent approval (often via an emergency CAB) and follows a separate, accelerated procedure to address high-impact incidents. Option B is wrong because 'service change' is a generic term in ITIL 4 for any change affecting a service, not a specific change type with pre-authorization and a defined procedure. Option C is wrong because a normal change requires formal assessment and approval by the change authority (e.g., CAB) before implementation; it is not pre-authorized.

119
MCQmedium

Which practice ensures that the performance of a service is measured and analyzed to meet current and future demand?

A.IT Asset Management
B.Availability Management
C.Capacity and Performance Management
D.Service Configuration Management
AnswerC

Capacity and Performance Management ensures that services and their components can meet current and future demand in a cost-effective manner, while achieving agreed performance targets. This practice involves monitoring, analyzing, and tuning service performance, such as response times, throughput, and resource utilization, to prevent bottlenecks and ensure optimal operation under various loads. It directly addresses the 'how well' a service performs to deliver value.

Why this answer

Capacity and Performance Management is the ITIL 4 practice whose explicit purpose is to ensure that services, service components, and resources meet current and future agreed-upon capacity and performance requirements in a cost-effective manner. It involves monitoring, measuring, and analyzing performance data against demand forecasts so that capacity can be scaled proactively. This directly matches the question's wording about measuring and analyzing service performance to meet current and future demand.

Exam trap

ITIL4F often tests the confusion between Availability Management and Capacity and Performance Management, since both deal with service performance metrics — candidates must remember that availability is about uptime/reliability while capacity is about meeting demand and performance levels.

How to eliminate wrong answers

Option A is wrong because IT Asset Management focuses on tracking the lifecycle, value, and cost of assets (hardware, software, licenses) rather than measuring service performance against demand. Option B is wrong because Availability Management is concerned with ensuring services meet agreed availability targets (uptime, reliability, MTBF/MTTR), not with capacity sizing or performance tuning against demand. Option D is wrong because Service Configuration Management maintains accurate configuration records (CIs and their relationships in the CMDB), which supports other practices but does not itself measure or analyze performance.

120
Multi-Selectmedium

Which TWO of the following are key components of the Service Desk practice?

Select 2 answers
A.Root cause analysis
B.Configuration baseline
C.Shift-left
D.Single point of contact (SPOC)
E.Omnichannel communication
AnswersD, E

A single point of contact (SPOC) satisfies the Service Desk practice’s requirement to provide a consistent, centralised entry for all user incidents and service requests. This mechanism ensures that users always log issues through one dedicated channel, preventing fragmented communication and enabling proper ticket logging, routing, and escalation according to ITIL4F’s service desk design.

Why this answer

The Service Desk practice is built around being the single point of contact (SPOC) for users, meaning option D is correct because the service desk serves as the centralized entry point through which all users can report incidents, make requests, and receive updates, ensuring consistent handling and communication. Option E is also correct because omnichannel communication is a key component of the modern Service Desk, enabling users to interact through multiple channels such as phone, email, chat, self-service portal, and walk-in while maintaining a consistent experience. Option A (root cause analysis) belongs primarily to the Problem Management practice, which investigates underlying causes of incidents rather than being a core Service Desk component.

Option B (configuration baseline) is part of Service Configuration Management, which defines and controls approved configurations of configuration items. Option C (shift-left) is a broader improvement strategy often associated with the Service Desk but is not itself listed as one of the two key components in this context.

Exam trap

The trap here is that candidates often confuse the Service Desk practice with other practices like Problem Management or Service Configuration Management, leading them to select root cause analysis or configuration baseline as key components, when in fact the service desk is about operational contact and communication, not analysis or configuration control.

121
MCQmedium

What is the PRIMARY difference between a problem and an incident?

A.Incidents are unplanned interruptions; problems are the cause of incidents
B.Incidents are always resolved within 24 hours; problems may take longer
C.Problems are logged by users; incidents are logged by the service desk
D.Incidents require a change request; problems do not
AnswerA

An incident, according to ITIL 4, is an unplanned interruption to a service or a reduction in the quality of a service. Its primary goal is to restore normal service operation as quickly as possible. Conversely, a problem is defined as a cause, or potential cause, of one or more incidents, even if the cause is not yet known. Problem management focuses on identifying these root causes and preventing future incidents, or at least minimizing their impact, making this the fundamental differentiating factor.

Why this answer

The primary difference is that an incident is an unplanned interruption or reduction in quality of an IT service, while a problem is the underlying cause of one or more incidents. In ITIL 4, incidents are managed to restore normal service operation as quickly as possible, whereas problems are analyzed to identify and eliminate root causes to prevent recurrence. This distinction is foundational because incidents are reactive events, while problems drive proactive improvement through problem management.

Exam trap

The trap here is that candidates confuse the symptom (incident) with the cause (problem) and assume time-based or role-based distinctions, when ITIL 4 explicitly defines them by their purpose and lifecycle, not by arbitrary metrics or logging sources.

How to eliminate wrong answers

Option B is wrong because ITIL 4 does not mandate any specific resolution time for incidents; SLAs may define targets, but incidents can take longer than 24 hours depending on complexity. Option C is wrong because both incidents and problems can be logged by users, the service desk, or automated monitoring tools; the source of logging does not define the difference. Option D is wrong because neither incidents nor problems inherently require a change request; a change request may be raised as part of the resolution process for either, but it is not a defining characteristic.

122
MCQeasy

An organization wants to improve its ability to detect and respond to security incidents. Which practice should be enhanced to achieve this objective?

A.Problem Management
B.Availability Management
C.Incident Management
D.Information Security Management
AnswerD

Information Security Management is the dedicated practice responsible for protecting an organization's information assets by identifying, assessing, and treating information security risks. It encompasses establishing security policies, implementing controls, conducting vulnerability assessments, and, critically, developing and executing robust security incident detection and response procedures to safeguard confidentiality, integrity, and availability against malicious activities.

Why this answer

Enhancing Information Security Management (ISM) directly improves an organization's ability to detect and respond to security incidents because ISM defines the policies, controls, and monitoring mechanisms (e.g., SIEM rules, intrusion detection signatures, and incident response playbooks) that enable proactive threat detection and structured response. While Incident Management handles the lifecycle of an incident once detected, ISM is the practice that establishes the security posture and detection capabilities in the first place.

Exam trap

The trap here is that candidates confuse Incident Management (the process for handling incidents) with Information Security Management (the practice that establishes detection and prevention controls), leading them to select Incident Management because it seems directly related to 'responding' to incidents, but the question specifically asks about improving the ability to 'detect and respond', which requires the security controls defined by ISM.

How to eliminate wrong answers

Option A is wrong because Problem Management focuses on identifying and eliminating the root causes of incidents to prevent recurrence, not on detecting or responding to security incidents in real time. Option B is wrong because Availability Management ensures that IT services meet agreed availability targets (e.g., uptime percentages) and does not directly address security detection or response mechanisms. Option C is wrong because Incident Management is the process for managing the lifecycle of all incidents, including security incidents, but it does not itself enhance detection capabilities; detection is a prerequisite that ISM provides through security controls and monitoring.

123
MCQmedium

Which type of change requires assessment and authorization by a change authority, but does not follow a pre-approved procedure?

A.Emergency change
B.Normal change
C.Service request
D.Standard change
AnswerB

Normal changes are those that are not standard (pre-authorized) or emergency (expedited). They require a full assessment of risk and impact, followed by formal authorization, typically by a Change Authority or Change Advisory Board (CAB), before implementation. This structured process ensures proper planning, resource allocation, and stakeholder communication, making them the type of change that precisely fits the description of requiring both assessment and authorization.

Why this answer

A normal change is any change that is not a standard change or an emergency change. It requires assessment and authorization by a change authority (e.g., the Change Manager or Change Advisory Board) but does not follow a pre-approved, low-risk procedure. This distinguishes it from standard changes, which are pre-authorized and follow a documented procedure.

Exam trap

The trap here is confusing 'normal change' with 'standard change' — candidates often assume that any change requiring authorization must follow a pre-approved procedure, but standard changes are the only type that are pre-authorized and follow a documented procedure, while normal changes require individual assessment.

How to eliminate wrong answers

Option A is wrong because an emergency change is a type of change that must be implemented as soon as possible (e.g., to resolve a major incident) and, while it also requires authorization, it follows a specific emergency change procedure (often with a separate emergency change authority) and is not defined by lacking a pre-approved procedure. Option C is wrong because a service request is a pre-defined, low-risk request from a user (e.g., password reset, access grant) that follows a standard, pre-approved procedure and typically does not require a separate change authority assessment. Option D is wrong because a standard change is a low-risk, pre-authorized change that follows a pre-approved procedure (e.g., applying a routine security patch) and does not require individual assessment by a change authority.

124
MCQhard

An IT team discovers that a recurring incident is caused by a known software bug. According to ITIL 4, what should be created to document this situation?

A.A known error record
B.A problem record
C.A change request
D.An incident record
AnswerA

A known error record is created when the root cause of a problem has been identified, but a permanent resolution has not yet been implemented. It serves to document the identified cause, symptoms, and any temporary workarounds, enabling incident management to quickly resolve recurring incidents by applying the documented solution and minimizing service impact.

Why this answer

A known error is documented when the root cause is identified and a workaround exists; it is part of Problem Management's error control phase.

125
Multi-Selecthard

Which THREE of the following are purposes or outputs of the Continual Improvement practice?

Select 3 answers
A.Maintaining an improvement register
B.Ensuring services are aligned with evolving business needs
C.Following the ITIL continual improvement model
D.Resolving incidents within agreed times
E.Assessing and authorizing changes
AnswersA, B, C

The continual improvement practice is responsible for maintaining an improvement register, which is a structured database or log of improvement opportunities. This register captures details such as the nature of the opportunity, its potential value, current status, and responsible parties. It serves as a central repository to track and manage all improvement initiatives across the organization, ensuring that identified opportunities are not lost and progress can be monitored effectively. This systematic approach is crucial for driving ongoing service and product enhancements.

Why this answer

Continual improvement uses the improvement register, follows the 7-step model, and aims to align services with business needs.

126
Multi-Selectmedium

Which TWO are components of the ITIL 4 Continual Improvement Model?

Select 2 answers
A.Define improvement objectives
B.Where are we now?
C.How do we keep momentum?
D.Plan the improvement
E.How do we get there?
AnswersB, E

"Where are we now?" is correctly identified as the second step in the ITIL 4 Continual Improvement Model. This phase is dedicated to conducting a thorough assessment of the current state of services, products, or practices. It involves gathering data, analyzing performance, identifying existing capabilities, and understanding the baseline from which improvements will be measured, providing a clear picture of the starting point.

Why this answer

The ITIL 4 Continual Improvement Model consists of seven steps: What is the vision?, Where are we now?, Where do we want to be?, How do we get there?, Take action, Did we get there?, and How do we keep the momentum going? The two correct components from the options are B ("Where are we now?") and E ("How do we get there?"). Options A, C, and D are not steps in the model.

127
MCQhard

Which practice in ITIL 4 includes the activities of problem identification, problem control, and error control?

A.Incident Management
B.Change Enablement
C.Service Level Management
D.Problem Management
AnswerD

Problem Management owns the full lifecycle: identifying problems, controlling them through root cause analysis, and managing known errors. These three activities map directly to the practice's scope, distinguishing it from Incident Management, which restores service.

Why this answer

Problem Management is the ITIL 4 practice specifically designed to manage the lifecycle of all problems. Its core activities are problem identification (detecting and logging problems), problem control (analyzing and documenting workarounds and root causes), and error control (managing known errors through the lifecycle until a permanent resolution is implemented).

Exam trap

The trap here is that candidates confuse Incident Management's focus on restoring service quickly with Problem Management's focus on finding and fixing root causes, especially since both practices handle service disruptions.

How to eliminate wrong answers

Option A is wrong because Incident Management focuses on restoring normal service operation as quickly as possible after an incident, not on identifying root causes or controlling known errors. Option B is wrong because Change Enablement manages the lifecycle of changes to IT services, ensuring standardized methods and procedures for efficient handling of changes, not problem analysis. Option C is wrong because Service Level Management negotiates, agrees, and monitors service level agreements (SLAs) and does not involve problem identification or error control activities.

128
MCQeasy

What is the ITIL 4 term for a measurement used to track the performance of a service desk?

A.Critical Success Factor (CSF)
B.Service Level Agreement (SLA)
C.Operational Level Agreement (OLA)
D.Key Performance Indicator (KPI)
AnswerD

A Key Performance Indicator (KPI) is a quantifiable metric used to evaluate the success of an organization, service, or activity in meeting its objectives. KPIs provide measurable values that demonstrate how effectively an organization is achieving its critical business objectives. They are specifically designed to track progress, identify trends, and provide actionable insights into performance, making them the precise ITIL 4 term for a measurement used to track performance.

Why this answer

In ITIL 4, a Key Performance Indicator (KPI) is the correct term for a metric used to measure and track the performance of a service desk, such as average response time or first-call resolution rate. KPIs are quantifiable measurements that directly reflect the effectiveness and efficiency of a service management process or practice, unlike CSFs which are strategic objectives.

Exam trap

The trap here is that candidates confuse CSFs with KPIs, thinking a strategic success factor is the same as a measurable metric, but ITIL 4 clearly separates the 'what' (CSF) from the 'how to measure it' (KPI).

How to eliminate wrong answers

Option A is wrong because a Critical Success Factor (CSF) is a strategic element required to achieve an objective, not a measurement; it describes what must be achieved (e.g., 'improve customer satisfaction'), not how it is tracked. Option B is wrong because a Service Level Agreement (SLA) is a documented contract between a service provider and a customer defining agreed service levels, not a performance measurement itself. Option C is wrong because an Operational Level Agreement (OLA) is an internal agreement between support teams to support SLA delivery, not a metric used to track service desk performance.

129
MCQhard

An organization is implementing a new monitoring tool. Which type of event should trigger an immediate response from the IT team?

A.Scheduled event
B.Exception event
C.Warning event
D.Informational event
AnswerB

An exception event signifies a critical deviation from the expected normal operation of a service or component, often indicating a service degradation or failure. When a new monitoring tool identifies an issue, particularly one that warrants attention, it is typically flagging an unexpected condition that requires immediate investigation and potential intervention to restore service or prevent further impact. These events demand prompt action due to their potential for significant business disruption.

Why this answer

Exception events indicate that a service or component has deviated from its normal or expected operation — for example, a server going down, a disk failing, or a process crashing. Because they signal an actual fault or breach of an operational threshold, ITIL 4 service management designates them as requiring immediate investigation and response. Scheduled events (e.g., backups, batch jobs) and informational events are expected and logged for reference, while warning events indicate a potential issue that may need attention but not necessarily an immediate reaction.

Exam trap

ITIL4F often tests the distinction between warning and exception events — candidates incorrectly assume any alert (including a threshold warning) requires immediate response, when only an exception (actual deviation from normal operation) does.

How to eliminate wrong answers

Option A is wrong because scheduled events are planned, expected occurrences (such as automated backups or maintenance jobs) that are logged for audit and trend analysis rather than triggering immediate intervention. Option C is wrong because a warning event signals a condition approaching a threshold (e.g., disk 80% full) — it warrants monitoring and possible proactive action, but ITIL distinguishes it from an exception that demands immediate response. Option D is wrong because informational events simply record normal operational activity (e.g., a user logging in) and are used for auditing and baselining, not for triggering any response.

130
MCQeasy

What is the main difference between a standard change and a normal change?

A.A standard change cannot be scheduled, while a normal change can be scheduled
B.A standard change is only used for emergency fixes, while a normal change is for planned improvements
C.A standard change is pre-approved and follows a defined procedure, while a normal change requires approval from a change authority
D.A standard change has no defined procedure, while a normal change has a defined procedure
AnswerC

A standard change is characterized by its pre-authorization, meaning it has already undergone risk assessment and approval, allowing for immediate implementation upon request or trigger, following a strict, documented procedure. Conversely, a normal change requires a formal assessment and explicit approval from a designated change authority, such as a Change Advisory Board (CAB) or an individual, before it can proceed. This distinction in the approval mechanism is fundamental to ITIL 4's change enablement practice, balancing speed with control.

Why this answer

In ITIL 4, a standard change is pre-authorized and follows a defined procedure, often low-risk and routine, so it does not require individual approval each time. A normal change is not pre-approved and must go through the change authority for assessment and authorization. This distinction is fundamental to change enablement.

Exam trap

ITIL4F often tests the confusion between standard and normal changes, so candidates must remember that standard changes are pre-approved and procedure-driven, while normal changes require approval from a change authority.

How to eliminate wrong answers

Option A is wrong because standard changes can be scheduled; the ability to schedule is not the differentiator. Option B is wrong because standard changes are not for emergency fixes — emergency changes are a separate category (emergency changes) in ITIL. Option D is wrong because standard changes do have a defined procedure; in fact, they are defined precisely because they follow a pre-approved, documented procedure.

131
Multi-Selecthard

Which THREE of the following are key activities of Monitoring and Event Management?

Select 3 answers
A.Negotiate SLAs
B.Detect events
C.Perform root cause analysis
D.Respond to events
E.Classify events as informational, warning, or exception
AnswersB, D, E

Detecting events involves actively observing and identifying any significant change of state that has meaning for the management of a service or other configuration item. This foundational activity uses various tools and techniques, such as system logs, network probes, and application performance monitors, to capture data and recognize patterns or specific occurrences that indicate normal operation, potential issues, or exceptions requiring attention. Effective detection is the first critical step in understanding the operational health of IT services.

Why this answer

Monitoring and Event Management in ITIL/ITSM centers on the operational loop of observing infrastructure and services, so option B (Detect events) is correct because detecting events is the core purpose of monitoring tools and agents that observe metrics, logs, and status changes. Option E (Classify events as informational, warning, or exception) is correct because once an event is detected it must be categorized by significance so that informational events are logged, warnings are assessed, and exceptions trigger incident or problem handling. Option D (Respond to events) is correct because the process must act on classified events, whether by automated remediation, raising an incident, or escalating to the appropriate team.

Option A (Negotiate SLAs) is not part of this practice; SLA negotiation belongs to Service Level Management, which defines targets that monitoring may later measure against. Option C (Perform root cause analysis) is not a Monitoring and Event Management activity either; root cause analysis is performed within Problem Management to identify the underlying cause of incidents.

Exam trap

PeopleCert often tests the distinction between Monitoring and Event Management (detection and response) and Problem Management (root cause analysis), leading candidates to incorrectly select root cause analysis as a monitoring activity.

132
MCQeasy

Which ITIL practice is responsible for negotiating and agreeing on service level targets?

A.Supplier Management
B.Capacity and Performance Management
C.Availability Management
D.Service Level Management
AnswerD

Service Level Management is the dedicated practice responsible for defining, negotiating, and agreeing upon service level targets with customers. It establishes Service Level Agreements (SLAs) that document these agreed expectations, then monitors and reports on the actual performance of services against these targets, ensuring a clear understanding and alignment between service providers and consumers.

Why this answer

Service Level Management is the ITIL practice responsible for negotiating, agreeing, and managing service level targets with customers. It defines, documents, and monitors Service Level Agreements (SLAs) and ensures that services are delivered according to agreed-upon expectations. This practice is the direct owner of the SLA lifecycle, from negotiation through review.

Exam trap

ITIL4F often tests the confusion between Service Level Management and practices like Availability or Capacity Management — candidates must remember that SLM owns the negotiation and agreement of targets, while other practices provide the technical inputs to meet those targets.

How to eliminate wrong answers

Option A is wrong because Supplier Management negotiates and manages agreements with external suppliers (underpinning contracts), not with customers for service level targets. Option B is wrong because Capacity and Performance Management ensures services meet demand and performance requirements, but it does not negotiate or agree on SLAs — it provides input to them. Option C is wrong because Availability Management focuses on ensuring services meet availability targets, again providing input to SLAs rather than owning the negotiation and agreement process.

133
MCQhard

What is the key difference between Deployment Management and Release Management in ITIL 4?

A.Deployment Management is part of Release Management
B.Release Management ensures the service is available for use; Deployment Management moves components into the live environment
C.Release Management is only for major releases; Deployment Management is for all releases
D.Deployment Management focuses on moving to production; Release Management focuses on building the release
AnswerB

Release Management makes services and features available for use, whereas Deployment Management moves components into the live environment. This axis — availability versus physical placement — satisfies the stem, distinguishing the two practices that often operate together but serve different purposes.

Why this answer

Release Management is responsible for making new or changed services available for use, which includes the decision to deploy and the overall coordination of the release. Deployment Management, in contrast, handles the technical movement of service components (e.g., software, hardware, documentation) into the live environment, ensuring they are installed, tested, and ready. This separation allows Release Management to focus on value and risk, while Deployment Management focuses on the technical execution.

Exam trap

The trap here is that candidates confuse the terms 'deployment' and 'release' as synonyms, but ITIL 4 defines them as separate practices with different scopes—deployment is the technical act of moving components, while release is the broader business decision to make the service available.

How to eliminate wrong answers

Option A is wrong because Deployment Management and Release Management are distinct practices in ITIL 4, not hierarchical; Deployment Management is not a sub-process of Release Management, though they are closely coordinated. Option C is wrong because Release Management applies to all releases (major, minor, emergency), not just major ones, and Deployment Management also handles all types of deployments. Option D is wrong because Release Management does not focus on building the release (that is the role of Service Design and Software Development); Release Management focuses on the overall planning, authorization, and making the service available, while Deployment Management focuses on moving components to production.

134
MCQmedium

A major outage has occurred, and the IT team needs to implement a fix immediately without following the normal change authorization process. According to ITIL 4, what type of change should be raised?

A.Normal change
B.Emergency change
C.Standard change
D.Service request
AnswerB

Emergency changes are specifically designed for urgent situations, such as resolving a major outage, where immediate action is required to restore service functionality. They involve an expedited assessment and authorization process, often with retrospective documentation and approval, to minimize service disruption and mitigate severe business impact. This streamlined approach prioritizes speed over full formality to address critical incidents and major incidents effectively.

Why this answer

Emergency changes are for urgent situations that require immediate implementation to restore service. They have a separate, faster authorization process.

135
MCQeasy

Which practice is responsible for managing the lifecycle of hardware and software assets?

A.Service Configuration Management
B.Supplier Management
C.IT Asset Management
D.Capacity and Performance Management
AnswerC

IT Asset Management is the practice responsible for planning, monitoring, and controlling the full lifecycle of IT assets, from their acquisition and deployment through maintenance, utilization, and eventual disposal. This comprehensive approach ensures that the organization maximizes value, controls costs, manages risks, and supports decision-making related to the entire inventory of IT hardware, software, and information assets.

Why this answer

IT Asset Management manages the lifecycle of IT assets. Option C is correct. Service Configuration Management manages configuration items and their relationships.

Capacity Management focuses on performance. Supplier Management manages vendors.

136
MCQeasy

What is the PRIMARY role of a Service Desk in ITIL 4?

A.To manage the CMDB
B.To approve changes
C.To be the single point of contact between users and IT
D.To analyse incident trends
AnswerC

The Service Desk's fundamental and primary role is to act as the Single Point of Contact (SPOC) for all users, facilitating seamless communication between them and the various IT services and teams. This crucial function ensures that users have a consistent, accessible, and reliable channel for logging incidents, requesting services, seeking information, and receiving timely updates. By centralizing initial interactions, the Service Desk effectively manages user expectations, streamlines support processes, and directs inquiries to the appropriate resolution groups, significantly enhancing the overall user experience.

Why this answer

The service desk serves as the single point of contact (SPOC) for users to report issues and request services.

137
MCQeasy

Which type of change is pre-approved and follows a low-risk, well-defined procedure?

A.Service request
B.Normal change
C.Standard change
D.Emergency change
AnswerC

A standard change is a pre-authorized change that is low-risk, relatively common, and follows a documented procedure or work instruction. These changes are typically well-understood, have a proven implementation plan, and are often initiated as service requests. Because their risk is assessed and approved in advance, they do not require additional authorization each time they are implemented, aligning perfectly with the description of being pre-approved and low-risk.

Why this answer

Standard changes are pre-approved with a defined procedure.

138
MCQeasy

Which of the following is the CORRECT sequence of phases in the Problem Management practice?

A.Problem Control, Error Control, Problem Identification
B.Problem Identification, Error Control, Problem Control
C.Problem Identification, Problem Control, Error Control
D.Error Control, Problem Control, Problem Identification
AnswerC

This sequence accurately represents the phases of ITIL Problem Management. Problem Identification is the crucial first step, involving the detection and logging of problems. This is followed by Problem Control, which focuses on root cause analysis and managing workarounds to minimize the impact of unresolved problems. Finally, Error Control is executed to implement permanent solutions for known errors, thereby preventing recurrence and reducing future incidents.

Why this answer

The correct sequence in the Problem Management practice is Problem Identification, Problem Control, and Error Control. Problem Identification detects and logs problems from incidents or proactive analysis; Problem Control performs root cause analysis and documents workarounds; Error Control manages known errors through the lifecycle until a permanent resolution is implemented. This order ensures that problems are first recognized, then analyzed, and finally resolved.

Exam trap

The trap here is that candidates confuse the order of Problem Control and Error Control, mistakenly thinking Error Control comes first because it sounds like 'fixing errors,' but in ITIL 4, Error Control follows Problem Control after root cause is established.

How to eliminate wrong answers

Option A is wrong because it starts with Problem Control before problems are even identified, which is logically impossible. Option B is wrong because it places Error Control before Problem Control, but Error Control depends on the root cause analysis and workaround documentation completed in Problem Control. Option D is wrong because it begins with Error Control, which requires a known error from Problem Control, and ends with Problem Identification, which must occur first to initiate the practice.

139
Multi-Selectmedium

Which TWO are types of change defined in ITIL 4?

Select 2 answers
A.Service request
B.Normal change
C.Scheduled change
D.Standard change
E.Urgent change
AnswersB, D

A normal change is any change that is not standard or emergency, requiring a full assessment and authorization process. These changes typically involve significant risk or impact, necessitating thorough planning, scheduling, and formal approval by a designated Change Authority. The comprehensive workflow ensures proper evaluation of potential effects on services and infrastructure before implementation, making it a core type of change in ITIL 4.

Why this answer

In ITIL 4, change types are categorized by how they are authorized and assessed, and two recognized types are the normal change (B) and the standard change (D). A normal change (B) is one that must go through the full change control process, including assessment, authorization, and scheduling by the change authority, because it carries meaningful risk or impact. A standard change (D) is a pre-authorized, low-risk, routine change with a documented procedure that can be executed without additional authorization each time.

The other options are not ITIL 4 change types: service request (A) is a separate practice (service request management) for user-initiated requests, scheduled change (C) describes a change that has been planned for a time window rather than a defined type, and urgent change (E) is an emergency change in ITIL terminology, not a formal ITIL 4 change type category.

Exam trap

The trap here is that candidates confuse 'scheduled change' (a common operational term) with a formal ITIL 4 change type, or they misremember 'urgent change' instead of the precise ITIL term 'emergency change'.

140
MCQhard

Which of the following best distinguishes an output from an outcome in ITIL 4?

A.An output is a deliverable, while an outcome is the result for the stakeholder
B.An output is the value created, while an outcome is the metric used
C.An output is the result of an activity, while an outcome is the cost of the activity
D.An output is what the service does, while an outcome is how it is delivered
AnswerA

This option correctly distinguishes an output from an outcome according to ITIL 4 principles. An output is a tangible or intangible deliverable produced by an activity or service, such as a new software release or a processed report. Conversely, an outcome represents the actual result or benefit realized by a stakeholder from consuming or utilizing that output, focusing on the value created or the change in state achieved for them.

Why this answer

In ITIL 4, an output is a tangible or intangible deliverable produced by an activity, while an outcome is the result or consequence for the stakeholder. The distinction is that outputs are what is produced, and outcomes are the value or effect experienced by the stakeholder.

Exam trap

The trap is confusing outputs with outcomes, especially when options use similar terms like 'result' or 'value'. Candidates must remember that outputs are deliverables and outcomes are the stakeholder results.

How to eliminate wrong answers

Option B is wrong because it reverses the definitions: output is not value created, and outcome is not a metric. Option C is wrong because it incorrectly defines output as result of an activity (that is closer to outcome) and outcome as cost. Option D is wrong because it describes output as what the service does (which is more like a process) and outcome as how it is delivered, which is not accurate.

141
MCQeasy

Which of the following is a type of change that is pre-approved and follows a defined procedure?

A.Standard change
B.Service request
C.Normal change
D.Emergency change
AnswerA

A standard change is pre-authorised and follows a documented procedure, so it can be implemented without a full change advisory board review each time. This matches the stem's definition of a pre-approved change with a defined procedure.

Why this answer

A standard change is a pre-approved change that follows a defined procedure, such as a low-risk, routine activity like applying a security patch or provisioning a new user account. ITIL 4 defines standard changes as having a documented, repeatable process that does not require additional authorization each time, making option A correct.

Exam trap

The trap here is confusing a 'service request' (which is a request for service delivery, not a change) with a 'standard change' (which is a pre-approved change type), leading candidates to incorrectly select service request when the question specifically asks for a type of change.

How to eliminate wrong answers

Option B (Service request) is wrong because a service request is a formal request for something to be provided (e.g., access, information), not a type of change; it may or may not involve a change, and it is not inherently pre-approved as a change category. Option C (Normal change) is wrong because a normal change requires assessment and authorization through the change advisory board (CAB) or equivalent, and is not pre-approved. Option D (Emergency change) is wrong because an emergency change is a high-urgency change that must be implemented as quickly as possible, often with expedited authorization, and is not pre-approved in the same way as a standard change.

142
Multi-Selecthard

Which THREE of the following are considered events in the Monitoring and Event Management practice?

Select 3 answers
A.A user requesting a password reset
B.A user reporting an application crash
C.A server CPU utilization exceeding a threshold
D.A disk drive failure alert
E.A backup job completing successfully
AnswersC, D, E

A server CPU utilization exceeding a predefined threshold is a classic example of a warning event. This notification, typically generated by monitoring tools, indicates a change in the state of a configuration item that could potentially lead to a service degradation or incident if not addressed. It serves as an early alert, allowing proactive intervention before a critical failure occurs.

Why this answer

In the Monitoring and Event Management practice, an event is any change of state that has significance for the management of a service or configuration item. Option C is correct because a server CPU utilization exceeding a threshold is a predefined condition that triggers an event, often an 'alert' or 'warning' event, which is automatically detected by monitoring tools (e.g., SNMP traps, Prometheus alerts) and requires attention or automated response.

Exam trap

The trap here is confusing user-initiated communications (requests, incident reports) with system-generated events, leading candidates to incorrectly select A or B because they think any 'notification' qualifies as an event.

143
Multi-Selectmedium

Which TWO of the following are roles involved in Change Enablement?

Select 2 answers
A.Change Authority
B.Service Desk Manager
C.Problem Manager
D.Supplier Manager
E.Change Manager
AnswersA, E

The Change Authority is responsible for authorizing changes, balancing the potential benefits against the risks involved. This role ensures that changes are properly assessed and approved before implementation, preventing unauthorized or high-risk modifications to services. Depending on the type and impact of the change, this authority can be a single individual, a change advisory board (CAB), or even an automated system for standard changes.

Why this answer

Change Enablement involves a Change Authority (who approves changes) and a Change Manager (who oversees the process). The Service Desk Manager is not necessarily involved.

144
MCQmedium

Which practice ensures that the availability of a service meets the agreed requirements?

A.Service Level Management
B.Availability Management
C.Capacity Management
D.Continual Improvement
AnswerB

Availability Management is the dedicated practice responsible for ensuring that services and components are available when needed, meeting or exceeding agreed-upon availability targets. This practice involves proactively planning, designing, implementing, and maintaining the resilience, reliability, and recoverability of IT services and infrastructure. It encompasses activities like availability planning, monitoring, analysis of availability events, and implementing improvements to maximize service uptime and minimize disruption.

Why this answer

Availability Management is the ITIL 4 practice specifically focused on ensuring that services deliver the level of availability agreed with the business. It defines, analyses, plans, measures, and improves all aspects of the availability of services, and it is responsible for ensuring that all IT infrastructure, processes, tools, roles, and techniques are appropriate to meet the agreed availability targets. While Service Level Management negotiates and monitors SLAs, it is Availability Management that actually ensures the service meets those availability requirements.

Exam trap

ITIL4F often tests the distinction between Service Level Management and Availability Management, as candidates may confuse the negotiation of SLAs with the actual assurance of availability.

How to eliminate wrong answers

Option A is wrong because Service Level Management is responsible for negotiating, agreeing, and monitoring service levels (including availability targets) but does not directly ensure that the availability requirements are met; that is the role of Availability Management. Option C is wrong because Capacity Management ensures that service and component capacity meets current and future agreed demand, not availability. Option D is wrong because Continual Improvement is a general practice for aligning services with changing business needs through ongoing improvement, not specifically for ensuring availability requirements are met.

145
MCQeasy

Which type of change is pre-approved and has a defined procedure?

A.Standard change
B.Service request
C.Normal change
D.Emergency change
AnswerA

A standard change is pre-authorised, low-risk and repeatable, following a documented procedure that removes the need for individual assessment each time. This directly satisfies the stem's requirement for a pre-approved change type with a defined procedure, unlike normal changes, which require assessment and authorisation through the change enablement practise.

Why this answer

Standard changes are low-risk, pre-approved, and follow a defined procedure.

146
MCQmedium

A service desk measures the percentage of calls resolved on first contact. Which metric is this?

A.Customer Satisfaction Score (CSAT)
B.Mean Time to Resolve (MTTR)
C.Service Level Achievement
D.First Contact Resolution (FCR)
AnswerD

First Contact Resolution (FCR) is a fundamental service desk metric that precisely measures the percentage of customer inquiries, incidents, or service requests that are completely resolved during the customer's initial interaction with the service desk. This means the customer does not need to call back, email again, or be transferred to another support agent for the same issue. It directly quantifies the efficiency of resolving issues at the first point of contact, aligning perfectly with 'percentage of calls resolved on' the first attempt.

Why this answer

First Contact Resolution (FCR) is the correct metric because it specifically measures the percentage of calls resolved during the initial contact with the service desk, without requiring a callback, escalation, or follow-up. This aligns directly with the question's definition, as FCR is a key performance indicator (KPI) in ITIL 4 for evaluating service desk efficiency and user satisfaction.

Exam trap

The trap here is that candidates often confuse FCR with MTTR, assuming that resolving quickly on first contact is the same as measuring resolution time, but MTTR focuses on duration rather than the count of first-contact resolutions.

How to eliminate wrong answers

Option A is wrong because Customer Satisfaction Score (CSAT) measures overall user satisfaction with a service or interaction, typically via post-interaction surveys, not the percentage of calls resolved on first contact. Option B is wrong because Mean Time to Resolve (MTTR) measures the average time taken to resolve an incident from the moment it is reported, not the proportion of calls resolved on first contact. Option C is wrong because Service Level Achievement measures whether a service meets predefined targets (e.g., response time or resolution time), not the specific metric of first-contact resolution rate.

147
Multi-Selectmedium

Which THREE of the following are key activities of the Continual Improvement practice?

Select 3 answers
A.Defining improvement initiatives based on stakeholder feedback
B.Negotiating and agreeing service level targets
C.Maintaining an improvement register
D.Applying the ITIL continual improvement model
E.Monitoring and responding to events
AnswersA, C, D

Continual Improvement actively seeks input from various stakeholders, including customers, users, and internal teams, to identify areas for enhancement. This feedback is crucial for understanding current service performance, identifying pain points, and defining specific, actionable improvement initiatives that align with organizational objectives and deliver tangible value. These initiatives then form the basis for the "What do we want to be?" step within the continual improvement model.

Why this answer

Option A is correct because the Continual Improvement practice uses stakeholder feedback (from customers, users, and other interested parties) to identify and define improvement initiatives that align with the organization's objectives. Option C is correct because maintaining an improvement register is a core activity of the practice, used to record, prioritize, and track improvement opportunities and their progress. Option D is correct because applying the ITIL continual improvement model provides the structured, iterative approach (vision, current state, target state, plan, act, evaluate) that guides improvement efforts.

Option B does not belong because negotiating and agreeing service level targets is an activity of the Service Level Management practice, not Continual Improvement. Option E does not belong because monitoring and responding to events is an activity of the Monitoring and Event Management practice.

Exam trap

ITIL4F often tests the boundaries between practices; candidates confuse Continual Improvement activities with those of Service Level Management or Monitoring and Event Management.

148
MCQmedium

A service desk team is overwhelmed by repeated incidents caused by a known software bug that the vendor has not yet patched. The IT manager wants to reduce the number of incidents without waiting for the vendor. Which ITIL practice would directly help in reducing the impact of this known issue?

A.Renegotiate service level targets with the customer in Service Level Management
B.Create a known error record in Problem Management and provide a workaround
C.Implement a faster incident resolution process in Incident Management
D.Submit a change request to Change Enablement to replace the software
AnswerB

Creating a known error record in Problem Management is the most appropriate action because it acknowledges a recurring issue with an identified root cause, even if a permanent solution is not yet available. Documenting a workaround enables the service desk to resolve future instances of this specific incident more efficiently and consistently, significantly reducing the impact and the burden of repeated calls while a permanent fix is pursued.

Why this answer

Problem Management creates known error records when a root cause is identified but not yet permanently resolved. The known error record documents the bug and, critically, includes a documented workaround that the service desk can apply to restore service quickly, reducing incident impact and volume. This directly addresses the situation without waiting for the vendor patch.

Exam trap

ITIL4F often tests the distinction between Incident Management (restore service) and Problem Management (root cause and workarounds), so candidates may incorrectly choose a faster incident process instead of creating a known error record with a workaround.

How to eliminate wrong answers

Option A is wrong because renegotiating SLAs does not reduce the number of incidents or their impact; it only changes contractual expectations. Option C is wrong because a faster incident resolution process does not address the underlying known error; it may help temporarily but does not provide a workaround or reduce recurrence. Option D is wrong because submitting a change request to replace the software is a long-term fix that does not immediately reduce incidents and may not be feasible without vendor support.

149
MCQhard

Which practice would be responsible for ensuring that a service's performance meets agreed targets during peak demand?

A.Service Level Management
B.Monitoring and Event Management
C.Capacity and Performance Management
D.Availability Management
AnswerC

The Capacity and Performance Management practice is specifically responsible for ensuring that services and their components can meet current and future performance and demand in a cost-effective way. This involves understanding the current utilization, forecasting future demand, and planning for necessary adjustments in infrastructure and application resources to maintain agreed service levels and prevent performance bottlenecks. It directly addresses the proactive management of resources to achieve performance goals.

Why this answer

Capacity and Performance Management is the correct practice because it specifically focuses on ensuring that services achieve agreed and expected performance levels, including during peak demand periods. This practice involves monitoring current usage, forecasting future demand, and planning capacity to meet service level targets, making it directly responsible for performance under load.

Exam trap

The trap here is that candidates often confuse Monitoring and Event Management (which detects performance issues) with Capacity and Performance Management (which proactively plans and adjusts resources to prevent those issues).

How to eliminate wrong answers

Option A is wrong because Service Level Management is responsible for defining, negotiating, and reporting on service level agreements (SLAs), but it does not directly manage the technical capacity or performance tuning required to meet those targets during peak demand. Option B is wrong because Monitoring and Event Management focuses on observing and detecting events, not on proactively planning or adjusting capacity to ensure performance targets are met. Option D is wrong because Availability Management ensures that services are available when needed, but it does not specifically address performance metrics like response time or throughput during peak load.

150
MCQmedium

A service desk agent is handling a request for a new software installation that is listed in the service catalogue. According to ITIL 4, what type of record should be raised?

A.Service request
B.Change request
C.Problem record
D.Incident record
AnswerA

A service request is a formal request from a user for something that is a normal part of service delivery, such as access to a service, information, or a standard IT asset like new software. These requests are typically predefined, often published in a service catalog, and have established, pre-approved workflows for efficient fulfillment. Requesting new software, when it's a standard offering, perfectly aligns with this definition, making it a routine and predictable transaction.

Why this answer

A service request is the correct record type because the user is asking for a new software installation that is already defined in the service catalogue. According to ITIL 4, a service request is a formal request from a user for something to be provided – for example, access to an application or installation of standard software – and it follows a pre-defined, standardized procedure. This is distinct from an incident (unplanned interruption), a problem (root cause of incidents), or a change (alteration to a service).

Exam trap

The trap here is that candidates confuse a service request with a change request, thinking any installation requires a formal change, but ITIL 4 explicitly treats pre-approved, catalogued items as service requests to streamline fulfillment and reduce overhead.

How to eliminate wrong answers

Option B (Change request) is wrong because a change request is used for modifications that may affect service operation, such as installing a non-standard or unapproved application, whereas the software is already listed in the service catalogue and thus follows a standard, low-risk procedure. Option C (Problem record) is wrong because a problem record is raised to document the root cause of one or more incidents, not to fulfill a user's request for a new installation. Option D (Incident record) is wrong because an incident is an unplanned interruption or reduction in quality of a service, whereas a software installation request is a planned, standard activity.

← PreviousPage 2 of 5 · 301 questions totalNext →

Ready to test yourself?

Try a timed practice session using only ITIL Management Practices questions.