Courseiva

CCNA ITIL Management Practices Questions

75 of 260 questions · Page 2/4 · ITIL Management Practices · Answers revealed

76
Multi-Selecthard

Which THREE of the following are considered events in the Monitoring and Event Management practice?

Select 3 answers
A.A scheduled backup completing successfully
B.A printer that is low on toner
C.A server reaching 100% CPU usage
D.A user reporting a slow computer
E.A new employee requesting access to a system
AnswersA, B, C

This represents an informational event, automatically generated by the backup system to confirm the successful completion of a routine operation. While it doesn't signal a problem or require immediate intervention, these events are vital for maintaining an audit trail, ensuring compliance, and confirming the ongoing health and reliability of critical IT services. Monitoring such positive events helps validate system functionality and operational integrity.

Why this answer

In ITIL 4, the Monitoring and Event Management practice classifies events into informational, warning, and exception categories. All three types are considered events within the practice. Informational events (e.g., a scheduled backup completing successfully) are routine and may not require immediate action, but they are still events that are monitored and recorded.

Warning events (e.g., printer low on toner) indicate a potential issue, and exception events (e.g., server reaching 100% CPU usage) require immediate attention. Therefore, options A, B, and C are all events.

77
MCQhard

An IT team is redesigning a process. They decide to review what already works well before making changes. Which ITIL 4 guiding principle are they applying?

A.Focus on value
B.Keep it simple
C.Start where you are
D.Progress iteratively
AnswerC

The "Start where you are" guiding principle explicitly advises against discarding existing resources and starting from scratch without first considering what is already available. When an IT team is redesigning a process, reviewing the current state is a direct application of this principle, as it involves understanding the baseline, identifying what works well, and recognizing what needs improvement, thereby leveraging existing foundations rather than reinventing solutions.

Why this answer

The guiding principle 'Start where you are' means using existing capabilities and services as a basis for improvement. Option C is correct. Option A (Focus on value) is about delivering value.

Option B (Keep it simple) is about simplicity. Option D (Progress iteratively) is about incremental improvements.

78
Multi-Selectmedium

Which TWO of the following are key metrics used by a service desk?

Select 2 answers
A.Mean Time Between Failures (MTBF)
B.Return on Investment (ROI)
C.Customer Satisfaction (CSAT)
D.Capacity Utilization
E.First Contact Resolution (FCR)
AnswersC, E

Customer Satisfaction (CSAT) is a pivotal metric for any service, directly measuring how satisfied customers are with a service or specific interaction, such as with the service desk. It typically involves direct feedback from users, often through surveys, providing invaluable insight into their perception of service quality, responsiveness, and overall value. High CSAT scores indicate that the service is meeting or exceeding customer expectations, making it a fundamental indicator of service success and customer-centricity.

Why this answer

Customer Satisfaction (CSAT) is a key metric for a service desk because it directly measures the user's perception of the quality and effectiveness of the support they received. ITIL 4 defines CSAT as a critical indicator of service value and customer experience, often collected via post-interaction surveys. First Contact Resolution (FCR) is equally vital as it tracks the percentage of incidents resolved during the first interaction, reducing downtime and operational costs.

Exam trap

The trap here is that candidates confuse infrastructure reliability metrics (MTBF) or financial metrics (ROI) with service desk performance indicators, but ITIL 4 explicitly defines CSAT and FCR as key service desk metrics in the Service Desk practice.

79
MCQeasy

What is the purpose of the Service Desk practice?

A.To monitor and control IT events
B.To manage the lifecycle of all IT assets
C.To negotiate service level agreements
D.To provide a single point of contact for users
AnswerD

The fundamental purpose of the Service Desk practice is to establish and maintain a single point of contact (SPOC) between the service provider and its users. This crucial role ensures that users have a consistent, accessible, and reliable channel for all IT-related inquiries, incident reporting, service requests, and information needs, thereby streamlining communication and enhancing user experience and satisfaction.

Why this answer

The Service Desk practice provides a single point of contact (SPOC) for users to report incidents, submit service requests, and receive updates. This ensures that all user interactions are logged, tracked, and managed consistently, aligning with the ITIL 4 guiding principle of 'Focus on Value' by reducing user confusion and improving resolution times.

Exam trap

The trap here is that candidates often confuse the Service Desk with other operational practices like Event Management or Asset Management, because all involve handling IT-related data, but the Service Desk is uniquely focused on being the user-facing single point of contact.

How to eliminate wrong answers

Option A is wrong because monitoring and controlling IT events is the purpose of the Event Management practice, not the Service Desk. Option B is wrong because managing the lifecycle of all IT assets is the purpose of the IT Asset Management practice, which focuses on tracking hardware, software, and licenses from acquisition to disposal. Option C is wrong because negotiating service level agreements is the purpose of the Service Level Management practice, which defines and reviews SLAs, not the Service Desk.

80
MCQhard

An organization implements a new monitoring tool that automatically detects and classifies events. A high-priority event triggers an alert. According to ITIL 4, what type of event is this?

A.Exception event
B.Informational event
C.Warning event
D.Normal event
AnswerA

An exception event signifies an abnormal situation where a service or component is operating outside its established baseline or expected parameters, often indicating a failure or a critical degradation. These events trigger immediate investigation and resolution efforts to prevent service disruption or restore normal operations, aligning with the core purpose of event management to detect and respond to deviations.

Why this answer

In ITIL 4, an exception event indicates that something has occurred that deviates from normal operation, often requiring immediate attention. A high-priority alert triggered by a monitoring tool automatically detecting and classifying events fits this definition, as it signals a significant anomaly that may impact services.

Exam trap

The trap here is that candidates confuse 'warning' with 'exception' because both involve alerts, but ITIL 4 distinguishes them by the required response—warnings are proactive notifications of potential issues, while exceptions are reactive alerts of actual failures requiring immediate action.

How to eliminate wrong answers

Option B is wrong because an informational event is a routine notification (e.g., a log entry confirming a scheduled task completed) that does not require action, not a high-priority alert. Option C is wrong because a warning event signals a potential future issue (e.g., disk usage exceeding 80%) but does not yet require immediate escalation, unlike a high-priority alert. Option D is wrong because a normal event is a standard operational occurrence (e.g., a user logging in) that is expected and does not trigger alerts.

81
Multi-Selectmedium

Which TWO statements about Problem Management are correct?

Select 2 answers
A.It includes root cause analysis to identify the underlying cause of incidents
B.It is responsible for implementing permanent fixes for recurring incidents
C.It focuses on recording and tracking individual incidents
D.It is responsible for restoring normal service operation
E.It is responsible for maintaining the known error database
AnswersA, E

Problem management fundamentally includes root cause analysis (RCA) as a core activity to systematically investigate and identify the underlying causes of incidents. This analytical process goes beyond merely restoring service, aiming to understand why incidents occur. By uncovering the true source of issues, problem management enables the development of effective solutions that prevent future recurrences, thereby improving service stability and reliability.

Why this answer

Problem management focuses on identifying root causes of incidents and managing known errors. Option A is correct because root cause analysis is a key activity. Option E is correct because maintaining the known error database is a primary responsibility.

Option B is incorrect: problem management is not responsible for implementing permanent fixes; it identifies root causes and proposes permanent solutions, but implementation is handled by other teams through change enablement. Option C is incorrect: recording and tracking individual incidents is the responsibility of incident management. Option D is incorrect: restoring normal service operation is also incident management.

82
Multi-Selecthard

Which THREE of the following are characteristics of a service request?

Select 3 answers
A.Unplanned
B.Low risk
C.Pre-approved
D.Require approval from the Change Advisory Board
E.Predefined and standardized
AnswersB, C, E

Service requests are characterized by their low inherent risk because they involve well-established, routine procedures with predictable outcomes. The potential for negative impact on IT services, users, or the business is minimal, as these requests typically concern standard offerings and have been thoroughly vetted. This low-risk profile allows for streamlined processing and often automated fulfillment without extensive scrutiny.

Why this answer

Service requests are characterized by being predefined, pre-approved, and low risk. Therefore, options B (Low risk), C (Pre-approved), and E (Predefined and standardized) are correct. Option A (Unplanned) is incorrect because service requests follow a standardized, predefined process and are not unplanned.

Option D (Require approval from the Change Advisory Board) is incorrect because service requests are pre-approved and do not require CAB approval; that is typical for normal changes.

83
MCQmedium

An organization monitors IT systems and detects an event indicating that a disk is 80% full. According to ITIL 4, what type of event is this?

A.Informational event
B.Warning event
C.Exception event
D.Error event
AnswerB

A warning event indicates a condition that is deviating from normal operational parameters but has not yet caused a service disruption or degradation. It serves as an early alert, signaling a potential future problem if left unaddressed, such as a disk approaching full capacity or high CPU utilization. Proactive intervention based on a warning event can prevent an actual incident, making it a critical classification for effective event management. The detection of an event that requires attention but isn't yet an incident aligns perfectly with a warning.

Why this answer

Events are categorized as informational, warning, or exception. A disk at 80% capacity is a warning that may require attention, not yet an exception. Option B is correct.

Option A (informational) is for routine notifications. Option C (exception) is for abnormal conditions. Option D (error) is not a standard event category.

84
MCQmedium

During a major incident, a workaround is applied by the service desk. Later, Problem Management identifies the root cause and implements a permanent fix through a normal change. Which sequence of practices is being followed?

A.Service Request Management → Incident Management → Change Enablement
B.Problem Management → Incident Management → Change Enablement
C.Change Enablement → Incident Management → Problem Management
D.Incident Management → Problem Management → Change Enablement
AnswerD

This sequence accurately reflects the ITIL 4 approach to managing service disruptions and their underlying causes. Incident Management prioritizes restoring service functionality, often via a workaround, during a major incident. Subsequently, Problem Management investigates the root cause to prevent recurrence. Finally, if a permanent solution requires a modification to a service or component, Change Enablement ensures that this change is planned, approved, and implemented in a controlled manner.

Why this answer

Incident Management restores service, Problem Management finds root cause, and Change Enablement implements the permanent fix.

85
MCQeasy

Which ITIL 4 practice has the PRIMARY purpose of restoring normal service operation as quickly as possible and minimizing the adverse impact on business operations?

A.Problem Management
B.Service Request Management
C.Incident Management
D.Change Enablement
AnswerC

Incident Management is the correct practice because its primary purpose is to minimize the negative impact of incidents by restoring normal service operation as quickly as possible. An incident is defined as an unplanned interruption to a service or a reduction in the quality of a service. This practice focuses on rapid diagnosis, workaround implementation, and resolution to ensure business continuity and user productivity are maintained.

Why this answer

Incident Management is the correct practice, as its primary purpose is to restore normal service operation as quickly as possible and minimize adverse impact on business operations. Problem Management focuses on identifying root causes of incidents, Service Request Management handles pre-defined service requests, and Change Enablement controls changes to services. Therefore, the correct answer is C: Incident Management.

86
MCQhard

A user requests new software that is already pre-approved in the service catalogue. The service desk team handles this request following a defined, automated workflow. According to ITIL 4, what type of record should be created?

A.Problem record
B.Normal change record
C.Service request record
D.Incident record
AnswerC

A service request record is the appropriate choice for a user requesting new software that is already pre-approved, as it represents a formal request for a standard, pre-defined service offering. These requests typically follow established, automated workflows and do not require additional assessment or authorization beyond the initial submission. ITIL 4 emphasizes that service requests are low-risk, frequently occurring events, making this the ideal mechanism for fulfilling such a pre-approved software provision.

Why this answer

A service request is a pre-defined, pre-approved request for something that is part of normal service delivery, such as a request for new software from the service catalogue. Option C is correct. Option A is incorrect because a problem record is used for the root cause of incidents, not for fulfilling requests.

Option B is incorrect because a normal change record is for changes that require assessment and approval, not for pre-approved items. Option D is incorrect because an incident record is for unplanned interruptions, not for standard requests.

87
MCQmedium

Which of the following describes a key difference between Incident Management and Problem Management in ITIL 4?

A.Incident Management aims to restore normal service as soon as possible; Problem Management aims to prevent incidents from happening or recurring
B.Incident Management is reactive; Problem Management is always proactive
C.Incident Management is only for major incidents; Problem Management is for minor issues
D.Incident Management always resolves the root cause; Problem Management only applies workarounds
AnswerA

Incident Management's primary objective is the swift restoration of normal service operation, minimizing business impact and returning users to productivity as quickly as possible. In contrast, Problem Management focuses on identifying and understanding the underlying causes of incidents, aiming to prevent their recurrence or to mitigate their impact if they cannot be entirely avoided. This clear distinction highlights their different but complementary roles in maintaining service stability and quality.

Why this answer

Incident Management focuses on restoring normal service operation as quickly as possible to minimize business impact, while Problem Management seeks to identify and eliminate the underlying root causes of incidents to prevent recurrence or reduce their impact. This distinction is fundamental in ITIL 4: Incident Management is about speed of recovery, Problem Management about long-term stability.

Exam trap

The trap here is confusing the reactive nature of Incident Management with the misconception that Problem Management is always proactive, when in fact Problem Management includes both reactive and proactive activities.

How to eliminate wrong answers

Option B is wrong because Problem Management can be both proactive (identifying potential causes before incidents occur) and reactive (analyzing incidents that have already happened), so it is not 'always proactive'. Option C is wrong because Incident Management handles all incidents, not just major ones, and Problem Management addresses both major and minor underlying issues. Option D is wrong because Incident Management does not resolve root causes—it restores service via workarounds or fixes—while Problem Management may apply workarounds as a temporary measure while seeking a permanent root cause resolution.

88
MCQeasy

What is the primary role of a service desk?

A.To negotiate SLAs with customers
B.To act as a single point of contact (SPOC) for users
C.To manage the lifecycle of all IT assets
D.To perform root cause analysis
AnswerB

The primary role of the Service Desk is to function as the single point of contact (SPOC) between the service provider and its users. This ensures that users have one consistent and recognizable channel for all service-related interactions, including requesting services, reporting incidents, and seeking information. By centralizing communication, the Service Desk streamlines support, improves user experience, and facilitates efficient incident resolution and service request fulfillment.

Why this answer

The primary role of a service desk is to act as a single point of contact (SPOC) for users, ensuring all incidents, service requests, and inquiries are logged, tracked, and resolved or escalated efficiently. This aligns with ITIL 4's guiding principle of 'focus on value' by providing a clear, accessible entry point for users to interact with IT services.

Exam trap

The trap here is that candidates often confuse the service desk's operational SPOC role with other ITIL practices like service level management (SLA negotiation), IT asset management (lifecycle tracking), or problem management (root cause analysis), leading them to select a plausible but incorrect option.

How to eliminate wrong answers

Option A is wrong because negotiating SLAs is a strategic activity performed by service level management, not the service desk, which focuses on operational incident and request handling. Option C is wrong because managing the lifecycle of IT assets is the responsibility of IT asset management (ITAM), which tracks hardware and software from acquisition to disposal, not the service desk's daily support role. Option D is wrong because root cause analysis is a key activity of problem management, which investigates underlying causes of incidents after they occur, whereas the service desk handles initial incident logging and resolution.

89
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To assess, authorize, and schedule changes to IT services
B.To negotiate and agree on service level targets with customers
C.To identify the root cause of incidents and prevent recurrence
D.To restore normal service as quickly as possible and minimize the negative impact on business operations
AnswerD

Incident Management aims to restore service quickly, often using workarounds.

Why this answer

The primary purpose of Incident Management is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations. Option D is correct. Option A describes Change Enablement (assessing, authorizing, and scheduling changes).

Option B describes Service Level Management (negotiating and agreeing on service level targets). Option C describes Problem Management (identifying root causes and preventing recurrence).

90
Drag & Dropmedium

Drag and drop the steps of the availability management process into the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Availability management begins with defining requirements, then designing, monitoring, analyzing, and improving.

91
MCQhard

During a major incident, the IT team implements a workaround to restore service. Later, they discover the root cause and submit a permanent fix as an emergency change. Which ITIL 4 practices are primarily involved in this sequence?

A.Incident Management, Problem Management, and Change Enablement
B.Incident Management and Problem Management only
C.Problem Management and Change Enablement only
D.Incident Management and Change Enablement only
AnswerA

Incident Management is crucial for detecting and managing the major incident, focusing on restoring service as quickly as possible. Problem Management then identifies the underlying cause and develops a workaround to mitigate the incident's impact. Finally, if implementing this workaround requires any modification to the live environment, even temporarily, Change Enablement ensures the change is properly assessed, authorized, and managed to minimize risk and prevent further disruption.

Why this answer

Incident Management restores service with a workaround; Problem Management identifies root cause; Change Enablement implements the fix. Option A includes all three practices. Option B lacks Change Enablement; Option C lacks Incident Management; Option D lacks Problem Management.

92
MCQmedium

An organization wants to improve its first call resolution rate. Which practice is most directly responsible for this metric?

A.Incident Management
B.Problem Management
C.Change Enablement
D.Service Desk
AnswerD

The Service Desk serves as the single point of contact between the service provider and its users, handling incidents, service requests, and providing information. A primary objective of the Service Desk is to resolve as many incidents and service requests as possible during the user's initial contact, directly contributing to enhanced user satisfaction and operational efficiency. First Call Resolution (FCR) is a critical and fundamental metric for evaluating the effectiveness and efficiency of Service Desk operations, as it directly quantifies their ability to resolve issues without escalation.

Why this answer

First call resolution rate is a key performance indicator for the Service Desk. The Service Desk practice is responsible for handling incidents and service requests on first contact, making FCR a direct measure of its effectiveness. Incident Management (A) focuses on restoring service, but FCR is specifically a Service Desk metric.

Problem Management (B) deals with root causes, and Change Enablement (C) manages changes, neither of which is directly measured by FCR.

93
MCQmedium

Which type of change is typically pre-approved and follows a predefined procedure?

A.Service request
B.Normal change
C.Emergency change
D.Standard change
AnswerD

Standard changes are low-risk, frequently occurring changes that are pre-authorized and follow a well-defined, documented procedure. These changes are typically initiated as service requests and do not require additional authorization each time they are implemented, as the risk has been assessed and approved in advance. Their predictable nature and established success criteria make them ideal for automation and streamlined execution, fitting the description of being pre-approved and following a procedure.

Why this answer

Standard changes are low-risk, pre-approved, and have a defined procedure. Normal changes require approval via change advisory board; emergency changes require urgent approval.

94
Multi-Selectmedium

Which TWO of the following are key metrics used to measure the performance of the Service Desk?

Select 2 answers
A.First Contact Resolution (FCR)
B.Mean Time to Resolve (MTTR)
C.Availability percentage
D.Capacity utilization
E.Customer Satisfaction Score (CSAT)
AnswersA, E

First Contact Resolution (FCR) directly satisfies the stem’s requirement for a key Service Desk metric because it measures the percentage of incidents resolved during the initial contact without escalation or callback. This quantifies both efficiency and user satisfaction, which are the two core performance axes the Service Desk must balance under the ITIL 4 framework.

Why this answer

First Contact Resolution (FCR) is a key Service Desk metric because it measures the percentage of incidents resolved during the initial contact without escalation or follow-up. A high FCR directly indicates efficiency, reduces operational costs, and improves user satisfaction by minimizing repeat interactions. ITIL 4 identifies FCR as a critical performance indicator for the Service Desk practice.

Exam trap

The trap here is that candidates often confuse MTTR as a Service Desk metric, but MTTR applies to the entire incident lifecycle across multiple support tiers, whereas FCR and CSAT are the two metrics specifically tied to the Service Desk's first-contact performance and user satisfaction.

95
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To find the root cause of incidents and prevent recurrence
B.To manage the lifecycle of all changes in the IT environment
C.To restore normal service operation as quickly as possible
D.To negotiate and agree on service level agreements
AnswerC

This is the correct primary purpose of the Incident Management practice according to ITIL 4. The practice aims to minimize the negative impact of incidents by restoring normal service operation as quickly as possible, ensuring that business processes can resume with minimal disruption. This often involves using temporary workarounds to restore functionality rapidly, even before a permanent solution to the underlying problem is found.

Why this answer

The primary purpose of Incident Management is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations. This is achieved through a structured lifecycle that includes logging, categorization, prioritization, escalation, and resolution of incidents. The focus is on speed of recovery, not root cause analysis, which belongs to Problem Management.

Exam trap

The trap here is that candidates confuse Incident Management with Problem Management, assuming that finding root causes is part of incident handling, but ITIL 4 explicitly separates these to ensure incidents are resolved quickly without delaying recovery for analysis.

How to eliminate wrong answers

Option A is wrong because finding the root cause of incidents and preventing recurrence is the purpose of Problem Management, not Incident Management. Option B is wrong because managing the lifecycle of all changes in the IT environment is the purpose of Change Enablement (formerly Change Management). Option D is wrong because negotiating and agreeing on service level agreements is the purpose of Service Level Management, not Incident Management.

96
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. According to ITIL 4, what should the analyst do FIRST?

A.Escalate to the service desk manager immediately
B.Log the incident and attempt to restore service
C.Initiate a problem record to find the root cause
D.Submit a change request to fix the system
AnswerB

Logging the incident is the foundational first step in the ITIL Incident Management practice, providing a formal record for tracking, communication, and analysis. Following this, the primary objective is to restore normal service operation as quickly as possible to minimize business impact. The service desk analyst should then proceed with initial diagnosis and attempt to resolve the incident based on available knowledge and tools before considering other actions.

Why this answer

The first step in incident management is to log and classify the incident to restore service as soon as possible. Root cause analysis belongs to problem management, which is initiated later if needed.

97
MCQhard

What is the difference between utility and warranty in ITIL 4?

A.Utility is about availability; warranty is about functionality
B.Utility is about cost; warranty is about value
C.Utility is about outputs; warranty is about outcomes
D.Utility is about functionality; warranty is about assurance
AnswerD

This is correct.

Why this answer

In ITIL 4, utility is defined as 'fit for purpose' — the functionality provided by a service to meet a specific user need, such as enabling a task or achieving an outcome. Warranty is defined as 'fit for use' — the assurance that the service will perform as agreed, covering availability, capacity, continuity, and security. Option D correctly captures this distinction: utility is about what the service does (functionality), while warranty is about how it is delivered reliably (assurance).

Exam trap

The trap here is that candidates often confuse utility with outputs or availability, but ITIL 4 strictly defines utility as functionality (what the service does) and warranty as assurance (how it is delivered reliably), not as performance metrics or cost factors.

How to eliminate wrong answers

Option A is wrong because it reverses the definitions: utility is about functionality, not availability, and warranty is about assurance (including availability), not functionality. Option B is wrong because utility and warranty are not defined in terms of cost or value; value is created by the combination of utility and warranty, not by one alone. Option C is wrong because it confuses the service value chain concepts: outputs are the tangible results of activities, while outcomes are the business results achieved; utility and warranty both contribute to outcomes, but this is not their defining difference.

98
MCQeasy

Which practice involves the use of a service catalogue for predefined offerings?

A.Service Request Management
B.Change Enablement
C.Problem Management
D.Incident Management
AnswerA

Service Request Management is the practice of supporting the agreed quality of a service by handling all pre-defined, user-initiated requests. These requests are typically standardized, often automated, and are prominently featured in a service catalogue, which acts as the primary interface for users to browse and order available services and their associated requests. The catalogue provides clear descriptions, fulfillment times, and costs, making it integral to the efficient processing of service requests.

Why this answer

Service Request Management uses the service catalogue to offer standardized, pre-approved requests.

99
MCQeasy

What is the PRIMARY purpose of the Service Desk practice?

A.To manage the lifecycle of all incidents
B.To monitor and manage IT services proactively
C.To analyze root causes of incidents
D.To provide a single point of contact for users
AnswerD

The primary purpose of the Service Desk practice is to establish and maintain a single point of contact (SPOC) between the service provider and its users. This ensures that users have one consistent, identifiable channel for all service-related interactions, including logging incidents, requesting services, making inquiries, and receiving communication. This centralized approach streamlines user experience and facilitates efficient communication flow within the service organization.

Why this answer

The Service Desk provides a single point of contact for users to report issues, ask questions, and request services.

100
Multi-Selecthard

Which TWO statements correctly describe the difference between Incident Management and Problem Management?

Select 2 answers
A.Problem Management includes the use of workarounds from known errors.
B.Problem Management is part of the Service Desk.
C.Incident Management is reactive; Problem Management is always proactive.
D.Incident Management aims to restore service quickly; Problem Management aims to find the root cause.
E.Incident Management is only for major incidents.
AnswersA, D

Problem Management is responsible for identifying the root causes of incidents and, when a root cause is known but a permanent fix is not yet available, it establishes and documents a "known error." Crucially, Problem Management then develops and manages workarounds associated with these known errors, providing temporary solutions that Incident Management can utilize to restore service quickly while a permanent resolution is pursued. This systematic approach minimizes the impact of recurring issues.

Why this answer

Incident Management focuses on restoring service; Problem Management focuses on finding root causes. Problem Management may use workarounds from known errors.

101
Multi-Selecthard

Which THREE of the following are key activities of Service Configuration Management?

Select 3 answers
A.Identifying and documenting configuration items (CIs)
B.Authorizing and scheduling changes to CIs
C.Maintaining the configuration management database (CMDB)
D.Verifying and auditing configuration records against actual state
E.Defining service level targets with customers
AnswersA, C, D

Identifying and documenting CIs is a core activity of Service Configuration Management.

Why this answer

Identifying and documenting configuration items (CIs) is a foundational activity of Service Configuration Management. It ensures that all components of the IT infrastructure, including hardware, software, and documentation, are uniquely identified and recorded in the configuration management database (CMDB) to support control and traceability.

Exam trap

The trap here is confusing the activities of Service Configuration Management with those of Change Management or Service Level Management, as ITIL 4F often tests the precise boundaries between practices by listing overlapping but distinct responsibilities.

102
MCQeasy

What is the difference between utility and warranty in ITIL 4?

A.Utility is about cost; warranty is about quality
B.Utility is for customers; warranty is for users
C.Utility is about functionality; warranty is about performance and availability
D.Utility is provided by the service provider; warranty is provided by the customer
AnswerC

Utility precisely describes the functionality a service provides, addressing what the service does and whether it is 'fit for purpose' in supporting customer outcomes. Warranty, conversely, focuses on the non-functional aspects, ensuring the service is 'fit for use' through guaranteed levels of performance, availability, capacity, and security. This distinction highlights that a service must not only do what is needed but also do it reliably and consistently.

Why this answer

Utility is 'fit for purpose' (does it do what it should?), while warranty is 'fit for use' (is it available, secure, etc.?).

103
MCQmedium

Which change type is pre-authorized and follows a defined procedure?

A.Emergency change
B.Service change
C.Normal change
D.Standard change
AnswerD

Standard changes are pre-authorized, low-risk changes that are frequently implemented and follow a well-documented, repeatable procedure. Because their risks are understood and managed, they do not require individual assessment and approval each time they are performed. This pre-authorization allows for efficient execution, aligning perfectly with the description of a change that is pre-authorized and follows a defined process.

Why this answer

Standard changes are pre-authorized and follow a defined, low-risk procedure, such as applying a routine security patch or provisioning a new user account. They do not require additional approval because the risk is well-understood and the implementation steps are documented in a standard operating procedure (SOP). This aligns with ITIL 4's definition of a standard change as a change that is fully documented, low risk, and can be implemented without a formal change advisory board (CAB) meeting.

Exam trap

The trap here is that candidates confuse 'pre-authorized' with 'no change record needed'—standard changes still require a change record for tracking, but they skip the approval step because the procedure is already approved.

How to eliminate wrong answers

Option A is wrong because an emergency change is not pre-authorized; it requires urgent approval (often via an emergency CAB) and follows a separate, accelerated procedure to address high-impact incidents. Option B is wrong because 'service change' is a generic term in ITIL 4 for any change affecting a service, not a specific change type with pre-authorization and a defined procedure. Option C is wrong because a normal change requires formal assessment and approval by the change authority (e.g., CAB) before implementation; it is not pre-authorized.

104
MCQmedium

Which practice ensures that the performance of a service is measured and analyzed to meet current and future demand?

A.IT Asset Management
B.Availability Management
C.Capacity and Performance Management
D.Service Configuration Management
AnswerC

Capacity and Performance Management ensures that services and their components can meet current and future demand in a cost-effective manner, while achieving agreed performance targets. This practice involves monitoring, analyzing, and tuning service performance, such as response times, throughput, and resource utilization, to prevent bottlenecks and ensure optimal operation under various loads. It directly addresses the 'how well' a service performs to deliver value.

Why this answer

Capacity and Performance Management ensures that services meet agreed and expected performance levels to satisfy current and future demand. Option C is correct because it directly focuses on measuring and analyzing service performance. Option A (IT Asset Management) manages the lifecycle of assets, not performance.

Option B (Availability Management) focuses on ensuring services are available when required, not specifically on performance measurement and analysis. Option D (Service Configuration Management) maintains information about configuration items, not performance.

105
MCQmedium

Which type of change requires assessment and authorization by a change authority, but does not follow a pre-approved procedure?

A.Emergency change
B.Normal change
C.Service request
D.Standard change
AnswerB

Normal changes are those that are not standard (pre-authorized) or emergency (expedited). They require a full assessment of risk and impact, followed by formal authorization, typically by a Change Authority or Change Advisory Board (CAB), before implementation. This structured process ensures proper planning, resource allocation, and stakeholder communication, making them the type of change that precisely fits the description of requiring both assessment and authorization.

Why this answer

A normal change is any change that is not a standard change or an emergency change. It requires assessment and authorization by a change authority (e.g., the Change Manager or Change Advisory Board) but does not follow a pre-approved, low-risk procedure. This distinguishes it from standard changes, which are pre-authorized and follow a documented procedure.

Exam trap

The trap here is confusing 'normal change' with 'standard change' — candidates often assume that any change requiring authorization must follow a pre-approved procedure, but standard changes are the only type that are pre-authorized and follow a documented procedure, while normal changes require individual assessment.

How to eliminate wrong answers

Option A is wrong because an emergency change is a type of change that must be implemented as soon as possible (e.g., to resolve a major incident) and, while it also requires authorization, it follows a specific emergency change procedure (often with a separate emergency change authority) and is not defined by lacking a pre-approved procedure. Option C is wrong because a service request is a pre-defined, low-risk request from a user (e.g., password reset, access grant) that follows a standard, pre-approved procedure and typically does not require a separate change authority assessment. Option D is wrong because a standard change is a low-risk, pre-authorized change that follows a pre-approved procedure (e.g., applying a routine security patch) and does not require individual assessment by a change authority.

106
MCQhard

An IT team discovers that a recurring incident is caused by a known software bug. According to ITIL 4, what should be created to document this situation?

A.A known error record
B.A problem record
C.A change request
D.An incident record
AnswerA

A known error record is created when the root cause of a problem has been identified, but a permanent resolution has not yet been implemented. It serves to document the identified cause, symptoms, and any temporary workarounds, enabling incident management to quickly resolve recurring incidents by applying the documented solution and minimizing service impact.

Why this answer

A known error is documented when the root cause is identified and a workaround exists; it is part of Problem Management's error control phase.

107
Multi-Selecthard

Which THREE of the following are purposes or outputs of the Continual Improvement practice?

Select 3 answers
A.Maintaining an improvement register
B.Ensuring services are aligned with evolving business needs
C.Following the ITIL continual improvement model
D.Resolving incidents within agreed times
E.Assessing and authorizing changes
AnswersA, B, C

The continual improvement practice is responsible for maintaining an improvement register, which is a structured database or log of improvement opportunities. This register captures details such as the nature of the opportunity, its potential value, current status, and responsible parties. It serves as a central repository to track and manage all improvement initiatives across the organization, ensuring that identified opportunities are not lost and progress can be monitored effectively. This systematic approach is crucial for driving ongoing service and product enhancements.

Why this answer

Continual improvement uses the improvement register, follows the 7-step model, and aims to align services with business needs.

108
Multi-Selectmedium

Which TWO are components of the ITIL 4 Continual Improvement Model?

Select 2 answers
A.Define improvement objectives
B.Where are we now?
C.How do we keep momentum?
D.Plan the improvement
E.How do we get there?
AnswersB, E

"Where are we now?" is correctly identified as the second step in the ITIL 4 Continual Improvement Model. This phase is dedicated to conducting a thorough assessment of the current state of services, products, or practices. It involves gathering data, analyzing performance, identifying existing capabilities, and understanding the baseline from which improvements will be measured, providing a clear picture of the starting point.

Why this answer

The ITIL 4 Continual Improvement Model consists of seven steps: What is the vision?, Where are we now?, Where do we want to be?, How do we get there?, Take action, Did we get there?, and How do we keep the momentum going? The two correct components from the options are B ("Where are we now?") and E ("How do we get there?"). Options A, C, and D are not steps in the model.

109
MCQhard

Which practice in ITIL 4 includes the activities of problem identification, problem control, and error control?

A.Incident Management
B.Change Enablement
C.Service Level Management
D.Problem Management
AnswerD

Problem Management includes problem identification, problem control, and error control.

Why this answer

Problem Management is the ITIL 4 practice specifically designed to manage the lifecycle of all problems. Its core activities are problem identification (detecting and logging problems), problem control (analyzing and documenting workarounds and root causes), and error control (managing known errors through the lifecycle until a permanent resolution is implemented).

Exam trap

The trap here is that candidates confuse Incident Management's focus on restoring service quickly with Problem Management's focus on finding and fixing root causes, especially since both practices handle service disruptions.

How to eliminate wrong answers

Option A is wrong because Incident Management focuses on restoring normal service operation as quickly as possible after an incident, not on identifying root causes or controlling known errors. Option B is wrong because Change Enablement manages the lifecycle of changes to IT services, ensuring standardized methods and procedures for efficient handling of changes, not problem analysis. Option C is wrong because Service Level Management negotiates, agrees, and monitors service level agreements (SLAs) and does not involve problem identification or error control activities.

110
MCQhard

An organization is implementing a new monitoring tool. Which type of event should trigger an immediate response from the IT team?

A.Scheduled event
B.Exception event
C.Warning event
D.Informational event
AnswerB

An exception event signifies a critical deviation from the expected normal operation of a service or component, often indicating a service degradation or failure. When a new monitoring tool identifies an issue, particularly one that warrants attention, it is typically flagging an unexpected condition that requires immediate investigation and potential intervention to restore service or prevent further impact. These events demand prompt action due to their potential for significant business disruption.

Why this answer

Exception events indicate a failure or breach of threshold and require immediate action.

111
MCQeasy

What is the main difference between a standard change and a normal change?

A.A standard change cannot be scheduled, while a normal change can be scheduled
B.A standard change is only used for emergency fixes, while a normal change is for planned improvements
C.A standard change is pre-approved and follows a defined procedure, while a normal change requires approval from a change authority
D.A standard change has no defined procedure, while a normal change has a defined procedure
AnswerC

A standard change is characterized by its pre-authorization, meaning it has already undergone risk assessment and approval, allowing for immediate implementation upon request or trigger, following a strict, documented procedure. Conversely, a normal change requires a formal assessment and explicit approval from a designated change authority, such as a Change Advisory Board (CAB) or an individual, before it can proceed. This distinction in the approval mechanism is fundamental to ITIL 4's change enablement practice, balancing speed with control.

Why this answer

Standard changes are pre-approved and follow a defined procedure, making them low risk and routine. Normal changes, on the other hand, require approval from a change authority (such as a CAB) because they are not pre-approved and may involve higher risk. Option A is incorrect because standard changes can be scheduled; Option B is incorrect because standard changes are not only for emergencies; Option D is incorrect because standard changes have a defined procedure.

112
MCQeasy

Which ITIL practice is responsible for negotiating and agreeing on service level targets?

A.Supplier Management
B.Capacity and Performance Management
C.Availability Management
D.Service Level Management
AnswerD

Service Level Management is the dedicated practice responsible for defining, negotiating, and agreeing upon service level targets with customers. It establishes Service Level Agreements (SLAs) that document these agreed expectations, then monitors and reports on the actual performance of services against these targets, ensuring a clear understanding and alignment between service providers and consumers.

Why this answer

Service Level Management is responsible for negotiating, agreeing, and monitoring service level targets. Option D is correct. Option A (Supplier Management) deals with suppliers and contracts.

Option B (Capacity and Performance Management) ensures services meet capacity demands. Option C (Availability Management) ensures services are available as agreed.

113
MCQhard

What is the key difference between Deployment Management and Release Management in ITIL 4?

A.Deployment Management is part of Release Management
B.Release Management ensures the service is available for use; Deployment Management moves components into the live environment
C.Release Management is only for major releases; Deployment Management is for all releases
D.Deployment Management focuses on moving to production; Release Management focuses on building the release
AnswerB

This correctly distinguishes the two practices.

Why this answer

Release Management is responsible for making new or changed services available for use, which includes the decision to deploy and the overall coordination of the release. Deployment Management, in contrast, handles the technical movement of service components (e.g., software, hardware, documentation) into the live environment, ensuring they are installed, tested, and ready. This separation allows Release Management to focus on value and risk, while Deployment Management focuses on the technical execution.

Exam trap

The trap here is that candidates confuse the terms 'deployment' and 'release' as synonyms, but ITIL 4 defines them as separate practices with different scopes—deployment is the technical act of moving components, while release is the broader business decision to make the service available.

How to eliminate wrong answers

Option A is wrong because Deployment Management and Release Management are distinct practices in ITIL 4, not hierarchical; Deployment Management is not a sub-process of Release Management, though they are closely coordinated. Option C is wrong because Release Management applies to all releases (major, minor, emergency), not just major ones, and Deployment Management also handles all types of deployments. Option D is wrong because Release Management does not focus on building the release (that is the role of Service Design and Software Development); Release Management focuses on the overall planning, authorization, and making the service available, while Deployment Management focuses on moving components to production.

114
Multi-Selectmedium

Which TWO of the following are types of events in Monitoring and Event Management?

Select 2 answers
A.Critical
B.Informational
C.Standard
D.Emergency
E.Warning
AnswersB, E

Informational events provide general data about the normal operation of a service, system, or component. They indicate routine activities, successful operations, or status changes that do not typically require immediate action but are crucial for auditing, trend analysis, and understanding system behavior over time. These events confirm that processes are functioning as expected.

Why this answer

In ITIL 4, Monitoring and Event Management defines three event types: Informational, Warning, and Exception. Informational events (option B) are routine notifications that indicate normal operations, such as a successful backup completion or a device powering on. They require no action but are logged for audit or trend analysis.

Exam trap

The trap here is that candidates confuse ITIL event types with incident priority levels (Critical, Emergency) or change categories (Standard), leading them to select options that are valid in other ITIL practices but not in Monitoring and Event Management.

115
MCQmedium

A major outage has occurred, and the IT team needs to implement a fix immediately without following the normal change authorization process. According to ITIL 4, what type of change should be raised?

A.Normal change
B.Emergency change
C.Standard change
D.Service request
AnswerB

Emergency changes are specifically designed for urgent situations, such as resolving a major outage, where immediate action is required to restore service functionality. They involve an expedited assessment and authorization process, often with retrospective documentation and approval, to minimize service disruption and mitigate severe business impact. This streamlined approach prioritizes speed over full formality to address critical incidents and major incidents effectively.

Why this answer

Emergency changes are for urgent situations that require immediate implementation to restore service. They have a separate, faster authorization process.

116
MCQeasy

Which practice is responsible for managing the lifecycle of hardware and software assets?

A.Service Configuration Management
B.Supplier Management
C.IT Asset Management
D.Capacity and Performance Management
AnswerC

IT Asset Management is the practice responsible for planning, monitoring, and controlling the full lifecycle of IT assets, from their acquisition and deployment through maintenance, utilization, and eventual disposal. This comprehensive approach ensures that the organization maximizes value, controls costs, manages risks, and supports decision-making related to the entire inventory of IT hardware, software, and information assets.

Why this answer

IT Asset Management manages the lifecycle of IT assets. Option C is correct. Service Configuration Management manages configuration items and their relationships.

Capacity Management focuses on performance. Supplier Management manages vendors.

117
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To fulfil service requests from users
B.To manage the lifecycle of all changes
C.To restore normal service operation as quickly as possible
D.To find the root cause of incidents
AnswerC

This is the core purpose of Incident Management.

Why this answer

The primary purpose of Incident Management is to restore normal service operation as quickly as possible and minimise the adverse impact on business operations.

118
MCQeasy

What is the PRIMARY role of a Service Desk in ITIL 4?

A.To manage the CMDB
B.To approve changes
C.To be the single point of contact between users and IT
D.To analyse incident trends
AnswerC

The Service Desk's fundamental and primary role is to act as the Single Point of Contact (SPOC) for all users, facilitating seamless communication between them and the various IT services and teams. This crucial function ensures that users have a consistent, accessible, and reliable channel for logging incidents, requesting services, seeking information, and receiving timely updates. By centralizing initial interactions, the Service Desk effectively manages user expectations, streamlines support processes, and directs inquiries to the appropriate resolution groups, significantly enhancing the overall user experience.

Why this answer

The service desk serves as the single point of contact (SPOC) for users to report issues and request services.

119
MCQeasy

Which type of change is pre-approved and follows a low-risk, well-defined procedure?

A.Service request
B.Normal change
C.Standard change
D.Emergency change
AnswerC

A standard change is a pre-authorized change that is low-risk, relatively common, and follows a documented procedure or work instruction. These changes are typically well-understood, have a proven implementation plan, and are often initiated as service requests. Because their risk is assessed and approved in advance, they do not require additional authorization each time they are implemented, aligning perfectly with the description of being pre-approved and low-risk.

Why this answer

Standard changes are pre-approved with a defined procedure.

120
MCQeasy

What is the purpose of the Continual Improvement practice?

A.To ensure services meet agreed levels of availability
B.To align IT services with changing business needs through ongoing improvements
C.To provide a single point of contact for users
D.To manage the lifecycle of all IT assets
AnswerB

This accurately defines the core purpose of the Continual Improvement practice. It emphasizes the critical need for IT services to remain relevant and valuable by adapting to evolving organizational objectives and external market conditions. This is achieved through a structured, iterative approach to identify, prioritize, and implement enhancements across all products, services, and practices, ensuring sustained value co-creation.

Why this answer

The Continual Improvement practice ensures that IT services remain aligned with evolving business needs by systematically identifying and implementing improvements. This is the core purpose defined in ITIL 4, focusing on ongoing enhancement of services, processes, and capabilities rather than maintaining a static state.

Exam trap

The trap here is that candidates often confuse Continual Improvement with other practices like Availability Management or Change Enablement, because all involve making changes, but Continual Improvement is specifically about ongoing, business-driven enhancements rather than reactive fixes or asset tracking.

How to eliminate wrong answers

Option A is wrong because ensuring services meet agreed levels of availability is the purpose of the Availability Management practice, not Continual Improvement. Option C is wrong because providing a single point of contact for users is the purpose of the Service Desk function, which is part of the Service Operation lifecycle. Option D is wrong because managing the lifecycle of all IT assets is the purpose of the IT Asset Management practice, which focuses on tracking and controlling assets from acquisition to disposal.

121
MCQeasy

Which of the following is the CORRECT sequence of phases in the Problem Management practice?

A.Problem Control, Error Control, Problem Identification
B.Problem Identification, Error Control, Problem Control
C.Problem Identification, Problem Control, Error Control
D.Error Control, Problem Control, Problem Identification
AnswerC

This sequence accurately represents the phases of ITIL Problem Management. Problem Identification is the crucial first step, involving the detection and logging of problems. This is followed by Problem Control, which focuses on root cause analysis and managing workarounds to minimize the impact of unresolved problems. Finally, Error Control is executed to implement permanent solutions for known errors, thereby preventing recurrence and reducing future incidents.

Why this answer

The correct sequence in the Problem Management practice is Problem Identification, Problem Control, and Error Control. Problem Identification detects and logs problems from incidents or proactive analysis; Problem Control performs root cause analysis and documents workarounds; Error Control manages known errors through the lifecycle until a permanent resolution is implemented. This order ensures that problems are first recognized, then analyzed, and finally resolved.

Exam trap

The trap here is that candidates confuse the order of Problem Control and Error Control, mistakenly thinking Error Control comes first because it sounds like 'fixing errors,' but in ITIL 4, Error Control follows Problem Control after root cause is established.

How to eliminate wrong answers

Option A is wrong because it starts with Problem Control before problems are even identified, which is logically impossible. Option B is wrong because it places Error Control before Problem Control, but Error Control depends on the root cause analysis and workaround documentation completed in Problem Control. Option D is wrong because it begins with Error Control, which requires a known error from Problem Control, and ends with Problem Identification, which must occur first to initiate the practice.

122
MCQhard

Which of the following best distinguishes an output from an outcome in ITIL 4?

A.An output is a deliverable, while an outcome is the result for the stakeholder
B.An output is the value created, while an outcome is the metric used
C.An output is the result of an activity, while an outcome is the cost of the activity
D.An output is what the service does, while an outcome is how it is delivered
AnswerA

This option correctly distinguishes an output from an outcome according to ITIL 4 principles. An output is a tangible or intangible deliverable produced by an activity or service, such as a new software release or a processed report. Conversely, an outcome represents the actual result or benefit realized by a stakeholder from consuming or utilizing that output, focusing on the value created or the change in state achieved for them.

Why this answer

An output is a tangible deliverable, while an outcome is the result for the stakeholder. Option A is correct. Option B reverses the definitions; Option C is about utility vs warranty; Option D is incorrect.

123
MCQeasy

Which of the following is a type of change that is pre-approved and follows a defined procedure?

A.Standard change
B.Service request
C.Normal change
D.Emergency change
AnswerA

Standard changes are pre-approved and routine.

Why this answer

A standard change is a pre-approved change that follows a defined procedure, such as a low-risk, routine activity like applying a security patch or provisioning a new user account. ITIL 4 defines standard changes as having a documented, repeatable process that does not require additional authorization each time, making option A correct.

Exam trap

The trap here is confusing a 'service request' (which is a request for service delivery, not a change) with a 'standard change' (which is a pre-approved change type), leading candidates to incorrectly select service request when the question specifically asks for a type of change.

How to eliminate wrong answers

Option B (Service request) is wrong because a service request is a formal request for something to be provided (e.g., access, information), not a type of change; it may or may not involve a change, and it is not inherently pre-approved as a change category. Option C (Normal change) is wrong because a normal change requires assessment and authorization through the change advisory board (CAB) or equivalent, and is not pre-approved. Option D (Emergency change) is wrong because an emergency change is a high-urgency change that must be implemented as quickly as possible, often with expedited authorization, and is not pre-approved in the same way as a standard change.

124
Multi-Selecthard

Which THREE of the following are considered events in the Monitoring and Event Management practice?

Select 3 answers
A.A user requesting a password reset
B.A user reporting an application crash
C.A server CPU utilization exceeding a threshold
D.A disk drive failure alert
E.A backup job completing successfully
AnswersC, D, E

A server CPU utilization exceeding a predefined threshold is a classic example of a warning event. This notification, typically generated by monitoring tools, indicates a change in the state of a configuration item that could potentially lead to a service degradation or incident if not addressed. It serves as an early alert, allowing proactive intervention before a critical failure occurs.

Why this answer

In the Monitoring and Event Management practice, an event is any change of state that has significance for the management of a service or configuration item. Option C is correct because a server CPU utilization exceeding a threshold is a predefined condition that triggers an event, often an 'alert' or 'warning' event, which is automatically detected by monitoring tools (e.g., SNMP traps, Prometheus alerts) and requires attention or automated response.

Exam trap

The trap here is confusing user-initiated communications (requests, incident reports) with system-generated events, leading candidates to incorrectly select A or B because they think any 'notification' qualifies as an event.

125
Multi-Selectmedium

Which TWO of the following are roles involved in Change Enablement?

Select 2 answers
A.Change Authority
B.Service Desk Manager
C.Problem Manager
D.Supplier Manager
E.Change Manager
AnswersA, E

The Change Authority is responsible for authorizing changes, balancing the potential benefits against the risks involved. This role ensures that changes are properly assessed and approved before implementation, preventing unauthorized or high-risk modifications to services. Depending on the type and impact of the change, this authority can be a single individual, a change advisory board (CAB), or even an automated system for standard changes.

Why this answer

Change Enablement involves a Change Authority (who approves changes) and a Change Manager (who oversees the process). The Service Desk Manager is not necessarily involved.

126
MCQmedium

Which practice ensures that the availability of a service meets the agreed requirements?

A.Service Level Management
B.Availability Management
C.Capacity Management
D.Continual Improvement
AnswerB

Availability Management is the dedicated practice responsible for ensuring that services and components are available when needed, meeting or exceeding agreed-upon availability targets. This practice involves proactively planning, designing, implementing, and maintaining the resilience, reliability, and recoverability of IT services and infrastructure. It encompasses activities like availability planning, monitoring, analysis of availability events, and implementing improvements to maximize service uptime and minimize disruption.

Why this answer

Availability Management is responsible for ensuring services are available as agreed in SLAs.

127
MCQeasy

Which type of change is pre-approved and has a defined procedure?

A.Standard change
B.Service request
C.Normal change
D.Emergency change
AnswerA

Standard changes are pre-approved and have a defined procedure.

Why this answer

Standard changes are low-risk, pre-approved, and follow a defined procedure.

128
MCQmedium

A service desk measures the percentage of calls resolved on first contact. Which metric is this?

A.Customer Satisfaction Score (CSAT)
B.Mean Time to Resolve (MTTR)
C.Service Level Achievement
D.First Contact Resolution (FCR)
AnswerD

First Contact Resolution (FCR) is a fundamental service desk metric that precisely measures the percentage of customer inquiries, incidents, or service requests that are completely resolved during the customer's initial interaction with the service desk. This means the customer does not need to call back, email again, or be transferred to another support agent for the same issue. It directly quantifies the efficiency of resolving issues at the first point of contact, aligning perfectly with 'percentage of calls resolved on' the first attempt.

Why this answer

First Contact Resolution (FCR) is the correct metric because it specifically measures the percentage of calls resolved during the initial contact with the service desk, without requiring a callback, escalation, or follow-up. This aligns directly with the question's definition, as FCR is a key performance indicator (KPI) in ITIL 4 for evaluating service desk efficiency and user satisfaction.

Exam trap

The trap here is that candidates often confuse FCR with MTTR, assuming that resolving quickly on first contact is the same as measuring resolution time, but MTTR focuses on duration rather than the count of first-contact resolutions.

How to eliminate wrong answers

Option A is wrong because Customer Satisfaction Score (CSAT) measures overall user satisfaction with a service or interaction, typically via post-interaction surveys, not the percentage of calls resolved on first contact. Option B is wrong because Mean Time to Resolve (MTTR) measures the average time taken to resolve an incident from the moment it is reported, not the proportion of calls resolved on first contact. Option C is wrong because Service Level Achievement measures whether a service meets predefined targets (e.g., response time or resolution time), not the specific metric of first-contact resolution rate.

129
Multi-Selectmedium

Which THREE of the following are key activities of the Continual Improvement practice?

Select 3 answers
A.Defining improvement initiatives based on stakeholder feedback
B.Negotiating and agreeing service level targets
C.Maintaining an improvement register
D.Applying the ITIL continual improvement model
E.Monitoring and responding to events
AnswersA, C, D

Continual Improvement actively seeks input from various stakeholders, including customers, users, and internal teams, to identify areas for enhancement. This feedback is crucial for understanding current service performance, identifying pain points, and defining specific, actionable improvement initiatives that align with organizational objectives and deliver tangible value. These initiatives then form the basis for the "What do we want to be?" step within the continual improvement model.

Why this answer

The key activities of the Continual Improvement practice include defining improvement initiatives based on stakeholder feedback (A), maintaining an improvement register (C), and applying the ITIL continual improvement model (D). Option B (negotiating and agreeing service level targets) is a key activity of Service Level Management, not Continual Improvement. Option E (monitoring and responding to events) belongs to Monitoring and Event Management.

Therefore, the correct answers are A, C, and D.

130
MCQmedium

A service desk team is overwhelmed by repeated incidents caused by a known software bug that the vendor has not yet patched. The IT manager wants to reduce the number of incidents without waiting for the vendor. Which ITIL practice would directly help in reducing the impact of this known issue?

A.Renegotiate service level targets with the customer in Service Level Management
B.Create a known error record in Problem Management and provide a workaround
C.Implement a faster incident resolution process in Incident Management
D.Submit a change request to Change Enablement to replace the software
AnswerB

Creating a known error record in Problem Management is the most appropriate action because it acknowledges a recurring issue with an identified root cause, even if a permanent solution is not yet available. Documenting a workaround enables the service desk to resolve future instances of this specific incident more efficiently and consistently, significantly reducing the impact and the burden of repeated calls while a permanent fix is pursued.

Why this answer

Problem Management aims to identify the root cause of incidents and provide workarounds or permanent solutions. In this scenario, creating a known error record and providing a workaround directly reduces the impact of the known bug. Option A is incorrect because Service Level Management focuses on setting and managing service level targets, not on addressing the technical problem.

Option C is incorrect because Incident Management is about restoring service quickly after an incident occurs, but it does not proactively address the underlying known error. Option D is incorrect because Change Enablement manages the lifecycle of changes, but replacing the software may not be feasible or immediate, and it is not the practice specifically designed to handle known errors.

131
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. What should they do FIRST according to ITIL 4?

A.Apply a workaround to restore service
B.Escalate the issue to the Problem Management team
C.Investigate the root cause of the issue
D.Log the incident in the IT service management tool
AnswerD

Logging the incident in the IT service management (ITSM) tool is the fundamental and mandatory first step for an IT service desk analyst. This action formally records the incident, captures all initial details such as caller information, symptoms, and impact, and initiates the Incident Management process. Proper logging ensures the incident is tracked, prioritized, and managed effectively through its lifecycle, providing a basis for communication and resolution.

Why this answer

The first step is to log the incident, which captures details and initiates the incident management process.

132
MCQmedium

A major incident has occurred. After restoring service, the team wants to update the Known Error Database (KEDB) with the workaround. Which practice is primarily responsible for this?

A.Service Desk
B.Change Enablement
C.Incident Management
D.Problem Management
AnswerD

Problem Management controls known errors and updates the KEDB.

Why this answer

Problem Management is responsible for managing the lifecycle of all problems, including updating the Known Error Database (KEDB) with workarounds. After a major incident is resolved, the workaround is documented in the KEDB by Problem Management to prevent future incidents and enable faster resolution. This aligns with ITIL 4's definition of Problem Management as the practice that identifies, analyzes, and documents known errors and workarounds.

Exam trap

The trap here is that candidates confuse the immediate service restoration (Incident Management) with the subsequent documentation of workarounds (Problem Management), leading them to select Incident Management instead of Problem Management.

How to eliminate wrong answers

Option A is wrong because the Service Desk is the single point of contact for users and handles incident logging and initial support, but it does not own the KEDB or the process of documenting workarounds—that is a Problem Management responsibility. Option B is wrong because Change Enablement focuses on controlling the lifecycle of changes to IT services, not on updating the KEDB with workarounds; its primary concern is risk assessment and approval of changes. Option C is wrong because Incident Management is responsible for restoring normal service operation as quickly as possible, but the KEDB update is a post-incident activity that falls under Problem Management to analyze root causes and prevent recurrence.

133
MCQmedium

A problem manager has identified multiple incidents with no known cause. Which phase of Problem Management is being performed?

A.Problem identification
B.Problem control
C.Error control
D.Post-implementation review
AnswerA

When a problem manager observes 'multiple incidents with no known cause,' this directly triggers the Problem Identification phase. This initial stage of the Problem Management practice is dedicated to detecting and logging potential problems, often by analyzing incident trends or significant single events that indicate an underlying structural flaw. It's about recognizing that a problem exists before diving into its root cause.

Why this answer

Problem identification involves detecting problems from incidents and other sources. In this scenario, the problem manager is identifying a problem from incidents, which is the first phase. Option A is correct.

Option B involves root cause analysis. Option C involves managing known errors. Option D is not a separate phase.

134
Multi-Selecthard

Which THREE statements correctly describe the difference between Deployment Management and Release Management in ITIL 4?

Select 3 answers
A.Release Management decides when to deploy a release
B.Release Management involves physically moving components to production
C.Release Management can decide to postpone a deployment
D.Release Management is responsible for the actual deployment of components
E.Deployment Management is a subset of Release Management
AnswersA, C, E

Release Management is strategically responsible for ensuring that new or changed services are made available for use, which includes the critical decision of when a release package should be deployed into the live environment. This involves coordinating with various stakeholders, assessing readiness, managing risks, and obtaining necessary authorizations before giving the green light for the deployment activity to commence. Its authority lies in the overall scheduling and timing of the release.

Why this answer

In ITIL 4, Deployment Management is a subset of Release Management. Release Management has the authority to decide when to deploy a release and can postpone deployment if needed. Option A is correct because Release Management decides the deployment timing.

Option C is correct because Release Management can postpone a deployment. Option E is correct because Deployment Management is indeed a subset of Release Management. Option B is incorrect because Release Management does not physically move components; that is the role of Deployment Management.

Option D is incorrect because Deployment Management, not Release Management, is responsible for the actual deployment.

135
Multi-Selectmedium

Which TWO of the following are components of the ITIL Service Value System?

Select 2 answers
A.Service catalogue
B.Guiding principles
C.Service desk
D.Configuration management database
E.Service value chain
AnswersB, E

Guiding principles are a core component of the ITIL Service Value System (SVS), providing universal recommendations that guide organizations in all circumstances. These principles, such as 'Focus on value' and 'Collaborate and promote visibility', are designed to help organizations adopt and adapt ITIL guidance to their specific needs and context. They ensure that all activities within the SVS are aligned towards effective value co-creation.

Why this answer

The SVS includes guiding principles, governance, service value chain, practices, and continual improvement.

136
MCQeasy

What is the PRIMARY purpose of Monitoring and Event Management in ITIL 4?

A.To manage service requests from users
B.To detect and respond to events that occur in the IT infrastructure
C.To manage the lifecycle of all problems
D.To restore normal service operation as quickly as possible
AnswerB

This is the core purpose of Monitoring and Event Management.

Why this answer

The primary purpose of Monitoring and Event Management in ITIL 4 is to systematically observe IT infrastructure components and services, detect any change of state (an event), and trigger appropriate responses. This practice ensures that both normal operational events (e.g., a scheduled backup completion) and exceptions (e.g., a server CPU threshold breach) are captured and acted upon, forming the foundation for proactive service management.

Exam trap

The trap here is that candidates often confuse Monitoring and Event Management with Incident Management, mistakenly thinking its primary goal is to restore service quickly, when in fact it is about detecting and responding to all events—both normal and abnormal—to enable proactive control.

How to eliminate wrong answers

Option A is wrong because managing service requests from users is the primary purpose of the Service Desk and Request Fulfillment practices, not Monitoring and Event Management. Option C is wrong because managing the lifecycle of all problems is the primary purpose of Problem Management, which focuses on root cause analysis and prevention of incidents. Option D is wrong because restoring normal service operation as quickly as possible is the primary purpose of Incident Management, which deals with unplanned interruptions or reductions in service quality.

137
Multi-Selectmedium

Which TWO are valid types of events in the Monitoring and Event Management practice?

Select 2 answers
A.Error
B.Warning
C.Critical
D.Informational
E.Alert
AnswersB, D

Warning events are a crucial category in ITIL 4 event management, signifying that a service, CI, or system is operating outside its predefined normal parameters but has not yet failed. These events indicate a potential degradation or risk, such as nearing a capacity threshold or experiencing unusual performance, requiring attention to prevent a future incident. Proactive monitoring for warnings allows for timely intervention, maintaining service quality and availability before critical issues arise.

Why this answer

In the ITIL 4 Monitoring and Event Management practice, events are classified into three types: Informational, Warning, and Exception. 'Warning' (B) is a valid type indicating an event that is not normal but does not yet require immediate action, such as a threshold being approached. 'Informational' (D) is also valid, representing routine events like a successful backup completion or a status update.

Exam trap

The trap here is that candidates confuse severity labels (like 'Critical' or 'Error') with the ITIL-defined event types, leading them to select options that describe impact levels rather than the formal classification of events.

138
MCQmedium

Which ITIL practice is responsible for managing the lifecycle of all IT assets, including financial aspects?

A.Service Configuration Management
B.Service Level Management
C.IT Asset Management
D.Supplier Management
AnswerC

IT Asset Management is the correct practice responsible for managing the full lifecycle of all IT assets, from procurement through deployment, maintenance, and eventual disposal. This includes optimizing asset value, controlling costs, and mitigating risks associated with IT assets throughout their entire economic and operational life. It encompasses financial, contractual, and inventory aspects to ensure assets are effectively utilized and accounted for.

Why this answer

IT Asset Management (ITAM) is the correct practice because it is specifically defined in ITIL 4 to manage the lifecycle of all IT assets, including their financial aspects such as procurement, depreciation, and disposal. This practice ensures that assets are accounted for, controlled, and optimized from acquisition to retirement, directly covering financial management of hardware, software, and licenses.

Exam trap

The trap here is that candidates confuse Service Configuration Management with IT Asset Management because both track IT items, but only ITAM handles financial aspects like cost, depreciation, and lifecycle budgeting.

How to eliminate wrong answers

Option A is wrong because Service Configuration Management focuses on maintaining accurate configuration records (CIs) and their relationships, not on financial management or lifecycle costing of assets. Option B is wrong because Service Level Management deals with defining, agreeing, and monitoring service level agreements (SLAs) and targets, not with asset lifecycle or financial tracking. Option D is wrong because Supplier Management manages relationships and contracts with external suppliers, not the internal lifecycle or financial aspects of IT assets.

139
Multi-Selectmedium

Which TWO of the following are types of changes in ITIL 4 Change Enablement?

Select 2 answers
A.Emergency change
B.Standard change
C.Incident
D.Problem
E.Service request
AnswersA, B

An emergency change is a type of change in ITIL 4 characterized by its high urgency and necessity to resolve an incident or implement a critical security fix with immediate impact. These changes bypass some steps of the normal change process due to their critical nature, requiring expedited authorization to restore service or mitigate severe risks quickly. Their primary goal is to minimize disruption or prevent catastrophic failure, often involving significant risk due to reduced assessment.

Why this answer

In ITIL 4 Change Enablement, changes are categorized into three types: standard, emergency, and normal. Option A (Emergency change) is correct because it refers to a change that must be implemented as soon as possible, often to resolve a major incident or security vulnerability, and follows a specific expedited process with minimized authorization steps. Option B (Standard change) is correct as it is a pre-authorized, low-risk change that follows a defined procedure, such as a routine patch deployment or password reset.

Exam trap

The trap here is that candidates confuse ITIL practices (Incident, Problem, Service Request) with change types, because all are service management activities, but only Standard, Emergency, and Normal are valid change categories in Change Enablement.

140
Multi-Selectmedium

Which TWO are benefits of using a shift-left strategy in the service desk?

Select 2 answers
A.Increased first contact resolution rates
B.Increased reliance on senior technicians
C.Reduced need for incident management
D.Fewer escalations to higher-level support
E.Elimination of service requests
AnswersA, D

A shift-left strategy empowers the initial support tiers, typically the service desk, with enhanced knowledge, tools, and access to resolve a greater proportion of incidents during the first interaction. By providing comprehensive runbooks, self-service portals, and improved training, the goal is to prevent the need for further transfers or callbacks. This direct resolution significantly boosts first contact resolution rates, improving user satisfaction and operational efficiency.

Why this answer

Shift-left in the service desk involves empowering front-line staff with better tools, knowledge, and automation to resolve issues at the first point of contact. This directly increases first contact resolution (FCR) rates because technicians can handle more incidents without escalating. Higher FCR reduces the number of incidents that need to be passed to higher-level support, which is the second correct benefit.

Exam trap

The trap here is that candidates may confuse 'shift-left' with simply adding more junior staff, when in fact it is about enabling those staff with better tools and processes to handle a wider range of issues, thereby reducing escalations and improving first-contact resolution.

141
MCQmedium

A user requests a new laptop as part of the onboarding process. According to ITIL 4, how should this be classified?

A.As a service request, because it is a standard, pre-approved request
B.As a problem, because it may cause future issues
C.As a change request, because it involves hardware
D.As an incident, because it requires IT action
AnswerA

A service request is a formal request from a user for something that is part of normal service delivery, often pre-defined and pre-approved within a service catalog. Onboarding a new employee with a standard laptop is a common, repeatable activity that fits the definition of a service request for a standard offering. It follows an established, streamlined process for efficient fulfillment, rather than requiring extensive assessment.

Why this answer

Service requests are predefined, pre-approved, and follow a standard process, unlike incidents which are unplanned.

142
MCQmedium

A service desk analyst resolves a user's password reset request. According to ITIL 4, what type of record should be closed?

A.Problem record
B.Incident record
C.Change request
D.Service request
AnswerD

A service request is a formal request from a user for something standard that is part of normal service delivery, such as information, advice, or access to a service. A password reset perfectly fits this definition, as it is a pre-defined, low-risk, and frequently requested action to restore a user's access to an existing service, typically fulfilled through a standard, documented procedure.

Why this answer

Password resets are pre-approved, routine requests, so they are service requests.

143
MCQhard

In ITIL 4, which practice involves managing the lifecycle of configuration items (CIs) and maintaining a configuration management database (CMDB)?

A.Deployment Management
B.IT Asset Management
C.Service Configuration Management
D.Change Enablement
AnswerC

Service Configuration Management is the practice of ensuring that accurate and reliable information about the configuration of services and the CIs that support them is available when and where needed. It involves planning, identifying, controlling, recording, reporting, and verifying all CIs throughout their lifecycle, including their relationships. This practice maintains a Configuration Management Database (CMDB) to provide a logical model of the organization's infrastructure and services.

Why this answer

Service Configuration Management is responsible for managing CIs and the CMDB, including configuration baselines.

144
MCQeasy

What is the purpose of the Service Level Management practice?

A.To handle predefined, pre-approved requests from users
B.To ensure that services meet current and future demand
C.To negotiate, agree, and monitor service level agreements (SLAs)
D.To ensure that services are available as agreed
AnswerC

This is the primary purpose of Service Level Management.

Why this answer

The Service Level Management practice is specifically defined in ITIL 4 to negotiate, agree, and monitor service level agreements (SLAs). It ensures that service targets are documented, measured, and reviewed, aligning service delivery with business expectations. This practice directly manages the lifecycle of SLAs, including their creation, ongoing monitoring, and periodic review.

Exam trap

The trap here is confusing the purpose of Service Level Management with Service Availability Management, as both involve 'agreed' levels, but Service Level Management focuses on the entire SLA lifecycle (negotiation, agreement, monitoring) while Availability Management specifically ensures uptime and resilience.

How to eliminate wrong answers

Option A is wrong because handling predefined, pre-approved requests from users is the purpose of the Service Request Management practice, not Service Level Management. Option B is wrong because ensuring services meet current and future demand is the purpose of the Capacity and Performance Management practice, which focuses on resource planning and demand forecasting. Option D is wrong because ensuring services are available as agreed is the purpose of the Service Availability Management practice, which monitors uptime and resilience, not the negotiation and monitoring of SLAs.

145
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. What should they do FIRST according to ITIL 4?

A.Escalate the issue to the problem management team
B.Log and categorize the incident
C.Inform the service level manager
D.Implement a known workaround
AnswerB

Logging and categorizing the incident is the essential first step in the ITIL Incident Management practice. This action creates a formal record of the event, allowing for tracking, communication, and subsequent management. Proper categorization, often based on impact and urgency, enables effective prioritization and routing to the appropriate support group, ensuring the incident is handled efficiently and in line with service level agreements.

Why this answer

The first step is to log and categorize the incident to initiate the incident management process and begin restoration of service.

146
Multi-Selecthard

Which THREE of the following are purposes or activities of the Problem Management practice?

Select 3 answers
A.Identify the root cause of incidents
B.Document known errors and workarounds
C.Proactively prevent incidents from occurring
D.Assess and authorize changes to resolve known errors
E.Restore normal service operation as quickly as possible
AnswersA, B, C

Problem Management's core purpose is to analyze recurring incidents or significant single incidents to determine their underlying causes. This activity, primarily conducted during the Problem Control phase, involves detailed investigation and diagnosis. By pinpointing the root cause, Problem Management aims to eliminate the source of disruption, preventing future recurrences and improving overall service stability.

Why this answer

Problem Management includes problem identification, root cause analysis, and known error management. Options A, B, and C are correct. Option D is Change Enablement; Option E is Incident Management.

147
MCQmedium

A user requests a new laptop for an employee who has just joined the company. According to ITIL 4, how should this request be classified?

A.An emergency change
B.A problem
C.A service request
D.An incident
AnswerC

A service request, according to ITIL 4, is a formal request from a user for something standard that is part of normal service delivery, such as information, advice, a standard change, or access to a service. Providing a new laptop for an employee falls squarely into this category as it is a predefined, often pre-approved, and routine fulfillment action for a standard item of equipment. These requests typically follow a streamlined, automated workflow.

Why this answer

A new laptop request for a new employee is a standardized, pre-approved service request because it follows predefined procedures (e.g., provisioning a standard device). It is not an incident (unplanned interruption), a problem (root cause analysis), or an emergency change (urgent, high-risk alteration). In ITIL 4, service requests are the correct classification for such common, low-risk requests.

148
Multi-Selecthard

Which TWO of the following are key activities of the Change Enablement practice?

Select 2 answers
A.Restoring service after an outage
B.Assessing and authorizing changes
C.Identifying workarounds for incidents
D.Negotiating service level agreements
E.Reviewing and closing changes after implementation
AnswersB, E

Assessing and authorizing changes are fundamental activities within the Change Enablement practice, ensuring that all proposed changes are properly evaluated for potential risks, benefits, and resource implications. This involves reviewing the change request, understanding its impact on services and users, and obtaining the necessary approvals before implementation. Effective assessment prevents unauthorized or detrimental modifications, maintaining service stability and value.

Why this answer

The Change Enablement practice focuses on managing changes in a controlled manner. Key activities include assessing and authorizing changes (Option B) to ensure they are viable and safe, and reviewing and closing changes after implementation (Option E) to capture lessons learned. Option A (Restoring service after an outage) belongs to Incident Management.

Option C (Identifying workarounds for incidents) is also part of Incident Management. Option D (Negotiating service level agreements) relates to Service Level Management.

149
MCQhard

An organization has an SLA that specifies a response time of 4 hours for priority 2 incidents. The IT team also has an OLA with the network team to resolve network-related incidents within 2 hours. According to ITIL 4, what is the relationship between the SLA and the OLA?

A.The OLA supports the SLA by ensuring internal teams meet their commitments.
B.The OLA is a contract with an external supplier, while the SLA is with internal customers.
C.The OLA and SLA are independent and have no relationship.
D.The SLA is more important than the OLA, so the OLA can be ignored if needed.
AnswerA

An Operational Level Agreement (OLA) is an internal contract between a service provider and another part of the same organization, defining the responsibilities and performance targets required to deliver a service. By setting clear expectations and metrics for internal teams, the OLA directly supports the Service Level Agreement (SLA) by ensuring that the underlying components and processes meet their commitments, thereby enabling the overall service to meet its customer-facing obligations.

Why this answer

An OLA supports the SLA by defining internal targets that help meet the SLA.

150
MCQeasy

Which of the following is a key metric for the Service Desk practice?

A.Percentage of changes implemented successfully
B.First Call Resolution (FCR) rate
C.Service level agreement (SLA) compliance
D.Mean Time to Restore Service (MTTR)
AnswerB

First Call Resolution (FCR) rate is a critical performance indicator for the Service Desk, directly measuring its efficiency and effectiveness in resolving user issues during the initial interaction. A high FCR rate signifies that Service Desk agents possess the necessary knowledge, tools, and authority to address common problems promptly, minimizing the need for escalations or follow-up contacts. This metric significantly contributes to enhanced customer satisfaction and optimizes operational costs by reducing repeat contacts and improving agent productivity.

Why this answer

First Call Resolution (FCR) rate is a key metric for the Service Desk practice, measuring how often issues are resolved on the first contact. SLA compliance is associated with Service Level Management, MTTR with Incident Management, and percentage of changes implemented successfully with Change Enablement. Option B is correct.

← PreviousPage 2 of 4 · 260 questions totalNext →

Ready to test yourself?

Try a timed practice session using only ITIL Management Practices questions.