Courseiva

CCNA ITIL Management Practices Questions

75 of 301 questions · Page 3/5 · ITIL Management Practices · Answers revealed

151
MCQmedium

A major incident has occurred. After restoring service, the team wants to update the Known Error Database (KEDB) with the workaround. Which practice is primarily responsible for this?

A.Service Desk
B.Change Enablement
C.Incident Management
D.Problem Management
AnswerD

Problem Management owns the KEDB, recording workarounds and root causes. Incident Management restores service; once a workaround exists, Problem Management documents it against the known error, satisfying the requirement to capture the workaround after service restoration.

Why this answer

Problem Management is responsible for managing the lifecycle of all problems, including updating the Known Error Database (KEDB) with workarounds. After a major incident is resolved, the workaround is documented in the KEDB by Problem Management to prevent future incidents and enable faster resolution. This aligns with ITIL 4's definition of Problem Management as the practice that identifies, analyzes, and documents known errors and workarounds.

Exam trap

The trap here is that candidates confuse the immediate service restoration (Incident Management) with the subsequent documentation of workarounds (Problem Management), leading them to select Incident Management instead of Problem Management.

How to eliminate wrong answers

Option A is wrong because the Service Desk is the single point of contact for users and handles incident logging and initial support, but it does not own the KEDB or the process of documenting workarounds—that is a Problem Management responsibility. Option B is wrong because Change Enablement focuses on controlling the lifecycle of changes to IT services, not on updating the KEDB with workarounds; its primary concern is risk assessment and approval of changes. Option C is wrong because Incident Management is responsible for restoring normal service operation as quickly as possible, but the KEDB update is a post-incident activity that falls under Problem Management to analyze root causes and prevent recurrence.

152
MCQmedium

A problem manager has identified multiple incidents with no known cause. Which phase of Problem Management is being performed?

A.Problem identification
B.Problem control
C.Error control
D.Post-implementation review
AnswerA

When a problem manager observes 'multiple incidents with no known cause,' this directly triggers the Problem Identification phase. This initial stage of the Problem Management practice is dedicated to detecting and logging potential problems, often by analyzing incident trends or significant single events that indicate an underlying structural flaw. It's about recognizing that a problem exists before diving into its root cause.

Why this answer

Problem identification involves detecting problems from incidents and other sources. In this scenario, the problem manager is identifying a problem from incidents, which is the first phase. Option A is correct.

Option B involves root cause analysis. Option C involves managing known errors. Option D is not a separate phase.

153
Multi-Selectmedium

Which TWO of the following are components of the ITIL Service Value System?

Select 2 answers
A.Service catalogue
B.Guiding principles
C.Service desk
D.Configuration management database
E.Service value chain
AnswersB, E

Guiding principles are a core component of the ITIL Service Value System (SVS), providing universal recommendations that guide organizations in all circumstances. These principles, such as 'Focus on value' and 'Collaborate and promote visibility', are designed to help organizations adopt and adapt ITIL guidance to their specific needs and context. They ensure that all activities within the SVS are aligned towards effective value co-creation.

Why this answer

The ITIL 4 Service Value System (SVS) is composed of five core components: guiding principles, governance, the service value chain, practices, and continual improvement. Option B (Guiding principles) is correct because the guiding principles are one of the central components of the SVS, providing recommendations that guide an organization in all circumstances. Option E (Service value chain) is correct because the service value chain is the central element of the SVS, describing the six activities (plan, improve, engage, design and transition, obtain/build, and deliver and support) that convert inputs into outputs and outcomes.

Options A (Service catalogue), C (Service desk), and D (Configuration management database) are not SVS components; they are specific practices, tools, or artifacts within ITIL (e.g., the service desk is a practice, and the CMDB is a data repository used by configuration management), not the high-level components that make up the Service Value System itself.

Exam trap

The trap is confusing ITIL practices and tools (service desk, service catalogue, CMDB) with the five formal SVS components — only guiding principles, governance, service value chain, practices, and continual improvement qualify.

154
MCQeasy

What is the PRIMARY purpose of Monitoring and Event Management in ITIL 4?

A.To manage service requests from users
B.To detect and respond to events that occur in the IT infrastructure
C.To manage the lifecycle of all problems
D.To restore normal service operation as quickly as possible
AnswerB

Monitoring and Event Management observes infrastructure and services, detecting state changes and generating events. Its primary purpose is to detect and respond to those events, restoring normal service operation quickly and providing visibility that supports other ITIL 4 practises.

Why this answer

The primary purpose of Monitoring and Event Management in ITIL 4 is to systematically observe IT infrastructure components and services, detect any change of state (an event), and trigger appropriate responses. This practice ensures that both normal operational events (e.g., a scheduled backup completion) and exceptions (e.g., a server CPU threshold breach) are captured and acted upon, forming the foundation for proactive service management.

Exam trap

The trap here is that candidates often confuse Monitoring and Event Management with Incident Management, mistakenly thinking its primary goal is to restore service quickly, when in fact it is about detecting and responding to all events—both normal and abnormal—to enable proactive control.

How to eliminate wrong answers

Option A is wrong because managing service requests from users is the primary purpose of the Service Desk and Request Fulfillment practices, not Monitoring and Event Management. Option C is wrong because managing the lifecycle of all problems is the primary purpose of Problem Management, which focuses on root cause analysis and prevention of incidents. Option D is wrong because restoring normal service operation as quickly as possible is the primary purpose of Incident Management, which deals with unplanned interruptions or reductions in service quality.

155
Multi-Selectmedium

Which TWO are valid types of events in the Monitoring and Event Management practice?

Select 2 answers
A.Error
B.Warning
C.Critical
D.Informational
E.Alert
AnswersB, D

Warning events are a crucial category in ITIL 4 event management, signifying that a service, CI, or system is operating outside its predefined normal parameters but has not yet failed. These events indicate a potential degradation or risk, such as nearing a capacity threshold or experiencing unusual performance, requiring attention to prevent a future incident. Proactive monitoring for warnings allows for timely intervention, maintaining service quality and availability before critical issues arise.

Why this answer

In the ITIL 4 Monitoring and Event Management practice, events are classified into three types: Informational, Warning, and Exception. 'Warning' (B) is a valid type indicating an event that is not normal but does not yet require immediate action, such as a threshold being approached. 'Informational' (D) is also valid, representing routine events like a successful backup completion or a status update.

Exam trap

The trap here is that candidates confuse severity labels (like 'Critical' or 'Error') with the ITIL-defined event types, leading them to select options that describe impact levels rather than the formal classification of events.

156
MCQmedium

Which ITIL practice is responsible for managing the lifecycle of all IT assets, including financial aspects?

A.Service Configuration Management
B.Service Level Management
C.IT Asset Management
D.Supplier Management
AnswerC

IT Asset Management is the correct practice responsible for managing the full lifecycle of all IT assets, from procurement through deployment, maintenance, and eventual disposal. This includes optimizing asset value, controlling costs, and mitigating risks associated with IT assets throughout their entire economic and operational life. It encompasses financial, contractual, and inventory aspects to ensure assets are effectively utilized and accounted for.

Why this answer

IT Asset Management (ITAM) is the correct practice because it is specifically defined in ITIL 4 to manage the lifecycle of all IT assets, including their financial aspects such as procurement, depreciation, and disposal. This practice ensures that assets are accounted for, controlled, and optimized from acquisition to retirement, directly covering financial management of hardware, software, and licenses.

Exam trap

The trap here is that candidates confuse Service Configuration Management with IT Asset Management because both track IT items, but only ITAM handles financial aspects like cost, depreciation, and lifecycle budgeting.

How to eliminate wrong answers

Option A is wrong because Service Configuration Management focuses on maintaining accurate configuration records (CIs) and their relationships, not on financial management or lifecycle costing of assets. Option B is wrong because Service Level Management deals with defining, agreeing, and monitoring service level agreements (SLAs) and targets, not with asset lifecycle or financial tracking. Option D is wrong because Supplier Management manages relationships and contracts with external suppliers, not the internal lifecycle or financial aspects of IT assets.

157
MCQhard

A known error has been documented and a workaround exists. According to ITIL 4, which practice is responsible for managing the known error?

A.Change Enablement
B.Service Desk
C.Problem Management
D.Incident Management
AnswerC

Problem Management is the ITIL practice responsible for reducing the likelihood and impact of incidents by identifying actual and potential causes of incidents and managing workarounds and known errors. Its 'error control' activity specifically involves identifying, documenting, and managing known errors, including finding and documenting workarounds, and ultimately facilitating the permanent resolution of the underlying problems. Therefore, managing a documented known error with an existing workaround is a core, explicit function of Problem Management.

Why this answer

According to ITIL 4, the Problem Management practice is responsible for managing known errors throughout their lifecycle, including documenting the known error record and ensuring a workaround is available. This practice focuses on identifying the root cause of incidents and preventing recurrence, with the known error being a formal record that may include a documented workaround to reduce incident impact.

Exam trap

The trap here is that candidates often confuse the use of a workaround during incident resolution with the ownership of the known error itself, incorrectly selecting Incident Management instead of Problem Management.

How to eliminate wrong answers

Option A is wrong because Change Enablement is responsible for controlling the lifecycle of all changes, enabling beneficial changes with minimal disruption, not for managing known errors or workarounds. Option B is wrong because the Service Desk is the single point of contact for users reporting incidents and handling service requests, but it does not own the known error record or its management. Option D is wrong because Incident Management focuses on restoring normal service operation as quickly as possible after an incident, but it does not manage the known error itself; it may use the workaround from the known error record to resolve incidents.

158
MCQeasy

What is the ITIL 4 guiding principle that emphasizes starting from what already exists and avoiding unnecessary complexity?

A.Progress iteratively with feedback
B.Keep it simple and practical
C.Start where you are
D.Focus on value
AnswerC

This principle explicitly mandates assessing the current state of services, processes, people, and technology before embarking on any improvement initiative. 'Start where you are' advocates for utilizing what is already available and proven, rather than discarding existing assets or starting from scratch, thereby ensuring efficiency, avoiding redundant efforts, and building upon established foundations. This directly addresses the emphasis on leveraging the current environment as the initial point of action.

Why this answer

The 'Start where you are' guiding principle in ITIL 4 directs organizations to leverage existing services, processes, and data rather than building from scratch. It avoids unnecessary complexity by assessing current capabilities and making incremental improvements, which aligns with minimizing waste and rework.

Exam trap

The trap here is that candidates confuse 'Start where you are' with 'Keep it simple and practical' because both involve reducing complexity, but the former specifically emphasizes using existing resources as a foundation.

How to eliminate wrong answers

Option A is wrong because 'Progress iteratively with feedback' focuses on breaking work into manageable steps and using feedback loops, not on leveraging existing assets. Option B is wrong because 'Keep it simple and practical' emphasizes minimizing complexity in design and execution, but does not specifically address starting from the current state. Option D is wrong because 'Focus on value' prioritizes delivering outcomes that matter to stakeholders, but does not directly relate to avoiding unnecessary complexity by using what already exists.

159
Multi-Selectmedium

Which TWO of the following are types of changes in ITIL 4 Change Enablement?

Select 2 answers
A.Emergency change
B.Standard change
C.Incident
D.Problem
E.Service request
AnswersA, B

An emergency change is a type of change in ITIL 4 characterized by its high urgency and necessity to resolve an incident or implement a critical security fix with immediate impact. These changes bypass some steps of the normal change process due to their critical nature, requiring expedited authorization to restore service or mitigate severe risks quickly. Their primary goal is to minimize disruption or prevent catastrophic failure, often involving significant risk due to reduced assessment.

Why this answer

In ITIL 4 Change Enablement, changes are categorized into three types: standard, emergency, and normal. Option A (Emergency change) is correct because it refers to a change that must be implemented as soon as possible, often to resolve a major incident or security vulnerability, and follows a specific expedited process with minimized authorization steps. Option B (Standard change) is correct as it is a pre-authorized, low-risk change that follows a defined procedure, such as a routine patch deployment or password reset.

Exam trap

The trap here is that candidates confuse ITIL practices (Incident, Problem, Service Request) with change types, because all are service management activities, but only Standard, Emergency, and Normal are valid change categories in Change Enablement.

160
Multi-Selectmedium

Which TWO are benefits of using a shift-left strategy in the service desk?

Select 2 answers
A.Increased first contact resolution rates
B.Increased reliance on senior technicians
C.Reduced need for incident management
D.Fewer escalations to higher-level support
E.Elimination of service requests
AnswersA, D

A shift-left strategy empowers the initial support tiers, typically the service desk, with enhanced knowledge, tools, and access to resolve a greater proportion of incidents during the first interaction. By providing comprehensive runbooks, self-service portals, and improved training, the goal is to prevent the need for further transfers or callbacks. This direct resolution significantly boosts first contact resolution rates, improving user satisfaction and operational efficiency.

Why this answer

Shift-left in the service desk involves empowering front-line staff with better tools, knowledge, and automation to resolve issues at the first point of contact. This directly increases first contact resolution (FCR) rates because technicians can handle more incidents without escalating. Higher FCR reduces the number of incidents that need to be passed to higher-level support, which is the second correct benefit.

Exam trap

The trap here is that candidates may confuse 'shift-left' with simply adding more junior staff, when in fact it is about enabling those staff with better tools and processes to handle a wider range of issues, thereby reducing escalations and improving first-contact resolution.

161
MCQmedium

A user requests a new laptop as part of the onboarding process. According to ITIL 4, how should this be classified?

A.As a service request, because it is a standard, pre-approved request
B.As a problem, because it may cause future issues
C.As a change request, because it involves hardware
D.As an incident, because it requires IT action
AnswerA

A service request is a formal request from a user for something that is part of normal service delivery, often pre-defined and pre-approved within a service catalog. Onboarding a new employee with a standard laptop is a common, repeatable activity that fits the definition of a service request for a standard offering. It follows an established, streamlined process for efficient fulfillment, rather than requiring extensive assessment.

Why this answer

A new laptop for onboarding is a standard, pre-approved, low-risk request that follows a defined fulfillment workflow, which ITIL 4 classifies as a service request. It is not a failure or unplanned event, so it does not meet the definitions of incident, problem, or change.

Exam trap

ITIL4F often tests the boundary between service requests and changes, so candidates who see 'hardware' and jump to change request miss that standard pre-approved fulfillment is a service request.

How to eliminate wrong answers

Option B is wrong because a problem is the cause (or potential cause) of one or more incidents; requesting a laptop is not a source of service failure. Option C is wrong because while hardware is involved, a standard pre-approved request does not require the change control process—only non-standard changes do. Option D is wrong because an incident is an unplanned interruption or reduction in service quality, whereas a laptop request is planned fulfillment, not a disruption.

162
MCQhard

A company implements a new monitoring system that sends alerts when server CPU usage exceeds 90%. Which ITIL 4 practice is primarily involved?

A.Monitoring and Event Management
B.Service Desk
C.Incident Management
D.Capacity and Performance Management
AnswerA

Monitoring and Event Management's core purpose is to systematically observe services and service components, recording and reporting selected changes of state identified as events. The implementation of a new monitoring system that sends alerts directly aligns with the detection and classification of these events. This practice ensures that appropriate actions are initiated, whether the event signifies normal operation, an exception, or a potential incident requiring further attention.

Why this answer

The monitoring system that sends alerts when CPU usage exceeds 90% directly involves detecting and responding to operational events. This is the core function of the Monitoring and Event Management practice, which defines how events (such as threshold breaches) are captured, analyzed, and acted upon. The alert itself is an 'event' in ITIL 4 terms, making this practice primarily responsible.

Exam trap

The trap here is that candidates confuse the Monitoring and Event Management practice (which handles the alert generation and initial response) with Capacity and Performance Management (which uses the same data for long-term planning), but the question specifically asks which practice is 'primarily involved' in the act of sending alerts when a threshold is breached.

How to eliminate wrong answers

Option B (Service Desk) is wrong because the Service Desk is the single point of contact for users reporting issues or requests, not the practice that monitors infrastructure metrics like CPU usage. Option C (Incident Management) is wrong because Incident Management handles unplanned interruptions or reductions in service quality after they occur, whereas the monitoring system is proactively detecting a potential issue before it becomes an incident. Option D (Capacity and Performance Management) is wrong because while it uses performance data to plan for future capacity needs, the immediate act of monitoring CPU thresholds and generating alerts is an operational event-handling activity, not a capacity planning activity.

163
MCQmedium

A service desk analyst resolves a user's password reset request. According to ITIL 4, what type of record should be closed?

A.Problem record
B.Incident record
C.Change request
D.Service request
AnswerD

A service request is a formal request from a user for something standard that is part of normal service delivery, such as information, advice, or access to a service. A password reset perfectly fits this definition, as it is a pre-defined, low-risk, and frequently requested action to restore a user's access to an existing service, typically fulfilled through a standard, documented procedure.

Why this answer

A password reset is a standard, pre-approved request from a user, which ITIL 4 classifies as a service request. Service requests are handled through the Service Request Management practice, not Incident Management. Since the request is not an unplanned interruption or degradation, it should be logged and closed as a service request record.

Exam trap

ITIL4F often tests the distinction between incidents and service requests, and candidates may incorrectly choose incident because they think any user contact is an incident, forgetting that standard requests like password resets are service requests.

How to eliminate wrong answers

Option A is wrong because a problem record is for the underlying cause of incidents, not for routine user requests. Option B is wrong because an incident record is for unplanned service interruptions or degradations; a password reset is planned and standard. Option C is wrong because a change request is for modifications to the IT infrastructure or services, not for fulfilling a user's standard request.

164
MCQhard

A company is undergoing a major organizational change that will affect several IT services. The change manager wants to ensure that all changes are assessed for risk and that the change schedule is maintained. Which practice provides the formal process for managing changes in a controlled manner?

A.Deployment Management
B.Release Management
C.Transition Planning and Support
D.Change Enablement
AnswerD

Change Enablement is the ITIL practice responsible for maximizing the number of successful service and product changes by ensuring risks are properly assessed, authorizing changes to proceed, and managing the change schedule. It provides the formal process for evaluating, approving, and scheduling all types of changes, from standard to emergency, ensuring they deliver expected value without undue disruption. This practice directly addresses the need for assessing and authorizing organizational changes.

Why this answer

Change Enablement is the ITIL 4 practice that provides the formal, controlled process for assessing, approving, and scheduling changes to IT services. It ensures that all changes are evaluated for risk, and that the change schedule is maintained, which directly addresses the change manager's requirements.

Exam trap

The trap here is that candidates often confuse the 'process for managing changes' with Release Management or Deployment Management, but ITIL 4 explicitly assigns the formal risk assessment and change scheduling to Change Enablement.

How to eliminate wrong answers

Option A is wrong because Deployment Management focuses on moving new or changed components into production environments, not on the formal risk assessment and scheduling of changes. Option B is wrong because Release Management handles the planning, building, testing, and deployment of releases, but the formal change authorization and risk assessment process is owned by Change Enablement. Option C is wrong because Transition Planning and Support coordinates the overall transition of new or changed services, but it does not provide the specific, controlled process for assessing and approving individual changes.

165
MCQhard

In ITIL 4, which practice involves managing the lifecycle of configuration items (CIs) and maintaining a configuration management database (CMDB)?

A.Deployment Management
B.IT Asset Management
C.Service Configuration Management
D.Change Enablement
AnswerC

Service Configuration Management is the practice of ensuring that accurate and reliable information about the configuration of services and the CIs that support them is available when and where needed. It involves planning, identifying, controlling, recording, reporting, and verifying all CIs throughout their lifecycle, including their relationships. This practice maintains a Configuration Management Database (CMDB) to provide a logical model of the organization's infrastructure and services.

Why this answer

Service Configuration Management is the ITIL 4 practice responsible for managing the lifecycle of configuration items (CIs) and maintaining the configuration management database (CMDB). It ensures that accurate and reliable configuration information about services and their components is available when and where it is needed. This practice evolved from the ITIL v3 Service Asset and Configuration Management process.

Exam trap

ITIL4F often tests the overlap between Service Configuration Management, IT Asset Management, and Change Enablement, so candidates must remember that only Service Configuration Management owns the CI lifecycle and CMDB.

How to eliminate wrong answers

Option A is wrong because Deployment Management focuses on moving new or changed hardware, software, documentation, and processes into live environments, not on maintaining CI records or the CMDB. Option B is wrong because IT Asset Management manages the financial, inventory, and contractual aspects of assets, which is related but distinct from configuration management's focus on relationships and CI attributes. Option D is wrong because Change Enablement ensures changes are assessed, authorized, and prioritized; it consumes CMDB data but does not own the CI lifecycle or CMDB maintenance.

166
MCQeasy

What is the purpose of the Service Level Management practice?

A.To handle predefined, pre-approved requests from users
B.To ensure that services meet current and future demand
C.To negotiate, agree, and monitor service level agreements (SLAs)
D.To ensure that services are available as agreed
AnswerC

Service Level Management's purpose is to set clear, agreed targets by negotiating SLAs with customers, then monitoring and reporting performance against them. This directly satisfies the stem's requirement to negotiate, agree, and monitor service level agreements.

Why this answer

The Service Level Management practice is specifically defined in ITIL 4 to negotiate, agree, and monitor service level agreements (SLAs). It ensures that service targets are documented, measured, and reviewed, aligning service delivery with business expectations. This practice directly manages the lifecycle of SLAs, including their creation, ongoing monitoring, and periodic review.

Exam trap

The trap here is confusing the purpose of Service Level Management with Service Availability Management, as both involve 'agreed' levels, but Service Level Management focuses on the entire SLA lifecycle (negotiation, agreement, monitoring) while Availability Management specifically ensures uptime and resilience.

How to eliminate wrong answers

Option A is wrong because handling predefined, pre-approved requests from users is the purpose of the Service Request Management practice, not Service Level Management. Option B is wrong because ensuring services meet current and future demand is the purpose of the Capacity and Performance Management practice, which focuses on resource planning and demand forecasting. Option D is wrong because ensuring services are available as agreed is the purpose of the Service Availability Management practice, which monitors uptime and resilience, not the negotiation and monitoring of SLAs.

167
Multi-Selecthard

Which THREE of the following are purposes or activities of the Problem Management practice?

Select 3 answers
A.Identify the root cause of incidents
B.Document known errors and workarounds
C.Proactively prevent incidents from occurring
D.Assess and authorize changes to resolve known errors
E.Restore normal service operation as quickly as possible
AnswersA, B, C

Problem Management's core purpose is to analyze recurring incidents or significant single incidents to determine their underlying causes. This activity, primarily conducted during the Problem Control phase, involves detailed investigation and diagnosis. By pinpointing the root cause, Problem Management aims to eliminate the source of disruption, preventing future recurrences and improving overall service stability.

Why this answer

Problem Management is the ITIL practice whose core purpose is to reduce the likelihood and impact of incidents by identifying their actual and potential causes, so option A ('Identify the root cause of incidents') is correct because root cause analysis is the central investigative activity of the practice. Option B ('Document known errors and workarounds') is correct because once a root cause is understood and a permanent fix is not yet in place, Problem Management records the known error in the known error database and documents workarounds that can be used by Incident Management. Option C ('Proactively prevent incidents from occurring') is correct because Problem Management includes proactive problem management, which analyzes trends and identifies potential failures to eliminate or mitigate them before they cause incidents.

Option D is incorrect because assessing and authorizing changes belongs to the Change Enablement practice, even when the change resolves a known error. Option E is incorrect because restoring normal service operation as quickly as possible is the purpose of the Incident Management practice, not Problem Management.

Exam trap

ITIL4F often tests the boundary between Problem Management and Incident Management — candidates pick 'restore normal service operation' because it sounds like problem resolution, but that is Incident Management's purpose.

168
MCQmedium

A user requests a new laptop for an employee who has just joined the company. According to ITIL 4, how should this request be classified?

A.An emergency change
B.A problem
C.A service request
D.An incident
AnswerC

A service request, according to ITIL 4, is a formal request from a user for something standard that is part of normal service delivery, such as information, advice, a standard change, or access to a service. Providing a new laptop for an employee falls squarely into this category as it is a predefined, often pre-approved, and routine fulfillment action for a standard item of equipment. These requests typically follow a streamlined, automated workflow.

Why this answer

A new-hire laptop request is a standard, pre-approved, low-risk request for something the user is entitled to — that is the definition of a service request in ITIL 4. Service requests are handled through the Service Request Management practice and are typically fulfilled via a predefined workflow, not through incident or change management.

Exam trap

ITIL4F often tests the boundary between service requests and incidents — candidates see 'user contacts the service desk' and reflexively pick 'incident', but a planned, standard ask is always a service request.

How to eliminate wrong answers

Option A is wrong because an emergency change is an unplanned change that must be implemented immediately to resolve a major incident or security issue — ordering a laptop is neither urgent nor a change to a live service. Option B is wrong because a problem is the underlying cause of one or more incidents, not a user request for a standard item. Option D is wrong because an incident is an unplanned interruption or degradation of a service — the user's laptop request is planned and expected, not a service failure.

169
Multi-Selecthard

Which TWO of the following are key activities of the Change Enablement practice?

Select 2 answers
A.Restoring service after an outage
B.Assessing and authorizing changes
C.Identifying workarounds for incidents
D.Negotiating service level agreements
E.Reviewing and closing changes after implementation
AnswersB, E

Assessing and authorizing changes are fundamental activities within the Change Enablement practice, ensuring that all proposed changes are properly evaluated for potential risks, benefits, and resource implications. This involves reviewing the change request, understanding its impact on services and users, and obtaining the necessary approvals before implementation. Effective assessment prevents unauthorized or detrimental modifications, maintaining service stability and value.

Why this answer

Option B (Assessing and authorizing changes) is correct because Change Enablement is responsible for evaluating change requests for risk, impact, and readiness, and for granting the authorization needed before a change is deployed into production. Option E (Reviewing and closing changes after implementation) is correct because the practice also covers post-implementation review to confirm the change achieved its intended outcome, did not cause unexpected issues, and can be formally closed in the change record. Option A (Restoring service after an outage) belongs to Incident Management, whose purpose is to return service to normal as quickly as possible rather than to manage changes.

Option C (Identifying workarounds for incidents) is also an Incident Management activity, used to temporarily restore service while a permanent fix is pursued. Option D (Negotiating service level agreements) is a Service Level Management activity, focused on agreeing and managing service targets with customers, not on controlling changes.

Exam trap

ITIL4F often tests the confusion between Change Enablement and Incident Management activities, particularly by including incident-related options like restoring service or identifying workarounds to lure candidates who associate 'change' with fixing problems.

170
MCQhard

An organization has an SLA that specifies a response time of 4 hours for priority 2 incidents. The IT team also has an OLA with the network team to resolve network-related incidents within 2 hours. According to ITIL 4, what is the relationship between the SLA and the OLA?

A.The OLA supports the SLA by ensuring internal teams meet their commitments.
B.The OLA is a contract with an external supplier, while the SLA is with internal customers.
C.The OLA and SLA are independent and have no relationship.
D.The SLA is more important than the OLA, so the OLA can be ignored if needed.
AnswerA

An Operational Level Agreement (OLA) is an internal contract between a service provider and another part of the same organization, defining the responsibilities and performance targets required to deliver a service. By setting clear expectations and metrics for internal teams, the OLA directly supports the Service Level Agreement (SLA) by ensuring that the underlying components and processes meet their commitments, thereby enabling the overall service to meet its customer-facing obligations.

Why this answer

An Operational Level Agreement (OLA) is an internal agreement between teams within the same organization that supports the delivery of services to meet an SLA. In this case, the OLA with the network team (2-hour resolution) supports the SLA commitment (4-hour response for priority 2 incidents) by ensuring internal dependencies are met. The OLA is a building block that enables the SLA to be achieved.

Exam trap

ITIL4F often tests the relationship between SLAs and OLAs, and candidates may confuse OLAs with underpinning contracts (UCs) or think they are independent, missing that OLAs are internal agreements that support SLAs.

How to eliminate wrong answers

Option B is wrong because an OLA is an internal agreement, not a contract with an external supplier; that would be an underpinning contract (UC). Option C is wrong because OLAs and SLAs are directly related: OLAs support SLAs. Option D is wrong because the SLA and OLA are interdependent; ignoring the OLA would jeopardize the SLA, and neither is inherently more important—they serve different but linked purposes.

171
MCQeasy

Which of the following is a key metric for the Service Desk practice?

A.Percentage of changes implemented successfully
B.First Call Resolution (FCR) rate
C.Service level agreement (SLA) compliance
D.Mean Time to Restore Service (MTTR)
AnswerB

First Call Resolution (FCR) rate is a critical performance indicator for the Service Desk, directly measuring its efficiency and effectiveness in resolving user issues during the initial interaction. A high FCR rate signifies that Service Desk agents possess the necessary knowledge, tools, and authority to address common problems promptly, minimizing the need for escalations or follow-up contacts. This metric significantly contributes to enhanced customer satisfaction and optimizes operational costs by reducing repeat contacts and improving agent productivity.

Why this answer

First Call Resolution (FCR) rate is a key metric for the Service Desk practice because it measures the percentage of incidents resolved during the first contact, reflecting the efficiency and effectiveness of the service desk. Other metrics like SLA compliance or MTTR are broader and not specific to the Service Desk's first-contact capability.

Exam trap

ITIL4F often tests the confusion between Service Desk metrics and other practice metrics; candidates may incorrectly associate SLA compliance or MTTR with the Service Desk, but FCR is the most direct metric.

How to eliminate wrong answers

Option A is wrong because the percentage of changes implemented successfully is a metric for Change Enablement, not the Service Desk. Option C is wrong because SLA compliance is a metric for Service Level Management, which monitors overall service performance against agreements. Option D is wrong because Mean Time to Restore Service (MTTR) is a metric for Incident Management, measuring the average time to restore service after an incident, not specifically the Service Desk's first-contact resolution.

172
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. The analyst verifies the issue and suspects it may be related to a recent change. What should the analyst do FIRST according to ITIL 4?

A.Immediately reverse the recent change
B.Create a service request to restore access
C.Log an incident record and begin initial diagnosis
D.Log a problem record to investigate the root cause
AnswerC

Logging an incident record and initiating initial diagnosis is the correct first step because ITIL 4 defines an incident as an unplanned interruption to a service or a reduction in the quality of a service. The primary objective of Incident Management is to restore normal service operation as quickly as possible, and logging the incident ensures it is tracked, prioritized, and managed effectively from the outset. Initial diagnosis is crucial for understanding the immediate impact and potential resolution.

Why this answer

According to ITIL 4, the first step in Incident Management is to log the incident record and begin initial diagnosis, ensuring the issue is captured, categorized, and investigated before any action is taken. Reversing a change or escalating to problem management without logging and diagnosing would violate the practice's workflow. Logging creates the audit trail and enables prioritization, communication, and tracking.

Exam trap

ITIL4F often tests the order of operations in Incident Management — candidates jump to 'reverse the change' or 'log a problem' because the scenario hints at a change, forgetting that logging and initial diagnosis must come first.

How to eliminate wrong answers

Option A is wrong because immediately reversing the change without diagnosis is premature — the change may not be the cause, and a rollback could introduce new issues; ITIL requires diagnosis first. Option B is wrong because a service request is for predefined user requests (e.g., password reset, software install), not for service outages or degradation, which are incidents. Option D is wrong because logging a problem record is premature; problem management is triggered after incidents are resolved or when recurring incidents suggest an underlying cause, not as the first response to a single incident.

173
MCQhard

Which statement BEST distinguishes a service request from an incident?

A.Incidents are only technical issues, while service requests are for information
B.Service requests always require a change, while incidents never do
C.Service requests are not logged, while incidents are always logged
D.Service requests are pre-defined and pre-approved, while incidents are unplanned service disruptions
AnswerD

This statement accurately distinguishes service requests from incidents. Service requests are typically standardized, routine requests for information, access, or a standard service component, often with pre-defined fulfillment steps and pre-approved costs and procedures. In contrast, incidents represent an unplanned interruption to a service or a reduction in the quality of a service, requiring prompt resolution to restore normal operation as quickly as possible.

Why this answer

A service request is a pre-defined, pre-approved user request such as a password reset, software installation, or information request, handled through the request fulfillment practice. An incident is an unplanned interruption or degradation of a service, handled through the incident management practice. This distinction is the defining difference between the two.

Exam trap

ITIL4F often tests the misconception that incidents are only technical issues or that service requests always require a change, so candidates who overgeneralize pick the wrong distinction.

How to eliminate wrong answers

Option A is wrong because incidents are not limited to technical issues; they include any unplanned service disruption, and service requests are not limited to information requests. Option B is wrong because service requests do not always require a change (many are pre-approved standard changes or simple fulfillments), and incidents can sometimes require a change to resolve. Option C is wrong because both service requests and incidents are logged in the ITSM tool; logging is not the distinguishing factor.

174
MCQeasy

In the ITIL 4 Service Value System, which component provides governance and guidance?

A.Guiding Principles
B.Continual Improvement
C.Service Value Chain
D.Governance
AnswerD

In the ITIL 4 Service Value System, Governance is the component that provides the overarching framework for direction and control within an organization. It ensures that the organization's activities, including its service management practices, are aligned with its strategic objectives and stakeholder requirements. This involves defining policies, establishing decision-making authorities, and ensuring compliance and accountability across all levels of the organization.

Why this answer

In the ITIL 4 Service Value System (SVS), the Governance component is specifically responsible for defining the direction, policies, and control mechanisms that ensure the organization's activities align with its objectives. It provides the overarching framework for decision-making and accountability, guiding how all other SVS components operate. Without governance, the SVS would lack the necessary oversight to ensure value co-creation is achieved in a controlled and compliant manner.

Exam trap

The trap here is that candidates often confuse the Guiding Principles (Option A) with governance because both provide 'guidance,' but the Guiding Principles are broad, flexible recommendations, whereas Governance is a formal, authoritative component that enforces policies and controls.

How to eliminate wrong answers

Option A is wrong because Guiding Principles are recommendations that guide an organization in its work, but they do not provide the formal governance and authority structure; they are a component of the SVS that supports decision-making, not governance itself. Option B is wrong because Continual Improvement is a practice and a component that ensures the SVS is constantly optimized, but it is a method for improvement, not a governance mechanism that provides direction and control. Option C is wrong because the Service Value Chain is an operating model that outlines the key activities to create value, but it is a framework for workflows, not a governance body that sets policies and ensures compliance.

175
MCQhard

An organization is reviewing its IT service management practices. They find that the same recurring incident is being logged multiple times without investigation. Which practice should address this to prevent recurrence?

A.Change Enablement
B.Incident Management
C.Problem Management
D.Service Desk
AnswerC

Problem Management is the ITIL practice specifically designed to reduce the likelihood and impact of incidents by identifying and analyzing the root causes of actual and potential service disruptions. It involves structured investigation, diagnosis, and the identification of workarounds or permanent solutions to prevent the recurrence of incidents. This practice proactively seeks to eliminate underlying issues, thereby improving overall service stability and quality.

Why this answer

Problem Management is responsible for identifying the root cause of recurring incidents and implementing permanent solutions to prevent recurrence. Incident Management focuses on restoring service quickly, while Change Enablement handles changes. Service Desk is the entry point but does not investigate root causes.

Exam trap

ITIL4F often tests the confusion between Incident Management and Problem Management; candidates may think Incident Management prevents recurrence, but it only restores service, while Problem Management addresses root causes.

How to eliminate wrong answers

Option A is wrong because Change Enablement manages changes to IT services, but does not investigate recurring incidents to find root causes. Option B is wrong because Incident Management aims to restore service as quickly as possible, often using workarounds, but does not focus on preventing recurrence. Option D is wrong because Service Desk is the first point of contact for users, but it does not typically perform root cause analysis; that is the role of Problem Management.

176
MCQhard

Which of the following BEST differentiates a normal change from an emergency change?

A.Normal changes are always low-risk; emergency changes are high-risk
B.Emergency changes are implemented without any approval
C.Normal changes are assessed and approved through standard procedures; emergency changes require urgent handling to avoid business impact
D.Emergency changes are only used for security incidents
AnswerC

This statement accurately differentiates normal and emergency changes by focusing on their procedural characteristics and underlying urgency. Normal changes are systematically planned, assessed, and approved through established, comprehensive procedures, allowing for thorough risk evaluation and resource allocation. In contrast, emergency changes are necessitated by an immediate, critical need to restore service or prevent significant business disruption, demanding an expedited assessment and approval process to mitigate severe impact swiftly.

Why this answer

Emergency changes are for urgent situations where delays would cause significant business impact, and they follow an expedited process. Normal changes follow standard assessment and approval.

177
Multi-Selectmedium

Which TWO of the following are phases of Problem Management?

Select 2 answers
A.Incident Resolution
B.Problem Identification
C.Event Classification
D.Problem Control
E.Service Desk
AnswersB, D

Problem Identification is the initial phase of Problem Management, where potential problems are recognized and logged for further investigation. This phase involves activities such as analyzing incident trends, detecting recurring issues, reviewing major incident reports, or receiving direct reports from monitoring tools or other practices. The objective is to identify the existence of an underlying cause that could lead to multiple incidents.

Why this answer

Problem Identification is a core phase of Problem Management because it involves detecting and logging problems before they are analyzed. In ITIL 4, Problem Management consists of three phases: Problem Identification, Problem Control, and Error Control. Problem Identification ensures that problems are formally recognized, often through trend analysis of incidents or proactive monitoring, so that root causes can be addressed.

Exam trap

The trap here is that candidates confuse the phases of Problem Management with other ITIL practices, such as Incident Management or Event Management, because all involve handling issues but have distinct objectives and workflows.

178
Multi-Selectmedium

Which TWO of the following are types of events in Monitoring and Event Management?

Select 2 answers
A.Incident
B.Problem
C.Service request
D.Informational
E.Warning
AnswersD, E

Informational events signify the successful completion of an activity or a normal operational state within an IT service or component. These events typically do not require immediate intervention but are crucial for maintaining an audit trail, understanding system behavior over time, and supporting trend analysis for capacity planning or performance optimization. They confirm that everything is functioning as expected.

Why this answer

In Monitoring and Event Management, events are classified by their significance and required action, and the two event types here are Informational (D) and Warning (E). An Informational event (D) is a normal, expected notification that requires no action, such as a device coming online or a routine job completing, so it is a valid event type. A Warning event (E) signals that a threshold is approaching or a condition is abnormal but service is not yet failed, so it alerts staff to investigate before an incident occurs, making it a valid event type.

By contrast, Incident (A) is a separate ITIL practice/record for an unplanned interruption or degradation of service, Problem (B) is the practice/record for the underlying root cause of one or more incidents, and Service request (C) is a user-initiated request handled by the Request Management practice; none of these are event types in Monitoring and Event Management.

Exam trap

The trap here is that candidates confuse the ITIL event types (Informational, Warning, Exception) with other ITIL practices (Incident, Problem, Service Request), leading them to incorrectly select Incident or Problem as event types.

179
Multi-Selectmedium

Which TWO of the following are characteristics of a service request compared to an incident?

Select 2 answers
A.They require root cause analysis
B.They cause unplanned service interruption
C.They are typically low-risk
D.They are pre-approved processes
E.They are always urgent
AnswersC, D

Service requests are inherently low-risk because they involve standard, well-understood procedures for providing information, access, or minor, pre-approved changes within established service parameters. Their pre-defined nature and often automated fulfillment minimize the potential for adverse impact on services or users. This characteristic ensures predictable outcomes and contributes to efficient service delivery without significant operational uncertainty.

Why this answer

Option C is correct because service requests are routine, low-risk interactions such as password resets or software installations, unlike incidents which may involve significant risk and disruption. Option D is correct because service requests follow pre-approved, standardized processes (often defined in a service catalog) with established workflows and approvals, whereas incidents require diagnosis and may need change management. Options A, B, and E are incorrect: root cause analysis is characteristic of problem management (not service requests), unplanned service interruption defines an incident, and urgency is not an inherent trait of service requests—they are handled by priority/SLA, not by being always urgent.

Exam trap

ITIL4F often tests the confusion between service requests and incidents, where candidates incorrectly assume any user-reported issue is an incident rather than recognizing that pre-approved, low-risk actions are service requests.

180
Multi-Selectmedium

Which THREE are components of the ITIL 4 Service Value System?

Select 3 answers
A.Service Level Agreements
B.Guiding Principles
C.Configuration Management Database
D.Governance
E.Service Value Chain
AnswersB, D, E

Guiding Principles are one of the five components of the ITIL 4 Service Value System, providing universal recommendations that guide an organisation's decision-making and improvement. This satisfies the stem's requirement for a Service Value System component, alongside governance, the service value chain, practices and continual improvement.

Why this answer

The ITIL 4 Service Value System (SVS) is composed of five core components: Guiding Principles, Governance, Service Value Chain, Practices, and Continual Improvement. Option B (Guiding Principles) is correct because the guiding principles are the recommendations that guide an organization in all circumstances and form one of the SVS components. Option D (Governance) is correct because governance is the means by which an organization is directed and controlled, and it is explicitly one of the SVS components.

Option E (Service Value Chain) is correct because the service value chain is the central operating model of the SVS, defining the six key activities (plan, improve, engage, design and transition, obtain/build, deliver and support) that convert inputs into outputs. Option A (Service Level Agreements) is not a component of the SVS; SLAs are documents/tools used within practices such as Service Level Management. Option C (Configuration Management Database) is not an SVS component either; the CMDB is a data repository used within the Service Configuration Management practice.

Exam trap

The trap here is that candidates often confuse operational artifacts (like SLAs or CMDBs) with the high-level structural components of the SVS, leading them to select familiar ITIL terms that are not part of the SVS framework.

181
MCQmedium

A major incident occurs. The IT team implements a workaround to restore service. Which practice is responsible for ensuring that the workaround does not become a permanent solution?

A.Change Enablement
B.Service Level Management
C.Problem Management
D.Incident Management
AnswerC

Problem Management is the practice responsible for reducing the likelihood and impact of incidents by identifying actual and potential causes of incidents and managing workarounds and known errors. After a major incident, especially one requiring a workaround, Problem Management actively investigates the root cause to prevent recurrence and drives the implementation of a permanent solution, thereby eliminating the need for the temporary workaround. This proactive and reactive approach ensures long-term stability and service improvement.

Why this answer

Problem Management is responsible for identifying the root cause of incidents and ensuring that workarounds are properly documented, analyzed, and eventually replaced with permanent fixes. In ITIL 4, Problem Management conducts root cause analysis (RCA) and manages known errors, so a workaround implemented during a major incident does not become a de facto permanent solution. This practice ensures that the workaround is tracked in the Known Error Database (KEDB) and that a permanent resolution is scheduled and implemented.

Exam trap

The trap here is that candidates confuse Incident Management's role in applying workarounds with the responsibility for ensuring those workarounds are temporary, but ITIL 4 explicitly assigns that long-term governance to Problem Management.

How to eliminate wrong answers

Option A is wrong because Change Enablement manages the lifecycle of changes (standard, normal, emergency) and ensures they are assessed, authorized, and implemented with minimal risk, but it does not own the process of ensuring workarounds are temporary or driving root cause analysis. Option B is wrong because Service Level Management focuses on defining, agreeing, and monitoring service level agreements (SLAs) and targets, not on the technical resolution of incidents or the permanence of workarounds. Option D is wrong because Incident Management is responsible for restoring normal service operation as quickly as possible, including implementing workarounds, but its primary goal is speed of recovery, not ensuring that workarounds are replaced with permanent solutions—that handoff belongs to Problem Management.

182
MCQmedium

Which metric is most commonly used to measure the effectiveness of the Service Desk?

A.SLA compliance
B.Mean Time to Repair (MTTR)
C.Number of changes
D.First Contact Resolution (FCR)
AnswerD

First Contact Resolution (FCR) is a key service desk metric that measures the percentage of customer issues or service requests that are fully resolved by the service desk agent during the customer's initial interaction, without requiring any further follow-up, transfer, or escalation. This metric directly reflects the service desk's efficiency and the quality of immediate support provided, significantly impacting customer satisfaction by minimizing effort and wait times. It is a direct indicator of the effectiveness of the initial support provided.

Why this answer

First Contact Resolution (FCR) is the most common metric for measuring Service Desk effectiveness because it directly reflects the ability to resolve user issues during the initial interaction without escalation or follow-up. A high FCR rate indicates efficient knowledge management, skilled analysts, and reduced user downtime, which are core objectives of the Service Desk practice as defined in ITIL 4.

Exam trap

The trap here is that candidates often confuse SLA compliance (a contractual metric) with effectiveness, but ITIL 4 emphasizes FCR as the key indicator of Service Desk value because it directly measures user experience and resolution efficiency.

How to eliminate wrong answers

Option A is wrong because SLA compliance measures adherence to agreed service levels (e.g., response time), not the effectiveness of resolving issues at first contact; it is a broader operational metric. Option B is wrong because Mean Time to Repair (MTTR) is a metric for incident management and technical resolution processes, not specifically for the Service Desk's first-contact effectiveness. Option C is wrong because the number of changes measures change management activity, not Service Desk performance; it is unrelated to user support resolution.

183
MCQhard

An IT team is investigating a recurring network outage. They have identified the root cause as a faulty router configuration. In which phase of Problem Management are they operating?

A.Error Control
B.Problem Identification
C.Incident Management
D.Problem Control
AnswerD

Problem Control is the phase of Problem Management dedicated to understanding the root cause of problems and developing workarounds. The IT team's activity of 'investigating a recurring network outage' directly aligns with the objectives of Problem Control, which involves detailed analysis to diagnose the underlying cause. This phase aims to identify the true reason for service disruptions, enabling effective resolution and preventing future recurrences.

Why this answer

Problem Control is the phase where root cause analysis is performed and the root cause is identified. Problem Identification is the first phase (detecting problems), and Error Control is the phase where known errors are managed and workarounds are created.

184
Multi-Selecthard

A company wants to improve how it handles problems. The problem manager is reviewing the current process and wants to ensure it aligns with the ITIL 4 Problem Management practice. Which TWO activities are part of the Problem Management practice? (Choose two.)

Select 2 answers
A.Negotiating and agreeing on service level targets with customers.
B.Investigating and diagnosing the root cause of incidents to determine how they can be eliminated or worked around.
C.Detecting and logging problems by analysing incident records and other sources for recurring or significant issues.
D.Restoring normal service operation as quickly as possible after an incident.
E.Managing the lifecycle of configuration items in the configuration management database.
AnswersB, C

Root cause investigation is central to Problem Management. Once a problem is logged, the practice analyses available data to determine why incidents are occurring and how to prevent recurrence. This may result in a permanent fix or a workaround, but the diagnostic work itself is a defining activity of the practice in ITIL 4.

Why this answer

Problem Management identifies potential and actual problems by analysing incident and other data, then investigates their root causes so they can be eliminated or worked around. Restoring service quickly belongs to Incident Management, negotiating targets belongs to Service Level Management, and managing configuration item lifecycles belongs to Service Configuration Management.

Exam trap

The trap here is conflating Incident Management's rapid restoration of service with Problem Management's slower root cause investigation, since the same people often perform both.

185
Multi-Selectmedium

Which TWO are phases of the Problem Management practice?

Select 2 answers
A.Service restoration
B.Problem control
C.Problem identification
D.Incident resolution
E.Change authorization
AnswersB, C

Problem control is a crucial phase within the Problem Management practice, primarily focused on analyzing identified problems to determine their root causes. This phase involves activities such as data analysis, trend analysis, and often includes developing workarounds or known errors to mitigate the impact of the problem while a permanent solution is being sought. Its objective is to understand the problem deeply and manage its effects.

Why this answer

Problem Management includes the phases Problem Identification (detecting and logging problems) and Problem Control (analyzing and documenting workarounds and root causes). These are the two phases that directly address the lifecycle of a problem, distinct from incident or change activities.

Exam trap

The trap here is that candidates confuse the phases of Incident Management (Service Restoration, Incident Resolution) with Problem Management phases, or mistakenly include Change Authorization as a problem phase due to its role in implementing fixes.

186
MCQhard

A service desk agent fulfills a password reset request for a user. According to ITIL 4, which practice does this activity belong to?

A.Change Enablement
B.Incident Management
C.Problem Management
D.Service Request Management
AnswerD

Service Request Management supports the agreed quality of a service by handling pre-defined, user-initiated requests for information, advice, or access to a service component. A password reset is a quintessential example of a standard service request, often automated or fulfilled through a well-documented process, enabling users to regain access efficiently and predictably.

Why this answer

A password reset is a standard, low-risk, pre-approved request that follows a defined procedure, which aligns with the Service Request Management practice. ITIL 4 defines a service request as a formal request from a user for something to be provided – such as information, advice, or access to a service – and password resets are a classic example. This practice focuses on fulfilling predefined, standardized requests efficiently, not on handling failures or changes.

Exam trap

The trap here is that candidates confuse a password reset with an incident because the user cannot log in, but ITIL 4 clearly separates a user's inability to access a service due to a forgotten password (a service request) from a system failure that prevents login (an incident).

How to eliminate wrong answers

Option A is wrong because Change Enablement manages changes to IT services that could impact service availability or performance, and a password reset is a routine, low-risk activity that does not require a formal change request. Option B is wrong because Incident Management deals with unplanned interruptions or reductions in service quality, whereas a password reset is a planned, user-initiated request, not a failure. Option C is wrong because Problem Management seeks to identify and eliminate the root causes of incidents, and a password reset is a standard operational task, not a root cause analysis activity.

187
MCQmedium

An organization wants to improve first-level resolution rates. Which practice should they focus on?

A.Service Desk
B.Problem Management
C.Service Level Management
D.Incident Management
AnswerA

The Service Desk is the primary functional unit responsible for direct interaction with users and the initial handling of incidents. Improving first-level resolution rates directly entails enhancing the Service Desk's capabilities, such as providing comprehensive staff training, optimizing access to knowledge management systems, and streamlining diagnostic tools and processes. While Incident Management is the overarching practice, the Service Desk is the operational entity whose performance directly impacts and can be optimized to improve this specific metric.

Why this answer

The Service Desk practice is the single point of contact between the provider and users, and it owns the handling of incidents and service requests at first level. Improving first-level resolution rates means empowering the Service Desk with better knowledge, scripts, and tools so more incidents are resolved without escalation.

Exam trap

ITIL4F often tests the confusion between Incident Management (the practice that restores service) and Service Desk (the practice that handles user contact and first-level resolution), causing candidates to pick Incident Management.

How to eliminate wrong answers

Option B is wrong because Problem Management focuses on root-cause analysis of recurring incidents, not on resolving individual incidents at first contact. Option C is wrong because Service Level Management defines and monitors SLAs and targets; it measures performance but does not directly improve first-level resolution capability. Option D is wrong because Incident Management is the broader practice that restores service; while related, the specific practice responsible for first-level resolution and user interaction is the Service Desk.

188
MCQmedium

During a major outage, a team implements a temporary workaround to restore service. Which ITIL 4 practice is primarily responsible for this action?

A.Problem Management
B.Incident Management
C.Change Enablement
D.Service Desk
AnswerB

Incident Management is the practice of minimizing the negative impact of incidents by restoring normal service operation as quickly as possible. Implementing a temporary workaround during a major outage directly aligns with this objective, as it prioritizes the rapid restoration of service availability and functionality to users, even if the underlying issue is not yet permanently resolved.

Why this answer

Incident Management is the ITIL 4 practice whose purpose is to minimize the negative impact of incidents by restoring normal service operation as quickly as possible. Implementing a temporary workaround during a major outage is the textbook definition of incident resolution, even though the underlying root cause is not yet addressed.

Exam trap

The trap is confusing Incident Management with Problem Management when a workaround is involved — candidates see 'root cause not fixed' and pick Problem Management, forgetting that restoring service is always Incident Management's mandate.

How to eliminate wrong answers

Option A is wrong because Problem Management focuses on identifying and eliminating the root cause of recurring incidents; it may log the workaround but does not own the act of restoring service during an active outage. Option C is wrong because Change Enablement authorizes and controls changes to the production environment; a workaround applied under incident pressure may follow an emergency change path, but the practice itself is not responsible for restoring service. Option D is wrong because the Service Desk is the single point of contact for users and handles logging, categorization, and initial triage — it does not typically implement technical workarounds to restore service.

189
MCQhard

An organization has identified that a recurring incident is caused by a specific software bug. The bug has been documented, and a workaround is known. What phase of Problem Management is this?

A.Problem Identification
B.Problem Control
C.Error Control
D.Incident Management
AnswerC

Error Control is the final phase of the Problem Management practice, specifically focused on managing known errors and their associated workarounds. Once a problem's root cause is identified and documented as a known error, Error Control ensures its impact is minimized through effective workarounds and that permanent solutions are developed and implemented via change enablement. For a recurring incident, this practice manages the ongoing response until the underlying known error is permanently resolved.

Why this answer

Error Control. In ITIL 4, once a problem has been identified and analyzed (Problem Control), and a known error (the documented bug with a workaround) is created, the lifecycle moves to Error Control. This phase manages known errors through their lifecycle, focusing on finding a permanent resolution (e.g., a software patch) while the workaround is used in the interim.

The question explicitly states the bug is documented and a workaround exists, which are the hallmarks of a known error under Error Control.

Exam trap

The trap here is that candidates confuse Problem Control (which includes diagnosing the root cause and finding a workaround) with Error Control (which manages the known error after the workaround is known), leading them to select B when the question explicitly states the bug is already documented and a workaround is known.

How to eliminate wrong answers

Option A is wrong because Problem Identification is the initial phase where incidents are grouped and analyzed to detect underlying problems; here, the bug is already documented and a workaround is known, so identification is complete. Option B is wrong because Problem Control involves diagnosing the root cause and determining a workaround; since the bug is already documented and a workaround exists, this phase has already been completed. Option D is wrong because Incident Management focuses on restoring normal service operation as quickly as possible for individual incidents, not on managing the lifecycle of a known error or its permanent fix.

190
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. According to ITIL 4, what should they do FIRST?

A.Investigate the root cause of the access issue
B.Log an incident and categorize it appropriately
C.Submit a change request to modify the CRM system
D.Create a service request for the users to regain access
AnswerB

Logging the reported issue as an incident is the foundational first step in the Incident Management process. This action creates a formal record, enabling tracking, communication, and assignment to the appropriate support teams. Categorizing it, typically by service, impact, and urgency, is crucial for correct prioritization and efficient routing, ensuring the incident receives the attention it requires based on its business effect.

Why this answer

According to ITIL 4, the first step in incident management is to log the incident and categorize it appropriately. This ensures the incident is recorded, can be tracked, and is routed to the correct support team. Logging is foundational before any investigation, escalation, or resolution activities.

This aligns with the incident management practice's workflow.

Exam trap

The trap is confusing incident management with problem management or service request management; candidates might think root cause investigation is first, but ITIL 4 stresses logging as the initial step.

How to eliminate wrong answers

Option A is wrong because investigating the root cause is part of problem management and typically occurs after the incident is logged and initial diagnosis is performed; it is not the first step. Option C is wrong because submitting a change request is not appropriate for an incident; changes are for modifying services, not for restoring them. Option D is wrong because creating a service request is for standard user requests, not for incidents; an incident is an unplanned interruption, so it should be logged as an incident, not a service request.

191
MCQmedium

An organization wants to improve customer satisfaction when users contact the service desk. Which metric is most appropriate to measure?

A.Customer Satisfaction (CSAT)
B.Mean Time to Restore Service (MTRS)
C.Number of incidents logged
D.First Call Resolution (FCR)
AnswerA

Customer Satisfaction (CSAT) is a direct feedback metric that quantifies how satisfied customers are with a product, service, or interaction. It is typically measured through surveys asking customers to rate their experience, often on a scale, providing immediate insight into their perception of value and service quality. Therefore, directly measuring CSAT is the most effective way to understand and improve customer satisfaction by capturing their subjective feelings.

Why this answer

CSAT is the direct measure of customer satisfaction, typically gathered through post-interaction surveys. It specifically captures the user's perception of the service desk experience, making it the most appropriate metric for the stated goal of improving satisfaction when users contact the service desk.

Exam trap

The trap here is that candidates often confuse First Call Resolution (FCR) with customer satisfaction, assuming that resolving an issue on the first call automatically means the customer is satisfied, but ITIL4F tests the distinction between operational metrics and experience metrics.

How to eliminate wrong answers

Option B (Mean Time to Restore Service) is wrong because it measures the average time to resolve an incident, not the user's satisfaction with the interaction. Option C (Number of incidents logged) is wrong because it measures volume of work, not quality or satisfaction. Option D (First Call Resolution) is wrong because while it correlates with satisfaction, it measures the percentage of issues resolved on the first contact, not the customer's direct sentiment or experience.

192
MCQhard

In ITIL 4, which practice is primarily responsible for managing the lifecycle of all IT assets?

A.Capacity Management
B.Service Configuration Management
C.IT Asset Management
D.Supplier Management
AnswerC

IT Asset Management (ITAM) is the practice responsible for planning, monitoring, and controlling the full lifecycle of all IT assets, from acquisition through disposal. This includes managing financial, contractual, and inventory details to optimize value, control costs, and support decision-making. ITAM ensures that an organization knows what IT assets it owns, where they are, who uses them, and how they are being utilized, thereby maximizing their value and minimizing risks throughout their service life.

Why this answer

IT Asset Management (ITAM) is the correct practice because it is specifically responsible for managing the lifecycle of all IT assets, including hardware, software, and licenses, from acquisition to disposal. This practice ensures financial and contractual accountability, tracking asset value, location, and status throughout their lifecycle. In contrast, Service Configuration Management focuses on configuration items (CIs) and their relationships, not the financial or lifecycle management of assets.

Exam trap

The trap here is that candidates often confuse Service Configuration Management with IT Asset Management because both involve tracking items, but ITAM specifically handles the financial and lifecycle aspects, while Configuration Management focuses on relationships and service model integrity.

How to eliminate wrong answers

Option A is wrong because Capacity Management focuses on ensuring that IT services and infrastructure meet current and future demand for performance and capacity, not on managing the lifecycle of IT assets. Option B is wrong because Service Configuration Management manages configuration items (CIs) and their relationships within the service model, but it does not handle the financial, contractual, or lifecycle aspects of assets like procurement, depreciation, or disposal. Option D is wrong because Supplier Management manages relationships with suppliers and their performance, contracts, and risks, not the lifecycle of IT assets themselves.

193
MCQhard

A company is designing a new service and wants to ensure that all IT services are described in a consistent manner. Which practice provides the framework for documenting service descriptions, including their functional and operational characteristics?

A.Service Catalog Management
B.Service Configuration Management
C.Service Level Management
D.IT Asset Management
AnswerA

This practice is responsible for providing a single source of consistent information on all services and service offerings, ensuring they are accurately described and available to the relevant audience. When designing a new service, Service Catalog Management ensures its details, including descriptions, availability, and how to request it, are properly documented and published for users. This ensures clarity and accessibility for consumers, aligning with the goal of designing a new service.

Why this answer

Service Catalog Management is the correct practice because it provides the single source of consistent information on all agreed services, ensuring that every service is described with its functional and operational characteristics in a standardized format. This practice defines the service catalog structure, which includes service descriptions, service level agreements, and operational details, enabling consistent documentation across the IT organization.

Exam trap

The trap here is that candidates often confuse Service Catalog Management with Service Configuration Management, thinking that documenting service characteristics is about managing configuration items, but the key distinction is that the catalog describes the service as a product, while configuration management tracks the underlying components.

How to eliminate wrong answers

Option B (Service Configuration Management) is wrong because it focuses on managing the configuration items (CIs) that support services, not on documenting the service descriptions themselves; it deals with relationships and attributes of CIs, not the functional/operational characteristics of services. Option C (Service Level Management) is wrong because it is concerned with negotiating, agreeing, and monitoring service level targets, not with the consistent documentation of service descriptions; it uses service descriptions but does not provide the framework for creating them. Option D (IT Asset Management) is wrong because it manages the lifecycle of tangible and intangible assets (e.g., hardware, software licenses), not the documentation of service characteristics; it tracks financial and contractual aspects, not functional or operational service details.

194
MCQhard

Which type of change is typically pre-approved and follows a predefined procedure?

A.Normal change
B.Emergency change
C.Service request
D.Standard change
AnswerD

Standard changes are low-risk, frequently occurring changes that are well understood and have a documented, pre-approved procedure. Because their risks are known, mitigated, and the steps are repeatable, they do not require individual assessment or authorization each time they are performed. This pre-approval allows for efficient and rapid implementation, aligning perfectly with the concept of following a predefined procedure without additional oversight.

Why this answer

Standard changes are pre-approved and follow a predefined procedure because they are low-risk, routine, and well-understood. ITIL 4 defines a standard change as one that is implemented through a documented, repeatable process, such as applying a security patch or provisioning a new user account, without requiring additional authorization each time.

Exam trap

The trap here is that candidates confuse a service request with a standard change, but ITIL 4 explicitly separates them: service requests are for predefined user needs (e.g., password reset), while standard changes are for predefined infrastructure or application modifications.

How to eliminate wrong answers

Option A is wrong because a normal change requires assessment and approval from the Change Authority before implementation, as it involves moderate to high risk and does not follow a predefined procedure. Option B is wrong because an emergency change is implemented urgently to resolve a major incident or security breach, but it still requires expedited approval and is not pre-approved. Option C is wrong because a service request is a formal request from a user for something like information or access, which may follow a predefined procedure but is not a type of change; it is handled through the service request management process, not change management.

195
Multi-Selecteasy

Which TWO of the following are true about a service request?

Select 2 answers
A.It is predefined and pre-approved
B.It can be fulfilled via the service catalogue
C.It is an unplanned interruption to a service
D.It is always caused by a known error
E.It requires a change authority approval
AnswersA, B

Service requests are inherently designed to be standard, repeatable transactions with predictable outcomes. Their predefined nature means that the necessary processes, resources, and often the associated costs are established in advance. Consequently, the required approvals are typically secured during the initial design and setup phase, allowing for efficient, automated, or semi-automated fulfillment without requiring ad-hoc authorization for each individual request instance.

Why this answer

Option A is correct because a service request is a predefined, pre-approved user request that follows a standard, documented procedure, so it does not require additional authorization each time. Option B is correct because service requests are typically fulfilled through the service catalogue, which lists the available standard services and their fulfillment workflows. Option C is incorrect because an unplanned interruption to a service is the definition of an incident, not a service request.

Option D is incorrect because a known error is a problem with a documented root cause and workaround, which relates to incident and problem management, not to standard service requests. Option E is incorrect because service requests are pre-approved and do not require change authority approval; that applies to changes, particularly normal changes.

Exam trap

The trap here is that candidates often confuse a service request with an incident or a change, mistakenly thinking that all user requests require formal approval or are caused by errors, when in fact service requests are predefined, low-risk, and pre-approved by design.

196
MCQmedium

A change request to upgrade the email server is assessed and authorized by the Change Advisory Board (CAB). After testing, it is scheduled for the next weekend. What type of change is this?

A.Emergency change
B.Normal change
C.Service request
D.Standard change
AnswerB

A normal change is the standard process for implementing significant modifications to services or service components that are not pre-approved as standard changes or necessitated by an emergency. This type of change requires thorough assessment of risks and benefits, detailed planning, and formal authorization by a designated Change Authority or Change Advisory Board (CAB). An email server upgrade, involving potential service disruption and requiring careful coordination, perfectly aligns with the structured governance provided by a normal change process.

Why this answer

A normal change is one that follows the full change authorization process, including assessment, approval by the Change Advisory Board (CAB), testing, and scheduling. The scenario describes a change that was assessed, authorized by the CAB, tested, and scheduled, which is the definition of a normal change.

Exam trap

The trap is confusing normal changes with standard changes — candidates may pick standard because it is scheduled, but standard changes are pre-authorized and do not require CAB approval, whereas normal changes do.

How to eliminate wrong answers

Option A is wrong because an emergency change is implemented urgently without prior CAB approval, often to resolve a major incident. Option C is wrong because a service request is a user request for something like password reset or software installation, not a planned infrastructure change. Option D is wrong because a standard change is pre-authorized, low-risk, and follows a defined procedure without requiring CAB approval each time.

197
MCQhard

A company wants to improve its incident resolution time. Which practice would be most relevant to analyze recurring incidents and identify underlying causes?

A.Problem Management
B.Continual Improvement
C.Incident Management
D.Change Enablement
AnswerA

Problem Management is the ITIL practice dedicated to reducing the likelihood and impact of incidents by identifying and resolving their root causes. By conducting thorough analysis of recurring incidents, it aims to implement permanent fixes or workarounds, thereby preventing future occurrences and significantly improving overall incident resolution times and service stability. This proactive approach moves beyond mere incident restoration to address underlying systemic issues.

Why this answer

Problem Management is the ITIL practice specifically designed to analyze recurring incidents by performing root cause analysis (RCA) and identifying underlying causes. By using techniques such as trend analysis, Kepner-Tregoe, or 5 Whys, Problem Management proactively reduces incident volume and resolution time, directly addressing the company's goal.

Exam trap

The trap here is confusing Incident Management (which restores service quickly) with Problem Management (which finds and fixes root causes), leading candidates to pick Incident Management because they focus on 'resolution time' rather than 'analyzing recurring incidents.'

How to eliminate wrong answers

Option B (Continual Improvement) is wrong because it focuses on overall service improvement through the CSI approach (Plan-Do-Check-Act) and does not specialize in analyzing recurring incidents or performing root cause analysis. Option C (Incident Management) is wrong because its primary goal is to restore normal service operation as quickly as possible, not to investigate underlying causes; it handles symptoms, not root causes. Option D (Change Enablement) is wrong because it manages the lifecycle of changes (RFCs, CAB approvals) to minimize risk, not to analyze incident patterns or identify root causes.

198
MCQmedium

A user contacts the service desk to request a new laptop because their current one is broken. The service desk analyst creates a ticket and arranges for a replacement. According to ITIL 4, what type of record should be raised?

A.Incident record
B.Change request
C.Problem record
D.Service request
AnswerD

A service request is a formal request from a user for something that is a normal part of service delivery, such as information, advice, a standard change, or access to a service. Requesting a replacement laptop, which is a pre-defined, pre-approved, and typically cataloged item, aligns perfectly with the definition of a service request. These requests are usually fulfilled through established, streamlined processes, often with minimal or no approval required beyond initial submission.

Why this answer

This is a service request because it is a pre-defined, pre-approved request for a standard item (replacement laptop for a broken one).

199
MCQmedium

A service desk team is implementing a 'shift-left' strategy. What is the PRIMARY goal of this approach?

A.To automate incident resolution using AI and chatbots
B.To ensure all calls are logged before escalation
C.To resolve more incidents and requests at the first point of contact without escalation
D.To increase empathy and customer satisfaction
AnswerC

A shift-left strategy is precisely defined by its objective to empower and equip the lowest possible support tier, typically the service desk, with the necessary knowledge, tools, and authority to resolve a greater volume of incidents and service requests immediately. This strategic approach aims to significantly reduce the number of issues that need to be escalated to more specialized and costly higher-level support teams. By resolving issues at the first point of contact, organizations improve efficiency, accelerate resolution times, and optimize resource allocation.

Why this answer

The primary goal of a 'shift-left' strategy in ITIL 4 is to resolve more incidents and service requests at the first point of contact (tier 0 or tier 1) without escalating to higher support levels. This reduces mean time to resolution (MTTR), lowers operational costs, and improves user satisfaction by minimizing handoffs. While automation and empathy can support shift-left, they are enablers, not the core objective.

Exam trap

The trap here is that candidates confuse the enablers (automation, empathy) with the primary goal, which is strictly about resolving incidents and requests at the first point of contact without escalation.

How to eliminate wrong answers

Option A is wrong because automating incident resolution with AI and chatbots is a tactic to enable shift-left, not its primary goal; the goal is resolution at first contact, not the tool used. Option B is wrong because logging all calls before escalation is a procedural requirement for tracking, but shift-left focuses on avoiding escalation altogether, not just logging. Option D is wrong because increasing empathy and customer satisfaction is a desired outcome of shift-left, but the primary goal is operational: resolving incidents and requests without escalation.

200
MCQhard

An organization has a change policy that requires all changes to be assessed and authorized by the Change Authority. A pre-approved change that has a low risk and follows a defined procedure is known as which type of change?

A.Normal change
B.Emergency change
C.Service request
D.Standard change
AnswerD

Standard changes are pre-authorised because they are low-risk, repeatable and follow a documented procedure, so they bypass the Change Authority's individual assessment and authorisation. This matches the stem's pre-approved, low-risk, defined-procedure constraint, distinguishing them from normal changes, which require assessment and authorisation.

Why this answer

A standard change is a pre-approved, low-risk change that follows a defined procedure, such as a password reset or server patch cycle. The ITIL 4 framework defines it as a change that does not require individual assessment or authorization by the Change Authority because its risk is well-understood and the implementation steps are documented in a standard operating procedure (SOP). This matches the description in the question exactly.

Exam trap

The trap here is that candidates confuse 'pre-approved' with 'normal change' because they think all changes need individual authorization, but ITIL 4 explicitly separates standard changes as pre-approved by definition, not requiring per-change authorization.

How to eliminate wrong answers

Option A is wrong because a normal change is any change that is not standard or emergency, and it requires assessment and authorization by the Change Authority on a case-by-case basis, not pre-approved. Option B is wrong because an emergency change is a high-risk, urgent change that must be implemented quickly to resolve a major incident or security threat, and it follows a separate expedited authorization process, not a low-risk pre-approved procedure. Option C is wrong because a service request is a formal request from a user for something to be provided (e.g., access, information), not a change to an IT service, and it is handled through the service request management process, not the change management process.

201
MCQhard

An organization has a CMDB that contains information about all configuration items (CIs) and their relationships. Which practice is primarily responsible for maintaining this information?

A.Service Catalog Management
B.Service Configuration Management
C.IT Asset Management
D.Deployment Management
AnswerB

Service Configuration Management is the practice responsible for maintaining information about services, configuration items (CIs), and their relationships. It ensures that accurate and reliable data concerning the configuration of services and the CIs that support them is available when and where needed. This practice explicitly owns and maintains the Configuration Management Database (CMDB), which stores all relevant CI attributes and their interdependencies. Its core function is to provide a logical model of the organization's infrastructure and services.

Why this answer

Service Configuration Management is the ITIL 4 practice responsible for ensuring that accurate and reliable information about configuration items (CIs) and their relationships is available when and where it is needed — including maintaining the CMDB. It covers the collection, storage, and ongoing accuracy of CI data throughout the service lifecycle.

Exam trap

ITIL4F often tests the overlap between Service Configuration Management and IT Asset Management — candidates pick IT Asset Management for CMDB questions, but the CMDB and CI relationships belong specifically to Service Configuration Management.

How to eliminate wrong answers

Option A is wrong because Service Catalog Management maintains the catalog of services offered to users, not the underlying CI relationships. Option C is wrong because IT Asset Management tracks the financial and inventory lifecycle of assets (cost, ownership, depreciation) — it overlaps with configuration management but does not own the CMDB relationships. Option D is wrong because Deployment Management moves new or changed components into live environments; it consumes CMDB data but does not maintain it.

202
MCQmedium

A problem has been identified and root cause analysis is underway. According to ITIL 4, which phase of Problem Management is this?

A.Problem control
B.Problem identification
C.Incident control
D.Error control
AnswerA

Problem control is the correct phase because it encompasses the activities required to analyze problems, identify their root causes, and develop workarounds or solutions. This phase actively manages problems from their initial logging through diagnosis and resolution, ensuring that recurring incidents are prevented. Root cause analysis is a core activity within problem control, aiming to understand the underlying reasons for incidents.

Why this answer

Problem control involves root cause analysis and resolution.

203
MCQhard

Which statement correctly distinguishes between a service request and an incident?

A.Service requests are managed by Problem Management, while incidents are managed by Incident Management
B.Service requests are always urgent, while incidents have varying priority
C.Service requests are for pre-approved, routine services; incidents are unplanned interruptions
D.Service requests are always initiated by the service desk, while incidents are initiated by users
AnswerC

This statement accurately distinguishes between service requests and incidents according to ITIL 4 principles. Service requests are formal requests from a user for something standard that is part of normal service delivery, such as requesting access to an application or a standard software installation, and are typically pre-approved. Conversely, an incident is defined as an unplanned interruption to a service or a reduction in the quality of a service, requiring prompt resolution to restore normal operations. This fundamental difference in nature and purpose is central to effective service management.

Why this answer

In ITIL 4, a service request is a user-initiated request for something that is pre-approved, routine, and part of normal service delivery — such as a password reset, software installation, or information request. An incident, by contrast, is an unplanned interruption to a service or a reduction in service quality. This distinction is fundamental to how the Service Desk triages and routes work.

Exam trap

ITIL4F often tests the misconception that urgency or priority distinguishes service requests from incidents — the real differentiator is whether the work is pre-approved/routine (request) versus an unplanned interruption or degradation (incident).

How to eliminate wrong answers

Option A is wrong because service requests are typically handled by the Service Desk or Request Management (not Problem Management), and Problem Management deals with root causes of incidents, not service requests. Option B is wrong because urgency is not the defining characteristic — service requests can have varying priorities just like incidents, and many incidents are low priority. Option D is wrong because both service requests and incidents are typically initiated by users; the Service Desk may log them on behalf of users, but initiation is not the distinguishing factor.

204
MCQmedium

A team is using the ITIL continual improvement model. After defining the vision, what is the NEXT step?

A.Define measurable targets
B.Create an improvement plan
C.Identify the improvement opportunities
D.Assess the current state
AnswerD

After a team has established "What is the vision?" for improvement, the logical and prescribed next step in the ITIL Continual Improvement Model is "Where are we now?", which involves assessing the current state. This step requires a thorough understanding of existing services, processes, and practices to establish a baseline. By evaluating current performance, capabilities, and challenges, the organization can accurately identify gaps and areas ripe for improvement, providing the necessary foundation for subsequent steps.

Why this answer

The ITIL continual improvement model defines a sequence of steps: 'What is the vision?', 'Where are we now?', 'Where do we want to be?', 'How do we get there?', 'Take action', 'Did we get there?', and 'How do we keep the momentum?'. After defining the vision (step 1), the next step is to assess the current state (step 2) to establish a baseline before setting measurable targets or creating an improvement plan.

Exam trap

The trap here is that candidates often confuse the order of the ITIL continual improvement model steps, mistakenly thinking that identifying improvement opportunities or setting targets comes immediately after defining the vision, rather than assessing the current state first.

How to eliminate wrong answers

Option A is wrong because defining measurable targets occurs after assessing the current state, as you need a baseline to set meaningful targets. Option B is wrong because creating an improvement plan comes later in the model, after you have identified where you want to be and how to get there. Option C is wrong because identifying improvement opportunities is part of the 'Where do we want to be?' step, which follows the current state assessment.

205
MCQeasy

Which practice is responsible for being the single point of contact (SPOC) between the service provider and users?

A.Incident Management
B.Change Enablement
C.Service Desk
D.Service Level Management
AnswerC

The Service Desk practice is explicitly designed to be the single point of contact (SPOC) between the service provider and its users. Its primary function is to handle all user interactions, including receiving and logging service requests, incidents, and general inquiries, providing initial support, and facilitating communication throughout the service lifecycle. By centralizing user contact, the Service Desk ensures efficient and consistent support, improving user experience and streamlining service operations.

Why this answer

The Service Desk practice is explicitly defined in ITIL 4 as the single point of contact (SPOC) between the service provider and users. It handles all user communications, including incidents, service requests, and feedback, ensuring users have one consistent entry point. This role is distinct from Incident Management, which is a broader practice that may involve multiple teams.

Exam trap

ITIL4F often tests the specific definition of the Service Desk as the SPOC, and candidates may incorrectly choose Incident Management because they associate incident handling with user contact, missing the broader SPOC role.

How to eliminate wrong answers

Option A is wrong because Incident Management is the practice focused on restoring service, not the functional SPOC; it may use the service desk as the entry point but is not itself the SPOC. Option B is wrong because Change Enablement is about authorizing and managing changes, not user communication. Option D is wrong because Service Level Management negotiates and manages SLAs, but it does not serve as the day-to-day contact point for users.

206
Multi-Selecthard

Which THREE of the following are types of events in Monitoring and Event Management?

Select 3 answers
A.Emergency
B.Informational
C.Exception
D.Warning
E.Standard
AnswersB, C, D

Informational events report normal operational status, such as a service completing successfully or a threshold remaining within limits. ITIL 4 defines three event types — informational, warning, and exception — so this satisfies the stem's requirement for a recognised type, requiring no action but logged for visibility.

Why this answer

In ITIL's Monitoring and Event Management practice, events are classified into three types: informational, warning, and exception. Option B (Informational) is correct because informational events simply notify that a device, service, or process has changed state or completed an activity and require no action. Option C (Exception) is correct because exception events indicate that a component or service is operating outside normal or expected parameters and typically requires intervention.

Option D (Warning) is correct because warning events signal that something is approaching a threshold or abnormal condition but has not yet breached it, so proactive action may be needed. Options A (Emergency) and E (Standard) are not part of the ITIL event type classification, even though 'emergency' may describe severity and 'standard' may describe a change type.

Exam trap

The trap here is that candidates often confuse event types with incident priority levels (like Emergency) or change categories (like Standard), leading them to select options that are valid in other ITIL practices but not in Monitoring and Event Management.

207
MCQhard

An organization is experiencing repeated incidents due to a software bug. The problem manager has identified the root cause and documented a known error with a workaround. According to ITIL 4, in which phase of problem management are they operating?

A.Incident resolution
B.Error control
C.Problem identification
D.Problem control
AnswerB

Error control is the specific phase within problem management that deals with known errors, which are problems with an identified root cause. When an organization experiences repeated incidents due to a known root cause, error control focuses on managing these known errors, implementing workarounds to reduce impact, and planning permanent solutions to eliminate the error. This phase ensures that the underlying issue is actively managed until a definitive fix is deployed.

Why this answer

Error control is the phase where known errors are managed, workarounds are documented, and resolution is pursued. Problem identification is the first phase, and problem control involves root cause analysis.

208
Multi-Selecthard

Which THREE of the following are key activities of Problem Management?

Select 3 answers
A.Restoring service as quickly as possible
B.Problem identification
C.Creating known error records
D.Authorizing changes
E.Root cause analysis
AnswersB, C, E

Problem identification is a crucial initial activity in Problem Management, involving the detection of potential problems through various means. This often includes trend analysis of recurring incidents, review of monitoring alerts, analysis of supplier reports, or direct input from service desk agents recognizing patterns. Proactive identification helps prevent future incidents and reduce their overall impact on services.

Why this answer

Problem Management is the ITIL practice responsible for managing the lifecycle of problems, and its core activities include problem identification (option B), which involves detecting and logging problems from incident trends, monitoring alerts, or supplier notifications so they can be investigated. It also performs root cause analysis (option E), using techniques such as the 5 Whys, Kepner-Tregoe, or Ishikawa diagrams to determine the underlying cause of one or more incidents. Once the cause is understood, Problem Management creates known error records (option C) documenting the problem, its root cause, and any workaround, which are stored in the known error database to support faster future incident resolution.

Option A, restoring service as quickly as possible, is an Incident Management objective, not a Problem Management activity. Option D, authorizing changes, belongs to Change Enablement (Change Management), which reviews and approves changes via the change authority, even though Problem Management may raise an RFC to implement a permanent fix.

Exam trap

The trap here is confusing the activities of Problem Management with those of Incident Management or Change Enablement, as candidates often mistakenly select 'restoring service' (an Incident Management goal) or 'authorizing changes' (a Change Enablement task) as Problem Management activities.

209
MCQmedium

Which type of change is pre-approved and follows a defined procedure with minimal risk?

A.Normal change
B.Urgent change
C.Emergency change
D.Standard change
AnswerD

Standard changes are low-risk, frequently occurring changes that are pre-authorized and do not require additional approval before implementation. They follow a well-documented, repeatable procedure that is already established and proven, making their execution efficient and predictable. This pre-approval and adherence to a defined process directly aligns with the question's description, as they are managed without needing a full assessment each time.

Why this answer

A standard change is pre-approved by the change authority and follows a defined, low-risk procedure. It does not require a separate change advisory board (CAB) meeting for each occurrence, as its risk is well-understood and the implementation steps are documented and repeatable.

Exam trap

The trap here is that candidates confuse 'standard change' with 'normal change' because both are routine, but standard change is the only one that is pre-approved and follows a low-risk, predefined procedure without requiring a new CAB decision each time.

How to eliminate wrong answers

Option A is wrong because a normal change requires approval from the change authority (e.g., CAB) and is not pre-approved; it follows a full assessment and authorization process. Option B is wrong because an urgent change is not a recognized ITIL 4 category; the correct term for a high-priority, time-sensitive change is 'emergency change'. Option C is wrong because an emergency change is implemented urgently to resolve a major incident or critical issue, carries higher risk, and requires expedited approval (often via an emergency CAB), not pre-approval.

210
MCQhard

A service desk analyst resolves an incident by providing a workaround from the Known Error Database. According to ITIL 4, this activity is part of which practice?

A.Problem Control
B.Error Control
C.Service Request Management
D.Incident Management
AnswerD

Incident Management's primary objective is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations. When a permanent solution is not immediately available, applying a workaround is a crucial and common strategy within Incident Management to achieve this rapid service restoration. The service desk analyst's action directly aligns with the core purpose of Incident Management: getting the service back up and running for the user.

Why this answer

Incident Management is the practice responsible for managing the lifecycle of all incidents, including resolving them, often by applying workarounds from the Known Error Database. The Known Error Database is maintained by Problem Management, but the act of resolving an incident using a workaround is part of Incident Management. Problem Control and Error Control are activities within Problem Management, not separate practices.

Service Request Management handles requests, not incidents.

Exam trap

ITIL4F often tests the confusion between Incident Management and Problem Management; candidates must remember that using a workaround from the KEDB is an Incident Management activity, while maintaining the KEDB is Problem Management.

How to eliminate wrong answers

Option A is wrong because Problem Control is an activity within Problem Management that focuses on identifying root causes, not resolving incidents. Option B is wrong because Error Control is also part of Problem Management and deals with managing known errors, not incident resolution. Option C is wrong because Service Request Management handles user requests (e.g., password resets) rather than incidents and workarounds.

211
MCQeasy

Which practice involves detecting and classifying events such as informational, warning, and exception?

A.Monitoring and Event Management
B.Incident Management
C.Change Enablement
D.Service Desk
AnswerA

Monitoring and Event Management is the dedicated ITIL practice responsible for systematically observing services and service components to detect changes of state, known as events. It involves establishing thresholds, collecting data from various sources, and then classifying these events to determine their significance and the appropriate response, whether it's an informational alert, a warning, or an exception requiring immediate action. This proactive approach ensures that potential issues are identified and addressed before they escalate into incidents or impact service quality.

Why this answer

The Monitoring and Event Management practice is specifically responsible for detecting and classifying events into categories such as informational, warning, and exception. This practice continuously observes IT services and infrastructure, generating events that are then categorized based on their severity and impact, enabling appropriate responses.

Exam trap

The trap here is that candidates often confuse 'event detection' with 'incident response,' mistakenly selecting Incident Management because they associate warnings and exceptions with incidents, but the practice of detecting and classifying events is explicitly Monitoring and Event Management.

How to eliminate wrong answers

Option B (Incident Management) is wrong because it focuses on restoring normal service operation after an incident has occurred, not on the initial detection and classification of events. Option C (Change Enablement) is wrong because it manages the lifecycle of changes to IT services, including approval and implementation, not event detection. Option D (Service Desk) is wrong because it provides a single point of contact for users to report issues and request services, but it does not perform automated event detection or classification.

212
Multi-Selecthard

Which THREE of the following are components of the ITIL 4 Service Value System?

Select 3 answers
A.Guiding principles
B.ITIL maturity model
C.Service value chain
D.Service catalogue
E.Governance
AnswersA, C, E

Guiding principles are recommendations that can guide an organization in all circumstances, regardless of changes in its goals, strategies, type of work, or management structure. They promote a holistic approach to service management and decision-making. As one of the foundational elements, guiding principles are a core component of the ITIL 4 Service Value System, ensuring effective and ethical practice across all activities.

Why this answer

The ITIL 4 Service Value System (SVS) is composed of five core components: guiding principles, governance, the service value chain, practices, and continual improvement. Option A (Guiding principles) is correct because the guiding principles are one of the SVS components, providing recommendations that guide an organization in all circumstances. Option C (Service value chain) is correct because the service value chain is the central operating model of the SVS, defining six key activities (plan, improve, engage, design and transition, obtain/build, and deliver and support) that convert inputs into outputs.

Option E (Governance) is correct because governance is an explicit SVS component, directing and controlling the organization through evaluation, direction, and monitoring. Option B (ITIL maturity model) is not part of the ITIL 4 SVS; maturity assessments are not one of its five components. Option D (Service catalogue) is not an SVS component either; a service catalogue is a practice/tool-level artifact within service management, not a structural element of the SVS.

Exam trap

The trap is mixing up ITIL 4 SVS components with other ITIL concepts like maturity models or service catalogue; candidates may select B or D incorrectly.

213
MCQhard

An organization wants to improve the user experience for password reset requests. Currently, users call the service desk for each password reset, resulting in high call volume. According to ITIL 4, which practice should be applied to streamline this process?

A.Incident Management, because password reset is a disruption
B.Problem Management, to find the root cause of forgotten passwords
C.Change Enablement, because resetting a password changes the user account
D.Service Request Management, by offering a self-service password reset option through the service catalogue
AnswerD

Service Request Management is the appropriate practice for handling pre-defined, pre-approved requests from users for information, advice, standard changes, or access to a service. A password reset perfectly fits this description as a common, routine, and often automated request for access. Offering a self-service password reset option through a service catalogue significantly enhances user experience and operational efficiency by providing immediate resolution.

Why this answer

A password reset is a routine, pre-approved request from a user, which ITIL 4 classifies as a service request handled by the Service Request Management practice. Publishing a self-service password reset option in the service catalogue lets users resolve the need without contacting the service desk, directly reducing call volume. This aligns with ITIL 4's emphasis on value co-creation and shifting work to self-service where appropriate.

Exam trap

ITIL4F often tests the boundary between incidents and service requests, tricking candidates into labeling any user-reported issue as an incident even when it is a routine, pre-approved request like a password reset.

How to eliminate wrong answers

Option A is wrong because an incident is an unplanned interruption or degradation of a service; a routine password reset is not a disruption, so Incident Management is the wrong practice. Option B is wrong because Problem Management investigates root causes of recurring incidents, and while forgotten passwords may be common, the question asks how to streamline the request process, not eliminate the underlying cause. Option C is wrong because Change Enablement authorizes changes to IT infrastructure; resetting a user's password is a standard, pre-authorized service request, not a change requiring assessment and approval.

214
MCQmedium

An IT team discovers a recurring pattern of errors in a financial application. According to ITIL 4, which practice should be initiated to investigate the root cause?

A.Problem Management
B.Change Enablement
C.Service Request Management
D.Incident Management
AnswerA

Problem Management is the ITIL practice focused on reducing the likelihood and impact of incidents by identifying and eliminating their root causes. When an IT team discovers a recurring pattern of errors, it indicates an underlying issue that needs investigation beyond just restoring service. This practice involves activities like trend analysis, major problem review, and known error identification to prevent future occurrences and improve service stability.

Why this answer

Problem Management identifies the root cause of incidents to prevent recurrence.

215
Multi-Selectmedium

Which THREE of the following are phases of the ITIL Continual Improvement Model?

Select 3 answers
A.What is the vision?
B.Where are we now?
C.How do we get there?
D.What is the budget?
E.Who is responsible?
AnswersA, B, C

"What is the vision?" is the crucial first step of the ITIL Continual Improvement Model. This phase focuses on establishing a clear understanding of the overall objectives, strategic goals, and desired outcomes for the improvement initiative, ensuring alignment with the organization's mission and stakeholder expectations. It defines the purpose and direction for all subsequent improvement activities, clarifying what success looks like.

Why this answer

The ITIL Continual Improvement Model includes 7 steps: What is the vision?, Where are we now?, Where do we want to be?, How do we get there?, Take action, Did we get there?, How do we keep the momentum going?

216
MCQhard

An event indicating that a server's CPU usage has exceeded 90% for 5 minutes is classified as which type?

A.Exception
B.Critical
C.Informational
D.Warning
AnswerD

A warning event in ITIL 4 signifies that a service, component, or configuration is operating outside its normal parameters and indicates a potential future issue or degradation. A server's CPU usage exceeding 90% is a clear precursor to performance problems or an eventual system failure (an exception) if left unaddressed. This event provides an opportunity for proactive intervention to prevent a more severe incident, perfectly aligning with the definition of a warning.

Why this answer

An event that signals a potential service degradation is a warning event.

217
MCQmedium

Which practice is responsible for negotiating and agreeing service level targets with customers?

A.Supplier Management
B.Service Level Management
C.Service Desk
D.Business Relationship Management
AnswerB

Service Level Management is the dedicated practice responsible for establishing clear, business-focused targets for service performance and ensuring these are met. This practice explicitly includes the critical activities of negotiating and agreeing upon Service Level Agreements (SLAs) with customers, defining the scope, quality, and availability of services. It then monitors, reports, and reviews actual service performance against these agreed levels to manage customer expectations effectively.

Why this answer

Service Level Management (SLM) is the ITIL practice specifically responsible for negotiating, agreeing, and documenting service level targets with customers, typically captured in a Service Level Agreement (SLA). It ensures that measurable targets (e.g., availability, response times) are aligned with business needs and are monitored, reported, and reviewed regularly.

Exam trap

The trap here is that candidates often confuse Business Relationship Management (BRM) with Service Level Management because both involve customer interaction, but BRM focuses on strategic relationships and overall satisfaction, while SLM handles the tactical negotiation and documentation of specific measurable targets.

How to eliminate wrong answers

Option A is wrong because Supplier Management focuses on managing relationships and contracts with external suppliers, not on negotiating service targets with customers. Option C is wrong because the Service Desk is the single point of contact for incident and request handling, not for negotiating SLAs. Option D is wrong because Business Relationship Management is responsible for understanding customer needs and ensuring overall satisfaction, but the actual negotiation and agreement of specific service level targets is performed by Service Level Management.

218
MCQeasy

A software company is experiencing frequent production outages due to unauthorized changes. Which practice should be implemented to improve control over changes?

A.Deployment Management
B.Release Management
C.Change Enablement
D.Service Validation and Testing
AnswerC

Change Enablement is the practice responsible for maximizing the number of successful service and product changes by ensuring risks are properly assessed, authorizing changes to proceed, and managing the change schedule. It establishes the policies and procedures for evaluating, approving, and scheduling changes, thereby preventing unauthorized modifications and reducing the likelihood of production outages caused by poorly managed changes. This practice directly addresses the need for control and authorization.

Why this answer

Change Enablement (option C) is the correct practice because it specifically governs the lifecycle of changes, including authorization, review, and control of changes to prevent unauthorized modifications. In a software company experiencing production outages due to unauthorized changes, implementing Change Enablement ensures that every change is assessed, approved, and logged before deployment, directly addressing the root cause of the outages.

Exam trap

PeopleCert often tests the distinction between 'doing the change' (Deployment/Release Management) and 'controlling the change' (Change Enablement), causing candidates to confuse the operational execution of changes with the governance and authorization of changes.

How to eliminate wrong answers

Option A (Deployment Management) is wrong because it focuses on moving new or changed components from development to production environments, not on authorizing or controlling the changes themselves; unauthorized changes can still occur if deployment processes are bypassed. Option B (Release Management) is wrong because it deals with the planning, scheduling, and controlling of releases (a set of changes) through production, but it does not enforce the initial authorization of individual changes; unauthorized changes can still be included in a release. Option D (Service Validation and Testing) is wrong because it ensures that a service or change meets its intended outcomes and quality criteria after implementation, but it does not prevent unauthorized changes from being made in the first place; testing cannot catch changes that were never authorized.

219
MCQmedium

In ITIL 4, which practice is responsible for maintaining the Configuration Management Database (CMDB)?

A.Change Enablement
B.IT Asset Management
C.Deployment Management
D.Service Configuration Management
AnswerD

Service Configuration Management is the dedicated practice responsible for maintaining accurate and reliable information about the services and the configuration items (CIs) that support them. This includes planning, identifying, controlling, monitoring, and verifying the versions, baselines, and relationships of all CIs throughout their lifecycle. Its core function is to ensure the integrity of the Configuration Management System (CMS) and the Configuration Management Database (CMDB), providing a foundational understanding of the service landscape for other practices.

Why this answer

Service Configuration Management (D) is the ITIL 4 practice responsible for maintaining the Configuration Management Database (CMDB). It ensures that accurate and reliable information about configuration items (CIs) and their relationships is available when and where needed, supporting all other service management practices.

Exam trap

The trap here is that candidates confuse the practice that uses the CMDB (Change Enablement or IT Asset Management) with the practice that is responsible for maintaining it, but ITIL 4 explicitly assigns CMDB maintenance to Service Configuration Management.

How to eliminate wrong answers

Option A is wrong because Change Enablement manages the lifecycle of changes to services and CIs, but it does not own or maintain the CMDB; it uses the CMDB to assess change impact. Option B is wrong because IT Asset Management focuses on managing the financial, contractual, and lifecycle aspects of IT assets (e.g., procurement, depreciation), not the logical configuration data stored in the CMDB. Option C is wrong because Deployment Management handles the movement of new or changed components to live environments, but it does not maintain the CMDB; it may update CI statuses as part of deployment, but the CMDB's ongoing maintenance is the responsibility of Service Configuration Management.

220
MCQmedium

A user requests a new software installation that is already approved and listed in the service catalogue. According to ITIL 4, how should this request be classified?

A.As an incident
B.As a normal change
C.As an emergency change
D.As a service request
AnswerD

A service request is a formal request from a user for something that is part of the normal service delivery, typically a pre-defined, low-risk, and repeatable action. These requests are often pre-authorized and follow a standard procedure, frequently managed through a service catalogue. The installation of pre-approved software perfectly aligns with this definition, representing a standard offering that can be fulfilled efficiently without extensive assessment or authorization.

Why this answer

According to ITIL 4, a service request is a request from a user that is a normal part of service delivery and is not an incident or a change. Since the software installation is already approved and listed in the service catalogue, it is a pre-approved, standard request that can be fulfilled through the service request management practice. Therefore, it should be classified as a service request.

Exam trap

ITIL4F often tests the confusion between service requests and changes, where candidates might think that any request that involves installing software is a change, but if it's pre-approved and in the service catalogue, it's a service request.

How to eliminate wrong answers

Option A is wrong because an incident is an unplanned interruption or reduction in service quality, which is not the case here; the user is requesting something that is working as intended. Option B is wrong because a normal change requires assessment and authorization by the change authority, but this request is already approved and listed in the service catalogue, so it does not need to go through the change process. Option C is wrong because an emergency change is for changes that must be implemented immediately to resolve a major incident or security issue, which is not applicable here.

221
Multi-Selectmedium

Which TWO of the following are key components of the ITIL 4 Service Value System (SVS)?

Select 2 answers
A.Continual improvement
B.Guiding principles
C.ITIL Maturity Model
D.Value
E.The Deming Cycle (Plan-Do-Check-Act)
AnswersA, B

Continual improvement is one of the five essential components of the ITIL 4 Service Value System (SVS). This component ensures that an organization's products, services, and practices are consistently aligned with evolving stakeholder needs and business objectives. It drives ongoing efforts to enhance value co-creation across all aspects of service management, making it integral to the SVS's dynamic nature.

Why this answer

The ITIL 4 Service Value System (SVS) is composed of five core components: guiding principles, governance, the service value chain, practices, and continual improvement. Option A (Continual improvement) is correct because it is one of these five components, representing the recurring organizational activity performed at all levels to ensure performance continually meets stakeholders' expectations. Option B (Guiding principles) is correct because recommendations that can guide an organization in all circumstances are a foundational component of the SVS, supporting decision-making and improvement across the value chain.

Option C (ITIL Maturity Model) is incorrect because it is a separate assessment tool used to evaluate an organization's ITIL practices, not a component of the SVS. Option D (Value) is incorrect because value is the perceived benefits, usefulness, and importance of something—the outcome the SVS is designed to co-create—not a structural component of the SVS itself. Option E (The Deming Cycle or Plan-Do-Check-Act) is incorrect because PDCA is a continual improvement model referenced within ITIL 4, not one of the five SVS components.

Exam trap

The trap is confusing the SVS components with other ITIL concepts like the Maturity Model or the Deming Cycle. Candidates might think 'Value' is a component because it's central, but it's the output. Also, the Deming Cycle is a tool used within continual improvement, not a standalone component.

222
MCQmedium

An event that indicates a breach of a threshold is classified as which type?

A.Critical event
B.Exception event
C.Warning event
D.Informational event
AnswerB

An exception event is specifically generated when a predefined operational or performance threshold has been violated, indicating a deviation from the expected or acceptable state of a service or component. This type of event signals that a specific metric, such as CPU utilization, memory usage, or response time, has crossed its upper or lower limit. It requires attention because it represents an actual breach, potentially impacting service quality or stability, and often triggers an alert for investigation.

Why this answer

In ITIL event management, an exception event is defined as an event that indicates a breach of a threshold or a deviation from normal operation. This includes events that signify something is not working as expected, such as a server exceeding CPU threshold or a service becoming unavailable.

Exam trap

The trap is confusing 'exception event' with 'critical event'—candidates often equate severity with type, but ITIL classifies exception events specifically as threshold breaches, regardless of severity.

How to eliminate wrong answers

Option A is wrong because a critical event is a severity level, not a type based on threshold breach; critical events may be exception events but the classification 'exception' specifically denotes threshold breach. Option C is wrong because a warning event indicates a threshold is approaching but not yet breached. Option D is wrong because an informational event is simply a notification of normal operation, not a breach.

223
MCQhard

Which of the following BEST distinguishes an incident from a service request?

A.Incidents are unplanned interruptions, while service requests are predefined and pre-approved
B.Incidents have a higher priority than service requests
C.Incidents are reported by users, while service requests are initiated by the service provider
D.Incidents require a workaround, while service requests require a change
AnswerA

This option correctly identifies the fundamental distinction in ITIL 4. Incidents represent an unplanned interruption or reduction in the quality of a service, disrupting normal operations unexpectedly. In contrast, service requests are predefined, standard requests for information, advice, or access to a service, which are typically pre-approved and follow established procedures without requiring extensive analysis or authorization.

Why this answer

ITIL 4 defines an incident as an unplanned interruption to a service or a reduction in its quality, whereas a service request is a predefined, pre-approved, and standardized request from a user for information, advice, access, or a change that does not require a formal risk assessment or approval process. This distinction is fundamental to ITIL's service value system, as incidents trigger the incident management practice to restore normal service operation, while service requests follow the service request management practice with a lower risk profile and standardized fulfillment procedures.

Exam trap

A common misconception is that priority or reporting source defines the difference, but the core distinction lies in the predefined, pre-approved nature of service requests versus the unplanned, interruption-based nature of incidents.

How to eliminate wrong answers

Option B is wrong because priority is not a distinguishing factor; both incidents and service requests can have varying priority levels based on business impact and urgency, and a service request (e.g., a critical access request) may have higher priority than a low-impact incident. Option C is wrong because both incidents and service requests can be reported or initiated by users or the service provider; for example, a monitoring system can automatically detect and report an incident, and a service provider may proactively initiate a service request for a user (e.g., password reset). Option D is wrong because a workaround is a temporary solution for an incident, not a defining characteristic, and service requests do not require a change; they are fulfilled through standard procedures, whereas a change is a separate practice for alterations to controlled services or components.

224
MCQmedium

A problem manager has identified that recurring incidents are caused by a software bug. The vendor has been notified and a permanent fix is scheduled for the next release. What should the problem manager do in the meantime?

A.Close the problem record since the fix is scheduled
B.Document the known error and provide a workaround
C.Escalate to change enablement for an emergency change
D.Implement the workaround immediately for all users
AnswerB

Documenting a known error and providing a workaround is a critical activity within the 'error control' phase of Problem Management. A known error signifies that the root cause of a problem has been identified, and a workaround is a temporary solution that reduces or eliminates the impact of incidents while awaiting a permanent fix. This enables Incident Management to restore service more quickly and efficiently, minimizing business disruption for users.

Why this answer

The problem manager should document the known error and provide a workaround to mitigate the impact until the permanent fix is released. This follows ITIL problem management practices: when a root cause is identified but a permanent fix is not yet available, the problem is classified as a known error, and a workaround should be documented and communicated to incident management for faster resolution of future incidents.

Exam trap

ITIL4F often tests the distinction between problem and incident management, and candidates may incorrectly think that a scheduled fix means the problem can be closed, but ITIL requires the problem to remain open until the fix is verified.

How to eliminate wrong answers

Option A is wrong because closing the problem record would lose track of the issue and prevent monitoring until the fix is implemented; the problem should remain open until the fix is verified. Option C is wrong because escalating to change enablement for an emergency change is not warranted if the fix is already scheduled for the next release; emergency changes are for urgent, unplanned fixes. Option D is wrong because implementing the workaround for all users may not be appropriate; the workaround should be documented and applied as needed by incident management, not necessarily deployed to all users immediately.

225
MCQmedium

During a major incident, a workaround is implemented to restore service. Later, the service desk continues to use the workaround to help users. According to ITIL 4, where should this workaround be documented?

A.In a change request
B.In a known error record in the KEDB
C.In the configuration management system (CMS)
D.In the incident record only
AnswerB

A known error is a problem that has been analyzed and for which a workaround or a permanent solution has been identified. The Known Error Database (KEDB) is the designated repository for these known errors, specifically including their associated workarounds. Documenting the workaround here ensures it is readily available for future incidents related to the same underlying problem, facilitating faster resolution and informing proactive problem management efforts.

Why this answer

According to ITIL 4, a workaround that is used repeatedly after a major incident should be documented in a known error record within the Known Error Database (KEDB). This ensures that the workaround is formally captured, linked to the underlying problem, and available for future incidents, rather than being lost in a single incident record or change request.

Exam trap

The trap here is that candidates confuse the KEDB with the CMS or assume a workaround belongs only in the incident record, but ITIL 4 explicitly requires workarounds to be stored in known error records for reuse and problem resolution.

How to eliminate wrong answers

Option A is wrong because a change request is used to authorize and track changes to services or infrastructure, not to document workarounds for known errors. Option C is wrong because the Configuration Management System (CMS) holds configuration item (CI) data and relationships, not workaround procedures or known error details. Option D is wrong because documenting the workaround only in the incident record limits its visibility and reuse; ITIL 4 requires workarounds to be captured in a known error record for broader accessibility and problem management.

← PreviousPage 3 of 5 · 301 questions totalNext →

Ready to test yourself?

Try a timed practice session using only ITIL Management Practices questions.