Courseiva

CCNA ITIL Management Practices Questions

75 of 260 questions · Page 3/4 · ITIL Management Practices · Answers revealed

151
Multi-Selecthard

Which THREE of the following are characteristics of a service request?

Select 3 answers
A.It is pre-approved and follows a defined procedure
B.It is a request for information or access
C.It involves an unplanned service disruption
D.It requires a change request to fulfill
E.It is often fulfilled by the service desk
AnswersA, B, E

A service request is inherently standardized, meaning it has a clear, documented procedure for its fulfillment. This pre-defined process allows for efficient handling, often with minimal human intervention or through automation, because the request itself has already been authorized and approved as a standard offering within the service catalog. This characteristic ensures predictability and consistency in service delivery.

Why this answer

Service requests are predefined, pre-approved, low-risk, and typically involve standard procedures. Incidents are unplanned, and service requests are separate from changes.

152
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. The analyst verifies the issue and suspects it may be related to a recent change. What should the analyst do FIRST according to ITIL 4?

A.Immediately reverse the recent change
B.Create a service request to restore access
C.Log an incident record and begin initial diagnosis
D.Log a problem record to investigate the root cause
AnswerC

Logging an incident record and initiating initial diagnosis is the correct first step because ITIL 4 defines an incident as an unplanned interruption to a service or a reduction in the quality of a service. The primary objective of Incident Management is to restore normal service operation as quickly as possible, and logging the incident ensures it is tracked, prioritized, and managed effectively from the outset. Initial diagnosis is crucial for understanding the immediate impact and potential resolution.

Why this answer

The first step is to log the disruption as an incident to initiate restoration of service, even if the cause is suspected to be a change.

153
MCQhard

Which statement BEST distinguishes a service request from an incident?

A.Incidents are only technical issues, while service requests are for information
B.Service requests always require a change, while incidents never do
C.Service requests are not logged, while incidents are always logged
D.Service requests are pre-defined and pre-approved, while incidents are unplanned service disruptions
AnswerD

This statement accurately distinguishes service requests from incidents. Service requests are typically standardized, routine requests for information, access, or a standard service component, often with pre-defined fulfillment steps and pre-approved costs and procedures. In contrast, incidents represent an unplanned interruption to a service or a reduction in the quality of a service, requiring prompt resolution to restore normal operation as quickly as possible.

Why this answer

Service requests are pre-defined and pre-approved requests from users (e.g., password reset, access grant), while incidents are unplanned service disruptions that affect normal operation. Option A is incorrect because incidents can be non-technical (e.g., request for information is a service request, not an incident). Option B is incorrect because not all service requests require a change (e.g., information request), and incidents may require a change to resolve.

Option C is incorrect because both incidents and service requests are logged in the IT service management system.

154
MCQhard

An organization is reviewing its IT service management practices. They find that the same recurring incident is being logged multiple times without investigation. Which practice should address this to prevent recurrence?

A.Change Enablement
B.Incident Management
C.Problem Management
D.Service Desk
AnswerC

Problem Management is the ITIL practice specifically designed to reduce the likelihood and impact of incidents by identifying and analyzing the root causes of actual and potential service disruptions. It involves structured investigation, diagnosis, and the identification of workarounds or permanent solutions to prevent the recurrence of incidents. This practice proactively seeks to eliminate underlying issues, thereby improving overall service stability and quality.

Why this answer

Problem Management is responsible for identifying the root cause of incidents and preventing recurrence. Option C (Problem Management) is correct. Incident Management focuses on restoring service, not preventing recurrence.

Service Desk logs incidents. Change Enablement manages changes.

155
MCQhard

Which of the following BEST differentiates a normal change from an emergency change?

A.Normal changes are always low-risk; emergency changes are high-risk
B.Emergency changes are implemented without any approval
C.Normal changes are assessed and approved through standard procedures; emergency changes require urgent handling to avoid business impact
D.Emergency changes are only used for security incidents
AnswerC

This statement accurately differentiates normal and emergency changes by focusing on their procedural characteristics and underlying urgency. Normal changes are systematically planned, assessed, and approved through established, comprehensive procedures, allowing for thorough risk evaluation and resource allocation. In contrast, emergency changes are necessitated by an immediate, critical need to restore service or prevent significant business disruption, demanding an expedited assessment and approval process to mitigate severe impact swiftly.

Why this answer

Emergency changes are for urgent situations where delays would cause significant business impact, and they follow an expedited process. Normal changes follow standard assessment and approval.

156
Multi-Selectmedium

Which TWO of the following are phases of Problem Management?

Select 2 answers
A.Incident Resolution
B.Problem Identification
C.Event Classification
D.Problem Control
E.Service Desk
AnswersB, D

Problem Identification is the initial phase of Problem Management, where potential problems are recognized and logged for further investigation. This phase involves activities such as analyzing incident trends, detecting recurring issues, reviewing major incident reports, or receiving direct reports from monitoring tools or other practices. The objective is to identify the existence of an underlying cause that could lead to multiple incidents.

Why this answer

Problem Identification is a core phase of Problem Management because it involves detecting and logging problems before they are analyzed. In ITIL 4, Problem Management consists of three phases: Problem Identification, Problem Control, and Error Control. Problem Identification ensures that problems are formally recognized, often through trend analysis of incidents or proactive monitoring, so that root causes can be addressed.

Exam trap

The trap here is that candidates confuse the phases of Problem Management with other ITIL practices, such as Incident Management or Event Management, because all involve handling issues but have distinct objectives and workflows.

157
Multi-Selectmedium

Which TWO of the following are characteristics of a service request compared to an incident?

Select 2 answers
A.They require root cause analysis
B.They cause unplanned service interruption
C.They are typically low-risk
D.They are pre-approved processes
E.They are always urgent
AnswersC, D

Service requests are inherently low-risk because they involve standard, well-understood procedures for providing information, access, or minor, pre-approved changes within established service parameters. Their pre-defined nature and often automated fulfillment minimize the potential for adverse impact on services or users. This characteristic ensures predictable outcomes and contributes to efficient service delivery without significant operational uncertainty.

Why this answer

Service requests are pre-approved and typically follow a standard fulfillment process, while incidents are unplanned disruptions.

158
MCQmedium

An IT organization wants to improve first-contact resolution (FCR) rates. According to ITIL 4, which practice is most directly associated with this metric?

A.Problem Management
B.Service Level Management
C.Incident Management
D.Service Desk
AnswerD

The Service Desk serves as the single point of contact between the service provider and its users, handling incidents, service requests, and providing information. First Contact Resolution (FCR) is a crucial Key Performance Indicator (KPI) for the Service Desk, directly measuring its ability to resolve a user's issue or fulfill a request during their very first interaction. This metric is a direct reflection of the Service Desk's operational effectiveness and its contribution to user satisfaction and efficiency.

Why this answer

First-contact resolution is a key performance indicator for the service desk, reflecting its ability to resolve issues on the first interaction.

159
Multi-Selectmedium

Which THREE are components of the ITIL 4 Service Value System?

Select 3 answers
A.Service Level Agreements
B.Guiding Principles
C.Configuration Management Database
D.Governance
E.Service Value Chain
AnswersB, D, E

Guiding Principles are part of the SVS.

Why this answer

The ITIL 4 Service Value System (SVS) explicitly includes the Guiding Principles as one of its five core components. The Guiding Principles are universal recommendations that guide an organization in all its work, such as 'Focus on Value' and 'Start Where You Are', and they are a mandatory element of the SVS framework.

Exam trap

The trap here is that candidates often confuse operational artifacts (like SLAs or CMDBs) with the high-level structural components of the SVS, leading them to select familiar ITIL terms that are not part of the SVS framework.

160
MCQhard

An IT team is investigating a recurring network outage. They have identified the root cause as a faulty router configuration. In which phase of Problem Management are they operating?

A.Error Control
B.Problem Identification
C.Incident Management
D.Problem Control
AnswerD

Problem Control is the phase of Problem Management dedicated to understanding the root cause of problems and developing workarounds. The IT team's activity of 'investigating a recurring network outage' directly aligns with the objectives of Problem Control, which involves detailed analysis to diagnose the underlying cause. This phase aims to identify the true reason for service disruptions, enabling effective resolution and preventing future recurrences.

Why this answer

Problem Control is the phase where root cause analysis is performed and the root cause is identified. Problem Identification is the first phase (detecting problems), and Error Control is the phase where known errors are managed and workarounds are created.

161
Multi-Selectmedium

Which TWO are phases of the Problem Management practice?

Select 2 answers
A.Service restoration
B.Problem control
C.Problem identification
D.Incident resolution
E.Change authorization
AnswersB, C

Problem control is a crucial phase within the Problem Management practice, primarily focused on analyzing identified problems to determine their root causes. This phase involves activities such as data analysis, trend analysis, and often includes developing workarounds or known errors to mitigate the impact of the problem while a permanent solution is being sought. Its objective is to understand the problem deeply and manage its effects.

Why this answer

Problem Management includes the phases Problem Identification (detecting and logging problems) and Problem Control (analyzing and documenting workarounds and root causes). These are the two phases that directly address the lifecycle of a problem, distinct from incident or change activities.

Exam trap

The trap here is that candidates confuse the phases of Incident Management (Service Restoration, Incident Resolution) with Problem Management phases, or mistakenly include Change Authorization as a problem phase due to its role in implementing fixes.

162
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. According to ITIL 4, what should they do FIRST?

A.Notify the service level manager of a potential SLA breach
B.Submit a change request to implement a permanent fix
C.Log an incident and attempt to restore service as quickly as possible
D.Initiate a problem record to identify the root cause
AnswerC

Logging an incident and attempting to restore service as quickly as possible is the correct and primary responsibility of the service desk when users report a service disruption. An incident is defined as an unplanned interruption to an IT service or a reduction in the quality of an IT service. The core objective of the Incident Management practice is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations.

Why this answer

The correct first action according to ITIL 4 Incident Management is to log the incident and attempt to restore service as quickly as possible. Option C is correct because restoring normal service operation is the primary objective of Incident Management. Option A (notifying the service level manager) is a Service Level Management activity, not the immediate priority.

Option B (submitting a change request) is part of Change Enablement, which occurs after the incident is resolved and a permanent fix is identified. Option D (initiating a problem record) is a Problem Management activity that focuses on root cause analysis, which is separate from immediate incident response.

163
MCQmedium

An organization wants to improve first-level resolution rates. Which practice should they focus on?

A.Service Desk
B.Problem Management
C.Service Level Management
D.Incident Management
AnswerA

The Service Desk is the primary functional unit responsible for direct interaction with users and the initial handling of incidents. Improving first-level resolution rates directly entails enhancing the Service Desk's capabilities, such as providing comprehensive staff training, optimizing access to knowledge management systems, and streamlining diagnostic tools and processes. While Incident Management is the overarching practice, the Service Desk is the operational entity whose performance directly impacts and can be optimized to improve this specific metric.

Why this answer

Improving first-level resolution rates is a primary objective of the Service Desk practice in ITIL 4. The Service Desk captures demand for incident resolution and service requests, and its capability directly influences first-contact resolution rates. Option A is correct.

Option B (Problem Management) focuses on identifying root causes of incidents to prevent recurrence, not on immediate resolution rates. Option C (Service Level Management) deals with setting and monitoring service level targets, not operational resolution activities. Option D (Incident Management) manages the lifecycle of incidents but does not directly own first-level resolution; that responsibility lies with the Service Desk practice.

164
MCQmedium

During a major outage, a team implements a temporary workaround to restore service. Which ITIL 4 practice is primarily responsible for this action?

A.Problem Management
B.Incident Management
C.Change Enablement
D.Service Desk
AnswerB

Incident Management is the practice of minimizing the negative impact of incidents by restoring normal service operation as quickly as possible. Implementing a temporary workaround during a major outage directly aligns with this objective, as it prioritizes the rapid restoration of service availability and functionality to users, even if the underlying issue is not yet permanently resolved.

Why this answer

Incident Management is responsible for restoring service as quickly as possible, even with a workaround. Option B is correct. Problem Management would later diagnose the root cause.

Service Desk may log the incident but the restoration action is Incident Management.

165
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. According to ITIL 4, what should they do FIRST?

A.Investigate the root cause of the access issue
B.Log an incident and categorize it appropriately
C.Submit a change request to modify the CRM system
D.Create a service request for the users to regain access
AnswerB

Logging the reported issue as an incident is the foundational first step in the Incident Management process. This action creates a formal record, enabling tracking, communication, and assignment to the appropriate support teams. Categorizing it, typically by service, impact, and urgency, is crucial for correct prioritization and efficient routing, ensuring the incident receives the attention it requires based on its business effect.

Why this answer

The first step in Incident Management is to log and categorize the incident. This ensures that the issue is recorded and can be properly prioritized and escalated. Option A is incorrect because root cause analysis belongs to Problem Management, which occurs after incidents are logged.

Option C is incorrect because a change request would be appropriate only after a solution is identified. Option D is incorrect because service requests are for pre-approved, routine needs.

166
MCQmedium

An organization wants to improve customer satisfaction when users contact the service desk. Which metric is most appropriate to measure?

A.Customer Satisfaction (CSAT)
B.Mean Time to Restore Service (MTRS)
C.Number of incidents logged
D.First Call Resolution (FCR)
AnswerA

Customer Satisfaction (CSAT) is a direct feedback metric that quantifies how satisfied customers are with a product, service, or interaction. It is typically measured through surveys asking customers to rate their experience, often on a scale, providing immediate insight into their perception of value and service quality. Therefore, directly measuring CSAT is the most effective way to understand and improve customer satisfaction by capturing their subjective feelings.

Why this answer

CSAT is the direct measure of customer satisfaction, typically gathered through post-interaction surveys. It specifically captures the user's perception of the service desk experience, making it the most appropriate metric for the stated goal of improving satisfaction when users contact the service desk.

Exam trap

The trap here is that candidates often confuse First Call Resolution (FCR) with customer satisfaction, assuming that resolving an issue on the first call automatically means the customer is satisfied, but ITIL4F tests the distinction between operational metrics and experience metrics.

How to eliminate wrong answers

Option B (Mean Time to Restore Service) is wrong because it measures the average time to resolve an incident, not the user's satisfaction with the interaction. Option C (Number of incidents logged) is wrong because it measures volume of work, not quality or satisfaction. Option D (First Call Resolution) is wrong because while it correlates with satisfaction, it measures the percentage of issues resolved on the first contact, not the customer's direct sentiment or experience.

167
MCQmedium

A service desk wants to improve first contact resolution (FCR) rate. Which practice should be primarily involved in defining and monitoring this metric?

A.Problem Management
B.Service Level Management
C.Service Desk
D.Incident Management
AnswerC

FCR is a key performance indicator for the service desk.

Why this answer

Service Desk practice is responsible for FCR and other service desk metrics.

168
MCQmedium

A change request to replace a server is categorized as a 'standard change'. What does this mean?

A.The change does not require any documentation or assessment
B.The change requires authorization from the Change Advisory Board (CAB)
C.The change must be implemented as soon as possible due to a critical incident
D.The change is low-risk and follows a predefined, approved procedure
AnswerD

This statement accurately defines a standard change within the ITIL framework. Standard changes are typically low-risk, frequently occurring activities that follow a well-documented, predefined, and pre-approved procedure. Their pre-authorization means they do not require additional assessment or approval each time they are implemented, allowing for efficient and consistent execution while minimizing potential disruption to services.

Why this answer

A standard change in ITIL is a pre-approved, low-risk change that follows a predefined procedure. Therefore, option D is correct. Option A is incorrect because even standard changes require documentation; they are pre-approved but still require recording.

Option B is incorrect because standard changes do not require CAB authorization; they are pre-authorized. Option C describes an emergency change, which is implemented urgently due to incidents.

169
MCQmedium

A change request to upgrade the email server is assessed and authorized by the Change Advisory Board (CAB). After testing, it is scheduled for the next weekend. What type of change is this?

A.Emergency change
B.Normal change
C.Service request
D.Standard change
AnswerB

A normal change is the standard process for implementing significant modifications to services or service components that are not pre-approved as standard changes or necessitated by an emergency. This type of change requires thorough assessment of risks and benefits, detailed planning, and formal authorization by a designated Change Authority or Change Advisory Board (CAB). An email server upgrade, involving potential service disruption and requiring careful coordination, perfectly aligns with the structured governance provided by a normal change process.

Why this answer

Normal changes require assessment and authorization by the CAB, unlike standard (pre-approved) or emergency (urgent) changes.

170
MCQhard

A company wants to improve its incident resolution time. Which practice would be most relevant to analyze recurring incidents and identify underlying causes?

A.Problem Management
B.Continual Improvement
C.Incident Management
D.Change Enablement
AnswerA

Problem Management is the ITIL practice dedicated to reducing the likelihood and impact of incidents by identifying and resolving their root causes. By conducting thorough analysis of recurring incidents, it aims to implement permanent fixes or workarounds, thereby preventing future occurrences and significantly improving overall incident resolution times and service stability. This proactive approach moves beyond mere incident restoration to address underlying systemic issues.

Why this answer

Problem Management is the ITIL practice specifically designed to analyze recurring incidents by performing root cause analysis (RCA) and identifying underlying causes. By using techniques such as trend analysis, Kepner-Tregoe, or 5 Whys, Problem Management proactively reduces incident volume and resolution time, directly addressing the company's goal.

Exam trap

The trap here is confusing Incident Management (which restores service quickly) with Problem Management (which finds and fixes root causes), leading candidates to pick Incident Management because they focus on 'resolution time' rather than 'analyzing recurring incidents.'

How to eliminate wrong answers

Option B (Continual Improvement) is wrong because it focuses on overall service improvement through the CSI approach (Plan-Do-Check-Act) and does not specialize in analyzing recurring incidents or performing root cause analysis. Option C (Incident Management) is wrong because its primary goal is to restore normal service operation as quickly as possible, not to investigate underlying causes; it handles symptoms, not root causes. Option D (Change Enablement) is wrong because it manages the lifecycle of changes (RFCs, CAB approvals) to minimize risk, not to analyze incident patterns or identify root causes.

171
MCQmedium

A user contacts the service desk to request a new laptop because their current one is broken. The service desk analyst creates a ticket and arranges for a replacement. According to ITIL 4, what type of record should be raised?

A.Incident record
B.Change request
C.Problem record
D.Service request
AnswerD

A service request is a formal request from a user for something that is a normal part of service delivery, such as information, advice, a standard change, or access to a service. Requesting a replacement laptop, which is a pre-defined, pre-approved, and typically cataloged item, aligns perfectly with the definition of a service request. These requests are usually fulfilled through established, streamlined processes, often with minimal or no approval required beyond initial submission.

Why this answer

This is a service request because it is a pre-defined, pre-approved request for a standard item (replacement laptop for a broken one).

172
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.Manage the lifecycle of all Changes
B.Identify the root cause of incidents and prevent recurrence
C.Restore normal service as quickly as possible
D.Provide a single point of contact for users
AnswerC

Restoring normal service as quickly as possible is the primary purpose because Incident Management is a reactive, time-constrained process that prioritises service continuity over root-cause analysis. The stem’s focus on “PRIMARY purpose” demands the immediate operational goal, not a secondary objective like problem diagnosis. This distinguishes it from Problem Management, which targets permanent elimination of underlying causes.

Why this answer

Incident Management aims to restore normal service operation as quickly as possible and minimize adverse impact on business operations.

173
MCQhard

An organization has a change policy that requires all changes to be assessed and authorized by the Change Authority. A pre-approved change that has a low risk and follows a defined procedure is known as which type of change?

A.Normal change
B.Emergency change
C.Service request
D.Standard change
AnswerD

Standard changes are pre-approved, low risk, and follow a defined procedure.

Why this answer

A standard change is a pre-approved, low-risk change that follows a defined procedure, such as a password reset or server patch cycle. The ITIL 4 framework defines it as a change that does not require individual assessment or authorization by the Change Authority because its risk is well-understood and the implementation steps are documented in a standard operating procedure (SOP). This matches the description in the question exactly.

Exam trap

The trap here is that candidates confuse 'pre-approved' with 'normal change' because they think all changes need individual authorization, but ITIL 4 explicitly separates standard changes as pre-approved by definition, not requiring per-change authorization.

How to eliminate wrong answers

Option A is wrong because a normal change is any change that is not standard or emergency, and it requires assessment and authorization by the Change Authority on a case-by-case basis, not pre-approved. Option B is wrong because an emergency change is a high-risk, urgent change that must be implemented quickly to resolve a major incident or security threat, and it follows a separate expedited authorization process, not a low-risk pre-approved procedure. Option C is wrong because a service request is a formal request from a user for something to be provided (e.g., access, information), not a change to an IT service, and it is handled through the service request management process, not the change management process.

174
MCQhard

An organization has a CMDB that contains information about all configuration items (CIs) and their relationships. Which practice is primarily responsible for maintaining this information?

A.Service Catalog Management
B.Service Configuration Management
C.IT Asset Management
D.Deployment Management
AnswerB

Service Configuration Management is the practice responsible for maintaining information about services, configuration items (CIs), and their relationships. It ensures that accurate and reliable data concerning the configuration of services and the CIs that support them is available when and where needed. This practice explicitly owns and maintains the Configuration Management Database (CMDB), which stores all relevant CI attributes and their interdependencies. Its core function is to provide a logical model of the organization's infrastructure and services.

Why this answer

Service Configuration Management is the practice responsible for maintaining the CMDB, ensuring accurate information about configuration items (CIs) and their relationships. Option B is correct. Option A, Service Catalog Management, deals with defining and maintaining the service catalog, not CIs.

Option C, IT Asset Management, manages the lifecycle of assets, but the CMDB is focused on configuration items, which may include assets but is broader. Option D, Deployment Management, is concerned with moving new or changed components into production, not maintaining CI data.

175
MCQmedium

A problem has been identified and root cause analysis is underway. According to ITIL 4, which phase of Problem Management is this?

A.Problem control
B.Problem identification
C.Incident control
D.Error control
AnswerA

Problem control is the correct phase because it encompasses the activities required to analyze problems, identify their root causes, and develop workarounds or solutions. This phase actively manages problems from their initial logging through diagnosis and resolution, ensuring that recurring incidents are prevented. Root cause analysis is a core activity within problem control, aiming to understand the underlying reasons for incidents.

Why this answer

Problem control involves root cause analysis and resolution.

176
MCQhard

Which statement correctly distinguishes between a service request and an incident?

A.Service requests are managed by Problem Management, while incidents are managed by Incident Management
B.Service requests are always urgent, while incidents have varying priority
C.Service requests are for pre-approved, routine services; incidents are unplanned interruptions
D.Service requests are always initiated by the service desk, while incidents are initiated by users
AnswerC

This statement accurately distinguishes between service requests and incidents according to ITIL 4 principles. Service requests are formal requests from a user for something standard that is part of normal service delivery, such as requesting access to an application or a standard software installation, and are typically pre-approved. Conversely, an incident is defined as an unplanned interruption to a service or a reduction in the quality of a service, requiring prompt resolution to restore normal operations. This fundamental difference in nature and purpose is central to effective service management.

Why this answer

Service requests are for pre-defined, pre-approved services (standard changes or information requests), while incidents are unplanned interruptions or reductions in service quality.

177
MCQeasy

Which practice is responsible for being the single point of contact (SPOC) between the service provider and users?

A.Incident Management
B.Change Enablement
C.Service Desk
D.Service Level Management
AnswerC

The Service Desk practice is explicitly designed to be the single point of contact (SPOC) between the service provider and its users. Its primary function is to handle all user interactions, including receiving and logging service requests, incidents, and general inquiries, providing initial support, and facilitating communication throughout the service lifecycle. By centralizing user contact, the Service Desk ensures efficient and consistent support, improving user experience and streamlining service operations.

Why this answer

The service desk is the single point of contact for users to report incidents, submit service requests, and seek guidance.

178
Multi-Selecthard

Which THREE of the following are types of events in Monitoring and Event Management?

Select 3 answers
A.Emergency
B.Informational
C.Exception
D.Warning
E.Standard
AnswersB, C, D

Informational events indicate normal operation.

Why this answer

In ITIL 4, Monitoring and Event Management categorizes events into three types: Informational, Warning, and Exception. An Informational event (Option B) is a routine notification that indicates normal operation, such as a scheduled task completion or a configuration change log entry, requiring no immediate action.

Exam trap

The trap here is that candidates often confuse event types with incident priority levels (like Emergency) or change categories (like Standard), leading them to select options that are valid in other ITIL practices but not in Monitoring and Event Management.

179
MCQhard

An organization is experiencing repeated incidents due to a software bug. The problem manager has identified the root cause and documented a known error with a workaround. According to ITIL 4, in which phase of problem management are they operating?

A.Incident resolution
B.Error control
C.Problem identification
D.Problem control
AnswerB

Error control is the specific phase within problem management that deals with known errors, which are problems with an identified root cause. When an organization experiences repeated incidents due to a known root cause, error control focuses on managing these known errors, implementing workarounds to reduce impact, and planning permanent solutions to eliminate the error. This phase ensures that the underlying issue is actively managed until a definitive fix is deployed.

Why this answer

Error control is the phase where known errors are managed, workarounds are documented, and resolution is pursued. Problem identification is the first phase, and problem control involves root cause analysis.

180
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To identify the root cause of incidents and prevent recurrence
B.To restore normal service operation as quickly as possible and minimize the adverse impact on business operations
C.To handle predefined, pre-approved service requests from users
D.To assess, authorize, and schedule changes to IT services
AnswerB

This statement accurately defines the core purpose of the Incident Management practice within ITIL 4. Its primary goal is to minimize the negative impact of unplanned service interruptions by restoring normal service functionality as swiftly as possible. This rapid restoration helps to maintain business operations and reduce financial or reputational damage caused by service degradation or outages.

Why this answer

The primary purpose of Incident Management is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations. This practice focuses on resolving incidents (unplanned interruptions or reductions in quality) to return the service to its agreed service level, rather than analyzing root causes or handling routine requests.

Exam trap

The trap here is confusing Incident Management with Problem Management, as both deal with incidents, but Incident Management focuses on speed of restoration, not root cause analysis.

How to eliminate wrong answers

Option A is wrong because identifying root causes and preventing recurrence is the purpose of Problem Management, not Incident Management, which deals with immediate restoration. Option C is wrong because handling predefined, pre-approved service requests is the purpose of Service Request Management, which covers standard changes and user requests, not unplanned incidents. Option D is wrong because assessing, authorizing, and scheduling changes is the purpose of Change Enablement, which manages the lifecycle of changes to IT services, not incident resolution.

181
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. According to ITIL 4, what should the analyst do FIRST?

A.Log an incident record with the details provided by the user
B.Assign the issue to Problem Management for root cause analysis
C.Send a service request to the infrastructure team
D.Search the known error database for a workaround
AnswerA

Logging an incident record is the foundational first step in the ITIL 4 Incident Management practice. This action formally documents the disruption, captures essential details directly from the user, and creates a traceable record for all subsequent activities, including prioritization, diagnosis, and resolution. Without proper logging, effective tracking, communication, and management of the service disruption would be impossible, hindering timely restoration.

Why this answer

The first action in ITIL 4 Incident Management is to log the incident. The analyst must record the details of the disruption to initiate the process. Therefore, Option A is correct.

Option B (assign to problem management) is premature; Option C (send a service request) is incorrect because this is an incident, not a service request; Option D (search known error database) occurs after logging during investigation.

182
MCQhard

A service desk analyst resolves an incident by providing a workaround from the Known Error Database. According to ITIL 4, this activity is part of which practice?

A.Problem Control
B.Error Control
C.Service Request Management
D.Incident Management
AnswerD

Incident Management's primary objective is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations. When a permanent solution is not immediately available, applying a workaround is a crucial and common strategy within Incident Management to achieve this rapid service restoration. The service desk analyst's action directly aligns with the core purpose of Incident Management: getting the service back up and running for the user.

Why this answer

According to ITIL 4, using a known error workaround during incident resolution is part of Incident Management. Incident Management aims to restore normal service operation as quickly as possible and minimize adverse impact. The Known Error Database (KEDB) is used in Incident Management to provide workarounds.

Option A (Problem Control) is incorrect because it identifies root causes of problems. Option B (Error Control) is incorrect because it documents known errors after root cause analysis, but using the workaround during an incident is Incident Management. Option C (Service Request Management) is incorrect as service requests are standard changes, not incident resolution.

183
MCQmedium

An IT service desk analyst receives a call that users cannot access the CRM system. What should they do FIRST according to ITIL 4?

A.Implement a known workaround from the known error database
B.Perform a root cause analysis
C.Log an incident record with all relevant details
D.Escalate the issue to the problem management team
AnswerC

Logging an incident record is the essential first step in the Incident Management process when a service desk analyst receives a report of a service disruption. This action formally captures the event, ensuring it is tracked, prioritized, and managed according to established procedures. It provides a complete history of the issue, facilitating diagnosis, communication, and eventual resolution, aligning directly with the immediate goal of restoring service.

Why this answer

The first step in Incident Management is to log the incident. All details should be captured before proceeding with triage or escalation.

184
Multi-Selecthard

Which THREE of the following are components of the ITIL 4 Service Value System?

Select 3 answers
A.Guiding principles
B.ITIL maturity model
C.Service value chain
D.Service catalogue
E.Governance
AnswersA, C, E

Guiding principles are recommendations that can guide an organization in all circumstances, regardless of changes in its goals, strategies, type of work, or management structure. They promote a holistic approach to service management and decision-making. As one of the foundational elements, guiding principles are a core component of the ITIL 4 Service Value System, ensuring effective and ethical practice across all activities.

Why this answer

The SVS includes guiding principles, governance, service value chain, practices, and continual improvement.

185
MCQhard

An organization wants to improve the user experience for password reset requests. Currently, users call the service desk for each password reset, resulting in high call volume. According to ITIL 4, which practice should be applied to streamline this process?

A.Incident Management, because password reset is a disruption
B.Problem Management, to find the root cause of forgotten passwords
C.Change Enablement, because resetting a password changes the user account
D.Service Request Management, by offering a self-service password reset option through the service catalogue
AnswerD

Service Request Management is the appropriate practice for handling pre-defined, pre-approved requests from users for information, advice, standard changes, or access to a service. A password reset perfectly fits this description as a common, routine, and often automated request for access. Offering a self-service password reset option through a service catalogue significantly enhances user experience and operational efficiency by providing immediate resolution.

Why this answer

Password resets are typically pre-approved, routine requests best handled as service requests via self-service. Option D is correct. Option A (Incident Management) is for unplanned disruptions; Option B (Problem Management) is for finding root causes; Option C (Change Enablement) is for managing changes.

186
MCQmedium

An IT team discovers a recurring pattern of errors in a financial application. According to ITIL 4, which practice should be initiated to investigate the root cause?

A.Problem Management
B.Change Enablement
C.Service Request Management
D.Incident Management
AnswerA

Problem Management is the ITIL practice focused on reducing the likelihood and impact of incidents by identifying and eliminating their root causes. When an IT team discovers a recurring pattern of errors, it indicates an underlying issue that needs investigation beyond just restoring service. This practice involves activities like trend analysis, major problem review, and known error identification to prevent future occurrences and improve service stability.

Why this answer

Problem Management identifies the root cause of incidents to prevent recurrence.

187
Multi-Selectmedium

Which THREE of the following are phases of the ITIL Continual Improvement Model?

Select 3 answers
A.What is the vision?
B.Where are we now?
C.How do we get there?
D.What is the budget?
E.Who is responsible?
AnswersA, B, C

"What is the vision?" is the crucial first step of the ITIL Continual Improvement Model. This phase focuses on establishing a clear understanding of the overall objectives, strategic goals, and desired outcomes for the improvement initiative, ensuring alignment with the organization's mission and stakeholder expectations. It defines the purpose and direction for all subsequent improvement activities, clarifying what success looks like.

Why this answer

The ITIL Continual Improvement Model includes 7 steps: What is the vision?, Where are we now?, Where do we want to be?, How do we get there?, Take action, Did we get there?, How do we keep the momentum going?

188
MCQhard

An event indicating that a server's CPU usage has exceeded 90% for 5 minutes is classified as which type?

A.Exception
B.Critical
C.Informational
D.Warning
AnswerD

A warning event in ITIL 4 signifies that a service, component, or configuration is operating outside its normal parameters and indicates a potential future issue or degradation. A server's CPU usage exceeding 90% is a clear precursor to performance problems or an eventual system failure (an exception) if left unaddressed. This event provides an opportunity for proactive intervention to prevent a more severe incident, perfectly aligning with the definition of a warning.

Why this answer

An event that signals a potential service degradation is a warning event.

189
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To identify the root cause of incidents
B.To restore normal service operation as quickly as possible
C.To fulfil service requests from users
D.To prevent all incidents from occurring
AnswerB

The primary purpose of the incident management practice is to restore normal service operation as quickly as possible, minimizing the negative business impact of unplanned service interruptions or reductions in quality. This rapid restoration ensures that users can resume their work and that the organization continues to deliver value, aligning with ITIL's focus on value co-creation. It prioritizes speed and efficiency in resolving immediate service disruptions.

Why this answer

The primary purpose of Incident Management is to restore normal service operation as quickly as possible and minimize adverse impact on business operations. Option B is correct. Option A describes the purpose of Problem Management, not Incident Management.

Option C describes Service Request Management. Option D is unrealistic and not the primary goal.

190
MCQmedium

In ITIL 4, which practice is responsible for maintaining the Configuration Management Database (CMDB)?

A.Change Enablement
B.IT Asset Management
C.Deployment Management
D.Service Configuration Management
AnswerD

Service Configuration Management is the dedicated practice responsible for maintaining accurate and reliable information about the services and the configuration items (CIs) that support them. This includes planning, identifying, controlling, monitoring, and verifying the versions, baselines, and relationships of all CIs throughout their lifecycle. Its core function is to ensure the integrity of the Configuration Management System (CMS) and the Configuration Management Database (CMDB), providing a foundational understanding of the service landscape for other practices.

Why this answer

Service Configuration Management (D) is the ITIL 4 practice responsible for maintaining the Configuration Management Database (CMDB). It ensures that accurate and reliable information about configuration items (CIs) and their relationships is available when and where needed, supporting all other service management practices.

Exam trap

The trap here is that candidates confuse the practice that uses the CMDB (Change Enablement or IT Asset Management) with the practice that is responsible for maintaining it, but ITIL 4 explicitly assigns CMDB maintenance to Service Configuration Management.

How to eliminate wrong answers

Option A is wrong because Change Enablement manages the lifecycle of changes to services and CIs, but it does not own or maintain the CMDB; it uses the CMDB to assess change impact. Option B is wrong because IT Asset Management focuses on managing the financial, contractual, and lifecycle aspects of IT assets (e.g., procurement, depreciation), not the logical configuration data stored in the CMDB. Option C is wrong because Deployment Management handles the movement of new or changed components to live environments, but it does not maintain the CMDB; it may update CI statuses as part of deployment, but the CMDB's ongoing maintenance is the responsibility of Service Configuration Management.

191
Multi-Selectmedium

Which TWO of the following are characteristics of a Standard Change?

Select 2 answers
A.Requires urgent implementation
B.Low risk and well-understood
C.Requires individual approval each time
D.Requires a change advisory board (CAB) meeting
E.Pre-approved by change authority
AnswersB, E

This statement accurately describes a standard change. Standard changes are inherently low risk because they are routine, repetitive, and have a proven track record of successful implementation. Their well-understood nature means the steps, potential impacts, and required resources are clearly defined and predictable, allowing for pre-authorization without individual assessment each time.

Why this answer

Standard changes are pre-approved, low risk, follow a defined procedure, and do not require individual approval each time. Options B (low risk and well-understood) and E (pre-approved by change authority) correctly describe standard changes. Options A (urgent implementation) describes emergency changes; Option C (requires individual approval each time) describes normal changes; Option D (requires a CAB meeting) is typically for normal or emergency changes, not standard changes.

192
MCQmedium

A user requests a new software installation that is already approved and listed in the service catalogue. According to ITIL 4, how should this request be classified?

A.As an incident
B.As a normal change
C.As an emergency change
D.As a service request
AnswerD

A service request is a formal request from a user for something that is part of the normal service delivery, typically a pre-defined, low-risk, and repeatable action. These requests are often pre-authorized and follow a standard procedure, frequently managed through a service catalogue. The installation of pre-approved software perfectly aligns with this definition, representing a standard offering that can be fulfilled efficiently without extensive assessment or authorization.

Why this answer

Service requests are predefined, pre-approved, and typically low-risk. This matches the description of a standard change, but in ITIL 4, service requests are a distinct practice separate from changes.

193
Multi-Selectmedium

Which TWO of the following are key components of the ITIL 4 Service Value System (SVS)?

Select 2 answers
A.Continual improvement
B.Guiding principles
C.ITIL Maturity Model
D.Value
E.The Deming Cycle (Plan-Do-Check-Act)
AnswersA, B

Continual improvement is one of the five essential components of the ITIL 4 Service Value System (SVS). This component ensures that an organization's products, services, and practices are consistently aligned with evolving stakeholder needs and business objectives. It drives ongoing efforts to enhance value co-creation across all aspects of service management, making it integral to the SVS's dynamic nature.

Why this answer

The ITIL 4 Service Value System (SVS) consists of five components: guiding principles, governance, service value chain, practices, and continual improvement. Option A (Continual improvement) is one of these components, and Option B (Guiding principles) is another. Option E (The Deming Cycle) is a model used within continual improvement, not a separate component of the SVS.

Option C (ITIL Maturity Model) is a separate assessment tool, and Option D (Value) is an outcome, not a component.

Exam trap

A common mistake is to associate the Deming Cycle (Plan-Do-Check-Act) directly as a component of the SVS, but it is actually a tool used in the continual improvement practice, not a distinct component.

194
Multi-Selecteasy

Which TWO of the following are types of changes defined in ITIL 4?

Select 2 answers
A.Urgent change
B.Major change
C.Emergency change
D.Standard change
E.Minor change
AnswersC, D

An Emergency change is a specific type of change that must be implemented as quickly as possible, typically to resolve an active incident, restore a failed service, or apply a critical security patch. These changes often bypass some of the standard authorization and testing steps due to the extreme urgency and potential severe impact of delay. However, they still require post-implementation review and formal documentation to ensure governance and learning.

Why this answer

ITIL 4 defines three types of changes: standard, emergency, and normal. Emergency changes (Option C) are those that must be implemented as soon as possible to resolve an incident or security vulnerability, following a specific emergency change process with reduced testing and approval. Standard changes (Option D) are pre-authorized, low-risk, and follow a defined procedure, such as password resets or server patching.

Exam trap

PeopleCert often tests the distinction between 'urgent' and 'emergency' changes, where candidates mistakenly select 'urgent' because it sounds similar, but ITIL 4 explicitly uses the term 'emergency change' for changes requiring immediate implementation.

195
Multi-Selectmedium

Which TWO of the following are components of the ITIL 4 Service Value System?

Select 2 answers
A.Organizational Culture
B.Service Value Chain
C.ITIL Best Practices
D.Guiding Principles
E.Service Level Agreements
AnswersB, D

The Service Value Chain is a central component of the SVS.

Why this answer

The ITIL 4 Service Value System (SVS) is a model representing how all components and activities of an organization work together to facilitate value creation. The Service Value Chain (B) is the central operating model of the SVS, outlining six key activities (Plan, Improve, Engage, Design & Transition, Obtain/Build, Deliver & Support) that guide the creation of value. The Guiding Principles (D) are the core recommendations that guide an organization in all circumstances, applicable to all roles and initiatives within the SVS.

Exam trap

The trap here is that candidates often confuse the components of the SVS (Guiding Principles, Governance, Service Value Chain, Practices, Continual Improvement) with other ITIL elements like organizational culture, best practices, or specific process outputs, leading them to select distractors that are related but not formal SVS components.

196
MCQmedium

An event that indicates a breach of a threshold is classified as which type?

A.Critical event
B.Exception event
C.Warning event
D.Informational event
AnswerB

An exception event is specifically generated when a predefined operational or performance threshold has been violated, indicating a deviation from the expected or acceptable state of a service or component. This type of event signals that a specific metric, such as CPU utilization, memory usage, or response time, has crossed its upper or lower limit. It requires attention because it represents an actual breach, potentially impacting service quality or stability, and often triggers an alert for investigation.

Why this answer

An exception event indicates that a threshold has been breached. Option B is correct. Option A is incorrect because critical events indicate a disaster or major incident.

Option C is incorrect because warning events indicate that a threshold is approaching, not that it has been breached. Option D is incorrect because informational events provide routine information.

197
MCQmedium

A problem manager has identified that recurring incidents are caused by a software bug. The vendor has been notified and a permanent fix is scheduled for the next release. What should the problem manager do in the meantime?

A.Close the problem record since the fix is scheduled
B.Document the known error and provide a workaround
C.Escalate to change enablement for an emergency change
D.Implement the workaround immediately for all users
AnswerB

Documenting a known error and providing a workaround is a critical activity within the 'error control' phase of Problem Management. A known error signifies that the root cause of a problem has been identified, and a workaround is a temporary solution that reduces or eliminates the impact of incidents while awaiting a permanent fix. This enables Incident Management to restore service more quickly and efficiently, minimizing business disruption for users.

Why this answer

In error control, when a permanent fix is pending, the problem manager should document the known error and provide a workaround to reduce impact. Option B is correct because it follows the known error process. Option A is wrong because closing the problem record is premature.

Option C is wrong because the fix is already scheduled and an emergency change is not needed. Option D is wrong because implementing a workaround globally may not be appropriate without proper assessment.

198
MCQeasy

What is the first step in the ITIL 4 Continual Improvement Model?

A.Where are we now?
B.How do we get there?
C.Take action
D.What is the vision?
AnswerD

This is indeed the correct first step in the ITIL 4 Continual Improvement Model, establishing the clear purpose and desired outcome of any improvement initiative. It involves defining the overall direction, understanding stakeholder value, and ensuring alignment with organizational objectives. This foundational step provides the guiding star for all subsequent activities, ensuring that efforts are focused on achieving a meaningful and beneficial future state.

Why this answer

The ITIL 4 Continual Improvement Model has 7 steps: 1. What is the vision? 2. Where are we now? 3.

Where do we want to be? 4. How do we get there? 5. Take action. 6.

Did we get there? 7. How do we keep the momentum going? Option D is the first step.

199
MCQeasy

What is the PRIMARY difference between an SLA and an OLA?

A.An SLA is between a service provider and a customer; an OLA is between the service provider and another internal team
B.An SLA is for external customers; an OLA is for internal customers
C.An SLA is a written agreement; an OLA is verbal
D.An SLA defines responsibilities; an OLA defines penalties
AnswerA

An SLA, or Service Level Agreement, formally establishes the agreed-upon service levels and responsibilities between a service provider and its customer, who consumes the service. Conversely, an OLA, or Operational Level Agreement, is an internal agreement between different teams or departments within the *same* service provider organization. Its purpose is to define the specific support activities and performance targets required to deliver the overall service levels committed in an SLA to the customer.

Why this answer

The primary difference is that a Service Level Agreement (SLA) is a documented agreement between a service provider and a customer (external or internal) that defines the service level targets, while an Operational Level Agreement (OLA) is an internal agreement between the service provider and another internal team (e.g., IT operations, network team) that supports the delivery of the SLA. Option A correctly captures this distinction, as OLAs are always internal to the organization and support the SLA's commitments.

Exam trap

The trap here is that candidates confuse 'internal customer' with 'internal team,' leading them to choose Option B, but ITIL 4 defines OLAs as agreements between internal teams, not between the service provider and an internal customer.

How to eliminate wrong answers

Option B is wrong because an SLA can be for both external and internal customers (e.g., an internal SLA between IT and HR), and an OLA is always internal between teams, not specifically for internal customers. Option C is wrong because both SLAs and OLAs are formal written agreements; neither is verbal in ITIL 4 practice. Option D is wrong because both SLAs and OLAs define responsibilities and targets, but penalties are not a required component of either; ITIL 4 focuses on service level targets and improvement, not punitive measures.

200
MCQmedium

Which practice uses the ITIL Continual Improvement Model (7 steps)?

A.Continual Improvement
B.Service Desk
C.Incident Management
D.Change Enablement
AnswerA

The ITIL Continual Improvement Model, often referred to as the 7-step model, is the foundational framework for the Continual Improvement practice. This structured approach guides organizations through identifying opportunities, planning improvements, implementing changes, and reviewing outcomes across all services and products. It ensures that improvements are systematically managed and contribute directly to value creation and organizational objectives, making it central to sustained service excellence.

Why this answer

Continual Improvement practice uses the 7-step model to drive improvements.

201
MCQeasy

What is the PRIMARY purpose of the Incident Management practice?

A.To manage changes to IT services
B.To restore normal service operation as quickly as possible
C.To fulfill service requests from users
D.To identify the root cause of incidents
AnswerB

The core objective of the incident management practice is to minimize the negative impact of incidents by restoring normal service operation as swiftly as possible. This often involves implementing temporary workarounds to enable users to continue working, rather than immediately seeking a permanent fix. Rapid restoration ensures business continuity and reduces disruption to service consumers.

Why this answer

The primary purpose of Incident Management is to restore normal service operation as quickly as possible and minimize the adverse impact on business operations. This ensures that service availability and quality are maintained, aligning with the ITIL 4 guiding principle of 'Focus on Value' by prioritizing rapid restoration over root cause analysis.

Exam trap

The trap here is that candidates confuse Incident Management with Problem Management, mistakenly thinking that finding the root cause is the primary goal, when ITIL explicitly separates these practices to prioritize speed of restoration over investigation.

How to eliminate wrong answers

Option A is wrong because managing changes to IT services is the purpose of Change Enablement, not Incident Management; Incident Management deals with unplanned interruptions, not planned changes. Option C is wrong because fulfilling service requests from users is the purpose of Service Request Management, which handles pre-defined, low-risk requests like password resets, not incidents. Option D is wrong because identifying the root cause of incidents is the purpose of Problem Management, which analyzes patterns to prevent recurrence, whereas Incident Management focuses on swift restoration without necessarily finding the underlying cause.

202
MCQmedium

An organization wants to improve its incident resolution time. According to the ITIL Continual Improvement Model, what is the FIRST step?

A.Create an improvement register
B.Identify current and desired states
C.Define measurable targets
D.Define the vision and direction
AnswerD

Defining the vision and direction is the correct first step in the ITIL Continual Improvement Model, corresponding to "What is the vision?". This foundational activity involves articulating a clear, high-level understanding of what the organization intends to achieve through its improvement efforts. Establishing this strategic context ensures that all subsequent improvement activities are aligned with organizational objectives, providing a guiding purpose before delving into current states, desired outcomes, or specific actions.

Why this answer

The first step is to define the vision and direction for improvement, including aligning with business objectives.

203
Multi-Selecthard

Which THREE of the following are key activities of the Problem Management practice?

Select 3 answers
A.Problem identification
B.Root cause analysis
C.Restoring service as quickly as possible
D.Managing known errors
E.Fulfilling service requests
AnswersA, B, D

Problem identification is the crucial initial phase of Problem Management, focusing on detecting and logging problems. This activity involves proactively identifying potential issues through trend analysis of recurring incidents, analyzing significant single incidents that indicate an underlying flaw, or recognizing patterns from monitoring data, all with the goal of understanding the root causes of service disruption or degradation. It sets the foundation for subsequent investigation and resolution efforts.

Why this answer

Problem Identification is a key activity of Problem Management, which involves detecting and logging problems through analysis of incidents, alerts, or proactive monitoring. This activity ensures that underlying issues are recognized before they cause widespread service disruption, aligning with the ITIL 4 Problem Management practice's focus on preventing incidents and minimizing their impact.

Exam trap

The trap here is that candidates confuse the reactive, fast-paced 'restore service' focus of Incident Management with the analytical, long-term 'prevent recurrence' focus of Problem Management, leading them to incorrectly select Option C as a Problem Management activity.

204
MCQhard

Which of the following is an example of an output, as defined in ITIL 4?

A.Reduction in average incident resolution time
B.Improved user satisfaction after a system upgrade
C.A monthly performance report generated by the IT system
D.Increased revenue from a new service
AnswerC

"A monthly performance report generated by the IT system" is a clear example of an output. This report is a tangible artifact and a direct deliverable produced by an IT activity (report generation). It is a specific product that can be consumed or used by stakeholders, providing information, even though its ultimate purpose is to enable better decision-making (an outcome).

Why this answer

An output, as defined in ITIL 4, is a tangible, deliverable result produced by an activity or process. A monthly performance report is a concrete, measurable artifact generated by the IT system, which aligns with the ITIL 4 definition of an output as something that is directly produced, not an outcome or benefit.

Exam trap

The trap here is that candidates often confuse outputs with outcomes, mistakenly selecting options that describe benefits or improvements (like reduced resolution time or increased revenue) instead of the tangible, directly produced deliverables defined in ITIL 4.

How to eliminate wrong answers

Option A is wrong because a reduction in average incident resolution time is an outcome—a measurable change in performance or state resulting from the output, not the output itself. Option B is wrong because improved user satisfaction is an outcome, specifically a perception-based result of a change, not a tangible deliverable. Option D is wrong because increased revenue is a business outcome or benefit derived from a service, not a direct, concrete product of an activity or process.

205
Multi-Selectmedium

Which TWO of the following are examples of utility in ITIL 4?

Select 2 answers
A.The system processes transactions within 2 seconds
B.The system is available 99.9% of the time
C.The system supports automated billing
D.The system allows users to generate reports
E.The system is secure and compliant
AnswersC, D

This statement identifies a specific functional capability that the system provides, enabling the automation of billing processes. In ITIL 4, utility refers to the functionality offered by a service, determining whether it is 'fit for purpose' by supporting the performance of tasks or the achievement of desired outcomes for the consumer. Providing automated billing directly contributes to the value derived from the service's core capabilities.

Why this answer

Utility in ITIL 4 refers to the functionality offered by a product or service to meet a specific user need. Option C is correct because automated billing directly fulfills a business requirement by performing a specific function, which is the essence of utility. Option D is correct because report generation is a functional capability that enables users to achieve a desired outcome.

Exam trap

The trap here is confusing warranty attributes (like performance, availability, security) with utility features, leading candidates to incorrectly select options that describe service quality or assurance rather than functional capability.

206
MCQeasy

In ITIL 4, what is the single point of contact (SPOC) between the service provider and users?

A.Incident Management
B.Service Desk
C.Configuration Management
D.Service Level Management
AnswerB

The Service Desk is the SPOC for users.

Why this answer

The Service Desk is the single point of contact (SPOC) between the service provider and users in ITIL 4. It handles all user interactions, including incident logging, service requests, and communication, ensuring a consistent and efficient interface. This role is defined in the ITIL 4 Service Desk practice, which focuses on restoring normal service operation as quickly as possible.

Exam trap

The trap here is that candidates confuse the Service Desk (a functional SPOC) with Incident Management (a process), thinking the process itself handles user contact, but ITIL 4 explicitly assigns the SPOC role to the Service Desk practice.

How to eliminate wrong answers

Option A is wrong because Incident Management is a practice that manages the lifecycle of incidents, not a dedicated SPOC; it coordinates resolution but does not serve as the primary user-facing contact. Option C is wrong because Configuration Management manages information about configuration items (CIs) and their relationships, not user interactions or support requests. Option D is wrong because Service Level Management negotiates, agrees, and monitors service level agreements (SLAs), but it does not act as a daily operational contact point for users.

207
MCQhard

An organization has a pre-approved process for adding new users to a system. A manager requests access for a new employee. According to ITIL 4, how should this request be classified?

A.As a normal change, because it involves granting access
B.As an emergency change, to expedite the request
C.As an incident, because the new employee cannot access the system yet
D.As a service request, because it is a predefined, pre-approved fulfillment
AnswerD

Service requests are for standard, pre-approved items like access requests.

Why this answer

Per ITIL 4, a service request is a predefined, pre-approved, and standardized request for a service action, such as granting access to a system. The process for adding new users is already approved and documented, so the manager's request fits the definition of a service request, not a change or incident.

Exam trap

The trap here is that candidates confuse a pre-approved process with a 'standard change' (which is still a change) rather than recognizing that predefined, low-risk fulfillment activities are classified as service requests in ITIL 4.

How to eliminate wrong answers

Option A is wrong because a normal change is used for modifications that require assessment and approval through the change control process, whereas granting access via a pre-approved process is a standard fulfillment activity. Option B is wrong because an emergency change is reserved for resolving a critical incident or urgent issue that cannot wait for the normal change process, and a new employee access request is not urgent or critical by default. Option C is wrong because an incident is an unplanned interruption or reduction in quality of a service, not a planned request for access; the new employee has not yet been granted access, so there is no service interruption.

208
MCQeasy

Which of the following is an example of a standard change?

A.Implementing a new firewall to protect the network
B.Patenting a critical server vulnerability during business hours
C.Upgrading the entire email system to a new version
D.Resetting a user's password after they forget it
AnswerD

Resetting a user's password is a classic example of a standard change because it is a routine, frequently occurring, and low-risk activity with a well-defined and proven procedure. This type of request is typically pre-authorized, allowing service desk staff to execute it immediately without requiring additional approvals, thereby ensuring efficient and rapid resolution for common user issues.

Why this answer

Standard changes are pre-approved, low-risk, and follow a defined procedure. Password resets are typical standard changes.

209
Multi-Selectmedium

Which TWO of the following are key activities of Service Level Management?

Select 2 answers
A.Negotiating and agreeing service level agreements (SLAs)
B.Monitoring and reporting service performance against SLAs
C.Authorizing changes to IT services
D.Managing contracts with external suppliers
E.Handling user requests and incidents
AnswersA, B

This is a key activity of Service Level Management.

Why this answer

Service Level Management (SLM) is responsible for negotiating and agreeing on Service Level Agreements (SLAs) with customers to set clear expectations for service quality. It also involves monitoring actual service performance against those SLAs and reporting the results to stakeholders, ensuring that agreed targets are met or corrective actions are taken. These two activities form the core cycle of defining, measuring, and improving service levels.

Exam trap

The trap here is that candidates confuse Service Level Management with operational support activities (like handling incidents or managing supplier contracts) because they all involve 'service' and 'management,' but ITIL 4 explicitly separates these practices by their specific focus on performance agreements versus execution or procurement.

210
MCQmedium

A change request to upgrade an application is classified as 'normal'. What is the correct sequence of activities for this type of change?

A.Request, implement, review, close
B.Plan, authorize, implement, review, close
C.Assess, authorize, implement, close
D.Request, assess, authorize, plan, implement, review
AnswerD

This sequence accurately reflects the logical and controlled flow of activities within the ITIL 4 change enablement practice. It begins with a formal "Request," followed by a thorough "Assess" phase to understand impact and risk. "Authorize" grants permission, "Plan" details the execution, "Implement" performs the change, and "Review" confirms success and captures lessons learned, ensuring a structured and effective change process.

Why this answer

ITIL 4 defines the normal change sequence as: request, assess, authorize, plan, implement, and review. This ensures that all normal changes are properly evaluated for risk and impact before authorization, then planned and implemented, followed by a review to confirm success and capture lessons learned.

Exam trap

The trap here is that candidates often confuse the normal change sequence with the simpler 'request, authorize, implement' model used for standard changes, forgetting the mandatory assessment, planning, and review steps for normal changes.

How to eliminate wrong answers

Option A is wrong because it omits the critical steps of assessment, authorization, and planning, which are mandatory for normal changes to manage risk. Option B is wrong because it starts with 'plan' instead of 'request' and omits the initial 'assess' step, which is required before authorization. Option C is wrong because it skips the 'plan' and 'review' phases, leaving no structured implementation or post-implementation evaluation.

211
MCQmedium

An organization uses the ITIL continual improvement model. What is the FIRST step in this 7-step model?

A.What is the vision?
B.Take action
C.Where are we now?
D.Define the improvement strategy
AnswerA

This is the foundational first step in the ITIL Continual Improvement Model. It establishes the overall direction and purpose for any improvement initiative, clearly articulating the desired future state and the value it aims to deliver. Without a clear vision, subsequent improvement efforts lack focus and a measurable target, making it impossible to align activities or assess success effectively. This initial step ensures all stakeholders understand the ultimate goal.

Why this answer

The ITIL 4 continual improvement model is a 7-step iterative process that begins with defining the guiding vision. Step 1, 'What is the vision?', establishes the high-level business goals and strategic direction that align all subsequent improvement activities. Without a clear vision, later steps like assessing current state or defining improvement strategies lack context and purpose.

Exam trap

The trap here is that candidates often confuse 'Define the improvement strategy' (a common phrase in other frameworks) with the ITIL model's first step, or mistakenly think 'Where are we now?' is the logical starting point, but ITIL explicitly requires the vision to be set first to provide direction for the assessment.

How to eliminate wrong answers

Option B is wrong because 'Take action' is the final step (step 7) of the model, not the first. Option C is wrong because 'Where are we now?' is step 2, which assesses the current state after the vision is defined. Option D is wrong because 'Define the improvement strategy' is not a separate step in the ITIL continual improvement model; the model uses 'What is the vision?' (step 1), 'Where are we now?' (step 2), and then 'Where do we want to be?' (step 3) before defining measurable targets and plans.

212
MCQmedium

An organization wants to ensure that IT services meet current and future demand. Which ITIL 4 practice is primarily responsible for this?

A.Capacity and Performance Management
B.Service Level Management
C.Availability Management
D.Monitoring and Event Management
AnswerA

Capacity and Performance Management is the ITIL practice specifically designed to ensure that services and service components can meet current and future demand in a cost-effective way. It proactively plans, monitors, and optimizes the utilization of resources, including infrastructure, applications, and people, to guarantee that services consistently achieve their agreed-upon performance targets and user experience requirements. This practice involves understanding demand patterns, forecasting future needs, and making informed decisions about scaling or optimizing resources.

Why this answer

Capacity and Performance Management ensures that IT services have the required capacity to meet current and future demand while meeting performance targets. This practice is primarily responsible for aligning service capacity with demand. Service Level Management focuses on defining and monitoring SLAs, Availability Management ensures uptime and reliability, and Monitoring and Event Management detects and responds to events.

Therefore, option A is correct.

213
Multi-Selecthard

Which TWO of the following activities are part of the ITIL Continual Improvement Model?

Select 2 answers
A.Where are we now?
B.Define the scope
C.Allocate resources
D.How do we get there?
E.Implement the change
AnswersA, D

This activity is the second step of the ITIL Continual Improvement Model, focusing on establishing a clear understanding of the current state. It involves baselining existing services, processes, and practices to measure current performance and identify areas requiring improvement. This critical assessment provides the factual basis for setting realistic targets and tracking progress effectively throughout the improvement journey.

Why this answer

The ITIL Continual Improvement Model consists of seven steps. Option A ('Where are we now?') is step 2, which involves assessing the current state to identify gaps and opportunities. Option D ('How do we get there?') is step 4, which defines the action plan.

Both are correct because they are part of the model's sequence, even though the model starts with 'What is the vision?' (step 1).

Exam trap

The trap here is that candidates confuse the ITIL Continual Improvement Model steps with generic project management phases (like 'Define scope' or 'Allocate resources'), leading them to select options that sound plausible but are not part of the model's specific seven-step sequence. Additionally, 'Implement the change' is not a step in the model, as it belongs to other practices. The correct steps are 'Where are we now?' (step 2) and 'How do we get there?' (step 4).

214
Multi-Selecteasy

Which TWO of the following are components of the ITIL 4 Service Value System?

Select 2 answers
A.Service Desk
B.Service Value Chain
C.Change Enablement
D.Guiding Principles
E.Incident Management
AnswersB, D

One of the five components.

Why this answer

The ITIL 4 Service Value System (SVS) is the core structural model that describes how all components and activities of an organization work together as a system to enable value creation. The Guiding Principles and the Service Value Chain are two of the five explicitly defined components of the SVS, alongside Governance, Practices, and Continual Improvement. The Service Value Chain is the central operating model for the SVS, outlining the key activities (Plan, Improve, Engage, Design & Transition, Obtain/Build, Deliver & Support) that transform demand into value.

Exam trap

PeopleCert often tests the distinction between the five core components of the Service Value System (Guiding Principles, Governance, Service Value Chain, Practices, Continual Improvement) and the individual management practices (like Incident Management, Change Enablement, or Service Desk) that operate within the SVS, causing candidates to mistakenly select operational practices as SVS components.

215
MCQmedium

A customer requests a new software installation that is listed in the service catalogue. According to ITIL 4, this should be handled as a:

A.Incident
B.Service request
C.Problem
D.Emergency change
AnswerB

A service request is a formal request from a user for something standard that is part of normal service delivery, often pre-defined and pre-approved within a service catalogue. Requesting a new software installation, especially if it's a standard offering, perfectly aligns with this definition. These requests are typically low-risk, frequently occurring, and follow a standardized process for fulfillment.

Why this answer

Service requests are pre-defined, pre-approved requests for new services listed in the service catalogue. Option B is correct. Option A (incident) is for unplanned disruptions.

Option C (problem) is for root cause analysis. Option D (emergency change) is for urgent changes.

216
MCQmedium

Which ITIL 4 practice ensures that services deliver the agreed level of availability to meet customer needs?

A.IT Asset Management
B.Service Level Management
C.Capacity and Performance Management
D.Availability Management
AnswerD

Availability Management ensures that services and components deliver their agreed-upon availability targets, meeting the current and future needs of the organization and its customers. This practice involves planning, designing, implementing, measuring, and improving the availability of services, components, and IT infrastructure. It focuses on maximizing service uptime, reliability, maintainability, and serviceability to ensure services are accessible whenever required by users.

Why this answer

Availability Management is responsible for ensuring that services are available as agreed.

217
MCQmedium

Which document defines the level of service expected between a service provider and a customer?

A.Service catalogue
B.Operational Level Agreement (OLA)
C.Service Level Agreement (SLA)
D.Underpinning Contract (UC)
AnswerC

A Service Level Agreement (SLA) is a formal, documented agreement between a service provider and a customer that precisely defines the services to be provided and the specific, measurable level of service expected. It outlines key performance indicators (KPIs), availability targets, responsibilities of both parties, and often includes remedies or penalties for non-compliance. This document directly addresses the question by establishing the mutually agreed-upon service quality and performance benchmarks.

Why this answer

A Service Level Agreement (SLA) defines the level of service expected between a service provider and a customer. Option A (Service catalogue) is a list of services, not an agreement. Option B (Operational Level Agreement) is an agreement between internal groups within the same organization.

Option D (Underpinning Contract) is an agreement between the provider and a supplier.

218
MCQeasy

What is the PRIMARY purpose of the Service Desk practice?

A.To provide a single point of contact for users
B.To manage the lifecycle of IT assets
C.To manage known errors and workarounds
D.To monitor and manage IT events
AnswerA

The service desk acts as the SPOC for all user interactions.

Why this answer

The primary purpose of the Service Desk practice is to provide a single point of contact (SPOC) for users to report incidents, submit service requests, and receive updates. This ensures that all user interactions are captured, tracked, and managed consistently, enabling efficient communication and resolution. Without a dedicated SPOC, users would face confusion about whom to contact, leading to delays and poor service experience.

Exam trap

The trap here is that candidates often confuse the Service Desk's SPOC role with the technical functions of other practices, such as Problem Management's focus on root cause analysis or Monitoring's focus on automated alerts, leading them to select a plausible but incorrect option.

How to eliminate wrong answers

Option B is wrong because managing the lifecycle of IT assets is the purpose of the IT Asset Management practice, which focuses on tracking hardware, software, and other assets from acquisition to disposal. Option C is wrong because managing known errors and workarounds is the responsibility of the Problem Management practice, which aims to identify root causes and reduce incident recurrence. Option D is wrong because monitoring and managing IT events is the domain of the Monitoring and Event Management practice, which deals with detecting and responding to operational alerts and notifications.

219
MCQmedium

Which ITIL 4 practice manages the lifecycle of all configuration items including their relationships and baselines?

A.Change Enablement
B.Service Configuration Management
C.IT Asset Management
D.Release Management
AnswerB

The Service Configuration Management practice is precisely responsible for maintaining accurate information about Configuration Items (CIs) throughout their entire lifecycle. This includes identifying, controlling, recording, reporting, and verifying CIs, their attributes, and their relationships. It ensures that the organization has a clear understanding of its service components and their interdependencies, supporting effective service delivery and change management through baselines.

Why this answer

Service Configuration Management is responsible for managing configuration items (CIs), their relationships, and configuration baselines throughout their lifecycle. Option B is correct. Option A (Change Enablement) manages changes to services and CIs but does not manage the overall CI lifecycle.

Option C (IT Asset Management) focuses on the financial and contractual aspects of assets, not the detailed configuration management. Option D (Release Management) manages the release of new or changed services, not the ongoing management of CIs.

220
Multi-Selectmedium

Which TWO of the following are types of changes defined in ITIL 4?

Select 2 answers
A.Emergency change
B.Standard change
C.Problem change
D.Service request change
E.Incident change
AnswersA, B

An emergency change is a high-priority change that must be implemented as soon as possible, typically to resolve an incident or implement a security fix that has an immediate and significant impact on services. These changes bypass some standard steps of the normal change process due to their urgency, often requiring a separate, expedited authorization process to minimize service disruption. Their primary goal is to restore service operation or prevent a major business impact.

Why this answer

In ITIL 4, changes are categorized into three types: standard, emergency, and normal. Option A (Emergency change) is correct because it is a specific type of change that must be implemented as soon as possible, often to resolve an incident or security vulnerability, and follows a expedited process with authorization from the change authority. Option B (Standard change) is correct because it is a pre-authorized, low-risk change that follows a defined procedure, such as password resets or server patching, and does not require additional approval each time.

Exam trap

The trap here is that candidates confuse the change types with other ITIL practices (problem, incident, service request) and incorrectly assume that any change related to an incident or problem is a distinct type, when in fact ITIL 4 only recognizes standard, emergency, and normal changes.

221
Multi-Selecthard

Which THREE of the following are components of the ITIL 4 Service Value System?

Select 3 answers
A.Guiding principles
B.Processes
C.Value streams
D.Governance
E.Continual improvement
AnswersA, D, E

Guiding principles are a core component of the SVS.

Why this answer

A is correct because the ITIL 4 Service Value System (SVS) is explicitly defined to include the Guiding Principles as one of its five core components. These principles, such as 'Focus on Value' and 'Start Where You Are,' provide universal guidance that shapes all SVS activities and decision-making, ensuring alignment with business objectives.

Exam trap

The trap here is that candidates often confuse the 'Service Value Chain' with 'Value Streams' or mistakenly think 'Processes' are a separate SVS component, when in fact the SVS explicitly lists only five components and processes are subsumed under Practices.

222
Multi-Selectmedium

Which TWO of the following are types of changes in ITIL 4 Change Enablement?

Select 2 answers
A.Emergency change
B.Problem change
C.Service request
D.Standard change
E.Incident change
AnswersA, D

Correct: Emergency changes are for urgent issues.

Why this answer

Standard and emergency are two of the three change types; normal is the third. Standard is pre-approved, emergency is urgent.

223
MCQmedium

According to ITIL 4, what is the difference between an SLA and an OLA?

A.SLA is for availability; OLA is for incident response
B.SLA is for services; OLA is for underpinning contracts with suppliers
C.SLA is with the customer; OLA is between internal teams
D.SLA is mandatory; OLA is optional
AnswerC

This statement accurately distinguishes between a Service Level Agreement (SLA) and an Operational Level Agreement (OLA) according to ITIL 4 principles. An SLA is a documented agreement between a service provider and a customer that specifies the service to be provided, the agreed service levels, and the responsibilities of both parties. An OLA, on the other hand, is an internal agreement between different functional units or teams within the service provider organization, outlining their commitments and responsibilities to each other to ensure the delivery of the agreed service levels to the customer.

Why this answer

SLA is between provider and customer; OLA is between internal teams to support the SLA.

224
MCQmedium

An event indicating that a server's disk usage has reached 85% is detected. According to ITIL 4, what type of event is this?

A.Exception
B.Warning
C.Alert
D.Informational
AnswerB

A warning event indicates a condition that, if left unaddressed, has the potential to escalate into a significant problem or service disruption. It serves as an early indicator, prompting proactive investigation or intervention before a critical threshold is breached. A server's disk usage reaching 80% precisely fits this category, as it signals a need for attention and potential action to prevent the disk from becoming full, which would then become a more severe issue.

Why this answer

In ITIL 4, events are categorized as informational, warning, or exception. A warning event indicates a potential problem, such as disk usage reaching 85%. Therefore, Option B is correct.

Option A (Exception) is for events that indicate a breach of a threshold or actual failure, such as disk full. Option C (Alert) is not a formal ITIL event category. Option D (Informational) is for routine operations, not potential problems.

225
Multi-Selectmedium

Which TWO of the following are characteristics of a standard change?

Select 2 answers
A.Only used for major infrastructure upgrades
B.Require a full Change Advisory Board (CAB) meeting
C.Pre-approved with a defined procedure
D.Low risk and pre-approved
E.Implemented via an emergency process
AnswersC, D

A defining characteristic of a standard change is its pre-approval, signifying that its risk has been thoroughly assessed and accepted prior to any implementation. This pre-authorization is coupled with a clearly defined, repeatable procedure that ensures consistent execution and minimizes potential errors. Adherence to such a procedure allows for efficient, predictable, and reliable delivery of these routine changes without requiring individual authorization each time.

Why this answer

A standard change is pre-approved by the Change Authority and follows a defined, low-risk procedure. This means the change does not require a full CAB meeting each time it is implemented, as its risk profile and implementation steps are already documented and authorized.

Exam trap

The trap here is that candidates often confuse standard changes with emergency changes, thinking that 'pre-approved' means they can be used for urgent fixes, but standard changes are for low-risk, routine tasks, not for emergencies that require an emergency change process.

← PreviousPage 3 of 4 · 260 questions totalNext →

Ready to test yourself?

Try a timed practice session using only ITIL Management Practices questions.