ITIL4F ITIL Management Practices Practice Question
Which THREE of the following are key activities of Monitoring and Event Management?
⚠ Common exam trap
PeopleCert often tests the distinction between Monitoring and Event Management (detection and response) and Problem Management (root cause analysis), leading candidates to incorrectly select root cause analysis as a monitoring activity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detect events
Monitoring and Event Management in ITIL/ITSM centers on the operational loop of observing infrastructure and services, so option B (Detect events) is correct because detecting events is the core purpose of monitoring tools and agents that observe metrics, logs, and status changes. Option E (Classify events as informational, warning, or exception) is correct because once an event is detected it must be categorized by significance so that informational events are logged, warnings are assessed, and exceptions trigger incident or problem handling. Option D (Respond to events) is correct because the process must act on classified events, whether by automated remediation, raising an incident, or escalating to the appropriate team. Option A (Negotiate SLAs) is not part of this practice; SLA negotiation belongs to Service Level Management, which defines targets that monitoring may later measure against. Option C (Perform root cause analysis) is not a Monitoring and Event Management activity either; root cause analysis is performed within Problem Management to identify the underlying cause of incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Negotiate SLAs
Why it's wrong here
Negotiating Service Level Agreements (SLAs) is a core activity within the Service Level Management practice, focusing on defining and agreeing upon the expected quality and utility of services with customers. While monitoring activities provide crucial data to assess performance against agreed SLAs, the actual negotiation and formalization of these agreements fall outside the scope of the day-to-day monitoring and event management activities, which are primarily concerned with detecting and responding to operational changes.
- ✓
Detect events
Why this is correct
Detecting events involves actively observing and identifying any significant change of state that has meaning for the management of a service or other configuration item. This foundational activity uses various tools and techniques, such as system logs, network probes, and application performance monitors, to capture data and recognize patterns or specific occurrences that indicate normal operation, potential issues, or exceptions requiring attention. Effective detection is the first critical step in understanding the operational health of IT services.
- ✗
Perform root cause analysis
Why it's wrong here
Performing root cause analysis (RCA) is a specialized activity belonging to the Problem Management practice, aimed at identifying the underlying causes of incidents to prevent their recurrence. While monitoring might detect an incident that subsequently triggers problem management, the detailed investigation, analysis, and identification of root causes are distinct from the real-time detection, classification, and initial response inherent in monitoring and event management. Problem Management focuses on long-term prevention, whereas monitoring focuses on immediate operational awareness.
- ✓
Respond to events
Why this is correct
Responding to events involves taking predefined actions based on the event's classification and significance to restore normal service operation or prevent further impact. This response can range from automated actions, such as restarting a service or allocating additional resources, to manual interventions like escalating to an incident management team or initiating a standard change. Effective response ensures that detected events are addressed promptly and appropriately, minimizing disruption and maintaining service quality.
- ✓
Classify events as informational, warning, or exception
Why this is correct
Classifying events as informational, warning, or exception is a crucial activity that assigns a level of significance to detected events, guiding subsequent actions and prioritization. Informational events confirm the normal operation of a service, warnings indicate potential issues that may require attention, and exceptions signify a breach of a threshold or a failure, often triggering an incident. This classification enables the organization to differentiate between routine operational noise and critical issues, ensuring resources are focused on the most impactful events.
Go deeper
Related to this question
About these practice questions
One of 805 original ITIL4F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ITIL4F practice question is part of Courseiva's free PeopleCert certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4F exam.