Courseiva
Reporting, SLA and ImportshardMultiple ChoiceObjective-mapped

SNOW-CSA Reporting, SLA and Imports Practice Question

An organization has a Service Level Agreement (SLA) defined on the Incident table with a condition of 'Category is Network' and a duration of 4 hours. The SLA is triggered when the incident state changes from 'New' to 'In Progress'. A network incident is created and assigned to the Network Support group. The incident state is changed to 'In Progress' immediately. After 3 hours, the incident is resolved. However, the SLA shows a breach despite the resolution being within 4 hours. What is the most likely cause?

⚠ Common exam trap

Many candidates assume the SLA timer runs continuously from trigger to stop, ignoring the impact of schedules and pause conditions that can cause a breach even when the actual working time is within the defined duration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The SLA stop condition is set to 'State is Resolved', but the SLA was paused due to a schedule (e.g., after-hours pause) and the pause time was not counted, causing the actual working time to exceed 4 hours.

The most likely cause is that the SLA stop condition is set to 'State is Resolved', but the SLA timer was paused due to a schedule (e.g., after-hours) at the time the incident was resolved. Because the timer was paused, the stop condition was not evaluated immediately. When the schedule resumed, the working timer continued to run, and by the time the stop condition was evaluated, the accumulated working time had already exceeded the 4-hour duration, resulting in a breach. In ServiceNow, SLA timers that are paused do not trigger stop conditions until they resume, which can cause breaches even when the incident is resolved within the expected real-time window.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The SLA stop condition is set to 'State is Resolved', but the SLA was paused due to a schedule (e.g., after-hours pause) and the pause time was not counted, causing the actual working time to exceed 4 hours.

    Why this is correct

    If the SLA has a schedule that pauses during non-business hours, the elapsed business time may exceed 4 hours even if real time is less.

  • The SLA is assigned to the Network Support group, but the assignment group was changed during the incident.

    Why it's wrong here

    SLA is based on the incident record, not the assignment group.

  • The SLA duration is defined in business hours, and the incident was created after business hours, so the elapsed time counted only business hours, making the 4-hour window longer in real time.

    Why it's wrong here

    Business hours would extend real time, not cause a breach within 3 hours.

  • The SLA condition 'Category is Network' was not evaluated correctly because the category field was updated after the SLA was triggered.

    Why it's wrong here

    The condition is evaluated at trigger time; changes after do not affect SLA.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every SNOW-CSA question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SNOW-CSA practice question is part of Courseiva's free ServiceNow certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SNOW-CSA exam.