CMA Practice Questions
Prepare for CMA with more than an answer.
- Exam fee
- $17000 USD
- Level
- Expert
- Valid for
- 2 years
- 1
A client wants to integrate their on-premise SAP S/4HANA system with ServiceNow for procurement workflows. The SAP system is behind a corporate firewall and has no direct inbound internet access. The client has a strict 'no VPNs for vendors' policy. Which integration architecture should the Master Architect propose?
Show answer details
Correct answer: B
The MID (Management, Instrumentation, and Discovery) Server is the standard and secure ServiceNow solution for this exact scenario. The MID Server is installed on a machine within the client's secure network. It initiates an outbound, encrypted connection to the ServiceNow instance in the cloud. The instance can then place jobs in a queue for the MID Server, which executes them locally (e.g., calling the SAP API) and returns the results over the secure outbound channel. This avoids the need for opening inbound firewall ports or establishing a VPN, satisfying the client's security constraints.
sequenceDiagram participant SN as ServiceNow Cloud participant MID as MID Server (On-Premise) participant SAP as SAP S/4HANA (On-Premise) Note over SN, MID: MID Server establishes secure outbound connection (AMQP) SN->>MID: Place REST request in ECC Queue MID->>SAP: Execute REST API call internally SAP-->>MID: Return API Response MID-->>SN: Return payload to instance - 2
A large enterprise has decided to adopt ServiceNow as its primary digital transformation platform. The program sponsor wants to establish a Center for Excellence (CCoE) but is unsure of the key roles required to make it successful. As a Master Architect, which set of roles would you identify as the essential core of a new CCoE?
Show answer details
Correct answer: B
A successful CCoE requires strategic, technical, and business-facing leadership. The Platform Owner is responsible for the overall vision, value, and budget. The Platform Architect is responsible for technical governance, standards, and instance health. The Business Relationship Manager (BRM) acts as the bridge to the business units, managing demand and ensuring alignment. This triad forms the essential core. While developers and project managers are part of the broader delivery team, they are not the core strategic roles of the CCoE itself. A support lead and trainer are important but secondary to the core leadership.
- 3
Case Study:
HealthCorp, a large hospital network, has implemented ServiceNow ITSM and HR Service Delivery. They are now planning to build a custom application for managing clinical trials, which will handle sensitive patient data. The development team is comprised of both internal employees and external contractors. The Chief Compliance Officer (CCO) is concerned about unauthorized access to data and code during the development lifecycle and has mandated a 'least privilege' access model.
The current development process involves all developers having admin access in sub-production instances and using shared update sets. The CCO has flagged this as a major compliance risk. The VP of Application Development is pushing back, arguing that restricting access will slow down development and hinder collaboration.
As the Master Architect, you must propose a solution that satisfies the CCO's compliance requirements without crippling the development team's productivity. What is the most comprehensive and architecturally sound solution?
Show answer details
Correct answer: C
This is the most robust and modern solution. Building the app in its own scope encapsulates it, preventing it from affecting other parts of the platform. Delegated Development allows the platform owner to grant specific, granular permissions (e.g., 'can create business rules', 'cannot modify ACLs') to different developers or teams, enforcing least privilege. Integrating with a source control system like Git moves the collaboration and versioning process off-platform, providing a full audit trail of every code change and who made it. This combination directly addresses the CCO's compliance concerns while providing developers with a structured, professional, and ultimately more efficient workflow than shared update sets.
- 4
A stakeholder from the finance department complains that their ServiceNow reports are slow and often time out. Upon investigation, you find they are running complex reports directly against production tables with millions of records during peak business hours. As the architect, what is the best practice solution to this problem?
Show answer details
Correct answer: C
Performance Analytics (PA) is designed to solve this exact problem. It runs scheduled jobs (typically nightly) to collect and aggregate data from transactional tables into optimized data marts (indicator scores). Reporting and dashboarding are then performed against these aggregated scores, not the live production tables. This prevents performance degradation on the production instance, allows for trend analysis over time, and provides much faster report generation. Simply increasing resources or restricting report times are temporary fixes that don't address the underlying architectural issue.
- 5
A company is planning to use the ServiceNow CMDB as the single source of truth for its hybrid cloud environment, which includes AWS, Azure, and on-premise VMware. Which ServiceNow ITOM application is essential for populating and maintaining the relationships between these different CIs?
Show answer details
Correct answer: C
ITOM Discovery is the core application for finding and populating the CMDB with infrastructure and application CIs. It uses probes and sensors, as well as cloud-native APIs, to scan the network, VMware environment, and cloud subscriptions (AWS, Azure) to identify devices, servers, software, and the relationships between them. While Service Mapping builds on this data to create service context, Discovery is the fundamental tool for the initial and ongoing population of the CMDB. Event Management deals with operational events, and Orchestration is for automation.
- 6
You are presenting a business case for implementing ServiceNow Application Portfolio Management (APM) to a steering committee. What are the primary business outcomes you would highlight? (Select TWO)
Show answer details
Correct answer: B, D
Application Portfolio Management (APM) provides the data and framework to make strategic decisions about the application landscape. Its primary business outcomes are cost reduction through application rationalization (identifying and decommissioning redundant or low-value apps) and risk reduction by identifying applications running on unsupported technology or with poor business fit. While it can indirectly influence development cycle times or improve availability, its core value propositions are cost optimization and risk mitigation.
Application Portfolio Management (APM) provides the data and framework to make strategic decisions about the application landscape. Its primary business outcomes are cost reduction through application rationalization (identifying and decommissioning redundant or low-value apps) and risk reduction by identifying applications running on unsupported technology or with poor business fit. While it can indirectly influence development cycle times or improve availability, its core value propositions are cost optimization and risk mitigation.
- 7
A platform owner is concerned that their ServiceNow instance is performing poorly after five years of organic growth and multiple implementations. A review of the instance shows the following governance anti-pattern. Which one is the most likely cause of systemic performance issues?
flowchart TD A[Requirement] --> B{Is it complex?} B -->|Yes| C[Assign to Senior Dev] B -->|No| D[Assign to Junior Dev] C --> E[Dev writes code in Default Update Set] D --> E E --> F[Dev tests in Dev instance] F --> G{Does it work?} G -->|Yes| H[Mark Update Set 'Complete'] H --> I[Admin merges Default Update Set to Test] I --> J[Admin merges Default Update Set to Prod]Show answer details
Correct answer: C
Using a shared 'Default' update set for all development is a major governance anti-pattern. It makes it impossible to deploy features independently, leads to massive, unmanageable update sets, and often causes developers to overwrite each other's work. More importantly, it encourages developers to make changes to global, out-of-the-box objects instead of working in scoped applications, which is a primary source of technical debt and long-term performance degradation.
- 8
A global pharmaceutical company with highly regulated GxP data is planning to adopt ServiceNow for both ITSM and a custom Drug Trial Management application. The CISO is concerned about data segregation and validation requirements. As the Master Architect, which multi-instance strategy would you recommend to balance compliance with platform consolidation benefits?
Show answer details
Correct answer: B
For highly regulated environments like GxP, physical instance separation is the gold standard. It provides a distinct validation boundary, simplifies audit processes, and ensures that changes to the non-GxP instance (e.g., ITSM upgrades) do not trigger a re-validation event for the sensitive Drug Trial Management application. While more costly, this approach provides the strongest compliance posture. Domain separation offers logical separation but shares the same physical database and application nodes, which is often insufficient for stringent GxP validation. A single instance with separate scopes is a weaker form of logical separation. Using non-production instances for production GxP data is a direct violation of compliance principles.
- 9
A major financial institution is implementing a global ServiceNow platform governance model. They have representation from North America, EMEA, and APAC. The key challenge is balancing global standardization with regional regulatory needs (e.g., GDPR in EMEA, CCPA in NA). Which governance structure is most effective for this scenario?
Show answer details
Correct answer: C
A federated governance model is the most appropriate for this complex scenario. It allows a global Center of Excellence (CCoE) to establish core platform standards, architectural principles, and data models, ensuring consistency and maintainability. Simultaneously, it empowers regional governance boards to define and implement policies specific to their local regulatory and business requirements (like GDPR). This strikes the necessary balance between central control and regional autonomy. A purely centralized model would fail to address regional needs, while a decentralized model would lead to fragmentation and loss of global standards.
- 10
During a presentation to the CIO of a retail giant, you are asked how ServiceNow will deliver tangible business value beyond IT cost savings. Which of the following metrics are most effective for articulating strategic business value to an executive audience? (Select TWO)
Show answer details
Correct answer: B, D
Executive audiences like a CIO are focused on strategic outcomes that impact the entire business. Increased employee productivity and accelerated speed-to-market for new products are high-level business value metrics. While MTTR and server uptime are important operational metrics for IT, they don't directly translate to top-line business growth or strategic advantage in the same way.
Executive audiences like a CIO are focused on strategic outcomes that impact the entire business. Increased employee productivity and accelerated speed-to-market for new products are high-level business value metrics. While MTTR and server uptime are important operational metrics for IT, they don't directly translate to top-line business growth or strategic advantage in the same way.
