Skip to content

CTA Practice Questions

Prepare for CTA with more than an answer.

255 questions in the full set20 sample questionsUpdated Jan 25, 2026
Exam fee
$7000 USD
Level
Expert
Valid for
Annual maintenance required
Domains covered on the exam 9
  1. CMDB and CSDM15%
  2. Technical Governance6%
  3. Testing Leading Practices15%
  4. Go-Live Preparation6%
  5. Security Architecture15%
  6. Data Strategies11%
  7. Current and To-Be Architecture9%
  8. Platform Data and Integrations15%
  9. Release and Instance Strategy8%
  1. 1

    When defining a data ownership strategy within a Technical Governance framework, what is the primary role of a 'Data Steward'?

    Show answer details

    Correct answer: B

    A Data Steward is a business or functional role, not a technical one. They are accountable for the quality, definition, and lifecycle of a specific set of data. For example, the manager of the server team might be the Data Steward for all Server CIs. They ensure the data is accurate, complete, and properly managed according to the governance policies. The Data Owner is typically a senior executive with ultimate accountability, while developers perform the technical implementation.

  2. 2

    A project team is preparing for the go-live of a new ServiceNow application. The architect emphasizes the need for a well-structured communication plan. What is the primary objective of the 'pre go-live' communication phase?

    Show answer details

    Correct answer: B

    The pre go-live communication phase is focused on organizational change management. Its purpose is to inform stakeholders about what is changing, why it's changing, when it will happen, and how it will affect them. This builds awareness and excitement, sets clear expectations, and ensures users are prepared and trained before the system is launched, which is crucial for successful user adoption.

  3. 3

    An architect is designing a solution that requires a visual representation of the logical components of the system and their relationships, independent of the underlying physical infrastructure. This artifact needs to be easily understood by both business analysts and developers. Which type of diagram would be most appropriate for this purpose?

    Show answer details

    Correct answer: C

    A C4 model component diagram is specifically designed to show the logical components within a container (e.g., an application or microservice) and their interactions. It abstracts away the physical infrastructure, focusing on the logical structure, which makes it ideal for communication between business analysts, architects, and developers. A network diagram focuses on physical infrastructure, an ERD on data structure, and a sequence diagram on time-based interactions, not logical structure.

  4. 4

    A manufacturing company uses a third-party cloud service for its inventory management. The architect needs to build an integration that allows ServiceNow to retrieve inventory levels on demand. The third-party service provides a well-documented REST API. Which ServiceNow component is the preferred, low-code solution for building this type of outbound integration?

    Show answer details

    Correct answer: C

    IntegrationHub, used within Flow Designer, is ServiceNow's primary low-code solution for building reusable integrations. For a standard outbound REST call, an architect would create a REST action in IntegrationHub. This action can then be easily incorporated into a flow, allowing for complex logic to be built around the integration without extensive scripting. Scripted REST APIs are for inbound integrations. Outbound SOAP is for the older SOAP protocol. A scripted include is a pro-code approach and not the preferred low-code solution.

  5. 5

    An architect is presented with the following diagram representing a customer's current architecture for handling inbound incidents from a monitoring tool. The customer is complaining about high maintenance costs and slow response to changes. Based on architectural best practices, what is the primary issue with this design?

    graph TD subgraph ServiceNow A[Email Inbound Action] --> B{Create Incident}; end subgraph Monitoring Tool C(Alert Triggered) --> D[Send Formatted Email]; end D --> A; subgraph Other Systems E(System E) --> F[Send Email]; G(System G) --> H[Send Email]; end F --> A; H --> A;

    Show answer details

    Correct answer: B

    The diagram clearly shows that multiple external systems are all funneled through a single point of failure: an email inbound action. Email parsing is inherently brittle; a small change in the email format from any source can break the integration. It lacks robust error handling, has no mechanism to send a success/failure response back to the source system, and is generally considered a poor practice for system-to-system integration. A modern approach would use REST APIs (e.g., the Incident API or a Scripted REST API) which are structured, reliable, and support response codes.

  6. 6

    A global pharmaceutical company is implementing ServiceNow to manage clinical trial data. They are required by regulations like HIPAA and GDPR to ensure that Personally Identifiable Information (PII) is not viewable by ServiceNow support personnel, even when they require access to the instance for troubleshooting. The solution must not impact the usability of platform features like global search or reporting on non-sensitive fields. Which security architecture component is specifically designed to meet this requirement?

    Show answer details

    Correct answer: D

    Edge Encryption is the correct solution. It encrypts data at the customer's network boundary before it is sent to the ServiceNow cloud. This means ServiceNow personnel, including support, never have access to the unencrypted data or the encryption keys. This approach meets the strict regulatory requirements while preserving platform functionality like searching and reporting on non-encrypted fields. SNC Access Control manages access for support but doesn't encrypt the data. RBAC is for internal user access. Database encryption protects data at rest within ServiceNow's data centers, but support personnel with access could still potentially view it.

  7. 7

    A large retail organization is migrating from a legacy, on-premises ITSM tool to ServiceNow ITSM Pro. The project includes migrating over 10 million incident, problem, and change records. The legacy data format is inconsistent and requires significant cleansing and field mapping. The technical architect must design a data import strategy that minimizes performance impact on the production instance during the import process and provides robust logging for troubleshooting. Which ServiceNow feature should be the core component of this strategy?

    Show answer details

    Correct answer: B

    The Robust Transform Engine (RTE) is specifically designed for large-scale data imports. It isolates the transformation and processing functions from the platform's primary schedulers, which minimizes performance impact on the instance. It also provides detailed, step-by-step logging and error handling, which is crucial for troubleshooting complex data migrations. While concurrent import sets can speed up imports, RTE is the underlying technology that provides the required performance isolation and robustness.

  8. 8

    A consultant is designing a testing strategy for a custom ServiceNow application that will be used by thousands of global users. The application has complex workflows that interact with multiple external systems via IntegrationHub. The client has mandated that any regression defects must be identified before they reach UAT. What are the key non-functional testing practices the architect must include in the plan to ensure application stability and scalability? (Select THREE)

    Show answer details

    Correct answer: B, C, E

    Performance, Load, and Security testing are critical non-functional tests for an application with these requirements. Performance testing checks the speed and responsiveness. Load testing simulates concurrent user access to ensure stability under stress. Security testing identifies vulnerabilities in the custom code and integrations. While Usability testing is important, it's a functional aspect. Unit testing is a developer-level activity focused on individual code components, not the overall application stability and scalability.

  9. 9

    True or False: In a well-architected ServiceNow environment following CSDM principles, an Application Service CI should always be related to a Business Application CI.

    Show answer details

    Correct answer: A

    This statement is true. In the Common Service Data Model (CSDM), the Business Application represents the conceptual or logical application used by the business (the 'what'). The Application Service represents the deployed, operational instance of that application (the 'how'). A core principle of CSDM is linking the operational world (Application Service) to the business portfolio world (Business Application) to enable capabilities like impact analysis and application portfolio management.

  10. 10

    Company Background:
    GlobalLogix is a multinational logistics company undergoing a major digital transformation. They are consolidating dozens of regional, homegrown applications onto a single global ServiceNow platform. The primary goal is to provide a unified portal for customers to track shipments, manage invoices, and open support cases. The company operates in North America, Europe, and Asia-Pacific, with strict data sovereignty laws in the European Union (GDPR) and several Asian countries.

    Current Situation:
    The architecture team has proposed a single production instance to maximize data aggregation for global reporting and analytics. However, the legal department has raised concerns about data sovereignty. The development teams are distributed globally and need isolated environments for their regional feature development without impacting other teams. The current CI/CD pipeline is immature, relying heavily on manual update set management.

    Requirements & Constraints:

    1. European customer data must physically reside within EU data centers.
    2. A single, unified customer portal experience is mandatory.
    3. Global executive dashboards require access to data from all regions.
    4. Development teams must not be blocked by each other's work.
    5. The solution must be scalable and maintainable in the long term.

    Which instance and data strategy best balances these competing requirements?

    Show answer details

    Correct answer: D

    This hybrid approach is the most robust and balanced solution. It directly addresses the strict data sovereignty requirement by having a dedicated EU production instance. It leverages standard platform features for instance-to-instance integration to meet the global reporting and unified portal requirements without building a complex custom solution. This strategy also naturally provides development isolation. A single instance with Domain Separation or Edge Encryption does not satisfy the 'data must physically reside' requirement. A single EU-hosted instance might violate data residency laws of other regions. A fully custom multi-instance portal is complex, costly, and difficult to maintain.

Create an account to continue.