Skip to content

EX0-115 IT Service Management Foundation Based on Iso / Iec 20000 Practice Questions

Prepare for EX0-115 with more than an answer.

256 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$250 USD
Level
Foundation
Valid for
Lifetime
Domains covered on the exam 3
  1. Introduction to IT service management15%
  2. Service management system (SMS)30%
  3. The operation of the service management system (SMS)55%
  1. 1

    A service provider signs a contract with a new cloud hosting supplier. To comply with ISO/IEC 20000, which THREE of the following must be defined and agreed upon with this supplier? (Select THREE).

    Show answer details

    Correct answer: B, C, D

    Clear definition of responsibilities is crucial for effective collaboration and accountability.

    The contract must specify the performance targets the supplier is expected to achieve, often documented in an Underpinning Contract (UC).

    ISO/IEC 20000 requires that a process for handling disputes with suppliers is established to ensure conflicts can be resolved formally.

  2. 2

    True or False: The 'Adapt and Adopt' principle means that an organization can change the requirements of the ISO/IEC 20000-1 standard itself to better fit its needs.

    Show answer details

    Correct answer: B

    'Adapt and Adopt' refers to tailoring service management guidance (like ITIL) and using it to create practices that meet the standard's requirements. The requirements of the ISO/IEC 20000-1 standard itself are fixed and must be met for certification; they cannot be changed by the organization.

  3. 3

    An organization is establishing its Service Management System (SMS). Top management is concerned about potential business disruptions and wants to understand the key risks and opportunities. Which of the following is an example of an OPPORTUNITY that should be considered?

    Show answer details

    Correct answer: B

    An opportunity is a circumstance that can be exploited to achieve objectives. Using automation improves efficiency and consistency, which is a clear opportunity to enhance the SMS and service delivery.

  4. 4

    Case Study

    MediCare Solutions provides a hosted Electronic Health Record (EHR) service to hospitals. Due to the critical nature of their service, they have a comprehensive Service Management System (SMS) certified against ISO/IEC 20000. Recently, a software bug in a planned release caused a 4-hour outage for three major hospitals, impacting patient care. The incident was resolved by rolling back the release.

    Following the major incident, the Problem Management team conducted a root cause analysis (RCA). The RCA revealed that the bug was introduced by a last-minute code change that was not properly tested. The Release and Deployment Management process did not have a mandatory checkpoint to verify final test results before authorizing deployment. The team documented this as a known error and proposed a permanent fix.

    The proposed fix involves updating the release and deployment process to include a mandatory 'Go/No-Go' review with the Change Advisory Board (CAB) after final testing is complete. Implementing this process change is expected to prevent similar incidents in the future.

    To implement this permanent fix, what is the NEXT process that must be formally initiated?

    Show answer details

    Correct answer: C

    The output of Problem Management is often a Request for Change (RFC) to implement a permanent fix. Since the fix involves modifying an established process (Release and Deployment Management), it must be formally proposed, assessed, and authorized through the Change Management process.

  5. 5

    What is the primary purpose of defining a configuration baseline in Configuration Management?

    Show answer details

    Correct answer: B

    A configuration baseline is a formally agreed-upon version of a configuration item (or a set of CIs) that serves as a stable point of reference. It is used to manage changes, ensure consistency in builds and tests, and provide a known good state to revert to if a change fails.

  6. 6

    Which two processes are most directly responsible for managing the expectations and satisfaction of the customer? (Select TWO).

    Show answer details

    Correct answer: B, C

    Business Relationship Management focuses on maintaining a positive relationship with customers, understanding their business needs, and ensuring their satisfaction with the services provided.

    Service Level Management is responsible for negotiating and agreeing upon achievable service level targets (in SLAs) and then ensuring these levels of service are met, which is a primary driver of customer satisfaction.

  7. 7

    What is the key difference between an 'incident' and a 'problem' in the context of ISO/IEC 20000?

    graph TD subgraph Problem_Management A[Root Cause Analysis] --> B{Known Error} B --> C[Permanent Fix] end subgraph Incident_Management D[Service Disruption] --> E[Workaround] E --> F[Service Restored] end D -- Triggers --> A

    Show answer details

    Correct answer: A

    This is the fundamental distinction. An incident is the event that users experience (e.g., 'the system is down'). A problem is the underlying issue that caused the incident(s) (e.g., 'a faulty memory chip in the server'). Incident Management focuses on restoring service quickly (a workaround), while Problem Management focuses on finding and fixing the root cause to prevent future incidents (a permanent fix).

  8. 8

    A financial services company is required by regulators to demonstrate the effectiveness of its IT service continuity plans. The service continuity manager has scheduled a full-scale disaster recovery test. According to ISO/IEC 20000, which process is essential for authorizing the timing and potential service impact of this test?

    Show answer details

    Correct answer: B

    A full-scale disaster recovery test has the potential to impact live services and requires significant coordination. Therefore, it must be planned, assessed, and authorized through the Change Management process to manage the risk and ensure all stakeholders are informed.

  9. 9

    During an audit of a newly certified Service Management System (SMS), an auditor finds that while service management objectives exist, they are not consistently measured or reported on. Which core principle of ISO/IEC 20000 has been most significantly violated?

    Show answer details

    Correct answer: C

    The Plan-Do-Check-Act (PDCA) cycle is fundamental to ISO/IEC 20000. Failing to measure ('Check') and report on objectives breaks the cycle, preventing the 'Act' phase (continual improvement). This is a direct violation of the requirement to monitor, measure, analyze, and evaluate the SMS.

  10. 10

    A healthcare provider's SMS scope includes clinical applications and patient record systems. To comply with ISO/IEC 20000, which TWO of the following must the information security management process specifically address? (Select TWO).

    Show answer details

    Correct answer: B, C

    ISO/IEC 20000 requires the information security management process to implement controls to maintain the confidentiality, integrity, and availability (CIA) of information, which is especially critical for sensitive patient data.

    A key activity of the information security management process is to have a defined procedure for managing security incidents, from detection and analysis to resolution and learning.

Create an account to continue.