Skip to content

CIS-ITSM Practice Questions

Prepare for CIS-ITSM with more than an answer.

159 questions in the full set20 sample questionsUpdated Jan 25, 2026
Exam fee
$450 USD
Level
Implementation Specialist
Valid for
2 years
Domains covered on the exam 6
  1. Incident Management25%
  2. Problem Management15%
  3. Change and Release Management25%
  4. Knowledge Management5%
  5. Service Catalog and Request Management25%
  6. Configuration Management Database (CMDB)5%
  1. 1

    A problem coordinator is reviewing the 'Related Incidents' list on a Problem record. They notice that several incidents linked to the problem have different Configuration Items listed. What is the most likely reason for this situation?

    Show answer details

    Correct answer: B

    A single underlying problem, such as a faulty network switch or a failing database cluster node, can cause incidents on multiple different upstream CIs that depend on it. For example, several application servers (each a separate CI) might report errors (separate incidents), but the root cause is a single storage array (the problem's CI). Therefore, it is common and expected for a problem to have related incidents with various CIs.

  2. 2

    What is the primary purpose of the 'Can Contribute' list on a Knowledge Base's configuration form?

    Show answer details

    Correct answer: B

    The 'Can Contribute' related list uses User Criteria to define which users or groups are permitted to author, edit, and submit articles for a specific knowledge base. The 'Can Read' list defines who can view published articles. Approval permissions are handled by workflows or approval policies, not directly by this list.

  3. 3

    A financial institution has a strict audit requirement for its change management process. They need to ensure that once a Normal change request reaches the 'Assess' state, the 'Risk' and 'Impact' fields cannot be altered. What is the most robust way to enforce this?

    Show answer details

    Correct answer: C

    For a strict audit requirement, security must be enforced on the server side. An Access Control List (ACL) is the correct mechanism for this. A write ACL on change_request.risk and change_request.impact with a condition that the state is 'Assess' (or any subsequent state) and a role/script that evaluates to false will prevent any user from modifying the fields, regardless of how they access the data (form, list view, API). UI Policies and Client Scripts are client-side and can be bypassed.

  4. 4

    The CMDB health dashboard shows that the 'Completeness' metric for the Linux Server class is low. An administrator investigates and finds that the 'RAM' and 'CPU Core Count' attributes are frequently empty. What is the most direct way to configure CMDB Health to specifically track whether these two attributes are populated?

    Show answer details

    Correct answer: C

    The CMDB Health 'Completeness' metric is configured using the 'Required' and 'Recommended' field lists in the CI Class Manager. Adding fields to the 'Recommended' list will cause the health metric to check if they are populated, and CIs with empty values will lower the completeness score. Making them 'Required' would enforce population at the data entry level (like a dictionary attribute or data policy), which might be too strict if the data isn't always available upon CI creation.

  5. 5

    A user submits an incident via the Service Portal. The underlying Record Producer for this incident has a script that sets the incident's impact and urgency based on the user's answers. After submission, an Assignment Rule fires and assigns the incident to the Service Desk. Finally, a 'before insert' business rule runs to set the priority based on the impact and urgency. What is the final priority of the incident record when it is created in the database?

    1. User submits Record Producer
    (Script: Impact=2, Urgency=2)
    2. Assignment Rule runs
    (Action: Assignment Group = Service Desk)
    3. Business Rule (before insert, order 100) runs
    (Action: Set Priority based on Impact/Urgency Lookup)
    
    Show answer details

    Correct answer: B

    The order of execution for record creation is critical. The Record Producer script runs first to populate the current object. Then, 'before' business rules execute. Since the business rule runs 'before' the record is inserted into the database, its calculation will overwrite any values previously set. Assignment rules also run before insert, but the final data modification before the database write will be from the business rule. The priority lookup will use the impact and urgency set by the record producer to perform its calculation.

  6. 6

    Case Study: A large retail company, 'GlobalMart', is overhauling its IT Service Management processes in ServiceNow.

    Company Background: GlobalMart has 500 retail stores, each with its own point-of-sale (POS) systems, network hardware, and local servers. They have a central IT department and regional support teams. Their current CMDB is poorly maintained and contains stale data.

    Current Situation: When a POS system fails, the store manager calls a central hotline. The incident is logged with a generic category and assigned to a general queue, leading to slow resolution times. Change management is informal, with changes often causing unforeseen outages in other stores. There is no formal problem management process.

    Requirements:

    1. Incidents related to POS systems must be automatically categorized as 'Retail Systems' and assigned to the 'POS Support' team.
    2. The CMDB must be updated to accurately reflect the relationships between each store's POS systems and its local network switch.
    3. A new 'Emergency Change' model must be created for break-fix scenarios like a store-wide POS system failure. This model should bypass initial CAB approval but require post-implementation review.

    Based on the case study, which action would directly address the requirement to improve incident routing for POS system failures?

    Show answer details

    Correct answer: C

    Requirement 1 specifically calls for automatic categorization and assignment for POS system incidents. The most direct and standard way to achieve this is by using rules that trigger based on information in the incident. An Assignment Rule can set the 'POS Support' group, and a Data Lookup rule (or a simple business rule) can set the 'Retail Systems' category when the CI of the incident is identified as a POS system. This directly addresses the routing problem.

  7. 7

    Referring to the GlobalMart case study, how should the new 'Emergency Change' model be configured to meet the requirements?

    Show answer details

    Correct answer: A

    Requirement 3 states the Emergency Change model must bypass initial CAB approval but include a post-implementation review (PIR). The best way to model this is with a custom state model and workflow. The workflow should skip the 'Assess' and 'Authorize' states (where CAB approval typically happens), move quickly to 'Implement', and then transition to a 'Review' state. In the 'Review' state, the workflow should generate a change task for the Post-Implementation Review.

  8. 8

    A global logistics company is implementing Incident Management. They require that when an incident's priority changes to P1, a specific set of senior network engineers must be automatically added to the watch list, and an SMS notification must be sent to the on-call manager defined in a separate On-Call Scheduling rotation. Which is the most appropriate tool to automate this entire sequence of actions?

    Show answer details

    Correct answer: B

    Flow Designer is the best tool for this scenario as it provides native, low-code actions for complex processes like looking up on-call schedules and sending notifications via various channels (like SMS through Notify). It can handle the entire sequence, including adding to the watch list, without requiring extensive custom scripting. A Business Rule with a Script Include could work but is a less modern, code-heavy approach. A Workflow is typically for record lifecycles, not discrete updates. A UI Action requires manual intervention.

  9. 9

    A healthcare organization wants to ensure that any change request targeting a CI with a 'Business Criticality' of '1 - most critical' automatically requires approval from the VP of Clinical Operations, in addition to the standard CAB approval. This approval must be logged in the change request's approval history. How should this be configured to be scalable and maintainable?

    Show answer details

    Correct answer: C

    The correct way to handle dynamic, data-driven approvals is within the process engine (Workflow or Flow Designer) that governs the change model. By adding an 'Approval - User' activity and scripting its input, the approval is formally requested, tracked, and logged. This is scalable because it's part of the defined process. A business rule could send a notification but wouldn't create a formal, auditable approval record. Relying on the VP to filter their approvals is not a reliable or automated process. An assignment rule is for assigning tasks, not approvals.

  10. 10

    A university is designing a Service Catalog. They have a request for 'New Faculty Onboarding' which involves provisioning a laptop, creating an email account, granting access to the learning management system, and ordering business cards. Each of these four items is already a separate, orderable catalog item with its own fulfillment workflow. What is the most efficient way to present this to the user as a single request?

    Show answer details

    Correct answer: C

    An Order Guide is specifically designed for bundling multiple, existing catalog items into a single request process. It allows the user to answer a set of initial questions, and based on the rules, it adds the relevant items (in this case, all four) to their cart. This approach reuses the existing items and their fulfillment processes without modification, making it the most efficient and maintainable solution.

Create an account to continue.