CMA Practice Questions
Prepare for CMA with more than an answer.
- Exam fee
- $17000 USD
- Level
- Expert
- Valid for
- 2 years
- 1
Case Study:
HealthCorp, a large hospital network, has implemented ServiceNow ITSM and HR Service Delivery. They are now planning to build a custom application for managing clinical trials, which will handle sensitive patient data. The development team is comprised of both internal employees and external contractors. The Chief Compliance Officer (CCO) is concerned about unauthorized access to data and code during the development lifecycle and has mandated a 'least privilege' access model.
The current development process involves all developers having admin access in sub-production instances and using shared update sets. The CCO has flagged this as a major compliance risk. The VP of Application Development is pushing back, arguing that restricting access will slow down development and hinder collaboration.
As the Master Architect, you must propose a solution that satisfies the CCO's compliance requirements without crippling the development team's productivity. What is the most comprehensive and architecturally sound solution?
Show answer details
Correct answer: C
This is the most robust and modern solution. Building the app in its own scope encapsulates it, preventing it from affecting other parts of the platform. Delegated Development allows the platform owner to grant specific, granular permissions (e.g., 'can create business rules', 'cannot modify ACLs') to different developers or teams, enforcing least privilege. Integrating with a source control system like Git moves the collaboration and versioning process off-platform, providing a full audit trail of every code change and who made it. This combination directly addresses the CCO's compliance concerns while providing developers with a structured, professional, and ultimately more efficient workflow than shared update sets.
- 2
A stakeholder from the finance department complains that their ServiceNow reports are slow and often time out. Upon investigation, you find they are running complex reports directly against production tables with millions of records during peak business hours. As the architect, what is the best practice solution to this problem?
Show answer details
Correct answer: C
Performance Analytics (PA) is designed to solve this exact problem. It runs scheduled jobs (typically nightly) to collect and aggregate data from transactional tables into optimized data marts (indicator scores). Reporting and dashboarding are then performed against these aggregated scores, not the live production tables. This prevents performance degradation on the production instance, allows for trend analysis over time, and provides much faster report generation. Simply increasing resources or restricting report times are temporary fixes that don't address the underlying architectural issue.
- 3
A company is planning to use the ServiceNow CMDB as the single source of truth for its hybrid cloud environment, which includes AWS, Azure, and on-premise VMware. Which ServiceNow ITOM application is essential for populating and maintaining the relationships between these different CIs?
Show answer details
Correct answer: C
ITOM Discovery is the core application for finding and populating the CMDB with infrastructure and application CIs. It uses probes and sensors, as well as cloud-native APIs, to scan the network, VMware environment, and cloud subscriptions (AWS, Azure) to identify devices, servers, software, and the relationships between them. While Service Mapping builds on this data to create service context, Discovery is the fundamental tool for the initial and ongoing population of the CMDB. Event Management deals with operational events, and Orchestration is for automation.
- 4
You are presenting a business case for implementing ServiceNow Application Portfolio Management (APM) to a steering committee. What are the primary business outcomes you would highlight? (Select TWO)
Show answer details
Correct answer: B, D
Application Portfolio Management (APM) provides the data and framework to make strategic decisions about the application landscape. Its primary business outcomes are cost reduction through application rationalization (identifying and decommissioning redundant or low-value apps) and risk reduction by identifying applications running on unsupported technology or with poor business fit. While it can indirectly influence development cycle times or improve availability, its core value propositions are cost optimization and risk mitigation.
Application Portfolio Management (APM) provides the data and framework to make strategic decisions about the application landscape. Its primary business outcomes are cost reduction through application rationalization (identifying and decommissioning redundant or low-value apps) and risk reduction by identifying applications running on unsupported technology or with poor business fit. While it can indirectly influence development cycle times or improve availability, its core value propositions are cost optimization and risk mitigation.
- 5
A platform owner is concerned that their ServiceNow instance is performing poorly after five years of organic growth and multiple implementations. A review of the instance shows the following governance anti-pattern. Which one is the most likely cause of systemic performance issues?
flowchart TD A[Requirement] --> B{Is it complex?} B -->|Yes| C[Assign to Senior Dev] B -->|No| D[Assign to Junior Dev] C --> E[Dev writes code in Default Update Set] D --> E E --> F[Dev tests in Dev instance] F --> G{Does it work?} G -->|Yes| H[Mark Update Set 'Complete'] H --> I[Admin merges Default Update Set to Test] I --> J[Admin merges Default Update Set to Prod]Show answer details
Correct answer: C
Using a shared 'Default' update set for all development is a major governance anti-pattern. It makes it impossible to deploy features independently, leads to massive, unmanageable update sets, and often causes developers to overwrite each other's work. More importantly, it encourages developers to make changes to global, out-of-the-box objects instead of working in scoped applications, which is a primary source of technical debt and long-term performance degradation.
- 6
A global pharmaceutical company with highly regulated GxP data is planning to adopt ServiceNow for both ITSM and a custom Drug Trial Management application. The CISO is concerned about data segregation and validation requirements. As the Master Architect, which multi-instance strategy would you recommend to balance compliance with platform consolidation benefits?
Show answer details
Correct answer: B
For highly regulated environments like GxP, physical instance separation is the gold standard. It provides a distinct validation boundary, simplifies audit processes, and ensures that changes to the non-GxP instance (e.g., ITSM upgrades) do not trigger a re-validation event for the sensitive Drug Trial Management application. While more costly, this approach provides the strongest compliance posture. Domain separation offers logical separation but shares the same physical database and application nodes, which is often insufficient for stringent GxP validation. A single instance with separate scopes is a weaker form of logical separation. Using non-production instances for production GxP data is a direct violation of compliance principles.
- 7
A major financial institution is implementing a global ServiceNow platform governance model. They have representation from North America, EMEA, and APAC. The key challenge is balancing global standardization with regional regulatory needs (e.g., GDPR in EMEA, CCPA in NA). Which governance structure is most effective for this scenario?
Show answer details
Correct answer: C
A federated governance model is the most appropriate for this complex scenario. It allows a global Center of Excellence (CCoE) to establish core platform standards, architectural principles, and data models, ensuring consistency and maintainability. Simultaneously, it empowers regional governance boards to define and implement policies specific to their local regulatory and business requirements (like GDPR). This strikes the necessary balance between central control and regional autonomy. A purely centralized model would fail to address regional needs, while a decentralized model would lead to fragmentation and loss of global standards.
- 8
During a presentation to the CIO of a retail giant, you are asked how ServiceNow will deliver tangible business value beyond IT cost savings. Which of the following metrics are most effective for articulating strategic business value to an executive audience? (Select TWO)
Show answer details
Correct answer: B, D
Executive audiences like a CIO are focused on strategic outcomes that impact the entire business. Increased employee productivity and accelerated speed-to-market for new products are high-level business value metrics. While MTTR and server uptime are important operational metrics for IT, they don't directly translate to top-line business growth or strategic advantage in the same way.
Executive audiences like a CIO are focused on strategic outcomes that impact the entire business. Increased employee productivity and accelerated speed-to-market for new products are high-level business value metrics. While MTTR and server uptime are important operational metrics for IT, they don't directly translate to top-line business growth or strategic advantage in the same way.
- 9
A manufacturing client is struggling with technical debt after five years of un-governed, department-led customizations on their ServiceNow instance. As the Master Architect, your first step is to establish a baseline for a remediation plan. What is the most critical initial action?
Show answer details
Correct answer: C
Before any remediation plan can be created, a thorough and objective assessment of the instance's health is required. A ServiceNow-led HealthScan provides a structured analysis of customizations, performance, security, and deviations from best practice. This data-driven baseline is essential for prioritizing remediation efforts, quantifying the technical debt, and building a business case for the necessary changes. Freezing development or proposing a re-implementation are premature actions without this critical diagnostic data. Establishing a CCoE is a necessary future step, but the immediate need is to understand the scope of the problem.
- 10
True or False: In a federated ServiceNow governance model, the global CCoE should own and manage the backlog for all regional development teams to ensure architectural consistency.
Show answer details
Correct answer: B
In a federated model, the global CCoE's role is to set standards, define architecture patterns, and govern the platform's core. However, regional business units or development teams should own their respective backlogs to maintain agility and address local needs. The CCoE provides oversight and guidance, ensuring backlog items align with global standards, but does not manage the day-to-day backlog itself. This separation of concerns is a key principle of the federated approach.
