CREST Certified Incident Manager (CCIM) — Questions and Answers
Question 1: When a major incident is escalated, who is typically the FIRST external audience to notify?
- Senior leadership and executive sponsors (Correct answer)
- Vendors and third-party suppliers
- End users and affected customers
- Regulatory bodies and auditors
Correct answer: Senior leadership and executive sponsors
Senior leadership must be notified first so they can authorize resources, set communication tone, and make high-level decisions.
Question 2: What is the purpose of a 'problem model' in problem management?
- A predefined approach for handling specific types of recurring problems efficiently (Correct answer)
- A diagram showing the physical layout of IT infrastructure
- A template for creating new service requests
- A financial model calculating the cost of downtime
Correct answer: A predefined approach for handling specific types of recurring problems efficiently
Problem models provide a structured, repeatable approach for addressing known types of problems, reducing investigation time and improving consistency.
Question 3: A post-incident review finds that the Incident Manager failed to update stakeholders for 90 minutes during a P1 incident. Which IRP component would have MOST directly prevented this?
- A pre-incident stakeholder training program on incident management
- Defined communication cadence requirements specifying maximum intervals between stakeholder updates (Correct answer)
- A severity classification matrix with clearer P1 definitions
- An automated monitoring dashboard accessible to stakeholders
Correct answer: Defined communication cadence requirements specifying maximum intervals between stakeholder updates
Mandatory update cadences (e.g., every 20-30 minutes for P1) create accountability and prevent communication gaps regardless of incident complexity.
Question 4: During a prolonged incident, which practice helps maintain stakeholder confidence even when resolution progress is slow?
- Escalating to a higher severity to signal urgency
- Providing regular honest updates with actions being taken and expected next steps (Correct answer)
- Reducing update frequency to avoid highlighting slow progress
- Shifting blame to third-party vendors in communications
Correct answer: Providing regular honest updates with actions being taken and expected next steps
Transparent, action-oriented updates sustain credibility and demonstrate active management even without resolution.
Question 5: What does 'time to escalate' (TTE) measure and why is it important?
- The elapsed time between incident detection and the decision to escalate, used to identify delays in Tier 1 triage (Correct answer)
- How long Tier 2 takes to respond after receiving an escalation
- The SLA target for Tier 2 resolution
- The total time an incident spends across all tiers
Correct answer: The elapsed time between incident detection and the decision to escalate, used to identify delays in Tier 1 triage
TTE identifies whether Tier 1 agents are holding incidents too long before escalating, which can cause SLA breaches downstream.
Question 6: What is risk avoidance?
- Choosing not to perform activities with risks (Correct answer)
- Accepting risks without changes
- Transferring risks
- Ignoring risk reports
Correct answer: Choosing not to perform activities with risks
Risk avoidance is a strategy where an organization chooses not to perform an activity or engage in a project that carries an unacceptable level of risk. By eliminating the source of the risk entirely, the organization avoids any potential negative consequences. This is often considered when the potential impact of a risk outweighs any potential benefits of the activity.
Question 7: An Incident Manager is coordinating a response across three geographic time zones. Which planning element is MOST critical to address in the IRP?
- Using a single centralized team to avoid coordination complexity
- Defining on-call schedules and follow-the-sun handoff procedures across time zones (Correct answer)
- Requiring all resolvers to be available 24/7 regardless of location
- Standardizing all communication in the headquarters local time
Correct answer: Defining on-call schedules and follow-the-sun handoff procedures across time zones
Follow-the-sun handoff procedures and on-call schedules ensure continuous coverage and smooth ownership transitions across geographic boundaries.
Question 8: Which of the following BEST describes 'two-way communication' during a crisis?
- Establishing channels for stakeholders to ask questions and receive responses in addition to broadcast updates (Correct answer)
- Sending updates via two different channels simultaneously (e.g., email and SMS)
- Using both internal and external communication plans at the same time
- Notifying both technical teams and business units in parallel
Correct answer: Establishing channels for stakeholders to ask questions and receive responses in addition to broadcast updates
Two-way communication enables stakeholder feedback and questions, building trust and surfacing concerns that could affect the response.
Question 9: What role does continuous improvement play in itil framework & best practices for CIM certified professionals?
- It applies only to new professionals in their first year
- It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation (Correct answer)
- It is optional and only necessary during certification renewal
- It focuses exclusively on cost reduction
Correct answer: It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation
Continuous improvement is fundamental to professional practice in itil framework & best practices, involving regular evaluation, feedback integration, and process enhancement to maintain high standards.
Question 10: A company replicates data to a secondary site every four hours. If a disaster occurs, what is the worst-case data loss scenario?
- Loss depends solely on the RTO, not replication frequency
- Up to four hours of data (Correct answer)
- Zero data loss because replication is active
- Up to eight hours of data
Correct answer: Up to four hours of data
The Recovery Point Objective is determined by the replication interval; with four-hour cycles, up to four hours of transactions could be lost.
Question 11: What is the primary purpose of a 'back-out plan' in a change management record?
- To document the estimated cost of implementing the change
- To schedule future changes after this one completes
- To assign accountability if the change fails
- To provide step-by-step procedures for reversing the change if it causes problems (Correct answer)
Correct answer: To provide step-by-step procedures for reversing the change if it causes problems
A back-out (rollback) plan documents the steps needed to reverse a change and restore the prior state if the change causes unintended incidents or service failures.
Question 12: What is the primary risk of consistently under-prioritizing incidents at intake?
- Overstaffing of the service desk
- Reduced number of problem records opened
- Increased number of change requests submitted
- SLA breaches and unresolved business-critical outages (Correct answer)
Correct answer: SLA breaches and unresolved business-critical outages
Consistent under-prioritization leads to SLA breaches, delayed resolution of critical outages, and significant business impact that correct categorization could have prevented.
Question 13: What role does continuous improvement play in automation & incident orchestration for CIM certified professionals?
- It applies only to new professionals in their first year
- It is optional and only necessary during certification renewal
- It focuses exclusively on cost reduction
- It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation (Correct answer)
Correct answer: It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation
Continuous improvement is fundamental to professional practice in automation & incident orchestration, involving regular evaluation, feedback integration, and process enhancement to maintain high standards.
Question 14: In the context of CIM certification, what is the most important consideration when implementing crisis communication & notifications?
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
- Minimizing documentation to save time
- Delegating all responsibilities to junior staff
- Completing implementation as quickly as possible regardless of quality
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing crisis communication & notifications, CIM professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 15: Which KPI best measures the effectiveness of an incident team's ability to contain damage once an incident is detected?
- Mean Time to Respond (MTTR)
- Incident Volume Trend
- Mean Time to Contain (MTTC) (Correct answer)
- Mean Time to Detect (MTTD)
Correct answer: Mean Time to Contain (MTTC)
Mean Time to Contain (MTTC) specifically measures how quickly the team limits the blast radius after detection, making it the most direct measure of containment effectiveness.
Question 16: What is a 'Known Error' in ITIL, and how does it support faster incident resolution?
- A problem with a documented root cause and workaround stored in the Known Error Database (KEDB) (Correct answer)
- An error that occurs only intermittently and cannot be reproduced in testing
- Any incident that has been open without resolution for more than 24 hours
- An error reported by users that has been deemed permanently unfixable
Correct answer: A problem with a documented root cause and workaround stored in the Known Error Database (KEDB)
A Known Error is a problem with an identified root cause and documented workaround recorded in the KEDB, enabling faster incident resolution and consistent handling of recurring issues.
Question 17: What information should ALWAYS be captured when a service desk agent escalates an incident?
- Only the user's name and phone number
- Steps already taken, current impact, priority, and reason for escalation (Correct answer)
- The agent's personal recommendation for resolution
- The full chat history but no diagnostic results
Correct answer: Steps already taken, current impact, priority, and reason for escalation
Complete escalation documentation prevents duplicated effort and ensures the receiving team has full context to continue resolution efficiently.
Question 18: A DR test reveals the restored database is missing three hours of transactions. Which control would most directly have prevented this gap?
- Hiring additional database administrators
- Increasing the frequency of full backups
- Extending the RTO window in the DR plan
- Implementing continuous log shipping or synchronous replication to reduce the RPO (Correct answer)
Correct answer: Implementing continuous log shipping or synchronous replication to reduce the RPO
Continuous log shipping or synchronous replication keeps the secondary database nearly current, shrinking the recovery point to seconds rather than hours.
Question 19: During a major incident, who is responsible for authorizing emergency changes to production systems?
- The Major Incident Manager
- The Change Advisory Board (CAB)
- The Service Desk Manager
- The Emergency Change Advisory Board (ECAB) (Correct answer)
Correct answer: The Emergency Change Advisory Board (ECAB)
The ECAB is convened to rapidly assess and authorize emergency changes during major incidents without requiring a full CAB meeting.
Question 20: Which categorization model uses a hierarchical structure such as 'Type > Category > Sub-category' for classifying incidents?
- Linear priority model
- RACI matrix
- Escalation ladder
- Multi-tiered categorization model (Correct answer)
Correct answer: Multi-tiered categorization model
A multi-tiered categorization model organizes incidents into hierarchical levels, enabling precise classification and richer trend reporting.
Question 21: A CIM wants to measure how effectively the team communicates during a major incident. Which KPI is most suitable?
- Total incident duration
- Number of status updates sent to stakeholders per incident hour (Correct answer)
- Number of escalations per incident
- Percentage of incidents classified as major
Correct answer: Number of status updates sent to stakeholders per incident hour
Measuring status update frequency during major incidents directly gauges communication effectiveness by tracking how consistently stakeholders are kept informed.
Question 22: What is the primary difference between an SLA and an OLA?
- An SLA is legally binding; an OLA is informal and optional
- An SLA covers security incidents; an OLA covers service requests
- An SLA is internal; an OLA is external
- An SLA is between provider and customer; an OLA is between internal support teams (Correct answer)
Correct answer: An SLA is between provider and customer; an OLA is between internal support teams
An SLA is a formal agreement with the customer, while an OLA (Operational Level Agreement) is an internal agreement between support groups that underpins the SLA commitments.
Question 23: What does the acronym SBAR stand for in structured crisis communication?
- Situation, Background, Assessment, Recommendation (Correct answer)
- Severity, Business impact, Action taken, Resolution timeline
- Status, Broadcast, Acknowledge, Resolve
- Scope, Briefing, Alert, Review
Correct answer: Situation, Background, Assessment, Recommendation
SBAR is a structured framework originally from healthcare now widely used in incident management to deliver concise, actionable briefings.
Question 24: What is the primary purpose of an incident communication log?
- To prioritize which teams should be notified first
- To automatically notify stakeholders via email and SMS
- To track SLA compliance and penalty calculations
- To document all messages sent and received during the incident for audit and learning (Correct answer)
Correct answer: To document all messages sent and received during the incident for audit and learning
The communication log creates an auditable record of all notifications, updates, and decisions made during the incident lifecycle.
Question 25: Which body is responsible for assessing risk and authorizing significant changes in ITIL?
- The service desk team
- The project management office
- The Incident Manager
- The Change Advisory Board (CAB) (Correct answer)
Correct answer: The Change Advisory Board (CAB)
The Change Advisory Board (CAB) assesses the risk, impact, and scheduling of significant changes, providing formal authorization before implementation proceeds.
Question 26: During a major incident, the technical lead insists the issue is almost resolved and requests that the Major Incident Manager not escalate. What should the Major Incident Manager do?
- Escalate only if the customer complains
- Trust the technical lead and delay escalation
- Defer the decision to the Service Desk
- Follow the escalation criteria defined in the major incident procedure regardless of opinion (Correct answer)
Correct answer: Follow the escalation criteria defined in the major incident procedure regardless of opinion
Escalation decisions must be based on defined criteria and timeframes, not on the subjective assessment of individuals involved in the fix.
Question 27: Which section of a post-incident report is typically read by executives who want to understand impact and next steps without technical detail?
- Executive summary (Correct answer)
- Technical timeline
- Alert log attachment
- Root cause analysis appendix
Correct answer: Executive summary
The executive summary provides a concise overview of the incident, business impact, and key remediation commitments in non-technical language.
Question 28: In incident management, a 'war room' serves what communication purpose?
- A room where the post-incident review is conducted after resolution
- A command center for monitoring social media sentiment during a crisis
- A physical or virtual space centralizing all responders to enable rapid, coordinated communication (Correct answer)
- A dedicated line for communicating with regulatory agencies only
Correct answer: A physical or virtual space centralizing all responders to enable rapid, coordinated communication
The war room consolidates key responders so decisions and communications happen in real time without lag from distributed teams.
Question 29: In Fault Tree Analysis (FTA), what does an AND gate signify?
- All input events must occur simultaneously to cause the output event (Correct answer)
- The input events are mutually exclusive
- The output event is caused by an unknown factor
- Any one of the input events alone can cause the output event
Correct answer: All input events must occur simultaneously to cause the output event
An AND gate in FTA means all connected input conditions must be present together for the higher-level failure event to occur.
Question 30: What is 'impact assessment' in the context of declaring a major incident?
- Calculating financial penalties owed to customers
- Evaluating the breadth and severity of service disruption to determine incident priority (Correct answer)
- Assessing the workload on the incident response team
- Reviewing past incidents to predict future failures
Correct answer: Evaluating the breadth and severity of service disruption to determine incident priority
Impact assessment evaluates how many users, services, and business functions are affected to determine whether a major incident declaration is warranted.
Question 31: When an incident affects multiple business units simultaneously, which coordination model is most effective for the Incident Manager?
- Allow each unit to self-resolve independently
- Siloed response with separate incident managers per unit
- Centralized command with designated liaisons from each business unit (Correct answer)
- Defer coordination to the Change Advisory Board
Correct answer: Centralized command with designated liaisons from each business unit
Centralized command with business unit liaisons ensures consistent messaging, avoids conflicting remediation actions, and provides a single point of authority.
Question 32: A CIM discovers that an incident initially logged as P3 is actually causing a complete outage for 200 users. What is the correct action?
- Close the incident and open a new one at P1
- Keep the original priority to avoid confusion in the system
- Wait for the next scheduled priority review to update the classification
- Re-prioritize the incident to P1 and initiate major incident procedures (Correct answer)
Correct answer: Re-prioritize the incident to P1 and initiate major incident procedures
When new information reveals significantly greater impact, the Incident Manager must immediately re-prioritize and trigger appropriate procedures such as major incident management.
Question 33: When an incident affects multiple regions with different regulatory requirements, which factor MOST influences notification timing?
- The severity classification assigned by the Incident Commander
- The organization's standard SLA with each regional customer
- The preference of the regional account management teams
- The strictest applicable regulatory deadline across all affected jurisdictions (Correct answer)
Correct answer: The strictest applicable regulatory deadline across all affected jurisdictions
Organizations must comply with the most stringent regulatory timeline to avoid violations; this often drives the overall notification schedule.
Question 34: Which of the following best describes a 'systemic root cause' found in a post-incident analysis?
- An operator who did not follow the runbook
- An underlying organizational, cultural, or process weakness that enabled the failure (Correct answer)
- A vendor hardware defect
- A single misconfigured server
Correct answer: An underlying organizational, cultural, or process weakness that enabled the failure
Systemic root causes are organizational or process-level weaknesses that create conditions for multiple potential failure modes.
Question 35: During a post-incident analysis, a responder reveals they deviated from the runbook because 'it didn't match the actual system state.' What is the best follow-up action?
- Require runbook sign-off by all responders monthly
- Discipline the responder for not following procedure
- Archive the runbook and create a new one from scratch
- Update the runbook to reflect reality and investigate why it became out of date (Correct answer)
Correct answer: Update the runbook to reflect reality and investigate why it became out of date
Runbook drift indicates a documentation maintenance failure; the correct action is updating the runbook and establishing a review cadence.
Question 36: According to ITIL, what distinguishes a 'major incident' from a standard high-priority incident?
- Major incidents are defined solely by the number of users affected
- Major incidents require a separate procedure with escalated management involvement (Correct answer)
- Major incidents are resolved only by vendor support
- Major incidents always involve hardware failures
Correct answer: Major incidents require a separate procedure with escalated management involvement
Major incidents invoke a separate, predefined procedure that includes senior management engagement and dedicated coordination roles.
Question 37: What is a critical element of post-incident review?
- Blaming individuals
- Discarding documentation
- Ignoring past incidents
- Analyzing response effectiveness and updating plans (Correct answer)
Correct answer: Analyzing response effectiveness and updating plans
A critical element of post-incident review is the objective analysis of the response's effectiveness. This involves evaluating what went well, what could be improved, and identifying any gaps in plans or procedures. The insights gained are then used to update and refine incident response plans, ensuring continuous improvement and better preparedness for future incidents.
Question 38: A major incident affects a business-critical application shared by multiple customer accounts. What is the BEST initial stakeholder notification strategy?
- Send a single broadcast notification to all affected customers simultaneously (Correct answer)
- Escalate internally only and let account managers notify customers individually
- Notify only the largest customer account first
- Wait for root cause confirmation before notifying any customers
Correct answer: Send a single broadcast notification to all affected customers simultaneously
All affected customers should be notified simultaneously with an initial impact statement to maintain transparency and prevent fragmented communication.
Question 39: Who should be involved in the post-incident review?
- No one
- All key stakeholders and response team members (Correct answer)
- Only senior management
- External auditors only
Correct answer: All key stakeholders and response team members
A post-incident review aims to learn from an incident and improve future responses. Involving all key stakeholders (those affected or responsible for systems) and response team members ensures a comprehensive understanding of the incident from various perspectives. This collaborative approach fosters shared learning, identifies systemic issues, and promotes buy-in for corrective actions.
Question 40: When a SOAR platform's API call to a third-party tool fails during playbook execution, what is the recommended handling pattern?
- Terminate the entire playbook immediately with no record
- Send the failed request to a public error log
- Skip all remaining steps and close the incident automatically
- Implement retry logic with exponential backoff, log the failure, and alert the analyst if retries are exhausted (Correct answer)
Correct answer: Implement retry logic with exponential backoff, log the failure, and alert the analyst if retries are exhausted
Exponential backoff retries handle transient failures gracefully, while logging and analyst alerts ensure no action is silently lost during orchestration.
Question 41: How can technology assist in stakeholder communication?
- Facilitates timely updates and collaboration (Correct answer)
- Complicates messages
- Limits access to information
- Replaces personal interaction
Correct answer: Facilitates timely updates and collaboration
Technology significantly assists in stakeholder communication by facilitating timely updates and enhancing collaboration. Tools like project management software, communication platforms, and video conferencing enable instant information sharing, document collaboration, and virtual meetings regardless of geographical location. This improves efficiency and ensures stakeholders remain connected and informed throughout the project.
Question 42: Which mitigation strategy is MOST appropriate when the cost of controlling a risk exceeds the value of the asset at risk?
- Risk transfer
- Risk acceptance (Correct answer)
- Risk reduction
- Risk avoidance
Correct answer: Risk acceptance
When control costs outweigh asset value, risk acceptance (knowingly tolerating the risk) is the rational economic choice.
Question 43: When a CIM professional encounters an unfamiliar challenge in metrics & kpi reporting, what is the recommended first course of action?
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
- Apply the solution used for the most recent similar problem without adaptation
- Proceed based on personal intuition alone
- Postpone addressing the issue indefinitely
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 44: Which metric measures the average time required to restore a failed system or component to full operation?
- Mean Time to Repair (MTTR) (Correct answer)
- Recovery Point Objective (RPO)
- Mean Time Between Failures (MTBF)
- Recovery Time Objective (RTO)
Correct answer: Mean Time to Repair (MTTR)
MTTR is the historical average time to repair or restore a system, used to set realistic RTOs and assess team and vendor performance.
Question 45: How does a well-maintained CMDB support proactive incident prevention?
- It automates the approval workflow for all change requests
- It provides accurate asset and dependency data to identify vulnerable components before they cause incidents (Correct answer)
- It maintains a real-time log of all open incidents in the environment
- It stores SLA targets and resolution time thresholds for all services
Correct answer: It provides accurate asset and dependency data to identify vulnerable components before they cause incidents
A well-maintained CMDB provides visibility into asset relationships and dependencies, enabling proactive identification of vulnerable or overloaded components before they cause incidents.
Question 46: What is the most effective way to measure success in itil framework & best practices within CIM professional practice?
- Count only the number of activities completed
- Rely solely on supervisor opinion
- Compare only with industry averages without considering context
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 47: When a CIM professional encounters an unfamiliar challenge in crisis communication & notifications, what is the recommended first course of action?
- Apply the solution used for the most recent similar problem without adaptation
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
- Postpone addressing the issue indefinitely
- Proceed based on personal intuition alone
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 48: A lessons-learned session reveals that during the last major incident, no one had authority to approve an emergency change needed for restoration. Which IRP section should be updated?
- Emergency change authority and pre-authorized change provisions (Correct answer)
- Business impact assessment template
- Severity classification criteria
- Incident closure checklist
Correct answer: Emergency change authority and pre-authorized change provisions
Pre-authorized emergency change provisions or delegated change authority definitions ensure resolvers can implement necessary fixes without waiting for standard approval cycles.
Question 49: A service desk ticket is nearing its SLA resolution deadline and Tier 2 has not responded. What is the correct action?
- Wait for Tier 2 to respond on their own schedule
- Close the ticket to stop the SLA clock
- Trigger an SLA escalation alert and notify the Tier 2 manager (Correct answer)
- Reassign the ticket back to Tier 1
Correct answer: Trigger an SLA escalation alert and notify the Tier 2 manager
SLA breach risk should trigger an automated alert and manager notification so the incident receives priority attention before the deadline passes.
Question 50: How should CIM professionals handle confidential information related to itil framework & best practices?
- Store information without any security measures
- Delete all records after project completion
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Share freely with all colleagues for transparency
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 51: Which of the following best describes a key competency required for crisis communication & notifications in CIM practice?
- The ability to work independently without any oversight
- Reliance on a single methodology for all situations
- Memorization of all relevant regulations without understanding context
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CIM professionals working in crisis communication & notifications need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 52: What is 'runbook automation' and how does it differ from a full SOAR playbook?
- Runbook automation executes predefined IT operational procedures step-by-step, while SOAR playbooks coordinate cross-tool security workflows with decision logic (Correct answer)
- Runbook automation replaces SOAR entirely
- They are identical in function and scope
- Runbook automation only applies to hardware provisioning
Correct answer: Runbook automation executes predefined IT operational procedures step-by-step, while SOAR playbooks coordinate cross-tool security workflows with decision logic
Runbook automation focuses on standardized IT operational steps, whereas SOAR playbooks integrate multiple security tools, apply conditional logic, and manage the full incident lifecycle.
Question 53: When a CIM professional encounters an unfamiliar challenge in root cause analysis & problem management, what is the recommended first course of action?
- Proceed based on personal intuition alone
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
- Apply the solution used for the most recent similar problem without adaptation
- Postpone addressing the issue indefinitely
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 54: Which of the following best describes a key competency required for disaster recovery & business continuity in CIM practice?
- Reliance on a single methodology for all situations
- Memorization of all relevant regulations without understanding context
- The ability to work independently without any oversight
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CIM professionals working in disaster recovery & business continuity need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 55: An incident manager is evaluating supply chain risks for the BCP. Which factor is MOST critical to assess for single-source suppliers?
- The supplier's marketing budget
- Whether the supplier uses the same ERP system as the organization
- The number of employees the supplier has
- The supplier's geographic concentration and its vulnerability to the same disaster scenarios as the organization (Correct answer)
Correct answer: The supplier's geographic concentration and its vulnerability to the same disaster scenarios as the organization
If a single-source supplier is in the same disaster zone, a regional event could eliminate both the organization and its sole supplier simultaneously.
Question 56: What is the primary purpose of incident categorization in ITIL-based incident management?
- To calculate SLA breach penalties
- To notify management of all incidents
- To determine the financial cost of incidents
- To assign incidents to the correct support team and enable trend analysis (Correct answer)
Correct answer: To assign incidents to the correct support team and enable trend analysis
Incident categorization primarily enables accurate routing to the appropriate support team and supports trend analysis for proactive service improvement.
Question 57: In a multi-tenant cloud environment, who is primarily responsible for ensuring business continuity for customer workloads?
- Government regulators who license the cloud provider
- The cloud provider is solely responsible for all continuity and recovery
- The customer's cyber insurance carrier
- Responsibility is shared: the cloud provider ensures platform availability while the customer designs and manages application-level continuity (Correct answer)
Correct answer: Responsibility is shared: the cloud provider ensures platform availability while the customer designs and manages application-level continuity
The shared responsibility model means cloud providers guarantee infrastructure availability, but customers must architect their applications for resilience, backup, and recovery.
Question 58: Which document pre-defines escalation paths and contact lists for use during major incidents?
- Asset management database
- Service portfolio
- Change Advisory Board charter
- Incident escalation policy and runbook (Correct answer)
Correct answer: Incident escalation policy and runbook
An incident escalation policy and runbook pre-defines contact trees, escalation criteria, and response roles to ensure consistent and rapid escalation during major incidents.
Question 59: In ITIL, a 'known error' is best described as:
- A problem that has a documented root cause and workaround (Correct answer)
- An unresolved incident older than 30 days
- An error found during software testing before release
- An incident that has been logged but not yet assigned
Correct answer: A problem that has a documented root cause and workaround
A known error is a problem with an identified root cause and a documented workaround, stored in the Known Error Database (KEDB).
Question 60: A CIM professional is conducting a risk assessment and needs to prioritize risks for treatment. Which criterion should be applied FIRST?
- The ease of implementing the mitigation control
- The age of the identified risk
- The political sensitivity of the affected department
- The combination of likelihood and impact scores (Correct answer)
Correct answer: The combination of likelihood and impact scores
Risk prioritization is fundamentally based on the product of likelihood and impact, identifying which risks pose the greatest overall threat.
Question 61: What is the purpose of a 'call tree' (or notification cascade) in a business continuity plan?
- To document the escalation path for IT help desk tickets
- To provide a structured, sequential notification process ensuring all key personnel are contacted rapidly during an incident (Correct answer)
- To outline the decision logic for declaring a disaster
- To map all network connections between the primary and recovery sites
Correct answer: To provide a structured, sequential notification process ensuring all key personnel are contacted rapidly during an incident
A call tree distributes the notification burden by having each person contact a small group, accelerating communication to all stakeholders without relying on a single point of contact.
Question 62: When designing an incident orchestration workflow, why should human approval gates be included for high-impact actions like blocking IP ranges?
- To ensure a qualified analyst validates the action before it causes unintended service disruption (Correct answer)
- To test the playbook's error-handling logic
- To satisfy audit requirements only
- To slow down the response and allow time for logging
Correct answer: To ensure a qualified analyst validates the action before it causes unintended service disruption
High-impact automated actions can cause outages or business disruption if triggered incorrectly, so human approval gates add a critical safeguard.
Question 63: What is the role of a 'scribe' in a major incident response?
- To lead technical troubleshooting activities
- To communicate with external customers and media
- To maintain a real-time log of actions taken, decisions made, and timeline of events (Correct answer)
- To authorize emergency changes on behalf of the CAB
Correct answer: To maintain a real-time log of actions taken, decisions made, and timeline of events
A scribe documents the incident timeline, actions, and decisions in real time, ensuring an accurate record for the PIR and audit trail.
Question 64: Which of the following best describes a key competency required for major incident management procedures in CIM practice?
- The ability to work independently without any oversight
- Memorization of all relevant regulations without understanding context
- Reliance on a single methodology for all situations
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CIM professionals working in major incident management procedures need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 65: The ITIL concept of a 'service consumer' encompasses which three distinct roles?
- Stakeholder, vendor, partner
- User, customer, sponsor (Correct answer)
- Manager, technician, analyst
- Owner, operator, developer
Correct answer: User, customer, sponsor
ITIL 4 defines service consumers as users (who use services), customers (who define requirements), and sponsors (who authorize budgets).
Question 66: What is the role of a communication plan?
- Defines communication methods and schedules (Correct answer)
- Is optional
- Is only for large projects
- Slows down communication
Correct answer: Defines communication methods and schedules
A communication plan is essential as it systematically defines how and when information will be shared with various stakeholders. It outlines communication methods (e.g., emails, meetings, reports), frequencies, and responsibilities, ensuring consistent and timely dissemination of information. This structured approach prevents miscommunication, manages expectations, and keeps everyone informed throughout the project lifecycle.
Question 67: Why is risk communication important?
- Is only for compliance
- Should be avoided
- Ensures all stakeholders understand risks (Correct answer)
- Creates unnecessary fear
Correct answer: Ensures all stakeholders understand risks
Risk communication is crucial because it ensures that all relevant stakeholders, including management, teams, and external parties, have a clear and shared understanding of identified risks. Transparent communication fosters informed decision-making, facilitates collaboration on mitigation efforts, and builds trust. It helps prevent misunderstandings and ensures everyone is aligned on potential threats and responses.
Question 68: A CIM is comparing MTTR across three different teams. Team A has the lowest MTTR but the highest escalation rate. What is the most likely explanation?
- Team A's ITSM tool calculates MTTR differently
- Team A receives simpler incidents than the others
- Team A has superior technical skills
- Team A is escalating incidents quickly rather than resolving them, artificially lowering their MTTR (Correct answer)
Correct answer: Team A is escalating incidents quickly rather than resolving them, artificially lowering their MTTR
Escalating incidents transfers ownership, which may stop the clock on Team A's MTTR while passing unresolved work downstream.
Question 69: Which of the following best describes a key competency required for service desk & escalation processes in CIM practice?
- Memorization of all relevant regulations without understanding context
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- Reliance on a single methodology for all situations
- The ability to work independently without any oversight
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CIM professionals working in service desk & escalation processes need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 70: What is 'case management integration' in an automated incident orchestration platform?
- Managing physical server cases in a data center
- Tracking software license cases separately from incidents
- Automatically creating, updating, and closing structured incident cases within a central platform as orchestration actions progress (Correct answer)
- Archiving network diagrams in a document system
Correct answer: Automatically creating, updating, and closing structured incident cases within a central platform as orchestration actions progress
Case management integration ensures that each automated action is reflected in a centralized incident case, giving analysts a single unified view of all activities, findings, and status.
Question 71: Why is timely reporting important after an incident?
- Ensures information is fresh and actionable (Correct answer)
- Delays accountability
- Reduces team morale
- Is unnecessary
Correct answer: Ensures information is fresh and actionable
Timely reporting after an incident is crucial because memories are fresh, and critical details are less likely to be forgotten or distorted. This allows for a more accurate and complete understanding of the incident, enabling quicker analysis and the implementation of actionable improvements. Delays can lead to loss of vital information and hinder effective response and recovery efforts.
Question 72: In a crisis communications plan, what is the primary role of a designated spokesperson?
- To document lessons learned immediately after the incident
- To coordinate logistics for alternate site activation
- To make all technical recovery decisions during an incident
- To serve as the single, authoritative voice to external stakeholders, media, and the public (Correct answer)
Correct answer: To serve as the single, authoritative voice to external stakeholders, media, and the public
A single spokesperson prevents conflicting messages, controls information flow, and maintains organizational credibility with external audiences during a crisis.
Question 73: Which metric measures the average time from incident detection to full service restoration?
- Recovery Time Objective (RTO)
- Mean Time Between Failures (MTBF)
- Mean Time to Repair (MTTR) (Correct answer)
- Recovery Point Objective (RPO)
Correct answer: Mean Time to Repair (MTTR)
Mean Time to Repair (MTTR) measures the average time elapsed from incident detection to complete service restoration and is a key SLA performance indicator.
Question 74: A 'dark site' in crisis communication refers to:
- A backup data center used during failover events
- An internal-only status page blocked from public access
- A pre-built standby website activated during a crisis to publish updates (Correct answer)
- An unmonitored social media account
Correct answer: A pre-built standby website activated during a crisis to publish updates
A dark site is a pre-staged, pre-approved website kept offline until a crisis occurs, at which point it is activated to serve as the official communications hub.
Question 75: What is a 'Standard Change' in ITIL change management?
- A high-risk change requiring emergency authorization
- A pre-approved, low-risk, frequently performed change that follows an established procedure (Correct answer)
- A change that must be fully documented post-implementation only
- A change that always requires full CAB approval
Correct answer: A pre-approved, low-risk, frequently performed change that follows an established procedure
A Standard Change is pre-authorized, low-risk, and follows an established procedure, allowing it to bypass full CAB review and streamline routine operational tasks.
Question 76: Which scenario would typically receive the highest incident priority?
- A complete outage of a revenue-critical customer-facing application (Correct answer)
- A slow-running report in a back-office system
- A single user unable to print non-critical documents
- A minor UI bug affecting one internal tool
Correct answer: A complete outage of a revenue-critical customer-facing application
A complete outage of a revenue-critical customer-facing application has both high impact and high urgency, warranting the highest priority classification.
Question 77: During incident coordination, the Incident Manager learns that a resolver group lacks access to a critical system needed for diagnosis. What should the Incident Manager do?
- Invoke the emergency access provisioning procedure defined in the IRP to grant temporary access (Correct answer)
- Wait for the normal access request process to complete
- Assign a different team that already has access, even if they lack expertise
- Escalate to the CISO to determine if access should be granted
Correct answer: Invoke the emergency access provisioning procedure defined in the IRP to grant temporary access
IRPs should include emergency access provisioning procedures that override standard request workflows to avoid resolution delays during critical incidents.
Question 78: What is the purpose of a workaround in the context of problem management?
- To temporarily reduce or eliminate the impact of an incident while the problem remains open (Correct answer)
- To escalate the problem to a vendor
- To permanently fix the root cause of a problem
- To close the problem record without investigation
Correct answer: To temporarily reduce or eliminate the impact of an incident while the problem remains open
A workaround provides a temporary means of restoring service or reducing impact without permanently resolving the underlying root cause.
Question 79: A stakeholder requests a root cause in the initial incident notification. The incident manager should:
- Assign a separate team member to investigate the root cause immediately
- Defer the notification until the root cause is confirmed
- State that the cause is under investigation and a follow-up will be provided (Correct answer)
- Provide a preliminary root cause hypothesis
Correct answer: State that the cause is under investigation and a follow-up will be provided
Speculating on root cause before investigation creates risk; acknowledging investigation status is the correct approach.
Question 80: Which of the following best describes a 'reciprocal agreement' as a business continuity strategy?
- Two organizations agree to host each other's operations in the event of a disaster (Correct answer)
- An SLA between a company and its cloud provider for uptime guarantees
- A vendor contract guaranteeing hardware replacement within four hours
- A government mandate requiring critical infrastructure operators to share recovery resources
Correct answer: Two organizations agree to host each other's operations in the event of a disaster
A reciprocal agreement is an informal or formal arrangement between organizations to provide mutual recovery space and resources, reducing individual DR costs.
Question 81: Why is transparency important with stakeholders?
- Only applies to financial matters
- Reduces stakeholder interest
- Hides project issues
- Ensures honest and open information sharing (Correct answer)
Correct answer: Ensures honest and open information sharing
Transparency with stakeholders is crucial because it ensures honest and open information sharing, fostering trust and credibility. By being transparent about progress, challenges, and decisions, organizations build stronger relationships and reduce skepticism. This openness encourages constructive dialogue and helps manage expectations effectively, even when facing difficulties.
Question 82: In ITIL, what is the primary purpose of the 'Service Level Management' practice?
- To manage the capacity of IT infrastructure components
- To negotiate vendor contracts for IT equipment
- To classify and escalate incidents based on urgency
- To set, monitor, and report on service level targets agreed with customers (Correct answer)
Correct answer: To set, monitor, and report on service level targets agreed with customers
Service Level Management ensures that defined service levels are agreed upon, monitored, and reported to stakeholders.
Question 83: What is the most effective way to measure success in disaster recovery & business continuity within CIM professional practice?
- Rely solely on supervisor opinion
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
- Count only the number of activities completed
- Compare only with industry averages without considering context
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 84: How does accurate impact assessment at incident intake most directly improve SLA compliance?
- It reduces the total number of incidents reported to the service desk
- It automatically extends SLA deadlines for complex incidents
- It ensures correct resources and priority are allocated from the very start (Correct answer)
- It eliminates the need for hierarchical escalation
Correct answer: It ensures correct resources and priority are allocated from the very start
Accurate impact assessment at incident intake ensures the correct priority, team, and resources are assigned immediately, maximizing the chance of resolving the incident within SLA targets.
Question 85: In the context of CIM certification, what is the most important consideration when implementing major incident management procedures?
- Delegating all responsibilities to junior staff
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
- Minimizing documentation to save time
- Completing implementation as quickly as possible regardless of quality
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing major incident management procedures, CIM professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 86: A post-incident report is being prepared. Which stakeholder group typically receives the executive summary section?
- Front-line support technicians
- External vendors involved in the incident
- Senior leadership and business owners (Correct answer)
- Regulatory compliance auditors only
Correct answer: Senior leadership and business owners
Executive summaries distill business impact and key decisions for senior leadership without technical detail.
Question 87: Which element of an Incident Response Plan defines who has authority to declare a Major Incident?
- Escalation matrix
- Declaration criteria and authority section (Correct answer)
- Service catalog
- RACI chart
Correct answer: Declaration criteria and authority section
The declaration criteria and authority section specifies thresholds and which roles are empowered to officially declare a major incident.
Question 88: What does the ITIL term 'warranty' refer to in the context of service value?
- The contractual guarantee of service features
- Assurance that a service will meet agreed requirements (Correct answer)
- The legal liability of the service provider
- A financial rebate for service failures
Correct answer: Assurance that a service will meet agreed requirements
Warranty assures customers that a service will meet agreed specifications including availability, capacity, and continuity.
Question 89: What is 'hierarchical escalation' primarily used for in incident management?
- Informing management when incidents breach SLA or require executive awareness and resources (Correct answer)
- Automatically categorizing incidents by type
- Routing incidents between technical teams of equal skill
- Reducing the number of active incidents in the queue
Correct answer: Informing management when incidents breach SLA or require executive awareness and resources
Hierarchical escalation notifies senior management or executives when an incident exceeds SLA thresholds or requires management decisions and additional resources.
Question 90: What is the key distinction between proactive and reactive incident management?
- Proactive management identifies and prevents potential incidents before they impact users (Correct answer)
- There is no practical difference between the two approaches in modern ITSM
- Proactive management only applies to Priority 1 incidents
- Reactive management uses automation while proactive relies on manual workflows
Correct answer: Proactive management identifies and prevents potential incidents before they impact users
Proactive incident management uses monitoring, trend analysis, and risk assessment to prevent incidents before they occur, while reactive management responds after service is already disrupted.
Question 91: What is the key difference between disaster recovery (DR) and business continuity (BC)?
- DR is a subset of BC; DR focuses on restoring IT systems while BC encompasses keeping all business operations running (Correct answer)
- DR and BC are interchangeable terms for the same set of activities
- BC is a subset of DR; BC focuses only on communication while DR covers all operations
- DR applies only to natural disasters while BC applies only to cyber incidents
Correct answer: DR is a subset of BC; DR focuses on restoring IT systems while BC encompasses keeping all business operations running
Business continuity is the broader discipline of maintaining essential functions during a disruption; disaster recovery specifically addresses restoring IT infrastructure and data.
Question 92: In the context of disaster recovery, what does 'failback' mean?
- Switching operations to the secondary site during a disaster
- Testing the secondary site under production load conditions
- Returning operations to the primary site after it has been restored (Correct answer)
- Backing up data immediately after a failover event
Correct answer: Returning operations to the primary site after it has been restored
Failback is the planned process of transitioning workloads from the recovery/secondary site back to the restored primary environment.
Question 93: What is the main purpose of post-incident analysis?
- Assess what happened and identify lessons learned (Correct answer)
- Duplicate the same response every time
- Ignore the incident after resolution
- Blame individuals involved
Correct answer: Assess what happened and identify lessons learned
The main purpose of post-incident analysis is to thoroughly assess what happened during an incident, identify its root causes, and determine the effectiveness of the response. This critical process aims to extract valuable lessons learned, which can then be used to improve future incident response plans, procedures, and overall organizational resilience. It focuses on systemic improvement rather than blame.
Question 94: Which recovery site type offers the fastest time-to-operational but also carries the highest ongoing cost?
- Cold site
- Warm site
- Mobile recovery unit
- Hot site (Correct answer)
Correct answer: Hot site
A hot site is a fully equipped, staffed, and continuously synchronized duplicate facility that can assume operations within minutes but incurs significant recurring costs.
Question 95: A service desk analyst resolves a recurring incident using a documented workaround from the KEDB. What ITIL practice benefit does this demonstrate?
- Change Enablement reducing unauthorized changes
- Service Level Management enforcing SLA compliance
- Release Management improving service quality
- Problem Management enabling faster incident resolution (Correct answer)
Correct answer: Problem Management enabling faster incident resolution
Problem Management's KEDB enables faster incident resolution by providing analysts with documented workarounds for known issues.
Question 96: In ITIL-aligned incident management, how are SLA targets typically differentiated?
- By incident priority level, which reflects impact and urgency (Correct answer)
- By the time of day the incident is reported
- By the geographic location of the customer
- By the name of the assigned technician
Correct answer: By incident priority level, which reflects impact and urgency
SLA targets are typically differentiated by incident priority (P1–P4), which is determined by combining the incident's impact on the business and its urgency.
Question 97: Which principle ensures that stakeholders receive only the information relevant to their role during a crisis?
- Transparency
- Redundancy
- Completeness
- Need-to-know (Correct answer)
Correct answer: Need-to-know
The need-to-know principle limits information sharing to individuals who require it for their specific responsibilities, reducing noise and protecting sensitive data.
Question 98: An Underpinning Contract (UC) differs from an OLA in that a UC:
- Applies only to P1 and P2 incidents
- Is an agreement with an external third-party supplier rather than an internal team (Correct answer)
- Defines the customer's responsibilities during an incident
- Is used exclusively for cloud-based services
Correct answer: Is an agreement with an external third-party supplier rather than an internal team
An Underpinning Contract governs the relationship with external third-party suppliers (e.g., hardware vendors, ISPs), whereas an OLA governs internal support groups.
Question 99: An incident communication plan should be tested MOST frequently under which condition?
- On a scheduled basis and after significant organizational changes (Correct answer)
- Annually, during the budget planning cycle
- When a new CIO is appointed
- Only after an actual major incident occurs
Correct answer: On a scheduled basis and after significant organizational changes
Regular testing and updates after organizational changes ensure the plan remains accurate and actionable.
Question 100: A SOAR platform receives 500 low-severity alerts per hour. What is the primary benefit of using automated triage for these alerts?
- Increase analyst headcount
- Improve network topology mapping
- Reduce mean time to acknowledge by auto-closing or escalating without manual review (Correct answer)
- Generate more detailed reports
Correct answer: Reduce mean time to acknowledge by auto-closing or escalating without manual review
Automated triage reduces MTTA by programmatically evaluating and acting on low-severity alerts without requiring manual analyst intervention.
Question 101: Which metric BEST measures the effectiveness of incident coordination during a major incident?
- Number of tickets opened during the incident
- Total customer complaint volume
- Mean Time to Restore (MTTR) compared against SLA targets (Correct answer)
- Number of resolver groups engaged
Correct answer: Mean Time to Restore (MTTR) compared against SLA targets
MTTR directly reflects how efficiently coordination activities accelerated restoration, making it the most meaningful coordination effectiveness metric.
Question 102: When reviewing an IRP for completeness, which of the following is MOST often found to be missing in immature plans?
- Clear criteria for downgrading or closing a major incident (Correct answer)
- Network topology diagrams
- List of IT assets
- Vendor contact information
Correct answer: Clear criteria for downgrading or closing a major incident
Many plans detail how to escalate and respond but omit explicit criteria for when an incident can be downgraded or officially closed, leading to prolonged major incident status.
Question 103: During a major outage, the incident manager learns that the alternate processing site lacks sufficient bandwidth for production workloads. Which BCP phase should have identified this gap?
- Testing and exercises (Correct answer)
- Crisis communications
- Plan maintenance
- Incident closure
Correct answer: Testing and exercises
Regular testing and exercises—particularly simulation or full interruption tests—are designed to uncover infrastructure shortfalls like inadequate bandwidth before a real disaster.
Question 104: An organization mandates that all third-party vendors complete a security questionnaire before contract award. This is an example of:
- Corrective control implementation
- Supply chain risk mitigation (Correct answer)
- Residual risk acceptance
- Risk avoidance
Correct answer: Supply chain risk mitigation
Vetting vendors through security questionnaires is a proactive supply chain risk mitigation practice.
Question 105: When communicating an incident to customers, which of the following should be AVOIDED?
- Committing to a follow-up communication within a defined timeframe
- Providing a realistic estimated time to resolution
- Using technical jargon and internal system names (Correct answer)
- Acknowledging the impact on customers
Correct answer: Using technical jargon and internal system names
Technical jargon confuses customers and reduces trust; external communications must use plain, customer-centric language.
Question 106: What is the most effective way to measure success in major incident management procedures within CIM professional practice?
- Rely solely on supervisor opinion
- Count only the number of activities completed
- Compare only with industry averages without considering context
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 107: In ITIL, which combination of factors determines incident priority?
- Cost and duration
- Number of tickets and technician skill level
- Impact and urgency (Correct answer)
- Complexity and time reported
Correct answer: Impact and urgency
ITIL defines incident priority based on the combination of impact (breadth of business effect) and urgency (how quickly the incident must be resolved).
Question 108: Which ITIL process is most directly responsible for negotiating and maintaining SLAs and OLAs?
- Service Level Management (SLM) (Correct answer)
- Availability Management
- Capacity Management
- Problem Management
Correct answer: Service Level Management (SLM)
Service Level Management (SLM) is the ITIL process responsible for negotiating, agreeing, documenting, monitoring, and reviewing SLAs and OLAs.
Question 109: In a multi-team incident response, who is typically responsible for managing external communications?
- The Technical Lead
- The Incident Commander
- The Communications Lead or Public Relations representative (Correct answer)
- The Change Manager
Correct answer: The Communications Lead or Public Relations representative
The Communications Lead owns external messaging to customers, media, and regulators, freeing the Incident Commander to focus on resolution.
Question 110: What does high 'change velocity' in an IT environment typically signal to an Incident Manager?
- A high rate of changes is occurring, which often correlates with increased incident risk (Correct answer)
- The CMDB is being updated at an accelerated rate
- Changes are being approved faster than industry benchmarks allow
- The CAB is meeting more frequently than its standard schedule
Correct answer: A high rate of changes is occurring, which often correlates with increased incident risk
High change velocity (many changes implemented in a short period) typically correlates with elevated incident rates, and Incident Managers should treat it as a heightened risk indicator.
Question 111: Which of the following is a leading practice for post-incident communication to customers?
- Provide only the resolution time and avoid discussing the root cause to prevent legal risk
- Send a brief apology email immediately at resolution with no further follow-up
- Send communications only to customers who formally complained during the outage
- Publish a detailed post-incident report (PIR) explaining what happened, why, and what was fixed (Correct answer)
Correct answer: Publish a detailed post-incident report (PIR) explaining what happened, why, and what was fixed
A published Post-Incident Report demonstrates accountability, builds trust, and shows commitment to preventing recurrence.
Question 112: Which ITIL practice ensures that accurate information about the configuration of services and CIs is available when needed?
- Service Catalogue Management
- Change Enablement
- Service Configuration Management (Correct answer)
- IT Asset Management
Correct answer: Service Configuration Management
Service Configuration Management maintains accurate records of configuration items (CIs) and their relationships in the CMDB.
Question 113: Which document governs the obligations of external third-party vendors in supporting incident resolution?
- Underpinning Contract (UC) (Correct answer)
- Project charter
- Operational Level Agreement (OLA)
- Service Level Agreement (SLA)
Correct answer: Underpinning Contract (UC)
An Underpinning Contract (UC) defines the obligations of external third-party vendors and suppliers that contribute to delivering services and supporting SLA commitments.
Question 114: In ISO 22301 (Business Continuity Management Systems), what is the purpose of the 'interested parties' analysis?
- To list all vendors contracted for disaster recovery services
- To identify employees responsible for executing recovery procedures
- To determine which stakeholders have requirements and expectations that the BCMS must address (Correct answer)
- To identify shareholders who must approve the BCP budget
Correct answer: To determine which stakeholders have requirements and expectations that the BCMS must address
ISO 22301 requires organizations to identify interested parties (customers, regulators, partners, communities) and understand their continuity-related needs and expectations.
Question 115: Which ITIL 4 guiding principle states that improvements should be iterative rather than attempting one large change?
- Think and work holistically
- Keep it simple and practical
- Collaborate and promote visibility
- Progress iteratively with feedback (Correct answer)
Correct answer: Progress iteratively with feedback
'Progress iteratively with feedback' encourages small, manageable improvement cycles with continuous learning.
Question 116: Which stakeholder communication principle helps prevent 'alert fatigue' during prolonged incidents?
- Delegate all communications to the help desk
- Consolidate updates to scheduled intervals unless a significant change occurs (Correct answer)
- Send updates every 15 minutes regardless of changes
- Only communicate when the incident is resolved
Correct answer: Consolidate updates to scheduled intervals unless a significant change occurs
Scheduled, meaningful updates preserve stakeholder attention and avoid desensitization from excessive noise.
Question 117: Which participant is typically responsible for facilitating a post-incident review meeting to ensure it remains blameless and productive?
- The most senior engineer on-call during the incident
- A legal representative to assess liability
- The department head who oversees the affected service
- A neutral facilitator, often the incident manager or a designated SRE (Correct answer)
Correct answer: A neutral facilitator, often the incident manager or a designated SRE
A neutral facilitator—typically the incident manager or an SRE—guides the PIR discussion to keep it focused, blameless, and outcome-oriented.
Question 118: What does SLA stand for in the context of incident management?
- Severity Level Allocation
- System Logging Activity
- Service Level Agreement (Correct answer)
- Standard Latency Assessment
Correct answer: Service Level Agreement
A Service Level Agreement (SLA) is a formal contract between a service provider and customer that defines agreed targets for incident response and resolution times.
Question 119: Which metric BEST measures the effectiveness of incident stakeholder communications?
- Total word count of status messages
- Number of updates sent per incident
- Number of escalations received
- Stakeholder satisfaction scores and time-to-first-notification (Correct answer)
Correct answer: Stakeholder satisfaction scores and time-to-first-notification
Satisfaction scores and speed of first notification directly reflect whether communications met stakeholder expectations.
Question 120: Which of the following best describes 'cyber resilience' in the context of incident management and business continuity?
- The capacity to anticipate, withstand, recover from, and adapt to adverse cyber conditions (Correct answer)
- The practice of encrypting all organizational data at rest
- A compliance framework mandated by federal law for financial institutions
- The ability to prevent all cyberattacks through technical controls alone
Correct answer: The capacity to anticipate, withstand, recover from, and adapt to adverse cyber conditions
Cyber resilience integrates cybersecurity and business continuity principles, acknowledging that some incidents will succeed and focusing on minimizing impact and enabling rapid recovery.
Question 121: In ITIL 4, the 'Service Value System' (SVS) represents which key concept?
- The contractual obligations of service providers
- How all components work together to enable value creation (Correct answer)
- The pricing model for IT services
- The hierarchy of IT support tiers
Correct answer: How all components work together to enable value creation
The SVS describes how all components and activities in an organization work together to create value for customers and stakeholders.
Question 122: What is the primary purpose of a Post-Incident Review (PIR) following a major incident?
- To calculate financial penalties from SLA breaches
- To identify root causes and prevent recurrence (Correct answer)
- To assign blame to the team responsible for the outage
- To document the incident for regulatory compliance only
Correct answer: To identify root causes and prevent recurrence
The PIR focuses on identifying root causes, contributing factors, and improvement actions to prevent the incident from recurring.
Question 123: A stakeholder who was not notified during an incident later complains. The incident manager's BEST corrective action is to:
- Review and update the stakeholder communication plan to close the gap (Correct answer)
- Apologize and add them to future distribution lists
- Delegate future notification responsibilities to the help desk
- Send a retroactive incident notification immediately
Correct answer: Review and update the stakeholder communication plan to close the gap
Updating the communication plan ensures the gap is systemic ally resolved, not just acknowledged with an apology.
Question 124: What key input does incident management provide to the change management process?
- SLA performance summaries from the previous quarter
- Requests for Change (RFCs) to implement permanent fixes for recurring incident root causes (Correct answer)
- Customer satisfaction surveys from affected users
- A list of all currently unresolved incidents in the queue
Correct answer: Requests for Change (RFCs) to implement permanent fixes for recurring incident root causes
Incident management feeds into change management through Requests for Change (RFCs) raised to implement permanent fixes for recurring or major incidents identified through problem management.
Question 125: In the context of CIM certification, what is the most important consideration when implementing root cause analysis & problem management?
- Minimizing documentation to save time
- Delegating all responsibilities to junior staff
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
- Completing implementation as quickly as possible regardless of quality
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing root cause analysis & problem management, CIM professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 126: Why is it important to segment incident volume metrics by shift or time-of-day when analyzing them?
- To comply with labor regulations
- To calculate individual team member productivity
- To identify staffing gaps or peak demand periods that cause SLA breaches (Correct answer)
- To satisfy executive reporting requirements
Correct answer: To identify staffing gaps or peak demand periods that cause SLA breaches
Time-segmented incident volume analysis reveals when demand spikes occur so staffing and resource allocation can be adjusted to maintain SLA compliance.
Question 127: What does 'impact' mean when prioritizing an incident?
- The number of support tickets raised
- How quickly the incident needs to be resolved
- The effect of the incident on business operations or users (Correct answer)
- The technical complexity of the problem
Correct answer: The effect of the incident on business operations or users
Impact refers to the extent to which an incident affects business processes, users, or services, distinguishing it from urgency which measures resolution speed.
Question 128: During a tabletop exercise, participants discover their DR plan references a vendor hotline that no longer exists. What should be the immediate corrective action?
- Proceed with the exercise without correction since it is only a drill
- Escalate to senior management for disciplinary action
- Update the plan with current vendor contact information and reassign ownership for keeping it current (Correct answer)
- Declare the exercise a failure and reschedule
Correct answer: Update the plan with current vendor contact information and reassign ownership for keeping it current
Tabletop exercises are designed to surface exactly these gaps; the correct response is to document and remediate the discrepancy and assign ongoing ownership.
Question 129: What is the primary purpose of a Business Impact Analysis (BIA) in a business continuity program?
- To identify and prioritize critical business functions and quantify the impact of their disruption (Correct answer)
- To calculate the total cost of insurance premiums needed
- To create a detailed technical recovery procedure for IT systems
- To assign blame for past incidents and prevent recurrence
Correct answer: To identify and prioritize critical business functions and quantify the impact of their disruption
A BIA identifies critical business functions, estimates financial and operational impacts of disruption, and informs recovery priority and resource allocation.
Question 130: What action should a Certified Incident Manager take when an incident's SLA resolution deadline is approaching but not yet breached?
- Wait until after the breach to formally escalate
- Document the delay and continue with normal procedures
- Proactively escalate and increase resource allocation to resolve before breach (Correct answer)
- Close the incident to pause the SLA clock
Correct answer: Proactively escalate and increase resource allocation to resolve before breach
A proactive Incident Manager escalates and increases resources before an SLA breach occurs, since post-breach recovery carries greater business and contractual consequences.
Question 131: What is a critical aspect of an effective incident report?
- Confidentiality breaches
- Clear timeline of events and factual information (Correct answer)
- Vague and incomplete details
- Biased opinions
Correct answer: Clear timeline of events and factual information
An effective incident report serves as a factual record for analysis and future reference. A clear timeline ensures an accurate reconstruction of events, while factual information prevents misinterpretation and supports evidence-based decision-making. This objectivity is crucial for identifying root causes and developing effective preventative measures.
Question 132: In the context of stakeholder management, 'managing up' refers to:
- Escalating every decision to senior management
- Assigning incident tasks to junior team members
- Reporting metrics to the board during incidents
- Proactively keeping senior leaders informed so they can advocate and unblock resources (Correct answer)
Correct answer: Proactively keeping senior leaders informed so they can advocate and unblock resources
Managing up means keeping leadership informed and equipped to remove organizational obstacles without micromanaging the response.
Question 133: Which of the following best describes 'bi-directional integration' between a ticketing system and a SOAR platform?
- SOAR sends reports to the ticketing system daily
- Changes in either system—SOAR or the ticketing tool—are synchronized with the other in real time (Correct answer)
- Integration only functions during business hours
- The ticketing system only sends alerts to SOAR
Correct answer: Changes in either system—SOAR or the ticketing tool—are synchronized with the other in real time
Bi-directional integration ensures that status updates, comments, or field changes in either system are reflected in the other, keeping records consistent.
Question 134: Which scenario BEST illustrates the concept of 'residual risk'?
- A risk that has been fully eliminated through preventive controls
- The risk remaining after all mitigation measures have been applied (Correct answer)
- A risk that was transferred to an insurance provider
- A newly identified risk that has not yet been assessed
Correct answer: The risk remaining after all mitigation measures have been applied
Residual risk is the exposure that remains after controls and mitigations have been applied to the inherent risk.
Question 135: Under the NIST SP 800-34 framework, which phase immediately follows the BCP development phase?
- Plan maintenance
- Business Impact Analysis
- Plan testing, training, and exercises (Correct answer)
- Contingency planning policy statement
Correct answer: Plan testing, training, and exercises
NIST SP 800-34 sequences BCP phases as: policy → BIA → preventive controls → recovery strategies → plan development → testing/training/exercises → maintenance.
Question 136: When should an incident's priority be re-evaluated during its lifecycle?
- When new information reveals a greater or lesser business impact (Correct answer)
- Only after the incident is fully resolved
- Every hour regardless of current status
- Only at the start of each shift
Correct answer: When new information reveals a greater or lesser business impact
Incident priority should be re-evaluated whenever new information changes the understanding of its impact or urgency on the business.
Question 137: In a standard priority matrix, which combination results in the highest (P1/Critical) priority?
- Medium impact, Low urgency
- High impact, High urgency (Correct answer)
- Low impact, Low urgency
- Low impact, High urgency
Correct answer: High impact, High urgency
In a standard priority matrix, High impact combined with High urgency produces the highest (P1/Critical) priority designation.
Question 138: When a recently deployed change causes a service incident, what is the correct immediate response?
- Execute the back-out plan and collaborate with the Incident Manager to restore service (Correct answer)
- Document the incident and wait for the scheduled Post-Implementation Review
- Deny any relationship between the change and incident until evidence is formally confirmed
- Continue with the change since it is already deployed to production
Correct answer: Execute the back-out plan and collaborate with the Incident Manager to restore service
When a change causes an incident, teams must execute the pre-prepared back-out plan and work with the Incident Manager to restore service as quickly as possible.
Question 139: In a multi-cloud incident orchestration strategy, what challenge does 'tool fragmentation' introduce?
- Simplified access control management
- Reduced storage requirements across environments
- Faster alert resolution due to specialized tools
- Inconsistent data formats and siloed workflows that make unified automation and correlation difficult (Correct answer)
Correct answer: Inconsistent data formats and siloed workflows that make unified automation and correlation difficult
Different cloud providers and security tools often produce data in incompatible formats, making it hard to build unified automation that works seamlessly across all environments.
Question 140: In the context of post-incident reporting, what is 'detection bias' and why is it a concern?
- Over-relying on automated alerts and ignoring manual detection methods in the analysis
- The tendency to report more incidents than actually occurred
- Focusing the analysis only on events that were detectable, ignoring near-misses that weren't caught
- Preferring certain root cause categories over others during analysis (Correct answer)
Correct answer: Preferring certain root cause categories over others during analysis
Detection bias occurs when analysts unconsciously favor familiar root cause categories (e.g., human error) over others, skewing findings and corrective actions.
Question 141: What is the purpose of an Operational Level Agreement (OLA) in incident management?
- To document all change requests submitted by internal teams
- To define external vendor obligations to the organization
- To track individual technician performance metrics
- To set internal team targets that underpin and support SLA delivery (Correct answer)
Correct answer: To set internal team targets that underpin and support SLA delivery
An OLA defines the responsibilities and targets for internal teams so that they collectively meet the commitments made in customer-facing SLAs.
Question 142: A Severity 1 incident notification differs from a Severity 3 notification primarily in:
- The length of the message and level of technical detail
- The speed of notification, audience breadth, and escalation path (Correct answer)
- Whether external customers or only internal staff are informed
- The communication channel used (phone vs. email only)
Correct answer: The speed of notification, audience breadth, and escalation path
Higher severity incidents demand faster notifications, a wider and more senior audience, and a more formal escalation chain.
Question 143: Which of the following best describes a key competency required for metrics & kpi reporting in CIM practice?
- Reliance on a single methodology for all situations
- The ability to work independently without any oversight
- Memorization of all relevant regulations without understanding context
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CIM professionals working in metrics & kpi reporting need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 144: A P1 incident is affecting a VIP customer. The account manager demands real-time access to the incident bridge. What should the incident manager do?
- Assign a dedicated liaison to relay filtered updates to the account manager (Correct answer)
- Transfer incident ownership to the account manager
- Grant full bridge access to the account manager immediately
- Refuse access and direct all inquiries to the help desk
Correct answer: Assign a dedicated liaison to relay filtered updates to the account manager
A dedicated liaison keeps the bridge focused on resolution while ensuring the VIP stakeholder receives timely information.
Question 145: What is the significance of 'time-to-live' (TTL) values when automating threat intelligence indicator blocking in firewall rules?
- TTL controls how fast packets travel across the network
- TTL sets the alert threshold for the SIEM
- TTL determines the severity score of the indicator
- TTL ensures that auto-added block rules expire after a set period, preventing stale rules from permanently blocking legitimate traffic (Correct answer)
Correct answer: TTL ensures that auto-added block rules expire after a set period, preventing stale rules from permanently blocking legitimate traffic
Setting a TTL on automatically added firewall block rules ensures they are removed after a defined period, reducing the risk of obsolete rules blocking legitimate traffic indefinitely.
Question 146: When a CIM professional encounters an unfamiliar challenge in disaster recovery & business continuity, what is the recommended first course of action?
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
- Proceed based on personal intuition alone
- Apply the solution used for the most recent similar problem without adaptation
- Postpone addressing the issue indefinitely
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 147: Which of the following is a key risk of over-communicating during an incident?
- Stakeholders become more engaged and ask fewer questions
- Alert fatigue may cause recipients to ignore critical future notifications (Correct answer)
- It reduces the time available for technical resolution teams
- Regulatory bodies may impose fines for excessive reporting
Correct answer: Alert fatigue may cause recipients to ignore critical future notifications
Excessive low-value notifications desensitize recipients, increasing the risk that critical alerts are missed or ignored.
Question 148: A user calls the service desk reporting that a critical business application is completely unavailable. What is the service desk agent's FIRST action?
- Begin troubleshooting the application immediately
- Log the incident and assign a priority based on impact and urgency (Correct answer)
- Ask the user to restart their computer
- Transfer the call to the application support team
Correct answer: Log the incident and assign a priority based on impact and urgency
The first action is always to log and prioritize the incident based on its business impact and urgency before any other steps.
Question 149: What is 'functional escalation' in incident management?
- Increasing the SLA resolution target time
- Automatically closing low-priority incidents
- Transferring the incident to a team with greater technical expertise (Correct answer)
- Notifying the board of directors about all incidents
Correct answer: Transferring the incident to a team with greater technical expertise
Functional escalation transfers an incident to a support group with greater skill or authority to resolve a specific technical issue, distinct from hierarchical escalation to management.
Question 150: Which notification method is considered MOST reliable for reaching on-call staff during a critical P1 incident?
- SMS to personal mobile devices
- Slack or Teams direct message
- Phone call or automated voice alert with acknowledgment required (Correct answer)
- Email with read receipts enabled
Correct answer: Phone call or automated voice alert with acknowledgment required
Phone calls with required acknowledgment ensure the recipient is actually reached and has confirmed awareness, unlike passive channels like email or chat.
Question 151: A BCP calls for staff to work remotely during a facility outage, but employees lack company-issued laptops. What planning assumption failed?
- The personnel resource assumption regarding equipment availability (Correct answer)
- The vendor SLA assumption
- The insurance coverage assumption
- The communication plan assumption
Correct answer: The personnel resource assumption regarding equipment availability
BCPs must account for the actual equipment available to staff; assuming remote work capability without ensuring devices are issued is a personnel resource planning gap.
CREST Certified Incident Manager (CCIM)
The CREST Certified Incident Manager (CCIM) certifies professionals in managing cyber security incidents end-to-end, covering incident response planning, categorization, stakeholder communication, ITIL frameworks, and business continuity.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds