CIM Service Desk & Escalation Processes 5 — Questions and Answers
Question 1: In ITIL-aligned incident management, what is the service desk's role during a major incident?
- Take full ownership of the technical resolution
- Act as the single point of contact for user communication while the major incident team handles resolution (Correct answer)
- Suspend all other incident work until the major incident is resolved
- Immediately delegate all communication to the problem management team
Correct answer: Act as the single point of contact for user communication while the major incident team handles resolution
During a major incident, the service desk maintains user communication and updates while a dedicated major incident team focuses on technical resolution.
Question 2: Which type of escalation should be triggered when an incident is likely to cause reputational damage to the organization?
- Functional escalation to the PR team only
- Hierarchical escalation involving senior management and possibly communications teams (Correct answer)
- Technical escalation to infrastructure engineers
- Automatic escalation via the ticketing system
Correct answer: Hierarchical escalation involving senior management and possibly communications teams
Reputational risk requires senior management awareness and may involve communications or legal teams, making hierarchical escalation appropriate.
Question 3: What is the recommended approach when a Tier 2 specialist cannot resolve an incident and needs to return it to the service desk?
- Close the original ticket and ask the user to re-log the issue
- Update the ticket with findings, revert ownership to service desk, and brief them on next steps (Correct answer)
- Archive the ticket as 'unresolvable'
- Transfer it directly to the user without service desk involvement
Correct answer: Update the ticket with findings, revert ownership to service desk, and brief them on next steps
Returning a ticket to the service desk requires full documentation of findings and a briefing so the service desk can manage the user relationship and next escalation path.
Question 4: How should the service desk handle duplicate incident tickets submitted by the same user through multiple channels (phone, email, chat)?
- Keep all tickets open to ensure nothing is missed
- Identify the duplicate tickets, merge them into one, and communicate the consolidated ticket ID to the user (Correct answer)
- Close the newer tickets and work only the oldest one silently
- Assign each ticket to a different agent to speed up resolution
Correct answer: Identify the duplicate tickets, merge them into one, and communicate the consolidated ticket ID to the user
Merging duplicates into a single ticket prevents fragmented effort and keeps the user informed with one reference point.
Question 5: What does 'time to escalate' (TTE) measure and why is it important?
- How long Tier 2 takes to respond after receiving an escalation
- The elapsed time between incident detection and the decision to escalate, used to identify delays in Tier 1 triage (Correct answer)
- The total time an incident spends across all tiers
- The SLA target for Tier 2 resolution
Correct answer: The elapsed time between incident detection and the decision to escalate, used to identify delays in Tier 1 triage
TTE identifies whether Tier 1 agents are holding incidents too long before escalating, which can cause SLA breaches downstream.
Question 6: A service desk receives an incident about a security breach in progress. What should the escalation process prioritize?
- Normal priority queue based on submission time
- Immediate escalation to the security incident response team, bypassing standard triage steps (Correct answer)
- Logging and scheduling for next-day review
- Functional escalation to the network team only
Correct answer: Immediate escalation to the security incident response team, bypassing standard triage steps
Active security breaches require immediate escalation to the security incident response team, overriding normal prioritization procedures.
Question 7: Which practice BEST reduces repeat escalations for the same category of incidents?
- Increasing Tier 2 headcount permanently
- Conducting root cause analysis and updating Tier 1 knowledge base with documented solutions (Correct answer)
- Lowering the SLA targets to allow more resolution time
- Restricting users from logging incidents directly
Correct answer: Conducting root cause analysis and updating Tier 1 knowledge base with documented solutions
Root cause analysis followed by knowledge base updates enables Tier 1 to resolve recurring incident types without repeated escalation.
In ITIL-aligned incident management, what is the service desk's role during a major incident?