CIM SLA & OLA Management in Incident Response 1 — Questions and Answers
Question 1: What does SLA stand for in the context of incident management?
- Service Level Agreement (Correct answer)
- System Lifecycle Assessment
- Security Licensing Arrangement
- Service Logging Audit
Correct answer: Service Level Agreement
SLA stands for Service Level Agreement, which is a formal contract between a service provider and a customer defining expected service levels and response commitments.
Question 2: Which SLA metric specifically measures the time elapsed from when an incident is reported to when work on its resolution begins?
- Resolution Time
- Response Time (Correct answer)
- Restore Time
- Recovery Point Objective
Correct answer: Response Time
Response Time measures the elapsed time from incident report to when the support team begins actively working on the incident.
Question 3: An SLA defines a P1 incident must be resolved within 4 hours. The incident was logged at 9:00 AM and resolved at 1:30 PM. What is the status of this SLA?
- SLA met — resolved within the 4-hour window
- SLA breached — resolved 30 minutes late (Correct answer)
- SLA paused — requires manual review
- SLA not applicable — P1 incidents are exempt
Correct answer: SLA breached — resolved 30 minutes late
The incident took 4.5 hours to resolve, which exceeds the 4-hour SLA target by 30 minutes, constituting an SLA breach.
Question 4: Which of the following best describes the purpose of an SLA clock pause (also called 'stop the clock')?
- To permanently exclude incidents from SLA reporting
- To suspend SLA timing when the delay is caused by the customer or a third party outside the provider's control (Correct answer)
- To reset the SLA timer after each escalation
- To automatically escalate incidents that are nearing breach
Correct answer: To suspend SLA timing when the delay is caused by the customer or a third party outside the provider's control
SLA clock pauses suspend timing when the resolution is delayed due to factors outside the provider's control, such as waiting for customer-provided information.
Question 5: In ITIL-aligned incident management, how are SLA targets typically differentiated?
- By the name of the assigned technician
- By incident priority level, which reflects impact and urgency (Correct answer)
- By the geographic location of the customer
- By the time of day the incident is reported
Correct answer: By incident priority level, which reflects impact and urgency
SLA targets are typically differentiated by incident priority (P1–P4), which is determined by combining the incident's impact on the business and its urgency.
Question 6: What is the primary difference between an SLA and an OLA?
- An SLA is internal; an OLA is external
- An SLA is between provider and customer; an OLA is between internal support teams (Correct answer)
- An SLA covers security incidents; an OLA covers service requests
- An SLA is legally binding; an OLA is informal and optional
Correct answer: An SLA is between provider and customer; an OLA is between internal support teams
An SLA is a formal agreement with the customer, while an OLA (Operational Level Agreement) is an internal agreement between support groups that underpins the SLA commitments.
Question 7: Which tool is most commonly used by incident managers to monitor real-time SLA compliance across open incidents?
- A post-incident review template
- An SLA dashboard or live queue view within the ITSM tool (Correct answer)
- A manual spreadsheet updated daily
- A configuration management database (CMDB)
Correct answer: An SLA dashboard or live queue view within the ITSM tool
An SLA dashboard within the ITSM tool provides real-time visibility into open incidents, their remaining SLA time, and breach risk, enabling proactive management.
What does SLA stand for in the context of incident management?