ISO/IEC 20000 Foundation Certification — Questions and Answers
Question 1: Which of the following best describes the scope of 'control and support processes' in ISO 20000-1:2018?
- Processes that only apply to infrastructure teams
- Processes that replace the service desk function entirely
- Processes that govern, track, and support delivery of services including change, configuration, release, and problem management (Correct answer)
- Processes limited to financial budgeting and cost management
Correct answer: Processes that govern, track, and support delivery of services including change, configuration, release, and problem management
Control and support processes in ISO 20000 encompass the mechanisms that govern service changes, maintain configuration data, manage releases, and resolve problems.
Question 2: An ISO 20000-compliant organization is transitioning a cloud-hosted service. Which of the following must be confirmed with the cloud supplier before go-live?
- The supplier's office location and headcount
- The supplier's ability to meet agreed service levels, security, and continuity requirements (Correct answer)
- The supplier's annual revenue figures
- Whether the supplier uses agile or waterfall development methods
Correct answer: The supplier's ability to meet agreed service levels, security, and continuity requirements
ISO 20000 requires that supplier capabilities are validated against agreed service levels, security, and continuity requirements before a service goes live.
Question 3: A company's monitoring data shows that it is consistently meeting its SLA target for incident resolution time. However, customer feedback indicates growing frustration with how incidents are handled. In the context of performance evaluation under ISO 20000, what is the most appropriate action?
- Dismiss the customer feedback as subjective since the objective SLA data proves the service is performing well.
- Analyze trends in both the quantitative SLA data and the qualitative customer feedback to identify the root cause of the dissatisfaction. (Correct answer)
- Immediately propose a less strict SLA target to the customer to better align with their perceived experience.
- Conclude that the monitoring tools are faulty and must be replaced immediately.
Correct answer: Analyze trends in both the quantitative SLA data and the qualitative customer feedback to identify the root cause of the dissatisfaction.
ISO 20000-1, clause 9.1, requires the analysis and evaluation of performance and effectiveness, which includes trends in customer satisfaction and feedback. Simply meeting a metric is not enough; the organization must evaluate all relevant data, including customer perception, to identify opportunities for improvement and ensure the SMS is effective.
Question 4: What should a service provider do when a supplier consistently fails to meet agreed performance targets?
- Ignore it if the customer is not yet impacted
- Immediately terminate the supplier contract without review
- Reroute all supplier work to internal teams without documentation
- Review the supplier's performance and take corrective action as per the supplier management process (Correct answer)
Correct answer: Review the supplier's performance and take corrective action as per the supplier management process
The supplier management process requires the service provider to monitor supplier performance and initiate corrective actions when targets are not met.
Question 5: An organization has completed a corrective action to address a nonconformity found during an internal audit. What must it do next according to ISO 20000?
- Update the service catalog to reflect the change
- Archive the nonconformity report without further review
- Schedule an external audit to validate the correction
- Review the effectiveness of the corrective action taken (Correct answer)
Correct answer: Review the effectiveness of the corrective action taken
ISO/IEC 20000-1 clause 10.1 requires that after implementing a corrective action, the organization reviews its effectiveness. Simply completing the action is insufficient — the standard mandates a follow-up to confirm the nonconformity has been resolved and will not recur.
Question 6: Which of the following BEST describes the role of benchmarking in CSI?
- It identifies staff training needs
- It is only used during initial certification
- It replaces internal audits
- It provides an external reference point for evaluating performance (Correct answer)
Correct answer: It provides an external reference point for evaluating performance
Benchmarking compares an organization's performance against external standards or peers to identify improvement gaps.
Question 7: Which of the following scenarios best illustrates a breakdown in business relationship management under ISO 20000?
- A complaint is logged and resolved within agreed timeframes
- A service review meeting identifies a minor SLA breach that is immediately corrected
- A new service is added to the catalog after customer consultation
- Customer service expectations change but are never formally communicated or documented with the provider (Correct answer)
Correct answer: Customer service expectations change but are never formally communicated or documented with the provider
Business relationship management requires that changes in customer expectations are formally captured and documented; failure to do so represents a process breakdown.
Question 8: Which tool is commonly used in CSI to visually identify the root cause of a recurring problem?
- RACI matrix
- Gantt chart
- Network topology map
- Fishbone (Ishikawa) diagram (Correct answer)
Correct answer: Fishbone (Ishikawa) diagram
A fishbone diagram maps cause-and-effect relationships to trace recurring problems back to their root causes.
Question 9: A change to a critical database is being planned. ISO 20000 requires that this change be tested. In which environment should testing occur BEFORE deployment to production?
- Any available spare server
- The development workstation of the requester
- The production environment during off-peak hours
- A test or non-production environment that mirrors production (Correct answer)
Correct answer: A test or non-production environment that mirrors production
ISO 20000 requires testing in a controlled, non-production environment that represents production conditions to minimize risk.
Question 10: What BEST describes the distinction between service metrics and technological metrics?
- Service metrics include critical success factors and Key Perfomance Indicators;Technology metrics include availabity and capacity
- Service metrics measure maturity and csost;Technology metrics measure efficiency and effectiveness
- Service metrics measure the end service;Technology metrics measure individual components (Correct answer)
- Service metrics measure each of the service management process;Technology metrics measure the infrastructure
Correct answer: Service metrics measure the end service;Technology metrics measure individual components
Service metrics measure the overall performance and quality of the IT service as experienced by the customer or user, focusing on end-to-end delivery (e.g., service availability, response times). In contrast, Technology metrics measure the performance of individual infrastructure components or Configuration Items (CIs) that underpin the service (e.g., CPU utilization of a server, network latency). This distinction helps in understanding both the holistic service delivery and the health of its underlying parts.
Question 11: Which of the following BEST describes a 'pilot deployment' in the context of ISO 20000 service transition?
- Deploying to all users simultaneously to test at scale
- A limited rollout to a subset of users to validate the service before full release (Correct answer)
- A rollback of a failed deployment to a previous version
- An emergency release bypassing normal change management
Correct answer: A limited rollout to a subset of users to validate the service before full release
A pilot deployment releases the service to a controlled user group to identify issues before organization-wide rollout.
Question 12: What is the meaning of 'shift-left' in the context of ITIL 4 service management?
- Transferring more support capabilities to users and lower support tiers (Correct answer)
- Moving services to cloud infrastructure
- Prioritizing incidents based on urgency
- Reducing the number of service desk agents
Correct answer: Transferring more support capabilities to users and lower support tiers
Shift-left means moving knowledge and resolution capability closer to the user, enabling self-service and first-contact resolution at lower support levels.
Question 13: In ISO 20000, which process ensures that the services delivered match the expectations agreed upon with the customer?
- Availability management
- Information security management
- Capacity management
- Service level management (Correct answer)
Correct answer: Service level management
Service level management ensures that agreed service levels are documented in SLAs and that actual service delivery meets those targets.
Question 14: An ISO 20000 auditor reviews corrective action records and finds that root causes were identified but the effectiveness of corrective actions was never verified. Which requirement is not being met?
- Clause 9.3 — Management review
- Clause 10.1 — Nonconformity and corrective action (Correct answer)
- Clause 8.7 — Problem management
- Clause 7.4 — Communication
Correct answer: Clause 10.1 — Nonconformity and corrective action
Clause 10.1 requires the organization to review the effectiveness of corrective actions taken, not merely implement them.
Question 15: In ISO 20000, when should a service provider invoke its service continuity plan?
- At the start of every fiscal quarter as a precaution
- When a disruption occurs that cannot be resolved through normal incident management within acceptable timeframes (Correct answer)
- Only when directed by the customer
- Whenever an incident is logged
Correct answer: When a disruption occurs that cannot be resolved through normal incident management within acceptable timeframes
Continuity plans are invoked when a disruption exceeds what normal incident management can handle within agreed recovery time objectives.
Question 16: An organization implementing ISO 20000 must ensure that emergency changes are handled how?
- By routing them through the standard change pre-authorization list
- By deferring them until the next scheduled CAB meeting
- By skipping all documentation to restore service immediately
- By following an expedited but documented process with retrospective review (Correct answer)
Correct answer: By following an expedited but documented process with retrospective review
Emergency changes use an expedited authorization path but must still be documented, and a post-implementation review is conducted after the change.
Question 17: An emergency change is deployed, but the post-implementation review reveals the change caused a service outage. What is the FIRST action according to ISO 20000 change management?
- Update the change schedule
- Close the change record immediately
- Notify the CAB of the failure
- Initiate a rollback and raise an incident (Correct answer)
Correct answer: Initiate a rollback and raise an incident
ISO 20000 requires restoring service as soon as possible, so initiating rollback and raising an incident is the correct first action.
Question 18: What does an ISO 20000 Auditor look at while designing IT services?
- The organizational structure of IT department.
- The compatibility and feasibility of proposed IT services. (Correct answer)
- The efficiency of deployed IT hardware.
- The budget allocated to IT services.
Correct answer: The compatibility and feasibility of proposed IT services.
When auditing the design phase of IT services, an ISO 20000 auditor assesses whether the proposed services are compatible with existing infrastructure and processes. They also evaluate the technical and operational feasibility of these services. This ensures that new or changed services can be effectively delivered and integrated without negatively impacting current operations or overall service quality.
Question 19: In ISO 20000, the problem management process aims to do which of the following as a long-term goal?
- Restore service as quickly as possible after each outage
- Escalate unresolved incidents to third-party vendors
- Log every user complaint into the service desk system
- Eliminate recurring incidents by identifying and resolving their root causes (Correct answer)
Correct answer: Eliminate recurring incidents by identifying and resolving their root causes
Problem management focuses on root cause analysis and elimination to prevent future incidents, making it a proactive and long-term process.
Question 20: Which of the following is an input to the continual improvement process under ISO 20000?
- Change advisory board minutes only
- Results of service reviews and audits (Correct answer)
- Completed service requests
- Customer invoices
Correct answer: Results of service reviews and audits
Service review and audit results are key inputs that identify gaps and drive the continual improvement process.
Question 21: What is the purpose of a service design package (SDP) in ISO 20000?
- To list all approved changes to existing services
- To record all incidents raised during the service lifecycle
- To provide a comprehensive set of documentation defining all aspects of a service and its requirements (Correct answer)
- To outline the financial budget for service operations
Correct answer: To provide a comprehensive set of documentation defining all aspects of a service and its requirements
A service design package collects all the information needed to build, test, deploy, and operate a service, ensuring that every aspect is documented and agreed before transition begins.
Question 22: In ISO 20000, service validation and testing is conducted primarily to achieve which outcome?
- Document the total cost of ownership of the service
- Assign ownership of the service to the operations team
- Update the service portfolio with the new service entry
- Confirm that the new or changed service meets agreed service requirements before release (Correct answer)
Correct answer: Confirm that the new or changed service meets agreed service requirements before release
Service validation and testing ensures that a new or changed service will deliver the value and outcomes required, and that it meets its agreed requirements, reducing the risk of failures after the service enters live operation.
Question 23: What is the purpose of a KPI metric?
- All of these (Correct answer)
- It is used to help mange a process
- It is used to help manage a Plan
- It is used to help manage an IT service
Correct answer: All of these
Key Performance Indicators (KPIs) are crucial metrics used to evaluate the success of an organization, a particular activity, or an individual. They are instrumental in managing IT services by tracking their performance against agreed targets, managing processes by monitoring their efficiency and effectiveness, and managing plans by assessing progress towards strategic objectives. Therefore, KPIs serve as vital tools across various levels of management.
Question 24: An ISO 20000 service design team is creating a continuity plan for a new service. Which aspect must be addressed during design, not after go-live?
- The exact wording of incident tickets
- Staff holiday schedules during the first month of operation
- The budget for the first year of service operation
- Recovery time objectives and recovery point objectives for the service (Correct answer)
Correct answer: Recovery time objectives and recovery point objectives for the service
Recovery time objectives (RTO) and recovery point objectives (RPO) are continuity requirements that must be designed into the service from the outset.
Question 25: In ISO 20000, which of the following best describes the relationship between change management and service transition?
- All changes introduced during transition must be assessed and authorized through the change management process (Correct answer)
- Service transition operates independently of change management to avoid delays
- Change management replaces the need for service validation and testing during transition
- Change management is only invoked after a service has completed transition
Correct answer: All changes introduced during transition must be assessed and authorized through the change management process
ISO 20000 requires that all changes, including those made during service transition, are subject to the change management process. This ensures that risks are assessed and that changes are authorized before being implemented.
Question 26: Which metric would be MOST useful for evaluating continual improvement of service delivery under ISO 20000?
- Amount spent on IT infrastructure upgrades
- Total number of configuration items in the CMDB
- Trend analysis of service level achievement over multiple reporting periods (Correct answer)
- Number of employees trained on ITIL this year
Correct answer: Trend analysis of service level achievement over multiple reporting periods
Trend analysis of service level achievement over time directly measures whether service delivery is continually improving against agreed targets.
Question 27: Which of the following best describes 'proactive problem management' in ISO 20000?
- Restoring services after a major outage as fast as possible
- Escalating all unresolved incidents to the vendor
- Identifying and resolving potential issues before they cause incidents (Correct answer)
- Logging every incident as a problem to ensure tracking
Correct answer: Identifying and resolving potential issues before they cause incidents
Proactive problem management analyzes trends and weaknesses to prevent incidents from occurring, rather than reacting after service disruption.
Question 28: What is a key output of the service design process that feeds into transition planning?
- A list of all open incidents sorted by priority
- The annual financial budget for IT operations
- A service design package containing the design specifications and implementation plan (Correct answer)
- A roster of on-call support staff
Correct answer: A service design package containing the design specifications and implementation plan
The service design package consolidates all design information needed for effective transition planning and execution.
Question 29: Under ISO 20000-1, who is accountable for ensuring the configuration management database (CMDB) remains accurate?
- Each individual service desk analyst
- The process owner of configuration management (Correct answer)
- The change advisory board (CAB)
- The service catalog manager
Correct answer: The process owner of configuration management
The configuration management process owner is accountable for the accuracy and integrity of CMDB data.
Question 30: How does ISO 20000-1 address the relationship with other parties involved in service delivery?
- It prohibits the use of external suppliers
- It exempts outsourced services from SMS requirements
- It requires that organizations control and manage services operated by other parties within the SMS scope (Correct answer)
- It only applies to services delivered entirely in-house
Correct answer: It requires that organizations control and manage services operated by other parties within the SMS scope
The standard requires organizations to retain accountability and apply SMS controls to services delivered by other parties, including suppliers and partners.
Question 31: During a review of service performance, a service manager notes a consistent failure to meet a specific Service Level Target (SLT). According to ISO/IEC 20000-1 Clause 10.1 (Nonconformity and corrective action), what is the most appropriate first step?
- Wait for the next internal audit to formally document the issue.
- Immediately renegotiate the SLT with the customer to make it easier to achieve.
- React to the nonconformity by taking action to control and correct it. (Correct answer)
- Assign blame to the team responsible for the service component.
Correct answer: React to the nonconformity by taking action to control and correct it.
ISO/IEC 20000-1 Clause 10.1 states that when a nonconformity occurs, the organization shall react to it and, as applicable, take action to control and correct it, and deal with the consequences. This immediate reaction is the first step before proceeding to evaluate the need for action to eliminate the cause (root cause analysis). Renegotiating the SLT without investigation, waiting for an audit, or assigning blame are not the correct initial actions.
Question 32: In ISO 20000, which document formally records the outcomes of a service review?
- Configuration management database
- Service review record (Correct answer)
- Risk register
- Service level agreement
Correct answer: Service review record
ISO 20000 requires that outcomes of service reviews be documented in a service review record.
Question 33: In ISO 20000, which process is responsible for ensuring that new or changed services are tested before being deployed to the live environment?
- Problem management
- Release and deployment management (Correct answer)
- Service level management
- Availability management
Correct answer: Release and deployment management
Release and deployment management includes testing requirements to verify that new or changed services meet defined criteria before entering the live environment.
Question 34: Which of the following is NOT typically an output of the continual improvement process?
- Updated service improvement plans
- Revised policies and procedures
- New customer contracts (Correct answer)
- Lessons learned documentation
Correct answer: New customer contracts
Customer contracts are a commercial output, not a direct output of the continual improvement process.
Question 35: An ISO 20000 surveillance audit reveals that an organization has changed its incident classification scheme without updating the incident management procedure. Which clause is most directly relevant?
- Clause 8.6 — Incident management
- Clause 6.1 — Actions to address risks and opportunities
- Clause 7.5 — Documented information (Correct answer)
- Clause 9.1 — Monitoring, measurement, analysis and evaluation
Correct answer: Clause 7.5 — Documented information
Documented information (Clause 7.5) must be controlled and kept up to date; a procedure that no longer reflects the actual process is a documented-information nonconformity.
Question 36: A company has successfully implemented an SMS and achieved ISO 20000 certification. To maintain this certification, the company must demonstrate a commitment to continual improvement. Which of the following activities BEST demonstrates this principle?
- Keeping all service management processes and documentation unchanged after the initial audit.
- Maintaining the same service level targets year after year.
- Conducting a management review of the SMS only when a major nonconformity is found.
- Analyzing trends in service performance and identifying opportunities for enhancement. (Correct answer)
Correct answer: Analyzing trends in service performance and identifying opportunities for enhancement.
Continual improvement is a core principle of ISO 20000, driven by the PDCA cycle. Analyzing trends, reviewing performance, and proactively identifying opportunities for improvement are key activities that demonstrate an ongoing commitment to enhancing the SMS and service delivery. The other options suggest a static or reactive approach, which is contrary to the principle of continual improvement.
Question 37: Which ISO 20000 process is responsible for defining the capacity requirements needed to support a new service before it is deployed?
- Change management
- Incident management
- Problem management
- Capacity management (Correct answer)
Correct answer: Capacity management
Capacity management ensures that the infrastructure and resources required to support a new service are identified and provisioned during service design, before the service goes live.
Question 38: An organization is defining the scope of its Service Management System (SMS) for ISO 20000 certification. According to the standard, which of the following must be considered during this activity?
- The specific software development methodology used by the engineering team.
- The personal preferences of the IT support staff.
- The marketing strategy for the services offered.
- The internal and external issues relevant to its purpose and the requirements of interested parties. (Correct answer)
Correct answer: The internal and external issues relevant to its purpose and the requirements of interested parties.
Clause 4, 'Context of the organization,' in ISO 20000-1 requires the organization to determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcomes of its SMS. It also requires understanding the needs and expectations of interested parties (stakeholders).
Question 39: Which of the following is not accurate regarding continuous service improvement?
- Continual Service Improvement begins after service goes into Service operation (Correct answer)
- Continual Service Improvement should be applied to all aspects of a service
- Continual Service Improvement will rely on the quality of metrics and KPIs measured
- Continual Service Improvement should be part of everyone's responsibilities
Correct answer: Continual Service Improvement begins after service goes into Service operation
This statement is inaccurate because Continual Service Improvement (CSI) is an overarching lifecycle stage that applies to *all* stages of the service lifecycle, not just after a service enters operation. Improvement opportunities should be identified and acted upon during Service Strategy, Design, Transition, and Operation. Waiting until operation would miss crucial opportunities for improvement in earlier, foundational stages of service development and deployment.
Question 40: A customer escalates a complaint after being dissatisfied with the initial resolution. According to ISO 20000, what should the complaint management process ensure?
- Escalated complaints bypass the normal process for speed
- There is a defined escalation path and the customer is kept informed throughout (Correct answer)
- Only senior management can handle escalated complaints
- The escalated complaint is closed automatically after 5 business days
Correct answer: There is a defined escalation path and the customer is kept informed throughout
ISO 20000 requires a defined escalation path for unresolved complaints and ongoing communication with the customer throughout the escalation process.
ISO/IEC 20000 Foundation Certification
The ISO/IEC 20000 Foundation certification validates an individual's understanding of the fundamental concepts and principles of IT Service Management (ITSM) based on the ISO/IEC 20000 standard.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds