ISO 20000 Certification Configuration Management 5 — Questions and Answers
Question 1: A configuration audit reveals that 15% of CMDB records are inaccurate. What does this indicate about the configuration management process?
- The CMDB tool is malfunctioning
- Configuration management processes are not being consistently followed or enforced (Correct answer)
- Audits are being performed too frequently
- The CI scope is too narrow
Correct answer: Configuration management processes are not being consistently followed or enforced
A high inaccuracy rate indicates that processes for updating CMDB records — especially after changes — are not being reliably executed.
Question 2: Which ISO 20000 clause directly governs configuration management as a control activity?
- Clause 6 (Planning)
- Clause 8.2 (Asset management)
- Clause 8.3 (Configuration management) (Correct answer)
- Clause 9.1 (Monitoring, measurement, analysis, and evaluation)
Correct answer: Clause 8.3 (Configuration management)
ISO 20000-1:2018 Clause 8.3 specifically covers configuration management requirements for service providers.
Question 3: What is the significance of maintaining configuration item version history in the CMDB?
- It allows financial auditors to calculate depreciation
- It supports rollback decisions and root cause analysis by showing what changed over time (Correct answer)
- It is required only for hardware CIs
- It replaces the need for change records
Correct answer: It supports rollback decisions and root cause analysis by showing what changed over time
Version history allows teams to trace changes, compare states, and support rollback or root cause investigations effectively.
Question 4: In ISO 20000 configuration management, what does 'configuration control' primarily govern?
- Access rights to the CMDB tool
- The process for approving and recording changes to CIs (Correct answer)
- The frequency of CI discovery scans
- The backup schedule for the CMDB
Correct answer: The process for approving and recording changes to CIs
Configuration control ensures that changes to CIs are authorized, documented, and reflected in the CMDB through formal processes.
Question 5: How should a service provider treat CI data confidentiality in the CMDB under ISO 20000?
- All CMDB data must be publicly accessible for transparency
- Access to CI data should be controlled based on roles and sensitivity of the information (Correct answer)
- Only external auditors need access restrictions
- Confidentiality is not addressed by ISO 20000 for configuration data
Correct answer: Access to CI data should be controlled based on roles and sensitivity of the information
CI data may be sensitive; role-based access controls protect against unauthorized viewing or modification of configuration records.
Question 6: What is the best practice for integrating automated discovery tools with configuration management under ISO 20000?
- Replace the CMDB entirely with discovery tool output
- Use discovery tool data to validate and supplement CMDB records, with human review for discrepancies (Correct answer)
- Only use manual processes to avoid automation errors
- Automated discovery eliminates the need for configuration audits
Correct answer: Use discovery tool data to validate and supplement CMDB records, with human review for discrepancies
Automated discovery provides ongoing CI data that should be reconciled with CMDB records, with human oversight for anomalies and discrepancies.
Question 7: Which of the following best demonstrates continuous improvement in configuration management as required by ISO 20000?
- Keeping the same configuration management plan unchanged for five years
- Reviewing audit findings, measuring CMDB accuracy trends, and updating processes to reduce errors (Correct answer)
- Increasing the number of CIs tracked without reviewing process effectiveness
- Outsourcing all configuration management responsibilities to a supplier
Correct answer: Reviewing audit findings, measuring CMDB accuracy trends, and updating processes to reduce errors
Continuous improvement in configuration management involves measuring accuracy, analyzing audit results, and refining processes to address identified weaknesses.
A configuration audit reveals that 15% of CMDB records are inaccurate.
What does this indicate about the configuration management process?