ISO 20000 Certification Control and Support Processes 3 — Questions and Answers
Question 1: In ISO 20000, which metric is most directly used to evaluate the effectiveness of problem management?
- Average time to resolve incidents
- Reduction in the number of recurring incidents over time (Correct answer)
- Number of changes approved by the CAB
- Total configuration items recorded in the CMDB
Correct answer: Reduction in the number of recurring incidents over time
A reduction in recurring incidents demonstrates that problem management is successfully identifying and eliminating root causes.
Question 2: An organization implementing ISO 20000 must ensure that emergency changes are handled how?
- By skipping all documentation to restore service immediately
- By following an expedited but documented process with retrospective review (Correct answer)
- By routing them through the standard change pre-authorization list
- By deferring them until the next scheduled CAB meeting
Correct answer: By following an expedited but documented process with retrospective review
Emergency changes use an expedited authorization path but must still be documented, and a post-implementation review is conducted after the change.
Question 3: Which of the following best describes the scope of 'control and support processes' in ISO 20000-1:2018?
- Processes limited to financial budgeting and cost management
- Processes that govern, track, and support delivery of services including change, configuration, release, and problem management (Correct answer)
- Processes that only apply to infrastructure teams
- Processes that replace the service desk function entirely
Correct answer: Processes that govern, track, and support delivery of services including change, configuration, release, and problem management
Control and support processes in ISO 20000 encompass the mechanisms that govern service changes, maintain configuration data, manage releases, and resolve problems.
Question 4: What is the primary purpose of a post-implementation review (PIR) in change management under ISO 20000?
- To punish staff responsible for failed changes
- To verify that the change achieved its objectives and identify lessons learned (Correct answer)
- To create a new problem record for every change
- To update the service catalog with new pricing
Correct answer: To verify that the change achieved its objectives and identify lessons learned
A PIR assesses whether the change met its goals and captures lessons learned to improve the change process and future changes.
Question 5: Under ISO 20000-1, a definitive media library (DML) is associated with which process?
- Problem management
- Service level management
- Release and deployment management / configuration management (Correct answer)
- Availability management
Correct answer: Release and deployment management / configuration management
The DML, which stores authorized and controlled copies of software, is managed under release and deployment management in coordination with configuration management.
Question 6: Which statement about the relationship between incident management and problem management in ISO 20000 is correct?
- They are the same process with different names
- Incident management restores service; problem management investigates underlying causes (Correct answer)
- Problem management replaces incident management for complex failures
- Incident management identifies root causes while problem management logs tickets
Correct answer: Incident management restores service; problem management investigates underlying causes
Incident management focuses on restoring service quickly, while problem management investigates and removes the root cause to prevent recurrence.
Question 7: ISO 20000-1 requires that changes are assessed for which of the following before authorization?
- Marketing impact and brand perception
- Risk, impact, and resource requirements (Correct answer)
- User satisfaction scores
- Number of service requests received
Correct answer: Risk, impact, and resource requirements
Before authorizing a change, ISO 20000 requires an assessment of its risk, potential impact on services, and the resources needed to implement it.
In ISO 20000, which metric is most directly used to evaluate the effectiveness of problem management?