ISO 20000 Certification Incident Management 1 — Questions and Answers
Question 1: According to ISO 20000-1, what is the primary objective of incident management?
- To prevent incidents from occurring in the IT environment
- To restore normal service operation as quickly as possible and minimize business impact (Correct answer)
- To identify the root cause of all service disruptions
- To document all incidents in the configuration management database
Correct answer: To restore normal service operation as quickly as possible and minimize business impact
ISO 20000-1 defines the primary objective of incident management as restoring normal service operation as quickly as possible and minimizing adverse impact on business operations.
Question 2: How does ISO 20000-1 distinguish between an incident and a service request?
- Incidents are reported by users while service requests are submitted by management
- An incident is an unplanned interruption or reduction in quality of a service, while a service request is a formal request for a standard change or information (Correct answer)
- Incidents always require escalation while service requests can be resolved at the first level
- Incidents are hardware-related and service requests are software-related
Correct answer: An incident is an unplanned interruption or reduction in quality of a service, while a service request is a formal request for a standard change or information
ISO 20000-1 clearly distinguishes incidents as unplanned interruptions or reductions in service quality, whereas service requests are formal user demands for standard services or information.
Question 3: Which of the following is a required activity in the ISO 20000-1 incident management process?
- Performing a root cause analysis for every incident
- Recording and classifying all incidents (Correct answer)
- Escalating all incidents to the problem management team
- Publishing incident reports to all customers
Correct answer: Recording and classifying all incidents
ISO 20000-1 requires that all incidents be recorded and classified as part of the incident management process to ensure proper tracking and prioritization.
Question 4: What does ISO 20000-1 require regarding incident prioritization?
- All incidents must be prioritized based solely on the time they were reported
- Incidents must be prioritized based on their impact and urgency to determine appropriate response times (Correct answer)
- Only major incidents require prioritization; minor incidents can be handled in any order
- Prioritization is optional and left to the discretion of the service desk
Correct answer: Incidents must be prioritized based on their impact and urgency to determine appropriate response times
ISO 20000-1 requires that incidents be prioritized based on their impact on the business and urgency, which together determine the appropriate response and resolution times.
Question 5: Under ISO 20000-1, what defines a major incident?
- Any incident that takes more than one hour to resolve
- An incident that affects more than ten users simultaneously
- An incident with a significant impact on the business that requires a separate procedure (Correct answer)
- An incident that cannot be resolved by the first-line support team
Correct answer: An incident with a significant impact on the business that requires a separate procedure
ISO 20000-1 defines a major incident as one that has a significant impact on the business and requires a separate, expedited management procedure to minimize disruption.
Question 6: According to ISO 20000-1, which team or role is typically responsible for coordinating the resolution of major incidents?
- The configuration manager
- The change advisory board
- A dedicated major incident manager or team (Correct answer)
- The IT steering committee
Correct answer: A dedicated major incident manager or team
ISO 20000-1 recommends that major incidents be coordinated by a dedicated major incident manager or team to ensure swift and organized resolution.
Question 7: What is the relationship between incident management and problem management in ISO 20000-1?
- They are the same process with different names
- Incident management focuses on immediate restoration while problem management investigates root causes (Correct answer)
- Problem management triggers incident management when a known error is detected
- Incident management is a sub-process of problem management
Correct answer: Incident management focuses on immediate restoration while problem management investigates root causes
In ISO 20000-1, incident management focuses on quickly restoring service, while problem management investigates the underlying root causes to prevent recurrence.
According to ISO 20000-1, what is the primary objective of incident management?