ISO 20000 Certification IT Service Management 5 — Questions and Answers
Question 1: In ISO 20000, which process is specifically responsible for controlling the financial aspects of IT service delivery, including budgeting and charging?
- Service Level Management
- Supplier Management
- Service Financial Management (Correct answer)
- Capacity Management
Correct answer: Service Financial Management
Service Financial Management covers budgeting, accounting, and charging for IT services within the ISO 20000 framework.
Question 2: When an organization integrates ISO 20000 with ISO 27001, which area of the SMS is most directly strengthened?
- Service continuity and information security controls (Correct answer)
- Supplier contract renewal processes
- Configuration item discovery automation
- Service request fulfillment speed
Correct answer: Service continuity and information security controls
Integrating ISO 27001 with ISO 20000 directly strengthens information security controls within the SMS, particularly service continuity planning.
Question 3: Under ISO 20000, which type of audit is conducted by the certification body to verify initial compliance?
- Internal audit
- Surveillance audit
- First-party audit
- Stage 2 certification audit (Correct answer)
Correct answer: Stage 2 certification audit
The Stage 2 audit is the full on-site certification audit conducted by the external certification body to verify conformance with ISO 20000-1.
Question 4: A service provider must prioritize and route incoming contacts from users. Under ISO 20000, this is the primary function of:
- Problem Management
- The Service Desk (Correct answer)
- Change Management
- Release Management
Correct answer: The Service Desk
The Service Desk is the single point of contact for users and is responsible for logging, prioritizing, and routing incidents and requests.
Question 5: Which of the following is NOT a required output of Incident Management under ISO 20000?
- Incident records
- Updated known error database
- Resolved incidents within agreed timescales
- Root cause analysis report for all incidents (Correct answer)
Correct answer: Root cause analysis report for all incidents
Root cause analysis is the responsibility of Problem Management, not Incident Management, which focuses on restoring service quickly.
Question 6: ISO 20000-1:2018 requires that competence of personnel performing roles in the SMS be ensured. Which clause covers this requirement?
- Clause 5 – Leadership
- Clause 7 – Support (Correct answer)
- Clause 8 – Operation
- Clause 9 – Performance Evaluation
Correct answer: Clause 7 – Support
Clause 7.2 (Competence) requires organizations to determine necessary competencies, ensure personnel are competent, and retain documented evidence.
Question 7: An organization's SMS scope covers only its help desk operations. During a surveillance audit, the auditor finds that the network team — excluded from scope — is causing SLA breaches. What should the organization do?
- Remove the SLA targets from the service catalog
- Expand the SMS scope to include the network team or implement supplier/dependency controls (Correct answer)
- Raise a problem record against the network team
- Request a scope waiver from the certification body
Correct answer: Expand the SMS scope to include the network team or implement supplier/dependency controls
When out-of-scope teams materially affect SMS performance, the organization must expand the scope or apply formal controls over that dependency.
In ISO 20000, which process is specifically responsible for controlling the financial aspects of IT service delivery, including budgeting and charging?