Home

Tutoring

Subjects

Live Classes

Study Coach

Essay Review

On-Demand Courses

Colleges

Games


Sign up

Log in

Opening subject page...

Loading your content

Practice

  • All Subjects
  • Algebra Flashcards
  • SAT Math Practice Tests
  • Math Question of the Day
  • Live Classes
  • On-Demand Courses

Varsity Tutors

  • Find a Tutor
  • Test Prep
  • Online Classes
  • K-12 Learning
  • College Search
  • VarsityTutors.com

© 2026 Varsity Tutors. All rights reserved.

← Back to quizzes

CPA Isc Quiz

CPA Isc Quiz: Evaluate Incident And Problem Management

Practice Evaluate Incident And Problem Management in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

Question 1 / 20

0 of 20 answered

A 'known error' in ITSM problem management refers to:

Select an answer to continue

What this quiz covers

This quiz focuses on Evaluate Incident And Problem Management, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

A 'known error' in ITSM problem management refers to:

  1. A documented security vulnerability that has been publicly disclosed.
  2. An error in the incident ticketing system that causes tickets to be misrouted.
  3. An error in the organization's financial statements identified by the external auditors.
  4. A problem that has been diagnosed with an identified root cause and a known workaround, but for which a permanent fix has not yet been implemented. (correct answer)

Explanation: A known error is a formally documented problem state where the root cause and a workaround are identified - it is tracked until a permanent fix (change) is implemented. Answer D is correct. Security vulnerabilities (A), ticketing errors (B), and financial statement errors (C) are not the ITSM definition.

Question 2

An organization's problem management process requires a root cause analysis (RCA) for all P1 (critical) incidents. After a major database outage, no RCA is conducted because 'the team was too busy with other work.' The most significant risk of this gap is:

  1. The organization may fail its next ISO 27001 certification audit.
  2. Staff involved in the incident may not receive performance reviews on time.
  3. The underlying cause of the outage remains unaddressed, increasing the likelihood of recurrence and future disruptions to critical systems and financial operations. (correct answer)
  4. The incident ticket will remain in 'open' status indefinitely in the ticketing system.

Explanation: Without RCA, the root cause of a critical outage is unknown and unresolved - the same failure mechanism can cause another outage. Answer C is correct. Certification impacts (A) are secondary. Performance reviews (B) are unrelated. Open tickets (D) are an administrative issue.

Question 3

Which of the following best describes a 'workaround' in ITSM incident and problem management?

  1. A permanent fix that eliminates the underlying cause of repeated incidents.
  2. A temporary patch applied by the IT team to a software vulnerability.
  3. A manual process that replaces automated system functionality indefinitely.
  4. A temporary solution that reduces the impact of an incident or problem until a permanent fix can be implemented. (correct answer)

Explanation: A workaround is a temporary measure - it mitigates impact but does not fix the underlying cause. It buys time until a proper solution is developed and implemented. Answer D is correct. A permanent fix (A) eliminates the need for a workaround. A security patch (B) may be a fix, not a workaround. Manual processes (C) may be workarounds but the definition is broader.

Question 4

An IT team resolves incidents by restarting servers whenever applications crash, without investigating why the crashes occur. Over six months, the same servers are restarted 47 times. This approach reflects:

  1. Effective incident management since service is restored quickly each time.
  2. Effective incident management but failed problem management - the root cause of the crashes has not been investigated or resolved. (correct answer)
  3. A technical limitation of the servers that cannot be resolved.
  4. An appropriate use of the change management process to address recurring issues.

Explanation: Quick restarts demonstrate responsive incident management. However, 47 restarts without root cause investigation is a clear problem management failure - the recurring crashes indicate an unresolved underlying issue. Answer B is correct. Quick restoration alone is not sufficient (A). The frequency suggests a resolvable problem (C). Restarts are not change management (D).

Question 5

During an audit, an IT auditor reviews the incident log and finds that several high-severity incidents affecting the financial reporting system were not logged in the incident management system. The primary risk of unlogged incidents is:

  1. The organization loses visibility into system reliability patterns, management cannot make informed decisions, and root cause analysis cannot be performed on untracked issues. (correct answer)
  2. The IT team will exceed its incident handling capacity.
  3. The organization will fail its SOC 2 audit automatically.
  4. Employees who experienced the incidents may file complaints about poor service.

Explanation: Unlogged incidents create blind spots - management cannot see patterns, cannot perform trend analysis, and cannot trigger problem management for recurring issues. Answer A is correct. Capacity (B), automatic SOC failures (C), and employee complaints (D) are not the primary risks.

Question 6

An organization's problem management process uses trend analysis of incident data. The primary purpose of this analysis is to:

  1. Determine whether the IT team is meeting its staffing targets.
  2. Identify recurring patterns or categories of incidents that may indicate underlying systemic problems requiring root cause investigation. (correct answer)
  3. Calculate the total cost of IT outages for financial reporting purposes.
  4. Provide data for the annual IT performance review.

Explanation: Trend analysis of incident data reveals patterns - the same system failing repeatedly, the same type of error occurring frequently - that signal underlying problems requiring problem management attention. Answer B is correct. Staffing (A), cost calculation (C), and performance reviews (D) are secondary uses.

Question 7

After a major security incident, an organization conducts a post-incident review. The primary purpose of this review is to:

  1. Determine which employees are responsible for the incident for disciplinary action.
  2. Satisfy the insurance company's requirements for incident reporting.
  3. Document the incident for inclusion in the annual IT report to the board.
  4. Understand what happened, why it happened, what was done well, what could be improved, and what actions will prevent recurrence. (correct answer)

Explanation: A post-incident review (also called a post-mortem or lessons learned) is focused on understanding and improvement - not blame - covering the full incident timeline, response effectiveness, and preventive actions. Answer D is correct. Blame assignment (A) is counterproductive. Insurance reporting (B) is a compliance activity. Board reporting (C) may follow but is not the review's primary purpose.

Question 8

Which of the following represents an effective integration between incident management and change management processes?

  1. When problem management identifies a root cause requiring a fix, the fix is implemented through the formal change management process to ensure it is authorized, tested, and documented. (correct answer)
  2. Change management should approve all incident resolutions before service is restored.
  3. Incident management and change management should operate independently to avoid delays.
  4. Only problem managers are authorized to initiate change requests.

Explanation: The formal link between problem management and change management ensures that fixes identified through root cause analysis are implemented in a controlled, authorized manner - preventing rushed fixes that could cause new problems. Answer A is correct. Pre-approval of all incident restorations (B) would cause unacceptable delays. Independence (C) creates gaps. Change initiation is not limited to problem managers (D).

Question 9

Which of the following is the most important information to capture in an incident record to support effective problem management?

  1. The name of the end user who first reported the incident.
  2. Symptoms, affected systems, timeline of events, steps taken to resolve, resolution method, and root cause if identified. (correct answer)
  3. The cost of IT staff time spent on the incident.
  4. The number of users affected by the incident.

Explanation: Comprehensive incident records with symptoms, timelines, and resolution details provide the foundation for problem management root cause analysis - enabling pattern recognition and systematic investigation. Answer B is correct. Reporter name (A), cost (C), and user count (D) are supplementary data that do not support root cause investigation.

Question 10

Which of the following is a key control that helps ensure incidents are escalated appropriately when they cannot be resolved within defined timeframes?

  1. Documented escalation paths and timeframes that automatically trigger notification of senior staff and management when incidents breach defined resolution windows. (correct answer)
  2. Requiring all IT staff to carry mobile phones so they can be reached at any time.
  3. Posting the IT team's organizational chart in the server room.
  4. Conducting monthly incident management training for IT staff.

Explanation: Documented escalation paths with defined triggers ensure that unresolved incidents automatically escalate to higher levels of authority, ensuring resources and management attention are applied before incidents cause unacceptable disruption. Answer A is correct. Mobile phones (B), org charts (C), and training (D) are supporting elements but not the escalation control itself.

Question 11

Which of the following metrics best measures the effectiveness of problem management?

  1. The number of incidents logged per month.
  2. The reduction in recurring incidents over time as root causes are identified and permanently fixed. (correct answer)
  3. The average cost of resolving each incident.
  4. The percentage of incidents resolved by the first-line support team.

Explanation: Problem management effectiveness is measured by whether it reduces incident recurrence - finding and fixing root causes should result in fewer repeat incidents over time. Answer B is correct. Incident volume (A) measures incident arrival rate, not problem management effectiveness. Cost (C) measures efficiency. First-call resolution (D) measures incident management performance.

Question 12

An organization's incident management process requires that all resolved incidents be reviewed within 5 business days to confirm the resolution is effective and the incident has not recurred. This post-resolution review primarily supports which objective?

  1. Verifying that the fix was effective and triggering problem management investigation if the incident recurs within the review window. (correct answer)
  2. Ensuring that IT staff properly documented the incident resolution for billing purposes.
  3. Confirming that the affected user has submitted a satisfaction rating for the support experience.
  4. Archiving the incident record for regulatory compliance purposes.

Explanation: Post-resolution review confirms fix effectiveness and catches early recurrences that should trigger problem management - connecting incident and problem management processes. Answer A is correct. Billing documentation (B), satisfaction ratings (C), and archiving (D) are administrative activities that are not the primary purpose.

Question 13

Which of the following best describes the concept of 'service degradation' in incident management?

  1. A permanent reduction in the organization's IT infrastructure capacity.
  2. A planned maintenance window during which certain services are temporarily unavailable.
  3. A condition where a service is partially available or operating below normal performance standards, representing an incident even if the service has not completely failed. (correct answer)
  4. The gradual deterioration of hardware performance over the asset's useful life.

Explanation: Service degradation - partial availability or reduced performance - qualifies as an incident and should be logged and addressed, even if users can still technically access the system. Answer C is correct. Permanent capacity reduction (A) is a different concept. Planned maintenance (B) is a scheduled activity, not an incident. Hardware aging (D) is a different phenomenon.

Question 14

When evaluating an organization's incident management process from a financial reporting perspective, which of the following types of incidents are most important to assess?

  1. All incidents regardless of which systems are affected.
  2. Only incidents that result in complete system unavailability.
  3. Only incidents that are reported by senior management.
  4. Incidents affecting systems that support financial transaction processing, financial reporting, or access to financial data. (correct answer)

Explanation: For financial reporting purposes, incidents affecting financial systems are most critical - they can delay reporting, corrupt data, or enable unauthorized access to financial information. Answer D is correct. Not all incidents affect financial reporting (A). Partial service degradation may also matter (B). Management reporting is not the selection criterion (C).

Question 15

An organization conducts quarterly incident management reviews with IT leadership. Which of the following agenda items would be most valuable for improving the incident management process?

  1. Reviewing the list of IT staff who were on call during the quarter.
  2. Reviewing the IT department's capital expenditure plan for the next quarter.
  3. Reviewing incident volume trends, SLA compliance rates, recurring incident patterns, open problem records, and outstanding root cause analysis actions. (correct answer)
  4. Reviewing vendor contracts for IT support services.

Explanation: Effective incident management review covers performance metrics (volume, SLAs), systemic patterns (recurring incidents), and follow-through on problem management (open problems, RCA actions) - enabling continuous improvement. Answer C is correct. On-call schedules (A), capital plans (B), and vendor contracts (D) are not incident management review content.

Question 16

Which of the following metrics is most useful for evaluating the effectiveness of an incident management process?

  1. Mean time to resolve (MTTR) - the average time from incident detection to service restoration. (correct answer)
  2. Mean time between failures (MTBF) - the average time between system failures.
  3. Total number of incidents logged per month.
  4. Percentage of incidents reported by end users versus automated monitoring.

Explanation: MTTR directly measures incident management effectiveness - how quickly the team restores service after an incident. Answer A is correct. MTBF (B) measures reliability, not incident management effectiveness. Total incidents logged (C) measures volume, not resolution effectiveness. Reporting source (D) is a detection metric.

Question 17

An organization's ITSM platform automatically creates a problem record when three or more incidents with the same category and affected system are logged within a 30-day period. This automation is designed to:

  1. Reduce the number of incident tickets by merging related incidents.
  2. Proactively trigger problem management investigation when patterns suggest an underlying systemic issue, preventing continued reactive incident handling. (correct answer)
  3. Alert end users that their issues are part of a known pattern.
  4. Calculate the financial cost of systemic problems for management reporting.

Explanation: Automated problem record creation based on incident patterns is a proactive problem management trigger - identifying systemic issues before they cause further damage, rather than waiting for manual escalation. Answer B is correct. Merging tickets (A) is a different function. User alerts (C) and cost calculation (D) are secondary functions.

Question 18

During an audit, an organization claims its incident management process is effective because 'issues get fixed.' The auditor should evaluate this claim by reviewing:

  1. Employee satisfaction survey results about IT support quality.
  2. The IT department's headcount and training certifications.
  3. The organization's IT strategic plan for planned system improvements.
  4. Incident logs, SLA compliance rates, recurring incident patterns, root cause analysis completion rates, and evidence of permanent fixes implemented. (correct answer)

Explanation: Auditing incident management effectiveness requires objective evidence: ticket data, SLA compliance, recurrence patterns, RCA completion, and fix implementation - not anecdotal claims. Answer D is correct. Satisfaction surveys (A), headcount (B), and strategic plans (C) do not directly measure incident management process effectiveness.

Question 19

Which of the following incident management controls most directly ensures that critical IT incidents are appropriately prioritized?

  1. Requiring all incidents to be resolved within 24 hours regardless of severity.
  2. Allowing end users to self-assign priority levels to their own incidents.
  3. Implementing a priority matrix that classifies incidents based on business impact and urgency, with defined response and resolution SLAs for each priority level. (correct answer)
  4. Assigning all incidents to the most senior IT staff member available.

Explanation: A formal priority matrix based on impact and urgency ensures objective, consistent prioritization - high-impact, urgent incidents receive immediate attention while lower-priority issues are queued appropriately. Answer C is correct. Uniform 24-hour resolution (A) doesn't differentiate priorities. User self-assignment (B) is unreliable. Seniority-based assignment (D) wastes senior resources on minor issues.

Question 20

In IT service management (ITSM), what is the primary distinction between 'incident management' and 'problem management'?

  1. Incident management is performed by senior staff; problem management is performed by junior staff.
  2. Incident management addresses security breaches; problem management addresses software defects.
  3. Incident management is a reactive process; problem management is a proactive process only.
  4. Incident management focuses on restoring normal service as quickly as possible; problem management focuses on identifying and eliminating the root cause to prevent recurrence. (correct answer)

Explanation: Incident management prioritizes speed of restoration - getting users back to work. Problem management digs deeper to find and eliminate the underlying root cause so the incident does not recur. Answer D is correct. Seniority (A) and domain scope (B) are not the distinguishing factors. Problem management can be both reactive and proactive (C).