A 'known error' in ITSM problem management refers to:
Opening subject page...
Loading your content
CPA Isc Quiz
Practice Evaluate Incident And Problem Management in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
Question 1 / 20
0 of 20 answered
A 'known error' in ITSM problem management refers to:
This quiz focuses on Evaluate Incident And Problem Management, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
A 'known error' in ITSM problem management refers to:
Explanation: A known error is a formally documented problem state where the root cause and a workaround are identified - it is tracked until a permanent fix (change) is implemented. Answer D is correct. Security vulnerabilities (A), ticketing errors (B), and financial statement errors (C) are not the ITSM definition.
An organization's problem management process requires a root cause analysis (RCA) for all P1 (critical) incidents. After a major database outage, no RCA is conducted because 'the team was too busy with other work.' The most significant risk of this gap is:
Explanation: Without RCA, the root cause of a critical outage is unknown and unresolved - the same failure mechanism can cause another outage. Answer C is correct. Certification impacts (A) are secondary. Performance reviews (B) are unrelated. Open tickets (D) are an administrative issue.
Which of the following best describes a 'workaround' in ITSM incident and problem management?
Explanation: A workaround is a temporary measure - it mitigates impact but does not fix the underlying cause. It buys time until a proper solution is developed and implemented. Answer D is correct. A permanent fix (A) eliminates the need for a workaround. A security patch (B) may be a fix, not a workaround. Manual processes (C) may be workarounds but the definition is broader.
An IT team resolves incidents by restarting servers whenever applications crash, without investigating why the crashes occur. Over six months, the same servers are restarted 47 times. This approach reflects:
Explanation: Quick restarts demonstrate responsive incident management. However, 47 restarts without root cause investigation is a clear problem management failure - the recurring crashes indicate an unresolved underlying issue. Answer B is correct. Quick restoration alone is not sufficient (A). The frequency suggests a resolvable problem (C). Restarts are not change management (D).
During an audit, an IT auditor reviews the incident log and finds that several high-severity incidents affecting the financial reporting system were not logged in the incident management system. The primary risk of unlogged incidents is:
Explanation: Unlogged incidents create blind spots - management cannot see patterns, cannot perform trend analysis, and cannot trigger problem management for recurring issues. Answer A is correct. Capacity (B), automatic SOC failures (C), and employee complaints (D) are not the primary risks.
An organization's problem management process uses trend analysis of incident data. The primary purpose of this analysis is to:
Explanation: Trend analysis of incident data reveals patterns - the same system failing repeatedly, the same type of error occurring frequently - that signal underlying problems requiring problem management attention. Answer B is correct. Staffing (A), cost calculation (C), and performance reviews (D) are secondary uses.
After a major security incident, an organization conducts a post-incident review. The primary purpose of this review is to:
Explanation: A post-incident review (also called a post-mortem or lessons learned) is focused on understanding and improvement - not blame - covering the full incident timeline, response effectiveness, and preventive actions. Answer D is correct. Blame assignment (A) is counterproductive. Insurance reporting (B) is a compliance activity. Board reporting (C) may follow but is not the review's primary purpose.
Which of the following represents an effective integration between incident management and change management processes?
Explanation: The formal link between problem management and change management ensures that fixes identified through root cause analysis are implemented in a controlled, authorized manner - preventing rushed fixes that could cause new problems. Answer A is correct. Pre-approval of all incident restorations (B) would cause unacceptable delays. Independence (C) creates gaps. Change initiation is not limited to problem managers (D).
Which of the following is the most important information to capture in an incident record to support effective problem management?
Explanation: Comprehensive incident records with symptoms, timelines, and resolution details provide the foundation for problem management root cause analysis - enabling pattern recognition and systematic investigation. Answer B is correct. Reporter name (A), cost (C), and user count (D) are supplementary data that do not support root cause investigation.
Which of the following is a key control that helps ensure incidents are escalated appropriately when they cannot be resolved within defined timeframes?
Explanation: Documented escalation paths with defined triggers ensure that unresolved incidents automatically escalate to higher levels of authority, ensuring resources and management attention are applied before incidents cause unacceptable disruption. Answer A is correct. Mobile phones (B), org charts (C), and training (D) are supporting elements but not the escalation control itself.
Which of the following metrics best measures the effectiveness of problem management?
Explanation: Problem management effectiveness is measured by whether it reduces incident recurrence - finding and fixing root causes should result in fewer repeat incidents over time. Answer B is correct. Incident volume (A) measures incident arrival rate, not problem management effectiveness. Cost (C) measures efficiency. First-call resolution (D) measures incident management performance.
An organization's incident management process requires that all resolved incidents be reviewed within 5 business days to confirm the resolution is effective and the incident has not recurred. This post-resolution review primarily supports which objective?
Explanation: Post-resolution review confirms fix effectiveness and catches early recurrences that should trigger problem management - connecting incident and problem management processes. Answer A is correct. Billing documentation (B), satisfaction ratings (C), and archiving (D) are administrative activities that are not the primary purpose.
Which of the following best describes the concept of 'service degradation' in incident management?
Explanation: Service degradation - partial availability or reduced performance - qualifies as an incident and should be logged and addressed, even if users can still technically access the system. Answer C is correct. Permanent capacity reduction (A) is a different concept. Planned maintenance (B) is a scheduled activity, not an incident. Hardware aging (D) is a different phenomenon.
When evaluating an organization's incident management process from a financial reporting perspective, which of the following types of incidents are most important to assess?
Explanation: For financial reporting purposes, incidents affecting financial systems are most critical - they can delay reporting, corrupt data, or enable unauthorized access to financial information. Answer D is correct. Not all incidents affect financial reporting (A). Partial service degradation may also matter (B). Management reporting is not the selection criterion (C).
An organization conducts quarterly incident management reviews with IT leadership. Which of the following agenda items would be most valuable for improving the incident management process?
Explanation: Effective incident management review covers performance metrics (volume, SLAs), systemic patterns (recurring incidents), and follow-through on problem management (open problems, RCA actions) - enabling continuous improvement. Answer C is correct. On-call schedules (A), capital plans (B), and vendor contracts (D) are not incident management review content.
Which of the following metrics is most useful for evaluating the effectiveness of an incident management process?
Explanation: MTTR directly measures incident management effectiveness - how quickly the team restores service after an incident. Answer A is correct. MTBF (B) measures reliability, not incident management effectiveness. Total incidents logged (C) measures volume, not resolution effectiveness. Reporting source (D) is a detection metric.
An organization's ITSM platform automatically creates a problem record when three or more incidents with the same category and affected system are logged within a 30-day period. This automation is designed to:
Explanation: Automated problem record creation based on incident patterns is a proactive problem management trigger - identifying systemic issues before they cause further damage, rather than waiting for manual escalation. Answer B is correct. Merging tickets (A) is a different function. User alerts (C) and cost calculation (D) are secondary functions.
During an audit, an organization claims its incident management process is effective because 'issues get fixed.' The auditor should evaluate this claim by reviewing:
Explanation: Auditing incident management effectiveness requires objective evidence: ticket data, SLA compliance, recurrence patterns, RCA completion, and fix implementation - not anecdotal claims. Answer D is correct. Satisfaction surveys (A), headcount (B), and strategic plans (C) do not directly measure incident management process effectiveness.
Which of the following incident management controls most directly ensures that critical IT incidents are appropriately prioritized?
Explanation: A formal priority matrix based on impact and urgency ensures objective, consistent prioritization - high-impact, urgent incidents receive immediate attention while lower-priority issues are queued appropriately. Answer C is correct. Uniform 24-hour resolution (A) doesn't differentiate priorities. User self-assignment (B) is unreliable. Seniority-based assignment (D) wastes senior resources on minor issues.
In IT service management (ITSM), what is the primary distinction between 'incident management' and 'problem management'?
Explanation: Incident management prioritizes speed of restoration - getting users back to work. Problem management digs deeper to find and eliminate the underlying root cause so the incident does not recur. Answer D is correct. Seniority (A) and domain scope (B) are not the distinguishing factors. Problem management can be both reactive and proactive (C).