ITIL practices
59 free practice questions with explanations
PassNova has 59 free ITIL 4 Foundation practice questions on ITIL practices, each with a clear explanation. Practise them in the browser with instant feedback — 100% free, no sign-up, on any device. Updated for 2026.
ITIL practices: example questions & answers
40 worked examples with answers and explanations below. Practise all 59 ITIL practices questions free in the browser, with instant feedback on every answer.
The ITIL 4 practices are grouped into which three categories?
- AGeneral management, service management, and technical management practices✓
- BStrategy, design, and operation practices, mirroring the stages of the older service lifecycle
- CPeople, process, and technology practices
- DPlan, build, and run practices, matching the way many IT departments choose to organise their internal teams
Answer: ITIL 4's 34 practices are grouped into general management practices, service management practices, and technical management practices.
What is the purpose of the 'incident management' practice?
- ATo identify and eliminate the root causes of problems
- BTo authorize and control changes
- CTo minimize the negative impact of incidents by restoring normal service operation as quickly as possible✓
- DTo handle requests for new services
Answer: The purpose of incident management is to minimize the negative impact of incidents by restoring normal service operation as quickly as possible.
How does ITIL 4 define an 'incident'?
- AThe addition, modification, or removal of anything that could affect services
- BAn unplanned interruption to a service or reduction in the quality of a service✓
- CA cause, or potential cause, of one or more incidents
- DA request from a user for something to be provided
Answer: An incident is an unplanned interruption to a service, or a reduction in the quality of a service.
What is the purpose of the 'problem management' practice?
- ATo restore service as quickly as possible after an incident so that the agreed level of availability is maintained and users can resume work without delay
- BTo coordinate the release of new software, scheduling each deployment window and confirming that the build has passed testing before it reaches the live environment
- CTo reduce the likelihood and impact of incidents by identifying actual and potential causes of incidents and managing workarounds and known errors✓
- DTo manage user access rights by granting and revoking the permissions each person needs, so that only authorised users are able to reach a service at all
Answer: Problem management reduces the likelihood and impact of incidents by identifying actual and potential causes of incidents, and managing workarounds and known errors.
How does ITIL 4 define a 'problem'?
- AA cause, or potential cause, of one or more incidents✓
- BAn unplanned interruption to a service, or a reduction in its quality
- CA change of state that is significant for a configuration item
- DA documented agreement between a provider and a customer that records the service levels to be delivered
Answer: A problem is a cause, or potential cause, of one or more incidents.
What is a 'known error' in ITIL 4?
- AA service request that was rejected
- BA change that failed during deployment
- CAn incident that occurs frequently
- DA problem that has been analyzed but has not been resolved✓
Answer: A known error is a problem that has been analyzed but has not been resolved. It often has a documented workaround.
The three phases of problem management in ITIL 4 are:
- AProblem identification, problem control, and error control✓
- BPlan, do, and check, applied as a repeating cycle to every problem record
- CDetection, diagnosis, and recovery
- DLogging, categorization, and closure
Answer: Problem management activities are organized into three phases: problem identification, problem control, and error control.
What is the purpose of the 'change enablement' practice?
- ATo restore normal service operation after an incident
- BTo maximize the number of successful service and product changes by ensuring risks are properly assessed and changes are authorized✓
- CTo capture demand for new services
- DTo manage the organization's suppliers
Answer: Change enablement maximizes the number of successful IT changes by ensuring risks are properly assessed, authorizing changes to proceed, and managing the change schedule.
Which type of change is pre-authorized, low risk, well understood, and fully documented, and can be implemented without additional authorization?
- AEmergency change
- BNormal change
- CStandard change✓
- DMajor change
Answer: A standard change is a low-risk, pre-authorized change that is well understood and fully documented, and can be implemented without additional authorization.
Which type of change must be assessed, authorized, and scheduled through the standard change enablement process?
- AStandard change
- BEmergency change
- CAutomatic change
- DNormal change✓
Answer: A normal change is one that needs to be scheduled, assessed, and authorized following a standard process. Authorization may use a change authority.
Which type of change must be implemented as soon as possible, for example to resolve a major incident or implement a security patch?
- APlanned change
- BEmergency change✓
- CStandard change
- DNormal change
Answer: An emergency change must be implemented as soon as possible, often to resolve an incident or apply a security patch. It may have a separate, expedited authorization process.
How does ITIL 4 define a 'change'?
- AThe addition, modification, or removal of anything that could have a direct or indirect effect on services✓
- BAn unplanned interruption to a service, or a reduction in the quality of a service, reported by a user or picked up by monitoring
- CA request from a user for information
- DA cause of one or more incidents, whether already proven or still only suspected, for which a workaround may have been recorded in the known error database
Answer: A change is the addition, modification, or removal of anything that could have a direct or indirect effect on services.
What is the purpose of the 'service desk' practice?
- ATo resolve the root causes of all incidents, recording each known error and its workaround so that recurrences across the estate are prevented
- BTo capture demand for incident resolution and service requests, and to be the entry point and single point of contact for users✓
- CTo authorise every change to the live environment, assessing each one for risk and scheduling it into a deployment window that has been agreed with the business in advance
- DTo negotiate service level agreements with customers and then report each month on whether the targets those agreements contain have been met
Answer: The service desk captures demand for incident resolution and service requests, acting as the entry point and single point of contact for the service provider with all its users.
What is the purpose of the 'service request management' practice?
- ATo control the deployment of new releases, moving each tested component out of the build environment and into the live environment at a time that has been agreed with the business
- BTo support the agreed quality of a service by handling all predefined, user-initiated service requests effectively and user-friendly✓
- CTo identify the root causes of problems and manage the resulting workarounds and known errors so that incidents become less frequent over time
- DTo minimise the impact of incidents by restoring normal service operation as quickly as possible after any unplanned interruption to an agreed service
Answer: Service request management supports the agreed quality of a service by handling all predefined, user-initiated service requests in an effective and user-friendly manner.
How does ITIL 4 define a 'service request'?
- AA request from a user or user's authorized representative that initiates a service action agreed as a normal part of service delivery✓
- BAn unplanned interruption to a service, or a reduction in its quality, that has to be logged and then resolved by the service desk inside its target time
- CA change that must be implemented urgently, usually to resolve a major incident or to close a security weakness before it can be exploited
- DA cause of one or more incidents
Answer: A service request is a request from a user, or a user's authorized representative, that initiates a service action which has been agreed as a normal part of service delivery.
What is the purpose of the 'service level management' practice?
- ATo manage the deployment of changes, moving new or altered components into the live environment once building and testing have been completed and signed off
- BTo restore normal service operation after an incident as quickly as possible, so that the effect on agreed business activity is kept to a minimum
- CTo set clear business-based targets for service levels and ensure delivery is properly assessed, monitored, and managed against these targets✓
- DTo handle user requests for new equipment, software and information, dealing with each one through a predefined and repeatable procedure that has been agreed with the business beforehand
Answer: Service level management sets clear business-based targets for service performance, so that the delivery of a service can be properly assessed, monitored, and managed against these targets.
What is the purpose of the 'continual improvement' practice?
- ATo manage relationships with suppliers
- BTo align the organization's practices and services with changing business needs through ongoing improvement of products, services, and practices✓
- CTo authorize all changes to services
- DTo resolve incidents as quickly as possible, restoring normal service operation so that the impact on agreed business activity is kept to a minimum
Answer: The continual improvement practice aligns the organization's practices and services with changing business needs through the ongoing identification and improvement of services, components, and practices.
What is the correct order of steps in the ITIL continual improvement model?
- AIdentify, log, categorize, resolve, close
- BWhat is the vision? Where are we now? Where do we want to be? How do we get there? Take action; Did we get there? How do we keep the momentum going?✓
- CPlan, do, check, act
- DDetect, diagnose, repair, recover, restore
Answer: The continual improvement model steps are: What is the vision? Where are we now? Where do we want to be? How do we get there? Take action; Did we get there? How do we keep the momentum going?
In the continual improvement model, which step establishes baseline measurements of the current state?
- ATake action
- BHow do we get there?
- CWhat is the vision?
- DWhere are we now?✓
Answer: The 'Where are we now?' step assesses the current state, including baseline measurements, so that improvement can be measured objectively.
What is the purpose of the 'relationship management' practice?
- ATo resolve incidents reported by users, restoring normal service operation inside the target time agreed for each priority level
- BTo establish and nurture the links between the organization and its stakeholders at strategic and tactical levels✓
- CTo detect events in the infrastructure
- DTo control changes to the IT environment so that each one is assessed, authorised and scheduled before it is deployed
Answer: Relationship management establishes and nurtures the links between the organization and its stakeholders at strategic and tactical levels, identifying and managing their needs.
What is the purpose of the 'supplier management' practice?
- ATo handle user-reported incidents, logging each one at the service desk and restoring normal service operation inside the target time agreed for its priority level
- BTo deploy new releases into production, moving tested components out of the build environment and into live at a time that has been agreed with the business in advance
- CTo identify the root cause of problems
- DTo ensure that the organization's suppliers and their performance are managed appropriately to support the provision of seamless, quality products and services✓
Answer: Supplier management ensures that the organization's suppliers and their performance are managed appropriately to support the seamless provision of quality products and services.
What is the purpose of the 'information security management' practice?
- ATo restore service after a security incident only
- BTo control physical access to data centers only
- CTo protect the information needed by the organization to conduct its business, ensuring confidentiality, integrity, and availability✓
- DTo deploy antivirus software
Answer: Information security management protects the information needed by the organization to conduct its business, including the confidentiality, integrity, and availability of information.
What is the purpose of the 'IT asset management' practice?
- ATo handle every user service request through a predefined, repeatable procedure that has been agreed as part of normal service delivery
- BTo authorise changes to services, assessing the risk that each one carries and scheduling it into a deployment window that has been agreed with the business well in advance
- CTo plan and manage the full lifecycle of all IT assets to maximize value, control costs, manage risks, and support decision-making✓
- DTo restore normal service operation after an incident as quickly as possible, keeping the effect on agreed business activity to a minimum
Answer: IT asset management plans and manages the full lifecycle of all IT assets, helping the organization maximize value, control costs, manage risks, and support decision-making.
What is the purpose of the 'monitoring and event management' practice?
- ATo manage the lifecycle of changes so that each addition, modification or removal is assessed, authorised and scheduled before deployment
- BTo identify the actual root causes of problems and then manage the workarounds and known error records that come out of that analysis
- CTo systematically observe services and service components, and record and report selected changes of state identified as events✓
- DTo restore service after an incident
Answer: Monitoring and event management systematically observes services and service components, and records and reports selected changes of state identified as events, determining the appropriate response.
What is the purpose of the 'deployment management' practice?
- ATo restore service after an incident as quickly as possible, so that the effect on agreed business activity is kept to a minimum
- BTo move new or changed hardware, software, documentation, processes, or any other component to live (or test) environments✓
- CTo capture demand from users for incident resolution and service requests, acting as the single point of contact for the provider
- DTo authorise changes before they are built, weighing the risk that each one carries against the benefit it is expected to deliver to the business as a whole once deployed
Answer: Deployment management moves new or changed hardware, software, documentation, processes, or any other component from build to live (or test) environments.
Which statement best describes the relationship between incident management and problem management?
- AThey are the same practice with different names
- BIncident management restores service quickly, while problem management addresses the underlying causes to prevent recurrence✓
- CProblem management restores service quickly, while incident management finds root causes
- DNeither practice is concerned with service restoration
Answer: Incident management focuses on restoring normal service operation as quickly as possible, while problem management identifies and addresses the underlying causes to reduce future incidents.
A major outage is affecting thousands of users. Which practice is primarily responsible for restoring normal service operation as quickly as possible?
- AProblem management
- BChange enablement
- CIncident management✓
- DService level management
Answer: Incident management aims to minimise negative impact by restoring normal service operation as quickly as possible, which is the immediate priority in an outage.
After repeated similar outages, the team wants to find and remove the underlying cause to prevent recurrence. Which practice is most appropriate?
- AService request management
- BIncident management
- CProblem management✓
- DDeployment management
Answer: Problem management reduces the likelihood and impact of incidents by identifying actual and potential causes and managing workarounds and known errors.
A user wants a temporary fix applied so they can keep working while the underlying cause is still being investigated. In ITIL 4 terms, the documented temporary fix is a:
- AKnown error
- BStandard change
- CService request
- DWorkaround✓
Answer: A workaround is a means of reducing or eliminating the impact of an incident or problem for which a full resolution is not yet available.
A problem has been analysed and its cause understood, but no permanent fix has yet been deployed. ITIL 4 calls this a:
- AEmergency change
- BWorkaround
- CKnown error✓
- DMajor incident
Answer: A known error is a problem that has been analysed but not resolved; it frequently has an associated documented workaround.
A request to reset a password follows a predefined, agreed procedure available to all users. Which practice handles this?
- AChange enablement
- BService request management✓
- CIncident management
- DProblem management
Answer: Service request management handles predefined, user-initiated requests that are a normal part of service delivery, such as a password reset.
A frequently repeated, low-risk, fully documented and pre-authorised deployment is best handled as which type of change?
- ANormal change
- BStandard change✓
- CMajor change
- DEmergency change
Answer: A standard change is low-risk, pre-authorised, well understood, and fully documented, so it can be implemented without additional authorisation each time.
A serious security vulnerability must be patched today to prevent exploitation. Which type of change applies, and which practice authorises it through an expedited route?
- ANormal change via service level management
- BStandard change via the service desk
- CRoutine change via problem management
- DEmergency change via change enablement✓
Answer: An urgent fix is an emergency change; change enablement handles its expedited assessment and authorisation, often via a separate emergency change authority.
A planned upgrade is not pre-authorised and carries moderate risk, so it must be scheduled, assessed, and authorised before proceeding. This is which type of change?
- APre-approved change
- BNormal change✓
- CEmergency change
- DStandard change
Answer: A normal change must be scheduled, assessed, and authorised through the change enablement process, typically using a defined change authority.
Which practice provides the single point of contact between the service provider and its users, capturing demand for incident resolution and service requests?
- AService desk✓
- BRelationship management
- CSupplier management
- DService level management
Answer: The service desk is the entry point and single point of contact for users, capturing demand for incident resolution and service requests.
A business and a provider want clear, business-based targets for service performance, with monitoring and regular review against those targets. Which practice meets this need?
- AChange enablement
- BService level management✓
- CIncident management
- DMonitoring and event management
Answer: Service level management sets clear business-based targets and ensures delivery is assessed, monitored, and managed against them.
For service level management to be effective, agreed targets should be:
- ABased solely on technical component metrics measured in isolation from the service
- BRelated to business outcomes and the customer's view of the service✓
- CSet only by the service desk on the basis of the figures its own tooling reports
- DHidden from the customer so that expectations are never raised too high
Answer: Effective SLM targets relate to the customer's experience and business outcomes, not just isolated technical metrics that may not reflect the service as a whole.
An organisation wants to embed regular, ongoing improvement of services and practices aligned to changing business needs. Which practice and model support this?
- ASupplier management and the supplier register held by the procurement team
- BContinual improvement practice and the continual improvement model✓
- CIncident management and the plan-do-check-act cycle used to review each ticket
- DChange enablement and the change schedule maintained for the coming quarter
Answer: The continual improvement practice, supported by the continual improvement model, aligns services and practices with changing business needs through ongoing improvement.
Which is the correct first step of the ITIL continual improvement model?
- ATake action
- BDid we get there?
- CWhere are we now?
- DWhat is the vision?✓
Answer: The continual improvement model begins with 'What is the vision?', establishing the high-level direction before assessing the current state.
In the continual improvement model, baseline measurements of the current state are established in which step?
- AWhere are we now?✓
- BHow do we get there?
- CWhat is the vision?
- DWhere do we want to be?
Answer: 'Where are we now?' assesses and baselines the current state so that subsequent improvement can be measured objectively.