ServiceNow CIS-ITSM - IT Service Management Implementation - Incident Problem Change CMDB SLA Catalog

By Marcus Chen · Updated May 25, 2026

Questions25
Passing Score75%
Format100% Multiple Choice
Sessions Logged823
Your progressLog in / Register to track times taken, best score, questions mastered, and coverage on this quiz.
Rating
Community rating 4.2 out of 5 from 40 ratings.
4.2 (40)

Topics covered

This quiz

Uncategorized25 (100%)

Uncategorized25 questions

Discussion

Log in to post a comment, reply, or expand a question.

Q-8630

Question Q-8630 An ITSM implementation team is conducting User Acceptance Testing (UAT)…

3 comments · last active May 28, 2026

  • Belovelant · May 26, 3:55 PM

    Anyone debate opt B vs C on CMDB baseline? I thought baseline was snapshot for comparison — re-read explanation before my exam.

  • gregbrial · May 27, 9:55 AM

    Read the rationale on this one — CIS-ITSM loves 'most correct' implementation, not 'technically possible'.

  • notorioususb · May 28, 9:55 PM

    Virtual Agent / Flow / CMDB questions stack up — pace yourself on timed runs.

Q-8618

Question Q-8618 A large enterprise wants to migrate their existing CMDB data…

3 comments · last active May 27, 2026

  • duther1 · May 25, 6:56 AM

    50k CIs = Import Set → Transform Map → cmdb_ci_* tables → IRE for dedupe. Discovery discovers live env; it won't ingest your legacy CSV history.

    +2 votes
  • _nine_ · May 26, 1:56 AM

    IRE matching on serial/hostname/IP saved us on a migration. Know identification vs reconciliation rules.

  • taz210 · May 27, 5:56 PM

    Manual entry (opt A) at 50k records is a joke answer — exam uses it to test if you're paying attention.

Q-8612

Question Q-8612 An organization receives 500 incidents per day from a single…

2 comments · last active May 26, 2026

  • howard300 · May 25, 6:53 PM

    500 incidents/day from one app — Intelligent Triage / ML clustering + Problem record is the right pattern. Don't mass-close as duplicates unless they're true dupes.

  • stupiduselessnames · May 26, 2:53 PM

    We used Problem linking without ML and it still worked — but exam wants the Similar Incidents / triage answer when it's offered.

Q-8615

Question Q-8615 An organization needs to implement Service Level Agreements (SLAs) for…

2 comments · last active May 25, 2026

  • rowdyray2003 · May 24, 8:13 PM

    Four SLA definitions: P1 response, P1 resolve, P2 response, P2 resolve — each with priority condition + business hours schedule. One mega-SLA with condition fields sounds nice but isn't the exam answer.

  • alakonda02 · May 25, 6:13 PM

    Schedule record Mon-Fri 8-6 then attach to each Task SLA. Pause on On Hold is standard.

Q-8621

Question Q-8621 An ITSM implementation includes incident categories that are now outdated.…

2 comments · last active May 24, 2026

  • RespectNDA · May 23, 6:01 PM

    Retire categories by marking sys_choice Inactive — historical incidents keep old value, dropdown stops showing it. Never delete choices in prod.

  • Mindwaves23 · May 24, 10:01 PM

    Mass update historical (opt C) breaks reporting integrity. Learned that in a CAB postmortem.

Q-8614

Question Q-8614 A Problem Manager wants to track known errors (problems where…

2 comments · last active May 21, 2026

  • howard300 · May 20, 11:54 PM

    Known Error = Problem state + workaround on record + KB article. Exam answer is D (both A and B) — don't pick only one if both are listed.

  • shotwithoutachaser · May 21, 3:54 PM

    Service desk finds workaround faster when KB is linked — agents search Global Search during incident.

Q-8620

Question Q-8620 A company wants to implement a Service Catalog with a…

2 comments · last active May 19, 2026

  • No_shunning · May 18, 8:42 PM

    Catalog approval over $1000 — conditional branch in the fulfillment flow/Flow Designer: if cost > 1000 → approval, else skip to fulfillment. Keeps one catalog item.

  • bonafont95 · May 19, 11:42 AM

    Two separate catalog items (opt A) works operationally but exam wants dynamic workflow condition on one item.

Q-8617

Question Q-8617 During a Change Management implementation, a client wants the system…

2 comments · last active May 17, 2026

  • MishaPink · May 16, 6:03 PM

    Change Collision Detection is native — flags same CI / maintenance window conflicts. Custom BR (opt C) duplicates platform capability.

  • claudication · May 17, 7:03 AM

    CAB manually reviewing CMDB (opt D) doesn't scale — that's why collision detection exists.

Q-8624

Question Q-8624 A global company has ITSM implemented across 5 regions, each…

2 comments · last active May 16, 2026

  • mufukin_sage · May 16, 6:23 AM

    Multi-region on ONE instance: regional groups, schedules, assignment rules, SLA conditions — not five instances unless legal/data residency forces it.

  • iPro_x_NuKeZ · May 16, 6:23 PM

    Domain Separation (opt D) is multi-tenant partitioning — different use case than APAC vs EMEA hours.

Q-8611

Question Q-8611 A company wants to implement a major incident process where…

2 comments · last active May 15, 2026

  • KingTutsBustedNut · May 15, 3:53 PM

    Major Incident Management isn't just emailing execs — you get the workbench, comms plan, stakeholder groups. Business rule alone (opt A) is a trap.

    +2 votes
  • mandatorytoast · May 15, 11:53 PM

    Correct — P1 SLA breach tells you you're late; it doesn't coordinate bridge calls and comms the way MIM does.

Q-8613

Question Q-8613 A change manager wants to ensure that high-risk changes always…

3 comments · last active May 15, 2026

  • ace2470 · May 13, 12:26 PM

    Standard vs Normal vs Emergency — separate workflows triggered by type/risk. Standard Change Catalog = pre-approved low risk path.

  • JojiBoutique · May 13, 11:26 PM

    CAB skipping low risk in a meeting (opt B) is terrible governance and not how SN implements it.

  • unhappythrowaway22 · May 15, 1:26 AM

    Memorize: Standard = auto, Normal = CAB, Emergency = fast track + PIR.

Q-8623

Question Q-8623 A company wants to measure their IT service desk performance…

2 comments · last active May 14, 2026

  • Yulppp · May 13, 11:03 PM

    Incident KPIs = MTTR, FCR, reopen rate, SLA %. Change metrics (opt A) and Problem backlog (opt C) are wrong process.

  • hohnersg · May 14, 8:03 AM

    Easy eliminate if you know ITIL process boundaries.

Question catalog for this preview

Catalog listing of the 5 preview questions for this quiz.

Question 1

A company wants to implement a major incident process where P1 incidents automatically notify senior management and create a dedicated communication bridge. Which ServiceNow ITSM features should be configured?

Answer choices

  • A. A business rule that sends emails and creates a conference bridge record when priority = 1

  • B. Major Incident Management workflow with automatic escalation, stakeholder notification groups, and a communication plan record linked to the major incident (Correct)

  • C. An SLA definition that triggers when P1 incidents breach their response time

  • D. A Change Management emergency change linked to the P1 incident

Explanation

ServiceNow's Major Incident Management process (part of ITSM Pro) includes dedicated features: (1) Major Incident criteria that auto-promotes incidents to Major Incident status based on conditions; (2) Automatic creation of a communication plan with predefined stakeholder groups; (3) Major Incident workbench for coordinating response; (4) Automated notification workflows to executives and senior management; (5) Audit trail of all response activities. Simple business rule emails (option A) lack the structured coordination features. SLAs measure timelines but don't coordinate response. Emergency Change Management may be linked but isn't the primary tool for incident response coordination.

Question 2

A ServiceNow ITSM implementation needs to support a "Virtual Agent" chatbot that can help users create incidents and check the status of their requests. What configuration is required?

Answer choices

  • A. Deploy a custom-coded chatbot using third-party platforms and integrate via REST API

  • B. Configure Virtual Agent Designer (NLU topics, conversation flows, fulfillment actions) within ServiceNow, connecting to ITSM tables and flows (Correct)

  • C. Create a simple FAQ widget on the Service Portal

  • D. Configure an email autoresponder for common incident types

Explanation

ServiceNow Virtual Agent is a native platform capability (part of Now Intelligence). Configuration includes: (1) Virtual Agent Designer — create conversation Topics (intents like "Create Incident" or "Check Request Status") using NLU (Natural Language Understanding); (2) Conversation flow nodes — capture user information through dialogue; (3) Fulfillment — connect to FlowAPI, GlideRecord, or ServiceNow Spoke actions to create/query records; (4) Integration channels — deploy on Teams, Slack, web, mobile. No third-party development is needed. The Virtual Agent integrates natively with ITSM workflows and provides 24/7 self-service. Third-party chatbots (option A) require significant integration effort.

Question 3

A company is implementing the Service Portal and wants the incident creation form to automatically populate the "Affected User" field with the logged-in user's information. What is the MOST appropriate way to implement this?

Answer choices

  • A. A business rule on the incident table that sets the caller after insertion

  • B. A Default Value on the Affected User field in the Incident table definition set to `javascript:gs.getUserID()` (Correct)

  • C. A Client Script on the Portal form that reads `g_user` and sets the field

  • D. A Transform Map that maps the user during import

Explanation

Setting a Default Value on the `caller_id` (Affected User) field in the Incident table definition is the cleanest approach. In the field's Default Value, you enter `javascript:gs.getUserID()` — this server-side script runs when a new incident record is created and automatically sets the caller to the current user's sys_id. This works across all entry points: the main UI, Service Portal, mobile app, and API calls when session context is available. A Client Script (option C) would only work in the browser UI and would need to handle the g_user object. Default values are the standard platform mechanism for auto-populating fields with user context.

Question 4

A company has implemented Knowledge Management and wants to measure the effectiveness of their knowledge base. The Knowledge Manager asks: "How many incidents were resolved using a knowledge article, and which articles are used most?" How can this be reported in ServiceNow?

Answer choices

  • A. Count knowledge articles and cross-reference with resolved incidents manually

  • B. Use the "Linked Knowledge" feature where agents attach KB articles to incidents; report on `m2m_incident_kb_knowledge` (or similar) relationship table and kb_knowledge usage statistics (Correct)

  • C. Review agent work notes for article references

  • D. Export both tables to Excel and use VLOOKUP to match

Explanation

ServiceNow tracks knowledge usage through relationship records. When an agent links a KB article to an incident (via "Knowledge" related list or the Knowledge Search widget), a many-to-many relationship record is created. The `kb_knowledge_task_mtom` table tracks these links. ServiceNow also tracks article views and ratings in `kb_use` and `kb_feedback` tables. You can create reports showing: (1) Number of incidents per article (most-used articles); (2) Incidents resolved after KB article was linked (deflection rate); (3) Article usefulness ratings. The ServiceNow Knowledge Analytics dashboard provides these metrics natively. Manual work notes analysis (option C) is not scalable or reliable.

Question 5

During an ITSM implementation, the client asks whether ServiceNow supports integration with monitoring tools like Nagios or Dynatrace to automatically create incidents when alerts fire. What is the recommended integration pattern?

Answer choices

  • A. Configure monitoring tools to send emails to ServiceNow, creating incidents via email inbound actions

  • B. Use ServiceNow IT Operations Management (ITOM) Event Management with the monitoring tool's REST or SNMP integration to receive events, deduplicate them, and auto-create/update incidents based on alert policies (Correct)

  • C. Have an operations team manually create incidents for each monitoring alert

  • D. Install the monitoring agent on the ServiceNow application server

Explanation

ServiceNow IT Operations Management (ITOM) Event Management is designed for this integration pattern: (1) Monitoring tools (Nagios, Dynatrace, Zabbix, PagerDuty) send events to ServiceNow via REST, SNMP, or native connectors; (2) Event Management deduplicates and correlates events (preventing alert storms from creating thousands of incidents); (3) Alert rules convert significant events into Alerts; (4) Alert Action policies automatically create, update, or resolve incidents based on alert conditions; (5) CMDB CI lookup adds CI context to incidents. This reduces false-positive incidents, correlates related alerts, and provides CI-enriched context. Email-based integration (option A) lacks structured data and deduplication. Manual creation (option C) introduces lag and human error.