A financial services company is required by regulators to demonstrate the effectiveness of its IT service continuity plans. The service continuity manager has scheduled a full-scale disaster recovery test. According to ISO/IEC 20000, which process is essential for authorizing the timing and potential service impact of this test?
Answer and explanation
Correct answer: B
A full-scale disaster recovery test has the potential to impact live services and requires significant coordination. Therefore, it must be planned, assessed, and authorized through the Change Management process to manage the risk and ensure all stakeholders are informed.
Question 2
During an audit of a newly certified Service Management System (SMS), an auditor finds that while service management objectives exist, they are not consistently measured or reported on. Which core principle of ISO/IEC 20000 has been most significantly violated?
Answer and explanation
Correct answer: C
The Plan-Do-Check-Act (PDCA) cycle is fundamental to ISO/IEC 20000. Failing to measure ('Check') and report on objectives breaks the cycle, preventing the 'Act' phase (continual improvement). This is a direct violation of the requirement to monitor, measure, analyze, and evaluate the SMS.
Question 3
Multiple answers
A healthcare provider's SMS scope includes clinical applications and patient record systems. To comply with ISO/IEC 20000, which TWO of the following must the information security management process specifically address? (Select TWO).
Answer and explanation
Correct answers: B, C
ISO/IEC 20000 requires the information security management process to implement controls to maintain the confidentiality, integrity, and availability (CIA) of information, which is especially critical for sensitive patient data.
A key activity of the information security management process is to have a defined procedure for managing security incidents, from detection and analysis to resolution and learning.
Question 4
Case Study
Global Logistics Inc. (GLI) provides worldwide shipping and tracking services. Their core business relies on a set of critical IT services, including a real-time package tracking portal, a warehouse management system, and a partner integration API. The company recently decided to pursue ISO/IEC 20000 certification to improve service quality and gain a competitive advantage. The CIO has been appointed as the management representative responsible for the Service Management System (SMS).
During the initial planning phase, the management team defined the scope of the SMS to cover all critical IT services. They established a service management policy and set high-level objectives, such as 'improve customer satisfaction' and 'reduce service downtime'. However, they have not yet defined specific, measurable targets for these objectives, nor have they allocated a formal budget for the necessary resources and tools.
An external consultant reviewing their plan highlights a significant gap related to top management's responsibilities. The consultant explains that merely appointing a representative and setting vague objectives is insufficient for demonstrating leadership and commitment as required by the standard.
Which action must GLI's top management take to BEST address this gap and demonstrate their commitment to the SMS?
Answer and explanation
Correct answer: C
According to ISO/IEC 20000, top management must demonstrate leadership by ensuring the SMS objectives are established and are compatible with the strategic direction, and by ensuring the resources needed for the SMS are available. This option directly addresses the identified gaps in resources and measurable objectives.
Question 5
True or False: According to ISO/IEC 20000, the service availability management process is solely responsible for calculating uptime percentages and reporting them to the customer.
Answer and explanation
Correct answer: B
The scope of service availability management is broader. It includes not only monitoring and reporting but also planning, implementing, and improving availability to ensure that services meet agreed targets. It also involves analyzing periods of non-availability to identify underlying causes.
Question 6
A software development company uses a single, integrated Management System Standard (MSS) to manage its ISO 9001 (Quality), ISO 27001 (Security), and ISO 20000 (Service Management) certifications. What feature of modern MSSs makes this integration possible?
Answer and explanation
Correct answer: B
Modern ISO Management System Standards (MSSs) like ISO 20000, 9001, and 27001 are based on a common high-level structure (HLS), also known as Annex SL. This provides a shared framework of clauses, terms, and definitions that greatly simplifies the integration of multiple management systems.
Question 7
A new service is being planned. The Business Relationship Manager has gathered requirements from the customer, and the Service Level Manager has drafted an SLA. At what point does the capacity management process need to be involved?
Answer and explanation
Correct answer: B
Capacity management must be involved early in the service lifecycle. It uses business requirements and SLA targets to plan and ensure that sufficient capacity is available to meet performance targets from the moment the service is launched.
Question 8
A manufacturing company's production line is halted due to a critical application failure. The incident is classified as a major incident. Which of the following actions is a required activity of the Incident Management process in this scenario?
Answer and explanation
Correct answer: C
ISO/IEC 20000 specifies that major incidents must have separate procedures. A key part of managing a major incident is ensuring that top management and all relevant interested parties are kept informed of the progress towards resolution.
Question 9
The objective of the ____________ process is to ensure that all service components, assets, and configuration items are identified, controlled, and maintained throughout their lifecycle.
Answer and explanation
Correct answer: D
Configuration Management is the process responsible for maintaining information about Configuration Items (CIs) required to deliver an IT service, including their relationships. This control over all service components is a core part of its objective.
Question 10
A cloud service provider defines its service offering in a document that is visible to potential and current customers. This document includes details about service features, pricing tiers, and how to request the service. What is this document called?
Answer and explanation
Correct answer: B
The Service Catalog is the single source of consistent information on all operational services and is used to provide this information to customers. It describes the services, and often includes details on how to request them and pricing information.