What this quiz covers
This quiz focuses on Evaluate Incident And Problem Management, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
An organization's problem management process requires a root cause analysis (RCA) for all P1 (critical) incidents. After a major database outage, no RCA is conducted because 'the team was too busy with other work.' The most significant risk of this gap is:
CPA Isc Quiz
Practice Evaluate Incident And Problem Management in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
This quiz focuses on Evaluate Incident And Problem Management, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
An organization's problem management process requires a root cause analysis (RCA) for all P1 (critical) incidents. After a major database outage, no RCA is conducted because 'the team was too busy with other work.' The most significant risk of this gap is:
Explanation: Without RCA, the root cause of a critical outage is unknown and unresolved - the same failure mechanism can cause another outage. Answer C is correct. Certification impacts (A) are secondary. Performance reviews (B) are unrelated. Open tickets (D) are an administrative issue.
An IT team resolves incidents by restarting servers whenever applications crash, without investigating why the crashes occur. Over six months, the same servers are restarted 47 times. This approach reflects:
Explanation: Quick restarts demonstrate responsive incident management. However, 47 restarts without root cause investigation is a clear problem management failure - the recurring crashes indicate an unresolved underlying issue. Answer B is correct. Quick restoration alone is not sufficient (A). The frequency suggests a resolvable problem (C). Restarts are not change management (D).
During an audit, an IT auditor reviews the incident log and finds that several high-severity incidents affecting the financial reporting system were not logged in the incident management system. The primary risk of unlogged incidents is:
Explanation: Unlogged incidents create blind spots - management cannot see patterns, cannot perform trend analysis, and cannot trigger problem management for recurring issues. Answer A is correct. Capacity (B), automatic SOC failures (C), and employee complaints (D) are not the primary risks.
An organization's incident management process requires that all resolved incidents be reviewed within 5 business days to confirm the resolution is effective and the incident has not recurred. This post-resolution review primarily supports which objective?
Explanation: Post-resolution review confirms fix effectiveness and catches early recurrences that should trigger problem management - connecting incident and problem management processes. Answer A is correct. Billing documentation (B), satisfaction ratings (C), and archiving (D) are administrative activities that are not the primary purpose.
An organization's ITSM platform automatically creates a problem record when three or more incidents with the same category and affected system are logged within a 30-day period. This automation is designed to:
Explanation: Automated problem record creation based on incident patterns is a proactive problem management trigger - identifying systemic issues before they cause further damage, rather than waiting for manual escalation. Answer B is correct. Merging tickets (A) is a different function. User alerts (C) and cost calculation (D) are secondary functions.
During an audit, an organization claims its incident management process is effective because 'issues get fixed.' The auditor should evaluate this claim by reviewing:
Explanation: Auditing incident management effectiveness requires objective evidence: ticket data, SLA compliance, recurrence patterns, RCA completion, and fix implementation - not anecdotal claims. Answer D is correct. Satisfaction surveys (A), headcount (B), and strategic plans (C) do not directly measure incident management process effectiveness.
An auditor evaluating incident management controls for a financial services company finds that the company has no documented incident response procedures. The primary risk is:
Explanation: Without documented procedures, incident response depends on individual knowledge and improvisation - leading to inconsistent, slower, and incomplete responses that increase damage. Answer D is correct. Regulatory fines (A) may follow but are secondary. System usability (B) is unrelated. Insurance (C) is a separate consideration.
An organization's incident management SLA requires that P1 incidents be resolved within 4 hours. The auditor reviews the incident log and finds that 35% of P1 incidents exceeded the 4-hour SLA during the past year. The auditor should:
Explanation: A 35% SLA breach rate for the highest-priority incidents is a significant finding that indicates systemic problems with incident response capacity, prioritization, or process - not isolated exceptions. Answer C is correct. Accepting high breach rates (A) ignores the control failure. Extending the SLA (B) masks the problem. Individual explanations (D) do not address the systemic issue.
During an audit of incident management controls, an auditor finds that critical system incidents are not escalated to senior management until they have been unresolved for more than 48 hours. The primary risk of this escalation policy is:
Explanation: A 48-hour escalation delay for critical incidents means management is unaware and cannot allocate additional resources for up to two days - potentially well beyond the RTO for critical systems. Answer B is correct. Over-notification (A) is not the risk for critical incidents. Report preparation (C) is a minor concern. Vendor SLAs (D) are a separate consideration.
A company experiences a system outage and the IT team restores service within the SLA timeframe. However, the same outage occurs again three weeks later. This pattern most likely indicates a failure in:
Explanation: Recurring incidents indicate that incident management restored service but problem management failed - the root cause was not found and fixed, allowing the same underlying issue to cause another outage. Answer A is correct. The first restoration met SLA (B). There is no evidence of a change (C) or backup issue (D).
Which of the following represents an effective integration between incident management and change management processes?
Explanation: The formal link between problem management and change management ensures that fixes identified through root cause analysis are implemented in a controlled, authorized manner - preventing rushed fixes that could cause new problems. Answer A is correct. Pre-approval of all incident restorations (B) would cause unacceptable delays. Independence (C) creates gaps. Change initiation is not limited to problem managers (D).
Which of the following is the most important information to capture in an incident record to support effective problem management?
Explanation: Comprehensive incident records with symptoms, timelines, and resolution details provide the foundation for problem management root cause analysis - enabling pattern recognition and systematic investigation. Answer B is correct. Reporter name (A), cost (C), and user count (D) are supplementary data that do not support root cause investigation.
Which of the following is a key control that helps ensure incidents are escalated appropriately when they cannot be resolved within defined timeframes?
Explanation: Documented escalation paths with defined triggers ensure that unresolved incidents automatically escalate to higher levels of authority, ensuring resources and management attention are applied before incidents cause unacceptable disruption. Answer A is correct. Mobile phones (B), org charts (C), and training (D) are supporting elements but not the escalation control itself.
Which of the following metrics is most useful for evaluating the effectiveness of an incident management process?
Explanation: MTTR directly measures incident management effectiveness - how quickly the team restores service after an incident. Answer A is correct. MTBF (B) measures reliability, not incident management effectiveness. Total incidents logged (C) measures volume, not resolution effectiveness. Reporting source (D) is a detection metric.
In IT service management (ITSM), what is the primary distinction between 'incident management' and 'problem management'?
Explanation: Incident management prioritizes speed of restoration - getting users back to work. Problem management digs deeper to find and eliminate the underlying root cause so the incident does not recur. Answer D is correct. Seniority (A) and domain scope (B) are not the distinguishing factors. Problem management can be both reactive and proactive (C).
A company experiences a ransomware attack that encrypts 60% of its production data. The incident response team's first priority should be:
Explanation: The first incident response priority is containment - isolating affected systems to stop the ransomware from spreading further. Investigation, notification, and recovery follow containment. Answer C is correct. Paying ransom (A) is a last resort that doesn't guarantee recovery. Customer notification (B) comes after containment and assessment. Root cause analysis (D) follows containment.
A 'known error' in ITSM problem management refers to:
Explanation: A known error is a formally documented problem state where the root cause and a workaround are identified - it is tracked until a permanent fix (change) is implemented. Answer D is correct. Security vulnerabilities (A), ticketing errors (B), and financial statement errors (C) are not the ITSM definition.
Which of the following best describes a 'workaround' in ITSM incident and problem management?
Explanation: A workaround is a temporary measure - it mitigates impact but does not fix the underlying cause. It buys time until a proper solution is developed and implemented. Answer D is correct. A permanent fix (A) eliminates the need for a workaround. A security patch (B) may be a fix, not a workaround. Manual processes (C) may be workarounds but the definition is broader.
An organization's problem management process uses trend analysis of incident data. The primary purpose of this analysis is to:
Explanation: Trend analysis of incident data reveals patterns - the same system failing repeatedly, the same type of error occurring frequently - that signal underlying problems requiring problem management attention. Answer B is correct. Staffing (A), cost calculation (C), and performance reviews (D) are secondary uses.
After a major security incident, an organization conducts a post-incident review. The primary purpose of this review is to:
Explanation: A post-incident review (also called a post-mortem or lessons learned) is focused on understanding and improvement - not blame - covering the full incident timeline, response effectiveness, and preventive actions. Answer D is correct. Blame assignment (A) is counterproductive. Insurance reporting (B) is a compliance activity. Board reporting (C) may follow but is not the review's primary purpose.