Karinoya Learning Room

Qualifications · IT Passport Success Lab

Service Management

Read the questions and explanations in English. The lectures (explanatory articles) are available in Japanese only.

View the Japanese version (with lectures) →

Q1 | ITIL

Which of the following is the most appropriate description of ITIL?

  1. An international standard defining software quality characteristics
  2. An international standard compiling the body of knowledge of project management
  3. A collection of best practices compiling successful cases in IT service management
  4. An international standard defining the requirements for an information security management system
AnswerC. A collection of best practices compiling successful cases in IT service management

ITIL is a guide collecting practices that have produced results in IT service management, a best-practice collection that organizations consult when creating their own rules. Requirements for an information security management system correspond to JIS Q 27001, that is ISO/IEC 27001; the project management body of knowledge to PMBOK and ISO 21500; and software quality characteristics to JIS X 25010 and the like; none of these is ITIL.

Q2 | SLA

Which of the following is the most appropriate item to include in an SLA, a service level agreement?

  1. That the monthly system availability shall be at least 99.5%
  2. That every effort shall be made to raise user satisfaction as much as possible
  3. The details of the service provider's internal personnel evaluation system
  4. The programming languages to be used in system development
AnswerA. That the monthly system availability shall be at least 99.5%

An SLA is a document that sets the level of service quality in a form that allows objective judgment of whether it was achieved. An availability of at least 99.5% can be measured and verified numerically, so it is appropriate. Making every effort cannot be measured and does not function as an agreement, and the languages used in development or the provider's personnel system are not levels of service quality, so they are not appropriate SLA items.

Q3 | SLM

Which of the following is the most appropriate activity of SLM, service level management?

  1. Measuring and recording the service level only when a failure occurs
  2. Regularly measuring and evaluating actual service levels and implementing improvements as needed
  3. Automatically lowering the SLA figures to match the actual results whenever the service level is not achieved
  4. Concluding the SLA when the service starts and operating thereafter without reviewing its content
AnswerB. Regularly measuring and evaluating actual service levels and implementing improvements as needed

SLM is the activity of maintaining and improving the levels agreed in the SLA by regularly measuring and evaluating results and continuing improvement through the PDCA cycle. Operating without reviews after conclusion, or measuring only at failures, does not amount to continuous quality management. Mechanically lowering targets to match results when they are missed is not improvement, and it would also require agreement with the users, so it is wrong.

Q4 | Service desk

Which of the following is the most appropriate role of a service desk, also called a help desk?

  1. Deciding the allocation of next year's IT investment budget based on the company's medium-term management plan
  2. Deciding the hiring of staff needed by the information systems department and their assignments within it
  3. Interviewing users about their business needs, performing requirements definition, and writing specifications for development
  4. Serving as the single point of contact that receives user inquiries and failure reports, keeping records and managing the progress of responses
AnswerD. Serving as the single point of contact that receives user inquiries and failure reports, keeping records and managing the progress of responses

The service desk is the single point of contact that receives inquiries, failure reports, and requests from users, recording what is received and managing progress until resolution. Requirements definition belongs to development, hiring and assignment to human resources, and IT investment budgeting to executives or the IT strategy division; none of these is the service desk's role.

Q5 | Incident management

What is the main purpose of incident management?

  1. To restore an interrupted service as quickly as possible and minimize the impact on business
  2. To assess the impact of change requests to the system and approve or reject their implementation
  3. To record configuration item information accurately and keep it up to date
  4. To identify the root cause of incidents and implement permanent countermeasures
AnswerA. To restore an interrupted service as quickly as possible and minimize the impact on business

The purpose of incident management is rapid service restoration: even when the cause is not fully understood, it prioritizes resuming business through workarounds, restarts, and the like. Removing root causes is problem management, assessing and approving changes is change management, and maintaining configuration information is configuration management; each is a separate process.

Q6 | Problem management

The same failure has been recurring every month. Which of the following is the most appropriate activity to prevent its recurrence?

  1. Preparing procedures to restart the server and recover quickly each time the failure occurs
  2. Totaling the number of reported failures and increasing service desk staff
  3. Investigating and identifying the root cause of the failure and implementing a permanent fix that removes it
  4. Preparing in advance the text of the e-mail used to notify users when the failure occurs
AnswerC. Investigating and identifying the root cause of the failure and implementing a permanent fix that removes it

Preventing recurrence is the role of problem management, which identifies the root cause and implements a permanent fix that removes it. Preparing restart procedures, drafting notification text, and adding staff are incident-management measures that speed up responses or spread the load; the cause itself remains, so they do not prevent recurrence.

Q7 | Release management

Which activity reliably deploys approved changes into the production environment according to plan and puts them into operation?

  1. Problem management
  2. Release management
  3. Incident management
  4. Availability management
AnswerB. Release management

Deploying approved changes into the production environment and putting them into operation is release management. Incident management aims at rapid service restoration, problem management at removing root causes, and availability management at keeping the service usable at the agreed level; none of them is the process responsible for deployment into production.

Q8 | Escalation

Which of the following is the most appropriate description of escalation at a service desk?

  1. Holding training sessions to teach users how to operate the system
  2. Totaling and reporting the number of inquiries received and the time taken to handle them
  3. Handing over cases that the person in charge cannot solve to specialist engineers or higher-level managers
  4. Publishing frequently asked questions and their answers as an FAQ on a website
AnswerC. Handing over cases that the person in charge cannot solve to specialist engineers or higher-level managers

Escalation is the mechanism by which first-line staff hand over cases they cannot solve to more specialized staff or higher-level managers, ensuring the cases are resolved. Publishing an FAQ supports users' self-service, totaling case counts is performance reporting, and holding training is user education; none of these is escalation.

Q9 | Differential backup

Which of the following is the most appropriate description of a differential backup?

  1. Copying all of the data in its entirety every time
  2. Writing changed data to another disk in duplicate in real time
  3. Copying, all together each time, the data changed since the last full backup
  4. Copying only the data changed since the immediately preceding backup, whether full or incremental
AnswerC. Copying, all together each time, the data changed since the last full backup

A differential backup copies, each time, everything changed since the last full backup, which serves as the baseline. Taking only the changes since the immediately preceding backup is an incremental backup, copying everything every time is a full backup, and real-time duplicate writing is mirroring, RAID 1; none of these is a differential backup.

Q10 | Incremental restore

A full backup is taken on Sunday, and incremental backups are taken every day from Monday through Saturday. If a disk failure occurs right after the backup taken at the end of business on Thursday, which combination of backup media is needed to restore the data?

  1. Only the incremental backup taken on Thursday
  2. Sunday's full backup plus the incremental backups from Monday, Tuesday, Wednesday, and Thursday
  3. Only the full backup taken on Sunday and the incremental backup taken at the end of business on Thursday
  4. Only the incremental backups taken from Monday through Thursday
AnswerB. Sunday's full backup plus the incremental backups from Monday, Tuesday, Wednesday, and Thursday

An incremental backup holds only the changes since the immediately preceding backup, so after restoring the full backup you must apply every incremental taken since then, oldest first. Therefore Sunday's full backup and the four incrementals from Monday through Thursday are needed. Incrementals alone do not contain all the data, and the full backup plus only Thursday's incremental would lose the changes from Monday through Wednesday; that combination would be correct for differential backups.

Q11 | Differential restore

A full backup is taken on Sunday, and differential backups are taken every day from Monday onward. If a failure occurs right after Thursday's differential backup is taken, how many backup media are needed for the restore?

  1. 4
  2. 1
  3. 5
  4. 2
AnswerD. 2

A differential backup contains all changes since the last full backup, so the newest differential alone consolidates all changes up to that point. Therefore Sunday's full backup and Thursday's differential, 2 media in total, are enough to restore. With 1 medium you would have only the full or only the differential, which is insufficient. 5 media would be needed with incremental backups, one full plus four incrementals from Monday through Thursday, and 4 matches the required count of no method.

Q12 | Backup size

For the same target data, which of the following is the most appropriate statement about the time and data volume required for a single backup run?

  1. Differential backup takes the most and incremental backup the least
  2. All three methods require the same time and data volume
  3. Full backup takes the most and incremental backup the least
  4. Incremental backup takes the most and full backup the least
AnswerC. Full backup takes the most and incremental backup the least

A full backup, which copies everything every time, takes the most, and an incremental backup, which takes only the changes since the immediately preceding backup, takes the least. A differential falls in between. Note that restore time runs in the opposite order: full is the shortest and incremental the longest. It is important to read carefully whether the question asks about backup time or restore time.

Q13 | Job management

Which of the following is the most appropriate role of job management, that is, a job scheduler?

  1. Setting, for each user, the range of accessible files and the operations permitted on them
  2. Performing unit tests to find errors in programs
  3. Defining in advance the execution order and times of multiple processes, and starting and monitoring them automatically
  4. Measuring network traffic and controlling bandwidth
AnswerC. Defining in advance the execution order and times of multiple processes, and starting and monitoring them automatically

Job management defines as jobs the processes that should run in a fixed order and at fixed times, such as overnight batches, and provides automatic startup, execution monitoring, and notification of abnormal endings. Setting access rights is access management, measuring traffic and controlling bandwidth is network management, and running unit tests is development work; none of these is the role of job management.

Q14 | System migration

Which of the following is the most appropriate characteristic of the big-bang approach to system migration, in which everything is switched over at once?

  1. Because departments or operations are switched over one by one, the migration period tends to become long
  2. The old and new systems run in parallel for a certain period, and results are cross-checked during the migration
  3. Because the old system's data is not used after the migration, no data migration work is needed
  4. The migration can be completed quickly and cheaply, but when a problem occurs its impact extends to the whole
AnswerD. The migration can be completed quickly and cheaply, but when a problem occurs its impact extends to the whole

The big-bang approach switches the whole system over to the new one at a single point in time; the migration period is short and costs are low, but a defect affects the entire company. Running old and new at the same time is parallel operation, and switching over in sequence is phased migration. Whatever the approach, migrating the old system's data is normally necessary and never becomes unnecessary.

Q15 | Operations management

Which of the following is a routine task performed as system operations management?

  1. Monitoring server operation and resource utilization, and collecting and retaining logs
  2. Interviewing user departments about the functions required of a new system and compiling a requirements document
  3. Reviewing the source code of developed programs and pointing out errors
  4. Deciding the priorities of IT investment based on the company's management strategy
AnswerA. Monitoring server operation and resource utilization, and collecting and retaining logs

System operations management covers the daily work that keeps a system running stably, such as monitoring operation, tracking resource usage, collecting and retaining logs, and taking backups. Requirements definition and code review are phases of system development, and prioritizing IT investment is a management and IT-strategy activity; none of these is operations management work.

Q16 | UPS

What is the main purpose of installing a UPS, an uninterruptible power supply?

  1. To switch automatically to a wireless line when the communication line is cut
  2. To write data to multiple disks in duplicate in preparation for disk failures
  3. To supply power for a certain time when a power outage occurs, securing time to shut the system down safely
  4. To keep the server room's temperature and humidity constant and prevent equipment failures
AnswerC. To supply power for a certain time when a power outage occurs, securing time to shut the system down safely

A UPS uses its internal battery to supply power for a short time during an outage, buying time to save data and shut the system down normally, or to hand over to a private generator. Switching lines is line redundancy, maintaining temperature and humidity is the job of air conditioning, and duplicate writing to disks is mirroring, RAID 1; none of these is the purpose of a UPS.

Q17 | Private generator

A lightning strike caused a power outage lasting several hours over a wide area. Which piece of equipment is needed to keep the business systems running during this time?

  1. A private power generator
  2. A security cable
  3. A UPS, an uninterruptible power supply, alone
  4. A surge protector
AnswerA. A private power generator

To cope with an outage lasting hours, a private power generator that can keep generating from fuel is needed. A UPS battery typically supplies power for only minutes to tens of minutes, serving merely as a bridge until a safe shutdown or a handover to the generator. A surge protector guards equipment against abnormal high voltage, and a security cable is an anti-theft device; neither can supply power during an outage.

Q18 | Tailgating

In a room using IC-card entry control, which of the following is the most appropriate measure against tailgating, where someone enters behind an authorized user without being authenticated?

  1. Having users change their IC card passwords regularly
  2. Retaining the IC card reading records at entry for one year
  3. Fastening the PCs in the room with security cables
  4. Introducing anti-passback, which refuses exit to anyone who has no entry record
AnswerD. Introducing anti-passback, which refuses exit to anyone who has no entry record

Anti-passback is a mechanism that refuses exit to a person with no entry record, or the reverse, so it can detect and deter tailgaters who entered without authenticating. Retaining reading records helps with tracing afterwards but does not prevent tailgating itself, changing passwords only strengthens personal authentication, and security cables prevent equipment theft and cannot control entry.

Q19 | Theft prevention

Which of the following is the most appropriate physical measure to prevent the theft of laptop PCs installed in an office?

  1. Using biometric authentication at login
  2. Fastening the laptops to the desks with security cables
  3. Applying the latest security patches to the OS
  4. Encrypting the contents of the hard disks
AnswerB. Fastening the laptops to the desks with security cables

A security cable fastens the unit to a desk or pillar with a wire, making it physically difficult to carry away, which is a theft-prevention measure. Encryption and biometric authentication prevent information leakage after a theft, and applying security patches counters attacks that exploit vulnerabilities; none of these prevents the theft itself.

Q20 | Green IT

Which of the following corresponds to a green IT initiative?

  1. Introducing a device that detects unauthorized access to servers
  2. Establishing a backup center at a remote site in preparation for system failures
  3. Storing important data spread across multiple media
  4. Consolidating multiple servers into one using virtualization to reduce power consumption
AnswerD. Consolidating multiple servers into one using virtualization to reduce power consumption

Green IT reduces the environmental impact of manufacturing, using, and disposing of IT equipment, for example by adopting power-saving devices or consolidating machines through virtualization. Detecting unauthorized access is an information security measure, and remote backup centers and distributed data storage are business continuity and disaster measures; they do not aim at reducing environmental impact.

Q21 | Surge protection

Which measure protects equipment from the momentary abnormal high voltage that lightning induces on power and communication lines?

  1. Keeping temperature and humidity constant with the server room's air conditioning
  2. Duplicating critical equipment in a redundant configuration so that service continues even when a unit fails
  3. Bolting server racks to the floor to prevent them from toppling
  4. Installing surge protection devices such as arresters and surge protectors
AnswerD. Installing surge protection devices such as arresters and surge protectors

The momentary abnormal high voltage caused by lightning and the like is called a surge, and surge protection devices, arresters and surge protectors, divert it away from equipment. Fixing racks is an earthquake measure, humidity control prevents static electricity and condensation, and duplicating equipment is redundancy for continuing service during failures; none of these guards against the surge itself.

Q22 | Audit purpose

Which of the following is the most appropriate purpose of a system audit?

  1. To inspect and evaluate whether the risks related to information systems are properly managed, and to advise on improvements
  2. To train information system users in operation and raise their proficiency
  3. To restore information system failures quickly and minimize the impact on business
  4. To design new functions for information systems and draw up development plans
AnswerA. To inspect and evaluate whether the risks related to information systems are properly managed, and to advise on improvements

A system audit inspects and evaluates, from an independent position, whether information systems are operated safely, effectively, and efficiently and whether the related risks are properly managed, and it advises on improvements. Designing and planning development belongs to the development department, quick failure recovery to incident management, and user education to the operations department; none is the purpose of an audit.

Q23 | Audit procedure

Which of the following puts the steps of a system audit in the appropriate order?

  1. Preliminary survey, then audit planning, then main survey, then audit report, then follow-up
  2. Audit planning, then main survey, then preliminary survey, then follow-up, then audit report
  3. Main survey, then preliminary survey, then audit planning, then audit report, then follow-up
  4. Audit planning, then preliminary survey, then main survey, then audit report, then follow-up
AnswerD. Audit planning, then preliminary survey, then main survey, then audit report, then follow-up

A system audit first draws up the audit plan, grasps the overall picture of the target in the preliminary survey to narrow down the key areas, gathers audit evidence and reaches conclusions in the main survey, reports in the audit report, and then confirms the state of improvements in the follow-up. The other options either survey before planning or reverse the order of reporting and follow-up, so they are wrong.

Q24 | Auditor independence

Which of the following is the most appropriate statement about the independence required of a system auditor?

  1. Systems in whose development or operation the auditor was personally involved must not be taken as audit targets
  2. By also handling the operation of the audited system, the auditor can grasp its actual state accurately
  3. The auditor must decide the audit items according to the instructions of the audited department's manager
  4. Audits must always be commissioned to an external audit firm and cannot be performed by in-house staff
AnswerA. Systems in whose development or operation the auditor was personally involved must not be taken as audit targets

An auditor must be independent of the audited department; auditing a system one was involved in would mean evaluating one's own work and would destroy objectivity, so it is not allowed. Concurrently operating the system is inappropriate for the same reason. Deciding audit items on the audited department's instructions also violates independence. As long as independence is secured, in-house staff such as an internal audit department can perform audits, so the claim that they must be external is also wrong.

Q25 | Audit trail

Which of the following is the most appropriate description of an audit trail?

  1. A document defining in advance the purpose, scope, and timing of the audit
  2. A document compiling the findings identified in the audit and advice for improvement, prepared for reporting to management
  3. Records such as processing logs and approval records that make it possible to trace afterwards when, by whom, and what processing was performed
  4. An improvement plan prepared by the audited department in response to the findings
AnswerC. Records such as processing logs and approval records that make it possible to trace afterwards when, by whom, and what processing was performed

An audit trail consists of records such as processing logs, input slips, approval records, and change histories that allow the course of processing to be traced and verified afterwards, supporting the auditor's judgments. The document compiling audit results is the audit report, the document defining scope and timing in advance is the audit plan, and the improvement plan is a document made by the audited department; none of these is the audit trail itself.

Q26 | Follow-up

Which of the following is the most appropriate description of the auditor's follow-up in a system audit?

  1. The auditor personally fixes the programs in order to resolve the deficiencies pointed out
  2. The auditor draws up the improvement plan for the findings and orders the audited department to carry it out
  3. The auditor withholds preparation and submission of the audit report until the improvements are complete
  4. The auditor confirms at a later date whether the audited department is implementing improvements for the findings
AnswerD. The auditor confirms at a later date whether the audited department is implementing improvements for the findings

Follow-up is the activity in which the auditor later confirms whether improvements have been implemented for the matters pointed out in the audit report. Responsibility for implementing improvements lies with the audited department, and if the auditor did the fixing personally, independence would be lost. The auditor's position is to advise, not to command, and the audit report is submitted without waiting for improvements to finish.

Q27 | Segregation of duties

Which of the following is the most appropriate action based on the idea of segregation of duties in internal control?

  1. Omitting the approval procedure and switching to after-the-fact reporting to reduce the staff's burden
  2. Giving a single person combined authority from data entry through approval so that processing is not delayed
  3. Making the person who enters payment data and the person who approves it different people
  4. Giving everyone the same authority so that anyone can stand in for any task
AnswerC. Making the person who enters payment data and the person who approves it different people

Segregation of duties divides roles rather than concentrating authority in one person, so that mutual checks operate; separating the person who enters from the person who approves is a classic example. Giving one person combined authority, omitting approval, or giving everyone the same authority all create situations where fraud or error can be completed single-handedly, which is inappropriate for internal control.

Q28 | IT governance

Which of the following is the most appropriate description of IT governance?

  1. Management giving direction to the use of IT in line with the business strategy, monitoring its execution, and putting in place a mechanism to correct it when necessary
  2. Systematically developing, through training, staff who are proficient in operating information systems
  3. Maintaining, through inspections, the power and air-conditioning facilities needed to run information systems
  4. Defining in advance the procedures for informing users of the status and expected recovery time when an information system failure occurs
AnswerA. Management giving direction to the use of IT in line with the business strategy, monitoring its execution, and putting in place a mechanism to correct it when necessary

IT governance refers to the responsibility and mechanisms by which management directs the use of IT in line with business strategy, monitors execution, and corrects it when needed. Preparing failure communication procedures is an incident-management operating procedure, developing staff is human resource management, and maintaining power and air conditioning is facility management; none of these is the management-level control mechanism itself.

Practice: answer the questions on this page

This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.

* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.

This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original