Which of the following is the most appropriate description of ITIL?
An international standard defining software quality characteristics
An international standard compiling the body of knowledge of project management
A collection of best practices compiling successful cases in IT service management
An international standard defining the requirements for an information security management system
AnswerC. A collection of best practices compiling successful cases in IT service management
ITIL is a guide collecting practices that have produced results in IT service management, a best-practice collection that organizations consult when creating their own rules. Requirements for an information security management system correspond to JIS Q 27001, that is ISO/IEC 27001; the project management body of knowledge to PMBOK and ISO 21500; and software quality characteristics to JIS X 25010 and the like; none of these is ITIL.
Q2 | SLA
Which of the following is the most appropriate item to include in an SLA, a service level agreement?
That the monthly system availability shall be at least 99.5%
That every effort shall be made to raise user satisfaction as much as possible
The details of the service provider's internal personnel evaluation system
The programming languages to be used in system development
AnswerA. That the monthly system availability shall be at least 99.5%
An SLA is a document that sets the level of service quality in a form that allows objective judgment of whether it was achieved. An availability of at least 99.5% can be measured and verified numerically, so it is appropriate. Making every effort cannot be measured and does not function as an agreement, and the languages used in development or the provider's personnel system are not levels of service quality, so they are not appropriate SLA items.
Q3 | SLM
Which of the following is the most appropriate activity of SLM, service level management?
Measuring and recording the service level only when a failure occurs
Regularly measuring and evaluating actual service levels and implementing improvements as needed
Automatically lowering the SLA figures to match the actual results whenever the service level is not achieved
Concluding the SLA when the service starts and operating thereafter without reviewing its content
AnswerB. Regularly measuring and evaluating actual service levels and implementing improvements as needed
SLM is the activity of maintaining and improving the levels agreed in the SLA by regularly measuring and evaluating results and continuing improvement through the PDCA cycle. Operating without reviews after conclusion, or measuring only at failures, does not amount to continuous quality management. Mechanically lowering targets to match results when they are missed is not improvement, and it would also require agreement with the users, so it is wrong.
Q4 | Service desk
Which of the following is the most appropriate role of a service desk, also called a help desk?
Deciding the allocation of next year's IT investment budget based on the company's medium-term management plan
Deciding the hiring of staff needed by the information systems department and their assignments within it
Interviewing users about their business needs, performing requirements definition, and writing specifications for development
Serving as the single point of contact that receives user inquiries and failure reports, keeping records and managing the progress of responses
AnswerD. Serving as the single point of contact that receives user inquiries and failure reports, keeping records and managing the progress of responses
The service desk is the single point of contact that receives inquiries, failure reports, and requests from users, recording what is received and managing progress until resolution. Requirements definition belongs to development, hiring and assignment to human resources, and IT investment budgeting to executives or the IT strategy division; none of these is the service desk's role.
Q5 | Incident management
What is the main purpose of incident management?
To restore an interrupted service as quickly as possible and minimize the impact on business
To assess the impact of change requests to the system and approve or reject their implementation
To record configuration item information accurately and keep it up to date
To identify the root cause of incidents and implement permanent countermeasures
AnswerA. To restore an interrupted service as quickly as possible and minimize the impact on business
The purpose of incident management is rapid service restoration: even when the cause is not fully understood, it prioritizes resuming business through workarounds, restarts, and the like. Removing root causes is problem management, assessing and approving changes is change management, and maintaining configuration information is configuration management; each is a separate process.
Q6 | Problem management
The same failure has been recurring every month. Which of the following is the most appropriate activity to prevent its recurrence?
Preparing procedures to restart the server and recover quickly each time the failure occurs
Totaling the number of reported failures and increasing service desk staff
Investigating and identifying the root cause of the failure and implementing a permanent fix that removes it
Preparing in advance the text of the e-mail used to notify users when the failure occurs
AnswerC. Investigating and identifying the root cause of the failure and implementing a permanent fix that removes it
Preventing recurrence is the role of problem management, which identifies the root cause and implements a permanent fix that removes it. Preparing restart procedures, drafting notification text, and adding staff are incident-management measures that speed up responses or spread the load; the cause itself remains, so they do not prevent recurrence.
Q7 | Release management
Which activity reliably deploys approved changes into the production environment according to plan and puts them into operation?
Problem management
Release management
Incident management
Availability management
AnswerB. Release management
Deploying approved changes into the production environment and putting them into operation is release management. Incident management aims at rapid service restoration, problem management at removing root causes, and availability management at keeping the service usable at the agreed level; none of them is the process responsible for deployment into production.
Q8 | Escalation
Which of the following is the most appropriate description of escalation at a service desk?
Holding training sessions to teach users how to operate the system
Totaling and reporting the number of inquiries received and the time taken to handle them
Handing over cases that the person in charge cannot solve to specialist engineers or higher-level managers
Publishing frequently asked questions and their answers as an FAQ on a website
AnswerC. Handing over cases that the person in charge cannot solve to specialist engineers or higher-level managers
Escalation is the mechanism by which first-line staff hand over cases they cannot solve to more specialized staff or higher-level managers, ensuring the cases are resolved. Publishing an FAQ supports users' self-service, totaling case counts is performance reporting, and holding training is user education; none of these is escalation.
Q9 | Differential backup
Which of the following is the most appropriate description of a differential backup?
Copying all of the data in its entirety every time
Writing changed data to another disk in duplicate in real time
Copying, all together each time, the data changed since the last full backup
Copying only the data changed since the immediately preceding backup, whether full or incremental
AnswerC. Copying, all together each time, the data changed since the last full backup
A differential backup copies, each time, everything changed since the last full backup, which serves as the baseline. Taking only the changes since the immediately preceding backup is an incremental backup, copying everything every time is a full backup, and real-time duplicate writing is mirroring, RAID 1; none of these is a differential backup.
Q10 | Incremental restore
A full backup is taken on Sunday, and incremental backups are taken every day from Monday through Saturday. If a disk failure occurs right after the backup taken at the end of business on Thursday, which combination of backup media is needed to restore the data?
Only the incremental backup taken on Thursday
Sunday's full backup plus the incremental backups from Monday, Tuesday, Wednesday, and Thursday
Only the full backup taken on Sunday and the incremental backup taken at the end of business on Thursday
Only the incremental backups taken from Monday through Thursday
AnswerB. Sunday's full backup plus the incremental backups from Monday, Tuesday, Wednesday, and Thursday
An incremental backup holds only the changes since the immediately preceding backup, so after restoring the full backup you must apply every incremental taken since then, oldest first. Therefore Sunday's full backup and the four incrementals from Monday through Thursday are needed. Incrementals alone do not contain all the data, and the full backup plus only Thursday's incremental would lose the changes from Monday through Wednesday; that combination would be correct for differential backups.
Q11 | Differential restore
A full backup is taken on Sunday, and differential backups are taken every day from Monday onward. If a failure occurs right after Thursday's differential backup is taken, how many backup media are needed for the restore?
4
1
5
2
AnswerD. 2
A differential backup contains all changes since the last full backup, so the newest differential alone consolidates all changes up to that point. Therefore Sunday's full backup and Thursday's differential, 2 media in total, are enough to restore. With 1 medium you would have only the full or only the differential, which is insufficient. 5 media would be needed with incremental backups, one full plus four incrementals from Monday through Thursday, and 4 matches the required count of no method.
Q12 | Backup size
For the same target data, which of the following is the most appropriate statement about the time and data volume required for a single backup run?
Differential backup takes the most and incremental backup the least
All three methods require the same time and data volume
Full backup takes the most and incremental backup the least
Incremental backup takes the most and full backup the least
AnswerC. Full backup takes the most and incremental backup the least
A full backup, which copies everything every time, takes the most, and an incremental backup, which takes only the changes since the immediately preceding backup, takes the least. A differential falls in between. Note that restore time runs in the opposite order: full is the shortest and incremental the longest. It is important to read carefully whether the question asks about backup time or restore time.
Q13 | Job management
Which of the following is the most appropriate role of job management, that is, a job scheduler?
Setting, for each user, the range of accessible files and the operations permitted on them
Performing unit tests to find errors in programs
Defining in advance the execution order and times of multiple processes, and starting and monitoring them automatically
Measuring network traffic and controlling bandwidth
AnswerC. Defining in advance the execution order and times of multiple processes, and starting and monitoring them automatically
Job management defines as jobs the processes that should run in a fixed order and at fixed times, such as overnight batches, and provides automatic startup, execution monitoring, and notification of abnormal endings. Setting access rights is access management, measuring traffic and controlling bandwidth is network management, and running unit tests is development work; none of these is the role of job management.
Q14 | System migration
Which of the following is the most appropriate characteristic of the big-bang approach to system migration, in which everything is switched over at once?
Because departments or operations are switched over one by one, the migration period tends to become long
The old and new systems run in parallel for a certain period, and results are cross-checked during the migration
Because the old system's data is not used after the migration, no data migration work is needed
The migration can be completed quickly and cheaply, but when a problem occurs its impact extends to the whole
AnswerD. The migration can be completed quickly and cheaply, but when a problem occurs its impact extends to the whole
The big-bang approach switches the whole system over to the new one at a single point in time; the migration period is short and costs are low, but a defect affects the entire company. Running old and new at the same time is parallel operation, and switching over in sequence is phased migration. Whatever the approach, migrating the old system's data is normally necessary and never becomes unnecessary.
Q15 | Operations management
Which of the following is a routine task performed as system operations management?
Monitoring server operation and resource utilization, and collecting and retaining logs
Interviewing user departments about the functions required of a new system and compiling a requirements document
Reviewing the source code of developed programs and pointing out errors
Deciding the priorities of IT investment based on the company's management strategy
AnswerA. Monitoring server operation and resource utilization, and collecting and retaining logs
System operations management covers the daily work that keeps a system running stably, such as monitoring operation, tracking resource usage, collecting and retaining logs, and taking backups. Requirements definition and code review are phases of system development, and prioritizing IT investment is a management and IT-strategy activity; none of these is operations management work.
Q16 | UPS
What is the main purpose of installing a UPS, an uninterruptible power supply?
To switch automatically to a wireless line when the communication line is cut
To write data to multiple disks in duplicate in preparation for disk failures
To supply power for a certain time when a power outage occurs, securing time to shut the system down safely
To keep the server room's temperature and humidity constant and prevent equipment failures
AnswerC. To supply power for a certain time when a power outage occurs, securing time to shut the system down safely
A UPS uses its internal battery to supply power for a short time during an outage, buying time to save data and shut the system down normally, or to hand over to a private generator. Switching lines is line redundancy, maintaining temperature and humidity is the job of air conditioning, and duplicate writing to disks is mirroring, RAID 1; none of these is the purpose of a UPS.
Q17 | Private generator
A lightning strike caused a power outage lasting several hours over a wide area. Which piece of equipment is needed to keep the business systems running during this time?
A private power generator
A security cable
A UPS, an uninterruptible power supply, alone
A surge protector
AnswerA. A private power generator
To cope with an outage lasting hours, a private power generator that can keep generating from fuel is needed. A UPS battery typically supplies power for only minutes to tens of minutes, serving merely as a bridge until a safe shutdown or a handover to the generator. A surge protector guards equipment against abnormal high voltage, and a security cable is an anti-theft device; neither can supply power during an outage.
Q18 | Tailgating
In a room using IC-card entry control, which of the following is the most appropriate measure against tailgating, where someone enters behind an authorized user without being authenticated?
Having users change their IC card passwords regularly
Retaining the IC card reading records at entry for one year
Fastening the PCs in the room with security cables
Introducing anti-passback, which refuses exit to anyone who has no entry record
AnswerD. Introducing anti-passback, which refuses exit to anyone who has no entry record
Anti-passback is a mechanism that refuses exit to a person with no entry record, or the reverse, so it can detect and deter tailgaters who entered without authenticating. Retaining reading records helps with tracing afterwards but does not prevent tailgating itself, changing passwords only strengthens personal authentication, and security cables prevent equipment theft and cannot control entry.
Q19 | Theft prevention
Which of the following is the most appropriate physical measure to prevent the theft of laptop PCs installed in an office?
Using biometric authentication at login
Fastening the laptops to the desks with security cables
Applying the latest security patches to the OS
Encrypting the contents of the hard disks
AnswerB. Fastening the laptops to the desks with security cables
A security cable fastens the unit to a desk or pillar with a wire, making it physically difficult to carry away, which is a theft-prevention measure. Encryption and biometric authentication prevent information leakage after a theft, and applying security patches counters attacks that exploit vulnerabilities; none of these prevents the theft itself.
Q20 | Green IT
Which of the following corresponds to a green IT initiative?
Introducing a device that detects unauthorized access to servers
Establishing a backup center at a remote site in preparation for system failures
Storing important data spread across multiple media
Consolidating multiple servers into one using virtualization to reduce power consumption
AnswerD. Consolidating multiple servers into one using virtualization to reduce power consumption
Green IT reduces the environmental impact of manufacturing, using, and disposing of IT equipment, for example by adopting power-saving devices or consolidating machines through virtualization. Detecting unauthorized access is an information security measure, and remote backup centers and distributed data storage are business continuity and disaster measures; they do not aim at reducing environmental impact.
Q21 | Surge protection
Which measure protects equipment from the momentary abnormal high voltage that lightning induces on power and communication lines?
Keeping temperature and humidity constant with the server room's air conditioning
Duplicating critical equipment in a redundant configuration so that service continues even when a unit fails
Bolting server racks to the floor to prevent them from toppling
Installing surge protection devices such as arresters and surge protectors
AnswerD. Installing surge protection devices such as arresters and surge protectors
The momentary abnormal high voltage caused by lightning and the like is called a surge, and surge protection devices, arresters and surge protectors, divert it away from equipment. Fixing racks is an earthquake measure, humidity control prevents static electricity and condensation, and duplicating equipment is redundancy for continuing service during failures; none of these guards against the surge itself.
Q22 | Audit purpose
Which of the following is the most appropriate purpose of a system audit?
To inspect and evaluate whether the risks related to information systems are properly managed, and to advise on improvements
To train information system users in operation and raise their proficiency
To restore information system failures quickly and minimize the impact on business
To design new functions for information systems and draw up development plans
AnswerA. To inspect and evaluate whether the risks related to information systems are properly managed, and to advise on improvements
A system audit inspects and evaluates, from an independent position, whether information systems are operated safely, effectively, and efficiently and whether the related risks are properly managed, and it advises on improvements. Designing and planning development belongs to the development department, quick failure recovery to incident management, and user education to the operations department; none is the purpose of an audit.
Q23 | Audit procedure
Which of the following puts the steps of a system audit in the appropriate order?
Preliminary survey, then audit planning, then main survey, then audit report, then follow-up
Audit planning, then main survey, then preliminary survey, then follow-up, then audit report
Main survey, then preliminary survey, then audit planning, then audit report, then follow-up
Audit planning, then preliminary survey, then main survey, then audit report, then follow-up
AnswerD. Audit planning, then preliminary survey, then main survey, then audit report, then follow-up
A system audit first draws up the audit plan, grasps the overall picture of the target in the preliminary survey to narrow down the key areas, gathers audit evidence and reaches conclusions in the main survey, reports in the audit report, and then confirms the state of improvements in the follow-up. The other options either survey before planning or reverse the order of reporting and follow-up, so they are wrong.
Q24 | Auditor independence
Which of the following is the most appropriate statement about the independence required of a system auditor?
Systems in whose development or operation the auditor was personally involved must not be taken as audit targets
By also handling the operation of the audited system, the auditor can grasp its actual state accurately
The auditor must decide the audit items according to the instructions of the audited department's manager
Audits must always be commissioned to an external audit firm and cannot be performed by in-house staff
AnswerA. Systems in whose development or operation the auditor was personally involved must not be taken as audit targets
An auditor must be independent of the audited department; auditing a system one was involved in would mean evaluating one's own work and would destroy objectivity, so it is not allowed. Concurrently operating the system is inappropriate for the same reason. Deciding audit items on the audited department's instructions also violates independence. As long as independence is secured, in-house staff such as an internal audit department can perform audits, so the claim that they must be external is also wrong.
Q25 | Audit trail
Which of the following is the most appropriate description of an audit trail?
A document defining in advance the purpose, scope, and timing of the audit
A document compiling the findings identified in the audit and advice for improvement, prepared for reporting to management
Records such as processing logs and approval records that make it possible to trace afterwards when, by whom, and what processing was performed
An improvement plan prepared by the audited department in response to the findings
AnswerC. Records such as processing logs and approval records that make it possible to trace afterwards when, by whom, and what processing was performed
An audit trail consists of records such as processing logs, input slips, approval records, and change histories that allow the course of processing to be traced and verified afterwards, supporting the auditor's judgments. The document compiling audit results is the audit report, the document defining scope and timing in advance is the audit plan, and the improvement plan is a document made by the audited department; none of these is the audit trail itself.
Q26 | Follow-up
Which of the following is the most appropriate description of the auditor's follow-up in a system audit?
The auditor personally fixes the programs in order to resolve the deficiencies pointed out
The auditor draws up the improvement plan for the findings and orders the audited department to carry it out
The auditor withholds preparation and submission of the audit report until the improvements are complete
The auditor confirms at a later date whether the audited department is implementing improvements for the findings
AnswerD. The auditor confirms at a later date whether the audited department is implementing improvements for the findings
Follow-up is the activity in which the auditor later confirms whether improvements have been implemented for the matters pointed out in the audit report. Responsibility for implementing improvements lies with the audited department, and if the auditor did the fixing personally, independence would be lost. The auditor's position is to advise, not to command, and the audit report is submitted without waiting for improvements to finish.
Q27 | Segregation of duties
Which of the following is the most appropriate action based on the idea of segregation of duties in internal control?
Omitting the approval procedure and switching to after-the-fact reporting to reduce the staff's burden
Giving a single person combined authority from data entry through approval so that processing is not delayed
Making the person who enters payment data and the person who approves it different people
Giving everyone the same authority so that anyone can stand in for any task
AnswerC. Making the person who enters payment data and the person who approves it different people
Segregation of duties divides roles rather than concentrating authority in one person, so that mutual checks operate; separating the person who enters from the person who approves is a classic example. Giving one person combined authority, omitting approval, or giving everyone the same authority all create situations where fraud or error can be completed single-handedly, which is inappropriate for internal control.
Q28 | IT governance
Which of the following is the most appropriate description of IT governance?
Management giving direction to the use of IT in line with the business strategy, monitoring its execution, and putting in place a mechanism to correct it when necessary
Systematically developing, through training, staff who are proficient in operating information systems
Maintaining, through inspections, the power and air-conditioning facilities needed to run information systems
Defining in advance the procedures for informing users of the status and expected recovery time when an information system failure occurs
AnswerA. Management giving direction to the use of IT in line with the business strategy, monitoring its execution, and putting in place a mechanism to correct it when necessary
IT governance refers to the responsibility and mechanisms by which management directs the use of IT in line with business strategy, monitors execution, and corrects it when needed. Preparing failure communication procedures is an incident-management operating procedure, developing staff is human resource management, and maintaining power and air conditioning is facility management; none of these is the management-level control mechanism itself.
Practice: answer the questions on this page
This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.
* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.
This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original