Which statement best describes what the incident management practice is intended to achieve?
ITIL 4 Foundation, objective 7. Seven ITIL practices in detail easy
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct Minimise the negative impact of incidents by restoring normal service operation as quickly as possible
Correct. The practice is defined around impact reduction through speed of restoration. Note that it is restoration of service that matters, not necessarily the removal of the underlying cause.
Not correct Reduce the likelihood and impact of incidents by identifying their actual and potential causes
This is problem management. Incident management is concerned with getting the service working again now; cause analysis is deliberately assigned to a separate practice so that restoration is never delayed by investigation.
Not correct Handle all pre-defined, user-initiated service requests in an effective and user-friendly way
This is service request management. Service requests are normal, agreed parts of service delivery, not unplanned interruptions, so they fall outside incident management.
Not correct Maximise the number of successful service and product changes by assessing risk before authorisation
This is change enablement. A change may well be needed to fix something permanently, but authorising changes is not what incident management exists to do.
Why
Incident management is judged on how quickly agreed service levels are restored to users. That is why workarounds are acceptable outcomes: a restored service with an unknown cause is a successful incident resolution, and the cause is then owned by problem management.
Where this comes from
- Cited
- ITIL 4 syllabus clause 7
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 7 and space the ones you get wrong.
More questions on this objective
- How is an incident defined in ITIL? machine-checked
- Several incidents are open at once and the support team must decide which to work on first. On what basis should the order be decided? machine-checked
- A difficult incident is worked on by pulling several specialists from different teams into the same session at the same time; once it becomes clear who is best placed to continue, the others step away. What is this technique called? machine-checked
- Why does an organisation define a separate procedure for major incidents rather than handling them exactly like all other incidents? machine-checked
- A support team routinely fixes incidents by phone and updates the incident record only with the word 'fixed'. What is the most significant consequence of this? machine-checked
- The service desk cannot resolve an incident with the information available to it. According to the incident management practice, what should normally determine where the incident goes next? machine-checked