A problem management team is asked how problems come to be identified in the first place. Which answer best reflects the practice as ITIL describes it?
ITIL 4 Foundation, objective 7. Seven ITIL practices in detail medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Not correct Automatically, whenever an incident exceeds its agreed target resolution time
A breached target says the incident was slow to resolve, which may have many causes. It is not evidence that a distinct underlying cause has been identified.
Not correct Only once at least one incident has been recorded and closed against the underlying fault
This drops the 'potential causes' half of the purpose. A problem may be identified from a supplier advisory or a monitoring trend without any incident having happened.
Not correct By the service desk, at the point a user reports that a service has been interrupted
That describes how an incident is captured. Problem identification is analytical work performed on records and other information, not a report taken at the point of contact.
Correct By analysing incident records and trends, and also by proactively examining other information such as supplier notifications and monitoring data, before any incident has occurred
Correct. The purpose refers to actual and potential causes, so identification is both reactive, from incidents already seen, and proactive, from information that suggests a cause that has not yet bitten.
Why
Problem identification is a distinct phase, ahead of problem control and error control, and it draws on more than the incident log. Treating it as purely reactive is the common mistake, and it is the reason 'potential causes' appears in the purpose statement alongside 'actual causes'.
Where this comes from
- Cited
- ITIL 4 syllabus clause 7
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 7 and space the ones you get wrong.
More questions on this objective
- Which statement best describes what the incident management practice is intended to achieve? machine-checked
- How is an incident defined in ITIL? machine-checked
- Several incidents are open at once and the support team must decide which to work on first. On what basis should the order be decided? machine-checked
- A difficult incident is worked on by pulling several specialists from different teams into the same session at the same time; once it becomes clear who is best placed to continue, the others step away. What is this technique called? machine-checked
- Why does an organisation define a separate procedure for major incidents rather than handling them exactly like all other incidents? machine-checked
- A support team routinely fixes incidents by phone and updates the incident record only with the word 'fixed'. What is the most significant consequence of this? machine-checked