A business application fails for the third time this month. The service desk restarts it, users get back to work within ten minutes, and nobody knows why it keeps failing. Which combination correctly describes what has happened and what should happen next?
ITIL 4 Foundation, objective 7. Seven ITIL practices in detail hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Not correct The failures are incidents that must remain open until the cause is found, because an incident is not resolved while its cause is unknown
Resolution in incident management means service is working again, not that the cause is understood. Keeping incidents open pending diagnosis would misreport restoration performance and blur the two practices together.
Correct Each failure is an incident that incident management has resolved; the repeated cause should now be handled by problem management
Correct. Service has been restored each time, which is the whole obligation of incident management. The unknown recurring cause is precisely what problem management exists to identify, and the recurrence is a classic trigger for problem identification.
Not correct The recurrence should be logged as a service request so that the application team investigates it under an agreed workflow
A service request is a pre-agreed, routine service action. An investigation into an unknown cause is neither pre-defined nor routine, and routing it this way would remove it from problem management's view.
Not correct The third failure should be reclassified as a problem, replacing the incident record
A problem does not replace an incident; the two coexist. The incident records the loss of service to users and its restoration, while a separate problem record owns the cause and any resulting workaround or known error.
Why
Incidents and problems are separate records with separate lifecycles running in parallel. Restoring service closes the incident; the recurring, undiagnosed cause is a problem, and if analysis explains it without resolving it, the outcome is a known error with a documented workaround that will speed up any future incident.
Where this comes from
- Cited
- ITIL 4 syllabus clause 7
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 7 and space the ones you get wrong.
More questions on this objective
- Which statement best describes what the incident management practice is intended to achieve? machine-checked
- How is an incident defined in ITIL? machine-checked
- Several incidents are open at once and the support team must decide which to work on first. On what basis should the order be decided? machine-checked
- A difficult incident is worked on by pulling several specialists from different teams into the same session at the same time; once it becomes clear who is best placed to continue, the others step away. What is this technique called? machine-checked
- Why does an organisation define a separate procedure for major incidents rather than handling them exactly like all other incidents? machine-checked
- A support team routinely fixes incidents by phone and updates the incident record only with the word 'fixed'. What is the most significant consequence of this? machine-checked