A business application fails for the third time this month. The service desk restarts it, users get back to work within ten minutes, and nobody knows why it keeps failing. Which combination correctly describes what has happened and what should happen next?
ITIL 4 Foundation, objective 7. Seven ITIL practices in detail hard
Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.
It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.
The options
Not correct The failures are incidents that must remain open until the cause is found, because an incident is not resolved while its cause is unknown
Resolution in incident management means service is working again, not that the cause is understood. Keeping incidents open pending diagnosis would misreport restoration performance and blur the two practices together.
Correct Each failure is an incident that incident management has resolved; the repeated cause should now be handled by problem management
Correct. Service has been restored each time, which is the whole obligation of incident management. The unknown recurring cause is precisely what problem management exists to identify, and the recurrence is a classic trigger for problem identification.
Not correct The recurrence should be logged as a service request so that the application team investigates it under an agreed workflow
A service request is a pre-agreed, routine service action. An investigation into an unknown cause is neither pre-defined nor routine, and routing it this way would remove it from problem management's view.
Not correct The third failure should be reclassified as a problem, replacing the incident record
A problem does not replace an incident; the two coexist. The incident records the loss of service to users and its restoration, while a separate problem record owns the cause and any resulting workaround or known error.
Why
Incidents and problems are separate records with separate lifecycles running in parallel. Restoring service closes the incident; the recurring, undiagnosed cause is a problem, and if analysis explains it without resolving it, the outcome is a known error with a documented workaround that will speed up any future incident.
Where this comes from
- Cited
- ITIL 4 syllabus clause 7
- What it says
- A problem is a cause, or potential cause, of one or more incidents; incident management restores service while problem management addresses the cause.
Practise this
Reading one question is not practice. The trainer will draw a set from objective 7 and space the ones you get wrong.