A business application fails for the third time this month. The service desk restarts it, users get back to work within ten minutes, and nobody knows why it keeps failing. Which combination correctly describes what has happened and what should happen next?

ITIL 4 Foundation, objective 7. Seven ITIL practices in detail hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Not correct The failures are incidents that must remain open until the cause is found, because an incident is not resolved while its cause is unknown

Resolution in incident management means service is working again, not that the cause is understood. Keeping incidents open pending diagnosis would misreport restoration performance and blur the two practices together.

Correct Each failure is an incident that incident management has resolved; the repeated cause should now be handled by problem management

Correct. Service has been restored each time, which is the whole obligation of incident management. The unknown recurring cause is precisely what problem management exists to identify, and the recurrence is a classic trigger for problem identification.

Not correct The recurrence should be logged as a service request so that the application team investigates it under an agreed workflow

A service request is a pre-agreed, routine service action. An investigation into an unknown cause is neither pre-defined nor routine, and routing it this way would remove it from problem management's view.

Not correct The third failure should be reclassified as a problem, replacing the incident record

A problem does not replace an incident; the two coexist. The incident records the loss of service to users and its restoration, while a separate problem record owns the cause and any resulting workaround or known error.

Why

Incidents and problems are separate records with separate lifecycles running in parallel. Restoring service closes the incident; the recurring, undiagnosed cause is a problem, and if analysis explains it without resolving it, the outcome is a known error with a documented workaround that will speed up any future incident.

Where this comes from

Cited
ITIL 4 syllabus clause 7

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 7 and space the ones you get wrong.

Practise ITIL 4 Foundation

More questions on this objective

All questions on Seven ITIL practices in detail

Practise ITIL 4 Foundation