A team repeatedly provisions a new laptop for a joiner using a fully documented, well-rehearsed procedure whose risk was assessed once when the procedure was written. How should each individual provisioning be handled?
ITIL 4 Foundation, objective 7. Seven ITIL practices in detail medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct As a standard change, implemented under the authorisation already granted to the documented procedure
Correct. A standard change is pre-authorised: the risk assessment and authorisation were done once, for the procedure, so each instance needs no fresh authorisation.
Not correct As a normal change, assessed and authorised individually each time it is requested
Wrong. Putting a low-risk, repeatable, fully documented activity through individual assessment is exactly the waste that the standard change type exists to remove.
Not correct As a standard change, but with the change authority re-confirming authorisation on each occurrence
Wrong, and this is the most tempting distractor. Re-authorising each occurrence contradicts the meaning of 'pre-authorised' and would make the standard change type pointless.
Not correct As an emergency change, because provisioning must be completed before the joiner's start date
Wrong. A known deadline is not an emergency. Emergency changes are for situations that must be resolved as soon as possible, such as restoring a service or applying an urgent security fix.
Why
Standard changes are low-risk, well-understood, fully documented and pre-authorised. The risk assessment happens once, when the procedure is created and approved; individual instances then proceed without further authorisation, and are often initiated as service requests. Requiring per-instance authorisation would defeat the purpose of the category.
Where this comes from
- Cited
- ITIL 4 syllabus clause 7
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 7 and space the ones you get wrong.
More questions on this objective
- Which statement best describes what the incident management practice is intended to achieve? machine-checked
- How is an incident defined in ITIL? machine-checked
- Several incidents are open at once and the support team must decide which to work on first. On what basis should the order be decided? machine-checked
- A difficult incident is worked on by pulling several specialists from different teams into the same session at the same time; once it becomes clear who is best placed to continue, the others step away. What is this technique called? machine-checked
- Why does an organisation define a separate procedure for major incidents rather than handling them exactly like all other incidents? machine-checked
- A support team routinely fixes incidents by phone and updates the incident record only with the word 'fixed'. What is the most significant consequence of this? machine-checked