wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Business Processes Preparedness

Total questions: 153

Worksheet time: 2hrs 8mins

Name
Class
Date
1.

A series of tasks that are completed in order to accomplish a goal.

a)

Process

b)

People

c)

Hardware

d)

Software

e)

Data

2.

What does “ERP” stand for?

a)

entrepreneur resource planning

b)

enterprise resource planning

c)

enterprise resource planting

d)

enterprise relevant planning

3.

Which is not the benefit of a business process management?

a)

Empowering employees

b)

Built-in reporting

c)

Enforcing best practices

d)

Enforcing inconsistency

4.

One of the criticisms of an ERP system has got is that ....

a)

the processes an ERP applies are the processes the organization adopts.

b)

the implementation of an ERP system is an excellent opportunity to improve their business practices

c)

an ERP can be used to manage an entire organization’s operations

d)

an ERP system commoditizes business process.

5.
Which one of the following is the best definition of a standard operating procedure (SOP)?
a)
A procedure that is enforceable by the government.
b)
A procedure that must be followed by everyone.
c)
A procedure that is not written down in the company handbook.
d)
A procedure that is recognised internationally by the ISO.
6.
During which stage of the business system lifecycle will a new service be normally rolled out or an old one withdrawn?
a)
Strategy Stage.
b)
Design Stage.
c)
Transition Stage.
d)
Operations Stage.
7.
What is the main purpose of the service strategy stage in the Business System Lifecycle?
a)
To identify improvements to a service in business operations.
b)
To discontinue a current service that is no longer needed.
c)
To hold a strategic service meeting for all parties involved.
d)
To plan the services needed to meet business requirements.
8.
Which one of the following organisational procedures refers to the allocation of equipment to an employee?
a)
Configuration Management.
b)
Joiner Mover Leaver process.
c)
Organisational Management.
d)
Personal Asset Tracking.
9.
Which one of the following organisational procedures refers to the allocation of equipment to an employee?
a)
Configuration Management.
b)
Joiner Mover Leaver process.
c)
Organisational Management.
d)
Personal Asset Tracking.
10.
Why is undertaking an Internal Audit an important aspect of information security management?
a)
It gives management a way to improve health and safety.
b)
It allows management to detect any non-compliance.
c)
It gives management a way of eliminating waste.
d)
It enables management to reduce costs.
11.
What does the Data Protection Act 1998 require?
a)
All computer software must be kept safe.
b)
All computer systems must be secure.
c)
All personal information must be held securely.
d)
All business networks must have a firewall.
12.
Which one of the following would be the best way to securely hold a confidential data file on a laptop?
a)
Give it a misleading name.
b)
Hide it in a system folder.
c)
Encrypt it using suitable software.
d)
Hold it as a JPEG image.
13.
A database is retrieved from backup and it is found that some records were unreadable. What type of issue is this?
a)
Data availability.
b)
Data confidentiality.
c)
Data integrity.
d)
Data security.
14.
How can the availability of backed up data from a remote site be improved?
a)
Increasing communication bandwidth between sites.
b)
Introducing a DMZ to protect the LAN at the local site.
c)
Limiting file and folder permissions at the remote site.
d)
Opening more ports in the firewall at the local site.
15.
Which one of the following software applications would be the best way to send a design drawing to various manufacturers to get a quotation?
a)
An electronic mail system.
b)
A Computer Aided Design package (CAD).
c)
A Desk Top Publishing suite.
d)
A financial projection package.
16.
What is the primary purpose of a document management system?
a)
It allows users to create new documents.
b)
It allows controlled access to documents.
c)
It allows users to edit documents.
d)
It allows reduction in office printing costs.
17.
Which one of the following refers to a system designed to track and manage all contact with those who purchase goods and services from a business?
a)
Employee Management System.
b)
Production Management System.
c)
Customer Information System.
d)
Customer Relationship Management System.
18.
Which one of the following refers to a system designed to ensure that a production line doesn’t run out of component parts unexpectedly?
a)
A Management Information System.
b)
A Financial Reporting System.
c)
A Stock Control System.
d)
A Customer Relationship Management System.
19.
Which one of the following describes the best way to handle customer criticisms?
a)
Consult with a colleague.
b)
Accept personal responsibility.
c)
Ensure that a neutral person is present.
d)
Follow the company's complaints procedure.
20.
Which one of the following is a key aspect of stakeholder management?
a)
Ensuring all parties are kept informed.
b)
Involving the end users in decision making.
c)
Knowing who can effect change.
d)
Enabling senior managers to plan effectively.
21.
What is the method of Fault Analysis called when a suspect component is replaced by a known working component in order to test it?
a)
Replacement.
b)
Simulation.
c)
Restitution.
d)
Substitution.
22.
What is the purpose of end-to-end testing when validating complex systems?
a)
The cost of the whole system can be measured.
b)
The functionality of the whole system can be verified.
c)
The structure of each subsystem can be checked.
d)
The integrity of the database can be assessed.
23.
Which one of the following best describes the situation where a business was unable to trade after a fire at its premises?
a)
Failure in business change.
b)
Unsuccessful management buyout.
c)
Failure to plan for business continuity.
d)
Lack of financial consultancy.
24.
Which one of the following refers to the use of iris scanning to control physical access to a restricted area?
a)
Biometric screening.
b)
Social Engineering.
c)
Two factor authentication.
d)
Radio Frequency IDentification (RFID).
25.

Which is an example of PII? (Personally Identifiable Information)

a)

Credit Card Number

b)

Name

c)

Home Address

d)

All of the above

26.
What law makes organisations look after your personal data properly?
a)
Data Privacy Act
b)
Data Protection Act
c)
Data Protection Law
d)
Data Privacy Law
27.
Why was the Computer Misuse Act of 1990 introduced?
a)
To help protect computer software
b)
To help protect computer hardware
c)
To stop the spread of computer viruses
d)
To stop people from accessing unauthorised information. 
28.
What is gaining unauthorised access to a computer system also known as?
a)
Hacking
b)
Spamming
c)
Phishing
d)
Logging on
29.
Which of the following is NOT an offence under the Computer Misuse Act?
a)
unauthorised access to someone else's files
b)
unauthorised access to someone else's files with intent to commit further criminal offences
c)
copying software and trying to sell it to someone for a profit
d)
writing and distributing a virus
30.
What are the principles of the Computer Misuse Act?
a)
Authorised access,Authorised access with intent, Authorised 
b)
Unauthorised access with intent and Unauthorised modification
c)
Unauthorised access and Unauthorised modification
d)
Unauthorised access, Unauthorised access with intent, Unauthorised modification
31.

Employee Onboarding is the process of ....

a)

Directing new employees to their work place

b)

Directing new employees about the daily tasks

c)

Introducing new employees to the organization’s environment and culture

d)

Introducing new employees to explore work environment on their own

32.

Why efficient employee onboarding matters

a)

All organisations have it

b)

Is the first interaction an employee has with the organization

c)

To help your new hires settle down in their jobs

d)

It will help in managers to direct on tasks to do

33.

Why efficient employee onboarding matters -2

a)

A memorable onboarding experience makes employees feel welcome

b)

To complete the joining formalities

c)

To Managers to start dictating the job

d)

To know about the rules and regulations

34.

____ is a well-defined, formal process help desk staff follow to:

–Handle problem incidents

–Get information to users

–Solve user problems

–Maintain records about the incident

a)

Call management

b)

Incident management

c)

ITIL

d)

None of the above

35.

_____ determines whether help desk staff are authorised to handle an incident.

a)

Prescreening

b)

Authentication procedure

c)

Logging

d)

None of the above

36.

_____ is a normal process in which an incident is transferred to a higher level support agent.

a)

Tracking

b)

Resolution

c)

Escalation

d)

None of the above

37.

_____ is a contract that defines expected performance of user support services or external vendor-provided services.

a)

SLA

b)

Last will and testament

c)

Terms and conditions

d)

None of the above

38.

How do we tighten our security?

a)

Use strong password

b)

Only connect to trusted network

c)

Log-off network account when not in use

d)

All of the above

39.

What's included in a strong password?

a)

A minimum of eight characters

b)

At least one lowercase alphabetical letter (a-z)

c)

At least one uppercase alphabetical letter (A-Z)

d)

At least one digit (0-9) and/or one special character (i.e., @ ! % & $ ^ * ( ) + = )

e)

All of the above

40.

What is one step you can take to protect yourself from social engineers on social media?

a)

Give out all your information

b)

Limit personal information in your social media profiles.

c)

Don't answer the phone

d)

Move to Harris County with no internet access.

41.

What is the document that details what a person who takes a certain job will be required to do?

a)

Job description

b)

Person specification

c)

Personality test

d)

Offer letter

42.

Which of the following does NOT describe the purpose or function of internal control?

a)

The means by which Management directs the company towards achievement of its objectives and corrects or redirects activities as circumstances change.

b)

It is a continuous activity and represents all the methods and processes which ensure adherence to policies, promote operational efficiency and enable risk to be managed by confining exposures to acceptable levels.

c)

It is designed to ensure activities and operations are carried out efficiently, effectively and economically.

d)

It is created to inspire people to work together to achieve business objectives by giving them a sense of purpose and destiny.

43.

______________is a group of people and other resources working together for a common goal.

a)

Organization

b)

Enterprise

c)

community

d)

resources

44.

_____________are interactive ,computer based systems that aid users in judgement and choice activities.

a)

Supply chain Management

b)

Decision Support System

c)

MIS

d)

PLM

45.

_____has the capability to generate reports as and when the user demands it.

a)

PLM

b)

CRM

c)

SCM

d)

MIS

46.

Which of the following is a reason for ERPs explosive growth?

a)

ERP is a logical solution to the mess of incompatible applications

b)

ERP addresses the need for global information sharing and reporting

c)

ERP is used to avoid the pain and expense of fixing legacy systems

d)

All of the above

47.

In a process-oriented organization, who is directly accountable for poor performance of a process?

a)

The process participants

b)

The executive management team

c)

The process owner

d)

The process analyst

e)

The BPM group

48.

Accounting and Finance is responsible for tasks related to:

a)

Recruits, hires, trains, and compensates employees, ensures compliance with government regulations, and oversees the evaluation of employees

b)

Provide summaries of operational data in managerial reports, controlling accounts, planning and budgeting, and cash-flow management

c)

Sets product prices, promotes products through advertising and marketing, takes customer orders, supports customers, and creates sales forecasts

d)

Develops production plans, orders raw materials from suppliers, receives raw material, manufactures products, maintains facilities, and ships products to customers

49.

Which of the following business function is involved in developing products and determine pricing?

a)

Finance and Accounting

b)

Supply Chain Management

c)

Human Resource

d)

Marketing and Sales

50.

An information system produces information using the ________ cycle.

a)

data analysis

b)

input-process-output.

c)

input-output.

d)

process-input-output.

51.
The ability for Service Operation to perform effective operational monitoring and control depends on data and information from which of the following processes?
a)
Incident Management
b)
Request Fulfilment
c)
Event Management
d)
Access Management
52.
“A warning that a threshold has been reached, something has changed, or a failure has occurred” describes which of the following?
a)
An Incident
b)
An Alert
c)
A Warning
d)
A Change
53.
Which of the following is NOT a concept within the Access Management process?
a)
Identity
b)
Rights
c)
Access
d)
Possession
54.
Which process would normally be used to efficiently handle low-risk, frequently occurring, low-cost small changes?
a)
Incident Management
b)
Request Fulfilment
c)
Demand Management
d)
Access Management
55.
Which of the following is most significant in determining the priority of an Incident?
a)
The impact on the business and how quickly the business needs a resolution
b)
The seniority of the person logging the Incident
c)
The ease and speed of implementing the fix
d)
The ability of the Service Desk to rectify the Incident without referral to specialist support groups
56.
Which of the following is most significant in determining the priority of an Incident?
a)
The impact on the business and how quickly the business needs a resolution
b)
The seniority of the person logging the Incident
c)
The ease and speed of implementing the fix
d)
The ability of the Service Desk to rectify the Incident without referral to specialist support groups
57.
Access Management will facilitate which of the following benefits?
1. Controlled access to services to enable an organisation to maintain the confidentiality of its information
2. Employees having the right level of access to execute their jobs effectively
3. An increase in the number of security breaches
a)
1 & 2 Only
b)
1 & 3 Only
c)
2 & 3 Only
d)
All the above
58.
With which other ‘progressive’ phases of the lifecycle does Service Operation need to interface?
a)
Service Transition only
b)
Service Design and Service Transition
c)
Service Strategy, Service Design, Service Transition
d)
Service Strategy, Service Design, Service Transition and CSI
59.
Which ITIL concept could be described as a “generic description for many varying types of demands that are placed upon the IT Department by the users”
a)
Service Request
b)
Standard Change
c)
A customer requested event
d)
Service demand
60.
Service Design relies on effective supplier and contract evaluation and selection. When selecting a supplier, which of the following should Supplier Management consider?
1. Track record
2. Capability
3. Credit rating
4. Size relative to the business being placed
a)
1, 3 and 4 only
b)
2 only
c)
1 and 2 only
d)
All of the above
61.
Which of the following is NOT a process within the Service Design publication?
a)
Service Portfolio Management
b)
Service Catalogue Management
c)
Service Level Management
d)
Supplier Management
62.
Which of the following statements are correct in respect of Service Design?
1. Service Design ensures not only that the functional elements of a service are addressed by the design, but also elements that facilitate management and operational performance
2. The main purpose of Service Design is the design of new or changed services
3. The goal of Service Design is to assist organisations seeking to plan the introduction of new or changed services and advise how to successfully deploy these new services into the production environment
a)
1 and 2 only
b)
1 and 3 only
c)
2 and 3 only
d)
All of the above
63.
Which of the following statements regarding Maintainability is/are correct?
1. Maintainability is concerned with how quickly and effectively a service, a service component or an individual CI can be restored to its normal working status following a failure
2. Maintainability is the measure of how long a service or service component can perform its agreed function without interruption
3. Maintainability is a measure of compliance to a contract by a supplier
a)
1 only
b)
1 and 3 only
c)
2 only
d)
All of the above
64.
A. Service Design Package is a key concept in the design phase of the Service Lifecycle. Which of the following would you expect to find within a Service Design Package?
1. Organisational Readiness Assessment
2. Service contacts
3. Service functional requirements
4. Business requirements
5. Service Transition Plans
a)
1, 3 and 4 only
b)
5 and 3 only
c)
2, 4 and 5 only
d)
All of the above
65.
A customer-based SLA could be best described as?
a)
A single agreement covering the needs of several customers
b)
A single document that covers the differing needs of several customers
c)
A multi-paged document that all parties agree complies with internal quality assurance requirements
d)
A single agreement for an individual customer group that details the levels of service provided to that group
66.
Which of the following is the best description of a document that details the initial requirements of the customer in terms of business needs?
a)
he Business Service Catalogue
b)
Service Level Requirements (SLR)
c)
Service Level Agreement (SLA)
d)
Service Overview Analysis (SOA)
67.
Which of the following statements most accurately describes the overall goal of Information Security Management?
a)
To protect the interests of customers and users by protecting systems from harm caused by failure of availability, confidentiality or integrity
b)
To align IT security with business security requirements and to ensure that information security is effectively managed in all Service Management activities
c)
To produce and maintain an overall Information Security Policy that defines the organisation’s stance and attitude on all security matters
d)
To develop an effective Information Security Management System that supports the business objectives and Information Security Policies
68.
Compliance to organisation-wide Information Security policy requirements should be referenced within which of the following documents?
1. Service Level Agreements
2. Operational Level Agreements
3. Third party underpinning contracts
4. Security policies
a)
1, 3, and 4 only
b)
1 and 4
c)
None of the above
d)
All of the above
69.
Which of the following is NOT an objective of Release and Deployment Management?
a)
To ensure there are comprehensive release and deployment plans
b)
To ensure minimal unpredicted impact when deploying new services
c)
To ensure all changes to services are reviewed in a controlled manner
d)
To ensure releases are deployed efficiently and on schedule
70.
The main goal of Knowledge Management is to enable organisations to?
a)
Document all aspects of a new or changed service
b)
Improve the quality of management decision making
c)
Ensure compliance with data management legislation
d)
Maintain accurate financial data regarding service assets
71.
Which of the following is NOT a goal of Service Transition?
a)
Setting customer expectations as to how the use of the changed service can enable business objectives to be met
b)
Reducing variations in the expected and actual service performance of any service elements that are to be changed
c)
Ensuring that secure and resilient IT infrastructures, environments, applications and data are designed for release into the live environment
d)
Ensuring that the service can be used as it was intended
72.
Which of the following are goals of Change Management?
1. To respond to customers? changing business requirements whilst maximising value, reducing Incidents, disruption and rework
2. To respond to business and IT requests for change that will align IT services with business needs
3. To minimise the number of quality and compliance issues caused by inaccurate recording of configurations and service assets
a)
1 Only
b)
3 Only
c)
1 & 2 Only
d)
All the above
73.

Identify the missing words in the following sentence. The purpose of the [?] is to ensure that the organization continually co-creates value with all stakeholders in line with the organization's objectives.

a)

‘Focus on value’ guiding principle

b)

Four dimensions of service management

c)

Service value system

d)

‘Service request management’ practice

74.

Which guiding principle is PRIMARILY concerned with consumer's revenue and growth?

a)

Progress iteratively with feedback

b)

Optimize and automate

c)

Keep it simple and practical

d)

Focus on value

75.

The ability of an organization, person, process, application, configuration item or IT service to carry out an activity

a)

Capability

b)

Service

c)

Value

76.

Which one of the following would be the MOST useful in helping to define roles and responsibilities in an organizational structure

a)

RACI model

b)

Incident model

c)

Continual service improvement (CSI) approach

d)

The Deming Cycle

77.

Service transition contains detailed descriptions of which processes?

a)

Change management, service asset and configuration management, release and deployment management

b)

Change management, capacity management event management, service request management

c)

Service level management, service portfolio management, service asset and configuration management

d)

Service asset and configuration management, release and deployment management, request fulfillment

78.

Match the following activities with the Deming Cycle stages

1. Monitor, Measure and Review

2. Continual Improvement

3. Implement Initiatives

4. Plan for Improvement

a)

1 Plan, 2 Do, 3 Check, 4 Act

b)

3 Plan, 2 Do, 4 Check, 1 Act

c)

4 Plan, 3 Do, 1 Check, 2 Act

d)

2 Plan, 3 Do, 4 Check, 1 Act

79.

What is the BEST description of an operational level agreement (OLA)?

a)

An agreement between the service provider and another part of the same organization

b)

An agreement between the service provider and an external organization

c)

A document that describes to a customer how services will be operated on a day-to-day basis

d)

A document that describes business services to operational staff

80.
How does categorization of incidents assist incident management
a)
It helps direct the incident to the correct support area
b)
It determines the priority assigend to the incident
c)
It ensures that incident are resolved in times agreed with the customer
d)
It determines how the service provider is perceived
81.
What is the purpose of the incident management practice?
a)
Supporting the agreed quality of a service by handling all pre-defined, user-initiated service requests in an effect and user friendly manner
b)
Ensuring that services deliver agreed levels of availability or that change can be assessed
c)
Ensuring that all an organization's are successfully delivered
d)
Minimizing the negative impact of incidents by restoring normal service operation as quickly as possible
82.
Indentify the missing word in the following sentence. The [?] is the practice of capturing demand for incident resolution and service requests
a)
Incident management
b)
Service level management
c)
Service request management
d)
Service desk
83.
Which of the following is NOT a process within the Service Design publication?
a)
Service Portfolio Management
b)
Service Catalogue Management
c)
Service Level Management
d)
Supplier Management
84.
Which of the following is NOT an objective of Continual Service Improvement?
a)
Identifying, selecting and prioritising market opportunities
b)
Improving the cost-effectiveness of delivering IT services
c)
Making recommendations for improvements in each lifecycle phase
d)
Ensuring applicable quality management methods are employed
85.
A customer-based SLA could be best described as?
a)
A single agreement covering the needs of several customers
b)
A single document that covers the differing needs of several customers
c)
A multi-paged document that all parties agree complies with internal quality assurance requirements
d)
A single agreement for an individual customer group that details the levels of service provided to that group
86.
What is the main goal of using the Deming Cycle?
a)
Measuring and reviewing improvements
b)
Facilitating steady ongoing improvement
c)
Performing an effective gap analysis
d)
Setting clear goals and targets
87.

Everything the organization does should link back, directly or indirectly, to value for itself, its customers, and other stakeholders

a)

True

b)

False

88.

Reactive Problem Management is identifying and solving Problems before any Incidents have occurred.

a)

True

b)

False

89.

Reactive Problem Management is identifying and solving Problems before any Incidents have occurred.

a)

True

b)

False

90.

What is the purpose of the 'relationship management' practice?

a)

To align the organization's practices and services with changing business needs

b)

To establish and nurture the links between the organization and its stakeholders at strategic and tactical levels

c)

To reduce the likelihood and impact of incidents by identifying actual and potential causes of incidents, and managing workarounds and known errors

d)

To minimize the negative impact of incidents by restoring normal service operation as quickly as possible

91.

How should an organization include third-party suppliers in the continual improvement of services?

a)

Ensure suppliers include details of their approach to service improvement in contracts

b)

Require evidence that the supplier uses agile development methods

c)

Require evidence that the supplier implements all improvements using project management practices

d)

Ensure that all supplier problem management activities result in improvements

92.

Which practice has a purpose that includes restoring normal service operation as quickly as possible?

a)

Supplier management

b)

Deployment management

c)

Problem management

d)

Incident management

93.

What does the 'service request management' practice depend on for maximum efficiency?

a)

Compliments and complaints

b)

Self-service tools

c)

Problem management

d)

Processes and procedures

94.

Which practice is responsible for moving components to live environments?

a)

Change control

b)

Release management

c)

IT asset management

d)

Deployment management

95.

What is defined as any valuable component that can contribute to the delivery of an IT product or service?

a)

Outcome

b)

Output

c)

IT asset

d)

Configuration item

96.

Which is a recommendation of the ‘continual improvement’ practice?

a)

There should be a small team dedicated to leading continual improvement efforts

b)

All improvements should be managed as multi-phase projects

c)

Continual improvement should be isolated from other practices

d)

External suppliers should be excluded from improvement initiatives

97.

What should be included in every service level agreement?

a)

Details of the system-based metrics used

b)

A technical description of the service components

c)

Clearly defined service outcomes

d)

Legal language

98.

How does ‘service request management’ contribute to ‘obtain/build’ value chain activity?

a)

It analyzes data to identify opportunities to provide new service request options

b)

It ensures users continue to be productive when they need assistance from the service provider

c)

It acquires pre-approved service components to help fulfil service requests

d)

It collects user-specific requirements, sets expectations and provides status updates

99.

Which is a purpose of the ‘service desk’ practice?

a)

To reduce the likelihood and impact of incidents by identifying actual and potential causes of incidents

b)

To maximize the number of successful IT changes by ensuring risks are properly assessed

c)

To capture demand for incident resolution and service requests

d)

To set clear business-based targets for service performance

100.

Which practice may involve the initiation of disaster recovery?

a)

Incident management

b)

Service request management

c)

Service level management

d)

IT asset management

101.

Why should service desk staff detect recurring issues?

a)

To engage the correct change authority

b)

To ensure effective handling of service requests

c)

To escalate incidents to the correct support team

d)

To help identify problems

102.

Why should incidents be prioritized?

a)

To encourage a high level of collaboration within and between teams

b)

To ensure that incidents with the highest business impact are resolved first

c)

To help automated matching of incidents to problems or known errors

d)

To identify which support team the incident should be escalated to

103.
Which of the following is NOT an objective of Continual Service Improvement?
a)
Identifying, selecting and prioritising market opportunities
b)
Improving the cost-effectiveness of delivering IT services
c)
Making recommendations for improvements in each lifecycle phase
d)
Ensuring applicable quality management methods are employed
104.
“The primary purpose of Continual Service Improvement is to continually align and realign IT Services to changing business needs.” What is the main way in which this is achieved?
a)
Identifying and implementing improvements to measurement methods that support IT processes
b)
Identifying and implementing improvements to IT services that support business processes
c)
Identifying and implementing improvements to technologies that support IT processes
d)
Identifying and implementing improvements to business processes that support IT services
105.
In what order would you typically expect the following steps to be conducted when building a RACI matrix?
1. Conduct meetings and assign the RACI codes
2. Identify/define the roles
3. Distribute the chart and incorporate feedback
4. Identify the activities/processes
5. Identify any gaps or overlaps
a)
1, 2, 4, 3 and 5
b)
4, 5, 2, 1 and 3
c)
2, 4, 1, 5 and 3
d)
4, 2, 1, 5 and 3
106.
Which of the following describes the main way in which the Service Strategy publication can assist an organisation?
a)
To manage strategic relationships within the IT industry
b)
To implement ITIL within an IT organisation
c)
To enable strategic integration with customers and suppliers
d)
To develop Service Management as a strategic assist
107.
Which of the following statements about the Service Portfolio are correct?
1. The Service Portfolio represents the investments made by a service provider
2. The Service Portfolio includes third party services that are part of service offerings
3. The Service Portfolio represents the ability of a service provider to serve customers and market spaces
a)
1 and 2 only
b)
All of the above
c)
1 and 3 only
d)
2 and 3 only
108.
What details are contained in the Service Pipeline?
a)
Operational capability within the context of a market space
b)
The resources engaged in all phases of the Service Lifecycle
c)
Business requirements that have not yet become live services
d)
Knowledge and information about phased-out services
109.
From a Service Management perspective which of the following is NOT a specific risk management activity?
a)
Financial analysis of the likely consequences of a Business action
b)
Ensuring processes are in place for on-going monitoring of risks
c)
Identification and selection of appropriate countermeasures
d)
Having access to reliable and up-to-date information about risks
110.
Which of the following most accurately describes the need for service providers to develop a marketing mind-set?
a)
To offer customers a comprehensive service catalogue
b)
To offer competitively priced service offerings
c)
To look at services from the customer’s perspective
d)
To utilise a wide range of communication channels
111.
‘Fitness for purpose’ of a service comes from which of the following?
a)
The attributes of the service that have a positive effect on the performance of the Business
b)
The ability of a service to remain operational at all times as agreed in an SLA
c)
The ability of a service to provide the required levels of functionality when required
d)
The service being provided by an outsourcing organisation
112.
Which of the following are potential benefits of analysing patterns of Business activity?
1. Service Design can optimise designs to suit Business demand patterns
2. Financial Management can approve incentives to influence demand
3. Service Operation can adjust allocation of resources and scheduling
4. Service Portfolio Management can prioritise appropriate investments
a)
1 and 3 only
b)
2 and 3 only
c)
1, 2 and 4 only
d)
All of the above
113.

Which term describes the functionality offered by a service?

a)

Cost

b)

Utility

c)

Warranty

d)

Risk

114.

What is a means of enabling value co-creation by facilitating outcomes that customers want to achieve?

a)

A service

b)

An output

c)

A practice

d)

Continual improvement

115.

Identify the missing word in the following sentence. A customer is a person who defines the requirements for a service and takes responsibility for the [?] of service consumption.

a)

Outputs

b)

Outcomes

c)

Costs

d)

Risks

116.

A service provider describes a package that includes a laptop with software, licenses, and support. What is this package an example of?

a)

Value

b)

An outcome

c)

Warranty of service

d)

A service offering

117.

What are the two types of cost that a service consumer should evaluate?

a)

The cost of creating the service, and the cost charged for the service

b)

The costs removed by the service, and the costs imposed by the service

c)

The cost of provisioning the service, and the cost of improving the service

d)

The cost of purchasing software, and the cost of purchasing hardware

118.

What does 'integrity of data' mean?

a)

"Accuracy and completeness of the data"

b)

"Data should be viewable at all times"

c)

"Data should be access by only the right people"

d)

"None of the above"

119.

What kind of cyber security risks can be minimised by using a Virtual Private Network (VPN)?

a)

Use of insecure Wi-Fi networks

b)

Key-Logging

c)

De-anonymization by network operators

d)

Phishing attacks

120.

An email that attempts to trick a reader into installing software that may contain a virus is:

a)

Phishing Scam

b)

Lobster trap

c)

Fishing Scam

d)

Phone Scam

121.

Which is an example of PII? (Personally Identifiable Information)

a)

Credit Card Number

b)

Name

c)

Home Address

d)

All of the above

122.

What is the best definition of Spear Phishing?

a)

"A Phishing email aimed directly at you"

b)

"A malicious virus that can encrypt or lock your computer"

c)

"A method hackers can use to guess your password"

d)

"A random Phishing email sent to a massive group"

123.

What is a step that you can take to minimise the chance and impact of a ransomware attack?

a)

"All of these answers"

b)

"Keep your computer software up to date"

c)

"Ensure that anti-virus tools are running and up to date"

d)

"Ensure that you are backing up your critical files"

124.

Who you are allowed to give your password to?

a)

"Anybody you trust"

b)

"Only supervisors and authorised IT staff if requested"

c)

"Only IT staff"

d)

"Nobody"

125.

Which security principles are covered by the CIA triad?

a)

certified, integrated, accessible

b)

continuity, integrity, accessibility

c)

confidentiality, integrity, availability

d)

confidentiality, installation, assembly

126.

What does compliance mean?

a)

providing secure access to user data

b)

using honest means to bypass security measures

c)

conducting tests to identify vulnerabilities in a system

d)

following the rules or standards that have been established

127.

Which of the following is not considered social engineering?

a)

dumpster diving

b)

convincing people to reveal information

c)

encrypting data to prevent user access until a fee is paid

d)

looking through social media sites for information

128.
What law makes organisations look after your personal data properly?
a)
Data Privacy Act
b)
Data Protection Act
c)
Data Protection Law
d)
Data Privacy Law
129.
Organisations storing your data must...
a)
Keep it up to date
b)
Keep it for no longer than 5 years after your death
c)
Ask for more data than required
d)
Wait for you to contact them to ensure its accurate
130.
How many principles does the Data Protection Act have?
a)
4
b)
8
c)
9
d)
10
131.
What is gaining unauthorised access to a computer system also known as?
a)
Hacking
b)
Spamming
c)
Phishing
d)
Logging on
132.
Why was the Computer Misuse Act of 1990 introduced?
a)
To help protect computer software
b)
To help protect computer hardware
c)
To stop the spread of computer viruses
d)
To stop people from accessing unauthorised information. 
133.
What is the name of the law that makes hacking illegal?
a)
Data Protection Act
b)
Computer Misuse Act
c)
Copyright, Designs and Patents Act
d)
Hacking Act
134.
Which of the following is NOT an offence under the Computer Misuse Act?
a)
unauthorised access to someone else's files
b)
unauthorised access to someone else's files with intent to commit further criminal offences
c)
copying software and trying to sell it to someone for a profit
d)
writing and distributing a virus
135.
Which of the following is NOT an offence under the Computer Misuse Act?
a)
unauthorised access to someone else's files
b)
unauthorised access to someone else's files with intent to commit further criminal offences
c)
copying software and trying to sell it to someone for a profit
d)
writing and distributing a virus
136.
Which of the following could protect against unauthorised access to an ICT system?
a)
anti-virus software
b)
a firewall
c)
anti-malware software
d)
disk defragger
137.
What are the principles of the Computer Misuse Act?
a)
Authorised access,Authorised access with intent, Authorised 
b)
Unauthorised access with intent and Unauthorised modification
c)
Unauthorised access and Unauthorised modification
d)
Unauthorised access, Unauthorised access with intent, Unauthorised modification
138.

Employee Onboarding is the process of ....

a)

Directing new employees to their work place

b)

Directing new employees about the daily tasks

c)

Introducing new employees to the organization’s environment and culture

d)

Introducing new employees to explore work environment on their own

139.

Why efficient employee onboarding matters

a)

All organisations have it

b)

Is the first interaction an employee has with the organization

c)

To help your new hires settle down in their jobs

d)

It will help in managers to direct on tasks to do

140.

Why efficient employee onboarding matters -2

a)

A memorable onboarding experience makes employees feel welcome

b)

To complete the joining formalities

c)

To Managers to start dictating the job

d)

To know about the rules and regulations

141.

Multilevel support model is also called...

a)

Frontline/backline model

b)

Help desk structure

c)

Support hierarchy

d)

None of the above

142.

____ is a well-defined, formal process help desk staff follow to:

–Handle problem incidents

–Get information to users

–Solve user problems

–Maintain records about the incident

a)

Call management

b)

Incident management

c)

ITIL

d)

None of the above

143.

_____ determines whether help desk staff are authorised to handle an incident.

a)

Prescreening

b)

Authentication procedure

c)

Logging

d)

None of the above

144.

_____ is a normal process in which an incident is transferred to a higher level support agent.

a)

Tracking

b)

Resolution

c)

Escalation

d)

None of the above

145.

_____ is a contract that defines expected performance of user support services or external vendor-provided services.

a)

SLA

b)

Last will and testament

c)

Terms and conditions

d)

None of the above

146.

_____ is a contract that defines expected performance of user support services or external vendor-provided services.

a)

SLA

b)

Last will and testament

c)

Terms and conditions

d)

None of the above

147.

How do we tighten our security?

a)

Use strong password

b)

Only connect to trusted network

c)

Log-off network account when not in use

d)

All of the above

148.

What's included in a strong password?

a)

A minimum of eight characters

b)

At least one lowercase alphabetical letter (a-z)

c)

At least one uppercase alphabetical letter (A-Z)

d)

At least one digit (0-9) and/or one special character (i.e., @ ! % & $ ^ * ( ) + = )

e)

All of the above

149.

What is one step you can take to protect yourself from social engineers on social media?

a)

Give out all your information

b)

Limit personal information in your social media profiles.

c)

Don't answer the phone

d)

Move to Harris County with no internet access.

150.

What is the document that details what a person who takes a certain job will be required to do?

a)

Job description

b)

Person specification

c)

Personality test

d)

Offer letter

151.

Which of the following does NOT describe the purpose or function of internal control?

a)

The means by which Management directs the company towards achievement of its objectives and corrects or redirects activities as circumstances change.

b)

It is a continuous activity and represents all the methods and processes which ensure adherence to policies, promote operational efficiency and enable risk to be managed by confining exposures to acceptable levels.

c)

It is designed to ensure activities and operations are carried out efficiently, effectively and economically.

d)

It is created to inspire people to work together to achieve business objectives by giving them a sense of purpose and destiny.

152.
An individual responsible for diagnosing and resolving users' technical hardware and software problems.
a)
1.  Help desk technician
b)
1.  Web site designer
c)
1.  Web application developer
d)
1.  Web site analyst
153.

Which of the following statement is FALSE?

a)

Helpdesk role does not include resolving an incident ticket

b)

All incident tickets will be assigned with the Urgency and Impacts defined in the Group Impact Classification Matrix

c)

If any CIMB IT Staff Member detected an incident, they need to ensure that an incident ticket is logged by either contacting the Helpdesk or raise the incident ticket by themselves

d)

If an incident ticket has been resolved and but the same issue is being reported again within a relatively-short period of time, this should be handled via the existing incident ticket