Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CIS - EVENT MANAGEMENT

Total questions: 110

Worksheet time: 58mins

Name
Class
Date
1.

When creating an alert management rule, where would you specify a workflow to resolve a given condition? (2 Possible Correct answer)

a)

From the Remediation tab

b)

From the Actions tab

c)

From the Launcher tab

d)

In the Related Links section

2.

What types of system can a MID Server install on?(Choose two)

a)

Any system inside the customer firewall

b)

Microsoft Windows Desktop

c)

OpenVMS System

d)

Linux System

e)

Microsoft Windows Server

3.

What would be the primary use case for creating Javascripts in Event Management?

a)

To create a customized pull connector to retrieve events on behalf of an event source

b)

To automatically populate the Configuration Management Database (CMDB)

c)

To parse a nodename out of your raw event data in an event rule

d)

To run as part of a remediation workflow for IT alerts that fail to execute

4.

What would you use to define the monitoring sources allowed to communicate with the ServiceNow instance for Operational Intelligence?

a)

Metric Registration

b)

Metric Config Rules

c)

Metric Type Actions

d)

Metric to CI

5.

The value of the Alert Priority score is a composite of what?

a)

The value of the alert’s category and its relative weight

b)

The value of the alert’s category and its Priority Group

c)

The value of the alert’s Severity and its Priority Group

d)

The value of the alert’s Severity and its relative weight

6.

Which attribute is responsible for de-duplication?

a)

Metric_name

b)

Message_key

c)

Short_description

d)

Additional_info

7.

How would you interpret the following data in the Operational Intelligence Insights Explorer?(2 Possible Correct answer)

a)

win-ces882ierw is one of your hottest Configuration Items (CIs) that is currently experiencing a high probability of anomalies and should be checked immediately

b)

win-ces882ierw is one of your hottest Configuration Items (CIs), but is currently experiencing a low probability of anomalies

c)

win-ces882ierw is one of your customized list of monitored Configuration Items (CIs) that is currently experiencing a high probability of anomalies and should be checked immediately

d)

win-ces882ierw is one of your customized list of monitored Configuration Items (CIs), but is currently experiencing a low probability of anomalies

8.

What is the default collection/polling interval applied to all event connectors?

a)

Every 120 seconds

b)

Every 5 seconds

c)

Every 40 seconds

d)

Every 60 seconds

e)

Every 10 seconds

9.

Where can you look to determine what event rule created an alert?(Choose two.)

a)

Alert Activity

b)

Event Additional Information

c)

Event Processing Notes

d)

Alert Message Key

e)

Alert Source

10.

What feature would you use to trigger a workflow or automatically generate tasks via templates?

a)

Event rules

b)

Task rules

c)

Alert management rules

d)

Alert correlation rules

11.

What are the valid states an alert can be in during its lifecycle?

a)

Open, Reopen, Flapping, Closed

b)

New, Updating, Waiting, Complete

c)

Open, Updating, Swinging, Closed

d)

Open, Warning, Flapping, Clear

12.

What Event Management module allows for configuration of automatic task creation?

a)

Alert management rules

b)

Task rules

c)

Event rules

13.

You have a system configured with a MID Web Server using Basic authentication to enable Operational Management Intelligence (OI) to push raw metric data to the MID Server. No data is getting through to the MID Server. What is the most likely cause of the issue?

a)

The MID Web Server needs to be Restarted

b)

The MID Web Server needs to be Started

c)

An invalid secret key is being passed in the header information of the URL for the REST request

d)

An invalid password is set in the MID Web Server Context

14.

In the event table, which field maps the external attributes from the target system?

a)

Resource

b)

Description

c)

Source

d)

Additional Information

15.

By default, the Alert Console displays what type of alerts?

a)

All Primary, Open alerts and anomaly alerts with a Severity of Critical, Major, Minor, and Warning that are not in Maintenance mode

b)

All Primary and Secondary Open alerts and anomaly alerts with a Severity of Critical, Major, Minor, and Warning that are not in Maintenance mode

c)

All Primary alerts with a Severity of Critical, Major, Minor, Warning that are not in Maintenance mode

d)

All Primary, Open alerts with a Severity of Critical, Major, Minor, and Warning that are not in Maintenance mode

e)

All Primary and Secondary Open alerts with a Severity of Critical, Major, Minor, and Warning that are not in Maintenance mode

16.

Which are recommended best practices for Event Management? (Choose three.)

a)

Filter out events on ServiceNow Instance for easier consolidation and aggregation.

b)

Promote all events to alerts during initial implementation until you fully understand which should be ignored.

c)

Filter out events at source rather than in the ServiceNow instance.

d)

Base-line “normal-state” events to filter out background noise.

e)

Ignore all non-critical events during initial implementation to streamline processing; add alerts over time as time and resources allow.

17.

For an incoming event with a matching message key, what allows an existing alert to be automatically closed?

a)

In the event rule, set the Severity to 0

b)

In the alert rule, set the Severity to 0

c)

In the alert rule, set the Severity to -1

d)

In the event rule, set the Severity to -1

18.

A support agent resolves an incident associated with an alert, but the alert does automatically close even though the evt_mgmt.incident_closes_alert property is set appropriately to close the alert. What is the most likely cause of this issue?

a)

The support agent does not have the evt_mgmt_user role.

b)

The support agent only has the evt_mgmt_admin role.

c)

The support agent has the evt_mgmt_operator role, but not the evt_mgmt_user role.

d)

The support agent has the evt_mgmt_user role, but not the evt_mgmt_operator role.

19.

What are the two most accurate statements regarding the ServiceNow CMDB (configuration management database) and CIs (configuration items)? (choose two)

a)

The CMDB is a series of tables that contain only key hardware components located in critical paths within your platform that must be managed.

b)

The CMDB is a dynamic list that tracks both the CIs within your platform and the relationship between those items.

c)

All CIs stored in the CMDB must have an assigned IP address within your infrastructure.

d)

A CI is any component within your infrastructure that needs to be managed in order to deliver Services.

20.

What would you use as a central location to explore the CMDB class hierarchy, CI table definitions, and CIs?

a)

CI Remediations

b)

CI Relation Types

c)

CI Identifiers

d)

Process to CI Type Mapping

e)

CI Class Manager

21.

A four node cluster makes up the components (CIs) of a Business Service. The impact influence for the cluster is set to 60%. How many members of the cluster must be in a Critical state in order for the Business Service to display as Critical in the Impact Tree?

a)

1

b)

2

c)

3

d)

4

22.

Which the following alert promotion rule defined in your ServiceNow instance, which of the anomalies below would be automatically promoted into IT alerts on the Alert Console?

a)

[Diagram]

b)

c)

Both anomaly A and anomaly B

d)

Neither anomaly A or anomaly B

23.

By default, Event Management tries to bind an alert to CI (configuration item), by matching the node name in the event to which three items in the CMDB (configuration management database)?

a)

A. CI name, Fully qualified domain name, IP or MAC address

b)

B. CI name, Webserver name, IP or MAC address

c)

C. CI name, Fully qualified domain name, SSH public host keys

d)

D. System class name, Fully qualified domain name, IP or MAC address

24.

The MID Server requires an outbound connection on which port?

a)

445

b)

161

c)

443

d)

143

25.

If more than one event rule applies to a particular event or metric, which of the event rules will run based upon the Order of execution number?

a)

Only the event rule with the highest Order of execution number will run.

b)

Only the event rule with the lowest Order of execution number will run.

c)

All event rules will run, from the lowest to the highest Order of execution numbers.

d)

All event rules will run, from the highest to the lowest Order of execution numbers.

26.

When creating event rules, is it best practice to create:

a)

Two rules for every event

b)

As many rules as possible

c)

As few rules as possible

d)

One rule for every event

27.

During processing of the event and if the event Severity is blank, the state of the event is set to:

a)

Ready

b)

Ignored

c)

Error

d)

Processing

28.

What two key steps must be performed after creating a new connector instance?(Choose Two)

a)

Assign a MID Server to the connector

b)

Enter credentials for the connector

c)

Debug the connector

d)

Test the connector

e)

Activate the connector.

29.

A customer informs you that they already have monitoring and event management tools. Which of the following describes the extra value that ServiceNow Event Management provides?(choose four)

a)

ServiceNow Event Management Alerts, Incidents, Problems, and changes are automatically correlated with CIs and Business Services that can be visualized in Business Service maps.

b)

ServiceNow Event Management manages relationships between alerts and related incidents to maintain an end-to-end event management lifecycle.

c)

ServiceNow Event Management provides a business-centric platform and single system of record for service monitoring and remediation results, to better control and manage performance and availability.

d)

ServiceNow Event Management provides state-of-the-art performance monitoring capabilities across a wide array of different types of infrastructures.

e)

ServiceNow Event Management utilizes the power of MID Servers provide important functions in your ITOM Health deployment.

30.

What does MID stand for?

a)

Management, Instrumentation, and Discovery

b)

Messaging, Integration, and Data

c)

Monitoring, Insight, and Domain

d)

Maintenance, Information, and Distribution with leading monitoring systems to automatically create actionable alerts.

31.

You have an event with a Source of ‘Trap from Enterprise 111’, but the alert created for this event shows a Source of ‘Oracle EM’. If you want to change what this is set to, where in the event rule would you do this?

a)

Transform and Compose Alert Output lab.

b)

Event rule info tab

c)

CI Binding tab

d)

Event Filter tab

32.

Copies of checks that have been included in Agent Client Collector policies are known as what?

a)

Check definitions

b)

Check models

c)

Check clones

d)

Check mirrors

e)

Check instances

33.

How often do baseline event connectors retrieve events?

a)

Every 30 seconds

b)

Every 2 minutes

c)

Every 10 minutes

d)

Every 1 minute

e)

Every 5 minutes

34.

Which attribute correlates multiple events to one alert?

a)

Additional_info

b)

Message_key

c)

Metric_name

d)

Short_description

35.

What attribute is used to consolidate events into a single alert?

a)

Event Rules

b)

Message Key

c)

Alert Priority

d)

Severity

36.

Which attribute within an event needs to be exactly the same to allow for deduplication?

a)

Metric Name

b)

Message Key

c)

Type & Node

d)

Description

e)

Correlation ID

37.

In default configuration using baseline connectors, how often is event data collected from event sources?

a)

Once every minute

b)

Every 2 minutes

c)

Twice every minute

d)

Every 5 minutes

38.

What applications are included in the ITOM Health product?

a)

Event Management and Operational Intelligence

b)

ITOM Visibility

c)

Discovery and Service Mapping

d)

Cloud Management

39.

What is one of the main benefits of using Event Management and Operational Intelligence?

a)

To improve service availability by helping IT staff pinpoint service issue causes and evaluate the impact of planned changes.

b)

To increase service agility and produce fast, predictable results by automating manual, routine, error-prone tasks.

c)

To rapidly configure and launch secure, agentless discovery of hardware and software resources and their relationships.

d)

To proactively warn against possible service outages using a range of advanced predictive machine learning methods.

40.

MID Servers provide important functions in your ITOM Health deployment. What does MID stand for?

a)

Management, Instrumentation, and Discovery

b)

Messaging, Integration, and Data

c)

Monitoring, Insight, and Domain

d)

Maintenance, Information, and Distribution

41.

Out-of-the-box, how often do the events get processed in ServiceNow?

a)

Every 5 seconds

b)

Every minute via a scheduled job

c)

As soon as the event record is inserted via a business rule.

d)

Depends on connectors used.

42.

HOTSPOT -

In what sequence are events processed?

A. Does the event Source match the event rule? 1

B. Does the event message key match an existing alert? 5

C. Is the event filtered out? 2

D. Is there a matching threshold? 3

E. Is a severity defined? 4

4 lines
43.

Which is not a valid method for accessing alert intelligence?

a)

In the right-click menu of an alert list, select Open in Workspace

b)

By appending/workspace to your instance URL

c)

The application navigator Alerts Console menu item

d)

The application navigator Alert Intelligence menu item

e)

Within an open alert record, click the Open in Workspace button.

44.

To determine the top incidents for the CI associated with an alert, where is the best place to look?

a)

Alert Insights

b)

Incident List View

c)

CMDB Health Dashboard

d)

Event Management Overview page

45.

Agent Client Collector is built on what framework that enables you to adopt and extend monitoring checks from the community?

a)

Icinga

b)

Sensu

c)

SolarWinds

d)

Nagios

e)

Zabbix

46.

Based on the information shown, which of the following three alerts should be processed first?

a)

A. The Alert Priority score 3106020.001 was calculated according to the following factors, ordered by their respective priority (2018-06-01 19:34:01 GMT) Category (Score, Weight)

1. Business services – (3.0, 1000000)
2. Severity – (1.0, 100000)
3. CI type – (60.0, 100)
4. Role – (2.0, 10)
5. Secondary – (0)
6. State – (1.0, 0.001)

b)

B. The Alert Priority score 4406020.001 was calculated according to the following factors, ordered by their respective priority (2018-05-31 20:04:47 GMT) Category (Score, Weight)
1. Business services – (4.0, 1000000.0)
2. Severity – (4.0, 100000.0)

3. CI type – (60.0, 100.0)

4. Role – (2.0, 10.0)
5. Secondary – (0)
6. State – (1.0, 0.001)

c)

C. The Alert Priority score 3306020.001 was calculated according to the following factors, ordered by their respective priority (2018-05-31 19:56:54 GMT) Category (Score, Weight)

1. Business services – (3.0, 1000000.0)

2. Severity – (3.0, 100000.0)

3. CI type – (60.0, 100.0)

4. Role – (2.0, 10.0)

5. Secondary – (0)

6. State – (1.0, 0.001)

d)

D. They should be processed in the order in which they were received.

47.

Applying recommended Event Management best practice guidelines, which of the following events should generate an alert?

a)

Every event should generate an alert so you have the opportunity to resolve them all.

b)

Only events that necessitate action should generate an alert.

c)

Only the most critical events on every CI in the CMDB should generate an alert.

d)

Every event on every critical CI in the CMDB should generate an alert.

48.

What makes all ServiceNow metrics, tasks, services, configuration items, assets, people, locations, and information a single system of record for IT and business processes?

a)

ServiceNow runs on supported Windows servers and is managed through Windows Update

b)

ServiceNow is installed within your datacenter providing you complete control.

c)

All applications are built on the Oracle database standard, providing uniformity across products.

d)

A single table houses all data elements within ServiceNow.

e)

All applications that are built by ServiceNow utilize the same data model and code base.

49.

You have a very large networking environment and have noticed that your event notifications are either not being triggered or are delayed.

What are best options to try to resolve this issue? (Choose two.)

a)

Ensure all Event Management – process events jobs are set to a Ready state.

b)

Verify that the Bucket field in the event table is set to zero (0)

c)

Add additional event processor jobs.

d)

Ensure multi-node event processing is disabled.

50.

What event value will auto close an alert?

a)

Severity of -1/OK

b)

Type of Clear

c)

Resolution State of Closing

d)

Resolution State of Clear

e)

Severity of 0/Clear

51.

Given the following Impact settings and Alerts in a three node cluster that makes up the components of a Business Service, what is the overall service health of this Business Service?

a)

Major

b)

Minor

c)

Error

d)

Critical

e)

Clear

52.

What does Operational Intelligence proactively identify before they cause service outages?

a)

Missing CMDB data

b)

Defects

c)

Alert correlations

d)

Orphaned CIs

e)

Anomalies

53.

What is the function of the External Communication Channel (ECC) Queue?(choose three)

a)

It is a connection point between a ServiceNow instance and the MID Server.

b)

It contains probe records to be executed on the customer’s network.

c)

It holds jobs that the MID Server needs to perform.

d)

It is a connection point between a hardware CI on a customer’s network and the MID Server.

e)

It contains records of CIs that the ServiceNow admin has submitted for entry into the CMDB.

54.

The correct regex to capture the name of the server in “the server webser3.domain.com is down” would be:

a)

A. .*(\w+\.\w+\.\w+).*

b)

B. The server (.*)\s.*

c)

C. .*\s(\w+\.\w+\.\w+).*

d)

D. the server (.*).*

55.

What is the recommended approach to normalizing data from a source system to the default values in Event Management?

a)

Event field mapping

b)

Transform maps

c)

Alert management rules

d)

Business rules

56.

You have an event that needs to be bound to a non-host CI. Which attribute needs to be removed from the Transform and Compose tab?

a)

Source Instance

b)

Metric Name

c)

Node

d)

Resource

57.

When are anomaly alerts generated by Operational Intelligence displayed in alert intelligence?

a)

When the statistical model threshold is breached.

b)

When they are promoted to IT alerts.

c)

When it is manually promoted in insights explorer.

d)

When the anomaly score is greater than 100.

58.

What are the possible actions available in alert management?(choose three)

a)

Execute remediation subflows.

b)

Execute remediation workflows.

c)

Launch applications

d)

Evaluate business rule.

e)

Create a service catalog request.

59.

What ServiceNow feature would you configure to process incoming email to create events?

a)

Transforms

b)

Inbound actions

c)

Event processing jobs

d)

Event Filter

e)

Event field mapping

60.

Within a PowerShell script, which two URI’s could you use to log events directly to the ServiceNow event table?(choose two)

a)

https://[Your_ServiceNow_instance_URL]/rest_api/now/my_tables/em_event

b)

https://[Your_ServiceNow_instance_URL]/api/global/em/jsonv2

c)

https://[Your_ServiceNow_instance_URL]/api/now/table/em_event

d)

https://[Your_ServiceNow_instance_URL]/api/table/em_event

e)

https://[Your_ServiceNow_instance_URL]/rest_api/now/table/em_event

61.

If more than one alert management rule applies to a particular alert, which of the rules will run based upon the Order of execution field?

a)

Only the alert management rule with the highest Order of execution number will run.

b)

Only the alert management rule with the lowest Order of execution number will run.

c)

All alert management rules will run, from the lowest to the highest Order of execution numbers.

d)

All alert management rules will run, from the highest to the lowest Order of execution numbers.

62.

Alerts are processed using which of the following?(Choose Three)

a)

Alert management rules

b)

Event action rules

c)

Event rules

d)

Scheduled jobs

e)

Java and Groovy scripts

63.

The individual commands that the Agent Client Collector executes on the host are known as what?(choose three)

a)

Events

b)

Metrics

c)

Policies

d)

Checks

e)

Parameters

64.

What is Event Management licensing based on?

a)

The number of unique nodes that can send events to the instance.

b)

The number of connectors and listeners it will collect data from

c)

The number of connectors it will collect data from

d)

The number of CIs in the CMDB that it will be monitoring.

65.

What missing attribute would cause an event to have a state of Error?

a)

Metric Name

b)

Source

c)

Classification

d)

Node

e)

Severity

66.

Modified Agent Client Collector policies do not take effect until what action is taken?

a)

The check is tested on an existing agent/host.

b)

The policy is republished.

c)

Agents re-run the discovery policy.

d)

MID server synchronization is initiated.

e)

Agents are restarted.

67.

What does the Asynchronous Messaging Bus (AMB) channel do on the MID Server?

a)

Opens an inbound connection to the MID Server.

b)

Allows Web Server transactions to be passed to ServiceNow.

c)

Sends heartbeat information to the ServiceNow instance to ensure MID is communicating.

d)

Continually queries the External Communication Channel (ECC) queue via a persistent query.

68.

Within the ServiceNow IT Operations Management solution set, which statement most accurately describes what Event Management is?

a)

The process responsible for defining, analyzing, planning, measuring, and improving all aspects of the availability of IT services.

b)

The process responsible for ensuring the capacity of IT Services and IT infrastructure is able to deliver agreed upon service level targets in a cost-effective manner.

c)

The process responsible for monitoring all abnormal occurrences throughout the IT infrastructure, allowing for normal operations, and detecting and escalating exception conditions.

d)

The process responsible for recovery action and planning through machine learning.

69.

When creating a task from an alert what Event Management Module would be used?

a)

Event Rules

b)

Alert Correlation Rules

c)

Task Management

d)

Alert Management

70.

What is the preferred method of parsing in the Transform/Compose step of an event rule?

a)

Python

b)

Regex

c)

sed/awk

d)

JavaScript

71.

What are the server requirements to allow Operational Intelligence to successfully collect operational metric data via a push?

a)

This requires a minimum of three MID Servers - two for Event Management and one additional MID Server dedicated for use by Operational Intelligence (OI).

b)

This requires a MID Web Server in addition to the MID Server.

c)

Nothing additional is required; this is handled by the MID Server.

d)

This requires a minimum of two MID Servers - one for Event Management and one additional MID Server dedicated for use by Operational Intelligence (OI).

72.

What would be an appropriate use case for having to write JavaScript in Event Management?

a)

To change the value of the message key

b)

To create a custom action within a subflow.

c)

To parse a node name out of your raw event data in an event rule.

d)

To automatically create an incident.

73.

A dynamic grouping of CIs based upon common criteria (filtered CI classes) that can be visualized in operator workspace is called?

a)

A business service

b)

A technical service

c)

An application service

d)

A manual service

74.

During CI binding, CI matching is done using which two fields?(choose two)

a)

Message Key

b)

Additional Information

c)

Source

d)

Node

75.

What three areas of data quality does the CMDB Health Dashboard focus on? (choose three)

a)

Correctness

b)

Configuration

c)

Completeness

d)

Compliance

e)

Conciseness

76.

When sending data from the monitoring source to the additional_info field, what format is supported?

a)

XML

b)

JSON

c)

YAML

d)

Comma separated

77.

Which step in the event rule configuration process enables you to ignore events and prevent alert generation?

a)

Transform and compose alert output

b)

Event filter

c)

Event options

d)

Threshold

78.

What is an alert called that moves from an open to a closed state multiple times within a designated time-frame?

a)

Fluctuating

b)

Swinging

c)

Flipping

d)

Flapping

79.

How would you ensure the quality of data in your Configuration Management Database (CMDB) over time?

a)

Manually inventorying configuration items in the CMDB and eliminating duplicate configuration items (CIs)

b)

Only use the ServiceNow Discovery application to populate your CMDB

c)

Using only scripts to automatically monitor for and remediate duplicate configuration items (CIs)

d)

Having well-defined Identification, Reconciliation, and Relationship rules

80.

Which is an invalid state for an alert?

a)

Flapping

b)

Closed

c)

Reopen

d)

Processed

81.

A support agent resolves an incident associated with an alert. What is the best method to close the alert?

a)

Set the evt_mgmt.incident_closes_alert

b)

Set the evt_mgmt.alert_closes_incident

c)

Switch over to the alert form and close the alert manually

d)

Create a business rule on the alert table to match the associated Incident with its respective alert

e)

Create a business rule on the incident table

82.

Impacted services for alerts are calculated using data from which table?

a)

cmdb_ci_hardware

b)

em_impacted_svc

c)

cmdb_ci_rei

d)

svc_ci_assoc

83.

A monitoring tool notification of a notable occurrence is known as what?

a)

An alert

b)

An event

c)

A metric

d)

An alarm

84.

If a Message Key is not provided, which fields are concatenated to make our own?

a)

Source, DNS, Node, Additional info, Metric Name

b)

Source, Type, Node, Resource, Metric Name

c)

Source, Type, DNS, Additional info, Metric Name

d)

Source, Source Instance, Node, Type, Resource

85.

A load balanced web application has a cluster of 5 Apache nodes. When considering impact calculation with application cluster member rule influence set to 45, how many impacted nodes within that cluster would cause the overall application service to have a degradation of service?

a)

5

b)

1

c)

2

d)

3

e)

4

86.

A Service is not viewable in Operator Workspace. What could be the issue?

a)

The service is a manual service

b)

The service is not set to operational

c)

The service was created through Service Mapping

d)

The service is a technical service

87.

What ServiceNow feature is an aid to rapid implementation of your Event Management and Operational Intelligence features?

a)

Deployment wizard

b)

Step-by-step guide

c)

Checklist application

d)

Guided setup

88.

The ServiceNow standard and shared set of service-related definitions that enable and support true service level reporting is known as what?

a)

Service level data model

b)

Business service data model

c)

Application service data model

d)

Common service data model

89.

A monitoring tool notification of a notable occurrence is known as what?

a)

An alarm

b)

An alert

c)

An incident

d)

A notice

e)

An event

90.

Which is the best option to reduce latency issues when receiving events?

a)

Verify bucket field in em_event table > 0

b)

Verify event_processor_job_count = 2

c)

Verify event_processor_job_count = 0

d)

Verify event_processor_enable_multi_node = 2

91.

The default polling time to collect events from an event source is:

a)

5 seconds

b)

30 seconds

c)

60 seconds

d)

120 seconds

92.

Which two methods can be used to improve the processing of events in large network environments? (Choose two.)

a)

Enable multi-node processing

b)

Increase the source polling interval

c)

Ensure the bucket value in the event table is greater than 0.

d)

Increase the number of scheduled jobs processing events.

93.

The Event Management operator workspace can display all of the following except?

a)

Alert groups

b)

Manual application services

c)

Discovered application services from Service Mapping

d)

Correlation groups

e)

Technical services

94.

Within an event rule, how would you parse a nodename out of your raw event data?

a)

JavaScript

b)

Groovy script

c)

PowerShell script

d)

Regex statement

95.

If events are not matching to alerts as you would like, what field should be changed?

a)

Resource

b)

Message Key

c)

Node

d)

Metric Name

96.

If the Message Key is not populated, the default value is created from which fields?

a)

Source, type. node, resource, and metric name

b)

Source, source instance, node, and resource

c)

Source, type. node, and metric name

d)

Source, source instance, node, and type

e)

Source, type. node, resource, and time of event

97.

Processing on an event will create a state of error if what value is not set?

a)

Node

b)

Source

c)

Severity

d)

Message Key

e)

Resource

98.

When performing CI Binding, what fields does Event Management match to the Node?

a)

CI Name, DNS, IP, MAC Address

b)

System class name, FQDN, IP or MAC address

c)

CI name, FQDN, SSH public host keys

d)

CI Name, FQDN, IP, MAC Address

99.

Applying recommended Event Management best practice guidelines, which of the following alerts should be processed first?

a)

Alert00l0042

b)

Alert0010003

c)

Alert00l0075

d)

Alert00l0074

100.

What is the minimum role needed to view alerts?

a)

. alert_operator

b)

evt_mgmt_user

c)

evt_mgmt_operator

d)

alert_user

101.

By default, when are idle alerts are closed?

a)

After 7 days

b)

After 14 days

c)

After 30 days

d)

Never

102.

What is used to correctly bind an alert to an application?

a)

Correlation rules

b)

Workflows

c)

Classifiers

d)

CI identification rules

103.

If you wanted to create a quick response alert rule to open an Ask Jeeves search on the description of the alert, where would it configured?

a)

Launch Applications

b)

Remediation Workflows

c)

Remediation SubFlows

d)

Operator Workspace

104.

Where would you find the Priority Breakdown for an Alert?

a)

Under the More Information section

b)

Under the Activities section

c)

Under the History section

d)

Under the CI Problems section

105.

Where does an operator give feedback on an automated alert grouping?

a)

Feedback attribute on the virtual alert record

b)

Feedback attribute on the child alert record

c)

Feedback attribute on the event record

d)

Feedback attribute on the alert record

e)

Dropdown box on the alert group record

106.

In your environment, no alert CMDB, automated, or text based grouping is occurring. What is most likely the problem?

 

a)

No correlation rules have been defined

b)

No event management rules have been defined.

c)

Application services are not operational.

d)

No CMDB is configured.

e)

The alert correlation property that enables grouping is set to false.

107.

The additional information field is a JSON string that gives more information about an event. An example of a supported JSON string is:

a)

{"CPU":100}

b)

{"CPU":100,’Status":3}

c)

{"CPU":"100","Status":3}

d)

{"CPU":"100"}

108.

In order for SNMP trap notifications to appear in ServiceNow as events, what option must be enabled in the required MID server?

a)

MID SNMP trap listener

b)

SNMP event manager module for MID

c)

Event collector MID server extension

d)

SNMP agent for MID

109.

What event will cause Agent Client Collector self-monitoring to pause data collection?

a)

Communication with the MID server is lost

b)

The amount of host memory being used by the agent exceeds a threshold.

c)

The amount of host disk space used by the agent exceeds a threshold.

d)

The amount of host CPU being utilized by the agent exceeds a threshold.

110.

Agent Client Collector can perform application service monitoring by configuring what option?

a)

. An alert management rule

b)

A proxy agent

c)

A distributed cluster

d)

A REST API