CIS-ITSM — ServiceNow Certified Implementation Specialist – IT Service Management
ServiceNow

ServiceNow Certified Implementation Specialist – IT Service Management (CIS-ITSM) Practice Questions

4.8 57 verified reviews
132 questions
2026-06-29 updated
Online quiz simulator

Domain coverage

  • Incident Management (25%)
  • Change Management (25%)
  • Request Fulfillment (25%)
  • Problem Management (10%)
  • Knowledge Management (10%)
  • Configuration Management Database (CMDB) (5%)

Sample Questions (14 of 132 shown)

Q1 Incident Management
In base ServiceNow ITSM configuration, what happens to a resolved incident if no one reopens it?
  1. It is deleted after 7 days
  2. It automatically moves to Closed after 7 days
  3. It remains Resolved until an agent closes it manually
  4. It converts to a problem after 7 days
✓ Correct Answer: B
In the base configuration, a resolved incident automatically moves to Closed after 7 days. This keeps the lifecycle moving without requiring manual follow-up on every resolved record.
Q2 Incident Management
A widespread outage requires networking, identity, and messaging teams to work in parallel while leadership wants one communication hub. What is the best record design?
  1. One major incident with child incidents for the specialist teams
  2. Three unrelated major incidents, one for each resolver group
  3. One problem record with no incident records
  4. One catalog request with fulfillment tasks
✓ Correct Answer: A
A parent major incident provides a single place for stakeholder communication and status. Child incidents let specialist teams work independently while remaining coordinated under the same outage.
Q3 Incident Management
In the out-of-box incident priority design, which fields should analysts set to drive priority?
  1. Impact and urgency
  2. Category and subcategory
  3. State and assignment group
  4. Caller and configuration item
✓ Correct Answer: A
Out of the box, incident priority is derived from impact and urgency. This keeps prioritization consistent and avoids agents setting priority arbitrarily.
Q4 Incident Management
The business wants one target for first response and a separate target for restoring service. What should be configured?
  1. A single resolution SLA only
  2. Separate response and resolution SLAs
  3. A problem task for every incident
  4. A CAB approval before assignment
✓ Correct Answer: B
Response and resolution are different commitments and should be measured separately. Using distinct SLAs gives clearer reporting and avoids masking slow response with fast resolution.
Q5 Incident Management
A service desk restores email by restarting a service, but the outage has happened several times this month and the root cause is unknown. What should happen next?
  1. Create a problem and relate the recurring incidents to it
  2. Close the incident and take no further action
  3. Open a catalog item for the email team
  4. Convert the incident directly into a standard change
✓ Correct Answer: A
Incident Management restores service quickly, but repeated incidents indicate an underlying issue. A problem record gives the team a place to investigate root cause and track prevention work.
Q6 Incident Management
Service has been restored, but the team wants a short period for user confirmation before final closure. Which incident state is the best fit?
  1. New
  2. On Hold
  3. Resolved
  4. Canceled
✓ Correct Answer: C
Resolved indicates that restoration work is complete while still allowing a confirmation or reopen window. Closed is the final state and should come after that validation period.
Q7 Incident Management
One incident requires the desktop team to replace a laptop and the security team to revoke tokens at the same time. What is the best design?
  1. Create two unrelated incidents
  2. Use incident tasks under the same incident
  3. Use a request and requested items instead of an incident
  4. Close the incident and open a problem
✓ Correct Answer: B
Incident tasks are appropriate when multiple discrete activities must be tracked under one service restoration record. They keep the main incident as the user-facing record while allowing parallel work assignment.
Q8 Incident Management
During a major incident, which record should normally act as the main status and stakeholder communication hub?
  1. The parent major incident
  2. The oldest child incident
  3. A related problem record
  4. A change request
✓ Correct Answer: A
The parent major incident is the central coordination record. Child incidents and tasks support technical work, but the parent should remain the primary status and communication point.
Q9 Incident Management
A regional network outage affects 12 branch offices, and each office needs its own field dispatch notes and local ownership. What is the most scalable approach?
  1. Create one incident with all branch notes mixed together
  2. Create a parent incident with a child incident for each branch
  3. Create one problem record only
  4. Create a separate catalog request for each branch
✓ Correct Answer: B
A parent-and-child incident structure separates local work while preserving overall outage coordination. This pattern scales better than forcing all branch activity into one record with crowded updates and conflicting assignments.
Q10 Incident Management
A customer wants to use the Service Catalog to generate task-based records for end-user inquiries. What Service Catalog capability can you use to generate these records?
  1. Catalog Items
  2. Record Producers
  3. Content Items
  4. Execution Plans
✓ Correct Answer: B
Record Producers allow the creation of task-based records from the Service Catalog, making them ideal for end-user inquiries that need to generate incident, request, or other task records automatically.
Q11 Incident Management
If the Assignment group is empty on an incident record, what happens when an agent that is a member of a single user group clicks the Assign to me UI action?
  1. The agent is prompted to select the Assignment group
  2. The Assignment group field is populated with agent's user group
  3. The Assignment group field remains empty
  4. An error is displayed indicating the Assignment group field must be populated
✓ Correct Answer: B
When an agent who is a member of a single group clicks "Assign to me", the system populates both the Assigned to field with the agent and the Assignment group field with that agent's group automatically.
Q12 Incident Management
Incidents are stored in what table?
  1. Incident [task_incident]
  2. Incident [incident]
  3. Incident [sn_incident]
  4. Incident [sn_task_incident]
✓ Correct Answer: B
Incidents are stored in the incident table in ServiceNow, which extends from the task table.
Q13 Incident Management
On an incident record, where are the fields that appear on the caller lookup select box defined?
  1. The ref_ac_columns attribute from the dictionary entry
  2. The Caller lookup field on the [user] table
  3. The ref_contributions attribute on the caller lookup form
  4. The form design of the caller lookup form
✓ Correct Answer: A
The ref_ac_columns attribute in the dictionary entry for the caller field determines which columns appear in the auto-complete lookup select box on the incident form.
Q14 Incident Management
An incident has Priority 3 with a running SLA. The priority changes to Priority 1. What happens to the existing SLA?
  1. The existing SLA continues unchanged
  2. The existing SLA is replaced with the Priority 1 SLA
  3. The existing SLA is paused until the priority is reset
  4. The existing SLA triggers a breach immediately
✓ Correct Answer: B
When the priority of an incident changes, the SLA is re-evaluated based on the new priority. A new SLA definition matching the updated priority is applied, replacing the old one.

You've viewed 3 of 132 questions. Start the free practice exam to answer all questions with instant feedback.

Exam overview

Built for ITSM implementers, process owners, and ServiceNow consultants, the ServiceNow Certified Implementation Specialist – IT Service Management (CIS-ITSM) credential certifies your ability to deploy and configure the core ITSM applications — Incident, Change, Request Fulfillment, Problem, Knowledge, and CMDB — on the Now Platform. Delivered through Kryterion Webassessor (integrated via the Now Learning portal), the exam voucher costs $450 USD with $150 USD per retake, and no hands-on simulator or practical lab tasks appear during the proctored examination.

Before purchasing the voucher, candidates must hold the Certified Implementation Specialist – Data Foundations (CIS-DF) certification as a mandatory system policy prerequisite and complete a multi-course track including ITSM Fundamentals and ITSM Implementation (both available as On-demand or Instructor-Led). ServiceNow also recommends a minimum of six months of general platform experience plus six months of active hands-on ITSM application deployment or customization exposure, plus completion of the ITSM Fundamentals LabX and the ITSM Implementation Simulator on Now Learning.

The CIS-ITSM blueprint is organized into six weighted domains, with the heaviest emphasis on the three core ITSM processes — Incident Management (25%), Change Management (25%), and Request Fulfillment (25%) — which together account for 75% of the exam score. The remaining weight splits across Problem Management (10%), Knowledge Management (10%), and CMDB (5%). Because the exam uses multiple-select items with no partial credit, scenario questions on CAB workbench setup and approval routing loops, conflict detection and risk assessment engines, and the incident / sc_request / sc_req_item / sc_task table interactions are heavily tested.

For candidates preparing for the CIS-ITSM exam, our practice materials cover all six weighted domains in the same proportions as the real test, with online practice questions, detailed answer explanations, and a downloadable PDF that mirrors the single-select and multiple-select format you will see on exam day.

Official Exam Domains & Weighting

To successfully pass the CIS-ITSM exam, candidates must master the following core domains:
  • Domain 1: Incident Management (25%)
Covers baseline functionality, state models, the default process flow, and advanced features, key tables such as incident with roles (itil, itil_admin) and default Access Controls, Major Incident Management configuration with triggers and communication mechanics, and Script Includes, Business Rules, UI Actions, and integrations affecting the incident lifecycle.
  • Domain 2: Change Management (25%)
Tests Standard, Normal, and Emergency change types and their state paths, Change Advisory Board (CAB) workbench setup and approval routing loops, conflict detection engines, risk assessment engines and calculation rules, and best practices for maintaining upgradeability while overriding default properties such as Copy Change configuration.
  • Domain 3: Request Fulfillment (25%)
Focuses on Service Catalog structure, Categories, Catalog Items, and Record Producers, Variable sets, user criteria restrictions, and multi-step fulfillment workflows, the sc_request, sc_req_item, and sc_task table interactions, and Service Operations Workspace layout mapping for service requests.
  • Domain 4: Problem Management (10%)
Validates root cause analysis (RCA) lifecycles, Known Error records, Workaround handling, state flows, and the relationship mapping from Incident to Problem records with processing logic for problem assignment groups.
  • Domain 5: Knowledge Management (10%)
Covers Knowledge base architecture, submission loops, approval flows, and publishing and retirement lifecycles, contextual search configuration, integration with incidents and Search blocks, and version tracking, ownership models, and user criteria configurations.
  • Domain 6: Configuration Management Database (CMDB) (5%)
Tests core CMDB tables, Configuration Item (CI) classes, operational relationships, interaction points between base ITSM workflows (Incident and Change) and the CMDB, and Common Service Data Model (CSDM) alignment considerations during basic structural configuration.

What Our Customers Say 57 verified reviews

4.8 Based on 57 reviews
I bought the CIS-ITSM question bank a week before my exam and passed with 90%+. The questions are that good.
— Maria V.
Was on the fence about buying the CIS-ITSM practice test, but man am I glad I did. Nailed my certification today.
— Tyler M.
I work full time and study at night. The CIS-ITSM question bank allowed me to learn efficiently without wasting precious time.
— Harper S.
Used the CIS-ITSM test bank for two weeks before my exam date. Felt very prepared going in and the results showed.
— Luke M.
I used this alongside video courses for CIS-ITSM prep. The questions helped solidify what I learned from the lectures.
— Aria N.
The CIS-ITSM bank has a good mix of easy, medium, and hard questions. Kept me engaged and prevented me from getting complacent.
— Skylar M.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

If an attempt is unsuccessful, you can pay a retake fee of $150 USD via Webassessor to sit for the exam again. You can attempt the mainline exam up to four total times (1 initial attempt plus 3 retakes). If you fail all four times, the registration window locks and you must re-enroll in and complete the required training course sequence to regain fresh eligibility.

Mainline credentials remain valid as long as you complete the platform's continuous learning maintenance parameters. This requires completing the brief online Delta Learning and Maintenance Paths within Now Learning for major platform versions, and keeping up with the annual Certification Maintenance Program (CMP) fees.

Your initial pass or fail status is calculated instantly upon exam submission on the Webassessor portal screen. However, ServiceNow flags all preliminary scores as Conditional, meaning they are subject to routine testing security audits. If any violations of the ServiceNow Test Security Policies are discovered post-test, the result can be updated and your credential may be revoked.

ServiceNow requires CIS-Data Foundations as a system-level eligibility gate because the ITSM implementation exam assumes you already understand CMDB structure, table relationships, and Import Set mechanics. Without that foundation, scenario questions on Major Incident triggers, CAB conflict detection rules, and CSDM alignment would be unfair. This is not a recommended course — it is documented in Now Learning as a mandatory status verification for all CIS-stream credentials.

The mock exam scenarios target the same CAB mechanics the real exam tests — Standard, Normal, and Emergency change type routing, CAB workbench approval loop configuration, conflict detection engine rules, and risk assessment calculations. Each scenario presents a change management setup, asks which routing or approval outcome applies, and walks through the CAB workbench step by step in the answer explanation, with references to the official ServiceNow ITSM documentation.

The PDF download is most useful when you want to trace the sc_requestsc_req_itemsc_task state flows offline — for example, walking through the multi-step fulfillment workflow from Catalog Item submission through Variable sets and user criteria restrictions. The mock exam scenarios cover the same request lifecycle in interactive format for timed practice, while the PDF lets you study the table interaction sequence on paper during commutes or in environments without stable internet.

You must hold the Certified Implementation Specialist – Data Foundations (CIS-DF) certification, complete the Welcome to ServiceNow, ServiceNow Administration Fundamentals (SNAF) (or hold the CSA credential), Get Started with the Now Create Methodology, ServiceNow Platform Implementation, ITSM Fundamentals, and ITSM Implementation courses on Now Learning. ServiceNow also recommends a minimum of six months of platform experience plus six months of active ITSM deployment or customization exposure, plus completion of the ITSM Fundamentals LabX and ITSM Implementation Simulator.