Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews
Q1. What is the POST process, and why is it important in hardware troubleshooting?
Answer: POST (Power-On Self-Test) is a diagnostic routine run by the BIOS/UEFI firmware immediately after power-on. It checks the CPU, RAM, chipset, video adapter and keyboard before handing control to the bootloader. It is important because failures are reported through beep codes, LED patterns or on-screen error codes, which let a technician isolate the faulty component before the operating system is even involved.
Q2. What is the difference between BIOS and UEFI?
Answer: BIOS (Basic Input/Output System) and UEFI (Unified Extensible Firmware Interface) are firmware interfaces used to initialize computer hardware and start the operating system during the boot process.
BIOS is the older firmware technology. It uses the traditional Legacy Boot method and commonly works with the MBR (Master Boot Record) partitioning scheme.
UEFI is the modern replacement for BIOS. It supports GPT (GUID Partition Table), Secure Boot, larger storage devices, faster boot processes, and a more advanced firmware environment.
Q3. A desktop does not power on at all. What are the possible causes and how do you approach it?
Answer: Start with the simplest checks and work inward: wall socket, power cable, surge protector and the PSU rear switch. Then check the front-panel power switch connector, the 24-pin and CPU power connectors, and the motherboard standby LED. Possible causes include a failed PSU, a shorted component, a faulty power button or a dead motherboard. The paper-clip PSU test or a PSU tester confirms power supply health. If it still fails, strip the machine to minimum components (CPU, one RAM stick) and add parts back one at a time.
Q4. What do continuous or repeated beep codes during startup indicate?
Answer: Beep codes are the BIOS's way of reporting hardware faults when no display is available. Continuous or repeating beeps usually point to a RAM or power problem. Other patterns can indicate video card or motherboard faults. The exact meaning depends on the BIOS vendor (AMI, Award, Phoenix, Dell, HP), so the technician must check the manufacturer's documentation. A common first fix is to reseat the RAM modules and clean their contacts.
Q5. What is the difference between SSD and HDD, and when would you replace an HDD with an SSD?
Answer: An HDD stores data magnetically on spinning platters and has moving parts, so it is slower, noisier and more prone to mechanical failure. An SSD uses NAND flash memory with no moving parts, giving much faster boot and application load times, lower power use and better shock resistance. Replacing an HDD with an SSD is recommended when a system is slow to boot, shows high disk usage, has SMART warnings or is an ageing machine that still has a usable CPU and RAM.
Q6. How do you identify and respond to an imminent hard drive failure?
Answer: Typical signs are clicking or grinding noises, very slow file access, frequent freezes, corrupted files, disappearing partitions, blue screens with disk errors and SMART warnings. The first priority is to back up or clone the data immediately. Then check SMART status with a tool such as CrystalDiskInfo or the manufacturer's utility, run chkdsk, and replace the drive if the reallocated or pending sector counts are rising.
Q7. What is SMART technology in storage devices?
Answer: SMART (Self-Monitoring, Analysis and Reporting Technology) is built into HDDs and SSDs. It tracks health attributes such as reallocated sectors, temperature, power-on hours, read error rate and wear level. It can predict failure before data loss occurs. It is a predictive indicator, not a guarantee, because some drives fail without any SMART warning.
Q8. Why does a laptop overheat, and how do you fix it?
Answer: Common causes are dust-clogged vents and fans, dried thermal paste, a failing fan, blocked airflow when used on soft surfaces, and high CPU load from malware or background processes. The fix is to clean the vents and fan with compressed air, replace the thermal paste, replace a faulty fan, update the BIOS and drivers, and use a cooling pad. Persistent overheating causes thermal throttling, random shutdowns and reduced component life.
Q9. What is thermal paste, and when should it be replaced?
Answer: Thermal paste is a heat-conductive compound applied between the CPU or GPU and the heatsink. It fills microscopic gaps so heat transfers efficiently. It should be replaced when the heatsink is removed, or when the system overheats despite clean fans. Old paste dries out, typically after 3 to 5 years, and loses its conductivity.
Q10. What is the difference between RAM and ROM?
Answer: RAM is volatile working memory that holds running programs and data and loses its content when power is removed. ROM is non-volatile memory that retains firmware such as BIOS/UEFI permanently or semi-permanently. Insufficient RAM slows the system, while corrupted firmware can stop it booting at all.
Q11. How do you diagnose faulty RAM?
Answer: Symptoms are random blue screens, freezes, failure to boot, beep codes and application crashes. Diagnosis involves reseating the modules, testing one stick at a time in different slots, and running Windows Memory Diagnostic or MemTest86. If errors appear, the faulty module should be replaced. Mixing incompatible speeds or types is another common cause and should be ruled out.
Q12. A laptop battery drains quickly or does not charge. What are the troubleshooting steps?
Answer: First check the adapter, charging port, cable and power LED. Then check battery health using the powercfg /batteryreport command or the manufacturer's tool. Update BIOS and power drivers, and perform a power reset by removing the battery and AC adapter and holding the power button. Check for high-drain applications. If the battery's design capacity has dropped significantly, it has degraded and must be replaced.
Q13. What is the difference between a laptop that is plugged in but not charging and one with a dead battery?
Answer: A plugged-in but not charging laptop has a battery that is detected but not accepting charge. This is often due to a driver or firmware issue, an incompatible adapter or a charging-circuit fault. A dead battery means the cell has failed or the system cannot detect it at all. A good way to differentiate is to run the laptop on AC power with the battery removed. If it runs normally, the battery is the fault.
Q14. A PC has no display. How do you troubleshoot it?
Answer: Check that the monitor has power and the correct input source selected, and check the video cable. Test with another monitor or cable. Reseat the RAM and the graphics card, and check whether the PC reaches POST by listening for beeps or watching the LEDs. Try the onboard video port instead of the discrete GPU. Resetting the CMOS can also clear a bad firmware configuration. If the monitor works elsewhere and the PC still shows nothing, suspect RAM, GPU or motherboard.
Q15. What is the difference between integrated and dedicated graphics?
Answer: Integrated graphics are part of the CPU or motherboard chipset and share system RAM. They are cheap and power efficient and suitable for office work. A dedicated GPU is a separate card with its own VRAM and processing power, meant for gaming, CAD and video editing. Dedicated GPUs use more power and produce more heat.
Q16. What is CMOS, and why would you clear it?
Answer: CMOS is a small memory chip, powered by the CMOS (CR2032) battery, that stores BIOS settings such as date, time and boot order. Clearing it resets BIOS settings to factory default using a jumper, a button or by removing the battery. It is done when a bad setting prevents boot, the BIOS password is forgotten, or the system loses time after power-off, which usually indicates a dead CMOS battery.
Q17. Why is a laptop keyboard not working, and how do you troubleshoot it?
Answer: Causes include liquid spills, a loose keyboard ribbon cable, a driver issue, a stuck key or a failed keyboard controller. Test the keyboard in BIOS and test with an external USB keyboard. If the external keyboard works, update or reinstall the driver, and if the internal keyboard is dead in BIOS too, reseat or replace the keyboard assembly.
Q18. What are the common causes of a laptop screen problem, such as flickering, lines or dim display?
Answer: Flickering or lines are often caused by a loose or damaged display cable, a failing LCD panel or graphics driver problems. A dim display may be a failed backlight or inverter. To isolate the fault, connect an external monitor. If the external display is fine, the fault is in the panel or cable. If it also shows problems, the GPU or driver is at fault.
Q19. What is a paper jam in a printer, and how do you resolve it correctly?
Answer: A paper jam occurs when paper stops moving through the paper path, usually because of wrinkled, damp or wrong-size media, worn pickup rollers, or debris. Resolve it by powering off, opening all access doors, and removing the paper gently in the direction of travel to avoid tearing it. Then check for torn fragments and clean or replace the rollers. Using the right paper type and not overfilling the tray prevents repeat jams.
Q20. What is the difference between inkjet, laser and thermal printers?
Answer: Inkjet printers spray liquid ink through nozzles and are good for colour and photos at low volume. Laser printers use toner, a drum and heat from a fuser to fuse the image onto paper, making them fast and cost-efficient for office volumes. Thermal printers use heat on special paper or ribbon, and are common for receipts, labels and barcodes.
Q21. Why do printouts have streaks, faded patches or blank pages, and how do you fix them?
Answer: In inkjets, the cause is clogged nozzles, so you run head cleaning and alignment. In laser printers, streaks are caused by a worn drum, low or leaking toner or a dirty corona wire. Faded print often means low toner, and blank pages can mean a toner cartridge fault or failed transfer roller. The fix is to clean, replace the consumable and, if the issue continues, check the fuser and imaging unit.
Q22. What is the role of the fuser unit in a laser printer?
Answer: The fuser applies heat and pressure to melt toner and bond it permanently to the paper. A failing fuser causes smudged toner that rubs off, wrinkled pages, paper jams near the exit or error codes. The fuser runs very hot, so the printer must be switched off and cooled before servicing.
Q23. What is a print spooler, and what do you do when print jobs are stuck?
Answer: The print spooler is a Windows service that queues print jobs and sends them to the printer in order. Jobs get stuck due to a corrupt job, a stopped service, a driver error or an offline printer. The fix is to stop the Print Spooler service, delete the files in the spool\PRINTERS folder, then start the service again. Also check the printer status, port and driver.
Q24. How do you troubleshoot a network printer that shows as offline?
Answer: Check the printer's power and network cable or Wi-Fi, and print a configuration page to confirm its IP address. Ping the IP from the PC. Check that the printer port in Windows uses the correct IP, since a DHCP change may have altered it. Restart the spooler, make sure that 'Use Printer Offline' is not ticked, and update the driver. A static IP or DHCP reservation for printers prevents recurrence.
Q25. Define preventive maintenance for IT hardware and give its benefits.
Answer: Preventive maintenance is the scheduled, proactive servicing of equipment to avoid failures. It includes cleaning dust, updating firmware and drivers, checking disk health, testing batteries, replacing consumables and verifying backups. Benefits are reduced downtime, longer hardware life, lower support costs and fewer emergency incidents, which is especially valuable in a payroll environment where systems must be reliable at month-end.
Q1. What is the OSI model, and why is it useful for troubleshooting?
Answer: The OSI model divides network communication into seven layers: Physical, Data Link, Network, Transport, Session, Presentation and Application. It gives a structured method to isolate faults. A common approach is bottom-up: check cabling and link lights (Layer 1), then switching and MAC (Layer 2), then IP addressing and routing (Layer 3), and so on, rather than guessing.
Q2. What is the difference between LAN, WAN and MAN?
Answer: A LAN covers a small area such as an office or building and is usually privately owned with high speed. A MAN spans a city or campus. A WAN connects networks across large geographical distances, often using leased lines, MPLS, SD-WAN or the internet from a service provider. WANs generally have higher latency, and less control over the path, than LANs.
Q3. What is the difference between a hub, switch and router?
Answer: A hub is a Layer 1 device that repeats traffic to all ports, creating a single collision domain. A switch is a Layer 2 device that uses the MAC address table to forward frames only to the destination port. A router is a Layer 3 device that forwards packets between different networks using IP routing tables. Switches create separate collision domains, and routers separate broadcast domains.
Q4. What is an IP address, and what is the difference between IPv4 and IPv6?
Answer: An IP address is a logical identifier assigned to a device on a network. IPv4 is 32 bits, written in dotted decimal such as 192.168.1.10, giving about 4.3 billion addresses. IPv6 is 128 bits, written in hexadecimal, which gives a practically unlimited address space and built-in features such as auto-configuration and IPsec support. IPv6 was introduced because IPv4 addresses are exhausted.
Q5. What is a subnet mask, and why is subnetting used?
Answer: A subnet mask separates the network portion of an IP address from the host portion, for example 255.255.255.0 or /24. Subnetting divides a large network into smaller ones to reduce broadcast traffic, improve security through segmentation and use addresses efficiently. A frequent fault is a wrong subnet mask, which stops a device communicating outside its own segment.
Q6. What is the default gateway, and what happens if it is misconfigured?
Answer: The default gateway is the router interface that a host sends traffic to when the destination is on a different network. If it is wrong or missing, the device can communicate within its local subnet but cannot reach other networks or the internet. This is a common cause of 'local works, internet does not'.
Q7. What is the difference between a public and a private IP address?
Answer: Public IPs are globally unique and routable on the internet, assigned by an ISP. Private IPs (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) are used inside internal networks and are not routable on the internet. NAT translates private addresses to a public address so internal devices can reach the internet.
Q8. What is NAT, and why is it used?
Answer: NAT (Network Address Translation) translates private IP addresses into a public address as traffic leaves the network. It conserves public IPv4 addresses and hides the internal addressing from outside. Its drawbacks are that it can break some protocols and make end-to-end connectivity and troubleshooting harder.
Q9. What is the difference between TCP and UDP?
Answer: TCP is connection-oriented and reliable. It uses a three-way handshake, sequencing, acknowledgements and retransmission, which suits web, email and file transfer. UDP is connectionless and has no guarantee of delivery, but it is faster and has lower overhead, which suits DNS queries, VoIP and video streaming.
Q10. What is DHCP, and what happens when a client gets a 169.254.x.x address?
Answer: DHCP automatically assigns IP address, subnet mask, gateway and DNS settings to clients using the DORA process (Discover, Offer, Request, Acknowledge). A 169.254.x.x address is an APIPA address, which Windows self-assigns when no DHCP server responds. It indicates a DHCP failure, a network connectivity problem or an exhausted scope, and the client can talk only to other APIPA devices on the same segment.
Q11. What is DNS, and how would you troubleshoot a user who can ping an IP address but cannot open websites by name?
Answer: DNS translates hostnames into IP addresses. If a user can reach an IP but not a name, the problem is name resolution. Check the configured DNS servers with ipconfig /all, test with nslookup, flush the cache with ipconfig /flushdns, and verify that the DNS server is reachable and its service is running. Wrong DNS settings, an offline DNS server or a blocked port 53 are typical causes.
Q12. What is the purpose of the ping command, and what does 'Request timed out' versus 'Destination host unreachable' mean?
Answer: Ping uses ICMP echo requests to test reachability and measure round-trip time. 'Request timed out' means no reply was received, which can be due to the target being down, a firewall blocking ICMP or a routing problem. 'Destination host unreachable' means a router or the local system reports it has no route to the destination, which usually points to a routing or gateway issue.
Q13. How do tracert/traceroute and pathping help in troubleshooting?
Answer: Tracert shows each hop that packets cross to reach a destination, along with latency per hop, so you can find where delay or failure occurs. Pathping combines tracert and ping, giving packet-loss statistics per hop over time. They help to identify whether the issue is local, within the ISP or at the destination.
Q14. What is the difference between ipconfig /release, /renew and /flushdns?
Answer: ipconfig /release drops the current DHCP lease, /renew requests a new lease from the DHCP server, and /flushdns clears the local DNS resolver cache. Together they are a standard first step to fix stale or incorrect IP or DNS settings on a client.
Q15. What is a VLAN, and why is it used?
Answer: A VLAN (Virtual LAN) logically segments a switch into separate broadcast domains regardless of physical location. It improves security, reduces broadcast traffic and simplifies management, for example by separating Finance, HR and Guest traffic. Inter-VLAN communication requires a Layer 3 device. Common faults are a wrong VLAN assignment on the port or a missing trunk configuration.
Q16. What is the difference between an access port and a trunk port?
Answer: An access port carries traffic for a single VLAN and connects end devices such as PCs and printers. A trunk port carries traffic for multiple VLANs between switches or to a router using tagging (IEEE 802.1Q). A mismatched trunk configuration is a common cause of VLAN connectivity loss.
Q17. What is a MAC address, and what is ARP?
Answer: A MAC address is a unique 48-bit hardware address burned into a network interface and used at Layer 2. ARP (Address Resolution Protocol) maps a known IP address to its MAC address on the local network. The arp -a command shows the ARP cache, and duplicate IP conflicts or stale entries can be diagnosed from it.
Q18. What causes an IP address conflict, and how do you resolve it?
Answer: An IP conflict occurs when two devices use the same IP address, typically because of a static address inside the DHCP range, or a rogue DHCP server or device. Windows displays an 'IP address conflict' warning. To resolve it, identify the duplicate using arp -a and the MAC address, assign unique addresses, exclude static ranges from DHCP, and use DHCP reservations.
Q19. What are common causes of slow network performance, and how do you troubleshoot it?
Answer: Causes include bandwidth saturation, duplex mismatch, faulty cables or ports, broadcast storms, switching loops, malware, misconfigured QoS and DNS delays. Troubleshooting involves checking link speed and duplex, interface error counters, bandwidth utilisation, replacing suspect cables, and testing against a known good connection to isolate the segment.
Q20. What is the difference between a straight-through and a crossover cable, and what are the common cable faults?
Answer: A straight-through cable connects unlike devices, such as a PC to a switch, and a crossover cable connects like devices, such as switch to switch. Modern devices use Auto-MDIX, so either type usually works. Common cable faults are open circuits, shorts, split pairs, excessive length over 100 metres and interference. A cable tester checks wiring and continuity.
Q21. What is a firewall, and how can it cause connectivity problems?
Answer: A firewall filters traffic based on rules for IP, port, protocol or application. Misconfigured rules can block legitimate traffic, for example blocking ICMP so ping fails, or blocking ports for email or web access. A technician can verify by testing with the firewall temporarily disabled in a controlled way, or by reviewing rule logs, then correcting the rule rather than leaving security off.
Q22. What is the difference between a VPN and a leased line for WAN connectivity?
Answer: A VPN creates an encrypted tunnel over the public internet. It is low cost and flexible, but performance depends on the internet quality. A leased line is a dedicated private circuit with guaranteed bandwidth and low latency, but it costs more. MPLS and SD-WAN are other WAN options that provide managed paths with quality-of-service.
Q23. How do you troubleshoot a WAN link that is down between two offices?
Answer: Confirm the scope of the outage and check local router and interface status for link lights and errors. Ping the local and remote router interfaces, then run tracert to see where the path breaks. Check the VPN tunnel status or the ISP circuit, review recent configuration changes and then raise a ticket with the ISP with evidence such as trace results and circuit ID. A documented failover link helps restore service meanwhile.
Q24. What is a structured approach to network troubleshooting?
Answer: Follow a standard method: identify the problem, establish a theory of probable cause, test the theory, establish a plan of action, implement the solution or escalate, verify full functionality, and document the findings. Using a systematic approach such as top-down, bottom-up or divide-and-conquer avoids random changes and shortens resolution time.
Q25. What is port security on a switch, and why is it used?
Answer: Port security limits which MAC addresses can use a switch port and how many, and defines the action on a violation (shutdown, restrict or protect). It prevents unauthorised devices from connecting and mitigates MAC flooding. A port that suddenly goes into an err-disabled state is a common troubleshooting scenario, and is resolved by removing the cause and re-enabling the port.
Q1. What is the Windows boot process, in sequence?
Answer: On a UEFI system: firmware performs POST, loads the Windows Boot Manager (bootmgfw.efi) from the EFI System Partition, which reads the BCD (Boot Configuration Data) and starts winload.efi. Winload loads the kernel (ntoskrnl.exe), the HAL and boot-start drivers. The kernel then initialises services, Session Manager (smss.exe) starts, and the logon screen appears via winlogon. Knowing the sequence tells you which stage a failure belongs to, for example a BCD error versus a driver crash.
Q2. What is Windows Recovery Environment (WinRE), and when do you use it?
Answer: WinRE is a minimal recovery operating system that starts automatically after repeated boot failures or from installation media. It offers Startup Repair, System Restore, Uninstall Updates, Command Prompt, Reset this PC and System Image Recovery. It is used when Windows will not boot, for example because of a corrupt BCD, a faulty update or a bad driver.
Q3. What is the difference between Safe Mode, Safe Mode with Networking and Clean Boot?
Answer: Safe Mode loads only essential drivers and services with no network. Safe Mode with Networking adds network drivers. Clean Boot starts Windows normally but disables non-Microsoft services and startup items, which helps find software conflicts. Safe Mode isolates driver or OS faults, and Clean Boot isolates third-party software conflicts.
Q4. How do you troubleshoot a Windows machine that is stuck on a boot loop or shows 'Automatic Repair'?
Answer: Boot into WinRE and try Startup Repair. If that fails, use the command prompt: bootrec /fixmbr, /fixboot, /scanos and /rebuildbcd, then sfc /scannow with offline parameters and chkdsk. Other options are uninstalling recent updates or drivers, System Restore, and as a last resort Reset this PC. Always check disk health too, because a failing drive often causes the loop.
Q5. What is a BSOD (Blue Screen of Death), and how do you diagnose it?
Answer: A BSOD is a stop error where Windows halts to prevent damage after a critical fault, typically caused by faulty drivers, bad RAM, disk corruption or overheating. Diagnose by noting the stop code (for example IRQL_NOT_LESS_OR_EQUAL or INACCESSIBLE_BOOT_DEVICE), reviewing the minidump with WinDbg or BlueScreenView, and checking Event Viewer. Then roll back or update the driver, run memory and disk tests and review recent changes.
Q6. What is the difference between SFC and DISM, and when are they used?
Answer: SFC (sfc /scannow) scans and repairs protected system files using the local component store. DISM (DISM /Online /Cleanup-Image /RestoreHealth) repairs the component store itself, using Windows Update or a source image. If SFC cannot repair files, you run DISM first and then SFC again.
Q7. What is Task Manager used for, and how do you use it to find the cause of a slow PC?
Answer: Task Manager shows processes, performance (CPU, memory, disk, network), startup impact, services and users. For a slow PC, check which resource is saturated, identify the process responsible, disable unnecessary startup apps and look for 100% disk usage or memory leaks. Resource Monitor and Performance Monitor can then give deeper detail.
Q8. What is Event Viewer, and how do you use it in fault finding?
Answer: Event Viewer is the central log tool that records system, application and security events. For troubleshooting, review the System and Application logs around the time of the fault, filter by Critical and Error levels, and use the Event ID and source to research the cause. For example Event ID 41 (Kernel-Power) indicates an unexpected shutdown.
Q9. What is the difference between a Local account, a Microsoft account and a Domain account in Windows?
Answer: A local account exists only on that PC. A Microsoft account is a cloud identity used to sync settings and access Microsoft services. A domain account is managed centrally by Active Directory (or Entra ID in a cloud setup) and is the standard in a corporate environment, allowing central policies, access control and password management.
Q10. How do you resolve the 'Trust relationship between this workstation and the primary domain failed' error?
Answer: This happens when the computer account's secret password with the domain is out of sync, for example after an image restore or a long offline period. Fix by logging on with a local administrator account, removing the PC from the domain and rejoining it, or by resetting the machine account with Reset-ComputerMachinePassword or Test-ComputerSecureChannel -Repair. Also check time synchronisation and DNS settings.
Q11. What is Windows Update, and how do you troubleshoot failing updates?
Answer: Windows Update delivers security patches, quality updates and feature updates. If an update fails, run the Windows Update troubleshooter, check disk space, stop services (wuauserv, bits), clear the SoftwareDistribution folder, run DISM and SFC, and review error codes in Event Viewer or the update history. If it still fails, install the update manually from the Microsoft Update Catalog.
Q12. What is the difference between Windows 10 and Windows 11 system requirements?
Answer: Windows 11 requires a 64-bit processor from a supported list, 4 GB RAM, 64 GB storage, UEFI with Secure Boot and TPM 2.0. Windows 10 does not require TPM 2.0 or Secure Boot. This is why many older machines cannot upgrade, and why the PC Health Check app is used to assess compatibility.
Q13. What is TPM, and why is it required for Windows 11?
Answer: A Trusted Platform Module is a hardware chip that securely stores cryptographic keys and supports features such as BitLocker, Windows Hello and measured boot. Windows 11 requires TPM 2.0 to strengthen security baselines against firmware and credential attacks.
Q14. What is BitLocker, and what do you do if a user is asked for a recovery key?
Answer: BitLocker is Windows full-disk encryption that protects data if a device is lost or stolen. A recovery key prompt appears after hardware changes, BIOS updates, boot-order changes or TPM issues. The administrator retrieves the 48-digit key from Active Directory, Entra ID, or the user's Microsoft account, and the key should be stored centrally by policy.
Q15. What are Windows Services, and how do you troubleshoot a service that fails to start?
Answer: Services are background processes that run without user interaction, managed through services.msc. If one fails to start, check Event Viewer for the error, verify its dependencies, the logon account and its permissions, check the executable path, and try restarting. Setting the correct startup type and recovery actions prevents repeated failure.
Q16. What is the Windows Registry, and what precautions should be taken when editing it?
Answer: The Registry is a hierarchical database that stores configuration for Windows, hardware, users and applications. Incorrect edits can make the system unbootable, so always back up the key or create a restore point before making changes, document the change, and edit only when no supported setting exists.
Q17. What is a user profile, and how do you fix a corrupt user profile?
Answer: A user profile contains a user's settings, desktop, documents and registry hive (NTUSER.DAT). Corruption shows as a temporary profile or failure to log on. Fix by backing up the old profile data, creating a new profile or fixing the registry ProfileList entry (removing .bak mismatches), and then restoring the user's data.
Q18. What is the difference between System Restore, Reset this PC and a System Image backup?
Answer: System Restore returns system files, drivers and registry to an earlier restore point without affecting personal files. Reset this PC reinstalls Windows, with the option to keep or remove files and apps. A System Image is a complete backup of the whole drive, allowing full recovery to an exact earlier state.
Q19. What is Group Policy, and how do you troubleshoot a policy that is not applying?
Answer: Group Policy is a feature of Active Directory that centrally controls computer and user settings. If a policy is not applying, run gpupdate /force and gpresult /r to see which GPOs applied, check OU linking, security filtering, WMI filters, inheritance and replication, and confirm that the client can reach the domain controller and resolve DNS.
Q20. How do you troubleshoot a slow Windows startup?
Answer: Review the Startup tab in Task Manager and disable high-impact apps. Check for disk bottlenecks (replace HDD with SSD), low RAM, malware and pending updates. Disable Fast Startup if it causes problems, update drivers, and review boot performance events in Event Viewer. Running chkdsk and checking the disk's SMART status rule out hardware causes.
Q21. How do you troubleshoot a PC that has no internet connection in Windows?
Answer: Check physical connectivity or Wi-Fi status, run the network troubleshooter, review ipconfig /all, and ping the gateway, an external IP and a domain name in sequence to find the failing layer. Then try ipconfig /release and /renew, flushing DNS, netsh winsock reset and netsh int ip reset, and update or reinstall the network adapter driver. Also check proxy settings and VPN software.
Q22. What is Windows Defender, and how do you handle a suspected malware infection?
Answer: Microsoft Defender is the built-in antivirus and security platform with real-time protection. For a suspected infection, disconnect the PC from the network, run a full or offline Defender scan, check startup items, scheduled tasks and installed programs for suspicious entries, apply updates, and change relevant passwords. If it cannot be cleaned, reimage the machine after backing up data.
Q23. What is the difference between a 32-bit and a 64-bit Windows operating system?
Answer: A 32-bit system can address a maximum of 4 GB of RAM and runs 32-bit applications. A 64-bit system can address far more memory, runs both 64-bit and 32-bit applications, and offers better security features. Modern hardware and Windows 11 are 64-bit only.
Q24. What are the common methods to deploy and manage Windows 10/11 at scale?
Answer: Common methods include imaging with WDS/MDT, Windows Autopilot for cloud-based provisioning, Microsoft Intune or SCCM/Configuration Manager for application deployment and policy management, and Group Policy for domain-joined machines. These ensure consistent configuration, faster rollout and easier support.
Q25. What is the difference between a clean install, an in-place upgrade and a repair install of Windows?
Answer: A clean install wipes the disk and installs a fresh copy of Windows, which removes persistent software faults but requires reinstalling apps and restoring data. An in-place upgrade installs a new Windows version over the existing one and keeps files, apps and settings. A repair install uses the same method on the same version to replace damaged system files while preserving user data.
Q1. What is Windows Server 2022, and what are its main editions?
Answer: Windows Server 2022 is Microsoft's server operating system, designed for hosting infrastructure roles such as Active Directory, DNS, DHCP, file services and virtualisation. Its main editions are Standard, Datacenter and Datacenter: Azure Edition. Standard suits physical or lightly virtualised environments, and Datacenter provides unlimited virtualisation rights and advanced features such as Storage Spaces Direct.
Q2. What is the difference between Server Core and Desktop Experience installation?
Answer: Server Core has no graphical shell and is managed by command line, PowerShell or remotely. It has a smaller attack surface, lower resource use and fewer patches. Desktop Experience includes the full GUI, which is easier for administrators who are less familiar with the command line.
Q3. What are Server Manager and Roles and Features?
Answer: Server Manager is the central console for managing local and remote servers. Roles (for example DNS, DHCP, AD DS, WDS) define the primary function of a server, and features are supporting components such as Failover Clustering or Windows Server Backup. They are added through the Add Roles and Features wizard or with Install-WindowsFeature in PowerShell.
Q4. What is Active Directory Domain Services (AD DS), and how does it relate to DNS?
Answer: AD DS is a directory service that stores objects such as users, computers and groups, and provides authentication and authorisation. It depends on DNS, because clients locate domain controllers using SRV records. If DNS fails, domain logon, group policy and replication break, which is why DNS is described as the backbone of Active Directory.
Q5. What is DNS, and what is the difference between a forward and a reverse lookup zone?
Answer: DNS resolves names to IP addresses. A forward lookup zone maps a hostname to an IP address using A and AAAA records. A reverse lookup zone maps an IP address back to a hostname using PTR records. Reverse zones are used for logging, email validation and some authentication checks.
Q6. What are the common DNS record types?
Answer: A maps a name to an IPv4 address, AAAA to an IPv6 address, CNAME creates an alias, MX identifies mail servers, NS identifies name servers for a zone, PTR does reverse lookup, SRV locates services such as domain controllers, and SOA holds the zone's authority and refresh information.
Q7. What is the difference between a Primary, Secondary and Active Directory-integrated DNS zone?
Answer: A primary zone holds the writable master copy of the zone file. A secondary zone is a read-only copy obtained by zone transfer. An AD-integrated zone stores data in Active Directory, replicates with AD, supports secure dynamic updates and multi-master writes, and is the recommended option on domain controllers.
Q8. What is the difference between a DNS forwarder and a conditional forwarder?
Answer: A forwarder sends queries that the DNS server cannot resolve to another DNS server, such as an ISP or public resolver. A conditional forwarder sends queries only for a specific domain name to a designated DNS server, which is useful for partner or branch-domain resolution.
Q9. How do you troubleshoot DNS issues on Windows Server?
Answer: Check that the DNS Server service is running, verify the server's own and clients' DNS settings, and use nslookup, ipconfig /flushdns and Resolve-DnsName to test. Review zone records for stale or missing entries, check Event Viewer (DNS Server log) and run dcdiag /test:dns. Confirm that firewall rules allow port 53 and test replication when AD-integrated.
Q10. What is DNS scavenging, and why is it important?
Answer: Scavenging automatically removes stale DNS records, mainly dynamically registered entries that were not refreshed. It prevents the zone from filling with outdated records that cause incorrect name resolution. It should be enabled carefully with appropriate no-refresh and refresh intervals to avoid deleting valid records.
Q11. What is DHCP, and what is the DORA process?
Answer: DHCP automatically provides IP configuration to clients. DORA stands for Discover (client broadcasts to find a server), Offer (server proposes an address), Request (client accepts) and Acknowledge (server confirms the lease). This is why a DHCP server and clients must be on the same broadcast domain or use a DHCP relay agent.
Q12. What are a DHCP scope, exclusion, reservation and lease?
Answer: A scope is the range of IP addresses a server can hand out. An exclusion is a range within the scope that is never assigned, used for static devices. A reservation ties a specific IP to a device's MAC address so it always receives the same address, which is ideal for printers. A lease is the time period for which a client may use an address.
Q13. What is a DHCP relay agent, and why is it needed?
Answer: DHCP discovery messages are broadcasts that routers do not forward. A relay agent (IP helper address) on the router or a server converts the broadcast into a unicast and forwards it to the DHCP server on another subnet. This lets one DHCP server serve multiple VLANs or subnets.
Q14. What does DHCP authorisation mean in Active Directory?
Answer: In a domain, a Windows DHCP server must be authorised in Active Directory before it can lease addresses. This prevents unauthorised or rogue DHCP servers from issuing incorrect configuration to clients. It is done in the DHCP console, and requires appropriate administrative rights.
Q15. What are the common causes when clients are not getting an IP address from DHCP?
Answer: The causes include a stopped DHCP service, an unauthorised server, an exhausted scope, an inactive scope, a missing relay agent, a VLAN or switch port problem, firewall blocking of UDP 67/68, or a rogue DHCP server. Check the scope statistics and address leases, Event Viewer and the client's ipconfig /all output, and then run ipconfig /renew.
Q16. What is a rogue DHCP server, and how is it detected and prevented?
Answer: A rogue DHCP server is an unauthorised device, often a personal router, that hands out incorrect IP settings and disrupts the network. It is detected by clients getting the wrong gateway or addresses, and by tools such as dhcploc or packet capture. Prevention uses AD authorisation and DHCP snooping on managed switches.
Q17. What is DHCP failover, and why is it used?
Answer: DHCP failover allows two Windows DHCP servers to share scope information so that clients continue to obtain leases if one fails. It supports load-balance and hot-standby modes, which improves availability without the older split-scope approach.
Q18. What is the difference between a static and a dynamic IP assignment, and when is each appropriate?
Answer: Static addresses are manually configured and suit servers, printers and network devices that must keep the same address. Dynamic addresses are assigned by DHCP and suit client devices, reducing administration and avoiding conflicts. The best practice is DHCP reservations for devices that need consistency.
Q19. What is Windows Deployment Services (WDS)?
Answer: WDS is a Windows Server role used to deploy Windows operating systems to computers over the network using PXE boot, without physical media. It stores boot images and install images, and is commonly used with MDT or unattended answer files to standardise rollouts.
Q20. What are boot images and install images in WDS?
Answer: A boot image (boot.wim) is a minimal Windows PE environment that loads on the client to run the installation process. An install image (install.wim) is the actual operating system image that is applied to the client's disk. Both must be added to WDS for deployment to work.
Q21. What is PXE boot, and what does it need to work with WDS?
Answer: PXE (Preboot Execution Environment) lets a computer boot from its network card. It requires the client to obtain an IP address from DHCP, find the WDS server through DHCP options or a configured boot server, and download the boot image through TFTP. The BIOS or UEFI network boot must be enabled on the client.
Q22. What are the prerequisites for installing WDS?
Answer: WDS needs a Windows Server with the role installed, an NTFS partition for the image store, a DHCP server on the network, a DNS server and, in standard mode, Active Directory membership. Administrator rights and the Windows installation media are needed to add images.
Q23. How do you troubleshoot a client that fails to PXE boot from WDS?
Answer: Verify that the client's network boot is enabled and the boot mode (UEFI vs Legacy) matches the boot image architecture. Check that DHCP is working and the client is on the correct VLAN or has an IP helper pointing to both DHCP and WDS. Confirm that the WDS service is running, the boot image exists and ports (UDP 67, 68, 69, 4011) are open. Review WDS and Event Viewer logs for errors.
Q24. What is the difference between standalone and Active Directory-integrated WDS?
Answer: Standalone mode works without Active Directory and is managed locally, with no domain join automation. AD-integrated mode uses AD for computer account pre-staging, domain join options and authorisation, which suits corporate environments.
Q25. What basic Windows Server maintenance and monitoring practices should an administrator follow?
Answer: Apply patches on a controlled schedule, maintain tested backups using Windows Server Backup or third-party tools, monitor disk, CPU, memory and services, review Event Viewer, apply the principle of least privilege, and document all changes. Regular health checks of AD, DNS and DHCP ensure issues are found before users are affected.
Q1. What is Microsoft 365 (Office 365), and what are its core services?
Answer: Microsoft 365 is a cloud subscription platform that bundles productivity apps and services. Core services include Exchange Online (email), SharePoint Online and OneDrive (file storage and collaboration), Microsoft Teams (chat and meetings), Office desktop apps such as Outlook, Word and Excel, and Entra ID for identity. It is managed centrally from the Microsoft 365 admin center.
Q2. What is the Microsoft 365 admin center, and what can an administrator do there?
Answer: It is the web portal (admin.microsoft.com) used to manage users, groups, licences, domains, billing, service health and support requests. Typical administrator tasks include creating users, assigning licences, resetting passwords, managing shared mailboxes and checking Service Health for outages.
Q3. What is the difference between Exchange Online and on-premises Exchange Server?
Answer: Exchange Online is hosted and maintained by Microsoft, with no server hardware to manage and automatic updates. On-premises Exchange runs on the organisation's own servers and gives more control but requires patching, capacity planning and backups. A hybrid deployment links the two so mailboxes can exist in both.
Q4. What is Entra ID (formerly Azure AD), and how does it relate to Microsoft 365?
Answer: Entra ID is Microsoft's cloud identity and access management service. Every Microsoft 365 tenant uses it to authenticate users, apply conditional access and multi-factor authentication, and manage groups and licences. It can be synchronised with on-premises Active Directory using Entra Connect, so users have a single identity.
Q5. What is the difference between a user mailbox, shared mailbox, resource mailbox and distribution group?
Answer: A user mailbox belongs to one person and needs a licence. A shared mailbox is used by multiple users, such as info@ or payroll@, and does not need a licence if under 50 GB with no archive. A resource mailbox represents a room or equipment for booking. A distribution group is a mailing list that forwards email to members and has no mailbox of its own.
Q6. What are licences in Microsoft 365, and what happens if a licence is removed?
Answer: Licences grant a user access to services, for example Exchange Online or Teams. If a licence is removed, the user loses access to the related services, and the mailbox is retained for a limited period (typically 30 days) before it is deleted, so licences should be removed only after data retention decisions are made.
Q7. What is MFA, and why is it important in Microsoft 365?
Answer: Multi-Factor Authentication requires a second verification step such as an authenticator app notification, in addition to the password. It protects accounts from credential theft and phishing, and is one of the most effective security controls. Administrators enable it through Conditional Access or security defaults.
Q8. What is an Outlook profile, and how do you fix a corrupted profile?
Answer: An Outlook profile stores account settings and links to mailbox data. If Outlook crashes, will not open or keeps asking for a password, a corrupted profile is a common cause. Create a new profile through Control Panel > Mail > Show Profiles, add the account, and set it as default. The mailbox data is on the server, so it is re-synchronised.
Q9. What is the difference between a PST file and an OST file?
Answer: A PST is a personal data file used for archives and backups that can be moved between computers. An OST is an offline cache of an Exchange or Exchange Online mailbox, which allows Outlook to work offline and sync later. An OST can be deleted and rebuilt from the server, but a PST must be backed up because it may contain the only copy of the data.
Q10. What are IMAP, POP3, SMTP and MAPI/HTTP, and how do they differ?
Answer: POP3 downloads email to one device and usually removes it from the server. IMAP keeps mail on the server and synchronises across devices. SMTP is used for sending mail. MAPI over HTTP is the modern protocol Outlook uses with Exchange to synchronise mail, calendar and contacts, and it supports full features. Exchange Online uses it by default.
Q11. How do you troubleshoot Outlook that is stuck on 'Disconnected' or 'Trying to connect'?
Answer: Check internet access and that Work Offline is not enabled. Then verify the account status in the Microsoft 365 portal, check for service outages, run Outlook in safe mode (outlook.exe /safe) to rule out add-ins, repair the Office installation, create a new profile and run the Microsoft Support and Recovery Assistant (SaRA) tool. Also check that credentials are not expired or locked.
Q12. Why does Outlook keep asking for a password, and how do you resolve it?
Answer: Causes include cached credentials that are outdated, a recently changed password, modern authentication not enabled, MFA or conditional access conflicts, or a corrupt profile. Clear saved credentials from Windows Credential Manager, sign out and back in of Office, confirm the account in Entra ID is not blocked, and recreate the profile if the problem persists.
Q13. How do you fix Outlook that crashes or will not start?
Answer: Start Outlook in safe mode to test add-ins, then disable problem add-ins, run Quick Repair then Online Repair of Office, update Office, rename or recreate the profile and scan the data file with scanpst.exe. Review Event Viewer for the faulting module. A conflicting antivirus or add-in is a frequent cause.
Q14. What is mailbox quota, and what do you do when a mailbox is full?
Answer: A mailbox quota is the maximum storage allowed for a mailbox (for example 50 GB or 100 GB depending on licence). When full, the user cannot send or receive messages. The solution is to delete or archive items, empty Deleted Items and Recoverable Items, enable the Online Archive, or increase storage by licence changes.
Q15. What is an Online Archive mailbox, and what is its purpose?
Answer: It is an additional mailbox in Exchange Online that stores older email and is accessible through Outlook. It helps keep the primary mailbox small and improves performance, and retention policies can move items automatically.
Q16. What is mail flow, and how do you troubleshoot an email that was not delivered?
Answer: Mail flow is the path an email takes from sender to recipient through mail servers and filters. For a non-delivery, read the NDR (Non-Delivery Report) code, verify the recipient address, run a message trace in the Exchange admin center, check spam and quarantine, mailbox full status, transport rules and mail routing records (MX). The trace shows whether the message was delivered, filtered or failed.
Q17. What are SPF, DKIM and DMARC, and why are they important?
Answer: SPF lists the servers permitted to send email for a domain. DKIM adds a digital signature to outgoing mail to prove it was not altered. DMARC tells receiving servers what to do if SPF or DKIM checks fail and gives reporting. Together they protect against spoofing and phishing, and improve delivery of legitimate mail.
Q18. What is the difference between a distribution list, a Microsoft 365 group and a security group?
Answer: A distribution list sends email to a set of people. A Microsoft 365 group provides a shared mailbox, calendar, Teams and SharePoint site for collaboration. A security group is used to assign permissions or licences to resources, and a mail-enabled security group can do both.
Q19. What is a mail flow (transport) rule?
Answer: Transport rules apply actions to messages in transit based on conditions, such as adding a disclaimer, blocking attachments, redirecting email, or applying encryption. They are used for compliance and security. Incorrect rules can cause unexpected delivery issues, so they should be tested and documented.
Q20. How do you reset a user's password and handle a locked account in Microsoft 365?
Answer: In the admin center select the user and choose Reset password, then force a change at next sign-in. If the account is blocked because of sign-in risk or too many failures, review the sign-in logs in Entra ID, unblock the user and ensure MFA registration is correct. Self-Service Password Reset can reduce helpdesk work.
Q21. What is OneDrive, and how do you troubleshoot sync problems?
Answer: OneDrive is the cloud file storage service for personal work files that syncs to the PC. For sync issues, check the cloud icon status, available storage, file path length and invalid characters, sign out and back in, pause and resume sync, or reset OneDrive using the onedrive.exe /reset command. Make sure the user is licensed and not blocked by policy.
Q22. What is the difference between Microsoft 365 Apps (click-to-run) and perpetual Office licences?
Answer: Microsoft 365 Apps are subscription-based, always up to date and tied to a user licence with several device installations. Perpetual Office (for example Office 2021) is a one-time purchase for one version, with no new features and a fixed support lifecycle. Click-to-run is the installation technology that streams updates for both.
Q23. How do you check Microsoft 365 service health and when would you raise a support ticket with Microsoft?
Answer: Check Service Health in the admin center and the Microsoft 365 Service Health status page to confirm any known incidents. If the problem is not listed as an incident and cannot be resolved with standard troubleshooting, raise a service request in the admin center with details such as affected users, error messages, timestamps and steps taken.
Q24. What basic security and administration best practices apply to Microsoft 365?
Answer: Enforce MFA, use the principle of least privilege with role-based admin accounts, enable audit logging, apply anti-phishing and anti-malware policies, set retention policies, review licence usage regularly and maintain documentation. Admin accounts should be separate from daily user accounts.
Q25. What is Microsoft Teams, and how is it related to Outlook and Microsoft 365 groups?
Answer: Teams is the collaboration hub for chat, meetings, calls and file sharing. Each team is backed by a Microsoft 365 group, which provides a shared mailbox, calendar and SharePoint site. The Outlook add-in lets users schedule Teams meetings directly. Meeting-link or calendar problems are usually fixed by checking the add-in, licences and the Teams and Outlook versions.
Q1. What is ITIL 4, and what are its key components?
Answer: ITIL 4 is the latest version of the ITIL framework for IT service management, which focuses on co-creating value with customers. Its key components are the Service Value System (SVS) and the four dimensions model. The SVS contains guiding principles, governance, the Service Value Chain, practices and continual improvement.
Q2. What are the four dimensions of service management in ITIL 4?
Answer: They are Organisations and People, Information and Technology, Partners and Suppliers, and Value Streams and Processes. All four must be considered for any service to be balanced and effective, and they are influenced by external factors such as PESTLE.
Q3. What is the Service Value Chain, and what are its activities?
Answer: The Service Value Chain is the operating model that converts demand into value. Its six activities are Plan, Improve, Engage, Design and Transition, Obtain/Build and Deliver and Support. Practices such as incident, change and problem management are combined within these activities to produce value streams.
Q4. What are the seven ITIL 4 guiding principles?
Answer: Focus on value, start where you are, progress iteratively with feedback, collaborate and promote visibility, think and work holistically, keep it simple and practical, and optimise and automate. They guide decisions in all circumstances and are not tied to a specific process.
Q5. What is an incident, and what is the purpose of Incident Management?
Answer: An incident is an unplanned interruption to a service or a reduction in its quality. The purpose of Incident Management is to minimise the negative impact of incidents by restoring normal service operation as quickly as possible, rather than finding the root cause.
Q6. What is the typical incident management lifecycle?
Answer: The lifecycle includes detection and logging, categorisation, prioritisation, initial diagnosis, escalation if needed, investigation and diagnosis, resolution and recovery, and closure with user confirmation. Good records, communication and timely updates are needed throughout, along with adherence to SLAs.
Q7. How is incident priority determined?
Answer: Priority is calculated from Impact (how many users or how much of the business is affected) and Urgency (how quickly the business needs it resolved). For example, a high impact and high urgency issue such as a payroll system outage during payroll processing is P1. A priority matrix gives consistent handling and response targets.
Q8. What is the difference between an incident and a service request?
Answer: An incident is an unplanned disruption to a service, such as a printer failing. A service request is a formal request for something that is standard and pre-approved, such as a new user account or software installation. They are handled through different workflows because service requests are predictable and often automated.
Q9. What is the difference between functional and hierarchical escalation?
Answer: Functional escalation passes an incident to a team with more specialised skills, such as from Service Desk to Network Support. Hierarchical escalation informs or involves higher management when an incident is critical or at risk of breaching the SLA.
Q10. What are SLA, OLA and UC, and why do they matter?
Answer: An SLA (Service Level Agreement) is a commitment between the provider and the customer. An OLA (Operational Level Agreement) is an internal agreement between teams that supports the SLA. A UC (Underpinning Contract) is an agreement with an external supplier. Together they ensure that response and resolution targets can realistically be met.
Q11. What is a major incident, and how is it handled?
Answer: A major incident is a high-impact incident that needs an urgent, coordinated response beyond normal procedures, such as a payroll platform outage. It is handled by a dedicated major incident team, with a Major Incident Manager, clear communication to stakeholders, a bridge call, a time-boxed restoration effort and a post-incident review.
Q12. What is a problem, and what is the purpose of Problem Management?
Answer: A problem is the cause, or potential cause, of one or more incidents. Problem Management reduces the likelihood and impact of incidents by identifying actual and potential causes and managing workarounds and known errors.
Q13. What is the difference between Incident Management and Problem Management?
Answer: Incident Management focuses on restoring service quickly, even with a temporary fix. Problem Management focuses on finding and removing the root cause to prevent recurrence. Incidents are reactive and short-term, and problem management can be both reactive and proactive.
Q14. What are a workaround, a known error and a Known Error Database (KEDB)?
Answer: A workaround is a temporary solution that reduces or eliminates the impact of an incident or problem when a permanent fix is not yet available. A known error is a problem that has been analysed and has a documented root cause and workaround. The KEDB stores these records so the service desk can resolve repeat incidents faster.
Q15. What techniques are used for root cause analysis?
Answer: Common techniques include the 5 Whys, Ishikawa (fishbone) diagram, Pareto analysis, fault tree analysis, timeline analysis and Kepner-Tregoe. The right technique depends on the complexity of the problem, and the analysis should be evidence-based.
Q16. What is the difference between reactive and proactive problem management?
Answer: Reactive problem management responds to problems caused by incidents that have already occurred. Proactive problem management analyses trends and data, such as repeat incidents, to identify and fix potential problems before they cause incidents.
Q17. What is a change in ITIL 4, and what is the purpose of Change Enablement?
Answer: A change is the addition, modification or removal of anything that could have a direct or indirect effect on services. The purpose of Change Enablement is to maximise the number of successful IT changes by ensuring risks are properly assessed, changes are authorised and the change schedule is managed. ITIL 4 uses the term 'change enablement' instead of 'change management'.
Q18. What are the three types of change in ITIL 4?
Answer: Standard changes are low risk, pre-authorised and follow a documented procedure. Normal changes need assessment and authorisation and follow the full process. Emergency changes must be implemented urgently, for example to fix a major incident, and follow an expedited approval route.
Q19. What is a Change Authority, and how does it differ from the CAB?
Answer: A Change Authority is the person or group that approves a change, and ITIL 4 recommends delegating authority according to risk, so low-risk changes can be approved by a team lead or automatically. A CAB (Change Advisory Board) is a group that advises on and assesses higher-risk changes. ITIL 4 reduces bureaucracy by not requiring the CAB to approve everything.
Q20. What is a Request for Change (RFC), and what information should it contain?
Answer: An RFC is the formal proposal for a change. It should contain the reason and business justification, description and scope, affected services and configuration items, risk and impact assessment, implementation plan, test plan, backout plan, schedule and approvals.
Q21. Why is a back-out (rollback) plan important in change management?
Answer: A back-out plan defines how to restore the previous state if a change fails. It reduces downtime and risk, and it must be tested or at least validated before implementation. Without one, a failed change can become a major incident.
Q22. What is a Post-Implementation Review (PIR), and why is it done?
Answer: A PIR evaluates whether a change met its objectives, whether it caused issues and what lessons were learned. The results improve future change planning, and feed into continual improvement and the change records.
Q23. What is ServiceNow, and which ITSM modules relate to incident, problem and change?
Answer: ServiceNow is a cloud-based platform for IT service management and workflow automation. Its ITSM suite includes Incident, Problem, Change, Request, Knowledge and CMDB modules. Records such as Incidents (INC), Problems (PRB), Changes (CHG) and Requests (RITM) are linked so that traceability is maintained.
Q24. What is the CMDB in ServiceNow, and why is it important?
Answer: The Configuration Management Database stores Configuration Items (CIs), such as servers, applications and network devices, and the relationships between them. It supports impact analysis for changes, helps diagnose incidents faster and provides a view of service dependencies. Its value depends on the accuracy of its data.
Q25. How do incident, problem and change records relate to one another in ServiceNow?
Answer: Multiple incidents with the same cause can be linked to a single problem record. Once the root cause is found, the problem can generate a change request to apply the permanent fix. The change links back to the problem, and when the change succeeds, the problem and related incidents can be closed, giving full traceability.