EVENT MANAGEMENT PRACTICE EXAMS ANSWERS
AND QUESTIONS SET A+
✔✔In what sequence are event processed? - ✔✔1) Does the event Source match the
Event Rule? 2) Is a Severity defined? 3) Is the event filtered out? 4) Is there a matching
Threshold? 5) Does the event Message Key match an existing alert?
✔✔Within an event rule, how would you parse a nodename out of your raw event data?
- ✔✔Regex statement
✔✔What is Event Management licensing based on? - ✔✔The number of unique nodes
that can send events to the instance
✔✔You have the following alert promotion rule defined in your ServiceNow instance.
Two anomalies, anomaly A and anomaly B (below), occur in your system, but only
anomaly B is promoted into an IT alert and logged on the alert console. What is the
most likely cause of this behavior? - ✔✔The anomaly_score of anomaly A was not high
enough to trigger the promotion in to an IT alert.
✔✔What three pieces are required to create a customized pull connector to retrieve
events on behalf of an event source? - ✔✔Connector definition
Connector instance
JavaScript
✔✔Processing on an event will error out if a value for __________is not set -
✔✔Source
✔✔When an anomaly is detected by Operational Intelligence (OI), an anomaly score is
assigned based on what metric specific statistical model learned from the metric data.
What is this anomaly score? - ✔✔A confidence score as to how likely it is that another
anomaly will occur at a given point in the future
, ✔✔How can you achieve binding an application on a host to an alert in event
management? - ✔✔metadata rules
CI Identifiers (Choose the criterion attributes to match event attributes)
✔✔Where can the default CI Binding for an event rule be changed - ✔✔Event rule
binding section
✔✔Default CI Type attached to an Alert - ✔✔cmdb_ci_hardware
✔✔The below Connector Definitions are available in the OOTB Event management -
✔✔SCOM
Zabbix
IBM Netcool
HP Operations Manager
✔✔What is the function of the ECC Queue - ✔✔Store probes/messages to be
processed by the mid server
✔✔Please choose the correct format for the REST Endpoint for PUSH of Operational
Intelligence Metrics - ✔✔http[https]://midserverip[fqdn]/api/mid/sa/metrics
✔✔______________ parses event source values into appropriate ServiceNow event
attributes - ✔✔event field mapping
✔✔How do you resolve latency issues with processing of events - ✔✔Use of bucket
field value on the event
✔✔What is the default action on Alerts when associated incidents are resolved -
✔✔Alerts are closed automatically
✔✔Remediation Workflows are triggered from : - ✔✔Alert management rules
✔✔What is the default CI binding rule for event management - ✔✔Binding to a Device
✔✔In Event Management, what module allows for automatic task creation? - ✔✔Alert
Action Rules
✔✔To troubleshoot transactions and events that occur in your instance, look in the
________________ - ✔✔system log module
✔✔How is a secondary alert identified - ✔✔using cmdb relationship
AND QUESTIONS SET A+
✔✔In what sequence are event processed? - ✔✔1) Does the event Source match the
Event Rule? 2) Is a Severity defined? 3) Is the event filtered out? 4) Is there a matching
Threshold? 5) Does the event Message Key match an existing alert?
✔✔Within an event rule, how would you parse a nodename out of your raw event data?
- ✔✔Regex statement
✔✔What is Event Management licensing based on? - ✔✔The number of unique nodes
that can send events to the instance
✔✔You have the following alert promotion rule defined in your ServiceNow instance.
Two anomalies, anomaly A and anomaly B (below), occur in your system, but only
anomaly B is promoted into an IT alert and logged on the alert console. What is the
most likely cause of this behavior? - ✔✔The anomaly_score of anomaly A was not high
enough to trigger the promotion in to an IT alert.
✔✔What three pieces are required to create a customized pull connector to retrieve
events on behalf of an event source? - ✔✔Connector definition
Connector instance
JavaScript
✔✔Processing on an event will error out if a value for __________is not set -
✔✔Source
✔✔When an anomaly is detected by Operational Intelligence (OI), an anomaly score is
assigned based on what metric specific statistical model learned from the metric data.
What is this anomaly score? - ✔✔A confidence score as to how likely it is that another
anomaly will occur at a given point in the future
, ✔✔How can you achieve binding an application on a host to an alert in event
management? - ✔✔metadata rules
CI Identifiers (Choose the criterion attributes to match event attributes)
✔✔Where can the default CI Binding for an event rule be changed - ✔✔Event rule
binding section
✔✔Default CI Type attached to an Alert - ✔✔cmdb_ci_hardware
✔✔The below Connector Definitions are available in the OOTB Event management -
✔✔SCOM
Zabbix
IBM Netcool
HP Operations Manager
✔✔What is the function of the ECC Queue - ✔✔Store probes/messages to be
processed by the mid server
✔✔Please choose the correct format for the REST Endpoint for PUSH of Operational
Intelligence Metrics - ✔✔http[https]://midserverip[fqdn]/api/mid/sa/metrics
✔✔______________ parses event source values into appropriate ServiceNow event
attributes - ✔✔event field mapping
✔✔How do you resolve latency issues with processing of events - ✔✔Use of bucket
field value on the event
✔✔What is the default action on Alerts when associated incidents are resolved -
✔✔Alerts are closed automatically
✔✔Remediation Workflows are triggered from : - ✔✔Alert management rules
✔✔What is the default CI binding rule for event management - ✔✔Binding to a Device
✔✔In Event Management, what module allows for automatic task creation? - ✔✔Alert
Action Rules
✔✔To troubleshoot transactions and events that occur in your instance, look in the
________________ - ✔✔system log module
✔✔How is a secondary alert identified - ✔✔using cmdb relationship