Free CIS-EM Practice Test Questions and Answers (2026)

Last Update Check

View Mode
Q: 1
Copies of checks that have been included in Agent Client Collector policies are known as what?
Options
Q: 2
Within an event rule, how would you parse a nodename out of your raw event data?
Options
Q: 3
A support agent resolves an incident associated with an alert. What is the best method to close the alert?
Options
Q: 4
What applications are included in the ITOM Health product?
Options
Q: 5
What is the recommended approach to normalizing data from a source system to the default values in Event Management?
Options
Q: 6
Which are recommended best practices for Event Management? (Choose three.)
Options
Q: 7
What Event Management module allows for configuration of automatic task creation?
Options
Q: 8
What is the primary function of the link view feature in the Service Operations Workspace express list?
Options
Q: 9
What ServiceNow feature is an aid to rapid implementation of your Event Management and Operational Intelligence features?
Options
Q: 10
Which the following alert promotion rule defined in your ServiceNow instance, which of the anomalies below would be automatically promoted into IT alerts on the Alert Console? ServiceNow CIS EM question A) ServiceNow CIS EM question B) ServiceNow CIS EM question C) Both anomaly A and anomaly B D) Neither anomaly A or anomaly B
Options
Q: 11
Which attribute within an event needs to be exactly the same to allow for deduplication?
Options
Q: 12
A Service is not viewable in Operator Workspace. What could be the issue?
Options
Q: 13
A support agent resolves an incident associated with an alert, but the alert does automatically close even though the evt_mgmt.incident_closes_alert property is set appropriately to close the alert. What is the most likely cause of this issue?
Options
Q: 15
When are anomaly alerts generated by Operational Intelligence displayed in alert intelligence?
Options
Q: 16
Where can you look to determine what event rule created an alert? (Choose two.)
Options
Q: 17
The correct regex to capture the name of the server in “the server webserver3.domain.com is down” would be:
Options
Q: 18
You have an event with a Source of ‘Trap from Enterprise 111’, but the alert created for this event shows a Source of ‘Oracle EM’. If you want to change what this is set to, where in the event rule would you do this?
Options
Q: 19
What does Operational Intelligence proactively identify before they cause service outages?
Options
Q: 20
What is one of the main benefits of using Event Management and Operational Intelligence?
Options
Question 1 of 20

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top