PeopleCert / Axelos study guide

How to pass ITIL 4 Foundation

24 min read7 domains coveredFree practice, no sign-up

ITIL 4 Foundation is the entry qualification for the ITIL service management framework. It tests whether you understand a shared language and a small set of models for creating value with IT-enabled services: what a service is, the guiding principles, the four dimensions, the service value system, the service value chain, and a defined set of management practices. It is conceptual throughout. There is no tooling, no configuration, and no scenario that asks you to run a process, only questions that check whether you hold the definitions and the relationships between them cleanly in your head.

It suits a broad audience: service desk and operations staff, project and delivery managers, business analysts, developers moving into a DevOps or platform role, and anyone in an organisation that has decided to adopt ITIL and wants a common vocabulary. No prior service management knowledge is assumed. If you already work in IT support you will recognise much of the material, but be warned: ITIL 4 uses several everyday words such as incident, problem, change, and service in precise, specific ways that may differ from how your workplace uses them.

The exam rewards precision over intuition. Most wrong answers are not absurd, they are near-misses that swap one defined term for a neighbouring one, or that describe a real activity but attribute it to the wrong practice. The skill being tested is recognising the exact definition and the exact boundary between two similar ideas. That is why rote familiarity is not enough, and why practising against questions that deliberately place the confusable pairs side by side is the fastest route to a confident pass.

ITIL 4 Foundation rewards precise definitions and clean boundaries between neighbouring terms, not workplace intuition about how IT support is run.

Difficulty

Foundational

Best for

Anyone needing a common service management vocabulary: service desk and operations staff, delivery and project managers, business analysts, and developers moving into DevOps or platform roles.

Prerequisites

None. Working in IT helps you recognise the material, but ITIL 4 redefines several familiar words precisely, so treat the definitions as new.

40
Questions
60 min
Time allowed
26 / 40 (65%)
Pass mark
$600
Exam cost (USD)
293
Practice questions

How this exam thinks

Two habits separate a pass from a fail, and neither is about knowing more facts.

First, the exam tests the exact definition, not the general idea. A question will offer four statements about, say, a problem, and three of them will be true statements about something else in the framework - an incident, a known error, a change. The correct answer is the one that matches the ITIL 4 wording precisely, including the qualifying words that carry the meaning: an incident is an unplanned interruption, a known error is a problem that has been analysed but not yet resolved. Read every option to the end, because the distractor usually changes a single load-bearing word - unplanned to planned, cause to symptom, analysed to awaiting analysis. If you skim, the near-miss reads as correct.

Second, the exam tests boundaries between neighbouring terms. It repeatedly places two ideas that share a home side by side and asks which one a scenario describes: incident versus problem, output versus outcome, utility versus warranty, customer versus user versus sponsor, change enablement versus release management. The framing is often a short workplace vignette, and your job is to map the situation onto the correct defined term rather than onto how your own organisation labels things. When two options both look plausible, the tie-breaker is almost always the precise scope of each term, so learn the one-line discriminator for each confusable pair until it is automatic.

What each domain tests and how to study it

The ITIL-4 blueprint is split across 7 domains. Weights are the official share of the exam; see the official exam guide for the authoritative breakdown.

  1. Understand the key concepts of service management

    12% of exam

    What you must be able to do. State the ITIL 4 definitions of the core terms exactly, and map a short scenario onto the right one: service, utility, warranty, cost, value, outcome, output, risk, and the customer, user, and sponsor roles.

    In one sentenceThe shared vocabulary the whole exam assumes: what a service is, how value is co-created, and the precise distinctions between utility and warranty, output and outcome, and customer, user, and sponsor.

    Recall check: answer these from memory first
    • Define utility and warranty in one line each, and say which is fitness for purpose and which is fitness for use.
    • Distinguish an output from an outcome, and give a one-line example where a system produces the output but not the outcome the stakeholder wanted.
    • Match customer, user, and sponsor to what each one does in a service relationship.

    What it tests. The foundational definitions and how they fit together: a service as a means of enabling value co-creation, utility as fitness for purpose and warranty as fitness for use, and the way cost, value, outcome, output, and risk combine when a provider and consumer co-create value. It also tests the service relationship concepts - service offering, provision, and consumption - and whether you can keep the customer, user, and sponsor roles distinct in a scenario.

    How to study it. Learn these as exact definitions, not paraphrases, because every later domain leans on them and the exam swaps one term for a neighbour. Write out utility versus warranty and output versus outcome as one-line contrasts and rehearse them until they are automatic. Practise the stakeholder roles against short vignettes: decide who pays and defines requirements (customer or sponsor) versus who actually uses the service (user). Remember that value is co-created, never delivered one way, and that a service lets the consumer achieve outcomes without owning specific costs and risks.

    Easy to confuse

    • Utility versus warranty. Utility is fitness for purpose - what the service does, the functionality that lets a user achieve an outcome. Warranty is fitness for use - how well it performs, its availability, capacity, security, and continuity. A service needs both; the exam gives a scenario where the function is present but the performance fails (available features, poor uptime) and asks which is lacking, and the answer is warranty.
    • Output versus outcome. An output is a tangible deliverable produced by an activity, such as a generated invoice or a provisioned account. An outcome is the result the stakeholder actually wanted, such as being paid faster. The exam plants a scenario where the output is delivered but the outcome is not, and the correct answer names the outcome as the thing that was really sought.
    • Customer versus user versus sponsor. The customer defines requirements and is accountable for the service's outcomes; the user actually uses the service day to day; the sponsor authorises the budget and spend. One person can hold more than one role, so the exam describes behaviour (approves the budget, logs in daily, agrees the service levels) and asks you to name the role from what the person does, not their job title.

    Worked example from the ITIL-4 bank

    Free sampleUnderstand the key concepts of service managementeasy

    According to ITIL 4, which statement most precisely captures the definition of a service?

    • AA tangible product delivered to a customer in exchange for an agreed fee under a formal contract.
    • BA set of specialised organisational capabilities for enabling value to customers in the form of services.
    • CA means of enabling value co-creation by facilitating outcomes that customers want to achieve, without the customer having to manage specific costs and risks. Correct
    • DA documented request from a user for something to be provided, such as access or information.
    A service enables value co-creation by facilitating customer outcomes while the provider manages specific costs and risks. ITIL 4 frames a service around outcomes and risk transfer: the provider takes on specific costs and risks so the customer can achieve outcomes without owning them, which is why value is co-created rather than simply handed over.

    Why A is wrong: It is tempting because many services are indeed paid for and governed by contracts, but ITIL 4 defines a service by the value it enables rather than by tangibility or a fee, and it is explicitly not limited to physical products.

    Why B is wrong: This is tempting because it is genuine ITIL wording, but it is the definition of service management, not of a service itself, so it answers a different question.

    Why C is correct: This is the ITIL 4 definition of a service: it enables value co-creation by facilitating the customer's desired outcomes while the provider carries specific costs and risks on the customer's behalf.

    Why D is wrong: This resembles the definition of a service request, which is one interaction within service delivery, and it is far narrower than what a service is in ITIL 4.

  2. Understand how the ITIL guiding principles help adopt and adapt service management

    15% of exam

    What you must be able to do. Explain each guiding principle and recognise it from a scenario, treating the principles as universal recommendations applied together rather than a checklist chosen one at a time.

    In one sentenceThe universal recommendations that hold in any situation - focus on value, start where you are, progress iteratively with feedback, collaborate and promote visibility, think holistically, keep it simple, and optimise then automate.

    Recall check: answer these from memory first
    • Name the guiding principles and give a one-line intent for each.
    • Explain why Optimise and automate insists you optimise before you automate.
    • State what Start where you are tells you to do before designing something new, and why direct measurement matters.

    What it tests. The nature, use, and interaction of the guiding principles as universal recommendations that apply regardless of changing objectives or strategy, and that an organisation should consider all of them together rather than picking one in isolation. It tests recognition of each principle from a described behaviour, with particular attention to Focus on value, Start where you are, Progress iteratively with feedback, Collaborate and promote visibility, and the correct meaning of Optimise and automate.

    How to study it. For each principle, learn a one-line intent and one telltale scenario cue, because the exam mostly asks you to name the principle a situation illustrates. Pin the traps: Start where you are means assess and reuse what already exists rather than rip and replace, and it relies on direct observation, not second-hand reports. Optimise and automate means optimise first, then automate, so automation does not entrench waste. Remember the principles are applied together and are recommendations, not mandatory rules, so any option calling them compulsory or saying you use just one is usually wrong.

    Easy to confuse

    • Optimise and automate: optimise first versus automate first. The principle is a sequence, not a pair of equals. You optimise a process first - remove waste and make it as effective as it can be - and only then automate what remains. Automating an unoptimised process just makes the waste run faster and cheaper to repeat, so any option that jumps straight to automation, or treats the two as interchangeable, is the distractor.
    • Start where you are versus starting from scratch. Start where you are says assess what already exists and reuse what you can, informed by direct observation and measurement rather than assumptions or reports. The trap option recommends discarding current services, processes, and tools to build fresh - which is exactly what the principle warns against.
    • Applying all principles together versus picking one principle. The principles are universal recommendations meant to be considered as a set, weighing how much each applies to the situation. An option that says an organisation should choose a single principle and ignore the rest, or that treats them as mandatory rules to obey exactly, misreads their nature - they guide judgement, they do not replace it.

    Worked example from the ITIL-4 bank

    Free sampleUnderstand how the ITIL guiding principles help adopt and adapt service managementeasy

    In ITIL 4, the guiding principles are described as universal recommendations. What does describing them as universal recommendations most precisely mean?

    • AThey are mandatory rules that every organisation must adopt in full before any other ITIL guidance can be used.
    • BThey apply only to organisations that are adopting ITIL for the very first time.
    • CThey apply only when an organisation is designing a brand new service from scratch.
    • DThey can guide an organisation in almost all circumstances, regardless of changes to its goals, strategies, type of work, or management structure. Correct
    Universal recommendations means the guiding principles apply in almost any situation regardless of changes in goals, strategy, work, or structure. ITIL 4 calls the guiding principles universal because their relevance does not depend on a particular initiative, maturity level, or organisational structure; they are meant to hold across changing circumstances rather than being conditional or mandatory.

    Why A is wrong: Tempting because the word principle can sound like an enforceable rule, but it is wrong: the guiding principles are recommendations, not mandatory controls, and ITIL does not require full adoption of all of them before other guidance applies.

    Why B is wrong: Tempting because guidance is often framed as adoption advice, but it is wrong: the principles are universal and continue to apply to established and experienced service providers, not just newcomers.

    Why C is wrong: Tempting because design work is a natural place to use guidance, but it is wrong: universal recommendations apply across all types of initiative and situation, not only new service design.

    Why D is correct: Correct: universal means the principles hold across situations, so they remain useful whether an organisation changes its objectives, strategy, working practices, or structure.

  3. Understand the four dimensions of service management

    5% of exam

    What you must be able to do. Name the four dimensions of service management, recognise which one a scenario concerns, and explain why all four must be balanced and how external PESTLE factors constrain them.

    In one sentenceThe four dimensions that must all be considered for a holistic service - organisations and people, information and technology, partners and suppliers, and value streams and processes - constrained by external PESTLE factors.

    Recall check: answer these from memory first
    • Name the four dimensions of service management.
    • Give a one-line example that clearly belongs to each dimension.
    • Explain what PESTLE stands for and how those factors relate to the four dimensions.

    What it tests. The four dimensions of service management - organisations and people, information and technology, partners and suppliers, and value streams and processes - what each covers, and why neglecting any one creates blind spots. It tests that the dimensions apply to every service, that a decision in one dimension forces consideration of the others, and that external PESTLE factors (political, economic, social, technological, legal, environmental) shape how each dimension is applied.

    How to study it. Memorise the four names precisely, because the exam asks you to sort an example under the right dimension: a skills or culture issue is organisations and people, a supplier contract is partners and suppliers, a workflow is value streams and processes. Learn the point of the model - it is holistic, so all four are balanced together rather than treated as silos. Keep PESTLE ready as the external constraint on the dimensions, and do not confuse those external factors with the internal dimensions themselves.

    Easy to confuse

    • The four dimensions versus the external PESTLE factors. The four dimensions are internal facets an organisation manages for every service; PESTLE factors are external forces that constrain how those dimensions are applied. The exam mixes the two lists to see whether you treat a legal or economic pressure as a dimension - it is not, it is an external factor acting on the dimensions.
    • Partners and suppliers versus organisations and people. Partners and suppliers covers external parties an organisation relies on - vendors, contracts, and the sourcing relationships. Organisations and people covers the internal workforce - roles, skills, culture, and structure. A scenario about a supplier agreement belongs to the first; a scenario about staff capability or culture belongs to the second.

    Worked example from the ITIL-4 bank

    Free sampleUnderstand the four dimensions of service managementmedium

    In ITIL 4, which statement most precisely describes what the organizations and people dimension of service management covers?

    • AThe workflows, controls, and sequences of activities that turn demand into value for consumers.
    • BAn organization's structure, roles and responsibilities, staffing and competencies, and the culture that shapes how work is done. Correct
    • CThe applications, data, and knowledge an organization needs, together with the relationships between those components.
    • DThe organization's relationships with the other firms it depends on to design, deploy, and support its services.
    The organizations and people dimension covers structure, roles, competencies, and culture within the service provider. ITIL 4 places human factors in the organizations and people dimension because delivering value depends not only on a sound structure and clear roles but on staff having the right competencies and a supportive culture, which the other three dimensions do not address.

    Why A is wrong: This is tempting because coordinated work does involve people, but it describes the value streams and processes dimension, which is concerned with how activities are organised rather than with roles, structure, and culture.

    Why B is correct: Correct: the organizations and people dimension covers formal structure and roles alongside the required skills, competencies, and the shared culture and leadership needed to deliver value effectively.

    Why C is wrong: This is tempting because staff use these assets daily, but it defines the information and technology dimension, not the human and structural factors that organizations and people addresses.

    Why D is wrong: This is tempting because external firms are staffed by people too, but it describes the partners and suppliers dimension, which concerns inter-organizational relationships rather than an organization's own people and culture.

  4. Understand the purpose and components of the ITIL service value system

    2% of exam

    What you must be able to do. Describe the service value system and its components, and explain that its purpose is to make the organisation respond to opportunity and demand as one whole rather than in silos.

    In one sentenceThe overarching model showing how all an organisation's components and activities - guiding principles, governance, the service value chain, practices, and continual improvement - work together to co-create value from opportunity and demand.

    Recall check: answer these from memory first
    • List the five components of the service value system.
    • State what the inputs to and the output of the SVS are.
    • Explain in one line the problem the SVS is designed to solve.

    What it tests. The purpose and components of the service value system (SVS): that it describes how all the components and activities of an organisation work together to enable value creation, and that its inputs are opportunity and demand and its output is value. It tests identification of the SVS components - guiding principles, governance, the service value chain, practices, and continual improvement - and the point that the SVS exists to reduce silos and prevent a fragmented response.

    How to study it. Learn the SVS as the container that holds everything else in the framework, then be able to list its five components from memory. Fix the inputs and outputs in your head: opportunity and demand go in, value comes out. Understand the why - the SVS is meant to stop the organisation working in silos and reacting to demand in a fragmented way. This is a small domain, so a short focused pass and a few practice questions are enough; do not over-invest here.

    Easy to confuse

    • The service value system versus the service value chain. The service value system is the whole model - guiding principles, governance, practices, continual improvement, and the value chain together. The service value chain is just one component inside it, the operating model of interconnected activities. The exam checks whether you treat the chain as the whole system; it is a part, not the container.

    Worked example from the ITIL-4 bank

    Free sampleUnderstand the purpose and components of the ITIL service value systemmedium

    In ITIL 4, which statement most accurately describes what the service value system (SVS) represents?

    • AA linear sequence of activities that transforms incoming demand into finished products ready for release to consumers.
    • BThe framework of authority an organisation uses to direct and control the way its service management practices operate.
    • CA model describing how all the components and activities of an organisation work together to facilitate value creation through IT-enabled services. Correct
    • DThe complete set of management practices an organisation applies to design, deliver, operate, and improve its services.
    The ITIL service value system describes how an organisation's components and activities work together to enable value co-creation through IT-enabled services. The SVS is the overarching model that takes opportunity and demand as inputs and produces value as its output, ensuring that guiding principles, governance, the service value chain, practices, and continual improvement operate as a coherent whole rather than in isolation.

    Why A is wrong: This is tempting because the SVS does turn demand into value, but it wrongly casts the SVS as a fixed linear sequence. That description fits an oversimplified view of the service value chain, which is itself only one component of the SVS and is deliberately non-linear.

    Why B is wrong: This is tempting because directing and controlling the organisation is genuinely part of the SVS, but it describes governance specifically. Governance is only one of the five SVS components, not the whole system.

    Why C is correct: Correct. The SVS is defined as the way the organisation's components and activities combine to enable value co-creation via IT-enabled services, taking opportunity and demand as inputs and producing value as the output.

    Why D is wrong: This is tempting because practices are central to service management, but it narrows the SVS down to just its practices component. The SVS is broader, also including guiding principles, governance, the service value chain, and continual improvement.

  5. Understand the activities of the service value chain and how they interconnect

    5% of exam

    What you must be able to do. Describe the six value chain activities and their purposes, and recognise that the activities are combined flexibly into value streams rather than run as a fixed linear sequence.

    In one sentenceThe central operating model of the SVS: six interconnected activities - plan, improve, engage, design and transition, obtain or build, and deliver and support - combined into value streams in whatever order a scenario needs.

    Recall check: answer these from memory first
    • Name the six activities of the service value chain.
    • Give the one-line purpose of Engage and of Deliver and support, and say how they differ.
    • Explain why the value chain is described as interconnected and not a fixed linear sequence.

    What it tests. The service value chain as the central operating model of the SVS: an interconnected set of activities that convert demand into value, and the purpose of each of the six activities. It stresses that the activities are not a fixed linear sequence - a value stream combines them in different orders for different scenarios and any activity can call on any practice - and it tests the distinct purpose of Engage, Deliver and support, Design and transition, Obtain or build, Plan, and Improve.

    How to study it. Learn a one-line purpose for each of the six activities, then drill the two facts the exam loves: the activities are interconnected and non-linear, so a value stream can route through them in any order, and any activity can draw on any practice. Watch for the distractor that describes the value chain as a rigid step-by-step pipeline. Keep Engage (stakeholder relationships and demand) and Deliver and support (running services to agreed levels) clearly apart, since these two are the most confused.

    Easy to confuse

    • The value chain as a flexible model versus a fixed linear sequence. The six activities are interconnected and combined into value streams in whatever order a given scenario requires, with any activity able to call on any practice. The trap presents them as a rigid pipeline that always runs in the same order from one end to the other - that fixed-sequence reading is exactly what ITIL 4 rejects.
    • Engage versus Deliver and support. Engage is about understanding stakeholders and managing demand and relationships - the outward-facing activity. Deliver and support is about ensuring services are delivered and supported to agreed specifications - the running of the service. A scenario about capturing needs or managing a relationship is Engage; one about keeping an agreed service running is Deliver and support.

    Worked example from the ITIL-4 bank

    Free sampleUnderstand the activities of the service value chain and how they interconnectmedium

    In ITIL 4, which statement most precisely describes how the six activities of the service value chain relate to one another?

    • AThey form a fixed linear sequence that always runs from plan through to deliver and support in the same order.
    • BThey are interconnected activities that combine in different sequences to form value streams for specific scenarios. Correct
    • CThey each operate independently, so an activity never passes inputs or outputs to any other activity.
    • DThey can only be triggered by the engage activity, which must precede every other activity in every case.
    The service value chain activities are interconnected and combine in varying sequences to form value streams, not a fixed linear pipeline. The service value chain is deliberately non-linear so that its activities can be arranged into many different value streams. Each stream selects and orders the activities needed to convert a specific demand into value, which is only possible because the activities interconnect rather than run in one fixed order.

    Why A is wrong: This is tempting because the activities are often drawn left to right, suggesting a pipeline. It is wrong because the service value chain is explicitly non-linear: activities are used in different orders and combinations, not one mandatory sequence.

    Why B is correct: Correct. ITIL 4 describes the value chain activities as interconnected, and value streams are specific combinations of these activities arranged to respond to a particular demand or scenario.

    Why C is wrong: This is tempting because each activity has a distinct purpose. It is wrong because the activities are interconnected and pass inputs and outputs between one another; isolation would defeat the point of a value chain.

    Why D is wrong: This is tempting because engage handles stakeholder demand, which often starts a stream. It is wrong because no single activity is a mandatory first step for all streams; any activity can act as an entry or exit point depending on the value stream.

  6. Know the purpose and key terms of 15 ITIL practices

    18% of exam

    What you must be able to do. Recall the one-line purpose of each ITIL practice in scope and the definitions of the key terms, and separate the purposes that candidates routinely conflate.

    In one sentenceThe recall layer: the one-line purpose of each named ITIL practice and the exact definitions of the key terms - IT asset, event, configuration item, change, incident, problem, and known error.

    Recall check: answer these from memory first
    • Give the one-line purpose of change enablement, release management, and deployment management, and say how they differ.
    • Define event, configuration item, and change in the ITIL 4 wording.
    • Explain why a configuration item is not always an IT asset.

    What it tests. Recall of the purpose of each ITIL practice in scope, including information security management, relationship management, supplier management, IT asset management, monitoring and event management, release management, service configuration management, deployment management, and change enablement. It also tests the ITIL 4 definitions of the key terms - IT asset, event, configuration item, change, incident, problem, and known error - and whether you can keep neighbouring purposes and definitions apart.

    How to study it. This domain is pure recall, so build a single sheet of one-line purposes and one-line definitions and rehearse it until each comes back instantly. Concentrate on the pairs the exam separates: change enablement authorises changes, release management makes a new or changed service available, deployment management moves components into environments. For the terms, drill the qualifying words - an event is a state change significant for management, a change can have a direct or indirect effect - and remember that not every configuration item is an IT asset.

    Easy to confuse

    • Change enablement versus release management versus deployment management. Change enablement authorises and controls changes by assessing risk before they proceed. Release management makes a new or changed service and its features available for use. Deployment management moves new or changed components into target environments. The exam attributes one practice's activity to another, so anchor each to its verb: authorise, make available, move into environments.
    • Configuration item versus IT asset. A configuration item is any component that must be managed to deliver a service; an IT asset is any financially valuable component that could contribute to service delivery. The sets overlap but are not identical - a documented process or a relationship can be a configuration item without being an asset - so treating every configuration item as an asset is the trap.
    • Incident versus event. An event is any change of state significant for the management of a service or configuration item, and most events are routine or informational. An incident is an unplanned interruption or reduction in quality that needs restoring. Monitoring detects events; only some events indicate incidents, so treating every event as an incident overstates it.

    Worked example from the ITIL-4 bank

    Free sampleKnow the purpose and key terms of 15 ITIL practicesmedium

    In ITIL 4, which statement most precisely describes the purpose of the change enablement practice?

    • ATo move new and changed hardware, software, and other components into live environments so that they are available for use as agreed.
    • BTo make new and changed services and features available for use, coordinating the point at which functionality is released to users.
    • CTo maximise the number of successful service and product changes by ensuring that risks are properly assessed, changes are authorised, and a change schedule is managed. Correct
    • DTo ensure that accurate and reliable information about configuration items and their relationships is available when and where it is needed.
    Recall that change enablement exists to maximise successful changes by assessing risk, authorising, and scheduling them. Change enablement is the authorisation-and-scheduling gate: it weighs the benefit of a change against the risk to users and the business, so its defining purpose is safe, authorised, well-scheduled change rather than the physical act of building, releasing, or deploying anything.

    Why A is wrong: Tempting because moving components into live environments is a core delivery activity, but this describes the deployment management practice, not change enablement, which is concerned with authorising and scheduling change.

    Why B is wrong: Tempting because it sounds like a change reaching users, but this is the purpose of release management, which governs when functionality becomes available, whereas change enablement governs whether the change is authorised at all.

    Why C is correct: This matches the ITIL 4 purpose of change enablement: it balances the need to make beneficial changes against the need to protect customers and users from the adverse effects of change through risk assessment, authorisation and scheduling.

    Why D is wrong: Tempting because configuration data supports change decisions, but this is the purpose of service configuration management; change enablement uses that information rather than being defined by maintaining it.

  7. Understand 7 ITIL practices

    43% of exam

    What you must be able to do. Explain the most heavily tested practices in depth - incident, problem, change enablement, service request, service desk, service level management, and continual improvement - and resolve the scenarios that pit their neighbouring concepts against each other.

    In one sentenceThe largest domain by far: the detailed workings of incident management, problem management, change enablement, service request management, the service desk, service level management, and continual improvement, and the boundaries between them.

    Recall check: answer these from memory first
    • State the purpose of incident management and of problem management, and explain how a workaround and a known error relate.
    • Name the three change types and the change authority appropriate to each.
    • Explain why a service request must not be treated as an incident, and list the traits of a good SLA.

    What it tests. The seven practices in detail: incident management (restore service fast) and problem management (reduce the likelihood and impact of incidents through problem and known-error control); change enablement and its three change types with the right change authority for each; service request management and why a service request is not an incident; the service desk as single point of contact; service level management and what makes a good SLA; and continual improvement and its model.

    How to study it. This carries the most weight, so give it the most time and drill it with scenario questions. Fix the incident-versus-problem split: incident management restores service fast, often with a workaround, while problem management finds and removes the underlying cause. Learn the three change types and their authorities - standard is pre-authorised, normal is assessed and authorised, emergency is expedited - and that a service request is a planned, normal part of delivery, never handled as an incident. Know the good-SLA traits (simple, outcome-based, agreed with the customer, and not a watermelon metric) and the first steps of the continual improvement model.

    Easy to confuse

    • Incident management versus problem management. Incident management aims to restore normal service as quickly as possible, accepting a workaround if it gets users going again. Problem management aims to reduce the likelihood and impact of incidents by finding and addressing their underlying cause. Speed of restoration signals incident management; investigating why it keeps happening signals problem management.
    • Problem versus known error versus workaround. A problem is a cause, or potential cause, of one or more incidents. A known error is a problem that has been analysed but not yet resolved, so its cause is understood while a permanent fix is still outstanding. A workaround is a means of reducing or eliminating an incident's impact without a full resolution. The exam swaps analysed for awaiting analysis, or calls a known error resolved - both are wrong.
    • A service request versus an incident. A service request is a predefined, normal part of service delivery - a request for something to be provided, such as access or information - and it flows through service request management. An incident is an unplanned interruption or reduction in quality. A scenario often pairs the two in one call; the routine request must not be logged or handled as an incident.
    • Standard versus normal versus emergency changes. A standard change is low-risk and pre-authorised, so it needs no fresh assessment each time. A normal change is assessed, scheduled, and authorised by the appropriate change authority. An emergency change is needed at once and follows an expedited assessment and authorisation path. The exam tests which change type, and therefore which authority, a scenario calls for.

    Worked example from the ITIL-4 bank

    Free sampleUnderstand 7 ITIL practiceshard

    According to ITIL 4, which statement most precisely describes the relationship between a problem and a known error?

    • AA known error is a problem that has been analysed but not resolved, so its cause is understood even though no permanent fix has been applied. Correct
    • BA known error is a problem that has been permanently resolved, so the underlying cause can no longer generate any further incidents.
    • CA known error is any incident that has recurred often enough for the service desk to recognise it and apply a scripted response.
    • DA known error is a problem awaiting analysis, recorded so that investigation can begin once resources become available.
    A known error is a problem that has been analysed but not resolved, meaning its cause is understood while a permanent fix is still outstanding. The known error state exists to record the outcome of problem analysis: the cause has been identified so that workarounds and future handling are informed, but because a permanent resolution has not yet been implemented the problem remains open rather than closed.

    Why A is correct: This matches the ITIL 4 definition: a known error is a problem for which analysis has established the cause, but which remains unresolved because a permanent fix is not yet in place.

    Why B is wrong: This is tempting because both terms sit within problem management, but a resolved problem is closed, not a known error; the known error status specifically means the cause is understood while the problem is still open.

    Why C is wrong: A recurring incident may prompt problem management to investigate, but a known error is a state of a problem, not a repeated incident, so this confuses the incident and problem practices.

    Why D is wrong: This inverts the sequence: a problem awaiting analysis has no established cause, whereas a known error is defined precisely by the analysis having already been done.

A study plan that works

  1. Map the syllabus and book a date

    Day 1

    Read the official exam specification and note the seven learning outcomes and their relative weights. Book a provisional exam date now: a fixed date turns open-ended reading into a plan and is the single biggest predictor of actually sitting the exam. Note that the two practice-focused domains carry the largest share of the marks.

  2. Nail the key concepts and definitions

    Week 1

    Lock down the core vocabulary before anything else, because every later domain assumes it. Get service, value co-creation, utility versus warranty, output versus outcome, and the customer, user, and sponsor roles exact and word-perfect. Use the recall prompts in this guide: cover the answer, respond from memory, then reveal.

  3. Learn the guiding principles and four dimensions

    Week 2

    Give each guiding principle a one-line intent and a telltale scenario cue, and pin the traps in Start where you are and Optimise and automate. Then memorise the four dimensions and how PESTLE factors constrain them. Both domains are mostly recognition questions, so practise naming the principle or dimension from a short vignette.

  4. Work through the SVS and the service value chain

    Week 2-3

    Learn the service value system as the container and its five components, then the six value chain activities and their purposes. Drill the two facts the exam loves: the SVS turns opportunity and demand into value, and the value chain is interconnected and non-linear, not a fixed pipeline. These are smaller domains - a focused pass is enough.

  5. Go deep on the practices

    Week 3-4

    Spend the bulk of your remaining time here, because the practice domains carry the most weight. Build a recall sheet of practice purposes and key-term definitions, then drill the detailed practices with scenarios: incident versus problem, the three change types and their authorities, service request versus incident, good SLAs, and the continual improvement model.

  6. Practise on scenario questions with worked explanations

    Week 4

    Move to full practice sets and read the explanation for every question, including the ones you got right. The exam turns on near-miss distractors that swap one defined word for another, so understanding why each wrong option is wrong is where the marks are. Keep a list of every pair you confuse and re-drill it.

  7. Sit a timed mock and close your weak domains

    Week 5

    Take at least one full timed mock to rehearse pacing and flag-and-return. Treat the score as a per-domain readiness signal, then use your per-domain accuracy to drill the outcomes dragging you down rather than re-reading what you already know. Repeat until every domain clears the pass line with margin on unseen questions.

Know when you're ready

Readiness for ITIL 4 Foundation is a score on questions you have not seen before, not a feeling that the material is familiar. Those are different things, and the gap between them is where people fail. Re-reading the definitions builds fluency, and fluency feels like knowledge, so confidence rises while real recall does not. The fix is to test yourself: if you can pick the precisely correct definition from four near-misses and explain why each distractor is wrong, you know it; if you can only nod along to the right answer once it is shown, you do not yet.

Be especially wary of early confidence if you already work in IT. Your workplace uses words like incident, change, and service loosely, and that habit actively works against you here, where each term has an exact scope. A first read feels like revision, but the exam rewards the precise boundary, which only practice against confusable pairs exposes. Trust your measured per-domain accuracy over your gut, and set the bar at clearing every domain comfortably on unseen questions across more than one session, not scraping the pass mark once.

This guide gives you the map. The practice bank is where you find out whether you can navigate it, with a worked explanation and a reason every distractor is wrong on every question. Readiness scoring tells you when you are there. Not before.

Ready to put this into practice?

Free ITIL-4 questions with worked explanations. No sign-up.

Practise ITIL-4 free

Exam-day tips

  • Read every option to the end before choosing. The wrong answers are near-misses that change a single load-bearing word, so the difference between right and wrong is often in the last few words.
  • Answer with the ITIL 4 definition, not your workplace's usage. The exam tests the exact framework meaning of incident, problem, change, and service, which may differ from how your organisation uses those words.
  • For confusable pairs, decide the discriminator first. Ask which single distinction separates the two terms - fitness for purpose versus fitness for use, output versus outcome - then match the scenario to it.
  • In role scenarios, judge behaviour, not job title. Who authorises the budget is the sponsor, who defines requirements and owns outcomes is the customer, who uses the service is the user - regardless of what the person is called.
  • Watch for absolute or fixed-sequence wording. Options that call the guiding principles mandatory, or the value chain a rigid pipeline, usually misread the framework and are the distractor.
  • Flag and move on. Do not lose time on one hard item when easier marks are waiting; cover every question first, then return to the flagged ones.
  • Eliminate two options fast. Most questions have two clearly weaker choices; removing them turns a hard question into a decision between the two remaining near-misses.

Frequently asked questions

Is ITIL 4 Foundation hard?

It is a foundational exam with no tooling or configuration, so the challenge is precision rather than depth. The difficulty comes from near-miss distractors that swap one defined term for a neighbouring one, which is why practising against confusable pairs matters more than re-reading definitions.

How long should I study for ITIL 4 Foundation?

Most candidates are ready in three to five weeks of focused study. If you already work in IT you will recognise the material quickly, but budget extra time to unlearn loose workplace usage of terms like incident and change, which the exam defines precisely.

Do I need IT experience to pass?

No. The exam is conceptual and assumes no prior service management knowledge. IT experience helps you relate to the scenarios, but the definitions are the same for everyone and must be learned as written.

Which domains should I focus on?

The two practice-focused domains together carry the largest share of the marks, so the detailed practices - incident, problem, change enablement, service request, service desk, service level management, and continual improvement - deserve the most time. The service value system and four dimensions domains are smaller and can be secured with a shorter pass.

What is the difference between an incident and a problem?

An incident is an unplanned interruption to a service or a reduction in quality, and incident management aims to restore service as quickly as possible, often with a workaround. A problem is a cause, or potential cause, of one or more incidents, and problem management aims to find and remove that underlying cause. The exam tests this boundary repeatedly.

Should the syllabus use change enablement or change enablement?

This qualification follows the 2019 ITIL 4 Foundation syllabus, which names the practice change enablement. Later editions renamed it change enablement, but for this exam use change enablement. Its purpose is to maximise successful changes by assessing risk and authorising changes.

How is the exam scored?

The exam is closed book and multiple choice, and the pass mark and question count are shown in the facts panel above. Aim to clear every learning outcome comfortably in practice rather than scraping the target, because a weak domain can sink an otherwise solid score.

How many practice questions should I do before booking?

Enough that every domain clears the pass line with margin on questions you have not seen before, and that a full timed mock feels comfortable on pacing. Quality of review matters more than raw volume: read the explanation on every question and re-drill the pairs you keep confusing.

Examworthy is not affiliated with or endorsed by PeopleCert / Axelos. This guide is original study material based on the public exam blueprint. We never reproduce live exam items. ITIL-4 and related marks belong to their respective owners.