CTA Sample Questions & Answers
Four areas tie for the top weight: CMDB health and governance, non-functional testing strategies, access control and security design, and integration patterns across platform data, next to data strategy, architecture blueprints, go-live support, and release planning.
Launch the full CTA simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Technical Governance · Governance Framework
A technical architect is establishing a Technical Governance Board for a rapidly growing organization. The board's primary mandate is to ensure the long-term health and maintainability of the ServiceNow platform. Which of the following responsibilities falls squarely within the primary focus of this governance board?
Show answer & explanation
Correct answer: B
The primary focus of a Technical Governance Board is to maintain the architectural integrity and long-term health of the platform. This is achieved by defining and enforcing standards for development, configuration, integrations, and data. This prevents the accumulation of 'technical debt' and ensures the platform remains scalable and easy to upgrade. Budgeting, project prioritization, and user training are typically handled by a steering committee, project management office, or business stakeholders, although the governance board may provide input.
- Question 2Intermediate
Go-Live Preparation · Hypercare Support
During a go-live weekend for a major CSM implementation, the project team identifies a critical defect that impacts the customer's ability to submit cases through the service portal. The deployment is scheduled to complete in four hours. The architect needs to provide guidance on the next steps. What is the most critical activity during the 'Hypercare' period that should have been planned for this exact scenario?
Show answer & explanation
Correct answer: B
While communication, post-mortem analysis, and training are all important parts of go-live and Hypercare, the most critical plan for a deployment-blocking defect is the rollback strategy. The ability to quickly and safely revert to the last known good state is paramount to minimize business impact. A well-defined rollback procedure, including criteria for when to execute it, is a cornerstone of go-live preparation.
- Question 3Intermediate
Current and To-Be Architecture · Architecture Blueprints
An architect is reviewing a 'to-be' architecture blueprint for a new HR Onboarding application. The blueprint contains diagrams, data models, and integration points. Which primary purpose does this blueprint serve when communicating with business stakeholders who are non-technical?
Show answer & explanation
Correct answer: C
For business stakeholders, the primary purpose of an architecture blueprint is to visually translate complex technical plans into an understandable format that demonstrates how the proposed solution will meet their business needs and deliver specific capabilities. It bridges the gap between technical implementation and business value. Technical specifications and hardware requirements are important but are secondary details for a different audience (developers and infrastructure teams).
- Question 4Advanced
Platform Data and Integrations · Enterprise Service Bus (ESB)
A financial institution is implementing ServiceNow and needs to integrate with its mainframe core banking system for real-time transaction validation. The mainframe system is decades old and only exposes its services through a proprietary, non-standard protocol. The architect must design a resilient and maintainable integration. Which integration pattern represents the best practice for this scenario?
Show answer & explanation
Correct answer: B
Using an Enterprise Service Bus (ESB) is the best practice for integrating with legacy systems that use proprietary protocols. The ESB acts as a middleware layer, abstracting the complexity of the mainframe from ServiceNow. It handles the protocol translation (e.g., from REST/SOAP to the mainframe's protocol), orchestrates the communication, and provides a standardized interface for ServiceNow to interact with. This decouples the systems, making the integration more resilient, maintainable, and easier to manage. A point-to-point integration would be brittle and hard to maintain. JDBC is for databases, and IntegrationHub spokes typically require standard protocols like REST or SOAP.
- Question 5Intermediate
CMDB and CSDM · Identification and Reconciliation Engine (IRE)
A large enterprise has a mature CMDB populated by multiple discovery sources, including ServiceNow Discovery, SCCM, and a custom API feed. The CMDB team frequently deals with duplicate CIs and incorrect attribute updates. The technical architect has been asked to improve the data integrity. Which specific ServiceNow engine is designed to prevent these issues by defining authoritative sources and merging CI data based on predefined rules?
Show answer & explanation
Correct answer: C
The Identification and Reconciliation Engine (IRE) is the core component responsible for maintaining CMDB data integrity when multiple data sources are involved. It uses identification rules to determine if an incoming record matches an existing CI, preventing duplicates. It then uses reconciliation rules to control which data sources are allowed to update which attributes, ensuring that the most authoritative source always wins. RTE is for data import, and the Business Rule engine is a general-purpose logic engine.
- Question 6AdvancedSelect 2
Security Architecture · Access Control Rules (ACLs)
A project requires creating a new table,
u_compliance_issue, to track regulatory issues. The security architect has determined that records in this table should only be readable by members of the 'Compliance' group. However, the user who created the issue, regardless of their group membership, must also have read access to the specific records they created. How should this security requirement be implemented using best practices? (Select TWO)Show answer & explanation
Correct answers: A, C
The best practice is to use multiple ACLs to handle different access contexts. The first ACL grants broad access to the 'Compliance' group via a role. The second ACL grants specific, record-level access to the creator of the issue using a condition or script. ServiceNow's security model evaluates all matching ACLs, and if any one of them grants access, the user can read the record. Using a Business Rule for security is not a best practice and can be easily bypassed. A single, complex scripted ACL is harder to maintain than two separate, specific ACLs.
- Question 7Intermediate
Testing Leading Practices · Automated Test Framework (ATF)
The ServiceNow Automated Test Framework (ATF) is used to create and run automated tests on an instance. What is the primary architectural benefit of using ATF for regression testing during platform upgrades?
Show answer & explanation
Correct answer: C
The primary benefit of ATF for regression testing is efficiency. Upgrades can introduce unintended changes to existing functionality, especially in customized environments. Manually testing all critical business processes is time-consuming and prone to error. ATF allows organizations to build a suite of repeatable tests that can be executed quickly after an upgrade, providing confidence that core functionality remains intact and significantly reducing the validation effort.
- Question 8Advanced
CMDB and CSDM · Common Service Data Model (CSDM)
A university is implementing ServiceNow for student services. They have a complex data model where 'Students' can enroll in multiple 'Courses', and each 'Course' is part of a 'Major'. The architect needs to model this in the CMDB according to CSDM principles to support service offerings like 'Tutoring for Major' and 'Course Registration Help'. Which CSDM domains and relationships are most critical to model this correctly?
Show answer & explanation
Correct answer: D
This is the correct CSDM alignment. 'Majors' represent what the university does (e.g., Capability to teach Engineering). 'Courses' are the services that enable this capability (e.g., Calculus 101 service). Service Offerings are the specific, commit-based ways these services are delivered (e.g., 'Tutoring for Calculus 101', 'Fall Semester Calculus 101 Registration'). This structure allows the university to connect operational CIs and incidents back to the services and capabilities they support, which is the core goal of CSDM.
- Question 9Intermediate
Release and Instance Strategy · Training Instance Strategy
A company has a primary production instance and a dedicated, isolated instance used exclusively for end-user training and sandbox activities. What is the main architectural advantage of this dedicated training instance strategy?
Show answer & explanation
Correct answer: B
The primary advantage is isolation. A dedicated training instance prevents user training, testing of new features by non-developers, or general sandbox experimentation from interfering with structured development, testing, and production operations. This ensures that the development lifecycle is not disrupted by unpredictable activities, accidental data changes, or performance degradation caused by training exercises.
- Question 10Advanced
Platform Data and Integrations · Integration with ITOM
Company Background:
HealthFirst is a large healthcare provider with a complex ecosystem of clinical applications, including an Electronic Health Record (EHR) system, a lab information system (LIMS), and a patient scheduling system. They are implementing ServiceNow ITOM Health to gain visibility into the operational status of these critical services. The goal is to create real-time service health dashboards for the IT operations center.Current Situation:
The EHR system is a modern, cloud-based application that provides a REST API for status updates. The LIMS is an older, on-premises system that writes status events to a log file. The patient scheduling system sends SNMP traps when it encounters errors. The CMDB is partially populated but lacks relationships between the infrastructure CIs and the application services.Requirements & Constraints:
- Create a single, consolidated health dashboard for the 'Clinical Services' portfolio.
- The solution must use ServiceNow-native tools where possible.
- Alerts must be automatically correlated to the correct Application Service CI.
- The solution must not require custom code to be written inside the legacy systems.
- The implementation must follow CSDM principles.
Which combination of ServiceNow features and architectural steps is required to meet these objectives?
Show answer & explanation
Correct answer: C
This option presents a complete, best-practice architectural approach. 1) It starts with CSDM to create the foundational data model, which is essential for service-aware operations. 2) It correctly identifies that ITOM Event Management has native connectors for various data sources (REST, Log File, SNMP), meeting the 'no custom code in legacy systems' requirement. 3) It leverages Alert Management rules, a key feature of ITOM, to perform the automatic correlation of events to the CIs defined in the CSDM model. This comprehensive strategy directly addresses all stated requirements.
Ready for the real thing?
The full CTA simulator has every exam-style question, timed mode, and instant scoring.