CIS-EM Certified Implementation Specialist - Event Management Exam Questions and Answers
If more than one event rule applies to a particular event or metric, which of the event rules will run based upon the Order of execution number?
What are the server requirements to allow Operational Intelligence to successfully collect operational metric data via a push?
If the Message Key is not populated, the default value is created from which fields?
When performing CI Binding, what fields does Event Management match to the Node?
During processing of the event and if the event Severity is blank, the state of the event is set to:
Which step in the event rule configuration process enables you to ignore events and prevent alert generation?
What two key steps must be performed after creating a new connector instance? (Choose two.)
What ServiceNow feature would you configure to process incoming email to create events?
What is the default collection/polling interval applied to all event connectors?
What are the key components that can be managed using Service Operations Workspace integrations Launchpad?
What is the primary function of the link view feature in the Service Operations Workspace express list?
What is an alert called that moves from an open to a closed state multiple times within a designated time-frame?
Agent Client Collector is built on what framework that enables you to adopt and extend monitoring checks from the community?
What would you use to define the monitoring sources allowed to communicate with the ServiceNow instance for Operational Intelligence?
You have an event with a Source of ‘Trap from Enterprise 111’, but the alert created for this event shows a Source of ‘Oracle EM’. If you want to change what this is set to, where in the event rule would you do this?
In Service Operations Workspace, what tool shows relationships between configuration items and alerts with real-time updates and detailed impact paths?
How would you interpret the following data in the Operational Intelligence Insights Explorer?

Based on the information shown, which of the following three alerts should be processed first?
The correct regex to capture the name of the server in “the server webserver3.domain.com is down” would be:
To determine the top incidents for the CI associated with an alert, where is the best place to look?
For an incoming event with a matching message key, what allows an existing alert to be automatically closed?
