01. How does observability differ from monitoring?
a) Monitoring is automated, while observability depends on engineers inspecting the system
b) Monitoring checks conditions somebody anticipated, while observability supports questions nobody thought to ask in advance
c) Monitoring applies to infrastructure, while observability applies to applications
d) Monitoring reports the current state, while observability reports historical trends
02. An established company with a large product portfolio now has to demonstrate to an external regulator that its access controls operate as described.
Which stage's concerns does this requirement belong to?
a) Growing from a single team into several, and coordinating the dependencies that appear between them
b) Formalizing product management as the company grows beyond its founders
c) Establishing the infrastructure on which the first product runs
d) Operating at enterprise scale, where the organization must account for itself to parties outside it
03. When planning recovery for a digital service, organizations distinguish a recovery point objective from a recovery time objective.
What does the recovery point objective describe?
a) How much recent data the organization can afford to lose
b) How quickly the service must be back in operation after a failure
c) The point in the recovery procedure at which the service is declared usable
d) The location from which the service will be operated during a failure
04. Controls are commonly classified as preventive, detective, or corrective.
What does a corrective control do?
a) It stops an unwanted event from taking place at all
b) It identifies that an unwanted event has taken place
c) It reduces the damage an event causes while it is happening
d) It restores the organization to a sound position after an event has occurred
05. While a live service is unavailable, what is the primary objective of the incident response?
a) Recording what happened so that the sequence of events can be reconstructed
b) Establishing the underlying cause so that the fault can be corrected properly
c) Returning the service to the users who depend on it
d) Notifying the stakeholders whose work the outage is disrupting
06. Why is applying security patches treated as a continuing operational obligation rather than as a task completed once a system is built?
a) Because auditors expect evidence that a patching process is operating
b) Because suppliers require patches to be applied to keep support entitlements valid
c) Because patches deliver the performance improvements a running system needs
d) Because weaknesses keep being discovered in components that were sound when the system was first assembled
07. Empirical process control rests on transparency, inspection, and adaptation.
What does inspection require?
a) That an independent reviewer checks the work, and signs it off before it is accepted
b) That progress is reported to stakeholders at the end of each iteration
c) That the work and its results are examined often enough to detect a problem
d) That the process itself is audited against the standard it was defined to meet
08. Who is meant by the term Digital Practitioner?
a) A software engineer responsible for building and maintaining the code behind the product
b) Anyone involved in creating or managing a product with a digital component, whatever role they hold in the organization
c) A manager held accountable for the delivery of an organization's transformation program
d) A consultant certified to advise organizations on digital strategy
09. Before a change is released, a document is produced summarizing it for a governance board. The board has not read one for two years, and no decision has ever turned on it.
How would Lean thinking classify this activity?
a) As necessary overhead, since governance requires a record of what was changed
b) As a control, since producing it gives the board an opportunity to intervene
c) As waste, since nobody derives value from it
d) As rework, since the information already exists elsewhere in the delivery record
10. What does a feature flag change about the relationship between deploying a change and releasing it?
a) Code can be deployed to production while the decision to expose it is taken separately
b) A change can be released to users before it has been deployed to production
c) Release happens automatically once the change has been observed running correctly
d) Deployment and release become a single step, so a merged change reaches users directly