CMDB comes up in almost every ServiceNow interview for ITOM, ITSM and platform developer roles. Panels open with definitions, then move to identification rules, Discovery behaviour and data quality, because that is where production problems sit. The questions below come from real interview rounds collected by RizeX Labs trainers. Each answer is written the way you should say it out loud: what it is, why it matters, then an example. The groups follow how the topic is examined, from CI classes and the class hierarchy through to CMDB health and governance.
CMDB fundamentals
What is CMDB in ServiceNow and why is it important?
CMDB (Configuration Management Database) is the central repository holding every Configuration Item in the IT estate and the relationships between them. A CI can be a server, application, database, network device, cloud resource, business service or storage device.
Why it matters:
- Centralised visibility. One source of truth for services and assets.
- Impact analysis. You see what breaks downstream during an outage.
- Incident management. Support identifies affected services quickly.
- Change management. Impact is known before the change window opens.
- Compliance. Governance teams have traceable records.
Discovery, Service Mapping and Event Management all depend on this data, so a weak CMDB quietly breaks everything built on top of it.
Difference between CMDB and Asset Management
| CMDB | Asset Management |
|---|---|
| Operational and configuration data | Financial and lifecycle data |
| Stores CIs | Stores assets |
| Used by IT Operations | Used by Finance and Procurement |
| Tracks dependencies and services | Tracks ownership and depreciation |
| Example: server linked to an application | Example: laptop purchase cost |
Many assets become CIs, but not all CIs are assets. A purchased laptop is both. A virtual application service is a CI only.
What are CIs (Configuration Items)?
Configuration Items are the components managed in CMDB that deliver an IT service: servers, routers, databases, applications, load balancers, cloud VMs.
Every CI sits under the base table cmdb_ci, with child classes such as cmdb_ci_server, cmdb_ci_linux_server and cmdb_ci_database. The attributes that carry weight are name, IP address, serial number, environment, owner, operational status and relationships.
CI classes and the class hierarchy
Explain CMDB hierarchy and class structure
CMDB uses table inheritance. Each class extends a parent and inherits its fields.
cmdb_ci
├── Hardware
│ └── Server
│ ├── Linux Server
│ └── Windows Server
├── Network Gear
│ ├── Router
│ └── Switch
└── Application
└── Business Application
A Linux server inherits from cmdb_ci, then cmdb_ci_hardware, then cmdb_ci_server, before adding its own fields. Common fields are defined once and reporting works across a whole branch.
What are CI classes?
A CI class is a table in that inheritance tree representing one type of Configuration Item, with its own attributes and identification rules. cmdb_ci_win_server is a class; one Windows server record inside it is a CI. Discovery classifies devices into classes and identifiers attach per class, so putting a database on a generic server class stops every database rule applying to it.
What is a CI Class Manager?
CI Class Manager is the workspace for the data model: class hierarchy, table inheritance, attributes, relationship rules and identifiers in one place. Typical use is creating cmdb_ci_custom_firewall as a child of cmdb_ci_network, then configuring its identifiers so Discovery and integrations can match records in it.
Relationships and dependency views
Explain CI Relationships with examples
Relationships define how CIs depend on each other. They live in cmdb_rel_ci, with a parent, a child and a type.
| Parent | Relationship | Child |
|---|---|---|
| Application | Runs on | Server |
| Server | Connected to | Switch |
| Database | Hosted on | Server |
Common types are Depends on, Runs on, Hosted on, Connected to and Used by. To read what a CI connects to:
var rel = new GlideRecord('cmdb_rel_ci');
rel.addQuery('parent', serverSysId);
rel.query();
while (rel.next()) {
gs.info(rel.type.getDisplayValue() + ' : ' + rel.child.getDisplayValue());
}
Relationships drive impact analysis, root cause analysis and Service Mapping. Without them CMDB is an inventory list.
Explain dependent relationships in CMDB
A dependent relationship records that one CI cannot function without another. An application depends on its database, web server and load balancer, so if the database fails the chain shows the application is impacted. Event Management uses it for correlation.
Memorised definitions collapse when an interviewer says "give me a real project example", so keep one dependency chain from your own work ready to describe end to end.
What is a Business Service in CMDB?
A Business Service represents an IT service as the business consumes it: Online Banking, HR Portal, E-commerce Platform. Underneath sit the applications, servers, databases and network dependencies that deliver it. Incidents and SLAs can then be reported in business language. "Three servers are down" means little to a manager. "Online Banking is degraded" starts an escalation.
Identification and reconciliation
What is Identification and Reconciliation Engine (IRE)?
IRE is the single entry point through which CI data should be written. Identification decides whether an incoming record matches a CI that already exists. Reconciliation decides whether the source is allowed to update those fields. You get fewer duplicates, controlled source priority, and data that survives several feeds writing to one record.
How does CI Identification work?
Identification uses rules defined per class. For a Windows server the criteria are typically serial number, then name, then IP address, in priority order.
- Payload arrives from Discovery or an integration.
- IRE reads the identification rules for that class.
- Match found, the existing CI is updated.
- No match, a new CI is created.
A server arriving with the same serial number and hostname as an existing record updates that record instead of creating a second one.
What are Identification Rules and Reconciliation Rules?
Identification rules uniquely identify a CI. For a server they use serial number, hostname and MAC address, held as identifier entries under that class's CI identifier, each with its own priority.
Reconciliation rules control which source may write which field.
| Field | Authorised source |
|---|---|
| RAM | Discovery |
| Owner | SCCM |
| Location | Manual update |
If SCCM sends a RAM value while Discovery owns the field, the update is rejected.
What is Data Source precedence in CMDB?
Precedence decides which source wins when more than one feed sends the same attribute.
| Source | Priority |
|---|---|
| Discovery | High |
| SCCM | Medium |
| Manual | Low |
If SCCM and Discovery both report CPU details, Discovery wins. Precedence is set per attribute, so one source can own hardware data while another owns software inventory on the same CI.
Explain Reconciliation Definitions with real-time examples
A reconciliation definition names the data source, the class and the attributes it may update. Discovery updates CPU, RAM and IP address. SCCM updates installed software and user details. Manual updates cover support group and assignment group. Field ownership is enforced rather than argued about after a bad overwrite, and when a value flips between two numbers every night, this is the first place to look.
What happens when duplicate CIs are created? How do you handle them?
Duplicates produce incorrect reporting, wrong impact analysis, incidents raised on the wrong record and changes approved against a CI nobody uses.
- Find them using duplicate CI remediation tasks and CMDB Health.
- Check the identification rules for that class.
- Correct the IRE configuration so matching works next time.
- Merge or retire the duplicates.
- Fix the source that created them.
To find them yourself:
var dup = new GlideAggregate('cmdb_ci_server');
dup.addNotNullQuery('serial_number');
dup.addAggregate('COUNT');
dup.groupBy('serial_number');
dup.query();
while (dup.next()) {
var count = parseInt(dup.getAggregate('COUNT'), 10);
if (count > 1) {
gs.info(dup.getValue('serial_number') + ' has ' + count + ' server CIs');
}
}
Step 4 without step 3 guarantees the duplicates return after the next Discovery run.
How do you prevent duplicate CI creation during integrations?
Route every integration through IRE instead of writing directly to CI tables, and give it something unique to match on: serial number, UUID or FQDN. Set coalesce on a unique field where an import set is unavoidable, and normalise data so one server does not arrive as three spellings. Hostname alone is weak, because the same hostname appears in dev, test and production more often than anyone admits.
Discovery and data sources
What is ServiceNow Discovery? How does it work internally?
Discovery finds infrastructure on the network and populates CMDB without manual entry. Internally it runs in phases:
- Scanning. Configured IP ranges are scanned for active IPs.
- Classification. Discovery determines what kind of device answered.
- Identification. IRE matches the device to an existing CI or creates one.
- Exploration. Detailed attributes are collected.
- Relationship mapping. Relationships between CIs are created.
- CMDB update. Records are inserted or updated.
It reaches targets over SSH, WMI, SNMP, PowerShell and HTTP, depending on device type and credentials.
What are discovery probes and sensors?
A probe is the instruction sent out to collect data. The MID Server runs it against the target and puts the result on the ECC Queue. A sensor is the script on the instance that parses that result and writes to CMDB. Probe collects, sensor processes. Patterns do the same work through a pattern definition instead of a chain of probes and sensors, which makes them easier to extend without scripting.
What is horizontal discovery?
Horizontal discovery works from the infrastructure upwards. It scans IP ranges, classifies each device, explores it, populates infrastructure CIs such as servers and network gear, and creates the relationships visible from the host. It answers "what do we have", and it is the mode most organisations implement first.
What is top-down discovery?
Top-down discovery is Service Mapping. You start from a business service entry point, usually a URL, and follow actual traffic and configuration files from tier to tier: web server to application server to database. It answers "what delivers this service", which horizontal discovery cannot fully answer, because a service map follows connections rather than IP ranges.
Difference between Discovery and Service Mapping
| Discovery | Service Mapping |
|---|---|
| Finds infrastructure devices | Maps business services |
| IP based scanning | Traffic and configuration based |
| Focus on infrastructure | Focus on applications |
| Creates infrastructure CIs | Creates application dependencies |
| Example: server discovery | Example: end to end application flow |
Both write to the same CMDB, and mature environments run both.
What are MID Servers and why are they used?
MID stands for Management, Instrumentation and Discovery. It is a Java application installed inside the customer network, bridging the instance and on-premise infrastructure, because the instance cannot reach into a private network directly.
The MID Server polls the instance over HTTPS, picks up work from the ECC Queue, runs it against internal devices and posts results back. All communication is outbound, so no inbound firewall rule is needed. The same MID Server supports Discovery, Service Mapping, Orchestration and integrations.
How do you troubleshoot failed Discovery?
Work from the outside in:
- MID Server. Is it Up, with the required capabilities and IP ranges.
- Credentials. Test the SSH, WMI or SNMP credential against the target.
- Firewall and ports. Confirm required ports are open from the MID subnet.
- Logs. Read the Discovery Status record, the ECC Queue payload and sensor errors.
- Connectivity. Ping and telnet the target on the port in question.
- Patterns. A customised pattern that worked before an upgrade is a common culprit.
Usual causes are invalid credentials, firewall blocks, DNS failures and timeouts. Panels lean on this question deliberately: "Discovery is not populating CIs, what do you check" separates people who have run it from people who have read about it, exactly as "your Business Rule is not firing, what do you check" beats "what is a Business Rule".
What are transform maps in CMDB integrations?
A transform map converts rows in a staging table into records in a target table. The flow is import set table, then transform map, then target CMDB table. It handles field mapping, value transformation, scripted maps and coalescing. A CSV column host_name maps to name on cmdb_ci_server. For CMDB, send the transformed payload through IRE rather than inserting directly.
Have you worked on SCCM, Intune, or JAMF integrations? Explain.
Answer only from work you have actually done. Interviewers go five levels deep on project claims: which table, what requirement, why this over that, what was your role. Fake experience disappears by level three.
- SCCM brings Windows device inventory, installed software and user mapping.
- Intune brings mobile device management data, compliance state and Azure sync.
- JAMF brings Mac and Apple device management data.
The flow is the same each time: import the data, run a transform map, pass the payload to IRE, update CMDB.
Difference between Manual CI creation and Discovery-based creation
| Manual creation | Discovery based creation |
|---|---|
| Created by hand | Created automatically |
| Higher chance of error | More accurate |
| Slow | Fast |
| Does not scale | Scales to thousands of devices |
| Suited to logical CIs | Suited to infrastructure |
Manual creation still fits CIs no scan can see, such as business services and contracts.
CMDB health and governance
Explain CMDB Health Dashboard
The CMDB Health Dashboard scores the quality of the data rather than the quantity. It reports completeness, correctness and compliance by CI class, surfaces stale records, missing relationships and orphan CIs, and gives the data owner a number to improve against instead of an opinion.
What are the three CMDB Health metrics?
Completeness. Are required fields populated. A server CI with no IP address or no owner fails here.
Correctness. Are values accurate and correctly formatted. An invalid IP address or a malformed serial number fails here.
Compliance. Do CIs follow organisational policy. A CI not updated for 90 days, or created in a class the data model does not permit, fails here.
Explain CMDB Data Manager and Data Certification
CMDB Data Manager runs the CI lifecycle through policies that move records through states and eventually archive, retire or delete them, for example retiring servers untouched for 180 days.
Data Certification asks a human instead. A schedule generates tasks for CI owners, who review the attributes on their records and either confirm or correct them. One keeps the table clean automatically, the other keeps the content trustworthy.
How do you optimize CMDB performance in large environments?
- Index attributes used in identification rules and frequent queries.
- Archive or retire old CIs so tables stop growing without limit.
- Limit excessive relationships. A CI with hundreds of children makes dependency views unusable.
- Tune Discovery schedules so ranges are not scanned more often than the data changes.
- Keep identification rules efficient, since every payload runs through them.
- Balance load across MID Servers and watch their memory.
What are the common issues you faced in CMDB projects?
The recurring ones are duplicate CIs, poor data quality, missing relationships, Discovery failures, incorrect reconciliation, stale records and integration conflicts. The fixes are less technical than candidates expect: a named data owner per class, everything written through IRE, health dashboards reviewed on a schedule, and data certification. Answer with one issue you personally fixed, as situation, approach, reason and result. Rambling from "basically in our project we had one requirement" loses the point.
How do you migrate CMDB data between instances?
| Method | Used for |
|---|---|
| Update sets | Classes, identifiers, reconciliation definitions |
| Export and import sets | CI records in moderate volume |
| IntegrationHub ETL | Large or complex migrations |
| Instance clone | A full environment copy |
The sequence is export, validate mappings, import, run transform maps, validate relationships, then run reconciliation. Relationships break most often, because they reference sys_ids that may not exist in the target.
Scenario question
A Server CI is getting updated from multiple sources with incorrect values. How will you troubleshoot and fix it?
Answer as an ordered investigation.
- Identify the sources. Discovery, SCCM, Intune, manual updates, custom integrations.
- Review audit history. See which account set the wrong value and when.
- Analyse reconciliation rules. Check which source is authorised for those attributes.
- Check identification rules. Confirm payloads match the intended CI rather than half matching two records.
- Validate transform maps. An incorrect field mapping overwrites good data quietly.
- Verify precedence. Confirm the intended source holds higher priority for the attribute.
- Fix the rules. Update the reconciliation definition so only the authorised source writes the field.
- Reprocess. Re-run Discovery or the integration and confirm the value holds.
The outcome: conflicting updates stop, ownership per attribute is documented, and the CI stays accurate between runs.
What the interviewer is actually checking
- Whether you can name the table.
cmdb_ci,cmdb_rel_ci, identifier entries. Vague answers about "the CMDB module" read as classroom knowledge. - Whether you treat IRE as a gate every source passes through, not a background feature.
- Whether you can troubleshoot. Failed Discovery and conflicting updates are asked far more often than definitions.
- Whether your project story holds under follow-up questions about the class, the requirement and your role.
- Whether you know the boundary between CMDB and Asset Management, because the two teams disagree about it in every organisation.
Preparing for the CMDB round
Work through each question above, then answer it out loud against something you have built. If you have no instance to point at, build a small one: a few server CIs, an application, the relationships between them, an identification rule on serial number, and one broken feed you then fix. Fifteen minutes of that beats an hour of re-reading definitions, because the panel is testing demonstration rather than recall.
Our ServiceNow training programme covers CMDB, Discovery and ITOM with hands on instance work and interview practice in each module.