Exam Prep · SRE Foundation (SREF)

Answer Triage — SREF

Every SREF question ends the same way: four options, one correct, the clock still running. Recognizing a familiar-sounding term gets you through the easy third of the exam without any trouble at all. It's the harder two-thirds — the questions where two, sometimes three, options all look defensible — that decide whether you clear 65%. This page is a procedure for that exact moment: a five-pass method for narrowing four options down to one when nothing about the stem is instantly obvious, the three named trap patterns DevOps Institute-style single-best-answer questions are built around, and a flag-and-return protocol for spending your sixty minutes on the questions that actually need it instead of bleeding time evenly across all forty. None of this replaces knowing the material — Know It Cold and the Concept Reference do that job, and Closed-Book Strategy covers how the material gets into your head in the first place. This page is what you run once the material alone hasn't settled which option to pick.

☺ Explain it like I'm 10

Picture a police lineup where the witness isn't asked "which one did it?" right away. First: who's obviously the wrong height or build entirely — cross those off. Then: who matches the general description but has a solid alibi for that night — cross those off too, even though they "fit" at first glance. What's left gets compared detail by detail, not by gut feeling, until exactly one person is left standing. That's the whole method on this page, aimed at a multiple-choice question instead of a lineup: don't ask "which one feels right," ask "which ones can I prove are wrong," in a fixed order, until only one is left.

🦊🦥Your hosts for this topic: Foxy & Sol the Sloth — Foxy runs the same skeptical, prove-it-before-you-believe-it instinct on a tempting answer option that she runs on a suspicious root cause: don't credit it just because it sounds plausible, disprove it or let it stand. Sol treats a genuinely hard question exactly like error-budget arithmetic — worked through in a fixed order, slowly and correctly, rather than fast and guessed. Between the two of them: the skepticism that catches a distractor, and the discipline that runs all five passes instead of stopping at three.

Why elimination beats recognition on a single-best-answer exam

☺ Like you're 10: Feeling like you've seen an answer before and being able to prove the other three are wrong are different skills — only the second one is what the exam is actually grading.

"Single-best-answer" is a specific, deliberate exam design, not a stylistic choice, and it changes what studying for it actually needs to produce. The format doesn't ask you to spot the one option that's correct among three that are nonsense — that would be a recognition test, and a well-prepared candidate would clear it by pattern-matching alone. It asks you to spot the one option that's most correct among several that are each defensible in isolation, which is a genuinely different task: at least one distractor is usually a true, accurate statement about SRE that simply doesn't answer the question being asked, and at least one more is often true and on-topic, just less complete than the credited answer. Both of those survive a "does this sound right?" scan easily, because they are right — about something. A candidate who studies by reading definitions until they feel familiar walks in with exactly the skill this format is built to defeat.

The fix isn't studying harder in the same way — it's replacing "which one sounds right" with a repeatable process that actively tries to disprove each option before it's allowed to survive. That's what the five passes below are: not five minutes of extra deliberation, but a fixed order of attack that turns "I feel torn between B and C" into "I can state, in one sentence, what's wrong with B" — which is a question you can actually answer under a clock, where a feeling of being torn usually isn't.

⚠ Recognizing every trap on this page once isn't the same as applying the method cold

You will likely nod along to every pattern below on a single read — that's what a good explanation is supposed to feel like, and it's exactly the same illusion Closed-Book Strategy warns about for content review: recognition, not recall. The only real test of this page is running the five passes against a question you haven't seen the answer to yet, with a clock on it. The practice bank and a timed mock exam are where that actually happens — this page is the procedure, not the rep.

The five-pass elimination method

☺ Like you're 10: Five short passes, not five minutes of staring — each one has exactly one job, and it removes exactly one option before handing off to the next.

Run these in order, every time you're not instantly sure of the answer. Skipping a pass because an option "obviously" survives it is the single most common way this method fails — the whole point is to make elimination mechanical instead of intuitive, because intuition is precisely what a well-built distractor is designed to fool.

PassWhat you doWhat it removes
1 · Paraphrase the stemBefore reading a single option, restate the actual question in one plain sentence in your own words — not the topic, the specific thing being asked.Nothing yet — but it stops you from answering the question you expected to see instead of the one actually in front of you.
2 · Strike the objectively falseKill any option containing a claim that's simply, factually wrong about SRE, no matter how confident, specific, or official-sounding it reads.The option any expert in the room would reject outright — often written in imprecise or superseded vocabulary. See the outdated-term option below.
3 · Strike the off-topic trueKill any option that's a true, accurate SRE statement — just not an answer to the question you paraphrased in Pass 1.The almost-right distractor — see below.
4 · Stress-test what survivesRead every surviving option against its own qualifiers — absolutes like "always," "never," "only," "the sole" — and compare completeness head-to-head against the paraphrased stem, not against each other in isolation.The true-but-not-the-best-answer option — see below — plus anything an absolute qualifier just quietly broke.
5 · Commit or flagExactly one option left: choose it and move on without revisiting. Two still tied after Passes 2–4: flag the question per the protocol below and continue — don't re-run the same three passes hoping for a different result.Nothing — this is a decision point, not an elimination step.
Pass 1 — paraphrase the stem (no elimination yet) A B C D Pass 2 strikes D objectively false / outdated term Pass 3 strikes B almost-right distractor Pass 4 strikes C true, not the best answer A — correct answer Pass 5 — commit Options originate top; the funnel shows narrowing, not their real order in the exam UI.

The three trap patterns single-best-answer questions are built around

☺ Like you're 10: Wrong answers on a test like this usually aren't nonsense — they're real facts wearing the wrong hat. Naming the hat is most of the battle.

A distractor that's obviously silly wastes a question-writer's effort — nobody picks it, so it tests nothing. The distractors that actually separate a 65% pass from a near miss are built out of real SRE material, aimed just slightly off target. These three patterns cover the overwhelming majority of that near-miss material, and naming which one you're looking at is what turns "I don't love any of these" into an actual elimination.

The almost-right distractor

A true, accurate statement about SRE — that answers a different question than the one the stem actually asked. This is the classic case covered on Know It Cold: an option that correctly defines an SLA when the stem asked about an SLO, or one that accurately describes a chaos experiment when the stem described a game day. Nothing about the sentence itself is wrong — read in isolation, it's a fact you'd happily agree with. It's wrong here, for this stem, because it answers the adjacent question instead of the asked one.

How to catch it: this is exactly what Pass 3 is for. Hold your Pass-1 paraphrase next to the option and ask, literally, "does this sentence answer that sentence?" — not "is this sentence true." An almost-right distractor passes the second test and fails the first, every time.

The true-but-not-the-best-answer option

A true, on-topic statement that survives Pass 3 because it genuinely does answer the question asked — it's just less complete, less immediate, or narrower in scope than the credited answer. This is the pattern "single-best-answer" exists specifically to test for, and it's the one recognition-based studying is worst at catching, because there's nothing factually wrong to notice. Both options are correct facts about the right topic; only one of them is the best answer to exactly what was asked.

How to catch it: Pass 4's head-to-head comparison. Don't ask "is this option right" — both survivors usually are. Ask "which of these two most completely and most directly answers my Pass-1 paraphrase, with nothing left over that the stem asked for and this option didn't cover." A partial or eventual-but-not-immediate answer loses to a complete, direct one every time the stem's own wording asks for the direct one.

The outdated-term option

Real vocabulary — just the wrong-era or wrong-precision word for the idea the stem is testing. Sometimes this is a genuinely retired or superseded term standing in for a concept the field now names more precisely; sometimes it's a colloquial word borrowed from an adjacent discipline that sounds like it fits but skips the mechanism the question actually cares about. Three concrete examples worth having ready:

Outdated / imprecise optionWhat it's standing in for, and why it's wrong here
"Convene a war room"Colloquial, undefined — no assigned roles, no scoped authority. The exam-correct concept is Incident Command: a named Incident Commander who coordinates without necessarily debugging, an Ops/Comms lead who owns outward-facing updates, and subject-matter responders pulled in as the incident narrows. See incident management & on-call.
Report headline "uptime"Infrastructure/host uptime measures whether servers are reachable, not whether user requests actually succeed end to end — the "vanity uptime" trap this course names explicitly. A question about reliability reporting wants the correct SLI measured at the boundary the user crosses, not a host-health number. See measuring & reporting reliability.
"Target five nines for every service"Treats reliability as one universal, fixed physics constant instead of a per-service choice. The correct SRE framing: the right SLO is the loosest one users won't notice missing — more reliability than that is wasted engineering effort, not virtue. See SLIs, SLOs & error budgets.

How to catch it: mostly Pass 2, since an outdated-term option is frequently just flatly wrong for the question asked, not merely imprecise. Occasionally it survives to Pass 4 as a vaguer, less-precise near-miss — in that case, treat unrecognized or informal vocabulary the way you'd treat an absolute qualifier: a flag to stress-test, not a reason to trust it.

◆ These three aren't mutually exclusive

A single wrong option can be an almost-right distractor written in outdated terms at once — "the war room's incident commander declares an SLA breach," say, mixes all three flaws into one sentence. The names aren't a taxonomy to memorize for its own sake; they're vocabulary for what Passes 2 through 4 are actually doing, so you can state in one sentence what's wrong with an option instead of just vaguely disliking it.

Worked example: running all five passes cold

☺ Like you're 10: One made-up question, four options, each one showing you exactly what a trap looks like in the wild — try it before you read the walkthrough.

This question is built to demonstrate all three trap patterns in a single stem, the way a real exam sometimes does. Read it once, pick an answer, then read the walkthrough — the exercise is worth far more if you commit to an option first.

🦊 Foxy's lineup · try it cold first

Wavelength's checkout-api holds a 99.9% SLO measured over a rolling 30-day window. This morning's dashboard shows the service sitting exactly on that line — 99.9% attainment, zero error budget remaining for the window. The platform team wants to ship a moderately risky config change today to shave 40ms off checkout latency. Per standard SRE practice, what should happen next?

A. New risky releases pause and the team's priority shifts to reliability work — fixing whatever is consuming the budget — until it recovers as the window rolls forward or the burn demonstrably stops.
B. The SLA has been breached, so the team owes affected customers a contractual service credit.
C. The team should investigate what's consuming the budget and consider whether the SLO itself needs renegotiating.
D. Check whether the underlying servers are still reporting healthy uptime before deciding anything.

Pass 1 — paraphrase. The actual question: given zero error budget remaining right now, what's the standard, immediate response to a risky release request today? Not "what could the team eventually do about reliability" — what happens next, about this release.

Pass 2 — strike the objectively false. Option D reaches for infrastructure "uptime" when nothing in the stem is about server health at all — it's an SLO/error-budget question, and "uptime" is the vanity-metric framing this course explicitly warns against on measuring & reporting reliability. Strike D. That's the outdated-term option: real vocabulary, wrong lens entirely for what's being asked.

Pass 3 — strike the off-topic true. Option B is a true statement about SLAs in general — a breached SLA can carry a contractual credit — but nothing in the stem establishes an SLA or claims one was breached; the stem describes the internal SLO sitting exactly on its line, which is a distinct, internal concept from the external SLA. B answers a real, adjacent SRE question — just not this one. Strike B. That's the almost-right distractor.

Pass 4 — stress-test what's left. A and C are both true and both on-topic. C — investigate the burn and consider renegotiating the SLO — is a real move a healthy team eventually makes, and it's exactly the quarterly-review renegotiation covered on measuring & reporting reliability. But it's not the immediate, standing response to hitting zero budget today, and Pass 1's paraphrase specifically asked what happens next about today's release decision. A is the complete error-budget policy response — pause the risky release now, shift to reliability work until recovery — and it directly answers the release question in front of the team, where C defers that question entirely in favor of a longer-term one. Strike C. That's the true-but-not-the-best-answer option.

Pass 5 — commit. One option survives: A.

The flag-and-return protocol for the 60-minute clock

☺ Like you're 10: Forty questions, sixty minutes — about ninety seconds each on average, which is generous for a question you know and brutal for one you're determined to fully solve on the spot.

Forty questions in sixty minutes averages ninety seconds each — comfortable for a question you know cold, unforgiving for one that needs the full five-pass treatment mid-sitting while thirty-nine other questions are still waiting. The fix isn't answering faster; it's refusing to let one hard question spend time that belongs to three easy ones later in the paper. Most PeopleCert-delivered online exams, the SREF included, provide a literal mark-for-review flag next to each question — confirm the exact mechanic during your pre-exam system check, since exam-platform interfaces do get updated, but the underlying tactic below works regardless of the exact UI.

PhaseRoughlyWhat happens
1 · First pass, all 40~35 minAnswer everything you're genuinely confident about, in order, at whatever pace that takes. The instant a question would need the full five-pass method, flag it and move on immediately — don't start Pass 2 mid-first-pass.
2 · Second pass, flagged only~20 minReturn to flagged questions only, in the order you flagged them, and run all five passes on each in full — this is where the method on this page actually gets used, with your easy points already banked.
3 · Final review~5 minConfirm nothing was left blank. Don't reopen an already-answered question without a specific new reason to distrust it — a vague "let me double-check" with no new evidence is how correct answers get changed into wrong ones.
⚠ Guessing beats a blank, but verify the policy

The standing assumption on most closed-book, single-best-answer certification exams — and, as far as public DevOps Institute material indicates, the SREF — is that an incorrect answer costs you exactly the one mark and nothing more; there's no separate penalty for guessing beyond simply not getting the mark. Confirm this on the official exam policy before you rely on it, but treat "leave nothing blank" as the safe default: a blank at time's up is a guaranteed zero, and a flagged-but-guessed answer at least has a chance.

🐢 Timmy's timeout drill

Timmy never lets a dependency call run without a timeout, and the same discipline applies here: pick a hard ceiling before you sit down — ninety seconds is the sitting's own average, so treat it as the trigger, not a hard rule to panic over. The moment you notice yourself re-reading the same option for the third time with no new information, that's the timeout firing: flag it, pick your current best guess as a placeholder, and move on. Rehearse this against a full timed mock exam at least once before the real sitting — the flag-and-return habit is easy to agree with in the abstract and surprisingly hard to actually do the first time a question is genuinely stuck, exactly like a circuit breaker that's never been tested against a real failure.

🎬 At the Reliability Watch
🐰

Remy the Rabbit: Question 14. "War room" is right there in option D. That's basically what happens during an incident, ship it.

🦊

Foxy: Name the roles in your "war room," Remy. Who's the Incident Commander? Who owns the status page?

🐰

Remy the Rabbit: ...nobody, it's just "war room."

🦥

Sol the Sloth: Which is exactly the tell. Real incident command has named roles. A vague, undefined room isn't the mechanism — it's the word people used before the mechanism had a name.

🐢

Timmy the Turtle: And Question 27's been open for ninety seconds now, Remy. Flag it. We'll come back with the whole method once the easy thirty-nine are banked.

🐰

Remy the Rabbit: Fine — flagged. But I'm still answering the next one in ten seconds.

🦊

Foxy: Ten seconds is fine, once it's earned. Speed on the easy ones is exactly what buys you the twenty minutes for the hard ones.

That's the full method: five passes that turn "torn between two options" into a provable elimination, three named traps so a bad option gets caught by what it's doing wrong instead of a vague feeling, and a two-pass sitting strategy that spends your sixty minutes where they're actually needed. None of it substitutes for the material itself — go to Know It Cold and the Concept Reference for that, and Closed-Book Strategy for how it gets into your head in the first place. Once the method feels natural, test it for real against the full practice bank or its three focused sets, then a timed mock exam — Sets 2 through 5 in that sequence lean harder into exactly the near-miss distractors this page is built to catch. Full exam-day logistics live on the exam guide.

✓ Checkpoint

1. Name the five passes in order, and what each one eliminates. 2. What's the difference between an almost-right distractor and a true-but-not-the-best-answer option — which pass is built to catch each? 3. In the worked example, why was option D eliminated in Pass 2, and what established trap from elsewhere in this course does its wording match? 4. What's the flag-and-return protocol in one sentence, and roughly how should the sixty minutes split across its three phases? 5. Why doesn't recognizing every trap pattern on this page once mean you're ready to apply the five-pass method under time pressure?

Check your answers
  1. Pass 1 paraphrase the stem (eliminates nothing, but fixes what's actually being asked). Pass 2 strike the objectively false (removes the option any expert would reject outright). Pass 3 strike the off-topic true (removes the almost-right distractor). Pass 4 stress-test what survives against qualifiers and completeness (removes the true-but-not-the-best-answer option). Pass 5 commit if one option remains, or flag and move on if two are still tied.
  2. An almost-right distractor is true but answers a different question than the one asked — caught in Pass 3 by checking whether the option answers the Pass-1 paraphrase. A true-but-not-the-best-answer option is true and on-topic, just less complete or less immediate than the credited answer — caught in Pass 4's head-to-head completeness comparison.
  3. Option D framed the question as an infrastructure "uptime" check when the stem was entirely about SLO/error-budget status — a lens mismatch, not just a wrong fact. It matches the "vanity uptime" trap covered on measuring & reporting reliability: reporting host/infrastructure uptime as if it represents the metric users actually experience.
  4. Answer everything you're confident about in a first pass through all 40 questions, flagging anything that needs the full five-pass method instead of stalling on it, then return to flagged questions only in a second pass. Roughly: ~35 minutes for the first pass, ~20 minutes for the flagged second pass, ~5 minutes for a final review that confirms nothing was left blank.
  5. Recognizing a pattern in an explanation is a different skill from producing the elimination yourself, cold, against a question you haven't seen the answer to, under a clock — the same recognition-versus-recall gap Closed-Book Strategy covers for content review generally. Only running the method against fresh questions in the practice bank or a timed mock exam actually tests whether it's usable under pressure.