← Home
🔥0 DAY
⚡0 XP
Developer Track · 2026

SERVICENOW DEVELOPER
INTERVIEW QUESTIONS.

The scripting questions ServiceNow developer interviews actually ask, with model answers short enough to say out loud and real code where it helps. Grouped by topic so you can drill the area your screen will cover.

GlideRecord & data access

Every developer screen starts here. Interviewers want to hear that you query efficiently and know what runs where.

  1. How do you write an efficient GlideRecord query?

    Filter as close to the data as possible: addQuery before setLimit, choose indexed fields, and never count with getRowCount() inside a loop — use GlideAggregate. Only ask for the rows you actually need.

    var gr = new GlideRecord("incident");
    gr.addQuery("state", "1"); // New
    gr.addQuery("assigned_to", gs.getUserID());
    gr.orderByDesc("sys_created_on");
    gr.setLimit(10);
    gr.query();
    while (gr.next()) {
      gs.info(gr.number + " - " + gr.short_description);
    }
  2. GlideRecord vs GlideAggregate — when does each win?

    GlideRecord when you need field values or to update rows. GlideAggregate when you need COUNT, SUM, AVG, MIN or MAX — the math happens in the database instead of pulling every row into memory.

  3. What is the difference between get() and query()?

    get() fetches a single record by sys_id or a unique field and returns a boolean. query() executes the full filter set and you iterate with next(). Using query() when a get() would do is a red flag in a screen.

  4. How do you query a reference field's display value?

    Dot-walk in the query (addQuery('caller_id.department.name', 'IT')) or use getDisplayValue() after the row loads. Dot-walking in the query keeps the filter in the database; getDisplayValue() is for output only.

Business rules

Expect the before/after/async decision and at least one recursion trap. These are the questions that separate scripters from configurators.

  1. Before, after, async, display — how do you choose?

    Before: change the record being saved without an extra update. After: touch other records once this one is committed. Async: heavy work that must not slow the transaction. Display: pass data to the form via g_scratchpad.

  2. Why is current.update() inside a business rule dangerous?

    It re-triggers business rules on the same record, causing recursion and a duplicate write. In a before rule, set fields directly and let the engine persist; in an after rule, guard with setWorkflow(false) only when you truly need a second write.

  3. How do you stop a business rule from running on every row of an import?

    Add tight conditions, check current.operation() and use setWorkflow(false) where flows are not needed. For transforms, prefer transform scripts or field-level logic over a table-wide rule.

  4. What is g_scratchpad and when do you use it?

    A display business rule can stash server-side values on g_scratchpad, and the client script reads them on load — the supported way to pass server data to a form without an extra GlideAjax round trip.

Client scripts & GlideAjax

Client-side questions test whether you respect the browser. Synchronous calls and DOM access are the classic traps.

  1. How do you call server code from a client script?

    GlideAjax against a Client Callable Script Include that extends AbstractAjaxProcessor, always with an asynchronous callback. Synchronous getXMLWait() freezes the browser and is an instant interview fail.

    var ga = new GlideAjax("UserUtils");
    ga.addParam("sysparm_name", "getUserDept");
    ga.addParam("sysparm_user", g_user.userID);
    ga.getXMLAnswer(function (answer) {
      g_form.setValue("department", answer);
    });
  2. UI Policy or Client Script — which do you reach for first?

    UI Policy for declarative mandatory/visible/read-only behaviour: less code, runs on server too, easier to maintain. Client Script only when you need imperative logic like calculations, string handling or AJAX lookups.

  3. Why should client scripts never use document or window directly?

    ServiceNow renders forms inside its own framework; direct DOM access breaks on UI16/Next Experience upgrades and in Service Portal. Use g_form and g_user APIs, which are stable across interfaces.

  4. Which client script types run when, and which should you avoid?

    onLoad when the form renders, onChange when a field changes, onSubmit before save, onCellEdit in lists. Avoid global onChange scripts on high-churn fields — they fire on every keystroke-driven change and slow the form.

Script Includes & reusable code

Architecture questions. Interviewers probe whether you write reusable, testable server code or copy-paste the same block into ten business rules.

  1. When do you move code into a Script Include?

    As soon as two callers need the same logic, or when a business rule grows past a screenful. A Script Include gives you one tested implementation, a clear API, and a single place to fix the bug.

  2. Class-based vs function-style Script Include?

    Class-based (var MyUtil = Class.create(); MyUtil.prototype = { ... }) is the modern default: it groups related methods, supports private helpers, and is what GlideAjax requires. Loose function includes are legacy.

  3. What makes a Script Include callable from the client, and what is the risk?

    Checking 'Client callable' and extending AbstractAjaxProcessor. The risk is exposure: every public method is reachable from the browser, so validate inputs server-side and keep the callable surface tiny.

  4. How do you make server code testable in ServiceNow?

    Keep Script Includes free of current/gs globals where possible — pass records and parameters in. Pure functions over GlideRecord queries can be exercised in background scripts and ATF steps without a form session.

Integrations & REST

Mid-level and senior screens always include one integration question. Know the outbound call, the auth story, and the failure modes.

  1. How do you call an external REST API from ServiceNow?

    RESTMessageV2 (or a REST Message record) with an endpoint, HTTP method, headers and body. Put credentials in a Connection & Credential alias, not in the script, and handle non-200 responses explicitly.

    var r = new sn_ws.RESTMessageV2();
    r.setEndpoint("https://api.example.com/tickets");
    r.setHttpMethod("POST");
    r.setRequestHeader("Content-Type", "application/json");
    r.setRequestBody(JSON.stringify({ short_description: current.short_description }));
    var response = r.executeAsync(); // never block the transaction
    var status = response.getStatusCode();
  2. Where do you store API credentials?

    In Connection & Credential records (backed by the credential store), referenced by alias. Hardcoded tokens in scripts leak into update sets and version history — interviewers specifically listen for this.

  3. Inbound vs outbound integration — what changes in your design?

    Inbound: you build a Scripted REST API or use Table API, and you own authentication, ACLs and rate concerns. Outbound: you own retries, timeouts and async patterns so a slow third party never stalls a user transaction.

  4. How do you keep an integration from blocking the user?

    Run it async: an async business rule, a scheduled job, or Flow Designer with an async action. Synchronous outbound calls inside a before rule are the classic production incident story.

Performance & architecture

Senior-level questions. These test whether you have operated a real instance, not just written scripts that work once.

  1. A list view is slow — how do you investigate?

    Check the filter against table indexes, look for unindexed dot-walked columns in the sort, and review any business rules firing on query. Slow query log and stats pages show the actual SQL cost.

  2. How do you keep a big instance healthy as data grows?

    Archive or purge rotated-out tables, index the fields you actually filter on, avoid leading-wildcard contains queries, and keep business rule conditions tight so cheap rules exit early.

  3. Update sets vs scoped apps vs CI/CD — how do you ship code?

    Update sets for small configuration batches, scoped applications for anything with a lifecycle, and source-control-backed pipelines (Git + CI/CD APIs) once a team is committing daily. The answer interviewers want is that you have a release discipline at all.

  4. What would you never put in a global business rule?

    Anything heavy or specific: global rules fire on every table, so a GlideRecord lookup inside one runs on every save in the system. Scope rules to the exact table and condition they serve.

Now write the code

Reading answers clears the phone screen; the technical round asks you to produce script under time pressure. Run the drills that match these topics.