Courseiva
Create, Deliver and Support →mediumMultiple Choice

ITIL4-CDS Create, Deliver and Support Practice Question

An organization is designing a value stream to deliver a new cloud-native application. The team notices that waiting for security approvals causes a major bottleneck in deployment frequency. According to ITIL 4, how should the team best address this constraint while maintaining control?

⚠ Common exam trap

Candidates often suggest 'removing security checks' to increase speed, failing to realize that ITIL 4 promotes 'shifting' controls, not abandoning them for the sake of velocity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Shift security validation left by automating checks within the continuous integration and deployment pipeline.

Shifting left involves moving quality assurance, security, and compliance checks earlier in the value stream, embedding them directly into the development and testing phases. This addresses bottlenecks by replacing manual approval gates with automated validation, ensuring that speed does not compromise governance and security requirements in modern service delivery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Eliminate all formal security reviews to maximize the flow of deployments and achieve continuous delivery goals.

    Why it's wrong here

    Removing security reviews entirely abandons the control the stem requires, so deployments flow but risk is unmanaged. It is tempting because ITIL 4 does advocate removing non-value-adding approval gates; however, that applies to low-risk changes automated through change enablement pipelines, not to eliminating security governance.

  • ✓

    Shift security validation left by automating checks within the continuous integration and deployment pipeline.

    Why this is correct

    Embedding security checks early into the pipeline allows automated scanning to catch vulnerabilities instantly. This prevents waiting for manual sign-offs, significantly reduces deployment lead time, and preserves compliance by design throughout the entire value stream.

  • ✗

    Centralize all authorization decisions under the executive change advisory board to guarantee strict compliance.

    Why it's wrong here

    Routing every authorisation through an executive change advisory board concentrates decision-making, adding queue time and reducing deployment frequency rather than relieving the constraint. It is tempting because centralised boards suit high-risk, infrequent changes needing broad oversight, but ITIL 4 delegates standard, low-risk changes to automated pipelines.

  • ✗

    Extend the testing phase duration to allow manual security auditors sufficient time to inspect each release package.

    Why it's wrong here

    Lengthening testing to accommodate manual auditors deepens the very bottleneck the value stream must relieve, since approval capacity stays fixed while queue time grows. It is tempting because thorough manual inspection suits high-risk, low-frequency releases, yet cloud-native delivery needs automated security controls embedded in the pipeline.

About these practice questions

This ITIL4-CDS question is part of Courseiva's 155-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official PeopleCert/AXELOS exam blueprint

This ITIL4-CDS practice question is part of Courseiva's free PeopleCert/AXELOS certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4-CDS exam.