ITIL4-CDS Create, Deliver and Support Practice Question
An organization is designing a value stream to deliver a new cloud-native application. The team notices that waiting for security approvals causes a major bottleneck in deployment frequency. According to ITIL 4, how should the team best address this constraint while maintaining control?
⚠ Common exam trap
Candidates often suggest 'removing security checks' to increase speed, failing to realize that ITIL 4 promotes 'shifting' controls, not abandoning them for the sake of velocity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shift security validation left by automating checks within the continuous integration and deployment pipeline.
Shifting left involves moving quality assurance, security, and compliance checks earlier in the value stream, embedding them directly into the development and testing phases. This addresses bottlenecks by replacing manual approval gates with automated validation, ensuring that speed does not compromise governance and security requirements in modern service delivery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Eliminate all formal security reviews to maximize the flow of deployments and achieve continuous delivery goals.
Why it's wrong here
Removing security reviews entirely abandons the control the stem requires, so deployments flow but risk is unmanaged. It is tempting because ITIL 4 does advocate removing non-value-adding approval gates; however, that applies to low-risk changes automated through change enablement pipelines, not to eliminating security governance.
- ✓
Shift security validation left by automating checks within the continuous integration and deployment pipeline.
Why this is correct
Embedding security checks early into the pipeline allows automated scanning to catch vulnerabilities instantly. This prevents waiting for manual sign-offs, significantly reduces deployment lead time, and preserves compliance by design throughout the entire value stream.
- ✗
Centralize all authorization decisions under the executive change advisory board to guarantee strict compliance.
Why it's wrong here
Routing every authorisation through an executive change advisory board concentrates decision-making, adding queue time and reducing deployment frequency rather than relieving the constraint. It is tempting because centralised boards suit high-risk, infrequent changes needing broad oversight, but ITIL 4 delegates standard, low-risk changes to automated pipelines.
- ✗
Extend the testing phase duration to allow manual security auditors sufficient time to inspect each release package.
Why it's wrong here
Lengthening testing to accommodate manual auditors deepens the very bottleneck the value stream must relieve, since approval capacity stays fixed while queue time grows. It is tempting because thorough manual inspection suits high-risk, low-frequency releases, yet cloud-native delivery needs automated security controls embedded in the pipeline.
About these practice questions
This ITIL4-CDS question is part of Courseiva's 155-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official PeopleCert/AXELOS exam blueprint
This ITIL4-CDS practice question is part of Courseiva's free PeopleCert/AXELOS certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4-CDS exam.