ITIL4-CDS Create, Deliver and Support Practice Question
An organization is designing a value stream to handle emergency security patching for cloud-hosted applications. During the flow analysis, the team notices that approval gates for urgent patches take an average of four hours due to manual compliance checks. Which action should the value stream manager take first to optimize this flow?
⚠ Common exam trap
Candidates often suggest 'removing the gate entirely' or 'increasing staff,' which ignores the need for governance and compliance; the correct ITIL approach is to automate the control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrate automated compliance checks and pre-approval policies into the CI/CD pipeline for low-risk security patches.
Optimizing a value stream requires identifying bottlenecks and waste without compromising control. Introducing automated compliance validation directly addresses the four-hour manual delay while maintaining rigorous security governance, thereby improving flow velocity. This matters in Create, Deliver and Support because balancing speed and governance is central to high-velocity service performance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove all approval gates entirely to ensure patches are deployed instantly to production environments without human intervention.
Why it's wrong here
Eliminating all approvals removes critical governance checkpoints, exposing the organization to severe operational risks and potential compliance failures. Value stream optimization seeks to streamline controls through automation rather than abandoning essential risk management procedures entirely.
- ✓
Integrate automated compliance checks and pre-approval policies into the CI/CD pipeline for low-risk security patches.
Why this is correct
Automating compliance checks removes manual bottlenecks and significantly reduces lead time for emergency patches while maintaining necessary audit trails and security standards. This directly enhances flow efficiency within the value stream without introducing unacceptable operational risks.
- ✗
Extend the standard change window by two hours to accommodate the manual compliance verification process safely.
Why it's wrong here
Extending the change window does not resolve the underlying bottleneck causing the four-hour delay during the value stream stages. It merely shifts the operational timeline rather than improving the flow efficiency or reducing overall lead time for patches.
- ✗
Reassign the compliance verification task to the development team to bypass the dedicated security review board.
Why it's wrong here
Removing the security review board eliminates the compliance control rather than the delay, creating unmanaged risk for emergency patches. Delegating verification to developers suits low-risk routine changes; here the four-hour manual gate itself must be streamlined while retaining independent security assurance.
About these practice questions
One of 155 original ITIL4-CDS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official PeopleCert/AXELOS exam blueprint
This ITIL4-CDS practice question is part of Courseiva's free PeopleCert/AXELOS certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4-CDS exam.