Courseiva

ITIL4-CDS Create, Deliver and Support Practice Question

Exhibit

POLICY_CHECK: 
- Access_Level: Level_3 
- Approval_Required: True 
- Automation_Allowed: False 
- Audit_Log: Mandatory

Refer to the exhibit. A team wants to automate the deployment process. Based on the current policy, what is the most appropriate next step?

⚠ Common exam trap

Candidates often assume the team has the authority to bypass or break policy for the sake of efficiency, ignoring the governance requirement to review and update policies through proper channels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request a review of the policy with relevant stakeholders to determine if it can be updated.

The policy explicitly states that automation is not allowed for this level of access. To move forward, the team must engage with governance and security stakeholders to discuss whether the policy is still fit for purpose in the current service delivery context. Simply bypassing the policy would violate compliance requirements, which could lead to significant security risks and potential legal or operational consequences for the organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Bypass the policy, as velocity and speed to market are the primary goals.

    Why it's wrong here

    Ignoring security and governance policies is a major risk. Even in fast-paced environments, compliance cannot be ignored. Bypassing the policy would lead to unauthorized changes, create security gaps, and expose the organization to significant operational risk that outweighs the temporary benefit of increased deployment speed.

  • ✓

    Request a review of the policy with relevant stakeholders to determine if it can be updated.

    Why this is correct

    In an ITIL 4 environment, policies should be reviewed to ensure they remain relevant. If the policy prevents efficient delivery, the team should engage in a formal review process. This aligns with the principle of 'Optimize and Automate' by seeking to remove unnecessary barriers while maintaining necessary controls.

  • ✗

    Implement the automation but disable the audit log to avoid compliance detection.

    Why it's wrong here

    Disabling audit logs to avoid detection is unethical and violates corporate governance standards. This action creates a dangerous lack of visibility, preventing the identification of unauthorized changes or security breaches. It is a fundamental violation of IT security practices that will lead to severe organizational consequences.

  • ✗

    Automate the process at Level_1 instead, as the policy only restricts Level_3.

    Why it's wrong here

    Automation at the wrong access level does not solve the underlying problem for the specific service module requiring the change. If the current module requires Level_3 access, changing the access level will likely lead to permission errors or security failures, failing to achieve the desired deployment outcome.

About these practice questions

Courseiva writes every ITIL4-CDS question from scratch — 155 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official PeopleCert/AXELOS exam blueprint

This ITIL4-CDS practice question is part of Courseiva's free PeopleCert/AXELOS certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4-CDS exam.