Courseiva

ITIL4-CDS Create, Deliver and Support Practice Question

Exhibit

CI/CD Pipeline Config:
- Stage 1: Unit Tests (Required)
- Stage 2: Security Scan (Optional)
- Stage 3: Integration Tests (Required)
- Stage 4: Production Deployment (Automatic)

Issue: A recent update introduced a critical vulnerability that was missed by Stage 1 and 3.

Refer to the exhibit. According to ITIL 4 CDS, what change to the pipeline configuration would most effectively prevent this type of failure in the future?

⚠ Common exam trap

Candidates often suggest manual reviews or increased documentation, missing the 'Shift Left' principle which requires embedding security checks automatically into the pipeline to prevent failures at the source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Make the Security Scan a required stage before production deployment.

The failure occurred because security testing was optional. To improve quality and reduce risk, the organization must integrate security testing as a mandatory quality gate. This aligns with the 'Shift Left' principle by ensuring that security is a non-negotiable part of the automated pipeline, preventing insecure code from ever reaching the production environment and maintaining overall service integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Make the Security Scan a required stage before production deployment.

    Why this is correct

    Making the security scan mandatory ensures that all code is validated against security standards before deployment. This proactive approach prevents vulnerable code from entering production, directly addressing the root cause of the current failure and enhancing the overall security and reliability of the automated delivery process.

  • ✗

    Increase the number of unit tests in Stage 1 to cover security scenarios.

    Why it's wrong here

    Unit tests are designed to verify the logic of individual components, not to conduct comprehensive security scanning. Relying on unit tests for security is inefficient and ineffective. Dedicated security scans are required to detect vulnerabilities that unit tests are not intended or equipped to identify during the CI process.

  • ✗

    Disable the automatic deployment in Stage 4 to require manual sign-off.

    Why it's wrong here

    Disabling automation is a regression that slows down delivery without addressing the underlying vulnerability. The focus should be on improving the quality of the automated checks, not removing the automation itself. Manual sign-offs are prone to error and do not provide the same rigor as automated security scans.

  • ✗

    Perform a manual security audit after the code is deployed to production.

    Why it's wrong here

    Post-deployment audits are reactive and fail to prevent the vulnerability from impacting users. The goal of a CI/CD pipeline is to catch defects before they reach production. Shifting the audit to after deployment increases the risk of exploitation and the cost of remediation, violating CDS principles.

About these practice questions

Courseiva writes every ITIL4-CDS question from scratch — 155 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official PeopleCert/AXELOS exam blueprint

This ITIL4-CDS practice question is part of Courseiva's free PeopleCert/AXELOS certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4-CDS exam.