Courseiva

ITIL4-CDS Create, Deliver and Support Practice Question

Exhibit

JSON_POLICY: {
  "policy_id": "SEC-09",
  "auto_approve": false,
  "require_peer_review": true,
  "max_change_risk": "medium",
  "deployment_strategy": "canary"
}

Refer to the exhibit. According to this change policy, what is the mandatory requirement for a medium-risk deployment?

⚠ Common exam trap

Candidates often overthink the technical aspects of the JSON policy, failing to notice the explicit boolean flag 'require_peer_review' set to true, which is the only mandatory human step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A mandatory peer review before the deployment proceeds.

The policy explicitly sets 'require_peer_review' to 'true'. This means that regardless of the automation or deployment strategy, human oversight is required for any change. CDS policies are designed to balance the speed of delivery with the risk of service disruption. By mandating a peer review, the organization ensures that a second pair of eyes evaluates the change before it reaches the production environment, reducing the likelihood of errors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Automated approval without any human intervention.

    Why it's wrong here

    The JSON policy clearly sets 'auto_approve' to false. Therefore, automated approval is prohibited for this policy level. Relying on automation alone for medium-risk changes contradicts the explicit requirement for peer review defined in the policy, which is intended to maintain oversight and manage operational risk effectively.

  • ✓

    A mandatory peer review before the deployment proceeds.

    Why this is correct

    The policy sets 'require_peer_review' to true. This is a clear, mandatory instruction that must be followed before any deployment can move forward. This control is designed to mitigate risk by ensuring that changes are reviewed and validated by another qualified individual, which is standard practice in ITIL governance.

  • ✗

    Immediate production deployment to all users.

    Why it's wrong here

    The policy specifies a 'canary' deployment strategy, which explicitly prevents immediate deployment to all users. Instead, it requires a phased rollout where the change is tested on a small subset of users first. This strategy is essential for minimizing the blast radius of any potential issues discovered.

  • ✗

    Only high-risk changes require a formal review process.

    Why it's wrong here

    The policy defines requirements based on the risk level. For a medium-risk change, the policy explicitly requires a peer review. Claiming that only high-risk changes need review ignores the specific configuration of the JSON policy, which sets governance standards for this specific category of change, regardless of other risk levels.

About these practice questions

One of 155 original ITIL4-CDS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official PeopleCert/AXELOS exam blueprint

This ITIL4-CDS practice question is part of Courseiva's free PeopleCert/AXELOS certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4-CDS exam.