ITIL4-CDS Create, Deliver and Support Practice Question
Which THREE practices are critical for maintaining security within a high-velocity CDS development lifecycle?
⚠ Common exam trap
Candidates often assume security is a separate 'gate' or 'check' performed by a dedicated security team, failing to recognize the DevSecOps requirement for shared responsibility and automation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrating automated vulnerability scanning into the CI/CD pipeline.
Security in a high-velocity environment cannot be an afterthought; it must be integrated throughout the development process (DevSecOps). This involves automating security scans, establishing clear policies, and ensuring that security is a shared responsibility across the entire team. These practices allow teams to identify vulnerabilities early, prevent security regressions, and ensure that rapid delivery does not compromise the overall security posture of the service or the organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Performing manual security reviews after every deployment.
Why it's wrong here
Manual reviews performed after deployment are too slow and occur too late in the process. This creates a bottleneck and increases the risk of deploying vulnerabilities. Instead, security reviews should be automated within the CI/CD pipeline to ensure that security checks are performed continuously and early in the development lifecycle.
- ✓
Integrating automated vulnerability scanning into the CI/CD pipeline.
Why this is correct
Automating vulnerability scanning allows teams to catch security flaws during the build process, long before code reaches production. This is essential for high-velocity environments, as it provides instant feedback to developers and ensures that security issues are addressed at the source, reducing the risk of costly post-deployment security incidents.
- ✓
Implementing a culture of shared responsibility for security.
Why this is correct
Security is not solely the job of a specialized security team; it is a shared responsibility of everyone involved in the product lifecycle. When developers, operations, and testers are all accountable for security, the team becomes more proactive and vigilant, leading to more robust and inherently secure service delivery.
- ✗
Keeping security policies hidden to prevent unauthorized bypasses.
Why it's wrong here
Security through obscurity is an ineffective and dangerous practice. Security policies should be transparent and well-communicated so that everyone understands the requirements. Hiding these policies prevents team members from knowing how to comply with them, which increases the likelihood of accidental security gaps that can be exploited by attackers.
- ✓
Defining and enforcing security guardrails in the infrastructure code.
Why this is correct
Defining security guardrails as code (Policy as Code) ensures that infrastructure is deployed in a secure state by default. By embedding these rules into the deployment scripts, the team can prevent insecure configurations from ever being instantiated, which is a highly scalable and reliable way to maintain security in dynamic environments.
About these practice questions
This ITIL4-CDS question is part of Courseiva's 155-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official PeopleCert/AXELOS exam blueprint
This ITIL4-CDS practice question is part of Courseiva's free PeopleCert/AXELOS certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4-CDS exam.