Courseiva
Direct, Plan and Improve →hardMultiple Choice

ITIL4-DPI Direct, Plan and Improve Practice Question

Exhibit

JSON_POLICY: {
  "enforce_security": true,
  "max_risk_score": 5.0,
  "allowed_regions": ["US", "EU"],
  "auto_approve_threshold": 2.5
}

Refer to the exhibit. A proposed improvement plan results in a risk score of 3.2 in the 'US' region. Based on the policy, what is the correct action?

⚠ Common exam trap

Test-takers frequently miscalculate threshold boundaries or assume that any score exceeding the minimum auto-approval limit must be outright rejected rather than manually reviewed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Submit the plan for manual review and authorization

The policy states that the auto-approval threshold is 2.5. Since the project risk score of 3.2 is above this threshold but below the maximum allowed risk of 5.0, it cannot be auto-approved. It requires manual review and authorization by the appropriate governance body before it can proceed. This ensures that higher-risk initiatives are vetted thoroughly, maintaining alignment with the organization’s established risk appetite and compliance requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Auto-approve the plan since it is below the max_risk_score of 5.0

    Why it's wrong here

    Auto-approval is limited to plans with a score of 2.5 or lower. A score of 3.2 exceeds this threshold, meaning the policy requires a formal review. Simply relying on the max score ignores the distinction between automated and manual processes defined in the policy's thresholds for risk management.

  • ✗

    Reject the plan immediately because it exceeds the auto_approve_threshold

    Why it's wrong here

    Exceeding the auto-approval threshold does not mean the plan is rejected; it means it requires manual intervention. Rejecting the plan without a proper review is premature and could lead to the loss of a valuable improvement opportunity that simply needs to be assessed by the appropriate human oversight.

  • ✓

    Submit the plan for manual review and authorization

    Why this is correct

    Since 3.2 is between the auto-approve threshold and the maximum risk limit, the policy dictates that the plan requires additional review. This process is necessary to verify the risk mitigation strategies and ensure that leadership is comfortable with the level of exposure before authorizing the improvement initiative.

  • ✗

    Ignore the risk score and proceed, as it complies with all other policies

    Why it's wrong here

    Ignoring a risk score violation is a direct breach of organizational policy. The policy is designed to enforce strict risk controls. Proceeding without addressing this violation would be a failure of governance and could expose the organization to unacceptable risks that the policy was explicitly designed to prevent.

About these practice questions

Courseiva writes every ITIL4-DPI question from scratch — 102 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official PeopleCert/AXELOS exam blueprint

This ITIL4-DPI practice question is part of Courseiva's free PeopleCert/AXELOS certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4-DPI exam.