Courseiva
Direct, Plan and Improve →mediumMultiple Choice

ITIL4-DPI Direct, Plan and Improve Practice Question

Exhibit

RISK_REPORT:
- RISK_1: HIGH_IMPACT_SECURITY_VULNERABILITY
- RISK_2: LOW_IMPACT_RESOURCE_SCHEDULING_CONFLICT
- ACTION_PLAN: ADDRESS_RISK_2_FIRST_AS_IT_IS_EASIER

Refer to the exhibit. Why is the proposed action plan a failure of governance?

⚠ Common exam trap

Candidates often confuse operational efficiency with governance, incorrectly assuming that prioritizing fast, easy tasks demonstrates good management rather than evaluating risk exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It ignores the risk prioritization principle by placing convenience above organizational stability.

The plan prioritizes an easy task (low impact) over a critical security vulnerability (high impact). This is a failure of governance because the primary goal of the governing body is to manage risk and protect the organization's assets. A failure to address a high-impact security risk is an abdication of duty and exposes the organization to severe potential consequences, which is the exact opposite of what effective governance should achieve.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It fails to account for the total cost of addressing all risks simultaneously.

    Why it's wrong here

    While cost is important, the primary failure here is the prioritization error. Addressing the high-impact security risk must take precedence regardless of cost, as the potential consequences of a security breach are far more damaging than the inefficiency of resource scheduling conflicts.

  • ✓

    It ignores the risk prioritization principle by placing convenience above organizational stability.

    Why this is correct

    Effective risk management requires prioritizing based on the level of impact and likelihood, not the effort required to resolve the issue. By choosing the 'easy' task, the leadership is prioritizing convenience over stability and security, which is a fundamental violation of sound governance and risk management practices.

  • ✗

    It neglects to consult with the human resources department regarding scheduling.

    Why it's wrong here

    While consultation might be helpful, it is not the reason this plan is a failure of governance. The failure is the incorrect prioritization of a high-impact security vulnerability. Even if HR were consulted, the plan to delay the security fix would remain a dangerous and improper decision.

  • ✗

    It does not provide a timeline for when the security vulnerability will be addressed.

    Why it's wrong here

    A timeline is useful, but it does not fix the fundamental issue of incorrect prioritization. Even with a timeline, delaying a high-impact security vulnerability is unacceptable. The core failure is the decision to ignore the high-risk item in favor of a low-impact one, which is an error in judgment.

About these practice questions

One of 102 original ITIL4-DPI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official PeopleCert/AXELOS exam blueprint

This ITIL4-DPI practice question is part of Courseiva's free PeopleCert/AXELOS certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4-DPI exam.