Courseiva
Direct, Plan and Improve →mediumMultiple Choice

ITIL4-DPI Direct, Plan and Improve Practice Question

Which approach is most appropriate for a Strategist when dealing with 'shadow IT' within an organization?

⚠ Common exam trap

Candidates often choose 'block the shadow IT' or 'enforce strict security protocols,' failing to recognize that shadow IT is a symptom of unmet business needs that require strategic engagement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify the underlying business need for the shadow IT.

Shadow IT is often a symptom of the official IT organization failing to meet business needs. Instead of just blocking it, a strategist should investigate why it exists, understand the unmet business requirement, and determine how IT can support or integrate those needs. This transforms a risk into an opportunity for innovation and improved partnership, ensuring that the organization can move fast without compromising security and governance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement strict firewall blocks on all unauthorized services.

    Why it's wrong here

    Blocking shadow IT often leads to employees finding even more obscure, less secure workarounds. It treats the symptom rather than the cause. When IT acts as a barrier rather than an enabler, business units will continue to circumvent it, which leads to increased security risks and fragmentation.

  • ✓

    Identify the underlying business need for the shadow IT.

    Why this is correct

    Shadow IT usually arises because business units need a solution quickly and IT cannot provide it. By understanding the requirement, the IT organization can either provide a secure alternative or bring the shadow solution under formal governance, thereby satisfying the business need while mitigating security and compliance risks.

  • ✗

    Mandate that all technology must be procured through IT.

    Why it's wrong here

    This approach is often ineffective in the modern digital age. It does not address why people are using shadow IT. It is likely to be ignored if the official procurement process is slow or burdensome. Relying on mandates is not a sustainable strategy for controlling IT usage in the enterprise.

  • ✗

    Discipline staff members for violating corporate policies.

    Why it's wrong here

    Punishing staff creates a culture of fear and secrecy. It does not address the fundamental issue of IT failing to provide the services the business needs. This approach will reduce morale and encourage employees to hide their work even more effectively, rather than solving the underlying process inefficiency.

About these practice questions

Courseiva writes every ITIL4-DPI question from scratch — 102 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official PeopleCert/AXELOS exam blueprint

This ITIL4-DPI practice question is part of Courseiva's free PeopleCert/AXELOS certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4-DPI exam.