Courseiva
ITIL Service Value SystemhardMultiple ChoiceObjective-mapped

ITIL4F ITIL Service Value System Practice Question

A security breach forces an organization to take immediate action to contain the threat. The change is implemented without prior approval due to urgency. According to ITIL 4, which change type is this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Emergency change

Emergency changes are those that must be implemented as soon as possible (e.g., to resolve a security breach). They may skip normal approval but must still be documented.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Emergency change

    Why this is correct

    An emergency change is specifically designed for situations requiring immediate action to resolve a high-impact incident, such as a security breach, or to implement a critical fix. These changes bypass some or all of the standard change authorization and assessment processes to expedite implementation, with approval often granted retrospectively or by a dedicated emergency change authority. Their primary purpose is to restore normal service operation or mitigate significant risks as quickly as possible.

  • Standard change

    Why it's wrong here

    A standard change is a pre-approved, low-risk change that follows a defined procedure, but this scenario describes an emergency change, which is implemented without prior approval to resolve an ongoing security incident. The temptation arises because standard changes are also pre-authorised, so one might assume urgency alone qualifies; however, standard changes require a fully documented, risk-assessed procedure completed before any implementation, which is impossible when immediate containment is needed.

  • Incident Management

    Why it's wrong here

    Incident Management is an ITIL practice focused on minimizing the negative impact of incidents by restoring normal service operation as quickly as possible. While a security breach would certainly trigger the Incident Management practice, it describes the *process* of handling disruptions, not the *category* or *type* of change that might be implemented to resolve the underlying problem. Therefore, it is not a type of change itself.

  • Normal change

    Why it's wrong here

    A normal change is a non-emergency change that follows a full, structured assessment and authorization process, including peer review, impact analysis, and formal approval by a Change Authority. This deliberate, planned approach ensures thorough evaluation of risks and benefits before implementation. A security breach, however, demands immediate action and cannot wait for the extensive planning and multi-stage approvals characteristic of a normal change.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This ITIL4F question is part of Courseiva's 531-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ITIL4F practice question is part of Courseiva's free PeopleCert certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4F exam.