ITIL4F ITIL Service Value System Practice Question
A security breach forces an organization to take immediate action to contain the threat. The change is implemented without prior approval due to urgency. According to ITIL 4, which change type is this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Emergency change
Emergency changes are those that must be implemented as soon as possible (e.g., to resolve a security breach). They may skip normal approval but must still be documented.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Emergency change
Why this is correct
An emergency change is specifically designed for situations requiring immediate action to resolve a high-impact incident, such as a security breach, or to implement a critical fix. These changes bypass some or all of the standard change authorization and assessment processes to expedite implementation, with approval often granted retrospectively or by a dedicated emergency change authority. Their primary purpose is to restore normal service operation or mitigate significant risks as quickly as possible.
- ✗
Standard change
Why it's wrong here
A standard change is a pre-approved, low-risk change that follows a defined procedure, but this scenario describes an emergency change, which is implemented without prior approval to resolve an ongoing security incident. The temptation arises because standard changes are also pre-authorised, so one might assume urgency alone qualifies; however, standard changes require a fully documented, risk-assessed procedure completed before any implementation, which is impossible when immediate containment is needed.
- ✗
Incident Management
Why it's wrong here
Incident Management is an ITIL practice focused on minimizing the negative impact of incidents by restoring normal service operation as quickly as possible. While a security breach would certainly trigger the Incident Management practice, it describes the *process* of handling disruptions, not the *category* or *type* of change that might be implemented to resolve the underlying problem. Therefore, it is not a type of change itself.
- ✗
Normal change
Why it's wrong here
A normal change is a non-emergency change that follows a full, structured assessment and authorization process, including peer review, impact analysis, and formal approval by a Change Authority. This deliberate, planned approach ensures thorough evaluation of risks and benefits before implementation. A security breach, however, demands immediate action and cannot wait for the extensive planning and multi-stage approvals characteristic of a normal change.
Visual reference
Go deeper
Related to this question
About these practice questions
This ITIL4F question is part of Courseiva's 531-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ITIL4F practice question is part of Courseiva's free PeopleCert certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4F exam.