ITIL4F ITIL Management Practices Practice Question
Exhibit
Refer to the exhibit. Configuration item: WebServer01 Status: Active Category: Software Location: Datacenter A Relationships: - Is connected to: NetworkSwitch03 - Runs on: VirtualHost01 - Is used by: Application: OrderApp Change order: CHG00123 Requested by: John.Smith Change authority: IT Manager Justification: Upgrade OS to patch security vulnerability Risk level: Low Status: Approved
Refer to the exhibit. A change order to patch a security vulnerability on WebServer01 has been approved. The IT manager is the change authority. During implementation, it is discovered that the patch requires a reboot, which will cause an outage for the OrderApp application. What is the MOST appropriate action?
⚠ Common exam trap
Many exam-takers assume a change approval is final and irrevocable, but ITIL 4 requires that any new risk discovered during implementation must be communicated to the change authority for a fresh decision, not blindly executed or automatically escalated to a CAB.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inform the IT manager and ask for a decision on whether to proceed.
The change order was approved based on the original scope, which did not include a reboot. The discovery that a reboot is required introduces a new risk (application outage) that was not assessed during the initial approval. The IT manager, as the change authority, must be informed and make a decision on whether to proceed with the change under the new circumstances, in line with the ITIL 4 'change enablement' practice of managing risk and ensuring authorized decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Inform the IT manager and ask for a decision on whether to proceed.
Why this is correct
When new information, such as an unexpected mandatory reboot causing an outage, emerges after a change has been approved but before its implementation, the designated change authority must be informed. The IT manager, acting as the change authority, is empowered to re-evaluate the change's risk, impact, and schedule based on this updated information. This ensures that decisions are made with the most current data, aligning with ITIL's principle of 'Progress Iteratively with Feedback' and maintaining service stability.
- ✗
Escalate to the change advisory board (CAB) for a new approval.
Why it's wrong here
Escalating this change to the Change Advisory Board (CAB) for a new approval is an unnecessary procedural step and introduces undue delay. The CAB is typically involved in assessing higher-risk or complex normal changes requiring broader stakeholder input, but the IT manager is clearly identified as the specific change authority for this particular change. Given the risk is still considered low, involving the CAB would add bureaucratic overhead without providing additional value beyond what the designated authority can provide.
- ✗
Proceed with the change as planned, since the change is already approved.
Why it's wrong here
Proceeding with the change as originally planned, despite discovering a new significant impact like a mandatory reboot, is highly irresponsible and could lead to unexpected service disruption. The initial approval was based on incomplete information, as it did not account for the potential outage. Implementing the change without re-evaluation violates the core principle of effective change control, which requires understanding and managing all known risks and impacts before deployment to prevent negative business consequences.
- ✗
Cancel the change and request a new one with updated information.
Why it's wrong here
Canceling the existing change and requesting an entirely new one with updated information is an overly drastic and inefficient response to new information. While the impact profile has changed, the fundamental need for the security patch remains valid and critical. This approach introduces unnecessary administrative overhead, delays the crucial security update, and wastes the effort already invested in the initial planning and approval stages. A more agile and appropriate action is to reassess the existing change with the designated authority.
Go deeper
Related to this question
About these practice questions
Courseiva writes every ITIL4F question from scratch — 805 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ITIL4F practice question is part of Courseiva's free PeopleCert certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4F exam.