Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

A bank is deploying a Claude agent that can call internal tools to move funds between accounts. Risk leadership wants a control that limits the blast radius if the agent is manipulated into performing unauthorized transfers. Which control best addresses this requirement?

⚠ Common exam trap

The trap here is treating a strong system prompt or deterministic sampling as a security boundary when only the downstream authorization layer can actually enforce limits.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce authorization and transaction limits in the downstream banking APIs the agent calls, independent of anything the model outputs.

When an agent can take consequential actions, enforcement must live outside the model in the systems that hold authority. Server-side authorization, per-transaction caps, and velocity limits ensure that even a fully manipulated agent cannot exceed policy, because the downstream API rejects anything outside its rules. Prompt instructions, sampling settings, and post-hoc monitoring cannot provide that hard boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Route all agent traffic through a proxy that logs every tool invocation and alerts the security operations center after transfers complete.

    Why it's wrong here

    Detection after the fact does not prevent an unauthorized transfer from succeeding. Logging and alerting are valuable for investigation and response, but the funds have already moved by the time an alert fires. Because the requirement is to limit the blast radius of unauthorized transfers, a purely detective control leaves the primary harm unmitigated and is insufficient on its own.

  • ✓

    Enforce authorization and transaction limits in the downstream banking APIs the agent calls, independent of anything the model outputs.

    Why this is correct

    This is correct because placing authorization, per-transaction caps, and velocity limits in the downstream systems means the model's output can never exceed what the API permits, regardless of manipulation. The blast radius is bounded by deterministic server-side policy rather than by model behavior, which is exactly the defense-in-depth posture risk leadership is requesting for a high-impact tool.

  • ✗

    Add a system prompt instructing the model to never perform transfers above a defined threshold or to accounts not previously seen.

    Why it's wrong here

    Prompt-level instructions are advisory, not enforcing. A manipulated or jailbroken agent can be steered around textual constraints, and the model has no reliable way to guarantee compliance under adversarial input. Because the requirement is to bound the blast radius of unauthorized transfers, a control that lives only in the prompt provides no hard guarantee and fails the risk objective.

  • ✗

    Increase the model's temperature to zero so its responses become fully deterministic and cannot be manipulated.

    Why it's wrong here

    Temperature controls sampling randomness, not adversarial robustness. A deterministic model can still be induced to emit a harmful tool call if the input is crafted to steer it, and determinism says nothing about whether that call is authorized. Lowering temperature does not create any enforcement boundary around fund transfers, so it does not reduce the blast radius of a manipulated agent.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CCAR-P question from scratch — 262 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.