Courseiva

CCAR-P Advanced Agentic Architecture Practice Question

A customer-support agent must sometimes escalate to a human and sometimes resolve autonomously. The compliance team requires that any action touching billing be reviewed by a human before execution, while password resets may proceed automatically. The architect wants the model to decide routing without hardcoding every rule in the prompt. Which design best satisfies the requirement?

⚠ Common exam trap

The trap here is assuming that a well-written system prompt or a fine-tuned model can serve as a compliance control, when only deterministic enforcement outside the model can guarantee a gated action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Classify each proposed tool call by risk tier in the orchestration layer, auto-approve low-risk actions, and require human approval for billing-tier actions regardless of model output.

The compliance requirement is a hard gate, so the decision to require human approval must live in deterministic orchestration code rather than in model judgment. Tiering tool calls by risk lets low-risk actions like password resets flow automatically while billing actions are held for approval before execution. The model can still propose actions, but the authoritative approval decision is enforced outside it, which makes the control auditable and immune to prompt drift or probabilistic misrouting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Fine-tune the model on historical escalations so it learns which actions compliance typically requires humans to approve.

    Why it's wrong here

    Fine-tuning shifts behavior statistically but provides no guarantee that a billing action will always be gated. A model trained on past escalations can still generalize incorrectly on a novel case, and the compliance requirement is absolute rather than typical. There is also no runtime mechanism to block an unapproved billing action, so the control remains probabilistic and unauditable.

  • ✓

    Classify each proposed tool call by risk tier in the orchestration layer, auto-approve low-risk actions, and require human approval for billing-tier actions regardless of model output.

    Why this is correct

    Enforcing the risk tier outside the model makes the control deterministic and auditable: billing actions cannot execute without human approval even if the model proposes them. Password resets proceed automatically because they fall in the low-risk tier. The model still decides routing in the sense of proposing actions, but the orchestration layer holds the authoritative gate, satisfying compliance without hardcoding every conversational rule in the prompt.

  • ✗

    Give the model a single escalate tool and instruct it in the system prompt to use judgment about when human review is required.

    Why it's wrong here

    Relying on model judgment for a compliance-mandated control means the decision is probabilistic and unauditable. The model may route a billing action to autonomous execution, violating the requirement. A single escalate tool also provides no structured signal about which category triggered review, making it hard to verify or report on compliance. The requirement demands deterministic enforcement, not discretionary behavior.

  • ✗

    Log every tool call the agent makes and have the compliance team review the logs weekly to catch any unauthorized billing actions.

    Why it's wrong here

    After-the-fact review does not prevent the unauthorized action; by the time the log is read, the billing change has already executed. The requirement is that billing actions be reviewed before execution, which retrospective auditing cannot satisfy. This approach also creates a detection gap of up to a week, during which many non-compliant actions could occur without being stopped.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CCAR-P question is part of Courseiva's 262-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.