CCAR-P Practice Question: Developer Productivity and Operational Enablement
A developer support team wants to give engineers a fast way to reproduce and debug failed Claude requests without exposing API keys or requiring them to install the SDK locally. Which approach best balances speed and safety?
⚠ Common exam trap
The trap here is thinking that a read-only key is safe to share, when any shared credential still violates the no-exposure requirement and blocks per-user attribution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide a web-based request playground that runs server-side, logs sanitized request IDs, and lets engineers replay a failed request with the same parameters.
A server-side playground with sanitized logging and request replay gives engineers self-service debugging at speed while keeping keys on the server. Replay of exact parameters makes failures reproducible, and per-request IDs support tracing. Shared keys, ticket queues, and keyed Docker images either expose credentials or slow engineers down, so they miss one of the two goals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Provide a web-based request playground that runs server-side, logs sanitized request IDs, and lets engineers replay a failed request with the same parameters.
Why this is correct
A server-side playground keeps API keys off developer machines while letting engineers replay exact request parameters tied to a logged request ID. Sanitized logging avoids leaking secrets. This gives fast reproduction and debugging without local installation, matching both the speed and safety goals. Replay with identical parameters is what makes failures reproducible.
- ✗
Share a read-only API key in the team wiki so engineers can paste requests into a local script.
Why it's wrong here
Sharing a key, even read-only, violates the requirement not to expose API keys and creates a credential that cannot be scoped per user or rotated easily. It also requires local setup, which the team wants to avoid. Any leaked key would affect the whole team, and usage cannot be attributed to individuals. This fails both the safety and speed criteria.
- ✗
Ask engineers to file tickets with the failing request body, and have a central team reproduce them manually.
Why it's wrong here
A manual ticket queue is slow and creates a bottleneck on the central team. Engineers cannot iterate quickly, and sensitive data may end up in tickets. It also does not give a self-service way to replay exact parameters. While it avoids key exposure, it fails the speed requirement and does not scale as request volume grows.
- ✗
Publish a Docker image containing the SDK and a preconfigured key so engineers can run requests locally in an isolated container.
Why it's wrong here
Bundling a key into a Docker image exposes the credential to anyone who pulls the image and makes rotation painful. It still requires engineers to run containers locally, adding setup friction. The key cannot be attributed per user or scoped tightly. This trades one form of exposure for another and does not meet the safety goal.
About these practice questions
One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.