Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

A financial services firm runs Claude-powered document review for loan applications. The CISO asks the platform team to produce evidence that every model change affecting production was reviewed and approved before deployment. Which governance mechanism most directly satisfies this requirement?

⚠ Common exam trap

The trap here is assuming that comprehensive runtime logging or version visibility in a catalog is equivalent to documented pre-deployment approval by an accountable owner.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce a change-management record that ties each production model or prompt revision to a named approver, its evaluation results, and its deployment timestamp.

Auditors need a traceable link between a deployed revision, the person who approved it, and the evidence that supported the decision. A change-management record that captures approver identity, evaluation results, and deployment time creates that chain, covering both model identifier updates and prompt changes. Logging, failover, and informal notification describe runtime behavior or awareness but cannot demonstrate pre-deployment authorization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enforce a change-management record that ties each production model or prompt revision to a named approver, its evaluation results, and its deployment timestamp.

    Why this is correct

    This is correct because an auditable change-management record links the exact revision deployed to a specific accountable approver, the evaluation evidence supporting it, and when it went live. That combination is precisely what an auditor needs to demonstrate that no model change reached production without prior review, and it scales across both model identifier updates and prompt changes in the review pipeline.

  • ✗

    Publish the current model version in the internal service catalog and notify stakeholders through the monthly engineering newsletter.

    Why it's wrong here

    Documenting the current version and announcing it informally provides visibility but no approval evidence. A service catalog entry describes state, not the review decision behind a change, and a newsletter is not an auditable control. The CISO needs proof that a specific approver authorized a specific revision before it went live, which this approach never produces.

  • ✗

    Configure automatic failover to a secondary model identifier whenever the primary model returns elevated error rates.

    Why it's wrong here

    Failover improves availability, not governance. It changes which model serves traffic based on operational health, and it does so without any human review or approval step. In fact, silent failover to a different model could undermine the very control being requested, because production behavior would shift without a documented approval record tied to the change.

  • ✗

    Enable verbose request logging on the Anthropic API so every prompt and completion is stored for later inspection by the security team.

    Why it's wrong here

    Verbose request logging captures runtime traffic, not the approval chain. It can show what the model processed, but it cannot prove that a human reviewed and authorized a given model or prompt revision before deployment. For a CISO seeking evidence of pre-deployment approval, raw request logs are the wrong artifact and would not close the control gap described.

About these practice questions

One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.