CCAR-P Governance, Safety, and Risk Management Practice Question
A fintech company's risk committee is operationalizing a governance program for Claude-powered customer support agents. They must demonstrate to regulators that model behavior changes are tracked, attributable, and reversible. Which TWO practices best satisfy this requirement? (Choose two.)
⚠ Common exam trap
The trap here is assuming that logging, caching, or prompt version control constitutes model change management, when none of them actually freezes or attributes changes to the model artifact itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a fixed regression suite against each candidate model version and archive the scored results before promoting it.
Attributable, reversible model change management requires two things working together: a frozen, dated artifact in production and comparable evidence captured before promotion. Pinning to dated model identifiers supplies the frozen artifact and the rollback target, while a fixed regression suite run against each candidate supplies the before-and-after evidence. Together they let the risk committee answer what changed, who approved it, and how to undo it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Route every request through a gateway that logs the full request and response payloads with the model identifier attached.
Why it's wrong here
Payload logging is valuable for incident forensics and quality review, but logs are observational evidence, not a control over model behavior. A log showing that responses changed overnight does not prevent the change, attribute it to a decision-maker, or provide a rollback path. Regulators asking for attributable, reversible change management need the pinning and evaluation record instead.
- ✗
Enable prompt caching on all production requests so that previously validated prompts are reused verbatim.
Why it's wrong here
Prompt caching reduces latency and cost by reusing prefix computations, but it does not version model weights or record behavioral change. Cached prompts still execute against whatever model is currently aliased, so a silent upgrade would change outputs while the cache layer reports nothing. It is a performance feature, not an auditability control.
- ✓
Run a fixed regression suite against each candidate model version and archive the scored results before promoting it.
Why this is correct
A fixed regression suite produces comparable, dated evidence that a candidate version behaves acceptably on the scenarios the business cares about. Archiving scores before promotion creates the attributable record regulators expect and gives the team an objective basis for approving or rejecting an upgrade. Combined with pinned identifiers, it closes the loop between decision and deployed artifact.
- ✓
Pin production deployments to dated model identifiers and maintain a change log linking each identifier to its evaluation results.
Why this is correct
Dated identifiers such as claude-3-5-sonnet-20240620 freeze model behavior, so any output shift can be attributed to a deliberate upgrade. Pairing each pinned identifier with stored evaluation results gives auditors a traceable record of what was tested and when, and it makes rollback a simple re-pointing exercise rather than an investigation.
- ✗
Store the system prompt in a version-controlled repository and require pull-request review before it is merged.
Why it's wrong here
Version-controlling the system prompt governs one input to the system, and review discipline is genuinely useful. However, the model itself can change beneath an unchanged prompt when an alias such as claude-3-5-sonnet-latest silently advances. This practice therefore cannot demonstrate that model behavior changes are tracked or reversible, which is the committee's stated obligation.
About these practice questions
Courseiva writes every CCAR-P question from scratch — 262 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.