CCAR-P Governance, Safety, and Risk Management Practice Question
A firm is building a financial advisor chatbot. Which safety measure is most critical for preventing the model from providing unauthorized investment advice?
⚠ Common exam trap
Candidates frequently assume that prompt engineering or system instructions alone are sufficient to prevent unauthorized advice. They underestimate the ease with which users can bypass these instructions through clever prompting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a guardrail layer to filter prohibited topics.
In financial contexts, providing unauthorized advice can lead to legal liability and significant user harm. Implementing a rigid system prompt that explicitly defines the model's limitations, combined with a deterministic 'guardrail' layer that checks for prohibited topics, is essential. This multi-layered approach ensures the model stays within its operational scope, protecting the firm from regulatory risk and ensuring users receive consistent, safe, and accurate information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Always set temperature to 0.0 for every query.
Why it's wrong here
While a temperature of 0.0 makes outputs more predictable and deterministic, it does not prevent the model from generating prohibited content if the system prompt is vague. Predictability is not the same as safety, and the model could still provide unauthorized advice if it lacks explicit, enforced constraints.
- ✓
Deploy a guardrail layer to filter prohibited topics.
Why this is correct
A guardrail layer acts as a safety gate, inspecting both input and output for prohibited topics like investment advice before they reach the user. This is a deterministic control that is far more reliable than relying solely on the model's internal prompt adherence, providing a robust safety boundary.
- ✗
Retrain the model on only financial regulations.
Why it's wrong here
Retraining is an extremely expensive and complex process that does not guarantee the model will refuse to give investment advice. It is not an appropriate or scalable solution for enforcing behavioral boundaries in an enterprise application; structural guardrails and prompt engineering are much more effective and maintainable.
- ✗
Add a disclaimer at the end of every response.
Why it's wrong here
A disclaimer is a legal necessity but not a technical safety control. It does not prevent the model from providing the advice in the first place. Governance requires preventing the harm, not just adding a notification after the potentially harmful content has already been delivered to the user.
About these practice questions
Courseiva writes every CCAR-P question from scratch — 262 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.