Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

A multinational bank deploys Claude to draft internal policy summaries for staff in the EU and Singapore. Legal requires that personal data embedded in employee questions never leave its region of origin, but the bank wants a single application codebase. Which architecture most directly enforces the residency requirement?

⚠ Common exam trap

A common mix-up: candidates confuse data residency with data retention or with contractual transfer permissions, when only the network path actually determines where processing occurs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure regional API endpoints so that EU traffic is served within the EU and Singapore traffic within its region, sharing only stateless application code.

Data residency is a geographic constraint on where processing happens, so the control must shape the request path rather than the contract or the retention window. Routing each jurisdiction to an in-region API endpoint keeps personal data inside its required boundary while a shared, stateless codebase avoids duplicated engineering effort. Redaction and retention settings reduce risk but do not guarantee the data never leaves the region.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable zero data retention on the account so that no request or response content is stored by the provider.

    Why it's wrong here

    Zero data retention limits how long content is persisted, and it is a meaningful privacy control. It says nothing about where processing occurs, however, so in-flight and processed data may still be handled outside the required region. Residency and retention are separate obligations, and this setting addresses only the latter.

  • ✓

    Configure regional API endpoints so that EU traffic is served within the EU and Singapore traffic within its region, sharing only stateless application code.

    Why this is correct

    Regional endpoints keep the request and response path inside the required geography while allowing one codebase to be deployed to multiple regions. Stateless application code carries no personal data between regions, so residency is enforced by the network topology rather than by policy language. This is the most direct technical control for the stated requirement.

  • ✗

    Deploy the application in one region and rely on the model provider's contractual data processing addendum to cover cross-border transfer.

    Why it's wrong here

    A data processing addendum governs legal obligations and permitted handling, but it does not enforce a technical boundary. Requests from EU staff would still traverse and potentially be processed outside the EU unless a regional endpoint is used. The scenario asks for enforcement of residency, and a contract alone leaves the actual data path unchanged.

  • ✗

    Apply client-side redaction of names and identifiers before the request is sent, then send all traffic to a single global endpoint.

    Why it's wrong here

    Redaction reduces exposure but is probabilistic and cannot guarantee that all personal data is removed, especially in free-text employee questions. Any residual personal data still crosses the border to the global endpoint. Because the requirement is that data never leaves its region, a best-effort filter that still routes abroad does not satisfy it.

About these practice questions

Courseiva writes every CCAR-P question from scratch — 262 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.