Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

A multinational bank runs a Claude-powered assistant that drafts internal credit memos. Auditors require the bank to prove that every generated memo can be traced to the exact human who requested it, the data sources the model retrieved, and the decision it influenced. Which governance capability should the architect implement first to satisfy this requirement?

⚠ Common exam trap

The trap here is assuming that any logging or monitoring already in place satisfies audit traceability, when only logs that correlate requestor identity, retrieved sources, and output identifiers create usable evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable structured audit logging that records request identity, retrieved source references, and downstream model output identifiers for each Claude invocation.

The requirement is evidentiary lineage: for each generated memo, the bank must show the requesting human, the retrieved sources, and the output that influenced a decision. Structured audit logging is the only control that binds identity, retrieval context, and output reference into a reviewable record. Filtering, caching, and spend dashboards address confidentiality, efficiency, and cost respectively, none of which reconstruct the chain of custody auditors demand.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure automatic prompt caching to reduce latency and cost for repeated credit memo templates.

    Why it's wrong here

    Prompt caching is a performance and cost optimization that reuses previously processed prompt prefixes. It has no bearing on attributing outputs to human requestors or documenting which data sources were consulted. Relying on caching would leave the audit requirement unmet because caching produces no identity or lineage evidence that auditors can inspect.

  • ✗

    Deploy a content moderation layer that filters sensitive financial terms before prompts are sent to Claude.

    Why it's wrong here

    Content moderation reduces the chance of leaking regulated data, but it does not record who requested a memo, which sources were retrieved, or how the output was used. The auditor here needs traceability of decisions and data lineage, not just prompt filtering. Filtering alone leaves the bank unable to reconstruct the chain of custody for any given memo.

  • ✓

    Enable structured audit logging that records request identity, retrieved source references, and downstream model output identifiers for each Claude invocation.

    Why this is correct

    Structured audit logging captures the requestor identity, the retrieval context, and the output reference together, producing an immutable trace that maps each memo to its origin, sources, and use. This directly satisfies the auditor's demand for end-to-end lineage, whereas the other controls improve security or quality but do not by themselves create the required evidentiary record.

  • ✗

    Set up a dashboard that tracks aggregate token consumption and monthly API spend per business unit.

    Why it's wrong here

    Cost and usage dashboards support financial governance and chargeback, but they aggregate activity rather than preserving per-request identity and source references. An auditor asking for the person, sources, and influence behind a specific memo cannot be satisfied by spend metrics. This control addresses budget oversight, not decision traceability.

About these practice questions

One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.