CCAR-P Governance, Safety, and Risk Management Practice Question
A multinational retailer operates Claude in three regions and must prove that customer data from each region never leaves that region, even during model upgrades. Which architectural approach best satisfies this requirement?
⚠ Common exam trap
The trap here is treating encryption, contractual language, or audit logs as sufficient proof of data residency when only architecture determines where processing occurs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy region-specific endpoints and storage in each geography, pin explicit model identifiers per region, and validate data flows so no cross-region replication occurs.
Residency requires architectural enforcement: region-specific endpoints and storage keep processing local, pinned model identifiers prevent silent rerouting during upgrades, and validated data flows prove no replication occurs. Contracts, encryption, and post-hoc logging address legal assurance, confidentiality, or detection, but none of them constrain where data is actually processed and stored.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable verbose audit logging on all regions and review the logs quarterly to detect any cross-region data movement.
Why it's wrong here
Detection after the fact does not satisfy a residency obligation. Logs can reveal that data moved, but by then the violation has already occurred and may have triggered regulatory exposure. Because the requirement is that data never leaves its region, a detective-only control leaves the primary risk unaddressed and would not convince an auditor that residency is architecturally enforced.
- ✗
Use a single global endpoint and rely on contractual terms stating that data will be handled in accordance with local laws.
Why it's wrong here
Contractual language does not guarantee technical residency. A single global endpoint may route or store data across regions, and the retailer would have no architectural control over where processing occurs. Because the requirement is to prove data never leaves its region, a legal assurance without matching technical controls cannot satisfy auditors who need evidence of actual data flow boundaries.
- ✗
Encrypt all customer data with a customer-managed key before sending it to a shared multi-region inference pool.
Why it's wrong here
Encryption protects confidentiality but does not control location. Data encrypted with any key still physically resides and is processed wherever the inference pool operates, so residency is violated even though the content is unreadable. The requirement concerns where data is processed and stored, not only who can read it, so encryption alone cannot satisfy the geographic constraint.
- ✓
Deploy region-specific endpoints and storage in each geography, pin explicit model identifiers per region, and validate data flows so no cross-region replication occurs.
Why this is correct
This is correct because regional endpoints and storage keep processing and persistence within the required geography, and pinning explicit model identifiers prevents a silent upgrade from routing traffic to a model hosted elsewhere. Validating data flows closes the loop by proving no replication path exists. Together these measures give auditors concrete evidence that residency holds even during model changes.
About these practice questions
One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.