Courseiva

CCAR-P Practice Question: Stakeholder Communication and Lifecycle Management

A product owner asks you to add a feature that lets internal users upload customer contracts so Claude can extract renewal dates and auto-populate a CRM. During intake you learn the contracts contain personally identifiable information and commercially sensitive terms. The product owner wants to launch in three weeks with no legal review. As the architect, what is the most appropriate action?

⚠ Common exam trap

The trap here is choosing between blind speed and total refusal, when the correct professional response is to surface the compliance risk and propose a scoped, reviewed path to delivery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the data flows and PII exposure, engage legal and security for a review, and propose a phased launch where extraction runs only on redacted or approved contract types first.

When a requested feature involves PII and sensitive commercial terms, the architect's role is to make the risk visible and enable a compliant path rather than to either block or bypass review. Documenting data flows, engaging legal and security, and scoping an initial launch to approved contract types satisfies the product owner's delivery goal while ensuring regulated data is handled under proper controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Document the data flows and PII exposure, engage legal and security for a review, and propose a phased launch where extraction runs only on redacted or approved contract types first.

    Why this is correct

    This action respects both the business goal and the compliance obligations the scenario surfaces. Documenting data flows gives reviewers what they need, and a phased approach limited to approved contract types lets the product owner deliver value sooner without exposing regulated data prematurely. It balances delivery pressure with the non-negotiable need for legal and security sign-off on PII handling.

  • ✗

    Agree to the three-week timeline but process all contract text through an external public model endpoint to reduce internal infrastructure work.

    Why it's wrong here

    Routing sensitive contracts through a public endpoint outside your approved data-processing agreement introduces legal and security exposure that no timeline justifies. It also contradicts the need for a documented review of PII handling. This choice trades compliance risk for speed in a way that would likely fail an internal audit and could breach customer contracts governing confidential information.

  • ✗

    Launch on schedule and add a note in the backlog to complete the privacy review after the first month of production usage once real data volumes are known.

    Why it's wrong here

    Deferring privacy review until after production exposure inverts the risk model: once PII has flowed through the system, remediation cannot undo the exposure. It also undermines the compliance posture and stakeholder trust if discovered later. Real data volumes are not a prerequisite for understanding data flows and obtaining approval; that work should happen before any production launch.

  • ✗

    Reject the feature outright because contracts always contain sensitive data and no AI system should ever be used for extraction tasks.

    Why it's wrong here

    A blanket refusal ignores that many contract extraction workflows are legitimate and can be made compliant with redaction, access controls, and approved endpoints. It also fails the stakeholder by not exploring a safe path forward. Architects are expected to enable responsible use, not to treat every sensitive-data scenario as categorically prohibited, which would stall valuable business initiatives.

About these practice questions

Courseiva writes every CCAR-P question from scratch — 262 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.