Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

A public-sector agency must demonstrate to an external auditor that its Claude-based citizen inquiry assistant was operated in line with its approved safety policy throughout the prior fiscal year. The agency has no centralized record of which policy text was in force, when it changed, or who approved each change. Which governance practice should the agency institute first?

⚠ Common exam trap

The trap here is reaching for technical assurance activities when the actual deficiency is the absence of an authoritative record of which policy applied and when.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish version-controlled policy documents with recorded approvals and effective dates.

Auditors reconstruct conformance by comparing what happened against the rules that were in force at the time, which requires an authoritative, dated policy history with named approvers. Version-controlled policies with effective dates supply that timeline; without it, no amount of monitoring, testing, or public communication can demonstrate year-long adherence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Establish version-controlled policy documents with recorded approvals and effective dates.

    Why this is correct

    The agency's core gap is knowing which policy was in force at any given time and who authorized it. Version control with approval records and effective dates creates that timeline, allowing the auditor to map any historical period to the exact policy text that governed it. Every other evidence request depends on this foundation being in place first.

  • ✗

    Publish a citizen-facing FAQ describing how the assistant works and what data it uses.

    Why it's wrong here

    Transparency material serves the public, not the audit trail. A FAQ does not record policy lineage or authorization, and it can drift out of date without any control noticing. It would not let the agency reconstruct which safety rules governed the assistant during any specific past period.

  • ✗

    Deploy an additional monitoring dashboard that tracks assistant uptime and query volume.

    Why it's wrong here

    Uptime and volume are service metrics that say nothing about policy adherence. Adding more operational telemetry does not tell the auditor what rules applied last year, nor who approved them, so it leaves the agency's central documentation gap completely unaddressed.

  • ✗

    Commission a penetration test of the assistant's public-facing endpoint.

    Why it's wrong here

    A penetration test examines technical security weaknesses at a point in time; it produces no record of policy versions, approvals, or effective dates. It is valuable assurance, but it cannot answer the auditor's question about whether operations conformed to the approved safety policy across the full fiscal year.

About these practice questions

Courseiva writes every CCAR-P question from scratch — 262 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.