Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

A retail company is building a governance program for a customer-facing Claude agent that can issue refunds and update order records. The risk committee wants controls that limit the blast radius of a compromised or misbehaving agent. (Choose two.)

⚠ Common exam trap

The trap here is treating observability and policy artifacts as if they were preventive controls, when only mechanisms that restrict or gate the agent's actions actually reduce the maximum damage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require human approval for refunds above a defined monetary threshold before the action is executed.

Blast-radius reduction requires preventive controls that bound what the agent can execute. Least-privilege tool scopes with per-action authorization shrink the callable action set, and threshold-based human approval stops high-value refunds before they happen. Logging, policy publication, and periodic transcript review are detective or administrative measures that document or discourage misuse but do not constrain the agent's real-time capabilities, so they fail the risk committee's objective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable verbose debug logging of every prompt and response for later forensic review.

    Why it's wrong here

    Verbose logging is valuable for investigation but is detective, not preventive. It records what a compromised agent did without restricting what it can do, so refunds and record edits would still occur at full scale. Forensic evidence helps after an incident, but the risk committee asked for controls that limit the damage an agent can cause while it is misbehaving.

  • ✓

    Require human approval for refunds above a defined monetary threshold before the action is executed.

    Why this is correct

    Threshold-based human approval inserts a checkpoint before high-impact actions, so an agent acting on a malicious instruction cannot unilaterally move large sums. It bounds financial exposure even when the agent is fully compromised. This is a preventive control on consequence size, which is precisely what reducing blast radius requires, whereas monitoring or documentation alone would not stop the loss.

  • ✗

    Schedule quarterly reviews of the agent's conversation transcripts to identify emerging misuse patterns.

    Why it's wrong here

    Periodic transcript review supports trend analysis and program improvement, but it operates on a quarterly cadence and cannot contain an active incident. Between reviews, a compromised agent could issue unlimited refunds and alter orders. As a governance rhythm it complements preventive controls, yet it does not reduce the maximum impact of a single malicious or erroneous action.

  • ✗

    Publish an acceptable use policy that prohibits employees from manipulating the agent.

    Why it's wrong here

    A policy communicates expectations and supports disciplinary action, but it does not technically constrain the agent's capabilities. A malicious external user or injected instruction is unaffected by an internal policy document. Since the goal is limiting blast radius from a compromised agent, a non-enforceable policy statement cannot substitute for scoped permissions or approval gates.

  • ✓

    Enforce least-privilege tool scopes so the agent can only call refund and order APIs permitted for the specific workflow, with per-action authorization checks.

    Why this is correct

    Least-privilege tool scoping constrains what a compromised agent can actually do by shrinking the set of callable actions to those needed for the workflow. Combined with per-action authorization, a manipulated prompt cannot escalate into arbitrary refunds or record edits. This directly limits blast radius, unlike controls that only observe, filter, or document behavior after the fact.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CCAR-P question is part of Courseiva's 262-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.