CCAR-P Governance, Safety, and Risk Management Practice Question
A retail company's legal team discovers that several engineering squads have been calling the Anthropic API with personal API keys obtained on individual credit cards, outside the corporate agreement. Leadership wants a governance model that both eliminates this practice and preserves the ability to audit all Claude usage centrally. Which governance model best achieves this?
⚠ Common exam trap
The trap here is choosing a policy statement or a network block as the fix, when shadow AI is driven by lack of a convenient sanctioned alternative and can only be governed by providing one plus centralized logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide a centralized Anthropic Console organization with workspace-scoped API keys issued per squad, and route all usage through a corporate gateway that logs every request.
Eliminating shadow AI requires giving teams a sanctioned, easy path while removing the unmanaged one, which a centralized Console organization with workspace-scoped keys accomplishes. Central auditability then follows from routing all traffic through a corporate gateway that records every request. Policies, attestations, blanket blocks, and vendor-side monitoring either lack enforcement teeth, suppress legitimate use, or rely on attribution the vendor cannot make.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Provide a centralized Anthropic Console organization with workspace-scoped API keys issued per squad, and route all usage through a corporate gateway that logs every request.
Why this is correct
Centralizing the account under one Console organization removes the incentive and the mechanism for personal keys, because squads receive sanctioned credentials scoped to their workspace. Routing traffic through a corporate gateway produces complete, uniform logging, so leadership gains the audit visibility it asked for. The approach pairs a technical prohibition with an enabling alternative, which is what makes it durable.
- ✗
Publish a policy prohibiting personal API keys and require engineers to attest annually that they comply.
Why it's wrong here
A policy with annual attestation states the expectation but provides no technical barrier, so the same shadow usage can continue undetected between attestations. Attestation also produces no telemetry, meaning leadership still cannot see which teams are calling Claude or how much. The requirement is both elimination and central auditability, and a paper control delivers neither.
- ✗
Block outbound traffic to api.anthropic.com at the corporate firewall for all users except the platform team.
Why it's wrong here
A blanket block stops sanctioned use along with unsanctioned use and does nothing about developers working from personal networks or mobile hotspots. It also yields no audit trail of what was previously accessed. Rather than channeling usage into a governed path, this control simply pushes it further out of sight, which is the opposite of the stated goal.
- ✗
Ask Anthropic account management to monitor for personal keys belonging to company employees and report them monthly.
Why it's wrong here
Anthropic cannot reliably attribute an individual's personal API key to a particular employer, and monthly reporting is retrospective rather than preventive. Even if such a report existed, it would not create a sanctioned path for the squads to follow. Governance depends on controls the organization itself operates, not on a vendor performing attribution it has no basis to make.
About these practice questions
One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.