Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

A security architect is configuring the Anthropic Console for a large enterprise. Which TWO features should be implemented to enforce centralized governance and reduce the risk of unauthorized account access?

⚠ Common exam trap

Candidates mistakenly select runtime code-level configurations or model parameters when asked about enterprise-level console governance and access management controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Single Sign-On (SSO) integration via SAML 2.0.

Centralized governance in the Anthropic Console involves managing how users authenticate and what permissions they have. Implementing enterprise-grade access controls ensures that only authorized personnel can generate API keys or view usage metrics, which is vital for maintaining a secure and compliant AI environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Single Sign-On (SSO) integration via SAML 2.0.

    Why this is correct

    SSO allows the enterprise to manage Anthropic access through their existing identity provider, such as Okta or Microsoft Entra ID. This ensures that when an employee leaves the company, their access to the Anthropic environment is automatically revoked, significantly reducing the risk of orphaned accounts and unauthorized access.

  • ✗

    Automatic rotation of all API keys every 24 hours.

    Why it's wrong here

    While frequent rotation is a security best practice, the Anthropic Console does not natively provide an automated 24-hour rotation service for all keys. This would typically need to be implemented by the customer using external secrets management tools like AWS Secrets Manager or HashiCorp Vault.

  • ✓

    Role-Based Access Control (RBAC) to limit 'Admin' permissions.

    Why this is correct

    RBAC allows organizations to assign specific roles like 'Member' or 'Admin' to different users. By following the principle of least privilege, an architect can ensure that only a small number of trusted users can modify billing settings or create new workspaces, while developers are limited to API usage.

  • ✗

    Real-time packet inspection of all API traffic.

    Why it's wrong here

    Packet inspection is a network-level security measure that is not a feature of the Anthropic Console. This type of monitoring would occur at the corporate firewall or proxy level. The Console focuses on identity and resource management rather than inspecting the contents of the HTTPS traffic.

  • ✗

    Hardware Security Module (HSM) storage for all model weights.

    Why it's wrong here

    Model weights are part of Anthropic's core intellectual property and infrastructure, managed entirely by Anthropic. Customers do not have access to these weights and cannot configure HSM storage for them through the Console; this is outside the scope of customer-facing governance features.

About these practice questions

One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.