CCAR-P Governance, Safety, and Risk Management Practice Question
A software company is using Claude to generate code snippets for internal projects. The security team is concerned that the model might inadvertently suggest code with known vulnerabilities. Which governance control should be implemented to best mitigate this risk?
⚠ Common exam trap
The trap here is relying on manual review or fine-tuning as primary controls, when automated SAST scanning provides a more systematic and reliable mitigation for vulnerable code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrate a static application security testing (SAST) tool into the CI/CD pipeline to scan all AI-generated code before merging.
Integrating SAST into the CI/CD pipeline is the most effective control because it automatically scans all AI-generated code for known vulnerabilities before merging. This provides a consistent, scalable, and early detection mechanism. Manual review and fine-tuning are helpful but less reliable, and restricting scope does not address the core risk of vulnerable code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require developers to manually review all AI-generated code for security issues.
Why it's wrong here
Manual review is important but prone to human error and may not catch subtle vulnerabilities. It is not as reliable or scalable as automated SAST scanning. While it adds a layer of oversight, it is not the best control to systematically mitigate the risk across all generated code.
- ✓
Integrate a static application security testing (SAST) tool into the CI/CD pipeline to scan all AI-generated code before merging.
Why this is correct
SAST tools analyze code for security vulnerabilities without executing it. Integrating SAST into the CI/CD pipeline ensures that all AI-generated code is automatically scanned before it is merged, catching issues early. This is a direct and effective control to mitigate the risk of vulnerable code being deployed.
- ✗
Restrict Claude's access to only generate code for non-critical components.
Why it's wrong here
Limiting scope reduces potential impact but does not mitigate the risk of vulnerable code in those components. Non-critical components can still introduce security weaknesses that might be exploited. This control is a risk reduction strategy but not as effective as directly scanning and fixing vulnerabilities.
- ✗
Fine-tune Claude on a dataset of secure code examples to reduce the likelihood of generating vulnerable code.
Why it's wrong here
Fine-tuning can influence the model's output but does not guarantee elimination of vulnerabilities. It is not a reliable control because the model may still generate insecure code in novel contexts. Additionally, fine-tuning is resource-intensive and does not provide a verification step like SAST.
About these practice questions
One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.