Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

A software company is using Claude to generate code snippets for internal projects. The security team is concerned that the model might inadvertently suggest code with known vulnerabilities. Which governance control should be implemented to best mitigate this risk?

⚠ Common exam trap

The trap here is relying on manual review or fine-tuning as primary controls, when automated SAST scanning provides a more systematic and reliable mitigation for vulnerable code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Integrate a static application security testing (SAST) tool into the CI/CD pipeline to scan all AI-generated code before merging.

Integrating SAST into the CI/CD pipeline is the most effective control because it automatically scans all AI-generated code for known vulnerabilities before merging. This provides a consistent, scalable, and early detection mechanism. Manual review and fine-tuning are helpful but less reliable, and restricting scope does not address the core risk of vulnerable code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require developers to manually review all AI-generated code for security issues.

    Why it's wrong here

    Manual review is important but prone to human error and may not catch subtle vulnerabilities. It is not as reliable or scalable as automated SAST scanning. While it adds a layer of oversight, it is not the best control to systematically mitigate the risk across all generated code.

  • ✓

    Integrate a static application security testing (SAST) tool into the CI/CD pipeline to scan all AI-generated code before merging.

    Why this is correct

    SAST tools analyze code for security vulnerabilities without executing it. Integrating SAST into the CI/CD pipeline ensures that all AI-generated code is automatically scanned before it is merged, catching issues early. This is a direct and effective control to mitigate the risk of vulnerable code being deployed.

  • ✗

    Restrict Claude's access to only generate code for non-critical components.

    Why it's wrong here

    Limiting scope reduces potential impact but does not mitigate the risk of vulnerable code in those components. Non-critical components can still introduce security weaknesses that might be exploited. This control is a risk reduction strategy but not as effective as directly scanning and fixing vulnerabilities.

  • ✗

    Fine-tune Claude on a dataset of secure code examples to reduce the likelihood of generating vulnerable code.

    Why it's wrong here

    Fine-tuning can influence the model's output but does not guarantee elimination of vulnerabilities. It is not a reliable control because the model may still generate insecure code in novel contexts. Additionally, fine-tuning is resource-intensive and does not provide a verification step like SAST.

About these practice questions

One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.