CCAR-P Practice Question: Stakeholder Communication and Lifecycle Management
A stakeholder demands that your team integrate Anthropic models into a sensitive financial system. How do you address the 'data privacy' concern?
⚠ Common exam trap
Candidates often provide generic assurances about security without referencing specific documentation, missing that formal data encryption and retention policies are required for compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide documentation on data encryption, retention, and compliance.
Addressing privacy concerns requires explaining the data security architecture, including data processing, storage, and retention policies. The architect must demonstrate that the implementation aligns with enterprise security standards. This is essential because stakeholder trust is the foundation of any deployment involving sensitive data; without clear documentation and assurance regarding privacy, the project will likely be blocked or experience significant delays during the security review phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Claim that privacy is guaranteed by Anthropic and no further action is needed.
Why it's wrong here
Relying on external guarantees without verifying internal implementation is a dereliction of duty. The architect must define how data is handled within the application perimeter. Blindly trusting third-party assurances without reviewing specific data flow controls is an unacceptable risk management strategy for sensitive financial systems and data environments.
- ✓
Provide documentation on data encryption, retention, and compliance.
Why this is correct
Supplying detailed, factual documentation on how data is encrypted, processed, and deleted provides the objective evidence stakeholders need to conduct a risk assessment. This transparency is the primary mechanism for building trust and ensuring the application passes compliance gates, which is essential for successful adoption in regulated industries.
- ✗
Ask them to sign a waiver saying they take responsibility for data leaks.
Why it's wrong here
Attempting to shift liability through waivers is unprofessional and does not mitigate the technical risk of data leakage. The architect is responsible for designing a secure system, not for delegating risk to the stakeholder. This approach will quickly destroy the professional relationship and likely lead to project termination.
- ✗
Agree to use the data for model training to improve performance.
Why it's wrong here
Using sensitive financial data for model training is a major privacy risk and often violates data governance policies. The architect must ensure that no sensitive data is used in a way that risks exposure. Proposing this as a solution demonstrates a dangerous lack of awareness regarding standard data privacy protocols.
About these practice questions
This CCAR-P question is part of Courseiva's 262-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.