Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

An enterprise wants to minimize the risk of PII (Personally Identifiable Information) being processed by Claude while maintaining low latency. Which architectural approach provides the best balance of safety and performance?

⚠ Common exam trap

Candidates often choose secondary LLM calls for PII detection because they assume AI is required for smart filtering, completely ignoring the severe latency penalty this introduces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using a local PII detection script before the API call

Managing PII risk requires a proactive approach that stops sensitive data before it reaches the model. Using a local, lightweight regex or NLP-based scanner for PII detection allows for immediate filtering without the latency of a secondary LLM call. This ensures that the organization maintains its privacy standards while providing a fast, responsive experience for the end user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sending all data to a second LLM for PII scrubbing

    Why it's wrong here

    While effective, using a second LLM to scrub data adds significant latency and cost to every request. For high-volume enterprise applications, this approach may not be performant enough, and it still involves sending potentially sensitive PII to a cloud-based service before it can be effectively neutralized.

  • ✓

    Using a local PII detection script before the API call

    Why this is correct

    A local detection script can quickly scan and redact PII before the data ever leaves the organization's controlled environment. This approach provides a high level of security by ensuring sensitive data is never sent to the API provider, while also maintaining the low latency required for production-grade applications.

  • ✗

    Asking Claude to ignore all PII in the system prompt

    Why it's wrong here

    Instructing the model to ignore PII is unreliable because the sensitive data has already been transmitted to the API. This does not fulfill data residency or privacy requirements that mandate PII should not be processed by third-party systems, and the model may still inadvertently leak the information.

  • ✗

    Relying on the base model's default safety filters

    Why it's wrong here

    Default safety filters are designed to block harmful or illegal content but are not specifically tuned to detect and redact every piece of PII relevant to a specific enterprise. Relying solely on these filters is insufficient for meeting strict data privacy regulations like GDPR or HIPAA.

About these practice questions

One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.