Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

An organization is deploying Claude to provide automated coding assistance. To manage the risk of generating insecure code or violating open-source licenses, which governance step is most effective?

⚠ Common exam trap

Candidates often rely solely on the model's internal safety training to prevent code vulnerabilities, forgetting that external developer workflows require active validation steps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing a mandatory 'Human-in-the-Loop' review and automated SAST scanning.

Risk management for AI-generated code requires a multi-layered approach. While the model is highly capable, it may occasionally suggest patterns that contain vulnerabilities or mimic copyrighted code. Integrating automated security scanning into the development lifecycle ensures that AI-generated artifacts meet the same standards as human-written code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disabling the model's ability to output code blocks entirely.

    Why it's wrong here

    Removing code generation capabilities would defeat the purpose of using the model for coding assistance. Governance should enable business value while mitigating risk, rather than simply blocking features. There are more nuanced ways to manage security without sacrificing the core utility of the AI tool.

  • ✓

    Implementing a mandatory 'Human-in-the-Loop' review and automated SAST scanning.

    Why this is correct

    Static Application Security Testing (SAST) tools can automatically detect vulnerabilities in the code Claude generates. Combined with human review, this ensures that any AI-driven suggestions are vetted for security flaws and license compliance before being merged into the production codebase, providing a robust governance layer.

  • ✗

    Relying on Claude's internal safety training to prevent all insecure code generation.

    Why it's wrong here

    While Claude is trained to be helpful and harmless, no model is perfect at identifying every possible security vulnerability or license nuance in real-time. Over-reliance on the model's internal guardrails without external verification creates a 'blind spot' that can lead to significant technical debt and security risks.

  • ✗

    Requiring all developers to use Claude only for writing documentation, not logic.

    Why it's wrong here

    Limiting the model to documentation is an overly restrictive policy that fails to capitalize on the efficiency gains of AI-assisted coding. Effective governance focuses on providing the right tools and checks to allow developers to use the model's full capabilities safely and responsibly.

About these practice questions

Courseiva writes every CCAR-P question from scratch — 262 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.