CCAR-P Practice Question: Stakeholder Communication and Lifecycle Management
During a pilot, a user discovers the AI can be 'prompt-injected' to reveal internal system instructions. What should be your immediate communication response?
⚠ Common exam trap
Candidates often attempt to hide the vulnerability or downplay its severity to avoid panic, which destroys stakeholder trust; transparency about the fix and testing timeline is essential.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Acknowledge the finding, explain the mitigation plan, and provide an updated timeline for testing.
Immediate, transparent, and proactive communication is the hallmark of a professional architect. By acknowledging the issue, explaining the fix (such as improved system message structure or input sanitization), and outlining the testing process, you maintain stakeholder trust. This response demonstrates that the team is on top of security and that the system is being actively hardened against threats, which is essential for maintaining project momentum during sensitive pilot phases.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Downplay the issue as a minor curiosity and claim it is common for all LLMs.
Why it's wrong here
Downplaying security vulnerabilities is irresponsible and undermines the trust of stakeholders. Prompt injection can lead to unauthorized data access and brand damage. Acknowledging the risk and presenting a clear plan to mitigate it is necessary to show that the project team takes security and compliance seriously.
- ✗
Issue an immediate apology to all users and take the system offline for a security audit.
Why it's wrong here
Taking the system offline without a clear plan is an overreaction that disrupts business and damages the project's reputation. While security is critical, the architect should assess the severity of the vulnerability and implement a measured, targeted response that balances security needs with operational availability and project continuity.
- ✓
Acknowledge the finding, explain the mitigation plan, and provide an updated timeline for testing.
Why this is correct
Transparency regarding vulnerabilities and clarity in the remediation plan are essential for maintaining stakeholder confidence. This approach shows that the team is proactive in identifying and fixing security flaws, which prevents loss of trust and ensures that the project remains on track despite the technical challenge encountered during the pilot.
- ✗
Blame the user for testing the system in a way it was not intended to be used.
Why it's wrong here
Blaming the user for finding a security vulnerability is defensive and unprofessional. The goal of a pilot is to identify such issues. The architect's responsibility is to build a robust system that can withstand varied inputs, not to criticize the users for stress-testing the application's boundaries and identifying weaknesses.
About these practice questions
This CCAR-P question is part of Courseiva's 262-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.