CCAR-P Governance, Safety, and Risk Management Practice Question
Exhibit
{
"model": "claude-3-5-sonnet-20240620",
"max_tokens": 1024,
"system": "You are a financial advisor. Never provide investment advice for individual stocks.",
"messages": [
{"role": "user", "content": "Should I buy AAPL today?"}
],
"metadata": {"user_id": "user_1234", "session_id": "sess_5678"}
}Refer to the exhibit. Which component in this API request represents the primary governance layer for preventing model bypass of organizational policies?
⚠ Common exam trap
Test-takers frequently look for external security tools or middleware in the exhibit, overlooking the direct governance role that system parameter instructions play in framing core operational rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The system parameter instructions
The system parameter serves as the primary governing instruction set for Claude, establishing the operational boundaries and persona before user input is processed. By defining safety constraints and behavioral rules within this field, architects can implement a foundational layer of protection that limits the model's susceptibility to certain prompt injection techniques and ensures consistent adherence to enterprise safety guidelines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The model version string
Why it's wrong here
The model version string specifies which version of Claude to invoke but does not contain any logic or instructions for safety. While newer models have improved safety features, the version string itself is not a governance mechanism but rather a resource identifier for the API request.
- ✓
The system parameter instructions
Why this is correct
The system prompt is specifically designed to provide high-priority instructions that the model prioritizes over user messages. This architectural feature allows developers to embed safety protocols and governance rules directly into the model's context, ensuring that the AI maintains its intended persona and security posture throughout the interaction.
- ✗
The metadata object fields
Why it's wrong here
Metadata tags are useful for tracking and auditing purposes but do not directly influence the model's output or provide a layer of safety against malicious inputs. While metadata is essential for usage monitoring and billing, it lacks the functional capacity to enforce behavioral constraints or prevent security breaches.
- ✗
The user role in the messages array
Why it's wrong here
The 'user' role identifies the source of the input but does not impose constraints on what the user can ask or how the model should respond. It is a structural requirement of the API rather than a governance tool for enforcing safety policies or managing organizational risk.
About these practice questions
This CCAR-P question is part of Courseiva's 262-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.