Courseiva

CCNA Governance Safety And Risk Management Questions

69 questions · Governance Safety And Risk Management topic · All types, answers revealed

1
MCQmedium

An organization is conducting a risk assessment for an AI application. They are concerned about 'model drift' over time. Which governance action is most appropriate to manage this risk?

A.Increase the system prompt complexity.
B.Conduct periodic evaluation against a golden dataset.
C.Switch to a different model provider immediately.
D.Automate user feedback loops for real-time retraining.
AnswerB

A golden dataset provides a consistent benchmark to measure the model's performance over time. Comparing current outputs against this baseline allows organizations to quantify drift, identify specific areas of failure, and maintain quality control. This is the most effective way to ensure long-term stability in AI production environments.

Why this answer

Model drift refers to the degradation of model performance as the environment or data distribution changes. Periodic re-evaluation against a baseline 'golden dataset' is a standard governance practice to ensure the model remains reliable. This proactive monitoring allows teams to detect performance drops, adjust system prompts, or re-train/update the model, ensuring that the AI remains safe and effective for its original intended use case.

Exam trap

Candidates often mistake model drift for a security breach or a training data issue. They focus on retraining the model immediately rather than implementing a monitoring process to detect the degradation first.

2
MCQhard

A bank is deploying a Claude agent that can call internal tools to move funds between accounts. Risk leadership wants a control that limits the blast radius if the agent is manipulated into performing unauthorized transfers. Which control best addresses this requirement?

A.Route all agent traffic through a proxy that logs every tool invocation and alerts the security operations center after transfers complete.
B.Enforce authorization and transaction limits in the downstream banking APIs the agent calls, independent of anything the model outputs.
C.Add a system prompt instructing the model to never perform transfers above a defined threshold or to accounts not previously seen.
D.Increase the model's temperature to zero so its responses become fully deterministic and cannot be manipulated.
AnswerB

This is correct because placing authorization, per-transaction caps, and velocity limits in the downstream systems means the model's output can never exceed what the API permits, regardless of manipulation. The blast radius is bounded by deterministic server-side policy rather than by model behavior, which is exactly the defense-in-depth posture risk leadership is requesting for a high-impact tool.

Why this answer

When an agent can take consequential actions, enforcement must live outside the model in the systems that hold authority. Server-side authorization, per-transaction caps, and velocity limits ensure that even a fully manipulated agent cannot exceed policy, because the downstream API rejects anything outside its rules. Prompt instructions, sampling settings, and post-hoc monitoring cannot provide that hard boundary.

Exam trap

The trap here is treating a strong system prompt or deterministic sampling as a security boundary when only the downstream authorization layer can actually enforce limits.

3
Multi-Selecthard

A security architect is performing red-teaming on a new Claude-powered application. They are specifically testing for 'jailbreaking' attempts where a user tries to bypass safety filters by using roleplay or adversarial framing. Which TWO strategies are most effective for mitigating this specific risk at the architectural level?

Select 2 answers
A.Increasing the temperature parameter to 1.0
B.Implementing a robust, immutable System Prompt
C.Reducing the max_tokens limit for all users
D.Utilizing a separate 'Safety' instance of Claude for output validation
E.Switching from Claude 3.5 Sonnet to Claude 3 Haiku
AnswersB, D

A well-defined system prompt acts as a foundational governance layer that defines the model's persona and safety constraints. By explicitly instructing the model to reject roleplay attempts that violate safety policies, architects can significantly harden the application against common jailbreaking techniques that rely on tricking the model into ignoring its rules.

Why this answer

Mitigating adversarial attacks requires a multi-layered approach that combines model-native features with external validation. Using a strong system prompt sets clear boundaries that the model prioritizes, while implementing an independent moderation layer provides a final check on outputs. These strategies ensure that even if one layer is bypassed, the overall system remains resilient against malicious intent.

Exam trap

Candidates often select client-side or prompt-only solutions, assuming standard instructions are bulletproof. They forget that jailbreaking specifically targets and bypasses text-based prompts, requiring multi-layered architectural safeguards like independent validators.

4
MCQhard

An organization is deploying Claude to provide automated coding assistance. To manage the risk of generating insecure code or violating open-source licenses, which governance step is most effective?

A.Disabling the model's ability to output code blocks entirely.
B.Implementing a mandatory 'Human-in-the-Loop' review and automated SAST scanning.
C.Relying on Claude's internal safety training to prevent all insecure code generation.
D.Requiring all developers to use Claude only for writing documentation, not logic.
AnswerB

Static Application Security Testing (SAST) tools can automatically detect vulnerabilities in the code Claude generates. Combined with human review, this ensures that any AI-driven suggestions are vetted for security flaws and license compliance before being merged into the production codebase, providing a robust governance layer.

Why this answer

Risk management for AI-generated code requires a multi-layered approach. While the model is highly capable, it may occasionally suggest patterns that contain vulnerabilities or mimic copyrighted code. Integrating automated security scanning into the development lifecycle ensures that AI-generated artifacts meet the same standards as human-written code.

Exam trap

Candidates often rely solely on the model's internal safety training to prevent code vulnerabilities, forgetting that external developer workflows require active validation steps.

5
MCQmedium

An organization is deploying a customer-facing chatbot using Claude 3.5 Sonnet and needs to ensure the model adheres to ethical guidelines without relying solely on manual moderation. Which core Anthropic safety framework is primarily responsible for the model's ability to self-correct based on a predefined set of principles during its training phase?

A.Reinforcement Learning from Human Feedback (RLHF)
B.Retrieval-Augmented Generation (RAG) Filtering
C.Constitutional AI
D.Differential Privacy Injection
AnswerC

Constitutional AI applies a specific list of rules that the model uses to evaluate its own outputs during the reinforcement learning phase. This method ensures that the model adheres to ethical guidelines and safety standards without requiring constant human oversight, making it a highly scalable and reliable solution for enterprise-grade deployments.

Why this answer

Claude's safety is built on Constitutional AI, which uses a set of principles to guide the model's self-improvement during training. This approach reduces the need for human-annotated safety data and allows for more transparent and steerable AI behavior compared to traditional RLHF. Architects must understand how this foundation impacts model responses to ambiguous or harmful prompts in enterprise production environments.

Exam trap

Candidates often confuse Constitutional AI with RLHF or fine-tuning. They miss the distinction that Constitutional AI is a specific training methodology using principles for self-correction.

6
Multi-Selectmedium

A hospital network is drafting its AI risk register for a Claude-based discharge-summary assistant. The governance lead wants entries that describe residual risk after existing controls are applied, and that can be assigned an owner and a review cadence. Which TWO characteristics must each risk register entry have to meet this standard? (Choose two.)

Select 2 answers
A.A verbatim copy of the vendor's model card and system prompt.
B.A list of every employee who has ever accessed the assistant.
C.A residual risk rating that reflects the effect of the controls already in place.
D.A projected cost saving attributed to deploying the assistant.
E.A named accountable owner and a defined review interval.
AnswersC, E

The governance lead explicitly asked for residual risk, meaning the exposure remaining after existing mitigations. Recording only inherent risk overstates exposure and misdirects investment; recording only that a control exists hides whether it is effective. A residual rating ties the register to the actual decision the network faces about accepting or further reducing exposure.

Why this answer

An operational risk register entry must state the exposure that remains after controls and must have someone accountable for watching it on a schedule. Residual rating captures what is actually at stake post-mitigation, while owner and review interval ensure the entry is revisited and acted upon as the assistant and its clinical context change.

Exam trap

The trap here is padding risk entries with supporting evidence and business-case data, which feels thorough but leaves the register without the ownership and residual-exposure statements that make it actionable.

7
MCQmedium

Which approach best aligns with the principle of 'least privilege' when providing API access to internal teams?

A.Create a single organization-wide API key for all departments to share.
B.Use separate API keys for each project with specific rate limits and usage quotas.
C.Provide all developers with unrestricted access to the master organization API key.
D.Rotate all team keys daily to ensure the highest level of security.
AnswerB

Granular, project-specific keys allow for precise control and oversight. By enforcing usage quotas and rate limits, the organization can manage costs and limit the impact of any potential security breach to a single project, directly adhering to the principle of least privilege in a production environment.

Why this answer

Least privilege is best enforced by utilizing scoped API keys and rate limits mapped to specific project requirements. By isolating access, an architect ensures that a compromise in one department does not cascade across the entire organization. This structure allows for granular monitoring and easier revocation, forming a robust foundation for organizational security and minimizing the blast radius of any potential credential leakage or misuse.

Exam trap

Candidates often choose a single shared API key for simplicity, incorrectly assuming organizational convenience overrides the security necessity of granular, project-level scoping and rate limits.

8
MCQmedium

A fintech company wants to use Claude to generate personalized financial advice for retail customers. The compliance team mandates that all AI-generated advice must be traceable to a specific model version and configuration for audit purposes. Which governance control best satisfies this requirement?

A.Implement a human review step where a compliance officer approves each piece of advice before it is sent.
B.Restrict API access to a whitelist of IP addresses and require multi-factor authentication.
C.Enable logging of all API requests and responses with model version and configuration metadata.
D.Use a single, static prompt template that never changes and is stored in version control.
AnswerC

This control directly provides an audit trail linking each piece of advice to the exact model version and configuration used. By capturing request and response data along with metadata, the company can reconstruct how any advice was generated, satisfying traceability requirements. It is the most direct and reliable method to meet the compliance mandate without altering the model's behavior.

Why this answer

The correct control is logging API requests and responses with model version and configuration metadata. This creates a detailed audit trail that links each output to the exact model version and settings used, enabling full traceability. Other options improve security or oversight but fail to provide the required technical record for auditing AI-generated financial advice.

Exam trap

The trap here is confusing security controls like IP whitelisting or human review with audit traceability, which specifically requires capturing model version and configuration in logs.

9
MCQhard

A software company's internal AI review board is defining escalation criteria for its Claude-powered support assistant. The board wants a rule that reliably routes the highest-consequence cases to human specialists rather than relying on the model's own confidence statements. Which escalation design best achieves this?

A.Route cases to specialists based on objective risk signals such as account tier, regulatory keywords, and prior complaint history.
B.Ask the assistant to flag any conversation it finds ambiguous and forward those to specialists for a second opinion.
C.Instruct the assistant to state a confidence percentage with each answer and escalate whenever it reports below ninety percent.
D.Sample five percent of all conversations at random for specialist review after the assistant has already replied.
AnswerA

Objective signals are observable before or independently of the model's output, so routing does not depend on the model judging its own reliability. High-value accounts, regulated topics, and repeat-complaint histories are exactly where errors carry the greatest consequence, making this a deterministic and auditable way to guarantee specialist review.

Why this answer

Reliable escalation must be driven by signals that exist independently of the model's self-assessment. Objective criteria such as account tier, regulatory keywords, and complaint history correlate directly with consequence and can be evaluated deterministically, guaranteeing that the cases the board cares most about reach a specialist before a reply is finalized.

Exam trap

The trap here is trusting the model's own confidence or ambiguity judgments as the routing trigger, when those signals are uncalibrated and can be high precisely when the answer is wrong.

10
MCQeasy

A public-sector agency must demonstrate to an external auditor that its Claude-based citizen inquiry assistant was operated in line with its approved safety policy throughout the prior fiscal year. The agency has no centralized record of which policy text was in force, when it changed, or who approved each change. Which governance practice should the agency institute first?

A.Establish version-controlled policy documents with recorded approvals and effective dates.
B.Publish a citizen-facing FAQ describing how the assistant works and what data it uses.
C.Deploy an additional monitoring dashboard that tracks assistant uptime and query volume.
D.Commission a penetration test of the assistant's public-facing endpoint.
AnswerA

The agency's core gap is knowing which policy was in force at any given time and who authorized it. Version control with approval records and effective dates creates that timeline, allowing the auditor to map any historical period to the exact policy text that governed it. Every other evidence request depends on this foundation being in place first.

Why this answer

Auditors reconstruct conformance by comparing what happened against the rules that were in force at the time, which requires an authoritative, dated policy history with named approvers. Version-controlled policies with effective dates supply that timeline; without it, no amount of monitoring, testing, or public communication can demonstrate year-long adherence.

Exam trap

The trap here is reaching for technical assurance activities when the actual deficiency is the absence of an authoritative record of which policy applied and when.

11
MCQmedium

An enterprise wants to minimize the risk of PII (Personally Identifiable Information) being processed by Claude while maintaining low latency. Which architectural approach provides the best balance of safety and performance?

A.Sending all data to a second LLM for PII scrubbing
B.Using a local PII detection script before the API call
C.Asking Claude to ignore all PII in the system prompt
D.Relying on the base model's default safety filters
AnswerB

A local detection script can quickly scan and redact PII before the data ever leaves the organization's controlled environment. This approach provides a high level of security by ensuring sensitive data is never sent to the API provider, while also maintaining the low latency required for production-grade applications.

Why this answer

Managing PII risk requires a proactive approach that stops sensitive data before it reaches the model. Using a local, lightweight regex or NLP-based scanner for PII detection allows for immediate filtering without the latency of a secondary LLM call. This ensures that the organization maintains its privacy standards while providing a fast, responsive experience for the end user.

Exam trap

Candidates often choose secondary LLM calls for PII detection because they assume AI is required for smart filtering, completely ignoring the severe latency penalty this introduces.

12
MCQhard

A financial services firm runs a Claude-powered agent that can call internal tools to move funds between accounts. Risk management wants a control that prevents the agent from executing a transfer above a threshold without human sign-off, and that remains effective even if the model is manipulated through injected content in a retrieved document. Which control best meets this requirement?

A.Lower the agent's temperature and restrict its tool list to a single transfer function with a fixed daily cap.
B.Enforce the threshold in the tool-execution layer so that any transfer exceeding the limit is rejected unless a human approval token is presented.
C.Add a system prompt rule stating that transfers above the threshold must be escalated to a human operator.
D.Run a second Claude instance as a reviewer that inspects each proposed transfer and vetoes suspicious ones.
AnswerB

Placing the limit in the layer that actually performs the transfer makes the control independent of model behavior, so a manipulated agent still cannot move funds above the threshold. Requiring a human approval token binds the exception to an accountable person. This is defense in depth: the model may propose, but the execution layer disposes, which is the only design that survives prompt injection.

Why this answer

When an agent can take consequential action, the authorization boundary must live outside the model, in the component that executes the action. Enforcing the threshold and requiring a human approval token at the tool layer means a manipulated model cannot exceed its authority, because the code performing the transfer refuses. Prompt rules, reviewer models, and sampling adjustments modify model behavior but cannot guarantee that a hijacked agent will decline a prohibited action.

Exam trap

The trap here is believing that a system prompt instruction or a second reviewing model constitutes an enforcement control, when only the component that executes the action can reliably refuse it.

13
Multi-Selectmedium

A large enterprise is setting up its governance framework for Anthropic API usage. Which THREE features provided by the Anthropic Console are essential for maintaining auditability and administrative control?

Select 3 answers
A.Audit Logs for API key usage and console activity
B.Direct access to the model's weight files
C.Single Sign-On (SSO) integration
D.Automatic prompt optimization for all users
E.Member roles and workspace permissions
AnswersA, C, E

Audit logs provide a detailed record of all actions taken within the console and by API keys, which is critical for security investigations and compliance audits. They allow administrators to see exactly when keys were created, used, or deleted, ensuring full accountability for the organization's AI resources.

Why this answer

Governance in an enterprise context requires tools that provide visibility into usage and restrict access to authorized personnel. Features like audit logs, SSO, and granular member roles allow administrators to track who is using the model and for what purpose. These tools are the backbone of a compliant AI strategy, ensuring that all activities are documented and secure.

Exam trap

Test-takers sometimes select operational runtime settings or prompt tuning features as governance tools, confusing general development features with administrative audit and control components.

14
MCQmedium

Refer to the exhibit. An audit of an Anthropic API configuration reveals the policy shown. What is the primary governance concern with this implementation?

A.The temperature setting is too high for professional administrative tasks.
B.The safety settings expose the organization to content moderation and liability risks.
C.The max_tokens limit is too low, restricting the capability of the system.
D.The system prompt is too generic, leading to poor model performance.
AnswerB

Disabling safety filters for harassment and hate speech ignores the responsibility to provide a safe AI environment. This exposure can lead to the generation of prohibited content, which the organization is legally responsible for, potentially resulting in severe regulatory scrutiny and damage to the corporate reputation.

Why this answer

The configuration explicitly disables core safety filters for harassment and hate speech. In an enterprise context, this creates significant legal and brand risk. Governance frameworks mandate that safety guardrails remain enabled to protect the organization from generating or facilitating harmful content.

By explicitly setting these to 'block_none', the organization bypasses essential protections that are designed to uphold safety standards and ethical AI usage requirements.

Exam trap

Candidates often focus on the 'performance' benefit of disabling filters (faster responses). They overlook that in an enterprise context, the legal and brand liability of unfiltered content is unacceptable.

15
MCQhard

Which THREE strategies are effective for managing bias in AI-driven decision-making systems?

A.Conduct regular testing using diverse datasets to identify performance disparities.
B.Implement a human-in-the-loop review for high-impact decision scenarios.
C.Audit the training data for representative balance and potential historical skew.
D.Disable all feedback loops to prevent users from influencing the model's bias.
E.Use a proprietary model that hides its reasoning to prevent users from detecting bias.
AnswerA, B, C

Regular testing against diverse benchmarks is essential for surfacing hidden biases. By measuring performance across different demographics or scenarios, the organization can identify where the model is failing to be equitable, allowing for timely adjustments and ensuring that decisions remain fair and consistent across all user groups.

Why this answer

Managing AI bias requires a combination of data-level intervention, model validation, and ongoing monitoring. Bias often originates in training data, so evaluating and cleansing datasets is a crucial first step. Continuous monitoring and testing against diverse benchmarks ensure that the model remains fair over time.

These strategies are essential for enterprise governance to ensure that automated decisions are equitable, legally compliant, and aligned with organizational values.

Exam trap

Test-takers often select only algorithmic adjustments while ignoring crucial data-level interventions and human oversight needed for a comprehensive bias management strategy.

16
MCQmedium

An organization requires strict adherence to data residency requirements for PII processed by Claude. Which strategy best ensures that customer prompts and completions remain within a specific geographic boundary while utilizing Anthropic's API?

A.Enable global load balancing across all available Anthropic regions to optimize latency.
B.Encrypt all outgoing prompts using a third-party gateway before sending to Anthropic.
C.Configure the API client to target region-specific endpoints and verify regional data residency settings.
D.Anonymize all data locally and rely on Anthropic's general model training to handle PII.
AnswerC

Targeting region-specific endpoints ensures that the API request is handled by infrastructure physically located within the required jurisdiction. When coupled with data residency settings, this architecture guarantees that neither prompts nor completions are stored in non-compliant regions, effectively addressing both processing and storage governance concerns.

Why this answer

Implementing region-specific API endpoints combined with Data Residency configurations ensures that data processing and storage occur within authorized borders. This approach is critical for regulatory compliance in jurisdictions like the EU. By limiting the scope of model interaction to regional infrastructure, architects prevent the inadvertent cross-border transfer of sensitive data, thereby aligning with global privacy governance frameworks and minimizing legal exposure for the enterprise.

Exam trap

Candidates often assume that simply 'enabling encryption' satisfies data residency. Data residency specifically requires ensuring the data physically stays within defined geographic boundaries, which requires endpoint configuration.

17
Multi-Selecthard

A fintech company's risk committee is operationalizing a governance program for Claude-powered customer support agents. They must demonstrate to regulators that model behavior changes are tracked, attributable, and reversible. Which TWO practices best satisfy this requirement? (Choose two.)

Select 2 answers
A.Route every request through a gateway that logs the full request and response payloads with the model identifier attached.
B.Enable prompt caching on all production requests so that previously validated prompts are reused verbatim.
C.Run a fixed regression suite against each candidate model version and archive the scored results before promoting it.
D.Pin production deployments to dated model identifiers and maintain a change log linking each identifier to its evaluation results.
E.Store the system prompt in a version-controlled repository and require pull-request review before it is merged.
AnswersC, D

A fixed regression suite produces comparable, dated evidence that a candidate version behaves acceptably on the scenarios the business cares about. Archiving scores before promotion creates the attributable record regulators expect and gives the team an objective basis for approving or rejecting an upgrade. Combined with pinned identifiers, it closes the loop between decision and deployed artifact.

Why this answer

Attributable, reversible model change management requires two things working together: a frozen, dated artifact in production and comparable evidence captured before promotion. Pinning to dated model identifiers supplies the frozen artifact and the rollback target, while a fixed regression suite run against each candidate supplies the before-and-after evidence. Together they let the risk committee answer what changed, who approved it, and how to undo it.

Exam trap

The trap here is assuming that logging, caching, or prompt version control constitutes model change management, when none of them actually freezes or attributes changes to the model artifact itself.

18
MCQhard

A multinational corporation is using Claude to process employee feedback surveys. The data includes sensitive personal opinions. The governance team must ensure that the AI system complies with the EU's General Data Protection Regulation (GDPR). Which control is most critical to address the 'right to explanation' requirement for automated decision-making?

A.Obtain explicit consent from all employees before processing their feedback with AI.
B.Implement a mechanism to provide a human-readable explanation of how the AI arrived at its conclusions for each individual.
C.Anonymize all employee feedback before processing to remove personal identifiers.
D.Store all data within the EU to comply with data residency requirements.
AnswerB

GDPR's right to explanation requires that individuals can obtain meaningful information about the logic involved in automated decisions. Providing a human-readable explanation for each individual directly satisfies this requirement. This control ensures transparency and accountability, which are core to GDPR compliance for automated processing.

Why this answer

The right to explanation under GDPR requires that individuals receive meaningful information about the logic of automated decisions. Implementing a mechanism to generate human-readable explanations for each individual directly fulfills this. Other controls like anonymization, consent, or data residency address different aspects of GDPR but not the specific transparency requirement.

Exam trap

The trap here is confusing other GDPR principles like consent or data residency with the right to explanation, which specifically demands transparency of automated decision logic.

19
MCQmedium

When designing an LLM application, what is the best strategy for managing 'system instructions' (system prompts) to prevent unauthorized alteration?

A.Hardcode the system prompt directly in the client-side JavaScript for speed.
B.Store the system prompt in a centralized, secured configuration service.
C.Allow users to modify the system prompt to customize their experience.
D.Use a public Git repository to store the system prompts for transparency.
AnswerB

Storing system prompts in a secure, backend configuration service keeps them out of the reach of the client, protecting them from tampering. This allows for centralized version control, auditing, and secure distribution, which are critical components of a resilient and well-governed AI application architecture in production.

Why this answer

System instructions should be stored in a secured, backend configuration service that is injected at runtime, rather than being hardcoded or exposed to the client-side. This architecture ensures that the system prompt is immutable from the user's perspective. By centralizing the storage and management of these instructions, architects provide a secure, auditable method for updating behavior without exposing the underlying logic to potential client-side manipulation or injection attacks.

Exam trap

Candidates frequently suggest embedding system prompts directly into client-side code or user-facing payloads, making them vulnerable to tampering and client extraction.

20
MCQhard

An enterprise wants to deploy an AI-powered customer service agent. What is the most important governance consideration when integrating with internal customer databases?

A.Ensure the model has write access to the database to update customer profiles.
B.Use a service account with scoped, read-only permissions to the necessary database views.
C.Store the database connection string directly in the prompt for ease of access.
D.Configure the agent to query the entire production database to ensure comprehensive answers.
AnswerB

Scoped, read-only permissions minimize risk by ensuring the AI agent can only access exactly what it needs to perform its function. This prevents unauthorized data exposure and ensures that any potential model hallucination or injection cannot result in unintended modifications to the underlying customer databases.

Why this answer

The most important consideration is implementing a robust access control layer between the AI agent and the database. The agent should only have read-only access to a strictly defined, non-sensitive subset of data. This prevents the model from inadvertently surfacing sensitive info or executing unauthorized data modifications, ensuring that the integration adheres to the principle of least privilege and maintains corporate data integrity standards.

Exam trap

Test-takers frequently select broad administrative permissions or full database access for the AI agent, failing to apply the principle of least privilege required for database integrations.

21
MCQmedium

An organization is evaluating the safety of an LLM-based agent. What is the 'Red Teaming' process in this context?

A.The process of updating the model's weights.
B.An adversarial testing methodology to find vulnerabilities.
C.The standard unit testing for API latency.
D.The automated deployment of new models.
AnswerB

Red Teaming specifically focuses on simulating adversarial behavior to probe for weaknesses in the AI's safety architecture. By proactively attempting to 'break' the model, teams can discover security flaws, prompt injection vulnerabilities, and other safety concerns before they can be exploited by real-world malicious actors.

Why this answer

Red Teaming is a structured adversarial testing approach where a dedicated team attempts to find weaknesses, bypass safety guardrails, and elicit harmful responses from an AI system. It is a vital component of the development lifecycle because it identifies edge cases and vulnerabilities that automated tests might miss. Conducting regular red teaming ensures that the system is resilient against sophisticated attacks and remains safe for production deployment.

Exam trap

Candidates often confuse Red Teaming with standard unit testing or QA processes. They assume it is about checking if the model works, rather than actively trying to break it.

22
MCQmedium

Which governance risk is most directly mitigated by using 'Versioned' model identifiers (e.g., 'claude-3-5-sonnet-20240620') instead of the generic 'claude-3-5-sonnet' alias in production?

A.The risk of exceeding the monthly API budget due to unexpected usage.
B.The risk of a 'Man-in-the-Middle' attack intercepting the API key.
C.The risk of 'Model Drift' where behavior changes unexpectedly after an update.
D.The risk of data residency violations in the US-EAST-1 region.
AnswerC

When Anthropic updates a model alias to point to a newer version, the model's nuances can change. By pinning to a specific versioned identifier, architects ensure that the model behaves exactly as it did during the testing and validation phase, maintaining consistent safety and performance.

Why this answer

Model versioning is a critical practice for ensuring the stability and predictability of AI applications. Using a specific versioned identifier prevents 'model drift', where updates to the underlying model could change its behavior, safety profile, or output format, potentially breaking production workflows or governance checks.

Exam trap

Candidates frequently confuse 'model drift' with 'latency' or 'cost'. While versioning affects consistency, its primary governance purpose is preventing unexpected behavioral changes that could break downstream application logic.

23
MCQmedium

Refer to the exhibit. An organization uses this configuration to prevent the model from continuing the conversation as the user. What is the governance benefit of this configuration?

A.It significantly reduces the total cost of the API call by limiting output length.
B.It prevents the model from generating text as the user, reducing injection risk.
C.It improves the creativity of the model by forcing it to summarize more frequently.
D.It allows the model to handle more complex logic by processing it in smaller chunks.
AnswerB

Stop sequences are a critical defense against models hallucinating further user turns. By forcing the model to stop at the 'Human:' token, the system prevents the model from generating its own prompts, which is a standard vector for prompt injection and conversation hijacking attacks in LLM applications.

Why this answer

Setting the stop sequence to 'Human:' prevents the model from generating text that mimics the user's voice, which is a common technique in jailbreaking and prompt injection. By forcing the model to stop, the organization maintains clear control over the conversational flow, ensuring that the model cannot 'speak' for the user or inadvertently generate unintended content that might mislead other systems or bypass security filters.

Exam trap

Test-takers often confuse stop sequences with content filtering or token truncation for cost management, missing their role in preventing user impersonation and jailbreaks.

24
MCQmedium

A company is using Claude to process customer feedback. They want to ensure that if a customer mentions self-harm or illegal activities, the system immediately flags this for a human moderator. Which tool is best suited for this specific governance task?

A.The 'Temperature' parameter, set to its lowest possible value.
B.An external Moderation API or a dedicated safety-tuned model layer.
C.A standard SQL database with a list of 'bad words' to block.
D.Increasing the 'max_tokens' to allow the model to explain the risks.
AnswerB

Moderation APIs are specifically built to categorize text into safety buckets like 'self-harm', 'violence', or 'hate speech'. By routing customer feedback through a moderation layer before or alongside Claude, the system can trigger immediate alerts and human reviews for any dangerous content.

Why this answer

Handling sensitive content like self-harm requires specialized safety tools that go beyond standard text classification. Anthropic and its partners provide moderation APIs and safety filters designed to detect these high-risk categories, allowing organizations to implement mandatory human intervention for critical safety events.

Exam trap

Candidates often suggest prompt engineering or 'system instructions' to handle safety. While helpful, these are insufficient for critical safety events; external moderation tools are required for reliable, auditable detection.

25
Multi-Selecthard

When conducting a risk assessment for a new Claude-based customer support bot, which TWO factors should be prioritized as 'High Risk' according to Anthropic's safety guidelines?

Select 2 answers
A.Providing automated, unreviewed medical or legal advice.
B.Generating personalized marketing copy for a retail website.
C.Summarizing publicly available news articles for internal research.
D.Automated processing of loan applications without human review.
E.Translating internal training manuals into multiple languages.
AnswersA, D

Medical and legal domains are considered high-risk because incorrect information can lead to severe personal harm or legal liability. Anthropic's safety guidelines emphasize that AI should not replace professional judgment in these areas without significant human-in-the-loop oversight and clear disclaimers to the end-user.

Why this answer

Identifying high-risk scenarios is a core part of an architect's role in safety governance. Applications that involve high-stakes decision-making or have the potential to cause physical or financial harm require more stringent guardrails, human oversight, and rigorous red-teaming compared to low-stakes creative or administrative tasks.

Exam trap

Candidates incorrectly classify creative content generation or standard administrative summarization tasks as high-risk, confusing routine utility with high-stakes automated decision-making.

26
MCQmedium

Refer to the exhibit. An architect reviews this API request log. Despite the 'Ignore all previous safety instructions' directive, Claude refuses to provide instructions for bypassing the firewall. Which safety mechanism is primarily responsible for this refusal?

A.The external Python-based regex filter applied to the API output.
B.Constitutional AI (CAI) and RLHF during the model's training phase.
C.The 'max_tokens' parameter being set to a value low enough to truncate the response.
D.A hardcoded list of forbidden words in the Anthropic Messages API gateway.
AnswerB

Constitutional AI uses a set of written principles to guide the model's behavior during training, teaching it to prioritize safety and helpfulness over following harmful user instructions. This makes the safety guardrails an intrinsic part of the model's reasoning rather than a superficial filter applied to the input.

Why this answer

Claude's resilience to prompt injection and malicious instructions is not accidental; it is the result of Anthropic's unique training methodology. This ensures that even when a user explicitly commands the model to ignore its rules, the model maintains its commitment to safety and refuses to generate harmful or illegal content.

Exam trap

Candidates often confuse runtime system prompts or input filtering mechanisms with the foundational training methods that actually instill baseline safety behaviors, choosing features instead of core training techniques.

27
MCQhard

When integrating Anthropic's API with a CI/CD pipeline for automated testing, which security practice is mandatory to avoid credential leakage?

A.Commit the API key to the Git repository, but encrypt it using the repository's encryption feature.
B.Use a dedicated secret management service to inject credentials at runtime.
C.Include the API key in the Dockerfile as an ARG so it's available during the build phase.
D.Store the API key in a plain text file on the CI/CD runner for easy access by all pipelines.
AnswerB

This method ensures that keys are never stored in the source code or build logs. By fetching the key dynamically at runtime, the application ensures that the credential remains secured within the environment, significantly reducing the risk of accidental exposure or misuse by unauthorized users or malicious actors.

Why this answer

Using a secret management service (like HashiCorp Vault or AWS Secrets Manager) to dynamically inject API keys at build time is the industry standard. Hardcoding keys or storing them in environment variables in a repository is a severe security failure. This approach ensures that secrets are never exposed in logs or version control, maintaining a tight security posture during the automated deployment of AI-powered applications.

Exam trap

Many candidates incorrectly assume storing secrets in code repository environment variables is secure, overlooking the requirement for dedicated dynamic secret management services.

28
MCQmedium

A financial services firm runs Claude-powered document review for loan applications. The CISO asks the platform team to produce evidence that every model change affecting production was reviewed and approved before deployment. Which governance mechanism most directly satisfies this requirement?

A.Enforce a change-management record that ties each production model or prompt revision to a named approver, its evaluation results, and its deployment timestamp.
B.Publish the current model version in the internal service catalog and notify stakeholders through the monthly engineering newsletter.
C.Configure automatic failover to a secondary model identifier whenever the primary model returns elevated error rates.
D.Enable verbose request logging on the Anthropic API so every prompt and completion is stored for later inspection by the security team.
AnswerA

This is correct because an auditable change-management record links the exact revision deployed to a specific accountable approver, the evaluation evidence supporting it, and when it went live. That combination is precisely what an auditor needs to demonstrate that no model change reached production without prior review, and it scales across both model identifier updates and prompt changes in the review pipeline.

Why this answer

Auditors need a traceable link between a deployed revision, the person who approved it, and the evidence that supported the decision. A change-management record that captures approver identity, evaluation results, and deployment time creates that chain, covering both model identifier updates and prompt changes. Logging, failover, and informal notification describe runtime behavior or awareness but cannot demonstrate pre-deployment authorization.

Exam trap

The trap here is assuming that comprehensive runtime logging or version visibility in a catalog is equivalent to documented pre-deployment approval by an accountable owner.

29
MCQhard

A multinational retailer operates Claude in three regions and must prove that customer data from each region never leaves that region, even during model upgrades. Which architectural approach best satisfies this requirement?

A.Enable verbose audit logging on all regions and review the logs quarterly to detect any cross-region data movement.
B.Use a single global endpoint and rely on contractual terms stating that data will be handled in accordance with local laws.
C.Encrypt all customer data with a customer-managed key before sending it to a shared multi-region inference pool.
D.Deploy region-specific endpoints and storage in each geography, pin explicit model identifiers per region, and validate data flows so no cross-region replication occurs.
AnswerD

This is correct because regional endpoints and storage keep processing and persistence within the required geography, and pinning explicit model identifiers prevents a silent upgrade from routing traffic to a model hosted elsewhere. Validating data flows closes the loop by proving no replication path exists. Together these measures give auditors concrete evidence that residency holds even during model changes.

Why this answer

Residency requires architectural enforcement: region-specific endpoints and storage keep processing local, pinned model identifiers prevent silent rerouting during upgrades, and validated data flows prove no replication occurs. Contracts, encryption, and post-hoc logging address legal assurance, confidentiality, or detection, but none of them constrain where data is actually processed and stored.

Exam trap

The trap here is treating encryption, contractual language, or audit logs as sufficient proof of data residency when only architecture determines where processing occurs.

30
Multi-Selecthard

A retail company is building a governance program for a customer-facing Claude agent that can issue refunds and update order records. The risk committee wants controls that limit the blast radius of a compromised or misbehaving agent. (Choose two.)

Select 2 answers
A.Enable verbose debug logging of every prompt and response for later forensic review.
B.Require human approval for refunds above a defined monetary threshold before the action is executed.
C.Schedule quarterly reviews of the agent's conversation transcripts to identify emerging misuse patterns.
D.Publish an acceptable use policy that prohibits employees from manipulating the agent.
E.Enforce least-privilege tool scopes so the agent can only call refund and order APIs permitted for the specific workflow, with per-action authorization checks.
AnswersB, E

Threshold-based human approval inserts a checkpoint before high-impact actions, so an agent acting on a malicious instruction cannot unilaterally move large sums. It bounds financial exposure even when the agent is fully compromised. This is a preventive control on consequence size, which is precisely what reducing blast radius requires, whereas monitoring or documentation alone would not stop the loss.

Why this answer

Blast-radius reduction requires preventive controls that bound what the agent can execute. Least-privilege tool scopes with per-action authorization shrink the callable action set, and threshold-based human approval stops high-value refunds before they happen. Logging, policy publication, and periodic transcript review are detective or administrative measures that document or discourage misuse but do not constrain the agent's real-time capabilities, so they fail the risk committee's objective.

Exam trap

The trap here is treating observability and policy artifacts as if they were preventive controls, when only mechanisms that restrict or gate the agent's actions actually reduce the maximum damage.

31
MCQmedium

Which governance model best minimizes the risk of 'shadow AI' usage within a large corporation?

A.Restrict all internet access to prevent employees from reaching AI websites.
B.Implement a centralized enterprise-approved AI service portal with clear usage policies.
C.Require employees to sign a manual waiver every time they use an unauthorized tool.
D.Trust individual departments to manage their own AI security and compliance audits.
AnswerB

A centralized portal serves as the single source of truth for approved tools and policies. By providing a secure, governed environment that meets business needs, the organization provides a legitimate alternative to shadow AI, effectively reducing the incentive for employees to bypass corporate IT policies.

Why this answer

Centralized oversight combined with a standardized, approved AI service catalog ensures that business units use vetted, secure, and compliant tools. This approach provides governance without completely stifling innovation, as teams can request new tools through a formal process. By creating a 'path of least resistance' through managed services, organizations can effectively prevent employees from using unauthorized, non-compliant tools that threaten the firm's security and data privacy posture.

Exam trap

Candidates often suggest 'blocking access' or 'firewalling'. These strategies are ineffective as they drive employees to find workarounds, whereas a service portal provides a compliant alternative.

32
MCQmedium

When deploying Claude in a production environment, an architect notices that the model occasionally generates responses that are slightly biased. What is the most appropriate governance-first approach to address this?

A.Ignore the bias as long as the model's overall accuracy remains high.
B.Switch to a smaller model version to reduce the complexity of the outputs.
C.Use a system prompt to define neutral behavior and implement bias-detection evals.
D.Manually rewrite every biased response before it reaches the end user.
AnswerC

System prompts can explicitly instruct the model to be objective and neutral. By pairing this with 'evals' (automated tests that measure bias in responses), an architect can create a feedback loop that continuously monitors and improves the model's adherence to fairness standards.

Why this answer

Bias in AI is an ongoing challenge that requires active management. A governance-first approach involves using a combination of model-native features, like system prompts, and external evaluation frameworks to measure and mitigate bias consistently across the application's lifecycle, rather than ignoring the problem.

Exam trap

Candidates often select 'retraining the model' or 'fine-tuning' as the solution. These are expensive, slow, and overkill for addressing occasional bias, which is better managed through prompt engineering and systematic monitoring.

33
MCQmedium

A global financial institution must ensure that all prompt data and model responses for their Claude 3.5 Sonnet implementation remain within the European Union to comply with strict GDPR data residency requirements. Which architecture strategy best fulfills this governance mandate?

A.Utilize regional endpoints in AWS Bedrock or GCP Vertex AI located in EU regions.
B.Enable cross-region inference to ensure high availability across global data centers.
C.Configure the standard Anthropic Console with an EU-based billing address.
D.Implement client-side encryption for all prompts using AWS KMS keys.
AnswerA

Regional endpoints in cloud provider environments guarantee that both the inference traffic and the underlying model compute operations are physically restricted to the selected geography. This architecture prevents cross-border data transfers, directly satisfying legal requirements for data sovereignty and internal compliance protocols for handling European citizen data.

Why this answer

Data residency is a critical governance requirement for enterprise deployments in regulated markets. Anthropic provides regional infrastructure through cloud partners like AWS Bedrock and GCP Vertex AI, which allows architects to pin data processing and storage to specific geographic boundaries. This ensures that sensitive information never leaves the legally required jurisdiction during the inference lifecycle.

Exam trap

Candidates often mistakenly believe they can configure data residency natively through the direct Anthropic Console, forgetting that hyperscaler integrations are required for regional pinning.

34
MCQhard

Refer to the exhibit. The model's response to the user's request is a safety violation. How should the architecture be updated to improve safety?

A.Change the model to a smaller, less capable version.
B.Implement an input-side content moderation guardrail.
C.Require the user to log in with MFA.
D.Increase the frequency of system prompt updates.
AnswerB

An input-side guardrail analyzes the user's prompt for malicious intent or prohibited content before it is processed by the model. This prevents the model from even considering a harmful request, effectively mitigating the risk of the model inadvertently generating malicious scripts or assisting in cyberattacks.

Why this answer

The exhibit shows a clear attempt to elicit malicious code, which constitutes a security risk. To improve safety, the organization must implement a content filtering service that sits between the user and the API. This layer inspects requests against a taxonomy of prohibited activities, such as cyberattacks or illegal actions, before they reach the model.

This is an essential architectural pattern for protecting against harmful inputs in enterprise AI systems.

Exam trap

Candidates often suggest updating the system prompt or retraining the model. They overlook that malicious inputs should be blocked before they ever reach the model's processing logic.

35
MCQmedium

An organization is deploying Claude for a customer support chatbot. They need to ensure that PII is not processed or stored by the model. Which approach best aligns with Anthropic’s safety governance standards?

A.Instruct the model via the system prompt to ignore PII.
B.Enable logging for all prompts to monitor PII usage.
C.Use an anonymization layer to mask PII before the API call.
D.Rely on the model's internal safety filters.
AnswerC

Preprocessing input data with an anonymization layer ensures that no identifiable information reaches the model. This architectural pattern isolates PII from the inference process, satisfying data privacy requirements. It is a highly reliable security control that operates independently of the model's internal capabilities or potential instruction-following vulnerabilities.

Why this answer

Implementing data redaction at the application layer before sending requests to the API ensures that sensitive data never enters the model's processing pipeline. This defense-in-depth strategy is crucial for regulatory compliance like GDPR or HIPAA, as it minimizes the risk of PII leakage. Organizations should always prioritize data minimization when working with LLMs to reduce the liability surface area and maintain strict control over data governance protocols.

Exam trap

Test-takers often choose post-generation filtering or rely on model prompt instructions to handle PII, failing to implement data redaction prior to the API call.

36
MCQmedium

Which governance practice is most effective for managing 'Third-Party Model Risk'?

A.Allowing free access to all models.
B.Conducting vendor due diligence and establishing SLAs.
C.Only using internal models.
D.Relying on public trust instead of contracts.
AnswerB

Vendor due diligence is the standard governance approach for managing third-party risk. It involves assessing the provider's safety practices, data handling, and reliability. Service Level Agreements (SLAs) then set clear expectations for performance, security, and support, ensuring the provider meets the needs of the enterprise's risk management framework.

Why this answer

Managing third-party model risk involves creating a clear vendor management strategy that includes rigorous due diligence, transparency requirements, and contractual guarantees regarding safety and performance. By treating AI providers as critical vendors, organizations ensure that the model provider is held accountable for their platform's safety. This allows the organization to align the provider's capabilities with their own internal risk tolerance and compliance requirements.

Exam trap

Candidates often suggest that the organization can 'fix' the third-party model. They fail to recognize that the organization's control is limited to contractual agreements and vendor oversight.

37
MCQhard

Refer to the exhibit. An application developer is testing a model endpoint. Which security control should be prioritized to prevent the specific risk demonstrated in the exhibit?

A.Increase the temperature setting to 1.0.
B.Implement prompt engineering guardrails and input validation.
C.Reduce max_tokens to 10.
D.Add a user authentication layer to the API.
AnswerB

Robust input validation filters out common injection patterns before they reach the model. Additionally, well-structured system prompts that explicitly define boundaries help the model resist manipulation. This layered security approach is essential for maintaining control over agentic workflows and preventing users from overriding core system instructions during runtime.

Why this answer

The exhibit illustrates a prompt injection attempt aimed at extracting sensitive system instructions. To mitigate this, developers should implement strict input validation and use robust system prompt design. Applying these controls is vital because prompt injection can lead to unauthorized data exposure, policy bypasses, and reputational damage.

Governance frameworks must mandate rigorous red-teaming and input sanitization to protect the integrity of the model's operational logic against adversarial inputs.

Exam trap

Candidates frequently select infrastructure scaling or network firewalls to stop prompt injections, ignoring that application-level guardrails and input validation are required.

38
MCQhard

An organization discovers that their AI application is producing biased outputs on certain demographic groups. What is the correct governance step to take first?

A.Immediately delete all historical user data.
B.Suspend the affected functionality to perform a root cause analysis.
C.Publish a press release explaining the bias.
D.Ignore the bias if the system is highly profitable.
AnswerB

Suspending the affected functionality is the responsible governance action to mitigate immediate harm. It allows the team to perform a thorough root cause analysis, identify the source of the bias, and ensure that appropriate fixes are in place before the service is resumed for the users.

Why this answer

The first step in addressing bias is to pause the specific application or feature until a root cause analysis can be performed. Continuing to use an AI that is known to exhibit bias causes ongoing harm and creates legal and reputational risk. Once the system is stabilized, the team can then perform a systematic audit, update the model instructions or data, and re-validate before moving back into a production state.

Exam trap

Candidates often rush to 're-train' the model to fix bias. They ignore the immediate need to halt the harmful output while a root cause analysis is performed.

39
MCQeasy

What is the primary role of an AI Safety Committee in an enterprise architecture?

A.To handle daily technical debugging of model latency.
B.To oversee ethical standards and risk-based governance.
C.To directly write all production system prompts.
D.To manage the cloud provider's physical data centers.
AnswerB

The primary mandate of an AI Safety Committee is to define and enforce ethical guidelines, assess risk profiles for new use cases, and ensure the deployment meets organizational safety requirements. This governance layer is essential for mitigating risks such as bias, safety violations, and regulatory non-compliance in enterprise AI.

Why this answer

An AI Safety Committee acts as the governance body responsible for overseeing the ethical and safe deployment of AI systems. This committee establishes policies, reviews high-risk use cases, and ensures compliance with legal and safety standards. Their role is critical in bridging the gap between technical implementation and organizational values, ensuring that safety is not an afterthought but a central component of the entire AI development lifecycle.

Exam trap

Candidates sometimes assume the AI Safety Committee handles code optimization or hardware procurement, rather than focusing purely on ethical oversight and governance.

40
MCQmedium

A firm is building a financial advisor chatbot. Which safety measure is most critical for preventing the model from providing unauthorized investment advice?

A.Always set temperature to 0.0 for every query.
B.Deploy a guardrail layer to filter prohibited topics.
C.Retrain the model on only financial regulations.
D.Add a disclaimer at the end of every response.
AnswerB

A guardrail layer acts as a safety gate, inspecting both input and output for prohibited topics like investment advice before they reach the user. This is a deterministic control that is far more reliable than relying solely on the model's internal prompt adherence, providing a robust safety boundary.

Why this answer

In financial contexts, providing unauthorized advice can lead to legal liability and significant user harm. Implementing a rigid system prompt that explicitly defines the model's limitations, combined with a deterministic 'guardrail' layer that checks for prohibited topics, is essential. This multi-layered approach ensures the model stays within its operational scope, protecting the firm from regulatory risk and ensuring users receive consistent, safe, and accurate information.

Exam trap

Candidates frequently assume that prompt engineering or system instructions alone are sufficient to prevent unauthorized advice. They underestimate the ease with which users can bypass these instructions through clever prompting.

41
MCQmedium

A financial services firm runs a Claude-powered loan pre-screening agent that reads applicant emails and drafts a preliminary recommendation. The firm's risk committee insists that no automated decision may be finalized without a documented human review step. Which control most directly satisfies this requirement while preserving the agent's throughput?

A.Log every model request and response to immutable storage and retain the logs for seven years.
B.Increase the model's temperature to zero and add a system prompt instructing Claude to be conservative in its recommendations.
C.Insert a mandatory human-in-the-loop approval gate before any recommendation is written back to the loan origination system.
D.Enable prompt caching on the applicant-email summarization step to reduce latency and cost per screening.
AnswerC

A human-in-the-loop gate places a person between the model's draft and the system of record, so an automated decision never becomes final without documented review. The agent still reads and drafts at machine speed, and only the last write is gated, which preserves throughput while producing the auditable review artefact the risk committee demands.

Why this answer

The risk committee's requirement is about who authorizes a decision, not how the model behaves or how well activity is recorded. Only a human-in-the-loop approval gate makes a person the final authorizing step before the recommendation reaches the loan origination system, yielding the documented review the committee expects while letting the agent handle upstream work automatically.

Exam trap

The trap here is assuming that making the model more cautious, faster, or better logged substitutes for an actual human decision point before the output is finalized.

42
MCQeasy

A software vendor is preparing for a customer security review of its Claude-powered support assistant. The customer asks how the vendor prevents the assistant from leaking one tenant's data into another tenant's conversation. Which architectural control most directly addresses this concern?

A.Add a system prompt instructing the assistant to answer only questions about the current customer.
B.Scope every retrieval query and every stored conversation to the authenticated tenant identifier, and reject requests whose tenant scope cannot be resolved.
C.Set the assistant's temperature to zero to make responses more predictable across tenants.
D.Enable Claude's extended thinking so the assistant reasons more carefully before answering.
AnswerB

Enforcing tenant scope at the data access layer ensures that only the authenticated tenant's documents can enter the context window, regardless of what the model is asked. Failing closed when scope cannot be resolved removes the ambiguous cases that typically cause leaks. Because the boundary is enforced in code the model cannot influence, it answers the customer's concern about isolation directly.

Why this answer

Cross-tenant leakage is prevented at the point where data is selected, not at the point where text is generated. Binding every retrieval and storage operation to the authenticated tenant identifier, and failing closed when that identifier is missing, guarantees that only authorized content can reach the model. Prompt instructions, extended thinking, and temperature settings alter model behavior but leave the underlying data access path unchanged.

Exam trap

The trap here is answering a data-isolation question with a model-behavior setting, when isolation is enforced by the retrieval and storage layer rather than by how the model is prompted or sampled.

43
MCQeasy

A government agency wants assurance that its Claude deployment will not be used to generate content that violates Anthropic's usage policies. Which action most directly supports ongoing policy compliance?

A.Disable all safety filters so the agency retains maximum control over what the model is allowed to output.
B.Review Anthropic's usage policies and configure the deployment so its use cases fall within permitted categories, documenting that mapping for internal review.
C.Route all requests through a third-party gateway that anonymizes the agency's identity from Anthropic.
D.Purchase the highest available usage tier so the agency's traffic is treated as a trusted enterprise workload.
AnswerB

This is correct because compliance starts with understanding the provider's usage policies and deliberately aligning the deployment's use cases to permitted categories. Documenting that mapping creates an auditable statement of intent and gives reviewers a concrete basis to confirm the agency is not operating in a prohibited area, which is the most direct and durable way to support ongoing policy compliance.

Why this answer

Policy compliance is achieved by understanding the provider's acceptable use categories, deliberately designing the deployment to stay within them, and documenting that alignment so it can be reviewed. Configuration changes, spending tier, and identity obfuscation do not alter the obligation to use the service within policy and provide no evidence of alignment.

Exam trap

The trap here is assuming that a higher commercial tier, or hiding traffic behind a gateway, grants exemption from the provider's usage policies.

44
MCQmedium

An architect needs to implement a 'Red Teaming' process for a new Claude deployment. What is the primary objective of this activity in the context of AI governance and safety?

A.To optimize the model's latency and throughput for high-volume traffic.
B.To adversarialy test the model to find safety gaps and potential for misuse.
C.To automate the generation of unit tests for the application's UI components.
D.To verify that the model's billing and usage credits are being tracked correctly.
AnswerB

The goal of Red Teaming is to simulate the behavior of a malicious actor. By intentionally trying to provoke the model into generating harmful, biased, or restricted content, architects can identify where the current guardrails are weak and strengthen them before the official launch.

Why this answer

Red Teaming is a proactive safety practice where a group of testers tries to find vulnerabilities, biases, or ways to make the model fail. This is a critical component of risk management, as it identifies potential issues before they can affect real users in a production environment.

Exam trap

Candidates confuse red teaming with standard performance benchmarking, accuracy testing, or automated unit testing of functional application code.

45
MCQhard

An enterprise architect is designing a Claude deployment where a single prompt may contain data belonging to customers in the EU, Brazil, and California. The legal team requires that each data subject's rights be honored independently and that processing purposes be documented per jurisdiction. Which architectural approach best supports this requirement?

A.Implement data classification and purpose tagging at ingestion so each record carries jurisdiction, lawful basis, and permitted processing purpose metadata that the orchestration layer enforces at prompt assembly time.
B.Route all prompts through a single global data lake so that lineage is consistent and easy to report.
C.Rely on the model provider's regional endpoints to satisfy all three jurisdictions automatically.
D.Ask business users to manually remove data from prompts when it is not needed for the current task.
AnswerA

Tagging records with jurisdiction, lawful basis, and purpose lets the orchestration layer include only data whose processing purpose matches the current request, honoring each subject's rights independently. Enforcement at prompt assembly prevents mixed-jurisdiction leakage. The other options either centralize data in ways that complicate localization or rely on manual, error-prone practices that cannot scale to per-subject obligations.

Why this answer

Honoring rights independently while documenting purpose per jurisdiction requires machine-readable metadata attached to each record and enforced during prompt assembly. Classification tags for jurisdiction, lawful basis, and permitted purpose let the orchestration layer exclude data whose purpose does not match the current request, which is the only approach here that scales and remains auditable. Centralization, endpoint selection, and manual pruning do not deliver per-subject enforcement or purpose documentation.

Exam trap

The trap here is believing that regional inference endpoints or a unified data lake solve multi-jurisdiction compliance, when the binding requirement is per-record purpose and rights enforcement.

46
MCQmedium

A media company uses Claude through the Anthropic API to draft articles. Legal counsel asks the platform team to demonstrate that every published draft can be traced to the exact model behavior that produced it, even after Anthropic deprecates older models. The team currently calls the alias claude-sonnet-4-5. Which change best satisfies counsel's requirement?

A.Increase max_tokens and set temperature to zero so outputs become deterministic.
B.Pin requests to a dated model snapshot identifier and archive the full request parameters and response with each draft.
C.Log the alias string claude-sonnet-4-5 alongside each draft in the content management system.
D.Enable prompt caching so identical requests return consistent outputs across model updates.
AnswerB

A dated snapshot identifier names an immutable model version, so a stored request can be replayed against the same behavior later instead of silently moving to a newer build. Archiving the complete request parameters and the returned response closes the loop, because it captures both the exact input and the output that was published. Together they give counsel a reproducible record that survives alias updates and routine model refreshes.

Why this answer

Traceability to a specific model behavior requires two things: an immutable model identifier and a durable record of the exact input and output. A dated snapshot pins behavior so it can be reproduced or referenced after deprecation, while archiving request parameters and responses preserves the actual interaction. Aliases, caching, and sampling settings modify cost, latency, or variance but none of them establish which model version produced a given published artifact.

Exam trap

The trap here is treating a model alias as a stable version identifier, when aliases are deliberately repointed to newer builds and therefore cannot anchor an evidentiary record.

47
MCQhard

A healthcare provider is using Claude to summarize patient clinical notes. Which governance control is most critical to prevent potential HIPAA violations?

A.Use a custom model fine-tuned on public medical journals to avoid using patient data.
B.Ensure that a Business Associate Agreement (BAA) is in place and strictly enforced.
C.Implement a strict 24-hour limit on the storage of all processed clinical summaries.
D.Anonymize all patient notes by removing names before sending them to the API.
AnswerB

The BAA is a legal requirement under HIPAA for any cloud service provider handling PHI. Without this agreement, the healthcare provider is in direct violation of the law. This is the paramount governance step, as it defines the legal responsibility and privacy safeguards that must be maintained.

Why this answer

The most critical control is ensuring that all data processed by the API is encrypted in transit and at rest, and that the organization has a Business Associate Agreement (BAA) with Anthropic. Without a BAA, the provider cannot legally process PHI. This legal framework, supported by technical encryption, is the foundational requirement for any healthcare entity utilizing cloud-based AI services to maintain regulatory compliance.

Exam trap

Candidates often focus on 'encryption' or 'prompt sanitization'. While necessary, these are technical details; the BAA is the essential legal prerequisite for handling PHI in a healthcare context.

48
MCQeasy

A fintech startup wants to use Claude to generate marketing copy that references competitor products by name and makes performance comparisons. Legal counsel asks the architect which governance step is most appropriate before this capability goes live.

A.Establish a documented review process that classifies the use case against Anthropic's Usage Policies and applicable advertising regulations before deployment.
B.Increase the model's temperature setting so the copy sounds more creative and varied.
C.Enable prompt caching to lower the cost of generating large volumes of marketing variants.
D.Add a spell-check and grammar pass to the generated marketing copy before publication.
AnswerA

Generating comparative claims about named competitors raises both usage-policy and regulatory questions, so a documented classification and review step is the right governance gate. It ensures the use case is assessed against Anthropic's policies and advertising law before any content is produced. The other measures improve output quality or performance but do not resolve the legal and policy eligibility question.

Why this answer

The scenario involves a potentially sensitive use case: comparative advertising that names competitors. Governance best practice is to classify the use case against Anthropic's usage policies and relevant advertising regulations through a documented review before deployment. Sampling parameters, proofreading, and caching affect style, quality, and cost, and none of them determine whether the activity is permitted or lawful.

Exam trap

The trap here is reaching for a technical or quality control when the actual blocker is a use-case eligibility question that must be resolved through policy review.

49
MCQhard

An insurer uses a Claude-based agent that can call internal tools to look up policy details. During review, the safety team finds that a document uploaded by a claimant contains text instructing the agent to email the full policy database to an external address. The agent has an email tool available. Which control most directly prevents this class of failure?

A.Scan uploaded documents with a classifier that flags imperative language and quarantine any document that scores above threshold.
B.Add a system prompt instruction telling the model to ignore any instructions found inside uploaded documents.
C.Require human approval for every tool invocation the agent proposes, regardless of which tool or argument is involved.
D.Enforce tool-level authorization so the agent's identity lacks permission to send external email, and constrain tool arguments to validated allowlists.
AnswerD

Removing the agent's ability to send external mail makes the injected instruction inert no matter how persuasive the document is, because the capability simply does not exist at the credential layer. Argument allowlisting further blocks misuse of tools the agent does retain, such as restricting a lookup to the current claimant's policy. This is a deterministic boundary rather than a behavioral request.

Why this answer

When untrusted content can reach a model that holds real capabilities, the reliable fix is to remove the dangerous capability from the agent's identity and constrain the arguments of the tools it keeps. Injected text can persuade a model but cannot grant permissions the credential layer denies, so an agent without external-email rights cannot exfiltrate regardless of what the document says. Detection and prompting remain useful layers but are not deterministic.

Exam trap

The trap here is treating prompt injection as a text-filtering problem, when the decisive control is limiting what the agent is authorized to do rather than what it is willing to read.

50
MCQmedium

A retail company's legal team discovers that several engineering squads have been calling the Anthropic API with personal API keys obtained on individual credit cards, outside the corporate agreement. Leadership wants a governance model that both eliminates this practice and preserves the ability to audit all Claude usage centrally. Which governance model best achieves this?

A.Provide a centralized Anthropic Console organization with workspace-scoped API keys issued per squad, and route all usage through a corporate gateway that logs every request.
B.Publish a policy prohibiting personal API keys and require engineers to attest annually that they comply.
C.Block outbound traffic to api.anthropic.com at the corporate firewall for all users except the platform team.
D.Ask Anthropic account management to monitor for personal keys belonging to company employees and report them monthly.
AnswerA

Centralizing the account under one Console organization removes the incentive and the mechanism for personal keys, because squads receive sanctioned credentials scoped to their workspace. Routing traffic through a corporate gateway produces complete, uniform logging, so leadership gains the audit visibility it asked for. The approach pairs a technical prohibition with an enabling alternative, which is what makes it durable.

Why this answer

Eliminating shadow AI requires giving teams a sanctioned, easy path while removing the unmanaged one, which a centralized Console organization with workspace-scoped keys accomplishes. Central auditability then follows from routing all traffic through a corporate gateway that records every request. Policies, attestations, blanket blocks, and vendor-side monitoring either lack enforcement teeth, suppress legitimate use, or rely on attribution the vendor cannot make.

Exam trap

The trap here is choosing a policy statement or a network block as the fix, when shadow AI is driven by lack of a convenient sanctioned alternative and can only be governed by providing one plus centralized logging.

51
MCQeasy

What is the primary risk associated with 'Prompt Injection' attacks in enterprise AI?

A.Increased latency for all users.
B.Unauthorized control of model behavior.
C.A reduction in model accuracy.
D.The model becoming permanently unavailable.
AnswerB

Prompt injection is the deliberate manipulation of the model's instructions by a user. This can lead to the model behaving in ways that contradict its original purpose, such as revealing internal data, bypassing security checks, or executing arbitrary commands, representing a significant risk to the integrity of the system.

Why this answer

Prompt injection allows attackers to override core system instructions, potentially forcing the AI to leak sensitive data, bypass safety filters, or perform unauthorized actions. This is a critical risk because it undermines the entire security model of the AI application. Enterprise systems must treat all external user input as untrusted, necessitating strong architectural controls to prevent attackers from hijacking the model's intended logic and operational behavior.

Exam trap

Candidates often focus on data leakage as the primary risk. While serious, the fundamental threat of prompt injection is the loss of control over the model's decision-making logic.

52
MCQmedium

Which document is essential for an organization to maintain when preparing for an AI audit?

A.A list of all model parameters and hyperparameters.
B.An up-to-date AI Risk Register.
C.The raw training data files for the LLM.
D.A transcript of every single user interaction.
AnswerB

An AI Risk Register is a critical document for any compliance or safety audit. It tracks potential risks, their severity, and the controls implemented to mitigate them. It serves as evidence that the organization is actively managing its AI safety profile and following best practices in governance.

Why this answer

An AI audit requires proof of governance, testing, and safety measures. An AI Risk Register, which documents identified risks, their potential impact, and the mitigation strategies in place, is essential. It provides auditors with a clear history of how the organization identifies, assesses, and manages its AI-related risks, demonstrating a mature approach to safety and compliance that satisfies both internal and external oversight requirements.

Exam trap

Candidates often confuse the AI Risk Register with technical logs or performance dashboards. They fail to realize that auditors need a high-level governance document, not just raw system data.

53
Multi-Selectmedium

An insurance company is preparing an AI risk register for its Claude-based claims triage system. The risk team must document controls that reduce the chance of biased or inconsistent decisions affecting policyholders. (Choose two.)

Select 2 answers
A.Collect aggregate throughput metrics showing how many claims the system processes per hour during peak periods.
B.Define and version the decision criteria and prompts used for triage, and re-validate them against a representative dataset whenever they change.
C.Raise the model's max_tokens setting so the triage system can produce longer, more detailed justifications for each decision.
D.Establish a human review and appeal path so affected policyholders can challenge a triage outcome and have a person re-examine the decision.
E.Switch to the largest available Claude model on the assumption that greater capability automatically eliminates biased outputs.
AnswersB, D

This is correct because bias and inconsistency often enter through drifting criteria or undocumented prompt edits. By versioning the decision logic and re-validating against a representative dataset on every change, the team can detect shifts in outcomes across demographic groups and demonstrate that the criteria were intentionally designed and reviewed, which is core evidence for a defensible risk register entry.

Why this answer

Fairness controls require both a defined, versioned decision logic that is re-validated against representative data and a human appeal path that catches harmful outcomes the model produces. Together they create a preventive and a corrective layer. Throughput, token budgets, and model size describe performance or capability, not equity, and cannot substantiate a claim that biased or inconsistent decisions have been controlled.

Exam trap

The trap here is equating a larger or more capable model, or longer outputs, with reduced bias, when fairness must be measured and governed through versioned criteria and human recourse.

54
MCQeasy

A media company wants a lightweight, recurring review of its Claude-powered content moderation assistant. The team has no dedicated compliance staff and wants the cheapest process that still produces defensible evidence of oversight. Which approach fits best?

A.Commission an annual third-party audit with formal attestation and a published report.
B.Track the volume of user complaints and treat a stable or declining trend as sufficient evidence of adequate oversight.
C.Rely on the vendor's published safety evaluations and model cards as the primary evidence of the assistant's suitability.
D.Adopt a scheduled sampling review where a rotating staff member scores a fixed sample of outputs against written criteria and records the results.
AnswerD

Periodic human sampling against documented criteria produces dated, reproducible evidence of oversight at low cost, and it can be run by existing staff with a short rubric. Recording scores and reviewer identity creates the audit trail regulators expect. This matches the requirement for a lightweight but defensible process.

Why this answer

Defensible oversight means showing that a named person reviewed outputs against written criteria on a defined schedule and recorded the outcome. Scheduled sampling achieves exactly that with minimal tooling and staffing, and the recorded scores form a durable evidence trail. Vendor documentation and complaint trends are supporting signals, not substitutes for local, documented human review.

Exam trap

The trap here is equating passive outcome metrics or vendor documentation with active oversight, when reviewers look for evidence that the deploying organization itself examined outputs against criteria.

55
Multi-Selectmedium

A security architect is configuring the Anthropic Console for a large enterprise. Which TWO features should be implemented to enforce centralized governance and reduce the risk of unauthorized account access?

Select 2 answers
A.Single Sign-On (SSO) integration via SAML 2.0.
B.Automatic rotation of all API keys every 24 hours.
C.Role-Based Access Control (RBAC) to limit 'Admin' permissions.
D.Real-time packet inspection of all API traffic.
E.Hardware Security Module (HSM) storage for all model weights.
AnswersA, C

SSO allows the enterprise to manage Anthropic access through their existing identity provider, such as Okta or Azure AD. This ensures that when an employee leaves the company, their access to the Anthropic environment is automatically revoked, significantly reducing the risk of orphaned accounts and unauthorized access.

Why this answer

Centralized governance in the Anthropic Console involves managing how users authenticate and what permissions they have. Implementing enterprise-grade access controls ensures that only authorized personnel can generate API keys or view usage metrics, which is vital for maintaining a secure and compliant AI environment.

Exam trap

Candidates mistakenly select runtime code-level configurations or model parameters when asked about enterprise-level console governance and access management controls.

56
Multi-Selecthard

An architect is defining the Shared Responsibility Model for a company deploying Claude via the Messages API. Which THREE tasks are the sole responsibility of the customer (the 'User') rather than Anthropic?

Select 3 answers
A.Classification and sanitization of PII within input prompts.
B.Physical security of the data centers housing the TPU/GPU clusters.
C.Fine-tuning the base model's Constitutional AI principles.
D.Implementing Identity and Access Management (IAM) for API key usage.
E.Monitoring model outputs for internal policy compliance and accuracy.
AnswersA, D, E

Customers are responsible for identifying and managing the sensitivity of the data they send to the model. Anthropic does not automatically know which data points constitute PII for a specific business context, so the customer must implement their own redaction or classification logic before calling the Messages API.

Why this answer

Understanding the Shared Responsibility Model is essential for risk management in AI deployments. While Anthropic secures the base model and underlying infrastructure, the customer remains responsible for the data they input, how they configure access to the API, and the specific ways the model's output is integrated into their business processes.

Exam trap

Candidates often assume that cloud providers or model vendors handle data privacy filtering and output correctness out of the box, confusing provider responsibilities with customer duties.

57
MCQhard

An enterprise is deploying Claude for high-stakes financial analysis. Which TWO governance controls should be implemented to mitigate the risk of model hallucinations and ensure factual accuracy?

A.Implement Retrieval-Augmented Generation (RAG) to ground responses in internal trusted knowledge bases.
B.Increase the temperature parameter to 1.5 to maximize response creativity.
C.Utilize a secondary model or deterministic script to validate the factual consistency of completions.
D.Require human intervention for every prompt sent to the API to guarantee zero errors.
E.Disable all safety filters to allow the model to process complex financial jargon.
AnswerA, C

RAG limits the model's knowledge scope by forcing it to answer based on provided context rather than its internal training weights. This grounding technique significantly reduces the likelihood of fabrications, ensuring that financial analyses remain consistent with internal facts and corporate data standards.

Why this answer

Mitigating hallucination risk requires a multi-layered approach involving technical constraints and validation processes. Implementing robust Retrieval-Augmented Generation (RAG) grounds the model's responses in verified source documents, while secondary verification steps add a deterministic layer to the output. These controls are essential in financial services where incorrect data can lead to severe regulatory penalties, financial loss, and significant reputational damage to the organization.

Exam trap

Candidates rely solely on increasing model parameters or prompt length to fix hallucinations, ignoring architectural solutions required for factual grounding.

58
MCQmedium

A software company is using Claude to generate code snippets for internal projects. The security team is concerned that the model might inadvertently suggest code with known vulnerabilities. Which governance control should be implemented to best mitigate this risk?

A.Require developers to manually review all AI-generated code for security issues.
B.Integrate a static application security testing (SAST) tool into the CI/CD pipeline to scan all AI-generated code before merging.
C.Restrict Claude's access to only generate code for non-critical components.
D.Fine-tune Claude on a dataset of secure code examples to reduce the likelihood of generating vulnerable code.
AnswerB

SAST tools analyze code for security vulnerabilities without executing it. Integrating SAST into the CI/CD pipeline ensures that all AI-generated code is automatically scanned before it is merged, catching issues early. This is a direct and effective control to mitigate the risk of vulnerable code being deployed.

Why this answer

Integrating SAST into the CI/CD pipeline is the most effective control because it automatically scans all AI-generated code for known vulnerabilities before merging. This provides a consistent, scalable, and early detection mechanism. Manual review and fine-tuning are helpful but less reliable, and restricting scope does not address the core risk of vulnerable code.

Exam trap

The trap here is relying on manual review or fine-tuning as primary controls, when automated SAST scanning provides a more systematic and reliable mitigation for vulnerable code.

59
MCQhard

Refer to the exhibit. Which component in this API request represents the primary governance layer for preventing model bypass of organizational policies?

A.The model version string
B.The system parameter instructions
C.The metadata object fields
D.The user role in the messages array
AnswerB

The system prompt is specifically designed to provide high-priority instructions that the model prioritizes over user messages. This architectural feature allows developers to embed safety protocols and governance rules directly into the model's context, ensuring that the AI maintains its intended persona and security posture throughout the interaction.

Why this answer

The system parameter serves as the primary governing instruction set for Claude, establishing the operational boundaries and persona before user input is processed. By defining safety constraints and behavioral rules within this field, architects can implement a foundational layer of protection that limits the model's susceptibility to certain prompt injection techniques and ensures consistent adherence to enterprise safety guidelines.

Exam trap

Test-takers frequently look for external security tools or middleware in the exhibit, overlooking the direct governance role that system parameter instructions play in framing core operational rules.

60
MCQeasy

Under the shared responsibility model for AI safety, which task is the primary responsibility of the customer when using Anthropic's APIs?

A.Conducting the base model's pre-training safety audits
B.Patching the underlying hardware infrastructure
C.Developing the Constitutional AI principles
D.Monitoring and filtering application-specific user inputs
AnswerD

Customers are responsible for the inputs they send to the model and the outputs they show to their users. Implementing application-level monitoring, moderation, and abuse detection is a critical customer responsibility to ensure the AI solution remains safe and compliant within its specific deployment context.

Why this answer

Anthropic manages the safety of the base model through training and infrastructure, but customers are responsible for how they implement the model in their specific context. This includes monitoring end-user behavior and ensuring that the application's specific use case complies with overall usage policies. Understanding this division is essential for establishing clear accountability and risk management procedures.

Exam trap

Candidates often assume the model provider is responsible for all safety. They fail to realize that the customer is responsible for filtering inputs specific to their unique application context.

61
MCQeasy

A startup is using Claude to generate marketing copy. The legal team is concerned about potential copyright infringement if the model reproduces copyrighted text. Which governance measure should the startup implement to best mitigate this risk?

A.Include a disclaimer that any resemblance to existing works is coincidental.
B.Set the model's temperature to zero to ensure deterministic outputs.
C.Use a plagiarism detection tool to scan all generated content before publication.
D.Fine-tune Claude on the startup's own proprietary content to avoid using external data.
AnswerC

A plagiarism detection tool compares generated content against a vast database of copyrighted works and can flag potential infringements. This allows the startup to review and modify problematic outputs before publication, directly mitigating the risk of reproducing copyrighted text. It is a practical and effective control for this scenario.

Why this answer

The plagiarism detection tool is the most direct mitigation because it actively checks generated content against known copyrighted works and flags potential matches. This allows human review and modification before publication. Other options either do not prevent infringement or are ineffective, such as disclaimers or temperature adjustments.

Exam trap

The trap here is assuming that technical settings like temperature or fine-tuning can prevent copyright infringement, when in fact external verification is needed.

62
Multi-Selectmedium

A company is integrating Claude into a high-stakes automated decision-making system. Which TWO practices should be implemented to align with Anthropic’s Responsible AI principles?

Select 2 answers
A.Allow the model to finalize decisions without human review.
B.Implement human-in-the-loop oversight for model outputs.
C.Establish a continuous monitoring and evaluation framework.
D.Only use the most advanced model available for all tasks.
E.Disable all system logs to preserve user privacy.
AnswersB, C

Human-in-the-loop (HITL) oversight is a foundational principle for responsible AI. By requiring humans to review and approve model outputs in high-stakes scenarios, organizations mitigate the risk of errors and ensure that decisions adhere to ethical standards and institutional policies, significantly improving the overall safety of the AI deployment.

Why this answer

Integrating LLMs into high-stakes environments requires a focus on human-in-the-loop (HITL) oversight and continuous monitoring. These practices help manage hallucinations and maintain accountability. Without these safeguards, automated systems can produce biased or incorrect outcomes without human correction.

Implementing these protocols ensures that AI governance remains aligned with human values and organizational safety goals, reducing the risk of unintended consequences in critical decision-making processes.

Exam trap

Test-takers might choose automated self-correction loops without human intervention, overlooking the mandate for human-in-the-loop oversight in high-stakes decisions.

63
MCQmedium

Refer to the exhibit. The user is attempting to trick the model into revealing sensitive information by claiming a high-clearance role. This is an example of which security threat, and how does the 'system' prompt help mitigate it?

A.Man-in-the-middle attack; the system prompt encrypts the secret code name.
B.Prompt injection (jailbreaking); the system prompt establishes a higher-priority context.
C.Denial of Service (DoS); the system prompt limits the tokens used to hide the secret.
D.Data poisoning; the system prompt cleans the training data in real-time.
AnswerB

The user is attempting a 'jailbreak' by assuming a false identity to override safety rules. The system prompt provides a separate, authoritative channel for instructions that Claude is trained to follow strictly, helping the model maintain its boundaries even when the user prompt is manipulative.

Why this answer

Social engineering and role-playing are common techniques used in prompt injection attacks to bypass security constraints. The system prompt is a powerful governance tool because it sets the foundational rules and persona for the model, which are prioritized by Claude's reasoning engine over conflicting instructions found in the user messages.

Exam trap

Candidates frequently misattribute the defense mechanism to post-processing filters or output guardrails, ignoring the structural priority given to the system prompt.

64
Multi-Selectmedium

When implementing AI safety policies, which THREE components should be included to ensure effective operationalization?

Select 3 answers
A.Clearly defined prohibited use cases.
B.Automated technical guardrails for enforcement.
C.The ability to ignore rules during testing.
D.A mechanism for user reporting and feedback.
E.Complete removal of human oversight.
AnswersA, B, D

Defining what the AI is not allowed to do is the first step in safety governance. This provides developers with clear boundaries, reducing the risk of accidental misuse and ensuring that the organization can consistently apply its ethical and compliance standards across all its AI-powered applications.

Why this answer

Operationalizing safety policy requires a combination of clear guidelines, technical enforcement, and feedback mechanisms. Without all three, policies remain abstract documents that are difficult to follow. Effective governance requires that these policies are baked into the CI/CD pipeline, audited regularly, and enforced by technical tools like guardrails, ensuring that the organization can maintain a consistent safety posture across all AI applications and development teams.

Exam trap

Candidates often pick only one of the three components, such as 'technical guardrails,' ignoring that policy requires a combination of human-centric reporting and clear definitions to be fully effective.

65
MCQmedium

What is the primary role of a 'Model Card' in the context of enterprise AI governance?

A.A list of all API keys associated with the model for billing purposes.
B.A comprehensive summary of the model's performance, limitations, and intended usage.
C.A tool for automatically deploying the model to production environments.
D.A physical card used for multi-factor authentication to access the API.
AnswerB

This is the core definition of a Model Card. It enables organizations to perform due diligence, ensuring that the model is appropriate for the proposed task and that the team understands its limitations, thereby reducing the risk of improper use and ensuring compliance with safety and governance standards.

Why this answer

Model Cards are essential documentation that provides transparency into a model's intended use, limitations, performance benchmarks, and known biases. For an enterprise architect, they serve as the technical source of truth for assessing whether a model is fit for a specific business use case. This documentation is critical for risk management, ensuring that deployments are grounded in a clear understanding of the model's capabilities and boundaries.

Exam trap

Candidates often mistake Model Cards for technical training logs or deployment scripts, missing their core purpose as a transparent summary of performance, limitations, and intended use.

66
MCQmedium

A media company uses Claude to moderate user-generated comments at high volume. The risk team wants a control that detects when the moderation model's behavior drifts, for example becoming unusually permissive or aggressive, before it affects the community at scale. Which control best fits this need?

A.Provide an appeal button so users can report comments they believe were moderated incorrectly.
B.Maintain a labeled evaluation set of representative comments and run scheduled regression tests that compare current moderation decisions against expected outcomes, alerting on threshold breaches.
C.Monitor average tokens per moderation request to detect changes in comment length.
D.Cache moderation verdicts for identical comments to reduce repeated inference costs.
AnswerB

A stable labeled evaluation set with scheduled regression runs turns drift into a measurable signal, comparing present behavior against known-good expectations. Alerts on threshold breaches catch permissiveness or aggression shifts before they spread across the community. The other options address cost, latency, or individual appeals rather than detecting systematic behavioral change over time.

Why this answer

Detecting behavioral drift requires a stable reference: a labeled evaluation set that defines expected moderation outcomes. Running scheduled regression tests against it converts drift into a measurable deviation and supports alerting before community-wide impact. Token monitoring, user appeals, and verdict caching each serve different purposes and cannot reveal systematic changes in how the model judges content.

Exam trap

The trap here is equating operational metrics or reactive user feedback with behavioral drift detection, when only repeated comparison against a fixed labeled benchmark exposes a shift in model judgment.

67
MCQmedium

A multinational bank deploys Claude to draft internal policy summaries for staff in the EU and Singapore. Legal requires that personal data embedded in employee questions never leave its region of origin, but the bank wants a single application codebase. Which architecture most directly enforces the residency requirement?

A.Enable zero data retention on the account so that no request or response content is stored by the provider.
B.Configure regional API endpoints so that EU traffic is served within the EU and Singapore traffic within its region, sharing only stateless application code.
C.Deploy the application in one region and rely on the model provider's contractual data processing addendum to cover cross-border transfer.
D.Apply client-side redaction of names and identifiers before the request is sent, then send all traffic to a single global endpoint.
AnswerB

Regional endpoints keep the request and response path inside the required geography while allowing one codebase to be deployed to multiple regions. Stateless application code carries no personal data between regions, so residency is enforced by the network topology rather than by policy language. This is the most direct technical control for the stated requirement.

Why this answer

Data residency is a geographic constraint on where processing happens, so the control must shape the request path rather than the contract or the retention window. Routing each jurisdiction to an in-region API endpoint keeps personal data inside its required boundary while a shared, stateless codebase avoids duplicated engineering effort. Redaction and retention settings reduce risk but do not guarantee the data never leaves the region.

Exam trap

The trap here is confusing data residency with data retention or with contractual transfer permissions, when only the network path actually determines where processing occurs.

68
MCQhard

A multinational insurer wants to quantify how often its Claude-based claims assistant produces outputs that violate its internal tone and fairness policy before it expands the pilot to three new countries. The compliance team needs a repeatable, statistically defensible measurement rather than anecdotal review. Which approach best meets this need?

A.Run a structured evaluation over a stratified sample of representative claims, scoring each output against a written tone-and-fairness rubric with two independent raters.
B.Review the model's system prompt and knowledge sources with legal counsel to confirm the policy language is correctly worded.
C.Monitor the assistant's average response latency and error rate in production dashboards during the pilot period.
D.Ask the pilot's ten claims adjusters to report any tone or fairness problems they notice in daily use.
AnswerA

A stratified sample drawn from representative claims produces a measurable denominator, and a written rubric applied by two independent raters yields inter-rater reliability evidence. This turns policy violations into a rate with confidence bounds, which is precisely the repeatable, statistically defensible measurement the compliance team requires before scaling.

Why this answer

Quantifying violation frequency requires a defined sample, a consistent scoring instrument, and controls for scorer bias. Stratified sampling over representative claims plus a written rubric scored by two independent raters yields a rate with reliability evidence, which is what lets compliance compare countries and justify or reject expansion on evidence rather than impressions.

Exam trap

The trap here is treating user complaints, prompt review, or system telemetry as if they produced a violation rate, when none of them establishes a sample denominator or a consistent scoring standard.

69
MCQmedium

A multinational bank runs a Claude-powered assistant that drafts internal credit memos. Auditors require the bank to prove that every generated memo can be traced to the exact human who requested it, the data sources the model retrieved, and the decision it influenced. Which governance capability should the architect implement first to satisfy this requirement?

A.Configure automatic prompt caching to reduce latency and cost for repeated credit memo templates.
B.Deploy a content moderation layer that filters sensitive financial terms before prompts are sent to Claude.
C.Enable structured audit logging that records request identity, retrieved source references, and downstream model output identifiers for each Claude invocation.
D.Set up a dashboard that tracks aggregate token consumption and monthly API spend per business unit.
AnswerC

Structured audit logging captures the requestor identity, the retrieval context, and the output reference together, producing an immutable trace that maps each memo to its origin, sources, and use. This directly satisfies the auditor's demand for end-to-end lineage, whereas the other controls improve security or quality but do not by themselves create the required evidentiary record.

Why this answer

The requirement is evidentiary lineage: for each generated memo, the bank must show the requesting human, the retrieved sources, and the output that influenced a decision. Structured audit logging is the only control that binds identity, retrieval context, and output reference into a reviewable record. Filtering, caching, and spend dashboards address confidentiality, efficiency, and cost respectively, none of which reconstruct the chain of custody auditors demand.

Exam trap

The trap here is assuming that any logging or monitoring already in place satisfies audit traceability, when only logs that correlate requestor identity, retrieved sources, and output identifiers create usable evidence.

Ready to test yourself?

Try a timed practice session using only Governance Safety And Risk Management questions.