CCAR-P Governance, Safety, and Risk Management Practice Question
What is the primary risk associated with 'Prompt Injection' attacks in enterprise AI?
⚠ Common exam trap
Candidates often focus on data leakage as the primary risk. While serious, the fundamental threat of prompt injection is the loss of control over the model's decision-making logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unauthorized control of model behavior.
Prompt injection allows attackers to override core system instructions, potentially forcing the AI to leak sensitive data, bypass safety filters, or perform unauthorized actions. This is a critical risk because it undermines the entire security model of the AI application. Enterprise systems must treat all external user input as untrusted, necessitating strong architectural controls to prevent attackers from hijacking the model's intended logic and operational behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increased latency for all users.
Why it's wrong here
Prompt injection is a security vulnerability, not a performance issue. While an injection attack might cause the model to perform complex tasks, the core risk is the loss of control and potential for unauthorized activity, not the latency impact on the system's overall response time.
- ✓
Unauthorized control of model behavior.
Why this is correct
Prompt injection is the deliberate manipulation of the model's instructions by a user. This can lead to the model behaving in ways that contradict its original purpose, such as revealing internal data, bypassing security checks, or executing arbitrary commands, representing a significant risk to the integrity of the system.
- ✗
A reduction in model accuracy.
Why it's wrong here
Accuracy issues are typically related to training data or model drift. Prompt injection is a specific type of adversarial attack that targets the instruction-following capabilities of the model. While it may result in incorrect output, the root cause is a security failure, not a lack of general model capability.
- ✗
The model becoming permanently unavailable.
Why it's wrong here
Prompt injection does not typically crash the service or make it permanently unavailable. It is a logical exploit that changes how the model processes input, not a denial-of-service attack that targets the underlying infrastructure or availability of the API endpoint itself.
About these practice questions
One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.