CCAR-P Governance, Safety, and Risk Management Practice Question
When designing an LLM application, what is the best strategy for managing 'system instructions' (system prompts) to prevent unauthorized alteration?
⚠ Common exam trap
Candidates frequently suggest embedding system prompts directly into client-side code or user-facing payloads, making them vulnerable to tampering and client extraction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the system prompt in a centralized, secured configuration service.
System instructions should be stored in a secured, backend configuration service that is injected at runtime, rather than being hardcoded or exposed to the client-side. This architecture ensures that the system prompt is immutable from the user's perspective. By centralizing the storage and management of these instructions, architects provide a secure, auditable method for updating behavior without exposing the underlying logic to potential client-side manipulation or injection attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hardcode the system prompt directly in the client-side JavaScript for speed.
Why it's wrong here
Hardcoding system prompts in client-side code is a major security risk. Any user can view the source code to see the instructions, making the model highly susceptible to prompt injection and unauthorized overrides. Security must always be prioritized over the slight latency gains of client-side logic.
- ✓
Store the system prompt in a centralized, secured configuration service.
Why this is correct
Storing system prompts in a secure, backend configuration service keeps them out of the reach of the client, protecting them from tampering. This allows for centralized version control, auditing, and secure distribution, which are critical components of a resilient and well-governed AI application architecture in production.
- ✗
Allow users to modify the system prompt to customize their experience.
Why it's wrong here
Allowing users to modify system prompts provides them with total control over the model's behavior, which is a massive security and safety failure. It essentially renders all safety guardrails and behavioral constraints useless, as a user could easily override them to force the model into malicious or unintended modes.
- ✗
Use a public Git repository to store the system prompts for transparency.
Why it's wrong here
Publicly exposing system prompts is not transparency; it is a security vulnerability. While open-source projects might benefit from public prompts, enterprise applications should keep their logic private to prevent adversarial exploitation. Transparency in AI should focus on model limitations and governance, not on exposing internal system-level logic.
About these practice questions
One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.