CCAR-P Governance, Safety, and Risk Management Practice Question
Which governance model best minimizes the risk of 'shadow AI' usage within a large corporation?
⚠ Common exam trap
Candidates often suggest 'blocking access' or 'firewalling'. These strategies are ineffective as they drive employees to find workarounds, whereas a service portal provides a compliant alternative.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a centralized enterprise-approved AI service portal with clear usage policies.
Centralized oversight combined with a standardized, approved AI service catalog ensures that business units use vetted, secure, and compliant tools. This approach provides governance without completely stifling innovation, as teams can request new tools through a formal process. By creating a 'path of least resistance' through managed services, organizations can effectively prevent employees from using unauthorized, non-compliant tools that threaten the firm's security and data privacy posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restrict all internet access to prevent employees from reaching AI websites.
Why it's wrong here
Restricting internet access is draconian and impractical for a modern workforce. It hampers productivity and drives employees to find even more obscure, unmonitored ways to access AI tools. A governance strategy should aim for enablement and control rather than complete restriction of modern connectivity.
- ✓
Implement a centralized enterprise-approved AI service portal with clear usage policies.
Why this is correct
A centralized portal serves as the single source of truth for approved tools and policies. By providing a secure, governed environment that meets business needs, the organization provides a legitimate alternative to shadow AI, effectively reducing the incentive for employees to bypass corporate IT policies.
- ✗
Require employees to sign a manual waiver every time they use an unauthorized tool.
Why it's wrong here
Manual waivers are administrative nightmares that do not mitigate the underlying security or privacy risks of shadow AI. They are reactive and ineffective, failing to prevent data leakage or regulatory non-compliance. Governance must focus on preventing the use of unauthorized tools rather than just documenting it.
- ✗
Trust individual departments to manage their own AI security and compliance audits.
Why it's wrong here
Decentralizing governance to departments often leads to inconsistent security postures and high risk. Without central oversight, departments may overlook critical safety configurations or fail to meet enterprise-wide compliance standards, leading to vulnerabilities that the entire organization is held accountable for if a breach occurs.
About these practice questions
This CCAR-P question is part of Courseiva's 262-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.