Courseiva

CCAR-P Advanced Agentic Architecture Practice Question

You are architecting a Claude-based agent for a regulated financial client that performs long-running portfolio rebalancing workflows. A compliance requirement mandates that no single trade instruction may be executed unless it is cryptographically traceable to the exact model-generated intent that produced it. The agent uses the Messages API with tool use, and several downstream services consume tool calls asynchronously. Which architectural mechanism best satisfies this requirement while preserving agent autonomy?

⚠ Common exam trap

The trap here is assuming that any unique value the model or cache layer produces can serve as an audit key, when only the platform-issued tool_use id is reliably echoed through the tool_result.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Persist every assistant turn containing a tool_use block, its tool_use id, and the matching tool_result, forming an immutable audit chain keyed by the tool_use id.

Binding each tool call to the platform-generated tool_use id and persisting the surrounding assistant turn creates a deterministic chain from model intent to executed instruction. Because the id appears in both the tool_use block and the tool_result, downstream services and auditors can reconcile them without trusting model-authored text. Caching, summaries, or self-hashes do not establish that binding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require the model to emit a SHA-256 hash of its own reasoning text inside the tool input, and verify that hash in the downstream trade service before execution.

    Why it's wrong here

    Self-reported hashes are generated by the same model whose behavior is under audit, so they provide no independent guarantee and can be fabricated or inconsistent across retries. Hashing free-form reasoning also produces unstable values because tokenization and sampling vary. Without a platform-issued identifier tying the tool call to the assistant turn, the downstream service cannot actually verify provenance.

  • ✗

    Route all trades through a single orchestrator agent that logs a natural-language summary of each decision to an append-only ledger after the trade is confirmed.

    Why it's wrong here

    A post-hoc natural-language summary is not cryptographically bound to the originating model turn; it can be paraphrased, truncated, or hallucinated by the summarizer. Logging after confirmation also breaks the causal order, since the trade already executed before any record existed. This approach gives narrative auditability but not the deterministic, per-instruction traceability the regulation requires.

  • ✗

    Enable prompt caching on the system prompt so that every trade instruction inherits a stable cache key that can be presented to auditors as proof of origin.

    Why it's wrong here

    Prompt caching reduces latency and cost by reusing processed prefixes; its cache keys are an optimization detail, not an intent-binding identifier. A cache key does not uniquely tie a specific trade instruction to the model turn that produced it, and cache entries can expire or be evicted. Auditors would be unable to reconstruct which model output authorized which trade, so this fails the traceability mandate.

  • ✓

    Persist every assistant turn containing a tool_use block, its tool_use id, and the matching tool_result, forming an immutable audit chain keyed by the tool_use id.

    Why this is correct

    The tool_use id is generated by Claude and echoed back in the corresponding tool_result, so pairing them creates a verifiable link between model intent and downstream execution. Persisting the full assistant turn preserves the reasoning context around the intent, and the id becomes the cryptographic join key that compliance can replay. This satisfies traceability without constraining how many tools the agent may call.

About these practice questions

Courseiva writes every CCAR-P question from scratch — 262 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.