CCAR-P Advanced Agentic Architecture Practice Question
You are designing an agentic workflow that must reliably complete a multi-step refund process across an internal billing service and an external payment gateway. The workflow can fail at any step, and partial completion is unacceptable. Which two architectural mechanisms are required to guarantee that the workflow either completes fully or leaves no partial effect? (Choose two.)
⚠ Common exam trap
The trap here is reaching for latency or model-tuning knobs such as timeouts and temperature, which change timing and variability but provide no mechanism for undoing a partially committed refund.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A compensating action for each forward step, invoked in reverse order when the workflow cannot proceed to completion.
Atomicity across independent services is achieved with a saga-style pattern: a durable log that records each step's intent and outcome, plus compensating actions that undo committed steps when the workflow cannot finish. The log enables correct recovery after a crash, and the compensations unwind partial effects in reverse order. Together they make the workflow effectively all-or-nothing even though no single transaction spans both systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A compensating action for each forward step, invoked in reverse order when the workflow cannot proceed to completion.
Why this is correct
Because the two services cannot share a single transaction, atomicity must be simulated with compensation. Each forward step needs a defined inverse, such as voiding a charge when a subsequent refund fails. Invoking them in reverse order unwinds partial effects, which is what makes the workflow effectively all-or-nothing despite spanning independent systems.
- ✗
A semantic cache that stores prior successful refund transcripts and replays them on similar requests.
Why it's wrong here
Replaying a prior transcript would re-execute side effects without regard to the current workflow's actual state, which can duplicate charges or refunds. Caching addresses latency and cost, not atomicity, and a semantic cache keyed on similarity may match a request that differs in an amount or account. It provides no mechanism for detecting or undoing partial completion.
- ✗
A higher model temperature on the planner so it can explore alternative step orderings when a step fails.
Why it's wrong here
Exploration of alternative orderings does not provide atomicity and can introduce new partial effects by reordering side-effecting calls. Temperature affects generation diversity, not transactional guarantees, so it cannot ensure the workflow leaves no partial effect. It may even worsen the problem by causing the planner to skip a required compensation step in favor of an untested alternative path.
- ✓
A durable execution log that records each step's intent and outcome so the orchestrator can resume or compensate after a crash.
Why this is correct
Without a durable log, a crash between the billing-service debit and the gateway refund leaves the orchestrator with no record of what was attempted, making correct resumption impossible. The log lets the orchestrator determine which steps committed and which did not, which is the prerequisite for either continuing the workflow or running compensating actions to undo partial effects.
- ✗
A longer per-step timeout so that slow external calls are given more time to finish before the orchestrator gives up.
Why it's wrong here
Timeouts affect how long the orchestrator waits, not whether partial effects are undone. A longer timeout may reduce spurious failures, but it cannot make two independent services atomic, and a crash or hard failure still leaves partial state. Timeout tuning is a resilience knob, not an atomicity mechanism, so it does not satisfy the all-or-nothing requirement.
About these practice questions
This CCAR-P question is part of Courseiva's 262-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.