Courseiva

CCAR-P Practice Question: Stakeholder Communication and Lifecycle Management

Your team is deploying an application that uses PII in prompts. A stakeholder asks how you are mitigating the risk of data leakage. How do you respond?

⚠ Common exam trap

Candidates often suggest 'just encrypting' the data, which ignores the need for PII masking and sanitization before the data ever reaches the model's context window.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Explain the use of PII masking and data sanitization pipelines.

The correct response involves explaining a combination of data sanitization, prompt masking, and secure infrastructure design. This is critical because PII handling is a high-liability area. By detailing a defense-in-depth strategy, the architect provides the necessary assurance that privacy is treated with the highest priority, which is vital for maintaining organizational compliance and preventing severe legal or reputational damage during the application's lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assure them that the model is smart enough to handle PII.

    Why it's wrong here

    Trusting a model to 'handle' PII autonomously is a massive, irresponsible risk. The architect must proactively implement controls to prevent PII from reaching the model or to ensure it is handled according to strict privacy policies. This answer shows a complete lack of understanding of data privacy requirements for LLMs.

  • ✓

    Explain the use of PII masking and data sanitization pipelines.

    Why this is correct

    Describing concrete architectural controls like masking or sanitization provides the stakeholder with confidence that privacy is actively managed. These techniques are standard for protecting sensitive information in LLM pipelines. This approach demonstrates a professional, risk-aware mindset that is expected of a certified architect managing complex AI deployments.

  • ✗

    Tell them the model does not store any data anyway.

    Why it's wrong here

    This response is misleading and fails to address the risk of data exposure during inference. Even if data isn't permanently stored, it is still transmitted and processed. Focusing only on storage ignores the critical risks involved in the transit and processing of data, which is where many leaks occur.

  • ✗

    Suggest moving the project to an on-premise LLM to ensure security.

    Why it's wrong here

    Moving to on-premise infrastructure is a major strategic change that may not be feasible or necessary. The architect should first address the security controls for the current implementation. Proposing this as a knee-jerk reaction avoids the actual problem and likely introduces significant new costs and deployment complexities.

About these practice questions

One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.