Rubric
Contents — domains, guide and mocks

Governance, Safety & Risk Management

CCAR-P · Domain 517 questions · 14% of the exam

Answer everything, then check. Each result links back to the lesson for the objective it came from.

0 of 17 answered0:00
  1. Question 1 · 5.1

    An insurer’s claims agent summarises documents that claimants upload. A tester uploads a PDF containing hidden text telling the agent to mark the claim as approved, and the agent calls its update_claim_status tool.

    Which change most directly addresses the root cause?

  2. Question 2 · 5.1

    A public-sector agency is building a citizen-facing assistant that searches the agency’s website and answers questions. The team wants controls against both users trying to jailbreak it and web pages that might contain injected instructions.

    Which two controls are most appropriate? (Select 2.)

  3. Question 3 · 5.1

    A team’s agent runs with permissionMode: "bypassPermissions" and allowedTools: ["Read"], believing this restricts it to reading files. What actually happens?

  4. Question 4 · 5.1

    A hospital network’s internal assistant answers staff questions from a library of clinical policies. Reviewers find it occasionally states a policy detail that is not in any document.

    Which guardrail best fits this failure?

  5. Question 5 · 5.2

    A retailer wants an assistant that answers “Is this item in stock at my local store?” The prototype answers from a product catalogue loaded into the prompt each morning.

    Which risk is most specific to this design?

  6. Question 6 · 5.2

    A bank pilots an agent that reconciles transactions and posts adjusting entries. In testing, it misread one account number at the start and then posted three entries to the wrong account, reporting success each time.

    Which failure mode does this illustrate, and what is the most fitting response?

  7. Question 7 · 5.2

    A public-sector team is reviewing a design for a benefits-enquiry assistant that reads citizens’ uploaded letters and answers questions about their case.

    Which two risks should the review flag as specific to this design? (Select 2.)

  8. Question 8 · 5.3

    A retailer’s agent can issue refunds. The system prompt says “Always confirm with a supervisor before refunds over £100,” but audits show some large refunds went through without confirmation.

    What is the best fix?

  9. Question 9 · 5.3

    A bank’s mortgage team uses Claude to assess applications. Reviewers approve 99% of recommendations, averaging 40 seconds per file, and a later audit finds several recommendations that misread income documents.

    Which two changes would most improve the human review? (Select 2.)

  10. Question 10 · 5.3

    An internal IT team deploys Claude to draft first responses to employee helpdesk tickets about password resets and software installs. Errors are easy to correct and employees can reply.

    Which human-in-the-loop strategy fits best?

  11. Question 11 · 5.3

    In the Claude Agent SDK, a team wants certain tool calls to always reach their approval callback, even if someone later runs the agent in bypassPermissions mode. Which mechanism fits?

  12. Question 12 · 5.4

    A hospital network has signed a BAA and enabled HIPAA readiness on its API organisation. Engineers want to process a backlog of 50,000 clinical notes overnight using the Message Batches API to save cost.

    What should the architect advise?

  13. Question 13 · 5.4

    A US federal agency built a successful pilot on a Claude Enterprise subscription purchased through AWS Marketplace. Production requires FedRAMP High authorisation.

    Which statement is most accurate?

  14. Question 14 · 5.4

    A French bank plans to use Claude to decide automatically whether to grant small personal loans, with no human involved. Legal asks what GDPR requires.

    Which two design responses best address GDPR? (Select 2.)

  15. Question 15 · 5.5

    A recruitment firm uses Claude to rank CVs for a shortlist. To avoid bias, the team removes the gender and date-of-birth fields before sending CVs to the model.

    What is the main weakness of this approach?

  16. Question 16 · 5.5

    A retailer launches a Claude-powered shopping assistant on its website. Marketing wants it to introduce itself as “Sam from our style team” without mentioning AI, to feel more personal.

    What should the architect advise?

  17. Question 17 · 5.5

    An insurer is preparing to launch a Claude-assisted claims triage tool. Leadership asks which activities would give credible evidence that the tool is fair.

    Which two activities provide the strongest evidence? (Select 2.)

You can change answers until you check. Nothing is saved or sent anywhere.