CClaude Cert Prep
P5 · 8 questions

Governance, Safety & Risk ManagementAttempt 3

CCAR-P P5 practice. Some items are “select all that apply” — they tell you how many to pick and are graded all-or-nothing. Commit before revealing, then read every explanation.

0 of 8 answered
  1. P5 · Q1Retrieval ACLs at the data layer
    In a multi-tenant RAG app, users occasionally see snippets from other tenants' documents. Which control most reliably enforces isolation?
  2. P5 · Q2Auditability and traceability
    After an incident, an investigator must reconstruct exactly why an agent took a specific action. Which logging design best supports this?
  3. P5 · Q3Bias/fairness and disparate-impact review
    An AI screens loan applications. Compliance asks how you would detect disparate impact. Which approach is most appropriate?
  4. P5 · Q4Responsible scaling and autonomy ceilings
    A pilot agent that suggested replies is being promoted to act autonomously across more systems. Every option looks like progress; which is the most appropriate governance step before increasing autonomy?
  5. P5 · Q5Allow/deny lists vs classifier gating
    A tool-using agent must only ever call three named internal APIs. Which control most appropriately enforces this?
  6. P5 · Q6Residual-risk acceptance and control drift
    A control register lists a nightly PII-redaction job as the control for a privacy obligation. The job silently stopped running six weeks ago but the register still shows it as active. All statements are partly true; what is the root cause of the audit finding?
  7. P5 · Q7Decision logging and auditabilitySelect 2
    A regulator may later demand proof of how automated decisions were made. Which two logging practices best support defensible auditability?
  8. P5 · Q8Tool poisoning and untrusted MCP contentSelect 2
    An agent connects to a third-party MCP server whose tool descriptions and returned data are attacker-influenced. Which two defenses most appropriately contain this threat?