Exam CCAR-P Topic 1 Question 59 Discussion
Actual exam question for Anthropic's CCAR-P exam
Question #: 59
Topic #: 1
Question #: 59
Topic #: 1
A security team is evaluating two proposed controls. Control A adds an outbound tool allow-list with destination restrictions and per-call review. Control B scores responses against a stable adversarial evaluation set after each model-version change.
Which two risk categories are correctly matched to these controls? (Select two.)
Which two risk categories are correctly matched to these controls? (Select two.)
Suggested Answer: C,E Vote an answer
Control A directly constrains the outbound action surface. An allow-list limits which tools and destinations may receive data, while per-call review introduces an approval boundary before information leaves the controlled environment. These measures therefore address data exfiltration through outbound tool calls, making Option C correct. Anthropic's security guidance recommends least privilege, narrowly scoped permissions, sandboxing, and limiting access to sensitive information and actions so that a compromised agent can cause minimal damage. Mitigate Jailbreaks and Prompt Injections Control B addresses model-version drift. Running a stable adversarial evaluation set after each version change creates a consistent comparison baseline and detects regressions that might otherwise remain invisible during routine testing. This correctly maps Control B to silent quality drift, making Option E correct. Anthropic's migration guidance repeatedly calls for workload reevaluation because instruction following, style, reasoning, and agent behavior can differ between versions. Model Migration Guide Control A may limit the consequences of successful prompt injection, but it does not prevent or directly detect adversarial instructions in retrieved content. Control B measures behavioral performance but does not impose outbound authorization controls. Each control must therefore be mapped to the risk it most directly mitigates.
Study Guide references/topics: Tool governance; least privilege; exfiltration controls; adversarial evaluations; model-change regression testing; defense in depth.
Study Guide references/topics: Tool governance; least privilege; exfiltration controls; adversarial evaluations; model-change regression testing; defense in depth.
by Allen at Aug 24, 2026, 10:27 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).