Practice — CCAO-F Domain 6: Governance, Risk, and Responsible Use (15%)
13 scenario-based MCQs. Answer key + explanations at the bottom.
Q1
An operations coordinator wants Claude to draft renewal-outreach emails from a spreadsheet containing customer names, personal email addresses, and account numbers. The company's AI policy classifies this data as restricted and permits it only in the organization's managed Claude workspace, but the coordinator only has a personal claude.ai account available today. Which approach best complies with the policy?
A. Paste the spreadsheet into the personal account, then delete the conversation as soon as the drafts are finished B. Paste only the rows for customers who have already opted in to receiving marketing communications C. Request access to the managed workspace, or anonymize the restricted fields before pasting anything D. Proceed in the personal account, since Claude's safety training prevents it from misusing customer data
Q2
In Anthropic's AI Fluency 4D framework, which competency covers being transparent about AI involvement, staying accountable for what you ship, and using AI in ways consistent with your obligations and values?
A. Description B. Discernment C. Delegation D. Diligence
Q3
A marketing manager used Claude to produce the first draft of a client-facing market analysis, then substantially edited and fact-checked it. The client's contract requires disclosure of AI use in deliverables. What is the manager's best course of action?
A. Disclose the AI assistance and stand behind the final content as their own work B. Skip the disclosure, because the substantial human edits made it the manager's original work C. Add a disclaimer that the analysis was AI-generated and the firm cannot vouch for its accuracy D. Redo the analysis without Claude so the disclosure requirement no longer applies to the deliverable
Q4
An HR director, impressed by Claude's resume-screening summaries, proposes letting Claude autonomously reject the bottom half of applicants for each role with no human review. Under responsible-use principles, what is the strongest objection?
A. Claude's context window cannot hold enough resumes at once to rank a full applicant pool fairly B. Consequential decisions about people need human review; Claude should inform screening, not decide it C. Resume screening is technical work that must first be escalated to Developers or Architects D. Claude is trained to refuse hiring-related tasks, so the automated workflow will not run
Q5
During a lunch-and-learn, four teammates each offer a rule of thumb for handling sensitive data in claude.ai. Which statement reflects correct practice?
A. "Deleting the conversation right after you get your answer undoes any policy problem with what you pasted." B. "Once we're on the company's enterprise plan, no data classification checks are needed before pasting." C. "Claude refuses to process personal data, so an accidental paste of PII is self-correcting." D. "Check the data's sensitivity classification against our AI policy before it goes into any conversation."
Q6
A consultant uses Claude for two tasks: (1) brainstorming names for an internal workshop, and (2) drafting a compliance summary that will be filed with a regulator. According to the Delegation–Diligence loop, how should her approach differ between the two?
A. Task 2 warrants narrower delegation and heavier review, because stakes determine what she must verify and own B. Task 1 warrants the heavier review, because open-ended creative output is where hallucinations concentrate C. Both tasks warrant identical review, because accountability applies equally to every piece of AI output D. Task 2 should not involve Claude at all, because regulated documents fall outside acceptable use
Q7
A team lead is trying Claude Cowork for the first time and wants it to clean up the team's shared drive — renaming, merging, and deleting years of accumulated files. Which rollout best follows Cowork safety guidance?
A. Grant full write access immediately, but watch the session live so any mistakes can be caught B. Grant full write access and rely on the drive's trash folder to restore anything deleted by mistake C. Start with reversible tasks — a proposed plan, work on copies — before granting write access to originals D. Decline to use Cowork for this job, since agents should never modify shared team resources
Q8
An operations analyst writes a Cowork skill that formats the team's weekly metrics report. It worked on the one report she tested. She wants to package it into a plugin for the whole department today. What is the most important step before she shares it?
A. Rewrite the skill's instructions so they also cover the monthly and quarterly report variants B. Run it on several representative real reports and review the outputs before packaging it C. Ask IT to rebuild the skill as an MCP server so it can be centrally version-controlled first D. Add a global instruction telling Claude to double-check its own work whenever this skill runs
Q9
A colleague asks what "Constitutional AI" means in Anthropic's safety approach. Which description is accurate?
A. A training method where the model critiques and revises its own outputs against written principles B. A legal review board at Anthropic that approves categories of model responses before release C. A runtime filter that checks each claude.ai response against national constitutional law D. A policy file users upload to each Project to constrain what Claude is allowed to answer
Q10
A project manager wants to attach the Gmail connector so Claude can triage an inbox that includes confidential HR complaints. IT has not yet reviewed connectors under the company's AI policy. Which approach is most appropriate?
A. Connect Gmail now, since connectors follow a permission-first pattern that makes them compliant by design B. Hold off, confirm with IT that the use is permitted under the AI policy, then grant only the access needed C. Skip the connector and paste the complaint emails into the chat manually until IT completes its review D. Connect Gmail through a personal claude.ai account so the company workspace never touches the data
Q11
Which of the following tasks is the MOST appropriate delegation to Claude?
A. Sending Claude-drafted replies to customer complaints automatically, with no one reading them first B. Making final medical-leave eligibility determinations directly from employee files C. Signing off on a regulatory filing based solely on Claude's compliance check of the document D. Producing first-draft summaries of internal meeting notes that the owner reviews before sharing
Q12
An analyst shipped a Claude-drafted market report to a client; a week later the client finds a fabricated statistic in it. In the retrospective, which conclusion correctly assigns responsibility?
A. Responsibility lies with the model vendor, because hallucination is a known product defect B. Responsibility is shared with the client, who should have verified the figures independently C. The analyst is accountable for what shipped; verification of factual claims must happen before release D. No one is at fault, because fabricated-but-plausible output is an unavoidable property of generative AI
Q13
A consultant added Client A's confidential pricing sheet to her Cowork global instructions so it would be "always available." She now uses the same account for tasks on Client B's engagement. What is the primary governance problem?
A. Global instructions reset between Cowork sessions, so the pricing data will silently disappear mid-engagement B. The pricing sheet consumes context and will slow down Client B's tasks, though it poses no confidentiality risk C. Claude will detect the conflict of interest in its standing context and refuse to run tasks for Client B D. Standing context is carried into every task, so Client A's confidential data enters Client B's work; scope it to a Client A project
Answers
Q1: C. The policy names an approved surface for restricted data, so the compliant moves are to use that surface or remove the restricted fields (anonymize) before anything is pasted. (A) is the delete-fixes-it misconception — the disclosure happened the moment the data was pasted. (B) confuses marketing consent with the data's sensitivity classification, which still forbids the personal account. (D) confuses model safety training with organizational data-handling policy; they are unrelated controls.
Q2: D. Diligence is the 4D pillar covering transparency about AI involvement, accountability for what you ship, and use consistent with your obligations — the exam blueprint maps Domain 6 to it directly. Discernment (B) is the tempting runner-up but covers evaluating output quality, not responsibility and disclosure. Description (A) is communicating the task; Delegation (C) is deciding what work to hand off.
Q3: A. Transparency diligence means disclosing AI involvement when obligations require it, while deployment diligence means owning the shipped content — do both. (B) fails because the disclosure duty comes from the contract, not from how much editing occurred. (C) discloses but abdicates accountability, which the human retains regardless of who drafted. (D) is avoidance overkill: the obligation is to disclose, not to abstain.
Q4: B. High-stakes, consequential decisions about people demand human-in-the-loop review — Claude can summarize and inform, but the decision must stay human (high stakes → narrower delegation, heavier diligence). (A) objects at the wrong layer: even if capacity sufficed, autonomous rejection would still be inappropriate. (C) misapplies the escalate-to-developers pattern, which is for technical builds, not governance calls. (D) invents a refusal behavior Claude does not have.
Q5: D. Data-sensitivity classification against the org's AI policy happens before data enters a conversation — that is the whole control. (A) is the delete-after misconception; exposure occurs at paste time. (B) confuses plan tier with policy: enterprise plans change terms, not your duty to classify. (C) wrongly delegates your privacy obligations to the model's behavior.
Q6: A. The Delegation–Diligence loop scales oversight with stakes: what you hand off determines what you must verify and own, so the regulator-facing document gets narrower delegation and heavier review. (C) is the runner-up — accountability does apply to both, but treating a workshop-name brainstorm and a regulatory filing identically ignores that the loop explicitly calibrates diligence to stakes. (B) inverts the risk. (D) over-restricts; regulated work needs heavier diligence, not a ban.
Q7: C. Cowork guidance is to start with reversible tasks — drafts, copies, summaries, proposed plans — before granting write access to originals. (A) is the runner-up: live supervision still lets an irreversible deletion happen faster than a human can intervene. (B) relies on recovery after harm rather than preventing it, and trash retention is not guaranteed for merges/renames. (D) over-corrects; file work is exactly what Cowork is for once access is staged responsibly.
Q8: B. The documented practice is to validate a skill on representative real tasks and review outputs before packaging it into a plugin, because a flawed skill inside a plugin scales the flaw across everyone who trusts it implicitly. (A) expands scope before the existing scope is validated. (C) is wrong-layer escalation — no custom technical build is needed to validate a Cowork skill. (D) substitutes a vague self-check for human review of real outputs.
Q9: A. Constitutional AI is a training technique: the model critiques and revises its own responses against a written constitution of principles, and those pairs feed RLAIF training. (B), (C), and (D) all relocate the constitution to the wrong place — an organizational board, a runtime filter, or a user-uploaded file — when it is baked in during training.
Q10: B. Operating within the org's AI policy comes first: confirm the use is permitted, then follow the permission-first pattern by granting only the specific surface needed. (A) confuses the permission-first mechanism (explicit, per-surface grants) with policy approval — the UI asking you is not IT allowing you. (C) is the runner-up trap: manual pasting exposes the same confidential data through a different path. (D) makes it worse by moving sensitive data outside organizational visibility entirely.
Q11: D. Low-stakes internal drafting with a human reviewing before anything is shared keeps the human in the loop and matches "review before you rely." (A) removes review from external-facing output. (B) and (C) delegate consequential determinations — eligibility decisions and regulatory sign-off — that must remain human judgments with Claude at most assisting.
Q12: C. Deployment diligence: the human who ships the work is accountable for it, and the corrective action is pre-release verification of factual claims against sources — hallucination is a known failure mode you must plan for. (A) and (B) push accountability to the vendor or the client; neither shipped the report. (D) treats a manageable, well-documented risk as an excuse — hallucination being possible is precisely why review is mandatory, not why no one is at fault.
Q13: D. Global instructions are standing context carried into every task, so Client A's confidential material now flows into Client B's engagement — a confidentiality breach. The fix is a scoped project, which bundles files and instructions for one initiative only. (A) is factually wrong: standing context persists, which is exactly the problem. (B) notes a real but secondary cost while denying the actual risk. (C) invents a conflict-detection refusal Claude does not perform.