CCAR-P - Stakeholder Communication & Lifecycle Management (14% of the exam) - Section 6.2

Communicate architectural decisions and trade-offs.

Explaining a design choice and what it gives up to technical and non-technical audiences, including security, legal and executive stakeholders. Candidates should choose the framing that lets each audience make the decision it owns.

trade-off communicationaudience-appropriate framingdecision records

Practice question for this objective

Free sampleStakeholder Communication & Lifecycle Managementmedium

A regional health service's referral triage agent currently suggests appointment slots that a scheduler then books by hand, which adds a median of two days to each referral. The product owner wants the agent to book directly in the patient scheduling system. The security review board owns the decision to grant any automated write access to patient systems, and must formally accept whatever residual risk it approves. What should the architect present to the board?

  • AThe two-day reduction and the scheduler hours it saves, since the board mainly needs to see that the benefit justifies the new access
  • BA system prompt rule forbidding the agent to cancel or move bookings, so the board can approve broad write access as negligible risk
  • CThe exact write actions requested, which records they can change, the controls scoping them and the residual risk, beside the two-day gain Correct
  • DBroad write access with monitoring that alerts on unusual booking patterns, so the board can approve the monitoring plan in its place
Frame a capability decision for a security audience as specific access, enforced scoping and residual risk, so the board can make the acceptance decision it owns. A security review board is accountable for accepting risk, so it needs to see the blast radius of the requested capability and the structural controls that bound it, not only the business benefit. Spelling out the exact write actions, the patient records they touch, the scoped credential and any human checkpoint, and then naming the residual risk, turns an open-ended request into a decision the board can make knowingly, with the two-day gain shown as the reason for taking it.

Why A is wrong: This is tempting because the benefit is the reason for the change and every approval needs a business case. It is wrong because the board owns a risk decision, and a benefit-only framing gives it nothing about what the agent could change or how that is constrained, so it cannot knowingly accept the residual risk.

Why B is wrong: This is tempting because the instruction does describe the intended limit in plain language. It is wrong because a prompt instruction is not an enforced control on a compliance-relevant write path; the credential would still permit cancellations, so presenting the risk as negligible misstates what the board is accepting.

Why C is correct: Correct. A security board decides by weighing blast radius against benefit. Stating the specific actions, the records within reach, the structural controls such as a credential scoped to booking only, and the risk that remains lets the board make the acceptance decision it owns, with the clinical benefit shown alongside.

Why D is wrong: This is tempting because monitoring is a familiar control that security teams often ask for. It is wrong because alerting detects misuse after the fact instead of removing capability the agent does not need, and asking the board to approve monitoring in place of the access question hides the decision it actually owns.

See more CCAR-P practice questions, answers explained.

Exam traps in Stakeholder Communication & Lifecycle Management

Answers that look right on this material and are not. Each one is a distractor from a different question in the CCAR-P bank for this domain.

  • A recommendation for the larger tier only, since clinical quality outweighs cost, so the committee is not distracted by a weaker option

    Why it is wrong: This is tempting because the larger tier halves the correction rate and patient safety feels like it should settle the matter. It is wrong because the committee owns the budget and the acceptable correction workload, and presenting one option with its costs hidden takes that decision away from the people who are accountable for it.

  • A recorded walkthrough video of the final architecture, so new IT staff can see how each component fits together without reading code

    Why it is wrong: This is tempting because onboarding new staff is a real problem in a district with high turnover. It is wrong because a walkthrough shows what was built, not why the alternatives were rejected or when to reconsider, so it would not have prevented last year's unnecessary rebuild.

  • The caseworker rubric was too lenient, so letters that breach agency policy still scored well in evaluation

    Why it is wrong: Tempting because a weak rubric is a real way for problems to slip through to launch. It is wrong because the blocker concerns retaining source material, not letter quality, and no quality rubric can test a requirement nobody gathered.

Examworthy is not affiliated with or endorsed by Anthropic. Original, blueprint-aligned practice material only.