Weekend Special - 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: discactive

Anthropic CCAR-P Claude Certified Architect - Professional Exam Practice Test

Page: 1 / 13
Total 129 questions

Claude Certified Architect - Professional Questions and Answers

Question 1

You are designing a human-in-the-loop validation workflow for a new Claude-based deployment and must complete the design steps before piloting the workflow.

Which two steps must be completed BEFORE piloting the workflow with a representative subset of traffic? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Define the sampling strategy and the escalation criteria at each oversight point in the pipeline.

B.

Iterate the workflow design based on observed pilot findings before broader rollout to production.

C.

Onboard the reviewer pool with role-specific training on the check criteria and escalation procedures.

D.

Document the workflow with check criteria, escalation paths, and service-level agreements (SLAs) for each step.

E.

Identify the decision points in the pipeline that require human oversight by impact and reversibility.

Question 2

You are building an ethics-review checklist for deployments supported by artificial intelligence.

Which two checks belong on the list? (Select two.)

Each correct answer presents a complete solution.

Options:

A.

Confirm that vendor licensing terms permit the planned production use of the model.

B.

Verify that outputs do not rely on generalizations about people that the underlying data does not support.

C.

Confirm that high-impact decisions retain human accountability rather than being attributed to the model.

D.

Restrict ethics review to outputs that exceed a defined model-confidence threshold.

E.

Confirm that latency and throughput targets are met across supported user populations.

Question 3

You are sequencing decomposed components in an invoice-processing pipeline.

For each of the decomposed components, select the execution layer it belongs to: “Pre-Processing,” “Model Stage,” or “Post-Processing.”

Question # 3

Options:

Question 4

You are integrating AI-assisted tooling into the team’s documentation workflow. The team wants generated documentation that stays grounded in the actual code.

Which integration approach best fits this requirement?

Options:

A.

Generate documentation from the model’s training-data recall without reading any of the actual repository code, accepting that the output will not reflect the current implementation.

B.

Have the subagents publish generated documentation directly to the public-facing site without passing through the team’s normal review workflow or any human approval step.

C.

Configure subagents that read the relevant code files via filesystem and code-search tools, generate the documentation, and emit changes through the team’s normal review workflow.

D.

Disable all filesystem and code-search tools so the subagents cannot read any repository code, accepting that documentation generation will be entirely disconnected from the actual implementation.

Question 5

A Claude architect observes that after a recent model-version upgrade, grounded responses began including claims not supported by the retrieved source documents.

Which mitigation is most directly targeted at this failure mode?

Options:

A.

Constrain responses to source-supported content, require citations, and add a verification step.

B.

Score each new model version against a stable adversarial evaluation set.

C.

Replace the shared API key with per-user OAuth tokens to restrict data access.

D.

Treat retrieved data as untrusted and apply input classifiers at ingestion time.

Question 6

You are selecting the documentation set that should accompany a Claude-based deployment at handoff. Which set is most complete?

Options:

A.

Architecture overview, ADRs, component-level diagrams, runbooks for common operations, an on-call playbook, and a list of known limitations.

B.

Code comments scattered across individual source files with no integrating architecture overview, no ADRs, no runbooks, and no on-call playbook to orient operators or new team members.

C.

A single one-page architecture diagram with no ADRs, no runbooks, no on-call playbook, and no list of known limitations to support operators or future maintainers.

D.

A verbal handover walkthrough conducted on the day of transition, with no written architecture overview, ADRs, runbooks, playbook, or known limitations captured for future reference.

Question 7

You are designing the prompt for a ticket-triage classifier with thirty well-defined categories and clear category descriptions in the prompt.

Which technique is most appropriate as the starting point?

Options:

A.

A chain-of-thought prompt for a routing decision that does not require multi-step reasoning.

B.

A zero-shot prompt that specifies the categories with their descriptions and the required output format.

C.

A prompt that demands the model invent new categories when the supplied ones do not fit.

D.

A prompt with no category descriptions, expecting the model to infer the category set.

Question 8

You are compiling factors that should drive the choice between Model Context Protocol (MCP), direct API integration, and agent-to-agent handoff.

Which two factors belong on the list? (Select two.)

Each correct answer presents a complete solution.

Options:

A.

Whether the vendor publishes detailed reference documentation for each candidate protocol.

B.

Whether the team has prior implementation experience with any of the candidate protocols.

C.

Whether the underlying transport supports encryption in transit between the integrated services.

D.

Whether the integration must be portable across multiple AI clients in the ecosystem.

E.

Whether the interaction is stateless and latency-sensitive or stateful and longer-running.

Question 9

You are supporting a team whose Claude Code sessions consistently load 60 or more MCP tools from many servers, exhausting context budget before the session begins.

Which adjustment most directly addresses this issue without removing capability?

Options:

A.

Enable Tool Search so tool definitions are deferred and discovered on demand rather than loaded into context upfront.

B.

Disable every MCP server in the configuration to free up context budget, accepting that the team loses all tool access and cannot perform any MCP-dependent task in the session.

C.

Increase the prompt’s verbosity with additional instructions and context, which consumes more of the context budget rather than reducing the tool-definition overhead causing the issue.

D.

Add additional MCP servers to give the team more capability, which increases rather than reduces the number of tool definitions loaded into the session’s context budget.

Question 10

A solutions architect is analyzing stakeholder feedback collected after the first quarter of a Claude-powered procurement automation deployment. The feedback includes four statements: (1) “Our procurement team is processing 3x more purchase orders per analyst per day.” (2) “We have eliminated the manual data entry role entirely and redeployed those staff to vendor relationship management.” (3) “The API integration costs are running 40% over the projected per-transaction budget.” (4) “Response latency during end-of-month batch runs is averaging 11 seconds, against our committed 5-second SLA.”

Which of the following correctly identifies the primary business value pillar each stakeholder statement represents?

Options:

A.

Statement 1: Efficiency; Statement 2: Transformation; Statement 3: Solution Cost; Statement 4: Performance SLA

B.

Statement 1: Productivity; Statement 2: Efficiency; Statement 3: Solution Cost; Statement 4: Performance SLA

C.

Statement 1: Transformation; Statement 2: Productivity; Statement 3: Solution Cost; Statement 4: Efficiency

D.

Statement 1: Efficiency; Statement 2: Productivity; Statement 3: Performance SLA; Statement 4: Solution Cost

Question 11

A pilot AI assistant for procurement specialists shows 89 percent first-response acceptance, but follow-up surveys reveal that specialists frequently override the assistant’s vendor recommendations after considering criteria the assistant did not evaluate. The pilot owner wants to ship the assistant unchanged because of the strong acceptance rate.

Which two Discernment-competency observations should you raise BEFORE approving the launch? (Select two.)

Options:

A.

The acceptance rate alone proves readiness for general production use.

B.

The survey response rate may not be statistically representative of all specialists.

C.

The unconsidered criteria represent a scope gap in the assistant’s input space.

D.

Acceptance does not establish whether recommendations remain correct after specialist review.

E.

The pilot duration was probably too short to demonstrate reliability across the full year.

Question 12

You are a platform architect designing an internal Claude-based assistant that serves both finance analysts and external auditors. Each population must access only documents permitted by its role.

Where should role-based access control be enforced in the pipeline?

Options:

A.

Inside the system prompt as a natural-language instruction for Claude to ignore unauthorized documents.

B.

At the retrieval layer, before any role-restricted content reaches the prompt-construction step or the model.

C.

Nowhere in the pipeline; rely on the model’s general refusal behavior to reject unauthorized document access without any enforced access control.

D.

After the response is generated, by post-filtering content that should not have been retrieved.

Question 13

You are identifying inefficiency in a Claude Code workflow where each engineer manually re-explains the project ' s conventions and architecture in every session.

Which adjustment most directly removes this inefficiency?

Options:

A.

Forbid the use of Claude Code on the project entirely to avoid the session-initialization overhead, accepting that the team loses all AI-assisted development productivity for this codebase.

B.

Capture the project ' s conventions and architecture in a project-scoped CLAUDE.md (or equivalent persistent project-context file) committed to the repository, so each session loads it automatically.

C.

Tell each engineer to retype the project conventions and architecture context more quickly at the start of each session, reducing time lost without eliminating the repeated manual effort.

D.

Remove all documented project conventions and architectural standards so engineers have nothing to re-explain at session start, accepting the loss of consistency and shared coding standards.

Question 14

An operations engineer reports that a Claude-based pipeline began returning malformed JSON responses after a scheduled maintenance window, causing downstream processing failures.

Which two investigative steps most directly isolate the root cause? (Select two.)

Options:

A.

Clear the prompt cache and resubmit all pending requests to eliminate stale cached prefixes.

B.

Compare the current system prompt and output schema configuration against the last known good version from before the maintenance window.

C.

Switch to a different Claude model tier to rule out provider-side changes as a contributing factor.

D.

Increase the max_tokens limit to determine whether output truncation is causing incomplete JSON structures.

E.

Replay a set of premaintenance requests against the current configuration and inspect the raw model output before downstream parsing.

Question 15

You are configuring tool permissions for a Claude-based assistant. The assistant’s defined responsibilities require read access to a knowledge base and write access to a draft queue, and nothing else.

Which scoping design best applies least privilege?

Options:

A.

Allow access to all tools with read permissions globally and restrict write permissions to the draft-queue tool, without scoping to only the specific tools required for defined tasks.

B.

Per-role allow-list of exactly the read-knowledge-base and write-draft-queue tools, enforced at the orchestration layer.

C.

Allow access to every tool in the catalog and rely on the model to decline tools it should not use.

D.

Disable all tools entirely to achieve a minimal permission surface, accepting that the assistant can no longer perform the read-knowledge-base or write-draft-queue tasks it was designed for.

Question 16

You are supporting an engineer whose Claude Code session reports a permission denial when the engineer expected the action to be allowed.

Which resolution step is most appropriate?

Options:

A.

Tell the engineer to retry the denied action verbatim repeatedly until the denial stops appearing, without inspecting the active permission rules to determine whether the denial is intentional.

B.

Disable the permission system entirely across all scopes to remove the denial, eliminating all tool-pattern and deny-rule controls rather than identifying and amending the specific rule.

C.

Inspect the active permission rules across all scopes—managed, command-line, local, project, and user—to identify which rule is denying the action and confirm whether it should be amended or remain denied.

D.

Grant the engineer unrestricted Bash access to bypass the specific rule causing the denial, removing all tool-pattern constraints rather than amending only the rule in question.

Question 17

A technical team is cataloging risks specific to Claude’s use in a document-grounded Q & A system.

Which two items represent failure modes that are intrinsic to LLM-based systems rather than generic software defects? (Select two.)

Options:

A.

The model refuses a legitimate query because surface features trigger an overly broad safety pattern.

B.

The model generates a plausible-sounding answer that is unsupported by any retrieved document.

C.

An expired TLS certificate blocks outbound API calls to the Claude endpoint.

D.

A misconfigured load balancer routes requests to a deprecated API version.

E.

A database connection timeout causes a retrieval call to return an empty result set.

Question 18

A Claude architect is configuring a shared Claude Code environment for a twelve-person development team.

Which two configuration decisions most directly establish a consistent, secure team environment? (Select two.)

Options:

A.

Commit shared MCP server definitions and tool permissions in project-scope configuration files alongside the repository.

B.

Apply managed configuration to enforce non-overridable security and compliance policies across all team members.

C.

Set editor theme and display preferences at the project scope so they are uniform across workstations.

D.

Instruct each engineer to configure their preferred Claude model in personal user-scope settings.

E.

Store the team’s shared API key in the project-scope settings.json so all engineers use the same credential.

Question 19

A Claude architect is auditing configuration scope assignments.

Which two statements correctly identify an appropriate use of user-scope configuration versus other scopes? (Select two.)

Options:

A.

Persisting personal editor theme preferences that follow an engineer across projects.

B.

Saving a preferred Claude response language that applies to all repositories the engineer uses.

C.

Enforcing a company-wide policy that disables a feature for all engineers.

D.

Defining MCP server endpoints shared by all contributors to a specific repository.

E.

Storing API authentication keys so they are not committed to version control.

Question 20

You are choosing the level of detail for an implementation guide. The audience is a delivery team that will build the deployment.

Which guidance composition best serves them?

Options:

A.

Component responsibilities, contracts between components, sequence diagrams of the dominant flows, configuration parameters with defaults, and operational runbooks.

B.

Component responsibilities and interface contracts only, without sequence diagrams of the dominant flows, configuration parameters with defaults, or runbooks to guide operational tasks.

C.

An architecture overview and sequence diagrams for the dominant flows, without interface contracts, configuration-parameter tables, or operational runbooks for the delivery team to follow.

D.

An architecture overview and a list of known limitations, without component-level diagrams, interface contracts, configuration parameters, or operational runbooks to support implementation.

Question 21

You are preparing an operational runbook for a Claude-based service.

Which content is essential to include in the runbook?

Options:

A.

Dashboard and log references only, without alert definitions, triage steps, escalation paths, or rollback procedures for the on-call engineer to act on.

B.

Common alerts and their triage steps, escalation paths, rollback procedures, and references to the relevant dashboards and logs.

C.

Alert definitions and triage steps only, without escalation paths, rollback procedures, or references to dashboards and logs for on-call use.

D.

Escalation paths and rollback procedures only, without alert definitions, triage steps, or dashboard references to guide initial incident response.

Question 22

You are listing characteristics of robust guardrail design for an enterprise deployment.

Which two characteristics belong on the list? (Select two.)

Each correct answer presents a complete solution.

Options:

A.

Centralized log retention for guardrail violations with quarterly review by the security team.

B.

Per-role tool allow-lists enforced at the orchestration layer before any tool call executes.

C.

User feedback channels that route reported guardrail failures into the product backlog for triage.

D.

Periodic refresh of the system prompt wording to keep refusal language current and clear.

E.

Adversarial-input coverage in the evaluation set with regression tracking on guardrail performance.

Question 23

You are classifying chunking strategies by the corpus type each is best suited to.

For each chunking strategy, select the appropriate corpus type: “Long Structured Documents,” “Heterogeneous Short Records,” or “Code or Hierarchical Specifications.”

Question # 23

Options:

Question 24

You are designing a feedback session for a deployment in flight.

Which structure best supports productive stakeholder feedback?

Options:

A.

Hold an open-ended meeting with no pre-distributed agenda or artifacts, and rely on participants’ memory to carry decisions and follow-up owners forward.

B.

Define a focused agenda, share the artifacts in advance, capture decisions and follow-ups in writing, and confirm action owners and dates.

C.

Distribute artifacts at the session start rather than in advance, so stakeholders review materials in real time without preparation before the discussion begins.

D.

End the session without recording decisions, follow-up items, action owners, or dates, relying on participant memory to carry the session’s outcomes forward.

Question 25

You are preparing a HIPAA-eligible deployment for a healthcare customer.

Which configuration supports HIPAA compliance using Anthropic-offered tools?

Options:

A.

Claude Free with no contractual addendum, since consumer products meet HIPAA requirements out of the box.

B.

Claude Enterprise with a signed Business Associate Agreement, Zero Data Retention enabled, and audit logging configured for compliance tracking.

C.

Disabling all audit logging so that no PHI is recorded in any log store, on the assumption that the absence of logs satisfies HIPAA requirements without a signed BAA.

D.

An ad-hoc personal Claude account used by individual clinicians for PHI-related tasks, with no Business Associate Agreement, no Zero Data Retention, and no audit logging configured.

Question 26

You are compiling team-setup practices for a Claude Code rollout across an engineering organization.

Which two practices belong on the list? (Select two.)

Each correct answer presents a complete solution.

Options:

A.

Use project scope for team-shared Model Context Protocol (MCP) servers and permission rules under version control.

B.

Apply managed configuration centrally for security-critical settings that must not be overridden by individual engineers.

C.

Use local scope for security-critical permission rules so each engineer can adapt them to ongoing work.

D.

Use user scope for team-shared MCP servers so every engineer on the team has consistent access.

E.

Use project scope for personal editor preferences so the preferences apply consistently within the project.

Question 27

You are rolling out a standardized Claude Code configuration to an engineering team and must complete the planning steps before piloting the configuration.

Which two steps must be completed BEFORE piloting the configuration with a small group of engineers? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Define the project-scope baseline covering Model Context Protocol (MCP) servers, permission rules, and subagents.

B.

Onboard every engineer in the organization to the new configuration through mandatory training sessions.

C.

Roll out the stabilized configuration to additional teams with documentation and a defined support channel.

D.

Identify the team workflows, security boundaries, and which decisions belong to managed configuration versus project scope.

E.

Iterate the configuration based on the pilot findings and stabilize the baseline before broader rollout.

Question 28

You are selecting a protocol for a single low-latency stateless tool call from a Claude-based assistant to an internal pricing service that already exposes a stable HTTP API.

Which integration mechanism is the most appropriate?

Options:

A.

A direct API call to the existing endpoint with the appropriate scoped credentials.

B.

A long-lived stateful session protocol for a stateless single-call interaction.

C.

A bespoke streaming protocol layered over an unrelated asynchronous message bus.

D.

An agent-to-agent handoff that introduces another Claude-based agent in front of the pricing service.

Question 29

You are distinguishing functional from non-functional requirements during discovery.

Which item is a non-functional requirement?

Options:

A.

The system must extract a defined set of specific fields from invoice attachments and populate a downstream data record.

B.

The system must produce a draft response that a human reviewer can edit before sending.

C.

The system must classify inbound tickets into a defined set of categories.

D.

The system must respond at p95 latency under 800 milliseconds at the expected request volume.

Question 30

You are an architect supporting the iteration phase of a deployed Claude-based system.

Which activity most directly fits this phase?

Options:

A.

Rebuild the entire system architecture from scratch at the start of every iteration cycle regardless of what production telemetry, evaluations, and stakeholder feedback indicate is needed.

B.

Stop measuring production outcomes once the deployment has successfully launched, treating the go-live milestone as the end of the evaluation and iteration cycle.

C.

Discard the evaluation framework and reference set once the deployment is in production, accepting that future iterations will have no structured basis for measuring the impact of changes.

D.

Review production telemetry, sampled output evaluations, and stakeholder feedback to identify the highest-impact change for the next cycle, then plan the change against the evaluation framework.

Question 31

A security audit uncovers two issues: (1) all end users share a single API key, and (2) tool calls are executed without logging the initiating user.

Which two mitigations directly address these specific findings? (Select two.)

Options:

A.

Validate structured outputs against a schema before downstream actions are executed.

B.

Enforce RBAC at the retrieval layer before content enters the model context.

C.

Move credentials out of the prompt context and resolve them from a server-side secret store.

D.

Add actor attribution to tool-call logs so each call records the initiating user identity.

E.

Replace the shared API key with per-user OAuth tokens carrying scope-restricted permissions.

Question 32

A managed agent deployment for claims triage has grown from 6 tools to 34 tools over 18 months as product teams added capabilities. Triage accuracy has declined from 91 percent to 78 percent, and average tool-selection latency has increased by 2.3 seconds. A junior engineer has proposed adding a tool-router agent in front of the current agent to filter the tool list per request.

Which two findings should you present to justify capability decomposition before adding the router? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Tool descriptions overlap across multiple claim categories within the agent’s tool set.

B.

Several tools have not been invoked across the most recent 90 days of traffic.

C.

The 34 tools serve four distinct claim-workflow domains within the triage scope.

D.

The router pattern is well documented across publicly available agent literature.

E.

The proposed router introduces an additional model call on every incoming request.

Question 33

The compliance team at a firm has approved a Claude Skill that generates client-facing investment summaries. The Skill includes the firm’s required disclaimers and prohibited-language list. A product manager has asked whether additional guardrails are needed at the application layer or whether the Skill alone is sufficient.

Which two guardrail responsibilities should remain at the application layer rather than the Skill? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Log every generated summary to the firm’s compliance audit trail for retention.

B.

Verify the requesting user is authorized to generate investment summaries at all.

C.

Format output sections according to the firm’s standardized house style guidelines.

D.

Apply the disclaimer template that the compliance team has standardized firm-wide.

E.

Apply the prohibited-language list that the compliance team maintains and updates.

Question 34

A technical team is cataloguing risks specific to Claude’s use in a document-grounded Q & A system.

Which two items represent failure modes intrinsic to LLM-based systems rather than generic software defects? (Select two.)

Options:

A.

An expired TLS certificate blocks outbound API calls to Claude.

B.

A database connection timeout causes retrieval to return an empty result set.

C.

The model refuses a legitimate query because surface features trigger an overly broad safety pattern.

D.

A misconfigured load balancer routes requests to a deprecated API version.

E.

The model generates a plausible-sounding answer unsupported by any retrieved document.

Question 35

You are defining where human review must remain in a planned automated pipeline. Which placement reflects sound human-in-the-loop design?

Options:

A.

Place a human reviewer only after the irreversible action has already executed, making the review a post-hoc audit rather than a meaningful pre-action check or approval gate.

B.

Place a human reviewer between the model’s output and any high-impact, irreversible action, with explicit criteria for what the reviewer must check before approval.

C.

Place a human reviewer in the loop for a randomly selected sample of requests, without defining criteria for what the reviewer should check or which output categories require mandatory review.

D.

Remove all human review steps from the pipeline to maximize throughput, accepting that high-impact and irreversible actions will be taken without any human approval or oversight.

Question 36

You are configuring Claude Code for a team that needs every engineer to share the same MCP server set, permission rules, and project context across the engineering monorepo.

Which configuration scope best supports this requirement?

Options:

A.

User scope, with the MCP server definitions and permission rules placed in each engineer’s ~/.claude/settings.json and synchronized manually through a shared setup script outside version control.

B.

Local scope configured only on the lead architect’s machine, with no configuration present on other engineers’ machines and no mechanism to distribute MCP servers or permission rules.

C.

Project scope, with the configuration committed to the repository so every engineer working in the project receives the same MCP servers, permissions, and context.

D.

User scope configured individually on each engineer’s machine, with no shared configuration committed to the repository and no guarantee of consistency across the team.

Question 37

A platform team operates a self-hosted multi-agent system on Kubernetes that orchestrates seven specialized agents for invoice processing. The team spends approximately 40 percent of engineering capacity on infrastructure maintenance, message bus reliability, and agent state recovery. The CFO has asked you to evaluate moving to managed agent infrastructure to reclaim engineering capacity. The security officer requires that all customer financial data remain within an approved network boundary.

Which factor should most heavily influence your recommendation?

Options:

A.

Whether the current seven agents map cleanly to the patterns supported by managed agents.

B.

Whether managed agents reduce per-invoice token costs across the existing processing volume.

C.

Whether managed agents support the current bus topology used by the platform team.

D.

Whether managed agent data handling satisfies the network boundary required by security.

Question 38

An architect at Trenova Systems, Inc. is reviewing two draft communication packages for the same architectural decision. Package 1 contains a threat model, residual-risk register, and control-mapping table. Package 2 contains a list of capabilities delivered and feature-level roadmap dependencies.

Which two audiences are correctly matched to these packages? (Select two.)

Options:

A.

Package 1 → engineering implementation team

B.

Package 2 → executive sponsor

C.

Package 1 → security and compliance reviewer

D.

Package 2 → product manager owning the roadmap

E.

Package 2 → security and compliance reviewer

Page: 1 / 13
Total 129 questions