Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Anthropic > Claude Certified Architect > CCAR-P

CCAR-P Claude Certified Architect - Professional Question and Answers

Question # 4

You are defining escalation criteria for ambiguous cases in an automated workflow.

Which set of criteria best supports consistent escalation?

A.

No escalation criteria; the model decides independently on every turn whether to escalate, without explicit confidence thresholds, impact categories, or classifier-based ambiguity flags.

B.

Escalation only after an affected customer has contacted support to complain, after the automated workflow has already completed without human review.

C.

Escalation at the discretion of whoever is available when the team’s on-call engineer has spare capacity, without a defined threshold, category, or ambiguity criterion.

D.

A confidence score below a defined threshold, presence of high-impact decision categories, ambiguity flags raised by content classifiers, and the user’s explicit request for review.

Full Access
Question # 5

You are running a risk assessment on a planned Claude-based deployment and must complete the inventory steps before assessing threats against assets.

Which two steps must be completed BEFORE assessing threats against assets to estimate likelihood and impact? (Select two.)

Each correct answer presents part of the solution.

A.

Document the assessment outcome with risks, mitigations, residual risk, and acceptance owners.

B.

Recommend mitigations and residual-risk acceptance for the risks that remain after analysis.

C.

Identify the assets that the deployment touches, along with the sensitivity of each asset.

D.

Recommend mitigations and residual-risk acceptance for risks that remain.

E.

Enumerate the threat actors and attack vectors relevant to the deployment.

Full Access
Question # 6

After a prompt-template update, several previously passing test cases now produce unexpected outputs.

Which test type is specifically designed to detect this category of failure?

A.

Adversarial tests that probe for prompt-injection vulnerabilities.

B.

Regression tests scored against a stable reference set of known-good behavior.

C.

Smoke tests that confirm high-level system availability after the change.

D.

Integration tests that validate cross-component pipeline behavior.

Full Access
Question # 7

A Claude Architect is reviewing a post-deployment performance report for an AI-assisted legal-document summarization system. The report includes these observations:

Average summarization time decreased from 47 minutes to 6 minutes per document.

Associates spend less time on summaries, but overall billable output has not measurably changed.

Infrastructure costs increased by 22% because redundant retry logic generated additional API calls.

Some summaries require attorney correction, adding an average of 8 minutes of review per document.

Which analysis correctly attributes each observation to the appropriate business-value pillar?

A.

Observations 1 and 2 both indicate efficiency gains; Observation 3 is a solution-cost issue; Observation 4 is a performance-SLA issue.

B.

Observation 1 is a transformation outcome; Observation 2 is an efficiency gain; Observation 3 is a performance-SLA degradation; Observation 4 is a solution-cost issue.

C.

Observations 1 and 4 together indicate a net performance-SLA improvement; Observation 2 is a transformation gap; Observation 3 is a productivity drain from over-engineering.

D.

Observation 1 indicates an efficiency gain; Observation 2 shows that productivity has not yet been realized; Observation 3 is a solution-cost issue; Observation 4 is an efficiency loss that partially offsets Observation 1.

Full Access
Question # 8

You are compiling continuity practices that span the deployment lifecycle.

Which two practices belong on the list? (Select two.)

Each correct answer presents a complete solution.

A.

Maintain a stakeholder register and notify the listed parties at every phase transition event.

B.

Carry the evaluation framework and reference set forward across iterations rather than rebuilding each time.

C.

Archive every phase deliverable in long-term storage to preserve a record of what was produced.

D.

Capture lessons learned at the end of each phase and surface them as inputs to the next phase.

E.

Lock decisions made in early phases to prevent revisiting them as later phases begin.

Full Access
Question # 9

You are designing the prompt for a ticket-triage classifier with thirty well-defined categories and clear category descriptions in the prompt.

Which technique is most appropriate as the starting point?

A.

A chain-of-thought prompt for a routing decision that does not require multi-step reasoning.

B.

A zero-shot prompt that specifies the categories with their descriptions and the required output format.

C.

A prompt that demands the model invent new categories when the supplied ones do not fit.

D.

A prompt with no category descriptions, expecting the model to infer the category set.

Full Access
Question # 10

A Claude architect is auditing configuration scope assignments.

Which two statements correctly identify an appropriate use of user-scope configuration versus other scopes? (Select two.)

A.

Persisting personal editor theme preferences that follow an engineer across projects.

B.

Saving a preferred Claude response language that applies to all repositories the engineer uses.

C.

Enforcing a company-wide policy that disables a feature for all engineers.

D.

Defining MCP server endpoints shared by all contributors to a specific repository.

E.

Storing API authentication keys so they are not committed to version control.

Full Access
Question # 11

You are supporting an engineer whose Claude Code session reports a permission denial when the engineer expected the action to be allowed.

Which resolution step is most appropriate?

A.

Tell the engineer to retry the denied action verbatim repeatedly until the denial stops appearing, without inspecting the active permission rules to determine whether the denial is intentional.

B.

Disable the permission system entirely across all scopes to remove the denial, eliminating all tool-pattern and deny-rule controls rather than identifying and amending the specific rule.

C.

Inspect the active permission rules across all scopes—managed, command-line, local, project, and user—to identify which rule is denying the action and confirm whether it should be amended or remain denied.

D.

Grant the engineer unrestricted Bash access to bypass the specific rule causing the denial, removing all tool-pattern constraints rather than amending only the rule in question.

Full Access
Question # 12

You are evaluating retrieval-strategy claims used by a peer team.

For each claim, select yes if the statement is generally accurate. Otherwise, select no.

Full Access
Question # 13

You are selecting the documentation set that should accompany a Claude-based deployment at handoff. Which set is most complete?

A.

Architecture overview, ADRs, component-level diagrams, runbooks for common operations, an on-call playbook, and a list of known limitations.

B.

Code comments scattered across individual source files with no integrating architecture overview, no ADRs, no runbooks, and no on-call playbook to orient operators or new team members.

C.

A single one-page architecture diagram with no ADRs, no runbooks, no on-call playbook, and no list of known limitations to support operators or future maintainers.

D.

A verbal handover walkthrough conducted on the day of transition, with no written architecture overview, ADRs, runbooks, playbook, or known limitations captured for future reference.

Full Access
Question # 14

You are a solution architect evaluating candidate use cases for a Claude-based program.

For each scenario, select Yes if Claude is appropriate as the primary solution at the architectural level. Otherwise, select No.

Full Access
Question # 15

You are listing characteristics of strong architectural-decision communication.

Which two characteristics belong on the list? (Select two.)

Each correct answer presents a complete solution.

A.

Ownership and review cadence for revisiting the decision when conditions or assumptions change.

B.

Distribution to a standing review forum with mandatory attendance from senior engineering leaders.

C.

Omission of rejected alternatives to keep the decision document focused and concise for readers.

D.

Alternatives considered along with the criteria that were used to evaluate each alternative.

E.

Use of a consistent template across the team to standardize the visual presentation of decisions.

Full Access
Question # 16

You are classifying token-management tactics by where in the request lifecycle each tactic applies.

For each tactic, select where in the request lifecycle it applies: Input Preparation , Prompt Construction , or Output Handling .

Full Access
Question # 17

During an architectural review, the security team identifies a risk that adversarial content injected into retrieved documents could manipulate the model’s behavior.

Which mitigation most directly addresses this threat?

A.

Treat all retrieved content as untrusted input and apply input classifiers with output validation.

B.

Require citations for each claim and constrain responses to source-supported content.

C.

Restrict outbound tool calls to an approved destination allow-list.

D.

Score outputs against a stable adversarial evaluation set on each model-version change.

Full Access
Question # 18

You are identifying inefficiency in a Claude Code workflow where each engineer manually re-explains the project ' s conventions and architecture in every session.

Which adjustment most directly removes this inefficiency?

A.

Forbid the use of Claude Code on the project entirely to avoid the session-initialization overhead, accepting that the team loses all AI-assisted development productivity for this codebase.

B.

Capture the project ' s conventions and architecture in a project-scoped CLAUDE.md (or equivalent persistent project-context file) committed to the repository, so each session loads it automatically.

C.

Tell each engineer to retype the project conventions and architecture context more quickly at the start of each session, reducing time lost without eliminating the repeated manual effort.

D.

Remove all documented project conventions and architectural standards so engineers have nothing to re-explain at session start, accepting the loss of consistency and shared coding standards.

Full Access
Question # 19

You are reviewing a peer’s end-to-end design for a Claude-based platform expected to scale to thousands of concurrent users.

For each statement, indicate Yes if it reflects sound architectural practice. Otherwise, select No.

Full Access
Question # 20

You are evaluating a Claude-based deployment for adherence to a specific regulation.

Which two steps must be completed BEFORE mapping deployment data flows to specific regulatory clauses? (Select two.)

Each correct answer presents part of the solution.

A.

Compare the in-place controls against the regulatory requirements to identify any compliance gaps.

B.

Identify the applicability of the regulation based on data types, jurisdiction, and audience.

C.

Schedule the remediation work with the engineering team based on the prioritized gap findings.

D.

Document the identified gaps along with recommended remediations and residual risk for sign-off.

E.

Inventory the vendor-provided compliance tooling and confirm which compliance affordances are in place.

Full Access
Question # 21

You are presenting an architectural decision to a mixed audience that includes an executive sponsor and the engineering leads who will implement the decision.

Which presentation strategy best serves both audiences?

A.

Open with a deep dive into low-level implementation details targeted at engineering leads, and stop there without addressing the business outcomes or trade-offs the executive sponsor needs.

B.

Lead with the decision, the business outcomes it serves, and the trade-offs accepted; follow with the technical rationale, alternatives, and implementation implications for the engineering audience.

C.

Skip the rationale, alternatives, and trade-off discussion entirely and simply announce the chosen decision, leaving both audiences without the context needed to implement or validate it.

D.

Present a single undifferentiated narrative that addresses technical and business concerns with equal weight throughout, treating both audiences as requiring the same depth on every section.

Full Access
Question # 22

You are running a controlled experiment to compare two prompts and must complete the design steps before executing the experiment.

Which two steps must be completed BEFORE running the experiment with random assignment? (Select two.)

Each correct answer presents part of the solution.

A.

Determine the minimum detectable effect size and the sample size needed for power.

B.

Decide whether to promote, reject, or iterate the candidate based on the analysis.

C.

Define the hypothesis and the primary success metric for the comparison.

D.

Analyze the results against the predefined success metric and significance threshold.

E.

Document the recommendation, the trade-offs accepted, and the alternatives considered.

Full Access
Question # 23

You are rolling out monitoring for a Claude-based deployment and must complete the specification steps before instrumenting the deployment.

Which two steps must be completed BEFORE instrumenting the deployment to emit metrics and traces? (Select two.)

Each correct answer presents part of the solution.

A.

Define the metrics and the slices the deployment will monitor across normal and adversarial traffic.

B.

Tune the alert thresholds based on observed normal-state distributions to reduce false positives.

C.

Define the service-level objectives (SLOs) and the error budgets the deployment will be held to.

D.

Build the dashboards that surface metrics across slices at the cadence the team operates on.

E.

Document the dashboards, alerts, and runbooks for the on-call rotation that will respond.

Full Access
Question # 24

A customer support team has proposed delegating customer refund decisions to a Claude-driven workflow with no human review for refunds under 50 USD. The team ' s reasoning is that small refunds are low-risk and human review would erase the efficiency gain.

Which Delegation-competency principle should guide your response?

A.

Delegation should always include human review on every decision the workflow produces.

B.

Delegation scope should reflect the type of risk involved, not the transaction size alone.

C.

Delegation scope should be set primarily by maximizing efficiency gains across the workflow.

D.

Delegation should be avoided entirely wherever financial transactions occur in the workflow.

Full Access
Question # 25

A healthcare organization is evaluating two Claude-powered AI architectures for a clinical documentation assistant. Architecture X produces higher output quality scores but costs $0.18 per documentation session and averages 4.2 seconds per response. Architecture Y scores slightly lower on quality metrics but costs $0.09 per session and averages 2.1 seconds per response. The stated SLA requires responses under 3 seconds, and the annual volume is projected at 2 million documentation sessions.

Which evaluation approach correctly applies business value pillar analysis to this decision?

A.

Select Architecture Y based solely on the 50% cost reduction, since solution cost is the most important value pillar in healthcare budget-constrained environments.

B.

Select Architecture X because the higher quality scores justify the cost premium, and any SLA gap can be addressed through infrastructure optimization after deployment.

C.

Eliminate Architecture X on SLA grounds, then evaluate Architecture Y against the efficiency and solution cost pillars by calculating annual cost difference and assessing whether the quality delta materially impacts clinical workflow productivity.

D.

Recommend a hybrid approach using Architecture X for complex cases and Architecture Y for routine cases, without additional analysis, since this preserves quality where it matters most.

Full Access
Question # 26

You are building an ethics-review checklist for deployments supported by artificial intelligence.

Which two checks belong on the list? (Select two.)

Each correct answer presents a complete solution.

A.

Confirm that vendor licensing terms permit the planned production use of the model.

B.

Verify that outputs do not rely on generalizations about people that the underlying data does not support.

C.

Confirm that high-impact decisions retain human accountability rather than being attributed to the model.

D.

Restrict ethics review to outputs that exceed a defined model-confidence threshold.

E.

Confirm that latency and throughput targets are met across supported user populations.

Full Access
Question # 27

You are configuring Claude Code for a team that needs every engineer to share the same MCP server set, permission rules, and project context across the engineering monorepo.

Which configuration scope best supports this requirement?

A.

User scope, with the MCP server definitions and permission rules placed in each engineer’s ~/.claude/settings.json and synchronized manually through a shared setup script outside version control.

B.

Local scope configured only on the lead architect’s machine, with no configuration present on other engineers’ machines and no mechanism to distribute MCP servers or permission rules.

C.

Project scope, with the configuration committed to the repository so every engineer working in the project receives the same MCP servers, permissions, and context.

D.

User scope configured individually on each engineer’s machine, with no shared configuration committed to the repository and no guarantee of consistency across the team.

Full Access
Question # 28

You are listing characteristics of robust guardrail design for an enterprise deployment.

Which two characteristics belong on the list? (Select two.)

Each correct answer presents a complete solution.

A.

Centralized log retention for guardrail violations with quarterly review by the security team.

B.

Per-role tool allow-lists enforced at the orchestration layer before any tool call executes.

C.

User feedback channels that route reported guardrail failures into the product backlog for triage.

D.

Periodic refresh of the system prompt wording to keep refusal language current and clear.

E.

Adversarial-input coverage in the evaluation set with regression tracking on guardrail performance.

Full Access
Question # 29

You are compiling a diagnostic toolkit for Claude Code operational issues.

Which two diagnostic actions belong in the toolkit? (Select two.)

Each correct answer presents a complete solution.

A.

Increase the model sampling temperature so that intermittent issues surface more frequently for analysis.

B.

File a support ticket with vendor support before any local reproduction or evidence collection.

C.

Reproduce the issue with a minimal reproduction case that isolates one variable at a time.

D.

Roll back to the previous Claude Code version immediately to confirm whether the issue is version specific.

E.

List the configured Model Context Protocol (MCP) servers and inspect server status to identify connection failures.

Full Access
Question # 30

You are selecting a protocol for a single low-latency stateless tool call from a Claude-based assistant to an internal pricing service that already exposes a stable HTTP API.

Which integration mechanism is the most appropriate?

A.

A direct API call to the existing endpoint with the appropriate scoped credentials.

B.

A long-lived stateful session protocol for a stateless single-call interaction.

C.

A bespoke streaming protocol layered over an unrelated asynchronous message bus.

D.

An agent-to-agent handoff that introduces another Claude-based agent in front of the pricing service.

Full Access
Question # 31

A Claude-based research assistant begins producing responses that confidently contradict its retrieved source documents despite no change to the retrieval pipeline.

Which two diagnostic actions most directly identify the root cause of this behavior? (Select two.)

A.

Increase the context-window size to allow more retrieved chunks per query.

B.

Switch the retrieval index to a denser embedding model to improve chunk-relevance scores.

C.

Determine whether the failure reproduces on the previous model version to test for a model mismatch.

D.

Reduce the temperature setting to lower response variance across all query types.

E.

Inspect the system-prompt grounding instructions to determine whether citation constraints remain intact.

Full Access
Question # 32

A team manager wants all engineers working on the same repository to share identical MCP server definitions without manual synchronization.

Which configuration approach satisfies this requirement?

A.

managed configuration pushed to all endpoints by the administrator

B.

environment variables set at the operating-system level on each workstation

C.

project-scope .claude/settings.json and .mcp.json files committed to the repository

D.

each engineer maintains a personal ~/.claude/settings.json with the shared definitions

Full Access
Question # 33

The compliance team at a firm has approved a Claude Skill that generates client-facing investment summaries. The Skill includes the firm’s required disclaimers and prohibited-language list. A product manager has asked whether additional guardrails are needed at the application layer or whether the Skill alone is sufficient.

Which two guardrail responsibilities should remain at the application layer rather than the Skill? (Select two.)

Each correct answer presents part of the solution.

A.

Log every generated summary to the firm’s compliance audit trail for retention.

B.

Verify the requesting user is authorized to generate investment summaries at all.

C.

Format output sections according to the firm’s standardized house style guidelines.

D.

Apply the disclaimer template that the compliance team has standardized firm-wide.

E.

Apply the prohibited-language list that the compliance team maintains and updates.

Full Access
Question # 34

A security team is evaluating two proposed controls. Control A adds an outbound tool allow-list with destination restrictions and per-call review. Control B scores responses against a stable adversarial evaluation set after each model-version change.

Which two risk categories are correctly matched to these controls? (Select two.)

A.

Control A — prompt injection from adversarial content in retrieved data

B.

Control A — silent quality drift after a model-version upgrade

C.

Control A — data exfiltration via outbound tool calls

D.

Control B — data exfiltration via outbound tool calls

E.

Control B — silent quality drift after a model-version upgrade

Full Access
Question # 35

The compliance team has authored a regulatory disclosure procedure that must be applied identically across customer service, sales, and onboarding workflows. The procedure changes when regulators issue updates, currently four to six times per year. You are designing how the procedure will be packaged for use by Claude across all three workflows.

Which two design decisions should you include? (Select two.)

Each correct answer presents part of the solution.

A.

Package the procedure as a Claude Skill owned directly by the compliance team.

B.

Embed the procedure text into each workflow’s system prompt at integration time.

C.

Store the procedure in a shared retrieval corpus accessed by all three workflows.

D.

Have each workflow team rewrite the procedure for its own context.

E.

Reference the same Claude Skill from all three workflow integrations.

Full Access
Question # 36

You are assessing a Claude-based system whose dominant risk is silent quality drift on safety-relevant outputs after a model-version upgrade.

Which assessment activity most directly addresses this risk?

A.

Disable adversarial evaluation entirely during model-version upgrade cycles to reduce evaluation cost, accepting that safety drift will go undetected until it appears in production.

B.

Rotate adversarial inputs randomly so no two upgrades are scored on the same set.

C.

Skip evaluation on each model-version upgrade and rely on user-submitted complaints to surface safety drift after the upgraded model has already served production traffic.

D.

Maintain an adversarial evaluation set with version-attributed scoring so each upgrade is measured against the same set before promotion.

Full Access
Question # 37

A Claude architect is configuring a shared Claude Code environment for a twelve-person development team.

Which two configuration decisions most directly establish a consistent, secure team environment? (Select two.)

A.

Commit shared MCP server definitions and tool permissions in project-scope configuration files alongside the repository.

B.

Apply managed configuration to enforce non-overridable security and compliance policies across all team members.

C.

Set editor theme and display preferences at the project scope so they are uniform across workstations.

D.

Instruct each engineer to configure their preferred Claude model in personal user-scope settings.

E.

Store the team’s shared API key in the project-scope settings.json so all engineers use the same credential.

Full Access
Question # 38

An architect at Trenova Systems, Inc. is reviewing two draft communication packages for the same architectural decision. Package 1 contains a threat model, residual-risk register, and control-mapping table. Package 2 contains a list of capabilities delivered and feature-level roadmap dependencies.

Which two audiences are correctly matched to these packages? (Select two.)

A.

Package 1 → engineering implementation team

B.

Package 2 → executive sponsor

C.

Package 1 → security and compliance reviewer

D.

Package 2 → product manager owning the roadmap

E.

Package 2 → security and compliance reviewer

Full Access