Pre-Winter Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Anthropic CCAR-P Dumps

Page: 1 / 13
Total 129 questions

Claude Certified Architect - Professional Questions and Answers

Question 1

You are reviewing an integration specification for security gaps.

Which two findings constitute valid security gaps in the specification? (Select two.)

Each correct answer presents a complete solution.

Options:

A.

Tool calls execute server-side under a least-privilege service principal scoped to the requested action.

B.

Service credentials are placed in the prompt context, where they can leak into logs and traces.

C.

Role-based access control is enforced only at the response-rendering layer after the model accesses restricted data.

D.

Per-user OAuth tokens are exchanged with scope-restricted permissions and refreshed within the active session.

E.

Tool inputs and outputs are encrypted in transit using transport-layer security between services.

Question 2

After a prompt-template update, several previously passing test cases now produce unexpected outputs.

Which test type is specifically designed to detect this category of failure?

Options:

A.

Adversarial tests that probe for prompt-injection vulnerabilities.

B.

Regression tests scored against a stable reference set of known-good behavior.

C.

Smoke tests that confirm high-level system availability after the change.

D.

Integration tests that validate cross-component pipeline behavior.

Question 3

You are designing a content moderation classifier that processes high volumes of user-generated comments under a tight per-message latency budget using well-defined classification labels.

Which model selection best aligns with the workload?

Options:

A.

Opus, because every moderation decision requires maximum reasoning depth regardless of classification complexity.

B.

Haiku, because its latency and cost profile align with high-volume classification workloads that require limited reasoning depth.

C.

Sonnet, because larger general-purpose models are preferred even when workload latency requirements are strict.

D.

Sonnet with extended thinking enabled, because deeper reasoning should be applied to every moderation request to improve edge-case handling.

Question 4

The engineering lead at Trenova Systems, Inc. is evaluating two proposals for improving developer workflows using Claude-assisted tooling. Proposal A adds Claude Code to the IDE for inline code generation and review. Proposal B routes all code-generation requests through a shared Slack bot without IDE integration.

Which two observations most accurately evaluate these proposals against workflow-improvement objectives? (Select two.)

Options:

A.

Proposal B is superior because centralizing requests in Slack creates an auditable log of all code-generation activity.

B.

Proposal B introduces workflow friction by requiring developers to leave the IDE, undermining the productivity objective.

C.

Proposal A reduces context switching by providing AI assistance at the point of development without requiring a separate tool.

D.

Proposal B improves workflow velocity because Slack notifications create an asynchronous review queue.

E.

Both proposals are equivalent because the model capabilities are identical regardless of the integration point.

Question 5

You are reviewing instrumentation in a multi-agent system.

Which two findings constitute valid observability gaps in the instrumentation? (Select two.)

Each correct answer presents a complete solution.

Options:

A.

Trace spans for each agent step are exported to the shared distributed-tracing backend.

B.

Latency and token usage on every span are emitted to the central metrics pipeline.

C.

Tool-call payloads and outcomes are recorded with redaction applied to known sensitive fields.

D.

Model identity and version on each turn are not recorded with the turn artifacts.

E.

Request-scoped correlation identifiers do not propagate across agent and tool calls.

Question 6

You are evaluating retrieval-strategy claims used by a peer team.

For each claim, select yes if the statement is generally accurate. Otherwise, select no.

as

Options:

Question 7

You are identifying the highest-impact optimization for a deployment whose token cost is dominated by a long, repeated system prompt and a large retrieved context per request.

Which optimization most directly targets the dominant cost driver?

Options:

A.

Increase retrieval depth on every request to maximize recall, worsening the dominant cost driver by adding more retrieved tokens per request rather than reducing them.

B.

Add additional repeated content to the system prompt to give the model more guidance.

C.

Move the long, repeated system prompt into a cacheable prefix and trim retrieved context to the spans relevant to each query.

D.

Switch every request to the heaviest available model to maximize output quality, accepting that higher per-request inference cost compounds rather than addresses the dominant cost driver.

Question 8

A Claude architect is implementing safety controls for a customer-facing advice assistant that must never provide regulated investment recommendations.

Which two guardrail implementations most directly enforce this constraint? (Select two.)

Options:

A.

Increase response temperature to introduce variability that reduces the likelihood of specific recommendations.

B.

Add an output classifier that detects and blocks responses containing regulated investment-recommendation language.

C.

Limit session length to reduce the volume of queries processed per user per day.

D.

Log all user queries to a SIEM for post-hoc compliance review.

E.

Define explicit out-of-scope categories in the system prompt with fixed refusal phrasing for investment advice requests.

Question 9

The compliance team has authored a regulatory disclosure procedure that must be applied identically across customer service, sales, and onboarding workflows. The procedure changes when regulators issue updates, currently four to six times per year. You are designing how the procedure will be packaged for use by Claude across all three workflows.

Which two design decisions should you include? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Package the procedure as a Claude Skill owned directly by the compliance team.

B.

Embed the procedure text into each workflow’s system prompt at integration time.

C.

Store the procedure in a shared retrieval corpus accessed by all three workflows.

D.

Have each workflow team rewrite the procedure for its own context.

E.

Reference the same Claude Skill from all three workflow integrations.

Question 10

You are evaluating a Claude-based deployment for adherence to a specific regulation.

Which two steps must be completed BEFORE mapping deployment data flows to specific regulatory clauses? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Compare the in-place controls against the regulatory requirements to identify any compliance gaps.

B.

Identify the applicability of the regulation based on data types, jurisdiction, and audience.

C.

Schedule the remediation work with the engineering team based on the prioritized gap findings.

D.

Document the identified gaps along with recommended remediations and residual risk for sign-off.

E.

Inventory the vendor-provided compliance tooling and confirm which compliance affordances are in place.

Question 11

You are running a discovery session with a business sponsor who asks for “an AI system to fix our customer escalations.”

Which approach best yields actionable requirements?

Options:

A.

Accept the sponsor’s original phrasing as a complete and final requirement and proceed directly to design without asking targeted questions to surface actors, triggers, or constraints.

B.

Decompose the request by asking targeted questions about who escalates, what triggers escalation, what good resolution looks like, and which constraints—latency, cost, audit, and data sensitivity—apply.

C.

Defer the discovery session indefinitely on the grounds that the sponsor must fully specify the system before the architect can ask any clarifying or scoping questions.

D.

Assume the requirement matches the architect’s previous engagement in a different industry and proceed with that context, without validating actors, triggers, or constraints for this sponsor.

Question 12

You are designing a human-in-the-loop validation workflow for a new Claude-based deployment and must complete the design steps before piloting the workflow.

Which two steps must be completed BEFORE piloting the workflow with a representative subset of traffic? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Define the sampling strategy and the escalation criteria at each oversight point in the pipeline.

B.

Iterate the workflow design based on observed pilot findings before broader rollout to production.

C.

Onboard the reviewer pool with role-specific training on the check criteria and escalation procedures.

D.

Document the workflow with check criteria, escalation paths, and service-level agreements (SLAs) for each step.

E.

Identify the decision points in the pipeline that require human oversight by impact and reversibility.

Question 13

You are integrating Claude Code into a team workflow and must complete the design and configuration steps before piloting the integrated workflow with a small group.

Which two steps must be completed BEFORE piloting the integrated workflow? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Document the integrated workflow with handoff criteria, permission boundaries, and on-call runbooks.

B.

Identify the workflow steps where AI-assisted tooling adds value and where human authority must remain.

C.

Negotiate the workflow change with affected teams and obtain formal sign-off from each manager.

D.

Iterate the integrated workflow based on pilot findings before broader rollout to the team.

E.

Configure the project-scope MCP servers, permissions, subagents, and persistent project context.

Question 14

You are producing an architecture guide for a new deployment and must complete the planning steps before drafting each section.

Which two steps must be completed BEFORE drafting each section of the guide? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Identify the audience and the questions the guide must answer for that audience.

B.

Translate the guide into the supported regional languages for the candidate population.

C.

Validate the guide with the implementation team and incorporate corrections.

D.

Establish the document under version control with a defined review cadence and approver list.

E.

Outline the guide sections covering the overview, components, contracts, flows, runbooks, and limitations.

Question 15

You are compiling team-setup practices for a Claude Code rollout across an engineering organization.

Which two practices belong on the list? (Select two.)

Each correct answer presents a complete solution.

Options:

A.

Use project scope for team-shared Model Context Protocol (MCP) servers and permission rules under version control.

B.

Apply managed configuration centrally for security-critical settings that must not be overridden by individual engineers.

C.

Use local scope for security-critical permission rules so each engineer can adapt them to ongoing work.

D.

Use user scope for team-shared MCP servers so every engineer on the team has consistent access.

E.

Use project scope for personal editor preferences so the preferences apply consistently within the project.

Question 16

You are designing the prompt for a ticket-triage classifier with thirty well-defined categories and clear category descriptions in the prompt.

Which technique is most appropriate as the starting point?

Options:

A.

A chain-of-thought prompt for a routing decision that does not require multi-step reasoning.

B.

A zero-shot prompt that specifies the categories with their descriptions and the required output format.

C.

A prompt that demands the model invent new categories when the supplied ones do not fit.

D.

A prompt with no category descriptions, expecting the model to infer the category set.

Question 17

You are integrating AI-assisted tooling into the team’s documentation workflow. The team wants generated documentation that stays grounded in the actual code.

Which integration approach best fits this requirement?

Options:

A.

Generate documentation from the model’s training-data recall without reading any of the actual repository code, accepting that the output will not reflect the current implementation.

B.

Have the subagents publish generated documentation directly to the public-facing site without passing through the team’s normal review workflow or any human approval step.

C.

Configure subagents that read the relevant code files via filesystem and code-search tools, generate the documentation, and emit changes through the team’s normal review workflow.

D.

Disable all filesystem and code-search tools so the subagents cannot read any repository code, accepting that documentation generation will be entirely disconnected from the actual implementation.

Question 18

You are explaining the precedence of Claude Code configuration scopes to the team.

Which precedence ordering, from highest to lowest, is correct?

Options:

A.

Local → managed → user → command-line arguments → project

B.

Project → user → managed → local → command-line arguments

C.

Managed → command-line arguments → local → project → user

D.

User → project → local → command-line arguments → managed

Question 19

You are reviewing a customer-support agent’s configuration. Each candidate tool falls into one of four categories: (1) required to complete defined tasks, (2) frequently used and reduces hand-offs, (3) occasionally useful for unrelated work, (4) speculative future utility.

Which categories should typically remain in the agent configuration?

Options:

A.

Only category 3, because occasionally useful tools for unrelated work provide broader coverage and should take priority over tools required for the agent’s defined tasks.

B.

Only category 4, because speculative future-utility tools provide the most flexibility and should be configured even when no defined task currently requires them.

C.

Categories 1 and 2 only, because they map to defined tasks and the agent’s regular hand-offs.

D.

All four categories, because broader tool access is categorically better for agent performance regardless of whether the tools map to defined tasks or regular hand-offs.

Question 20

You are integrating human review into a high-volume classification pipeline where reviewing every output is infeasible.

Which sampling strategy best balances throughput with quality oversight?

Options:

A.

No sampling, relying entirely on user complaints to reveal quality and safety problems after they affect users.

B.

Risk-stratified sampling that reviews all low-confidence and high-impact outputs and a smaller random sample of high-confidence routine outputs.

C.

Inverse sampling that reviews only high-confidence routine outputs and skips low-confidence and high-impact outputs.

D.

Universal review of every output regardless of confidence or throughput impact.

Question 21

You are defining where human review must remain in a planned automated pipeline. Which placement reflects sound human-in-the-loop design?

Options:

A.

Place a human reviewer only after the irreversible action has already executed, making the review a post-hoc audit rather than a meaningful pre-action check or approval gate.

B.

Place a human reviewer between the model’s output and any high-impact, irreversible action, with explicit criteria for what the reviewer must check before approval.

C.

Place a human reviewer in the loop for a randomly selected sample of requests, without defining criteria for what the reviewer should check or which output categories require mandatory review.

D.

Remove all human review steps from the pipeline to maximize throughput, accepting that high-impact and irreversible actions will be taken without any human approval or oversight.

Question 22

You are running a controlled experiment to compare two prompts and must complete the design steps before executing the experiment.

Which two steps must be completed BEFORE running the experiment with random assignment? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Determine the minimum detectable effect size and the sample size needed for power.

B.

Decide whether to promote, reject, or iterate the candidate based on the analysis.

C.

Define the hypothesis and the primary success metric for the comparison.

D.

Analyze the results against the predefined success metric and significance threshold.

E.

Document the recommendation, the trade-offs accepted, and the alternatives considered.

Question 23

You are building an evaluation pipeline for a Claude-based deployment and must complete the specification steps before running the deployment against the dataset.

Which two steps must be completed BEFORE running the deployment against the evaluation dataset? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Publish the aggregated metrics to a dashboard and gate releases on threshold checks.

B.

Curate and label the evaluation dataset to match the defined slices.

C.

Review failure cases with subject matter experts to refine the scoring rubric.

D.

Define the metrics and slices the framework will report across representative, edge, and adversarial cases.

E.

Score the deployment outputs against the reference labels and aggregate the metrics.

Question 24

A security audit uncovers two issues: (1) all end users share a single API key, and (2) tool calls are executed without logging the initiating user.

Which two mitigations directly address these specific findings? (Select two.)

Options:

A.

Validate structured outputs against a schema before downstream actions are executed.

B.

Enforce RBAC at the retrieval layer before content enters the model context.

C.

Move credentials out of the prompt context and resolve them from a server-side secret store.

D.

Add actor attribution to tool-call logs so each call records the initiating user identity.

E.

Replace the shared API key with per-user OAuth tokens carrying scope-restricted permissions.

Question 25

You are documenting an architectural decision to support future audit and onboarding.

Which artifact is the strongest fit?

Options:

A.

A slide deck in a presentation folder with no accompanying written rationale.

B.

A code comment in a single file that contains an opinion of one engineer.

C.

An Architecture Decision Record that states the context, the decision, the alternatives considered, the consequences, and the date and authors.

D.

A short verbal note shared during a hallway conversation with no written record.

Question 26

You are responding to an adversarial input pattern in which users include text claiming admin authority and instructing the model to bypass safety restrictions.

Which combination of controls most effectively mitigates this attack pattern?

Options:

A.

Trusting that the model will intrinsically recognize and reject all bypass attempts without prompt-level instructions, runtime classifiers, scoped permissions, or audit logging.

B.

Prompt-level instructions that treat user content as untrusted data, runtime classifiers that detect override attempts, scoped tool permissions that cannot be elevated by user content, and audit logging of attempts.

C.

Removing all safety restrictions and guardrails to eliminate the attack surface that bypass attempts target, accepting that this makes the assistant unrestricted for all inputs.

D.

Granting users any privilege level they assert in their message content, on the assumption that cooperative behavior requires honoring self-declared authority without independent verification.

Question 27

An architect is reviewing a set of architecture documentation packages before handing off a Claude-based pipeline to an implementation team.

Which two characteristics indicate that a documentation package is sufficient to support implementation without ongoing architect involvement? (Select two.)

Options:

A.

The document specifies integration contracts, configuration schemas, and expected input/output shapes for each component.

B.

The document includes a decision log that records the rationale for key architectural choices and the alternatives rejected.

C.

The document provides a high-level narrative description of the business problem without component-level detail.

D.

The document includes the architect’s contact information for questions arising during implementation.

E.

The document lists all Claude models that were evaluated but does not specify which was selected or why.

Question 28

A technical team is cataloging risks specific to Claude’s use in a document-grounded Q & A system.

Which two items represent failure modes that are intrinsic to LLM-based systems rather than generic software defects? (Select two.)

Options:

A.

The model refuses a legitimate query because surface features trigger an overly broad safety pattern.

B.

The model generates a plausible-sounding answer that is unsupported by any retrieved document.

C.

An expired TLS certificate blocks outbound API calls to the Claude endpoint.

D.

A misconfigured load balancer routes requests to a deprecated API version.

E.

A database connection timeout causes a retrieval call to return an empty result set.

Question 29

You are choosing the level of detail for an implementation guide. The audience is a delivery team that will build the deployment.

Which guidance composition best serves them?

Options:

A.

Component responsibilities, contracts between components, sequence diagrams of the dominant flows, configuration parameters with defaults, and operational runbooks.

B.

Component responsibilities and interface contracts only, without sequence diagrams of the dominant flows, configuration parameters with defaults, or runbooks to guide operational tasks.

C.

An architecture overview and sequence diagrams for the dominant flows, without interface contracts, configuration-parameter tables, or operational runbooks for the delivery team to follow.

D.

An architecture overview and a list of known limitations, without component-level diagrams, interface contracts, configuration parameters, or operational runbooks to support implementation.

Question 30

You are preparing an operational runbook for a Claude-based service.

Which content is essential to include in the runbook?

Options:

A.

Dashboard and log references only, without alert definitions, triage steps, escalation paths, or rollback procedures for the on-call engineer to act on.

B.

Common alerts and their triage steps, escalation paths, rollback procedures, and references to the relevant dashboards and logs.

C.

Alert definitions and triage steps only, without escalation paths, rollback procedures, or references to dashboards and logs for on-call use.

D.

Escalation paths and rollback procedures only, without alert definitions, triage steps, or dashboard references to guide initial incident response.

Question 31

A Claude architect at a health services organization is defining evaluation metrics for a clinical-summary pipeline. The pipeline must remain within a per-query cost ceiling and must never surface patient data to unauthorized roles.

Which two metrics directly address these requirements? (Select two.)

Options:

A.

BLEU score computed against a human-annotated reference summary set

B.

Role-based access-control enforcement rate measured on a red-team dataset

C.

Throughput measured as successful requests processed per minute

D.

Per-query token cost measured against the defined cost ceiling

E.

Response latency at the 95th percentile across a one-week sample window

Question 32

You are defining when to introduce a project subagent versus relying on Claude Code ' s general capabilities.

Which scenario most directly justifies a dedicated subagent?

Options:

A.

The team has a recurring specialized task, such as database schema review, that requires a focused system prompt, narrow tool permissions, and a specific model selection across many sessions.

B.

The team has a one-time ad hoc question that will not recur and does not require a focused system prompt, narrow tool permissions, or dedicated model selection.

C.

The team has no recurring specialized tasks and uses Claude Code only for isolated general-purpose work that does not justify a dedicated system prompt or tool scope.

D.

The team wants every Claude Code interaction to use the same generic system prompt with no task-specific specialization, narrow tool permissions, or dedicated model selection.

Question 33

You are running a discovery engagement for a new Claude-based capability and must complete the requirements-gathering steps before validating with stakeholders.

Which two steps must be completed BEFORE validating the captured requirements with stakeholders? (Select two.)

Each correct answer presents part of the solution.

Options:

A.

Produce architecture decision records that capture the rationale for major design choices.

B.

Capture the business goals, success criteria, and the in-scope user population for the engagement.

C.

Document the consolidated requirements with traceability to the source stakeholder for each item.

D.

Schedule the rollout milestones and dependencies with engineering and product partners.

E.

Identify the non-functional constraints covering latency, cost, audit, data sensitivity, and regulatory needs.

Question 34

A team manager wants all engineers working on the same repository to share identical MCP server definitions without manual synchronization.

Which configuration approach satisfies this requirement?

Options:

A.

managed configuration pushed to all endpoints by the administrator

B.

environment variables set at the operating-system level on each workstation

C.

project-scope .claude/settings.json and .mcp.json files committed to the repository

D.

each engineer maintains a personal ~/.claude/settings.json with the shared definitions

Question 35

A Claude architect is configuring a shared Claude Code environment for a twelve-person development team.

Which two configuration decisions most directly establish a consistent, secure team environment? (Select two.)

Options:

A.

Commit shared MCP server definitions and tool permissions in project-scope configuration files alongside the repository.

B.

Apply managed configuration to enforce non-overridable security and compliance policies across all team members.

C.

Set editor theme and display preferences at the project scope so they are uniform across workstations.

D.

Instruct each engineer to configure their preferred Claude model in personal user-scope settings.

E.

Store the team’s shared API key in the project-scope settings.json so all engineers use the same credential.

Question 36

A document analysis service processes legal filings averaging 80,000 tokens each. Each filing is queried by attorneys an average of 14 times during a case. The current architecture sends the full filing on every query. The CFO has asked you to reduce per-query costs while preserving response quality. The security officer requires that filing contents not be stored outside Fabrikam ' s tenancy.

Which optimization approach should you recommend?

Options:

A.

Summarize each filing once at intake and run all subsequent queries against the summary.

B.

Cache the filing as the prompt prefix for reuse across the 14 queries per case.

C.

Index filings in a vector store and retrieve only the relevant passages per query.

D.

Move the workload to a smaller Claude model to reduce the per-token cost paid.

Question 37

You are a solution architect designing a Claude-based assistant with access to 60 internal tools across multiple business domains. Loading every tool definition on every request increases token usage and time to first response.

Which design pattern best addresses this issue without sacrificing capability breadth?

Options:

A.

Apply progressive tool discovery so a curated initial subset is exposed and additional tools are loaded on demand based on the task.

B.

Use a separate model call to summarize all 60 tool definitions before each user turn.

C.

Increase the maximum context length and load all 60 tool definitions on every request, accepting the higher token cost and latency as necessary for full capability.

D.

Hard-code a fixed set of five tools per request to reduce token usage, regardless of whether those tools are relevant to the current task.

Question 38

You are classifying token-management tactics by where each tactic applies in the request lifecycle: “Input Preparation,” “Prompt Construction,” or “Output Handling.”

as

Options:

Page: 1 / 13
Total 129 questions