Anthropic Claude Certified Architect - Professional CCAR-P Exam Questions

Page: 1 / 14
Total 126 questions
Question 1

A Claude Architect is reviewing a post-deployment performance report for an AI-assisted legal-document summarization system. The report includes these observations:

Average summarization time decreased from 47 minutes to 6 minutes per document.

Associates spend less time on summaries, but overall billable output has not measurably changed.

Infrastructure costs increased by 22% because redundant retry logic generated additional API calls.

Some summaries require attorney correction, adding an average of 8 minutes of review per document.

Which analysis correctly attributes each observation to the appropriate business-value pillar?



Answer : D

Observation 1 is a direct efficiency improvement because the time required for one summarization task fell substantially. Observation 2 shows that local time savings have not yet translated into higher organizational productivity or billable output. Observation 3 is explicitly a solution-cost problem caused by unnecessary API calls. Observation 4 introduces additional human correction time and therefore partially offsets the gross efficiency gain reported in Observation 1. Option D is the only answer that keeps these value dimensions distinct. Measuring only generation speed would overstate realized value because review effort, retry costs, and downstream output must also be included. A valid post-deployment assessment should calculate net cycle time, cost per accepted summary, correction rate, and resulting business output.


Question 2

You are assessing a Claude-based system whose dominant risk is silent quality drift on safety-relevant outputs after a model-version upgrade.

Which assessment activity most directly addresses this risk?



Answer : D

A stable adversarial regression set provides a controlled basis for detecting behavioral change between model versions. Version-attributed results show whether the proposed upgrade improves, preserves, or degrades performance on the same safety-relevant cases. The evaluation must run before promotion so a regression can block deployment rather than becoming a production incident. Randomly replacing the test inputs removes comparability and makes score changes difficult to attribute. Disabling evaluation or relying on complaints converts a preventable release-control failure into reactive incident handling. Anthropic characterizes regression evaluations as tests of whether an agent still handles tasks it previously completed and recommends maintaining them continuously to detect backsliding. Demystifying evals for AI agents


Question 3

You are reviewing a peer's Claude Code permission rules for an enterprise rollout. The rules grant unrestricted Bash access to all projects across all developers.

Which response is most appropriate?



Answer : C

Unrestricted Bash access exposes filesystem, credential, process, network, package-management, and potentially infrastructure-administration capabilities across every repository. Option C applies least privilege by identifying the commands genuinely required by approved workflows and permitting only those patterns. Explicit deny rules should protect destructive commands, sensitive files, credential stores, deployment systems, and other prohibited operations.

Anthropic's permission system supports allow, ask, and deny rules, with deny evaluated before ask and allow. It also warns that command patterns intended to constrain network utilities can be fragile, so stronger controls such as WebFetch domain restrictions, hooks, and sandbox boundaries may be required. Claude Code Permissions

Enterprise configuration should combine managed baseline restrictions with project-specific permissions where necessary. High-impact commands should remain subject to confirmation, and sandboxing should provide operating-system-level filesystem and network containment.

Options A and D deliberately enlarge the attack surface. Option B treats configuration simplicity as more important than enterprise security and fails to account for prompt injection, accidental commands, compromised repositories, or excessive human approval. The configuration should be narrow, auditable, centrally governed, and validated against real development workflows.

Study Guide references/topics: Claude Code permissions; Bash restrictions; least privilege; managed controls; explicit deny rules; sandboxing; enterprise rollout security.

===============


Question 4

You are operating an interactive assistant whose dominant performance constraint is per-turn latency. Quality on routine turns is already acceptable.

Which configuration adjustment most directly improves latency without disproportionately damaging quality?



Answer : B

Option B targets two major contributors to per-turn latency: retrieved-context size and repeated prompt processing. Reducing retrieval to an empirically validated top-k limits the tokens Claude must process while preserving the passages that historically provide sufficient answer coverage. Caching the stable system-prompt prefix avoids repeatedly processing identical instructions.

Anthropic's latency guidance recommends choosing an appropriate model and reducing unnecessary input and output tokens. Its prompt-caching documentation explains that caching reusable prompt prefixes can reduce both repeated processing cost and latency. Reducing Latency, Prompt Caching

The retrieval depth must be selected through evaluation rather than arbitrary truncation. The team should compare answer quality, retrieval recall, latency, and failure rates across candidate values and retain escalation logic for complex queries requiring deeper retrieval.

Option A removes an applicable latency optimization. Option C maximizes context consumption regardless of demonstrated benefit. Option D deliberately selects the slowest model class even though routine-turn quality already meets requirements.

Study Guide references/topics: Latency optimization; top-k retrieval; prompt caching; token reduction; quality--latency evaluation; adaptive retrieval.

===============


Question 5

A Claude architect needs to ensure that a security-hardening flag cannot be disabled by any individual engineer after it is set.

Which configuration scope correctly enforces this requirement?



Answer : C

Managed configuration is designed for organization-wide security and compliance controls that individual users and repositories must not override. Applying the hardening flag centrally establishes an administrative policy boundary and prevents engineers from disabling the control through user, project, or local settings.

Anthropic identifies managed scope as the appropriate location for security policies, non-overridable compliance requirements, and standardized configurations deployed by IT or DevOps. Managed values ordinarily take precedence over command-line arguments and every user-controlled settings scope. Claude Code Settings

Option A depends on every engineer maintaining the setting and allows the user to edit or delete it. Option B affects only pipeline execution and does not protect local, interactive, IDE, or other execution paths. Option D standardizes the setting within the repository but does not make it tamper-resistant; contributors with repository write access could alter the file, use higher-precedence local settings where permitted, or operate outside the repository configuration.

The implementation should also verify active policy delivery, monitor configuration-change events, and test that startup or execution fails safely if the managed setting is absent or invalid. Central definition without enforcement and verification would not fully satisfy the requirement.

Study Guide references/topics: Managed settings; non-overridable controls; enterprise hardening; policy enforcement; configuration governance; defense against local override.

===============


Question 6

A Claude architect is designing a HIPAA-compliant pipeline that processes patient records.

Which two design decisions directly support HIPAA compliance requirements? (Select two.)



Answer : C, D

Role-based access control directly supports HIPAA's access-control and minimum-necessary principles. The retrieval and orchestration layers must verify the authenticated user's role before protected health information enters the model context. Authorization should be applied to individual records, data sources, tools, and actions, with audit events recording the requesting identity, accessed resource, purpose, and result. Model instructions alone are not a security boundary.

Patient information must also remain within services and processing activities covered by the organization's Business Associate Agreement. Anthropic states that PHI processing requires a HIPAA-ready organization and an accepted BAA, and that only specified eligible services and configurations are covered. Patient data must not be submitted through training, feedback, beta, third-party, or integration pathways that fall outside the applicable agreement. A BAA is not blanket authorization; architects must verify feature eligibility and disable inappropriate data-sharing mechanisms.

Reducing max_tokens, selecting a more capable model, and enabling streaming affect output length, quality, or latency. They do not establish authorization, contractual coverage, minimum-necessary access, or compliant PHI handling.

Study Guide references/topics: Anthropic Business Associate Agreement requirements; HIPAA-ready services; PHI access control; minimum necessary; eligible-service boundaries; auditability.

===============


Question 7

You are reviewing a customer-support agent's configuration. Each candidate tool falls into one of four categories: (1) required to complete defined tasks, (2) frequently used and reduces hand-offs, (3) occasionally useful for unrelated work, (4) speculative future utility.

Which categories should typically remain in the agent configuration?



Answer : C

Category 1 tools are necessary for the agent to complete its approved responsibilities and must remain. Category 2 tools are also justified when they are regularly used and eliminate predictable hand-offs without expanding the agent beyond its defined operating role.

Categories 3 and 4 create capability bloat. A tool that is occasionally useful only for unrelated work does not belong to this agent's responsibility boundary. A speculative tool has no validated requirement and adds attack surface, context consumption, authorization complexity, evaluation burden, and operational dependencies without demonstrated value.

Tool inclusion should be based on task traceability: every configured capability should map to a documented user journey, responsibility, permission scope, and evaluation case. Anthropic recommends least privilege so that a successful injection or model error can cause minimal damage. Mitigate Jailbreaks and Prompt Injections

The architect should periodically review tool-call telemetry and remove unused capabilities. New tools can be added when a validated workflow requires them, after security review and evaluation. The objective is not the smallest possible catalog regardless of usefulness; it is the smallest catalog that reliably completes the agent's approved tasks.

Study Guide references/topics: Capability-bloat analysis; tool necessity; hand-off reduction; least privilege; attack-surface management; tool lifecycle review.

===============


Page:    1 / 14   
Total 126 questions