Anthropic · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
An organization is building an internal CLI tool that uses Anthropic's API. They want to improve developer productivity by implementing robust error handling and monitoring. Which TWO strategies should they implement? (Select TWO)
Implement exponential backoff logic for handling 429 and 5xx API responses.
Exponential backoff is a standard pattern for distributed systems to handle temporary overloads and rate limits. By waiting longer between retries, it reduces pressure on the API and increases the likelihood of a successful subsequent request. This prevents automated tasks from crashing when facing high traffic or transient congestion.
Store API keys as plain text in the CLI configuration file for ease of developer access.
Use structured logging to track token usage, response latency, and request IDs.
Structured logging provides the observability needed to optimize LLM performance and costs. By tracking metadata like token counts and latency, teams can identify bottlenecks and optimize prompts. This data is essential for effective capacity planning and monitoring the health of internal tools powered by Claude's API endpoints.
Set the maximum token limit to 4096 for all requests to ensure uniform response times.
Disable all request retries to ensure the CLI tool fails fast during network issues.
Your organization is scaling an internal library that wraps Anthropic API calls. To minimize the cognitive load on developers using this library, what is the most effective pattern to implement?
Require developers to write raw HTTP requests to the API in every microservice.
Bundle all API interaction logic into a shared, versioned SDK with built-in observability.
A centralized SDK provides a unified, well-tested interface for API consumption. By including observability, retries, and security defaults, it enables developers to integrate Claude quickly and reliably. This approach lowers the barrier to entry, ensures consistent performance, and simplifies maintenance as the organization's usage of the API grows.
Mandate that all developers use a specific GUI tool for prompt testing rather than code.
Provide only documentation on how to authenticate, leaving all implementation to teams.
Which THREE practices most effectively support a 'Prompt Engineering as Code' workflow for enterprise teams? (Select THREE)
Storing prompts in text files within the same repository as the application code.
Treating prompts as code assets allows for version control, branching, and pull-request-based reviews. This ensures that changes to prompts are tracked, auditable, and easily reversible. Keeping them in the repo ensures that the prompt version is always aligned with the application logic that consumes it at runtime.
Using hardcoded prompt strings in the production environment for maximum speed.
Implementing automated evaluation scripts to test prompt changes against a golden dataset.
Automated evaluations ensure that changes to prompts do not negatively affect existing performance. By testing against a golden dataset, developers can quantify the impact of their changes, preventing regressions. This provides the confidence required to ship updates frequently and reliably in a production environment.
Mandating manual review for every single request made by the production model.
Establishing a peer review process for all changes to prompt templates.
Peer review ensures that prompts are clear, follow organizational guidelines, and are optimized for the specific task at hand. Just like code reviews, this process catches errors, security risks, or inefficiencies early, improving the quality of the final output and fostering knowledge sharing among the team members.
An organization wants to allow non-technical business users to test Claude prompts without exposing them to raw API code. What is the most productive approach to empower these users?
Give every user their own API key and a Python IDE to write scripts.
Create a secure web-based UI that allows users to test prompts against specific model versions.
A web-based UI provides a safe, intuitive environment for users to experiment without needing code. It allows them to see model responses in real-time, facilitating faster iteration. Centralizing this via a UI also allows the organization to monitor usage, manage costs, and enforce security policies at the entry point.
Require all prompt suggestions to be submitted via a ticket system for developers to code.
Provide access to the public Anthropic Console directly for all business users.
When evaluating the performance of Claude for a new feature, which metric is most useful for understanding the impact on end-user experience?
Total number of API calls made per month.
Time to First Token (TTFT).
TTFT directly correlates with the user's perception of application speed. When users interact with a chat interface, waiting for the first word to appear is the most impactful moment. Minimizing this time significantly improves the user experience, making the application feel much more responsive and interactive.
The total number of tokens generated per response.
The memory usage of the server hosting the API client.
To ensure long-term maintainability and performance of LLM-based applications, which THREE architectural patterns should architects recommend? (Select THREE)
Decouple prompt management and model selection from core application logic.
Separating these layers allows developers to swap models or update prompts without deploying new application code. This modularity is essential for long-term maintainability, as it enables the team to adapt to new model releases or optimization requirements without the risk of breaking existing functionality.
Cache frequent identical API requests at the application level.
Caching significantly reduces costs and latency for repetitive inputs. For many applications, users ask similar questions or the system processes common data patterns. By serving cached results, you avoid unnecessary API calls, save money, and provide an instantaneous experience to users who are requesting known information.
Hardcode system prompts to ensure the model behavior cannot change over time.
Implement continuous monitoring of token usage, costs, and latency.
Monitoring is the only way to ensure that performance and costs remain within acceptable bounds. It provides alerts when latency spikes or costs trend upward, allowing the team to investigate before a minor problem becomes a critical failure or a massive budget overrun in production.
Use the largest available context window for every single request to maximize intelligence.
Want more Developer Productivity and Operational Enablement practice?
Practice this domainWhat is the primary benefit of using a 'System Prompt' to define an agent's persona and constraints compared to embedding these in the user message?
System prompts are cached globally, reducing latency to zero.
User messages can be easily ignored, while system prompts cannot.
It establishes a distinct boundary between the agent's identity and user intent.
Separating identity and constraints from user inputs creates a robust architecture. This ensures that the agent's core instructions remain constant regardless of the user's conversational turns. This separation is fundamental to maintaining agent integrity and prevents users from coercing the agent into behaviors that violate defined policies.
It is the only way to enable tool-use capabilities.
When implementing a 'Human-in-the-loop' (HITL) checkpoint, what is the best way to handle the state persistence during the wait period?
Keep the connection open to avoid re-initializing the agent.
Persist the state in an external database and terminate the process.
Externalizing the state allows for scalability and durability. By saving the session context in a database, the system can remain idle without consuming compute resources. Once the human provides input, the system can reload the state, reconstructing the agent's context to resume the task seamlessly and reliably.
Store the state only in the client-side browser memory.
Retry the tool call periodically until the human responds.
An agentic system is struggling with 'context fragmentation' over long-running sessions. What is the most effective architectural solution?
Increase the context window size of the model indefinitely.
Implement a hierarchical memory system with summarization.
Hierarchical memory allows the agent to access both recent, detailed context and summarized long-term history. By managing memory at different levels of abstraction, you keep the agent's prompts concise and relevant, significantly improving its performance and goal-tracking accuracy over sessions that span hours or days.
Force the user to clear their history periodically.
Only use the most recent 10 messages of the history.
When designing an agent capable of multi-step tool use, what is the most important property to maintain across steps?
The exact same temperature parameter for every step.
The model's internal memory of its own personality.
Synchronization between the agent's world model and the environment.
The 'world model' is the agent's mental map of the current environment state. If this map deviates from reality, the agent will choose incorrect tools or pass wrong arguments. Maintaining strict synchronization ensures that the agent's next action is always based on the most accurate, real-world data available.
Using the same model provider for every single step.
Which architectural approach is best for handling an agent's failure to retrieve information from a database tool?
Simply return the raw error message to the end user.
Configure the agent to automatically retry the exact same query 5 times.
Provide the error back to the agent as a new observation for re-planning.
Treating an error as an observation is a key principle of agentic architecture. By letting the agent 'see' what went wrong, it can apply its reasoning to correct the error, such as by broadening a query scope or sanitizing an input, leading to much higher success rates.
Default to a hard-coded fallback value to satisfy the user.
When designing an agent that must perform highly sensitive operations (e.g., deleting records), what architectural pattern is mandatory?
Fine-tune the model to never delete records.
Implement a mandatory human-in-the-loop confirmation step.
The HITL pattern forces an external, verifiable authorization layer into the workflow. This ensures that no destructive or sensitive action can proceed without an explicit, audit-trailed human approval, which is the gold standard for secure agentic systems dealing with sensitive backend operations and data integrity.
Use a low-temperature setting for sensitive tool calls.
Log the action to a secure bucket after execution.
Want more Advanced Agentic Architecture practice?
Practice this domainA global financial institution must ensure that all prompt data and model responses for their Claude 3.5 Sonnet implementation remain within the European Union to comply with strict GDPR data residency requirements. Which architecture strategy best fulfills this governance mandate?
Utilize regional endpoints in AWS Bedrock or GCP Vertex AI located in EU regions.
Regional endpoints in cloud provider environments guarantee that both the inference traffic and the underlying model compute operations are physically restricted to the selected geography. This architecture prevents cross-border data transfers, directly satisfying legal requirements for data sovereignty and internal compliance protocols for handling European citizen data.
Enable cross-region inference to ensure high availability across global data centers.
Configure the standard Anthropic Console with an EU-based billing address.
Implement client-side encryption for all prompts using AWS KMS keys.
An architect is defining the Shared Responsibility Model for a company deploying Claude via the Messages API. Which THREE tasks are the sole responsibility of the customer (the 'User') rather than Anthropic?
Classification and sanitization of PII within input prompts.
Customers are responsible for identifying and managing the sensitivity of the data they send to the model. Anthropic does not automatically know which data points constitute PII for a specific business context, so the customer must implement their own redaction or classification logic before calling the Messages API.
Physical security of the data centers housing the TPU/GPU clusters.
Fine-tuning the base model's Constitutional AI principles.
Implementing Identity and Access Management (IAM) for API key usage.
The customer is responsible for ensuring that API keys are stored securely and that only authorized applications or developers can access the Claude endpoints. Failure to manage IAM properly can lead to unauthorized usage, data leaks, and unexpected costs, all of which fall under the customer's operational domain.
Monitoring model outputs for internal policy compliance and accuracy.
While Claude has built-in safety filters, the customer must verify that the model's responses align with their specific industry regulations and internal brand guidelines. This includes setting up human-in-the-loop reviews or automated evaluation pipelines to catch hallucinations or policy violations that are specific to the enterprise.
Refer to the exhibit. An architect reviews this API request log. Despite the 'Ignore all previous safety instructions' directive, Claude refuses to provide instructions for bypassing the firewall. Which safety mechanism is primarily responsible for this refusal?
The external Python-based regex filter applied to the API output.
Constitutional AI (CAI) and RLHF during the model's training phase.
Constitutional AI uses a set of written principles to guide the model's behavior during training, teaching it to prioritize safety and helpfulness over following harmful user instructions. This makes the safety guardrails an intrinsic part of the model's reasoning rather than a superficial filter applied to the input.
The 'max_tokens' parameter being set to a value low enough to truncate the response.
A hardcoded list of forbidden words in the Anthropic Messages API gateway.
A security architect is configuring the Anthropic Console for a large enterprise. Which TWO features should be implemented to enforce centralized governance and reduce the risk of unauthorized account access?
Single Sign-On (SSO) integration via SAML 2.0.
SSO allows the enterprise to manage Anthropic access through their existing identity provider, such as Okta or Microsoft Entra ID. This ensures that when an employee leaves the company, their access to the Anthropic environment is automatically revoked, significantly reducing the risk of orphaned accounts and unauthorized access.
Automatic rotation of all API keys every 24 hours.
Role-Based Access Control (RBAC) to limit 'Admin' permissions.
RBAC allows organizations to assign specific roles like 'Member' or 'Admin' to different users. By following the principle of least privilege, an architect can ensure that only a small number of trusted users can modify billing settings or create new workspaces, while developers are limited to API usage.
Real-time packet inspection of all API traffic.
Hardware Security Module (HSM) storage for all model weights.
An organization is deploying Claude to provide automated coding assistance. To manage the risk of generating insecure code or violating open-source licenses, which governance step is most effective?
Disabling the model's ability to output code blocks entirely.
Implementing a mandatory 'Human-in-the-Loop' review and automated SAST scanning.
Static Application Security Testing (SAST) tools can automatically detect vulnerabilities in the code Claude generates. Combined with human review, this ensures that any AI-driven suggestions are vetted for security flaws and license compliance before being merged into the production codebase, providing a robust governance layer.
Relying on Claude's internal safety training to prevent all insecure code generation.
Requiring all developers to use Claude only for writing documentation, not logic.
When conducting a risk assessment for a new Claude-based customer support bot, which TWO factors should be prioritized as 'High Risk' according to Anthropic's safety guidelines?
Providing automated, unreviewed medical or legal advice.
Medical and legal domains are considered high-risk because incorrect information can lead to severe personal harm or legal liability. Anthropic's safety guidelines emphasize that AI should not replace professional judgment in these areas without significant human-in-the-loop oversight and clear disclaimers to the end-user.
Generating personalized marketing copy for a retail website.
Summarizing publicly available news articles for internal research.
Automated processing of loan applications without human review.
Automated financial decision-making can lead to systemic bias and unfair outcomes, which are major governance concerns. Such systems must be carefully audited for fairness and transparency, and typically require a human to make the final determination to comply with financial regulations and ethical standards.
Translating internal training manuals into multiple languages.
Want more Governance, Safety, and Risk Management practice?
Practice this domainA project manager is overseeing a multi-phase implementation of Claude-based automated workflows. During the transition to production, the CISO expresses concerns regarding data privacy. Which strategy best addresses the stakeholder’s requirements while maintaining project momentum?
Present the technical documentation of the Claude model architecture to demonstrate overall robustness.
Delay the deployment until the CISO completes an independent audit of the third-party infrastructure.
Initiate a collaborative risk assessment focusing on data residency, encryption, and API access controls.
Collaborative risk assessment directly aligns with the CISO's mandate to ensure security and compliance. By focusing on tangible controls like residency and encryption, you provide concrete evidence that the system complies with organizational standards, which facilitates an informed decision-making process and fosters institutional confidence in the project.
Ask the legal department to provide a formal exemption for the project to bypass standard security reviews.
Refer to the exhibit. An audit team identifies that the system message lacks specific data handling instructions for sensitive reports. As the architect, what is the best approach to communicate this to the development team?
Directly update the production configuration files without consulting the developers to expedite the fix.
Schedule a review meeting to explain the requirement for a system message that enforces data classification.
A review meeting facilitates shared understanding of the security risk and the proposed technical solution. This collaborative approach allows developers to ask questions and ensures the guardrails are integrated correctly into the application code, which is vital for maintaining consistent policy enforcement across the entire AI service lifecycle.
Send an email suggesting that they use a different model that has built-in data filtering.
Ignore the finding since the model is generally helpful and unlikely to leak information.
During a project post-mortem, stakeholders feel that the technical limitations of the LLM were not clearly explained during the planning phase. What action would have best mitigated this perception?
Provide stakeholders with the full technical whitepaper of the model's training data.
Conduct an expectation-setting workshop demonstrating both model strengths and known limitations.
An interactive workshop allows stakeholders to see the model in action, creating a balanced understanding of its capabilities and constraints. This direct experience helps stakeholders frame their expectations appropriately, ensuring they understand the necessity of human-in-the-loop workflows and other safeguards required for a production-ready system.
Include a disclaimer in the final project report acknowledging the potential for errors.
Ask the AI engineers to write a memo outlining the model's performance metrics.
An enterprise client is concerned about the 'black box' nature of LLMs. Which THREE communication strategies should the architect use to build transparency and trust?
Present the results of red-teaming exercises to show how vulnerabilities are identified and patched.
Sharing red-teaming results demonstrates a proactive security posture and a commitment to rigorous testing. It helps stakeholders understand that the organization is actively looking for flaws and improving the system's resilience, which builds significant confidence in the robustness of the chosen AI solution for sensitive business applications.
Explain the use of citations and grounding techniques to reduce hallucination risks.
Grounding and citations provide verifiable evidence that the model's outputs are tied to authoritative sources. This is a powerful mechanism for increasing stakeholder trust, as it provides a clear path for verification and reduces the perception of the model as an unreliable 'black box' that generates information out of thin air.
Promise stakeholders that the model will have a 100% accuracy rate for all inputs.
Detail the human-in-the-loop (HITL) workflows used to validate critical AI-generated outputs.
HITL workflows provide a safety net that assures stakeholders that AI-generated decisions undergo human oversight before impacting operations. This visibility into the decision-making process reassures stakeholders that the AI is acting as a decision-support tool rather than an autonomous actor, which is crucial for high-stakes business process deployment.
Avoid mentioning technical constraints to keep the stakeholder focused on the positive benefits.
Your organization is transitioning from a pilot project to an enterprise-wide deployment of Claude. A key stakeholder is worried about the impact on current staff roles. How should you frame the communication to address this?
State that the AI is faster and more efficient, so fewer staff will be required in the future.
Emphasize how the AI automates mundane tasks, allowing staff to focus on complex, creative work.
Highlighting augmentation is a constructive communication strategy that aligns the AI's capabilities with employee career development. It positions the technology as a partner in success, which helps reduce anxiety and encourages staff to participate in training and adoption efforts, ultimately leading to a more successful and sustainable implementation.
Keep the discussion purely technical and avoid mentioning any impact on existing staff roles.
Offer bonuses to staff who agree to use the new AI tools in their daily workflows.
You are presenting a quarterly progress report to executive sponsors. Which information should be highlighted to ensure continued project funding and sponsorship?
Detailed logs of all API latency issues and the specific network configurations used to solve them.
The number of lines of code written by the developers during the last quarter.
Key performance indicators showing cost savings and alignment with strategic business goals.
KPIs that demonstrate clear ROI and alignment with business strategy are the standard for executive reporting. These metrics provide the justification for continued investment, showing how the project contributes to the organization's bottom line and competitive advantage, which is essential for maintaining sponsorship in a budget-constrained environment.
A list of all the personal opinions of the development team regarding the Claude model.
Want more Stakeholder Communication and Lifecycle Management practice?
Practice this domainThe CCAR-P exam has 60–90 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 4 domains: Developer Productivity and Operational Enablement, Advanced Agentic Architecture, Governance, Safety, and Risk Management, Stakeholder Communication and Lifecycle Management. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Anthropic CCAR-P exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.