CCAR-F Claude Code Configuration and Workflows Practice Question
A consultant is preparing a Claude Code setup for a client whose repository must never send secrets to the model. The consultant wants to block reads of `.env` files and any file under a `secrets/` directory at the tool level. Which configuration achieves this?
⚠ Common exam trap
The trap here is treating natural-language instructions or a made-up ignore file as a security boundary, when only explicit permission deny rules enforce what Claude Code is allowed to read.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add `Read(./.env)` and `Read(./secrets/**)` deny rules to the permissions block in `.claude/settings.json`.
Claude Code permission rules are evaluated by tool and path pattern, and deny rules take effect before the tool executes. Denying `Read` for `.env` and `secrets/**` in the project settings ensures the assistant cannot open those files even if a prompt asks for them, providing the tool-level enforcement the security requirement demands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set file permissions with `chmod 000` on `.env` and the `secrets/` directory so the assistant cannot open them.
Why it's wrong here
Removing filesystem permissions would break the developer's own tooling and build process, and it is a fragile control that depends on the account running Claude Code. It also does not express intent within Claude Code's configuration, so it is neither practical nor the appropriate mechanism for scoping tool access.
- ✗
Instruct the assistant in `CLAUDE.md` to never open `.env` files or anything inside `secrets/`.
Why it's wrong here
Natural-language instructions in a memory file influence behavior but are not an enforcement boundary. A determined prompt or an ambiguous request could still lead the assistant to read those files, so this approach fails the requirement for tool-level blocking that the client's security review would demand.
- ✗
List `.env` and `secrets/` in a `.claudeignore` file at the repository root so Claude Code skips them.
Why it's wrong here
Claude Code does not use a `.claudeignore` file; ignore-style behavior is expressed through permission rules or by relying on `.gitignore` awareness for search tools. Creating this file would give a false sense of protection because the assistant could still read the files when explicitly asked, leaving secrets exposed.
- ✓
Add `Read(./.env)` and `Read(./secrets/**)` deny rules to the permissions block in `.claude/settings.json`.
Why this is correct
The permissions block in Claude Code settings supports allow, ask, and deny rules keyed by tool and path pattern. Denying `Read` for `.env` and everything under `secrets/` prevents the assistant from reading those files at the tool layer, which is exactly the enforcement the client requires for secret protection.
About these practice questions
One of 271 original CCAR-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.