Courseiva

CCAR-F Claude Code Configuration and Workflows Practice Question

A platform team wants Claude Code to be allowed to run only a specific set of safe Bash commands (for example, `npm test` and `git status`) without prompting, while still blocking arbitrary shell commands. They want this policy applied automatically to every developer who clones the repository. Where should they define this allowlist so it is version-controlled and enforced for the whole team?

⚠ Common exam trap

The trap here is conflating advisory model guidance in CLAUDE.md with enforceable permission rules, which must be declared in a structured settings file.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the project's .claude/settings.json file committed to the repository

Project-scoped settings live in .claude/settings.json inside the repository and are committed to version control, so every developer automatically inherits the same permission allowlist. User-scoped settings apply only locally, environment files are not parsed by Claude Code, and CLAUDE.md provides advisory context rather than enforceable permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    In a .env file at the repository root

    Why it's wrong here

    A .env file provides environment variables to processes that explicitly load them; Claude Code does not read .env files to determine permission allowlists. Using it here would neither enforce the policy nor be recognized by the CLI, leaving all Bash commands subject to normal prompting.

  • ✗

    In the user's ~/.claude/settings.json file

    Why it's wrong here

    The user-scoped settings file applies only to that individual's machine and is not version-controlled with the repository, so teammates cloning the repo would not inherit the allowlist. This location is appropriate for personal preferences, not for team-wide enforcement.

  • ✗

    In the CLAUDE.md file at the repository root

    Why it's wrong here

    CLAUDE.md carries natural-language guidance for the model but does not enforce hard permission rules. Claude Code's permission system requires structured configuration, so writing 'allow npm test' in CLAUDE.md would not reliably prevent prompting or block arbitrary shell commands.

  • ✓

    In the project's .claude/settings.json file committed to the repository

    Why this is correct

    The project-scoped .claude/settings.json is checked into version control and applies to everyone working in that repository, making it the correct place for a shared permission allowlist. Claude Code reads this file automatically, so the safe Bash commands are pre-approved for all developers without individual setup.

About these practice questions

This CCAR-F question is part of Courseiva's 271-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.