CCAR-F Claude Code Configuration and Workflows Practice Question
A platform team wants Claude Code to be allowed to run only a specific set of safe Bash commands (for example, `npm test` and `git status`) without prompting, while still blocking arbitrary shell commands. They want this policy applied automatically to every developer who clones the repository. Where should they define this allowlist so it is version-controlled and enforced for the whole team?
⚠ Common exam trap
The trap here is conflating advisory model guidance in CLAUDE.md with enforceable permission rules, which must be declared in a structured settings file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In the project's .claude/settings.json file committed to the repository
Project-scoped settings live in .claude/settings.json inside the repository and are committed to version control, so every developer automatically inherits the same permission allowlist. User-scoped settings apply only locally, environment files are not parsed by Claude Code, and CLAUDE.md provides advisory context rather than enforceable permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
In a .env file at the repository root
Why it's wrong here
A .env file provides environment variables to processes that explicitly load them; Claude Code does not read .env files to determine permission allowlists. Using it here would neither enforce the policy nor be recognized by the CLI, leaving all Bash commands subject to normal prompting.
- ✗
In the user's ~/.claude/settings.json file
Why it's wrong here
The user-scoped settings file applies only to that individual's machine and is not version-controlled with the repository, so teammates cloning the repo would not inherit the allowlist. This location is appropriate for personal preferences, not for team-wide enforcement.
- ✗
In the CLAUDE.md file at the repository root
Why it's wrong here
CLAUDE.md carries natural-language guidance for the model but does not enforce hard permission rules. Claude Code's permission system requires structured configuration, so writing 'allow npm test' in CLAUDE.md would not reliably prevent prompting or block arbitrary shell commands.
- ✓
In the project's .claude/settings.json file committed to the repository
Why this is correct
The project-scoped .claude/settings.json is checked into version control and applies to everyone working in that repository, making it the correct place for a shared permission allowlist. Claude Code reads this file automatically, so the safe Bash commands are pre-approved for all developers without individual setup.
About these practice questions
This CCAR-F question is part of Courseiva's 271-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.