Courseiva

CCAR-F Claude Code Configuration and Workflows Practice Question

A team is configuring Claude Code for a new project. They want to enforce specific tool permissions to prevent Claude Code from executing potentially dangerous shell commands without approval. Which two configuration approaches should they use? (Choose two.)

⚠ Common exam trap

Test-takers frequently confuse file exclusion mechanisms like .claudeignore with tool permission controls, or assuming interactive commands persist across sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define allowed and disallowed tools in the project's .claude/settings.json file.

Tool permissions in Claude Code are configured via settings.json files, either at the project level (.claude/settings.json) or user level (~/.claude/settings.json). Project settings allow team-wide enforcement and can be version-controlled. Global settings provide a fallback but are user-specific. Together, they can restrict tools like shell execution. Interactive commands and environment variables are not persistent configuration methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Define allowed and disallowed tools in the project's .claude/settings.json file.

    Why this is correct

    The .claude/settings.json file in a project can specify tool permissions, including which tools are allowed or disallowed. By configuring this file, the team can restrict Claude Code from using certain tools, such as shell execution, without approval. This is a project-scoped, version-controlled method to enforce permissions consistently.

  • ✗

    Add a .claudeignore file listing tools to exclude.

    Why it's wrong here

    The .claudeignore file is used to exclude files and directories from Claude Code's context, not to control tool permissions. It cannot restrict shell command execution. Therefore, this approach does not address the requirement of enforcing tool permissions to prevent dangerous commands.

  • ✓

    Configure tool permissions in the user's global ~/.claude/settings.json file.

    Why this is correct

    The global ~/.claude/settings.json file can also define tool permissions. While it applies to all projects for that user, it can be used in conjunction with project settings. In this scenario, using both project and global settings ensures that permissions are enforced, though project settings take precedence. Thus, it is a valid approach to enforce restrictions.

  • ✗

    Set the CLAUDE_TOOL_POLICY environment variable to 'restricted'.

    Why it's wrong here

    Claude Code does not recognize a CLAUDE_TOOL_POLICY environment variable. Tool permissions are configured through settings files, not environment variables. Using this would have no effect, and the team would not achieve the desired restriction on shell commands.

  • ✗

    Use the /permissions command during a session to interactively adjust tool access.

    Why it's wrong here

    The /permissions command allows interactive adjustment of permissions during a session, but it is not a persistent configuration method. Changes made this way are not automatically applied to future sessions or shared with the team. Therefore, it does not meet the requirement for enforcing permissions across the project.

About these practice questions

One of 271 original CCAR-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.