CCAR-F Claude Code Configuration and Workflows Practice Question
A team is configuring Claude Code for a new project. They want to enforce specific tool permissions to prevent Claude Code from executing potentially dangerous shell commands without approval. Which two configuration approaches should they use? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse file exclusion mechanisms like .claudeignore with tool permission controls, or assuming interactive commands persist across sessions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define allowed and disallowed tools in the project's .claude/settings.json file.
Tool permissions in Claude Code are configured via settings.json files, either at the project level (.claude/settings.json) or user level (~/.claude/settings.json). Project settings allow team-wide enforcement and can be version-controlled. Global settings provide a fallback but are user-specific. Together, they can restrict tools like shell execution. Interactive commands and environment variables are not persistent configuration methods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Define allowed and disallowed tools in the project's .claude/settings.json file.
Why this is correct
The .claude/settings.json file in a project can specify tool permissions, including which tools are allowed or disallowed. By configuring this file, the team can restrict Claude Code from using certain tools, such as shell execution, without approval. This is a project-scoped, version-controlled method to enforce permissions consistently.
- ✗
Add a .claudeignore file listing tools to exclude.
Why it's wrong here
The .claudeignore file is used to exclude files and directories from Claude Code's context, not to control tool permissions. It cannot restrict shell command execution. Therefore, this approach does not address the requirement of enforcing tool permissions to prevent dangerous commands.
- ✓
Configure tool permissions in the user's global ~/.claude/settings.json file.
Why this is correct
The global ~/.claude/settings.json file can also define tool permissions. While it applies to all projects for that user, it can be used in conjunction with project settings. In this scenario, using both project and global settings ensures that permissions are enforced, though project settings take precedence. Thus, it is a valid approach to enforce restrictions.
- ✗
Set the CLAUDE_TOOL_POLICY environment variable to 'restricted'.
Why it's wrong here
Claude Code does not recognize a CLAUDE_TOOL_POLICY environment variable. Tool permissions are configured through settings files, not environment variables. Using this would have no effect, and the team would not achieve the desired restriction on shell commands.
- ✗
Use the /permissions command during a session to interactively adjust tool access.
Why it's wrong here
The /permissions command allows interactive adjustment of permissions during a session, but it is not a persistent configuration method. Changes made this way are not automatically applied to future sessions or shared with the team. Therefore, it does not meet the requirement for enforcing permissions across the project.
About these practice questions
One of 271 original CCAR-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.