CCAR-F Agentic Architecture and Orchestration Practice Question
A team wants Claude to call an internal `create_invoice` tool only after the user has explicitly approved the line items. Which mechanism should the architect use to enforce this gate?
⚠ Common exam trap
The trap here is believing a strong system-prompt instruction is sufficient to prevent an unauthorized tool call, when the reliable control is removing the tool from the request.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Withhold the `create_invoice` tool definition from the request until the orchestrator records explicit user approval, then include it in a subsequent turn.
Enforce business-critical gates in the orchestrator, not in prompts. If the create_invoice tool is absent from the request, the model cannot emit a tool_use for it. Once the host records explicit approval, the tool definition is added and the conversation continues, giving the architect deterministic control over a sensitive side effect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Withhold the `create_invoice` tool definition from the request until the orchestrator records explicit user approval, then include it in a subsequent turn.
Why this is correct
Tools that are not in the request cannot be called. By gating the tool definition behind an approval flag in the host application, the architect enforces the policy structurally rather than relying on model compliance. After consent, the tool becomes available and Claude can proceed normally within the same conversation.
- ✗
Use a system prompt instructing Claude to always ask for confirmation before calling `create_invoice`.
Why it's wrong here
Prompt instructions influence but do not guarantee behavior; a sufficiently persuasive user turn can still trigger the tool. For a financially sensitive action, policy must live in code, not in a prompt. The orchestrator should withhold the tool definition or reject the tool_use until an explicit approval flag is set.
- ✗
Set `tool_choice` to force a specific tool so Claude cannot pick anything else.
Why it's wrong here
Forcing a tool removes the model's flexibility and would make the agent call create_invoice deterministically, which is the opposite of requiring human approval. Forced tool_choice is useful when you need one specific call, not when you need a policy gate that depends on an external human decision.
- ✗
Set `tool_choice` to `auto` so Claude decides when to call `create_invoice`.
Why it's wrong here
`auto` lets the model choose whether and when to invoke any available tool, which is exactly the opposite of a hard approval gate. The model could call create_invoice before the user confirms. To enforce human approval, the tool must not be exposed to the model until after consent, or the orchestrator must intercept and hold the call.
About these practice questions
This CCAR-F question is part of Courseiva's 271-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.