Courseiva

CCAR-F Claude Code Configuration and Workflows Practice Question

An architect is standardizing Claude Code usage across a large engineering organization. They want to ensure that every developer's sessions automatically inherit a curated set of project conventions and that destructive shell commands are blocked unless explicitly approved. Which TWO configurations should the architect implement? (Choose two.)

⚠ Common exam trap

The trap here is assuming documentation in a README or manual per-developer configuration provides the same automatic, enforceable coverage as committed project memory plus structured permission rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Commit a CLAUDE.md file at the repository root containing the shared coding conventions and architectural notes

A committed CLAUDE.md at the repository root distributes shared conventions automatically to every session, and deny rules in the project's .claude/settings.json enforce hard blocks on destructive commands organization-wide. Manual per-developer setup and README-based expectations lack reliability and auditability, while blanket Bash auto-approval undermines the safety objective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Instruct each developer to run /config and manually set the desired conventions on first launch

    Why it's wrong here

    Relying on each developer to configure conventions manually is error-prone and inconsistent, and /config manages local runtime preferences rather than embedding durable project knowledge. It does not scale across a large organization and leaves no auditable, version-controlled source of truth.

  • ✗

    Enable auto-approval for all Bash commands to reduce interruptions during long sessions

    Why it's wrong here

    Auto-approving all Bash commands removes the safety boundary the architect is trying to establish and directly contradicts the goal of blocking destructive operations. It increases risk rather than enforcing a curated, reviewable permission policy across the organization.

  • ✓

    Commit a CLAUDE.md file at the repository root containing the shared coding conventions and architectural notes

    Why this is correct

    A committed CLAUDE.md at the repository root is read automatically by Claude Code at session start for every developer who clones the repo, delivering shared conventions without individual setup. It is the documented project memory mechanism and the correct vehicle for durable, team-wide natural-language guidance.

  • ✗

    Place convention notes in a README.md and expect Claude to infer them from repository files

    Why it's wrong here

    README.md is not automatically loaded as project memory, so Claude would only see it if it happened to read the file during a task. Conventions placed there are not guaranteed to influence behavior, making this an unreliable substitute for a committed CLAUDE.md.

  • ✓

    Add deny rules for destructive commands such as rm -rf to the project's .claude/settings.json permissions block

    Why this is correct

    Project-scoped settings in .claude/settings.json are version-controlled and merged for every session in the repository. Placing deny rules there blocks destructive commands organization-wide and, because deny rules outrank allow rules, prevents a developer's personal allow entry from silently re-enabling them.

About these practice questions

Courseiva writes every CCAR-F question from scratch — 271 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.