CCAR-F Claude Code Configuration and Workflows Practice Question
An architect is standardizing Claude Code usage across a large engineering organization. They want to ensure that every developer's sessions automatically inherit a curated set of project conventions and that destructive shell commands are blocked unless explicitly approved. Which TWO configurations should the architect implement? (Choose two.)
⚠ Common exam trap
The trap here is assuming documentation in a README or manual per-developer configuration provides the same automatic, enforceable coverage as committed project memory plus structured permission rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Commit a CLAUDE.md file at the repository root containing the shared coding conventions and architectural notes
A committed CLAUDE.md at the repository root distributes shared conventions automatically to every session, and deny rules in the project's .claude/settings.json enforce hard blocks on destructive commands organization-wide. Manual per-developer setup and README-based expectations lack reliability and auditability, while blanket Bash auto-approval undermines the safety objective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Instruct each developer to run /config and manually set the desired conventions on first launch
Why it's wrong here
Relying on each developer to configure conventions manually is error-prone and inconsistent, and /config manages local runtime preferences rather than embedding durable project knowledge. It does not scale across a large organization and leaves no auditable, version-controlled source of truth.
- ✗
Enable auto-approval for all Bash commands to reduce interruptions during long sessions
Why it's wrong here
Auto-approving all Bash commands removes the safety boundary the architect is trying to establish and directly contradicts the goal of blocking destructive operations. It increases risk rather than enforcing a curated, reviewable permission policy across the organization.
- ✓
Commit a CLAUDE.md file at the repository root containing the shared coding conventions and architectural notes
Why this is correct
A committed CLAUDE.md at the repository root is read automatically by Claude Code at session start for every developer who clones the repo, delivering shared conventions without individual setup. It is the documented project memory mechanism and the correct vehicle for durable, team-wide natural-language guidance.
- ✗
Place convention notes in a README.md and expect Claude to infer them from repository files
Why it's wrong here
README.md is not automatically loaded as project memory, so Claude would only see it if it happened to read the file during a task. Conventions placed there are not guaranteed to influence behavior, making this an unreliable substitute for a committed CLAUDE.md.
- ✓
Add deny rules for destructive commands such as rm -rf to the project's .claude/settings.json permissions block
Why this is correct
Project-scoped settings in .claude/settings.json are version-controlled and merged for every session in the repository. Placing deny rules there blocks destructive commands organization-wide and, because deny rules outrank allow rules, prevents a developer's personal allow entry from silently re-enabling them.
About these practice questions
Courseiva writes every CCAR-F question from scratch — 271 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.