CCAR-F Claude Code Configuration and Workflows Practice Question
Which TWO of the following practices should be implemented to ensure Claude Code operates securely within a production-adjacent environment?
⚠ Common exam trap
Candidates frequently rely solely on system-level permissions or assume the model understands safety intuitively, failing to explicitly implement hard constraints like human-in-the-loop confirmation for destructive commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use custom instructions to explicitly forbid 'rm -rf' or database deletion commands.
Security in AI-assisted coding requires a defense-in-depth approach. By enforcing the principle of least privilege through custom instructions and strictly auditing shell execution commands, architects can mitigate risks associated with autonomous code generation. These practices protect against inadvertent destructive actions and ensure that the agent remains within defined operational boundaries, which is essential for maintaining the integrity of production-adjacent environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant Claude Code full sudo permissions to debug system-level issues.
Why it's wrong here
Granting sudo permissions to an AI agent is a critical security vulnerability. If the model is compromised or makes an error, it could execute destructive system commands or exfiltrate sensitive data. Agents should always operate with the minimum necessary permissions to perform their designated development tasks safely.
- ✓
Use custom instructions to explicitly forbid 'rm -rf' or database deletion commands.
Why this is correct
Custom instructions provide a safety layer by defining behavioral constraints for the agent. Explicitly forbidding dangerous commands prevents the model from attempting destructive operations during refactoring or cleanup tasks. This acts as a guardrail, significantly reducing the blast radius of potential mistakes or misinterpreted user intent.
- ✗
Enable 'auto-approve' for all shell command executions to speed up workflows.
Why it's wrong here
Auto-approval for shell commands removes the human-in-the-loop requirement, which is essential for security. Without manual verification of every command, an agent could inadvertently execute malicious or problematic code, leading to data loss or system instability, especially in environments that are close to production-level configurations.
- ✓
Require human confirmation for all terminal commands that modify the filesystem.
Why this is correct
Requiring human confirmation provides a crucial verification step before any permanent changes are made. This ensures that the developer understands and approves the agent's proposed actions, maintaining high standards of code quality and preventing unintended deletions or modifications to the codebase in critical development environments.
- ✗
Hardcode the Anthropic API key into the project's config file for convenience.
Why it's wrong here
Hardcoding API keys into configuration files is a major security risk, as these files are often committed to version control systems like Git. If the repository is leaked, the API key could be used by unauthorized parties, leading to potential financial loss and unauthorized access.
About these practice questions
This CCAR-F question is part of Courseiva's 271-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.