Courseiva

Claude Certified Architect - Professional (CCAR-P) — Questions 151–225

262 questions total · 4pages · All types, answers revealed

Page 2

Page 3 of 4

Page 4
151
MCQmedium

When designing an agent capable of multi-step tool use, what is the most important property to maintain across steps?

A.The exact same temperature parameter for every step.
B.The model's internal memory of its own personality.
C.Synchronization between the agent's world model and the environment.
D.Using the same model provider for every single step.
AnswerC

The 'world model' is the agent's mental map of the current environment state. If this map deviates from reality, the agent will choose incorrect tools or pass wrong arguments. Maintaining strict synchronization ensures that the agent's next action is always based on the most accurate, real-world data available.

Why this answer

Ensuring state consistency is the most important property. Each tool call changes the environment, and the agent must understand the new state to plan the next step. If the state becomes inconsistent—e.g., the agent thinks a file was deleted but it wasn't—the agent's plan will fail.

Architecting for state observability ensures that the model always has an accurate 'world model' to work from.

Exam trap

Candidates often assume that simply tracking tool execution logs is sufficient, failing to realize that discrepancies between the agent's internal assumptions and the actual remote environment cause silent multi-step execution failures.

152
MCQeasy

A software vendor is preparing for a customer security review of its Claude-powered support assistant. The customer asks how the vendor prevents the assistant from leaking one tenant's data into another tenant's conversation. Which architectural control most directly addresses this concern?

A.Add a system prompt instructing the assistant to answer only questions about the current customer.
B.Scope every retrieval query and every stored conversation to the authenticated tenant identifier, and reject requests whose tenant scope cannot be resolved.
C.Set the assistant's temperature to zero to make responses more predictable across tenants.
D.Enable Claude's extended thinking so the assistant reasons more carefully before answering.
AnswerB

Enforcing tenant scope at the data access layer ensures that only the authenticated tenant's documents can enter the context window, regardless of what the model is asked. Failing closed when scope cannot be resolved removes the ambiguous cases that typically cause leaks. Because the boundary is enforced in code the model cannot influence, it answers the customer's concern about isolation directly.

Why this answer

Cross-tenant leakage is prevented at the point where data is selected, not at the point where text is generated. Binding every retrieval and storage operation to the authenticated tenant identifier, and failing closed when that identifier is missing, guarantees that only authorized content can reach the model. Prompt instructions, extended thinking, and temperature settings alter model behavior but leave the underlying data access path unchanged.

Exam trap

The trap here is answering a data-isolation question with a model-behavior setting, when isolation is enforced by the retrieval and storage layer rather than by how the model is prompted or sampled.

153
MCQmedium

During a project milestone review, a stakeholder asks why the Anthropic model output occasionally varies. How do you explain this in a way that manages expectations?

A.State it is a bug and that a patch will be deployed.
B.Explain that LLMs use probabilistic sampling, which creates variance.
C.Suggest setting the temperature to 0 for all future requests.
D.Ignore the concern as it is common knowledge in AI.
AnswerB

Providing a technical explanation of how sampling parameters influence output helps stakeholders understand the underlying logic. It shifts the discussion from 'broken vs. working' to 'tuning for desired outcomes.' This transparency builds confidence and allows stakeholders to participate in defining the desired balance between creativity and consistency.

Why this answer

Explaining the concept of 'temperature' and probabilistic nature of LLMs is essential to manage expectations. By framing variation as a feature that allows for creative and diverse responses, the architect aligns the stakeholder with the technology's strengths. This is crucial for avoiding frustration when stakeholders expect deterministic software-like behavior from generative AI models, which can lead to misaligned quality assessments.

Exam trap

Candidates often suggest trying to eliminate output variance entirely by forcing zero temperature, failing to explain the fundamental probabilistic nature of LLMs to stakeholders.

154
MCQeasy

A government agency wants assurance that its Claude deployment will not be used to generate content that violates Anthropic's usage policies. Which action most directly supports ongoing policy compliance?

A.Disable all safety filters so the agency retains maximum control over what the model is allowed to output.
B.Review Anthropic's usage policies and configure the deployment so its use cases fall within permitted categories, documenting that mapping for internal review.
C.Route all requests through a third-party gateway that anonymizes the agency's identity from Anthropic.
D.Purchase the highest available usage tier so the agency's traffic is treated as a trusted enterprise workload.
AnswerB

This is correct because compliance starts with understanding the provider's usage policies and deliberately aligning the deployment's use cases to permitted categories. Documenting that mapping creates an auditable statement of intent and gives reviewers a concrete basis to confirm the agency is not operating in a prohibited area, which is the most direct and durable way to support ongoing policy compliance.

Why this answer

Policy compliance is achieved by understanding the provider's acceptable use categories, deliberately designing the deployment to stay within them, and documenting that alignment so it can be reviewed. Configuration changes, spending tier, and identity obfuscation do not alter the obligation to use the service within policy and provide no evidence of alignment.

Exam trap

The trap here is assuming that a higher commercial tier, or hiding traffic behind a gateway, grants exemption from the provider's usage policies.

155
MCQmedium

An organization wants to enforce consistent prompt engineering standards across teams. They have a large library of prompts and need to ensure that developers use approved versions while maintaining audit trails of prompt usage. What is the most effective approach?

A.Require developers to manually copy-paste prompt templates into a shared documentation Wiki.
B.Implement a custom middleware layer that encrypts all prompt traffic at the network edge.
C.Deploy a central prompt management service that provides versioned API endpoints for prompt retrieval.
D.Enforce strict hardcoding of all prompts within the application source code with mandatory PR reviews.
AnswerC

A central registry enables immutable versioning and structured metadata, allowing developers to fetch vetted prompts via API. This creates a single source of truth that simplifies auditing and testing. It allows prompt engineers to update prompts centrally without requiring developers to redeploy their application code frequently.

Why this answer

Using a centralized Prompt Registry allows teams to version-control, audit, and distribute approved prompt templates. This ensures governance without hindering developer velocity, as teams can reference specific versions through API calls rather than hardcoding prompts. Establishing a registry mitigates risks associated with prompt injection and inconsistent model behavior across different product features, effectively bridging the gap between security compliance and rapid software iteration.

Exam trap

Candidates often suggest hardcoding prompts in application code or using simple version control systems like Git, failing to realize that these do not provide the necessary runtime API-based governance and auditability required.

156
MCQmedium

A team is concerned about data privacy. They want to ensure that no personally identifiable information (PII) is sent to the LLM. What is the most effective way to manage this in a developer-friendly way?

A.Provide all developers with a PII detection manual and perform monthly audits.
B.Deploy a middleware proxy layer that detects and redacts PII before model submission.
C.Only use the LLM to process public data that has been vetted by legal teams.
D.Require developers to encrypt all prompt text using AES-256 before sending.
AnswerB

A centralized middleware layer provides a 'secure-by-default' architecture. By automatically redacting PII, the team ensures compliance without adding friction to the developer's workflow. This is a scalable, robust pattern that minimizes the risk of data leakage while keeping the application code clean and manageable.

Why this answer

Building a middleware proxy for PII redaction ensures that sensitive data is scrubbed before it ever leaves the company's network. By automating this at the infrastructure level, developers are freed from the responsibility of manual redaction, reducing the risk of human error. This approach balances developer productivity with strict security compliance, making it an essential operational pattern for enterprise-scale LLM adoption.

Exam trap

Test-takers frequently select client-side regex checks or manual code reviews, overlooking that a centralized middleware proxy layer provides automated, scalable, and foolproof PII redaction without burdening individual developers.

157
MCQmedium

An architect needs to implement a 'Red Teaming' process for a new Claude deployment. What is the primary objective of this activity in the context of AI governance and safety?

A.To optimize the model's latency and throughput for high-volume traffic.
B.To adversarialy test the model to find safety gaps and potential for misuse.
C.To automate the generation of unit tests for the application's UI components.
D.To verify that the model's billing and usage credits are being tracked correctly.
AnswerB

The goal of Red Teaming is to simulate the behavior of a malicious actor. By intentionally trying to provoke the model into generating harmful, biased, or restricted content, architects can identify where the current guardrails are weak and strengthen them before the official launch.

Why this answer

Red Teaming is a proactive safety practice where a group of testers tries to find vulnerabilities, biases, or ways to make the model fail. This is a critical component of risk management, as it identifies potential issues before they can affect real users in a production environment.

Exam trap

Candidates confuse red teaming with standard performance benchmarking, accuracy testing, or automated unit testing of functional application code.

158
MCQhard

An enterprise architect is designing a Claude deployment where a single prompt may contain data belonging to customers in the EU, Brazil, and California. The legal team requires that each data subject's rights be honored independently and that processing purposes be documented per jurisdiction. Which architectural approach best supports this requirement?

A.Implement data classification and purpose tagging at ingestion so each record carries jurisdiction, lawful basis, and permitted processing purpose metadata that the orchestration layer enforces at prompt assembly time.
B.Route all prompts through a single global data lake so that lineage is consistent and easy to report.
C.Rely on the model provider's regional endpoints to satisfy all three jurisdictions automatically.
D.Ask business users to manually remove data from prompts when it is not needed for the current task.
AnswerA

Tagging records with jurisdiction, lawful basis, and purpose lets the orchestration layer include only data whose processing purpose matches the current request, honoring each subject's rights independently. Enforcement at prompt assembly prevents mixed-jurisdiction leakage. The other options either centralize data in ways that complicate localization or rely on manual, error-prone practices that cannot scale to per-subject obligations.

Why this answer

Honoring rights independently while documenting purpose per jurisdiction requires machine-readable metadata attached to each record and enforced during prompt assembly. Classification tags for jurisdiction, lawful basis, and permitted purpose let the orchestration layer exclude data whose purpose does not match the current request, which is the only approach here that scales and remains auditable. Centralization, endpoint selection, and manual pruning do not deliver per-subject enforcement or purpose documentation.

Exam trap

The trap here is believing that regional inference endpoints or a unified data lake solve multi-jurisdiction compliance, when the binding requirement is per-record purpose and rights enforcement.

159
MCQmedium

When implementing a 'Human-in-the-loop' (HITL) checkpoint, what is the best way to handle the state persistence during the wait period?

A.Keep the connection open to avoid re-initializing the agent.
B.Persist the state in an external database and terminate the process.
C.Store the state only in the client-side browser memory.
D.Retry the tool call periodically until the human responds.
AnswerB

Externalizing the state allows for scalability and durability. By saving the session context in a database, the system can remain idle without consuming compute resources. Once the human provides input, the system can reload the state, reconstructing the agent's context to resume the task seamlessly and reliably.

Why this answer

Externalizing state to a persistent database is essential. Agentic systems are often stateless by design, but a wait period requires 'pausing' execution. Saving the entire conversation history, current tool state, and reasoning chain allows the process to resume exactly where it left off once human approval is received.

This prevents data loss and maintains context continuity, which is critical for long-running, complex workflows.

Exam trap

Test-takers often assume that keeping the process alive in memory or using local process threads is sufficient for waiting states, ignoring that agentic architectures require externalized database persistence.

160
Multi-Selecthard

Your team is building an LLM-powered application and experiencing high latency during peak times. Which TWO actions would best improve developer productivity and operational efficiency when debugging these bottlenecks?

Select 2 answers
A.Implement distributed tracing with custom spans for model inference and prompt processing.
B.Switch all internal communications to asynchronous polling to avoid blocking operations.
C.Enable detailed token usage monitoring and latency logging for every API call.
D.Force all developers to use the largest available model to ensure high quality results.
E.Disable all logging and monitoring to minimize overhead on the network layer.
AnswersA, C

Distributed tracing provides the necessary visibility into the complete request lifecycle. By identifying exactly how long the model takes versus pre-processing tasks, developers can isolate the root cause of latency. This reduces debugging time and allows for data-driven decisions when selecting model tiers or implementing caching.

Why this answer

Observability and granular tracing are critical for diagnosing LLM latency. By capturing token usage and latency metrics per request, developers can pinpoint whether the bottleneck is model inference, networking, or pre-processing. These insights enable targeted optimizations like prompt caching or streaming, which are essential for scaling production-grade generative AI applications while keeping developer workflows focused on high-impact performance improvements rather than guesswork.

Exam trap

Candidates often suggest generic performance tuning like model quantization or hardware upgrades, missing the specific need for observability tools that provide granular visibility into LLM-specific bottlenecks like token processing.

161
MCQmedium

A media company uses Claude through the Anthropic API to draft articles. Legal counsel asks the platform team to demonstrate that every published draft can be traced to the exact model behavior that produced it, even after Anthropic deprecates older models. The team currently calls the alias claude-sonnet-4-5. Which change best satisfies counsel's requirement?

A.Increase max_tokens and set temperature to zero so outputs become deterministic.
B.Pin requests to a dated model snapshot identifier and archive the full request parameters and response with each draft.
C.Log the alias string claude-sonnet-4-5 alongside each draft in the content management system.
D.Enable prompt caching so identical requests return consistent outputs across model updates.
AnswerB

A dated snapshot identifier names an immutable model version, so a stored request can be replayed against the same behavior later instead of silently moving to a newer build. Archiving the complete request parameters and the returned response closes the loop, because it captures both the exact input and the output that was published. Together they give counsel a reproducible record that survives alias updates and routine model refreshes.

Why this answer

Traceability to a specific model behavior requires two things: an immutable model identifier and a durable record of the exact input and output. A dated snapshot pins behavior so it can be reproduced or referenced after deprecation, while archiving request parameters and responses preserves the actual interaction. Aliases, caching, and sampling settings modify cost, latency, or variance but none of them establish which model version produced a given published artifact.

Exam trap

The trap here is treating a model alias as a stable version identifier, when aliases are deliberately repointed to newer builds and therefore cannot anchor an evidentiary record.

162
MCQhard

A healthcare provider is using Claude to summarize patient clinical notes. Which governance control is most critical to prevent potential HIPAA violations?

A.Use a custom model fine-tuned on public medical journals to avoid using patient data.
B.Ensure that a Business Associate Agreement (BAA) is in place and strictly enforced.
C.Implement a strict 24-hour limit on the storage of all processed clinical summaries.
D.Anonymize all patient notes by removing names before sending them to the API.
AnswerB

The BAA is a legal requirement under HIPAA for any cloud service provider handling PHI. Without this agreement, the healthcare provider is in direct violation of the law. This is the paramount governance step, as it defines the legal responsibility and privacy safeguards that must be maintained.

Why this answer

The most critical control is ensuring that all data processed by the API is encrypted in transit and at rest, and that the organization has a Business Associate Agreement (BAA) with Anthropic. Without a BAA, the provider cannot legally process PHI. This legal framework, supported by technical encryption, is the foundational requirement for any healthcare entity utilizing cloud-based AI services to maintain regulatory compliance.

Exam trap

Candidates often focus on 'encryption' or 'prompt sanitization'. While necessary, these are technical details; the BAA is the essential legal prerequisite for handling PHI in a healthcare context.

163
MCQeasy

Which of the following describes the role of the 'System Prompt' in an agentic architecture?

A.A temporary buffer for user-provided instructions.
B.A mechanism for defining the agent's identity and constraints.
C.An automated script for executing Python code.
D.A method to store long-term user history.
AnswerB

The system prompt is the primary location for defining 'who' the agent is and the boundaries it must respect. This is an essential architectural component that dictates how the agent processes information, adheres to safety protocols, and interacts with tools, forming the foundation of its autonomous behavior.

Why this answer

The system prompt serves as the 'DNA' of the agent, dictating its core behavior, constraints, and operational goals. By setting the context outside of the user's conversation stream, it ensures that the model adheres to defined roles and ethical boundaries consistently, regardless of user input. It provides the necessary structure that turns a raw LLM into a purposeful, reliable assistant within a larger system architecture.

Exam trap

Candidates frequently confuse the system prompt with dynamic few-shot learning examples, mistakenly thinking it handles turn-by-turn conversation memory rather than persistent global boundaries and agent identity.

164
Multi-Selecthard

You are preparing a go-live readiness review for a Claude-powered advisory assistant used by field staff. The steering committee wants assurance that operational ownership is clear before launch. Which two artifacts are most essential to demonstrate that the lifecycle handover from project to operations is complete? (Choose two.)

Select 2 answers
A.A list of all stakeholders who attended the project kickoff meeting.
B.A documented service ownership agreement naming the accountable team, support hours, and service level objectives.
C.A complete archive of every prompt version ever tested during development.
D.A signed operations runbook covering incident response, escalation paths, and routine maintenance tasks.
E.A slide deck summarizing the assistant's key features for the marketing team.
AnswersB, D

Naming the accountable team, support windows, and service level objectives converts vague intent into enforceable commitments. It tells the steering committee exactly who answers for availability, quality, and response times after launch, and it gives operations a mandate to staff and monitor the service. This artifact is the clearest evidence that the lifecycle handover is complete and that ownership will not lapse.

Why this answer

A complete handover requires both a named owner and the operational procedures that owner will follow. The service ownership agreement establishes accountability, support hours, and service level objectives, while the signed runbook documents incident response, escalation, and maintenance. Together they give the steering committee confidence that the assistant will be sustained after the project team transitions away, rather than drifting without ownership or support coverage.

Exam trap

The trap here is accepting development artifacts such as prompt archives or attendee lists as readiness evidence, when handover requires explicit ownership and operational procedures.

165
MCQhard

You are architecting a Claude-based agent for a regulated financial client that performs long-running portfolio rebalancing workflows. A compliance requirement mandates that no single trade instruction may be executed unless it is cryptographically traceable to the exact model-generated intent that produced it. The agent uses the Messages API with tool use, and several downstream services consume tool calls asynchronously. Which architectural mechanism best satisfies this requirement while preserving agent autonomy?

A.Require the model to emit a SHA-256 hash of its own reasoning text inside the tool input, and verify that hash in the downstream trade service before execution.
B.Route all trades through a single orchestrator agent that logs a natural-language summary of each decision to an append-only ledger after the trade is confirmed.
C.Enable prompt caching on the system prompt so that every trade instruction inherits a stable cache key that can be presented to auditors as proof of origin.
D.Persist every assistant turn containing a tool_use block, its tool_use id, and the matching tool_result, forming an immutable audit chain keyed by the tool_use id.
AnswerD

The tool_use id is generated by Claude and echoed back in the corresponding tool_result, so pairing them creates a verifiable link between model intent and downstream execution. Persisting the full assistant turn preserves the reasoning context around the intent, and the id becomes the cryptographic join key that compliance can replay. This satisfies traceability without constraining how many tools the agent may call.

Why this answer

Binding each tool call to the platform-generated tool_use id and persisting the surrounding assistant turn creates a deterministic chain from model intent to executed instruction. Because the id appears in both the tool_use block and the tool_result, downstream services and auditors can reconcile them without trusting model-authored text. Caching, summaries, or self-hashes do not establish that binding.

Exam trap

The trap here is assuming that any unique value the model or cache layer produces can serve as an audit key, when only the platform-issued tool_use id is reliably echoed through the tool_result.

166
MCQhard

You are managing a long-term AI project. How should you handle stakeholder communication when the underlying model architecture changes (e.g., release of a new model generation)?

A.Update the model automatically without telling stakeholders to avoid confusion.
B.Create a transition plan with a phased testing period using a sandbox environment.
C.Recommend staying on the old model forever to avoid any potential issues.
D.Ask the stakeholders to choose the new model for you.
AnswerB

This is the standard architectural procedure for managing model upgrades. It allows for performance validation, regression testing, and quality assurance before the new model goes live in production. This approach minimizes risk and provides stakeholders with the assurance that the change is being managed, tested, and vetted properly.

Why this answer

Communicating major model changes requires a proactive, structured approach that highlights both benefits and potential disruptions. By framing the upgrade as a planned lifecycle event, you can manage the transition by defining testing phases, regression benchmarks, and a rollback strategy. This demonstrates professional control, reassuring stakeholders that the change is an intentional improvement rather than an unpredictable disruption to their business operations.

Exam trap

Candidates often propose a 'switch' to the new model without a testing phase, ignoring that stakeholders need to see a validation strategy to trust the new deployment.

167
MCQmedium

A logistics agent needs to fetch shipping rates from five different carriers simultaneously to find the best price. Which architecture is best suited for this requirement?

A.Chain of Thought (CoT) prompting
B.Orchestrator-Worker Pattern
C.Recursive Reflection
D.Single-Agent Sequential Loop
AnswerB

This pattern allows a lead agent to delegate independent tasks to multiple specialized workers. In this scenario, the orchestrator can trigger five carrier-specific tool calls in parallel, collect the results, and then synthesize the findings to determine the best price, optimizing both speed and logical separation.

Why this answer

The Orchestrator-Worker pattern is ideal for tasks that can be parallelized. A central orchestrator identifies the need for multiple independent lookups and dispatches them to parallel workers (or tool calls). This significantly reduces total execution time compared to a sequential process where each carrier is queried one after another.

Exam trap

Candidates often choose a sequential loop or a single-agent architecture. They fail to recognize that parallelizing independent tasks is the primary driver of performance gains in modern agentic systems.

168
MCQeasy

In the Anthropic tool-use workflow, what is the primary purpose of the 'system prompt' relative to tool usage?

A.To provide the JSON schema for each tool
B.To store the results of previous tool executions
C.To define the API keys for the external services
D.To establish the agent's persona and tool-use guidelines
AnswerD

The system prompt is the correct place to define the agent's role (e.g., 'You are a helpful logistics assistant') and provide high-level instructions on how to prioritize different tools, how to handle errors, and how to interact with the user after receiving results from the tools.

Why this answer

The system prompt serves as the 'instruction manual' for the agent. It defines the agent's identity, its overall goals, and the constraints within which it must operate. While tool schemas define the 'how,' the system prompt provides the 'why' and 'when,' guiding the model's decision-making process for tool selection.

Exam trap

Candidates often confuse the system prompt with the actual JSON tool schemas, failing to realize the system prompt dictates the operational guidelines while schemas define syntax.

169
MCQeasy

A team is rolling out an internal Claude-powered assistant for their engineering organization. Adoption is low and developers report that they do not trust the answers for anything beyond trivial questions. The enablement lead wants to increase adoption by making the assistant's behavior more transparent and debuggable. Which change best supports that goal?

A.Restrict the assistant to answering only questions about internal documentation and disable all other capabilities.
B.Hide the system prompt and tool definitions from users to keep the interface simple.
C.Expose the system prompt, the tools available, and the retrieved context used for each answer, and log request IDs for support.
D.Increase the model's temperature so answers vary more and feel more natural to developers.
AnswerC

Showing the instructions, tools, and retrieved context lets developers verify why an answer was produced and whether the assistant had the right information. Request IDs make it possible to investigate specific bad answers with support. This transparency directly addresses the trust gap that is suppressing adoption across the engineering organization.

Why this answer

Trust grows when developers can see the inputs that shaped an answer. Exposing the system prompt, available tools, and retrieved context lets engineers verify whether the assistant had the right information and instructions. Logging request IDs enables targeted investigation of bad answers, turning vague distrust into specific, fixable issues that the enablement team can address.

Exam trap

The trap here is treating low adoption as a model quality problem and reaching for temperature or scope changes, when the actual blocker is that developers cannot see how answers are produced.

170
MCQeasy

A fintech startup wants to use Claude to generate marketing copy that references competitor products by name and makes performance comparisons. Legal counsel asks the architect which governance step is most appropriate before this capability goes live.

A.Establish a documented review process that classifies the use case against Anthropic's Usage Policies and applicable advertising regulations before deployment.
B.Increase the model's temperature setting so the copy sounds more creative and varied.
C.Enable prompt caching to lower the cost of generating large volumes of marketing variants.
D.Add a spell-check and grammar pass to the generated marketing copy before publication.
AnswerA

Generating comparative claims about named competitors raises both usage-policy and regulatory questions, so a documented classification and review step is the right governance gate. It ensures the use case is assessed against Anthropic's policies and advertising law before any content is produced. The other measures improve output quality or performance but do not resolve the legal and policy eligibility question.

Why this answer

The scenario involves a potentially sensitive use case: comparative advertising that names competitors. Governance best practice is to classify the use case against Anthropic's usage policies and relevant advertising regulations through a documented review before deployment. Sampling parameters, proofreading, and caching affect style, quality, and cost, and none of them determine whether the activity is permitted or lawful.

Exam trap

The trap here is reaching for a technical or quality control when the actual blocker is a use-case eligibility question that must be resolved through policy review.

171
MCQeasy

During a project post-mortem, stakeholders feel that the technical limitations of the LLM were not clearly explained during the planning phase. What action would have best mitigated this perception?

A.Provide stakeholders with the full technical whitepaper of the model's training data.
B.Conduct an expectation-setting workshop demonstrating both model strengths and known limitations.
C.Include a disclaimer in the final project report acknowledging the potential for errors.
D.Ask the AI engineers to write a memo outlining the model's performance metrics.
AnswerB

An interactive workshop allows stakeholders to see the model in action, creating a balanced understanding of its capabilities and constraints. This direct experience helps stakeholders frame their expectations appropriately, ensuring they understand the necessity of human-in-the-loop workflows and other safeguards required for a production-ready system.

Why this answer

Transparency regarding model capabilities and constraints is vital for setting realistic expectations. By providing a clear, non-technical overview of what the model can and cannot do during the initial planning phase, stakeholders can better align their business objectives with the actual technical reality, reducing disappointment and friction during later project stages and establishing a foundation of trust and professional credibility.

Exam trap

Candidates often select technical documentation handoffs or post-project surveys, forgetting that proactive expectation-setting workshops during planning are vital to prevent stakeholder misalignment.

172
MCQhard

An insurer uses a Claude-based agent that can call internal tools to look up policy details. During review, the safety team finds that a document uploaded by a claimant contains text instructing the agent to email the full policy database to an external address. The agent has an email tool available. Which control most directly prevents this class of failure?

A.Scan uploaded documents with a classifier that flags imperative language and quarantine any document that scores above threshold.
B.Add a system prompt instruction telling the model to ignore any instructions found inside uploaded documents.
C.Require human approval for every tool invocation the agent proposes, regardless of which tool or argument is involved.
D.Enforce tool-level authorization so the agent's identity lacks permission to send external email, and constrain tool arguments to validated allowlists.
AnswerD

Removing the agent's ability to send external mail makes the injected instruction inert no matter how persuasive the document is, because the capability simply does not exist at the credential layer. Argument allowlisting further blocks misuse of tools the agent does retain, such as restricting a lookup to the current claimant's policy. This is a deterministic boundary rather than a behavioral request.

Why this answer

When untrusted content can reach a model that holds real capabilities, the reliable fix is to remove the dangerous capability from the agent's identity and constrain the arguments of the tools it keeps. Injected text can persuade a model but cannot grant permissions the credential layer denies, so an agent without external-email rights cannot exfiltrate regardless of what the document says. Detection and prompting remain useful layers but are not deterministic.

Exam trap

The trap here is treating prompt injection as a text-filtering problem, when the decisive control is limiting what the agent is authorized to do rather than what it is willing to read.

173
MCQmedium

A retail company's legal team discovers that several engineering squads have been calling the Anthropic API with personal API keys obtained on individual credit cards, outside the corporate agreement. Leadership wants a governance model that both eliminates this practice and preserves the ability to audit all Claude usage centrally. Which governance model best achieves this?

A.Provide a centralized Anthropic Console organization with workspace-scoped API keys issued per squad, and route all usage through a corporate gateway that logs every request.
B.Publish a policy prohibiting personal API keys and require engineers to attest annually that they comply.
C.Block outbound traffic to api.anthropic.com at the corporate firewall for all users except the platform team.
D.Ask Anthropic account management to monitor for personal keys belonging to company employees and report them monthly.
AnswerA

Centralizing the account under one Console organization removes the incentive and the mechanism for personal keys, because squads receive sanctioned credentials scoped to their workspace. Routing traffic through a corporate gateway produces complete, uniform logging, so leadership gains the audit visibility it asked for. The approach pairs a technical prohibition with an enabling alternative, which is what makes it durable.

Why this answer

Eliminating shadow AI requires giving teams a sanctioned, easy path while removing the unmanaged one, which a centralized Console organization with workspace-scoped keys accomplishes. Central auditability then follows from routing all traffic through a corporate gateway that records every request. Policies, attestations, blanket blocks, and vendor-side monitoring either lack enforcement teeth, suppress legitimate use, or rely on attribution the vendor cannot make.

Exam trap

The trap here is choosing a policy statement or a network block as the fix, when shadow AI is driven by lack of a convenient sanctioned alternative and can only be governed by providing one plus centralized logging.

174
MCQeasy

What is the primary risk associated with 'Prompt Injection' attacks in enterprise AI?

A.Increased latency for all users.
B.Unauthorized control of model behavior.
C.A reduction in model accuracy.
D.The model becoming permanently unavailable.
AnswerB

Prompt injection is the deliberate manipulation of the model's instructions by a user. This can lead to the model behaving in ways that contradict its original purpose, such as revealing internal data, bypassing security checks, or executing arbitrary commands, representing a significant risk to the integrity of the system.

Why this answer

Prompt injection allows attackers to override core system instructions, potentially forcing the AI to leak sensitive data, bypass safety filters, or perform unauthorized actions. This is a critical risk because it undermines the entire security model of the AI application. Enterprise systems must treat all external user input as untrusted, necessitating strong architectural controls to prevent attackers from hijacking the model's intended logic and operational behavior.

Exam trap

Candidates often focus on data leakage as the primary risk. While serious, the fundamental threat of prompt injection is the loss of control over the model's decision-making logic.

175
MCQmedium

Which document is essential for an organization to maintain when preparing for an AI audit?

A.A list of all model parameters and hyperparameters.
B.An up-to-date AI Risk Register.
C.The raw training data files for the LLM.
D.A transcript of every single user interaction.
AnswerB

An AI Risk Register is a critical document for any compliance or safety audit. It tracks potential risks, their severity, and the controls implemented to mitigate them. It serves as evidence that the organization is actively managing its AI safety profile and following best practices in governance.

Why this answer

An AI audit requires proof of governance, testing, and safety measures. An AI Risk Register, which documents identified risks, their potential impact, and the mitigation strategies in place, is essential. It provides auditors with a clear history of how the organization identifies, assesses, and manages its AI-related risks, demonstrating a mature approach to safety and compliance that satisfies both internal and external oversight requirements.

Exam trap

Candidates often confuse the AI Risk Register with technical logs or performance dashboards. They fail to realize that auditors need a high-level governance document, not just raw system data.

176
MCQmedium

A platform team at a large enterprise wants to standardize how Claude is invoked across 30 internal microservices. They need to enforce prompt templates, model selection, and retry logic centrally, while still allowing service teams to customize business-specific instructions. Which approach best balances central governance with team autonomy?

A.Publish an internal SDK that wraps the Anthropic API and embeds a versioned prompt template registry from which teams can inherit and override specific sections.
B.Let each service team manage its own Anthropic API keys, prompts, and retry logic, and rely on quarterly architecture reviews to keep behavior aligned.
C.Require each service team to copy a canonical prompt file into their repository and update it manually whenever the platform team changes standards.
D.Deploy a shared API gateway that rewrites every request to a single canonical prompt and strips service-specific instructions before forwarding to Claude.
AnswerA

A versioned internal SDK with a prompt template registry gives the platform team a single control point for model choice, retries, and base prompts, while services inherit and override only what they need. This preserves governance and developer velocity without duplicating integration code across 30 services.

Why this answer

The best solution provides a single, versioned integration layer that centralizes cross-cutting concerns like authentication, retries, and model selection, while exposing extension points for domain-specific prompts. This gives the platform team enforceable standards and gives service teams the flexibility they need, without code duplication or prompt drift.

Exam trap

The trap here is assuming central governance must mean a single shared prompt, when governance is really about controlling the integration layer and letting teams extend it safely.

177
Multi-Selectmedium

An insurance company is preparing an AI risk register for its Claude-based claims triage system. The risk team must document controls that reduce the chance of biased or inconsistent decisions affecting policyholders. (Choose two.)

Select 2 answers
A.Collect aggregate throughput metrics showing how many claims the system processes per hour during peak periods.
B.Define and version the decision criteria and prompts used for triage, and re-validate them against a representative dataset whenever they change.
C.Raise the model's max_tokens setting so the triage system can produce longer, more detailed justifications for each decision.
D.Establish a human review and appeal path so affected policyholders can challenge a triage outcome and have a person re-examine the decision.
E.Switch to the largest available Claude model on the assumption that greater capability automatically eliminates biased outputs.
AnswersB, D

This is correct because bias and inconsistency often enter through drifting criteria or undocumented prompt edits. By versioning the decision logic and re-validating against a representative dataset on every change, the team can detect shifts in outcomes across demographic groups and demonstrate that the criteria were intentionally designed and reviewed, which is core evidence for a defensible risk register entry.

Why this answer

Fairness controls require both a defined, versioned decision logic that is re-validated against representative data and a human appeal path that catches harmful outcomes the model produces. Together they create a preventive and a corrective layer. Throughput, token budgets, and model size describe performance or capability, not equity, and cannot substantiate a claim that biased or inconsistent decisions have been controlled.

Exam trap

The trap here is equating a larger or more capable model, or longer outputs, with reduced bias, when fairness must be measured and governed through versioned criteria and human recourse.

178
Multi-Selectmedium

Which TWO metrics are most useful for evaluating developer productivity in an LLM-driven organization? (Choose TWO)

Select 2 answers
A.Mean time to deploy a prompt improvement to production.
B.Total number of prompts written by a developer each week.
C.Success rate of automated evaluation suites in CI/CD.
D.Total API usage cost per day for the entire organization.
E.Number of lines of code written in the application backend.
AnswersA, C

Reducing the time between identifying a prompt improvement and deploying it is a key metric for developer velocity. It reflects the efficiency of the CI/CD pipeline and the quality of the surrounding tooling, directly impacting how fast a team can iterate on their LLM features and respond to feedback.

Why this answer

Measuring productivity in LLM development requires balancing speed of iteration with the quality of the output. Metrics like mean time to deploy prompt changes and the success rate of automated evaluations provide a clear picture of how quickly and effectively a team can work. These indicators help identify bottlenecks in the CI/CD pipeline and ensure that improvements are actually enhancing the system's overall performance rather than just adding complexity.

Exam trap

Test-takers frequently select traditional software agile metrics like lines of code or commit frequency, which do not accurately reflect LLM engineering productivity.

179
MCQmedium

An agent is engaged in a multi-hour troubleshooting session involving dozens of tool calls and thousands of lines of log data. The architect notices that the agent is starting to 'forget' early symptoms of the problem. Which strategy best addresses this while managing token costs?

A.Truncating the oldest messages once the limit is reached
B.Implementing a recursive summarization buffer
C.Switching to a model with a 1-million token window
D.Storing all tool results in an external vector database
AnswerB

Summarizing previous turns into a concise narrative preserves the essential findings and progress of the agent. By passing this summary forward into new turns, the agent maintains a continuous understanding of the session history without needing to re-process every individual token from the original, verbose tool outputs.

Why this answer

Managing context in long-running agentic sessions requires a balance between detail and capacity. A summarization strategy combined with a sliding window allows the agent to retain the 'gist' of historical turns while keeping the most recent, high-fidelity data available. This prevents context overflow while maintaining the logical continuity of the troubleshooting process.

Exam trap

Candidates frequently suggest simply increasing the context window or dumping all logs into the prompt. This ignores the exponential cost of token usage and the degradation of model focus over time.

180
MCQmedium

Which pattern is most suitable for an agent that must balance the need for speed (latency) versus the need for correctness in a customer support scenario?

A.Always prioritize speed by using the smallest, fastest model available.
B.Use a dual-path architecture with immediate streaming and background verification.
C.Force the user to wait for verification before showing any response.
D.Use a RAG-only architecture to guarantee factual accuracy.
AnswerB

This architecture provides the best of both worlds: immediate feedback for the user and a secondary validation layer that ensures the content is accurate. This pattern manages the trade-off between perceived latency and result quality, delivering a superior user experience without sacrificing the precision required for high-quality support.

Why this answer

The 'Dual-Path' pattern, where the system initiates an immediate low-latency response while simultaneously running a more comprehensive, high-correctness check in the background, optimizes for both user experience and accuracy. This ensures the user feels acknowledged immediately, while the eventual output remains verified and accurate. This balance is critical in customer support, where perceived responsiveness is as vital as providing correct, verified information for technical or complex queries.

Exam trap

Candidates often choose between either speed or accuracy. They mistakenly assume they must sacrifice one, ignoring that a dual-path architecture allows for both immediate user feedback and eventual verification.

181
MCQmedium

Six months after launch, a logistics company's operations VP reports that the Claude-based exception-handling assistant 'used to be great and now gives worse answers,' though no code has changed. You confirm the application code and system prompt are untouched. What is the most likely explanation you should investigate first?

A.The prompt caching layer has expired its entries, forcing the model to reason without the operational context it previously had.
B.The assistant is now encountering a broader distribution of exception types than during the pilot, including cases that were out of scope for the original evaluation set.
C.Latency has increased over time, and the operations team is now perceiving slower responses as lower quality answers.
D.The model provider has silently retrained the underlying model, so previously correct behaviours have been overwritten without notice.
AnswerB

A stable application facing a shifting input distribution will appear to degrade even when nothing in the code changed. As the assistant gains adoption, users bring exception categories the pilot never covered, and accuracy on those unfamiliar cases is naturally lower. Comparing current input distributions against the original evaluation set is the fastest way to confirm whether the workload itself has drifted.

Why this answer

When code, prompt, and model snapshot are unchanged but users report degradation, input distribution drift is the leading hypothesis. Early pilots exercise a narrow set of exception types chosen by the implementation team, while production usage expands into long-tail cases the evaluation never covered. Measuring the current mix of incoming exception categories against the original test set either confirms drift or rules it out, and it is a cheap first check before investigating infrastructure.

Exam trap

The trap here is assuming that unchanged code implies unchanged behaviour, when the inputs reaching the system are the more likely variable in a maturing deployment.

182
MCQeasy

When designing an LLM-based application, what is the primary benefit of using a 'System Prompt' compared to embedding instructions in the user message?

A.It significantly reduces the latency of every request sent to the model.
B.It provides a dedicated space for behavioral instructions, improving consistency and safety.
C.It allows the model to cache the entire user conversation history automatically.
D.It eliminates the need for any further user input during the conversation.
AnswerB

System prompts are treated as high-priority instructions by the model, setting clear boundaries for tone, format, and safety. This enhances consistency across user interactions and is a standard architectural pattern for building robust, secure, and reliable LLM applications. It is essential for predictable operational behavior.

Why this answer

System prompts define the core persona, constraints, and operational boundaries of the model, which remains consistent throughout the session. This separation of concerns improves developer productivity by keeping the application logic clean and separating user-provided data from behavioral instructions. It also helps prevent prompt injection attacks, as the model is explicitly instructed to treat the system prompt as a higher-priority directive compared to the user's input.

Exam trap

Candidates often argue that system prompts are for 'security' only, missing the primary benefit of behavioral consistency and the separation of instruction from user-provided data.

183
Multi-Selectmedium

An organization is building an internal CLI tool that uses Anthropic's API. They want to improve developer productivity by implementing robust error handling and monitoring. Which TWO strategies should they implement? (Select TWO)

Select 2 answers
A.Implement exponential backoff logic for handling 429 and 5xx API responses.
B.Store API keys as plain text in the CLI configuration file for ease of developer access.
C.Use structured logging to track token usage, response latency, and request IDs.
D.Set the maximum token limit to 4096 for all requests to ensure uniform response times.
E.Disable all request retries to ensure the CLI tool fails fast during network issues.
AnswersA, C

Exponential backoff is a standard pattern for distributed systems to handle temporary overloads and rate limits. By waiting longer between retries, it reduces pressure on the API and increases the likelihood of a successful subsequent request. This prevents automated tasks from crashing when facing high traffic or transient congestion.

Why this answer

Implementing exponential backoff and structured logging are foundational for operational reliability. Exponential backoff gracefully handles rate-limiting and transient errors, preventing pipeline failures. Structured logging allows teams to parse API metrics, latency, and token usage, providing visibility into costs and performance.

These practices directly improve developer experience by reducing time spent troubleshooting intermittent failures and optimizing API resource consumption in automated workflows.

Exam trap

Candidates rely on basic try-catch blocks without implementing exponential backoff or structured logging for transient API failures.

184
MCQmedium

A customer-support agent must sometimes escalate to a human and sometimes resolve autonomously. The compliance team requires that any action touching billing be reviewed by a human before execution, while password resets may proceed automatically. The architect wants the model to decide routing without hardcoding every rule in the prompt. Which design best satisfies the requirement?

A.Fine-tune the model on historical escalations so it learns which actions compliance typically requires humans to approve.
B.Classify each proposed tool call by risk tier in the orchestration layer, auto-approve low-risk actions, and require human approval for billing-tier actions regardless of model output.
C.Give the model a single escalate tool and instruct it in the system prompt to use judgment about when human review is required.
D.Log every tool call the agent makes and have the compliance team review the logs weekly to catch any unauthorized billing actions.
AnswerB

Enforcing the risk tier outside the model makes the control deterministic and auditable: billing actions cannot execute without human approval even if the model proposes them. Password resets proceed automatically because they fall in the low-risk tier. The model still decides routing in the sense of proposing actions, but the orchestration layer holds the authoritative gate, satisfying compliance without hardcoding every conversational rule in the prompt.

Why this answer

The compliance requirement is a hard gate, so the decision to require human approval must live in deterministic orchestration code rather than in model judgment. Tiering tool calls by risk lets low-risk actions like password resets flow automatically while billing actions are held for approval before execution. The model can still propose actions, but the authoritative approval decision is enforced outside it, which makes the control auditable and immune to prompt drift or probabilistic misrouting.

Exam trap

The trap here is assuming that a well-written system prompt or a fine-tuned model can serve as a compliance control, when only deterministic enforcement outside the model can guarantee a gated action.

185
MCQmedium

A platform team maintains a shared prompt library used by 40 internal services. After a subtle wording change to a summarization prompt caused a 12% drop in a downstream classification F1 score, the team wants every prompt change to be reviewable, version-pinned, and automatically regression-tested before rollout. Which approach best satisfies these requirements?

A.Move all prompts into a shared spreadsheet with a change log column, and instruct service owners to copy the latest text into their code before each release.
B.Deploy every prompt change straight to production behind a feature flag, then compare aggregate F1 scores over the following week and revert manually if quality declines.
C.Store prompts as versioned files in a Git repository, require pull-request review, and run a CI job that evaluates each changed prompt against a held-out golden dataset before merge.
D.Keep prompts inline in each service's source code and rely on each team's existing unit tests, which mock the Claude response, to catch quality regressions.
AnswerC

Git gives immutable versions, diffable history, and mandatory peer review, while the CI evaluation job gates merge on measured quality against a golden dataset. This directly addresses reviewability, version pinning through commit SHAs or tags, and automated regression detection, so a wording change that degrades the classification F1 score is caught before it reaches the 40 consuming services.

Why this answer

Treating prompts as versioned code in Git couples three needed controls: peer review through pull requests, immutable references through commits or tags, and automated quality gates through a CI evaluation against a golden dataset. Because the evaluation runs before merge, a wording change that harms the downstream classification score is blocked rather than discovered in production, which protects all consuming services.

Exam trap

The trap here is assuming that ordinary unit tests with mocked model responses validate prompt quality, when only evaluation against real model outputs on a golden dataset can detect a semantic regression.

186
Multi-Selecthard

An autonomous agent is designed to browse the web and perform research. Which TWO mechanisms are most critical for preventing infinite loops and excessive API consumption during autonomous tool-calling cycles?

Select 2 answers
A.Increasing the context window size
B.Implementing a maximum iteration counter
C.Using a lower temperature setting
D.Hashing and comparing previous state snapshots
E.Enabling prompt caching for tool definitions
AnswersB, D

A hard limit on the number of turns an agent can take provides a definitive fail-safe against recursive behavior. This ensures that even if the model's reasoning fails to reach a conclusion, the process terminates after a pre-defined threshold, protecting the system from infinite execution and associated costs.

Why this answer

In autonomous agentic loops, the risk of 'stuck' states or recursive logic is high. Implementing both hard iteration limits and state-based detection ensures the system remains within operational bounds. These safeguards are essential for production-grade agents to prevent runaway costs and to provide a predictable user experience in non-deterministic environments.

Exam trap

Candidates often rely only on simple prompt instructions telling the agent not to loop, failing to implement hard programmatic safety limits like iteration counters and state hashing.

187
MCQeasy

What is the primary benefit of using a standardized Prompt Library for a large enterprise development team?

A.It completely replaces the need for custom code in application development.
B.It enforces strict compliance and reduces the need for developer ingenuity.
C.It facilitates prompt versioning, sharing, and standardized performance evaluation.
D.It ensures that the model always generates the same output.
AnswerC

Centralizing prompts enables version control, which is essential for tracking changes. Sharing templates across teams reduces duplication, while standard evaluation metrics within the library allow for consistent benchmarking. This infrastructure is critical for professional teams, as it directly improves quality, efficiency, and collaboration during the development of AI applications.

Why this answer

A centralized Prompt Library ensures consistency, reusability, and easier version management. By treating prompts as shared assets, developers avoid duplication of effort and can leverage proven, high-quality prompt templates. This accelerates the development lifecycle and improves the reliability of AI applications across the organization, as team members can contribute to and benefit from a common repository of optimized, tested prompts.

Exam trap

Candidates frequently focus on prompt performance optimization alone, missing that the primary enterprise benefit is the operational governance provided by versioning, sharing, and centralized management.

188
MCQmedium

A platform team is building a shared Claude integration library used by 40 internal microservices. Each service currently hard-codes its own model ID, max_tokens, and retry logic. The team wants a single place to roll out model upgrades and enforce consistent retry behaviour without redeploying every service. What is the most effective architecture for this requirement?

A.Place an HTTP proxy in front of the Anthropic API that rewrites the model field on every request and centralizes retries.
B.Move all Claude calls into a single shared monolith service and have the 40 microservices call it over gRPC.
C.Publish a versioned internal SDK that reads model configuration from a central configuration service at startup and exposes typed client wrappers with built-in retry and backoff.
D.Add a shared environment variable file to each repository and require every service owner to pull the latest values before each deployment.
AnswerC

A versioned SDK backed by a central configuration service lets the platform team change model IDs, token limits, and retry policy for all 40 services without touching each codebase. Typed wrappers enforce consistent behaviour and can be regression-tested once. Because configuration is fetched at startup, upgrades roll out on the next service restart, balancing safety and speed.

Why this answer

A versioned SDK reading from a central configuration service gives the platform team one lever for model IDs, token limits, and retry policy while preserving per-service autonomy. It enforces consistent behaviour through typed wrappers, supports staged rollouts, and avoids the fragility of repository-level environment files or an opaque rewriting proxy. This is the standard pattern for operational enablement at scale.

Exam trap

The trap here is assuming that centralizing retries through a proxy also solves configuration management, when it actually hides model changes and removes the typed contract developers need.

189
Multi-Selecthard

You are scaling an agentic system that uses external APIs. Which THREE design patterns prevent the agent from being blocked by third-party rate limits or latency?

Select 3 answers
A.Circuit breaker pattern to detect and isolate failing API endpoints.
B.Synchronous, real-time polling for every single tool invocation.
C.Asynchronous task queuing for long-running tool operations.
D.Request-response caching to serve recurring tool result patterns.
E.Increasing model temperature to provide more creative workarounds.
AnswersA, C, D

A circuit breaker monitors for failures and trips when a threshold is reached. This stops the agent from sending requests to a service known to be down, preventing wasted resources and allowing the service time to recover. It is essential for protecting the agent from external system instability.

Why this answer

Managing external dependency risk is critical for production agents. Implementing a circuit breaker prevents cascading failures by halting calls to failing services. A task queue enables asynchronous execution, decoupling the agent's reasoning from external latency.

Finally, caching common responses reduces total API calls, improving throughput and reliability. Combined, these patterns create a resilient boundary between the autonomous agent and the unpredictable nature of external network services.

Exam trap

Candidates often focus on increasing API rate limits or scaling infrastructure, failing to recognize that architectural patterns like circuit breakers and caching are the standard for handling third-party instability.

190
MCQhard

An organization runs a nightly batch job that uses the Claude Messages API to classify support tickets. The job currently processes tickets one at a time, taking several hours and occasionally exceeding the nightly window. The team wants to cut wall-clock time substantially without exceeding their rate limits or degrading classification quality. Which change is most effective?

A.Split the tickets across multiple API keys belonging to different team members to multiply the effective rate limit.
B.Submit the batch via the Message Batches API, which processes requests asynchronously at a lower cost and returns results without holding a synchronous connection.
C.Increase the max_tokens value on each request so the model has more room to reason before classifying.
D.Lower the temperature to zero and retry any borderline classifications until the model returns a confident label.
AnswerB

The Message Batches API is designed for high-volume, non-interactive workloads and processes requests asynchronously, which removes the sequential bottleneck and reduces cost. It fits the nightly classification job because results are not needed in real time. This directly shortens wall-clock time while respecting rate limits, since batching is the intended mechanism for bulk work.

Why this answer

The runtime problem is a throughput problem, not a model-quality problem. The Message Batches API is purpose-built for high-volume, non-interactive work, processing requests asynchronously and at lower cost than synchronous calls. For a nightly classification job that does not need real-time responses, batching removes the sequential bottleneck and shortens wall-clock time while staying within rate limits.

Exam trap

The trap here is optimizing the model's output settings or spreading keys when the actual bottleneck is that requests are issued one at a time and should be submitted as a batch.

191
MCQhard

A product owner asks you to add a feature that lets internal users upload customer contracts so Claude can extract renewal dates and auto-populate a CRM. During intake you learn the contracts contain personally identifiable information and commercially sensitive terms. The product owner wants to launch in three weeks with no legal review. As the architect, what is the most appropriate action?

A.Document the data flows and PII exposure, engage legal and security for a review, and propose a phased launch where extraction runs only on redacted or approved contract types first.
B.Agree to the three-week timeline but process all contract text through an external public model endpoint to reduce internal infrastructure work.
C.Launch on schedule and add a note in the backlog to complete the privacy review after the first month of production usage once real data volumes are known.
D.Reject the feature outright because contracts always contain sensitive data and no AI system should ever be used for extraction tasks.
AnswerA

This action respects both the business goal and the compliance obligations the scenario surfaces. Documenting data flows gives reviewers what they need, and a phased approach limited to approved contract types lets the product owner deliver value sooner without exposing regulated data prematurely. It balances delivery pressure with the non-negotiable need for legal and security sign-off on PII handling.

Why this answer

When a requested feature involves PII and sensitive commercial terms, the architect's role is to make the risk visible and enable a compliant path rather than to either block or bypass review. Documenting data flows, engaging legal and security, and scoping an initial launch to approved contract types satisfies the product owner's delivery goal while ensuring regulated data is handled under proper controls.

Exam trap

The trap here is choosing between blind speed and total refusal, when the correct professional response is to surface the compliance risk and propose a scoped, reviewed path to delivery.

192
Multi-Selecthard

An engineering organization wants to raise developer productivity across teams building on Claude. Leadership asks the platform team to identify interventions that reduce repeated manual work and shorten the feedback loop for prompt and integration changes. (Choose two.)

Select 2 answers
A.Mandate that all prompt changes be approved by a central architecture board that meets twice monthly.
B.Provide a reusable internal library that wraps common Claude API calls, including retry, streaming, and token accounting, so teams stop reimplementing the same plumbing.
C.Require every team to freeze its prompt text for a full quarter so that results remain comparable across services.
D.Instruct each team to build its own bespoke evaluation scripts and dashboards so that tooling matches local needs exactly.
E.Stand up an evaluation harness that runs candidate prompts against versioned golden datasets and reports quality and latency deltas on every pull request.
AnswersB, E

A shared library removes duplicated plumbing work and standardizes behavior such as retries and streaming, which shortens the path from idea to working integration. Because token accounting is centralized, teams get consistent cost visibility without building it themselves. This directly reduces repeated manual work and lets engineers focus on product logic instead of re-solving transport concerns in every service.

Why this answer

The two interventions that directly reduce repeated work and tighten feedback are a shared client library that absorbs common plumbing and a centralized evaluation harness that reports quality and latency deltas on every pull request. Together they remove duplicated effort and surface regressions early, letting teams iterate faster while keeping results comparable across services.

Exam trap

The trap here is equating rigor with control, so freezing prompts or adding a slow approval board feels productive even though both lengthen the feedback loop and reduce throughput.

193
MCQmedium

In a swarm of specialized agents, what is the primary benefit of using a 'Blackboard' pattern for inter-agent communication?

A.It forces all agents to run sequentially, which improves execution speed.
B.It eliminates the need for any form of agent orchestration or management.
C.It enables decoupled, non-linear collaboration between specialized agents.
D.It increases security by isolating agent memory into individual silos.
AnswerC

By utilizing a shared blackboard, agents can contribute findings independently, allowing for a non-linear problem-solving process. This decoupling is crucial because it allows individual agents to focus on their specific tasks while providing a unified view of the current progress, enabling more sophisticated emergent reasoning across the entire multi-agent swarm.

Why this answer

The Blackboard pattern allows multiple agents to contribute their expertise to a shared data structure, or blackboard, which serves as a common knowledge base. This promotes decoupling, as agents do not need to know about each other's existence, only how to read from or write to the blackboard. This architecture is essential for complex, multi-faceted problems where multiple specialized agents must collaborate without creating rigid, brittle dependency chains.

Exam trap

Candidates often confuse the Blackboard pattern with a centralized controller. They mistakenly believe the pattern is about command-and-control, rather than the decoupling of agents through a shared knowledge space.

194
MCQmedium

Refer to the exhibit. Your application is hitting rate limits. A stakeholder is concerned about the user impact. What is your communication strategy?

A.Tell them the service is unusable and wait for Anthropic to fix it.
B.Explain the rate limit, the automatic retry mechanism, and the scaling plan.
C.Ignore the issue until the stakeholder asks about it again.
D.Blame the engineering team for poor code quality.
AnswerB

This provides a comprehensive answer that covers the problem (rate limits), the immediate fix (retry mechanisms), and the long-term solution (scaling). This approach demonstrates control, foresight, and a proactive management style, which reassures the stakeholder that the issue is understood and being handled correctly according to architectural best practices.

Why this answer

When hit by technical constraints, the architect must communicate the limitation, the current mitigation (retry logic), and the plan for long-term scaling. This is vital because stakeholders need to know that the system is self-healing, but also that you are actively working on increasing capacity. Clear communication prevents panic and demonstrates that the system was designed with resilience in mind, maintaining stakeholder trust during temporary service interruptions.

Exam trap

Candidates often focus solely on the technical fix (e.g., increasing limits) without addressing the communication aspect, leaving stakeholders unaware of the system's resilience and current recovery status.

195
MCQeasy

A media company wants a lightweight, recurring review of its Claude-powered content moderation assistant. The team has no dedicated compliance staff and wants the cheapest process that still produces defensible evidence of oversight. Which approach fits best?

A.Commission an annual third-party audit with formal attestation and a published report.
B.Track the volume of user complaints and treat a stable or declining trend as sufficient evidence of adequate oversight.
C.Rely on the vendor's published safety evaluations and model cards as the primary evidence of the assistant's suitability.
D.Adopt a scheduled sampling review where a rotating staff member scores a fixed sample of outputs against written criteria and records the results.
AnswerD

Periodic human sampling against documented criteria produces dated, reproducible evidence of oversight at low cost, and it can be run by existing staff with a short rubric. Recording scores and reviewer identity creates the audit trail regulators expect. This matches the requirement for a lightweight but defensible process.

Why this answer

Defensible oversight means showing that a named person reviewed outputs against written criteria on a defined schedule and recorded the outcome. Scheduled sampling achieves exactly that with minimal tooling and staffing, and the recorded scores form a durable evidence trail. Vendor documentation and complaint trends are supporting signals, not substitutes for local, documented human review.

Exam trap

The trap here is equating passive outcome metrics or vendor documentation with active oversight, when reviewers look for evidence that the deploying organization itself examined outputs against criteria.

196
Multi-Selectmedium

When designing an agentic system, which TWO of these 'observability' metrics are most crucial for monitoring the health of the agent's reasoning process?

Select 2 answers
A.Total Step Count per Task.
B.Average latency of the user's internet connection.
C.Tool Call Success Rate.
D.The color profile of the agent's UI dashboard.
E.Number of times the user clicks the refresh button.
AnswersA, C

Monitoring the number of steps an agent takes helps identify inefficient workflows or runaway reasoning. If a task that should take 3 steps is taking 50, the agent is likely stuck in a loop or struggling to formulate a plan, indicating a need for better prompt instructions or debugging.

Why this answer

Tracking 'Step count per task' and 'Tool call success rate' provides immediate visibility into whether the agent is diverging or struggling. An unusually high step count indicates potential infinite loops or circular reasoning. A low tool call success rate reveals integration failures or ambiguous tool definitions.

By monitoring these, you can detect system degradation before it impacts the end-user, allowing for proactive debugging and iterative improvements to the agent's core instruction set.

Exam trap

Candidates frequently select vanity metrics like total token usage or wall-clock elapsed time, failing to realize that reasoning health is specifically evaluated via step counts and tool success rates.

197
MCQeasy

A stakeholder asks why the AI system occasionally provides different answers to the same question. How do you explain this?

A.Tell them it is a bug and that the team is working on a fix for consistency.
B.Explain that the model uses a 'temperature' parameter to balance variety and predictability, which is key to its generative nature.
C.Blame the training data for being inconsistent and poorly structured.
D.State that the system is broken and should be shut down until it is perfect.
AnswerB

This explanation is technically accurate and provides the stakeholder with a mechanism for control. By understanding that temperature controls creativity, they can now participate in decisions about how to tune the model, which empowers them and improves their confidence in the overall system design and performance.

Why this answer

Explaining the concept of model temperature and non-determinism is crucial for managing expectations about AI behavior. By framing it as a balance between creativity and consistency, you help stakeholders understand that this variability is a fundamental aspect of generative AI. This allows them to make informed decisions about whether to adjust parameters for their specific use case, ensuring they have the right tool for the job while maintaining realistic expectations about performance.

Exam trap

Candidates often blame the model for being 'broken' or inconsistent, failing to explain that variability is a configurable feature intended to provide diverse and creative outputs when necessary for the task.

198
Multi-Selectmedium

A security architect is configuring the Anthropic Console for a large enterprise. Which TWO features should be implemented to enforce centralized governance and reduce the risk of unauthorized account access?

Select 2 answers
A.Single Sign-On (SSO) integration via SAML 2.0.
B.Automatic rotation of all API keys every 24 hours.
C.Role-Based Access Control (RBAC) to limit 'Admin' permissions.
D.Real-time packet inspection of all API traffic.
E.Hardware Security Module (HSM) storage for all model weights.
AnswersA, C

SSO allows the enterprise to manage Anthropic access through their existing identity provider, such as Okta or Azure AD. This ensures that when an employee leaves the company, their access to the Anthropic environment is automatically revoked, significantly reducing the risk of orphaned accounts and unauthorized access.

Why this answer

Centralized governance in the Anthropic Console involves managing how users authenticate and what permissions they have. Implementing enterprise-grade access controls ensures that only authorized personnel can generate API keys or view usage metrics, which is vital for maintaining a secure and compliant AI environment.

Exam trap

Candidates mistakenly select runtime code-level configurations or model parameters when asked about enterprise-level console governance and access management controls.

199
Multi-Selecthard

Which THREE strategies should be employed to securely manage sensitive data within an agentic workflow?

Select 3 answers
A.Apply PII masking/redaction before passing text to the LLM.
B.Enable the model to have full administrative access to the file system.
C.Implement fine-grained access control (RBAC) on all tool calls.
D.Maintain immutable audit logs of all model inputs and outputs.
E.Embed all user data directly into the system prompt for faster access.
AnswersA, C, D

PII masking ensures that sensitive data never leaves your secure environment in a readable format. By replacing names, emails, or IDs with tokens, the model can still perform logic based on the pattern without ever having access to the real, private data, which is essential for GDPR/HIPAA compliance.

Why this answer

Securing agents requires a layered approach: PII masking before sending to the model keeps data private; granular access control ensures the agent only touches data it is authorized to see; and audit logging provides traceability for every decision made. These components ensure that even if the agent is compromised or hallucinates, the impact is contained, data privacy is maintained, and there is a clear record of actions taken for compliance and forensics.

Exam trap

Candidates often focus solely on encrypting data at rest while forgetting that sensitive PII must be actively scrubbed before being passed to external LLM APIs.

200
MCQmedium

You are operating a Claude-based support agent that must follow a strict refund policy: refunds over $500 require a manager approval code that is only obtainable through a separate internal API. The agent has access to a `get_manager_code` tool, but in production it occasionally issues refunds above $500 without calling the tool. Which architectural change most reliably prevents this?

A.Expand the system prompt to describe the $500 threshold in bold and add two few-shot examples of correct refund handling.
B.Increase the max_tokens setting so the agent has more room to reason about whether approval is needed.
C.Add a pre-tool-use hook that inspects the refund amount and blocks any refund tool call above $500 unless a valid manager code is present in the session state.
D.Lower the model temperature to 0 so the agent produces deterministic decisions.
AnswerC

A pre-tool-use hook runs deterministically before the tool executes, so it can inspect the refund payload and reject any call over $500 that lacks a verified manager code. This enforces the policy outside the model's probabilistic reasoning, which is exactly where a hard business rule belongs. It makes violation architecturally impossible rather than merely unlikely.

Why this answer

Hard business constraints must be enforced deterministically outside the model. A pre-tool-use hook inspects the pending refund call and rejects any amount above $500 that lacks a validated manager code, making the violation impossible rather than improbable. Prompting, temperature, and token limits only shift probabilities and cannot guarantee compliance with a policy that carries financial or legal consequences.

Exam trap

The trap here is assuming that stronger prompting or lower temperature can enforce a hard business rule, when only deterministic interception outside the model can guarantee it.

201
MCQhard

A stakeholder demands that your team integrate Anthropic models into a sensitive financial system. How do you address the 'data privacy' concern?

A.Claim that privacy is guaranteed by Anthropic and no further action is needed.
B.Provide documentation on data encryption, retention, and compliance.
C.Ask them to sign a waiver saying they take responsibility for data leaks.
D.Agree to use the data for model training to improve performance.
AnswerB

Supplying detailed, factual documentation on how data is encrypted, processed, and deleted provides the objective evidence stakeholders need to conduct a risk assessment. This transparency is the primary mechanism for building trust and ensuring the application passes compliance gates, which is essential for successful adoption in regulated industries.

Why this answer

Addressing privacy concerns requires explaining the data security architecture, including data processing, storage, and retention policies. The architect must demonstrate that the implementation aligns with enterprise security standards. This is essential because stakeholder trust is the foundation of any deployment involving sensitive data; without clear documentation and assurance regarding privacy, the project will likely be blocked or experience significant delays during the security review phase.

Exam trap

Candidates often provide generic assurances about security without referencing specific documentation, missing that formal data encryption and retention policies are required for compliance.

202
Multi-Selecthard

You are designing a long-running agent that executes a sequence of irreversible operations, such as issuing refunds and sending customer notifications. The agent runs unattended overnight. Which TWO architectural patterns best ensure that a partial failure does not leave the system in an inconsistent state? (Choose two.)

Select 2 answers
A.Cache all tool responses in memory so the agent can replay the session without re-calling tools after a restart.
B.Raise the max_tokens limit for each planning step so the agent can reason through more contingencies before acting.
C.Implement compensating actions so that each irreversible operation has a defined reversal or mitigation step.
D.Increase the model's temperature so it explores alternative execution orders and avoids getting stuck on a failing step.
E.Record each intended operation in a durable journal before executing it, and mark it complete only after the tool confirms success.
AnswersC, E

Compensating actions provide a defined path to undo or mitigate an operation that succeeded but belongs to a workflow that later failed. For refunds and notifications, this might mean issuing a reversal or a correction notice. Together with journaling, compensation ensures that a partially completed sequence can be brought back to a consistent state rather than left with orphaned side effects.

Why this answer

Unattended agents performing irreversible actions need both a durable record of intent and a way to reverse or mitigate completed steps. Journaling provides the audit trail and restart logic, while compensating actions provide the semantic undo. Together they allow the orchestrator to detect partial completion and bring the workflow back to a consistent state after a crash or timeout.

Exam trap

The trap here is reaching for model-side knobs like temperature or token limits to solve what is fundamentally a distributed-systems durability and compensation problem.

203
Multi-Selecthard

An architect is defining the Shared Responsibility Model for a company deploying Claude via the Messages API. Which THREE tasks are the sole responsibility of the customer (the 'User') rather than Anthropic?

Select 3 answers
A.Classification and sanitization of PII within input prompts.
B.Physical security of the data centers housing the TPU/GPU clusters.
C.Fine-tuning the base model's Constitutional AI principles.
D.Implementing Identity and Access Management (IAM) for API key usage.
E.Monitoring model outputs for internal policy compliance and accuracy.
AnswersA, D, E

Customers are responsible for identifying and managing the sensitivity of the data they send to the model. Anthropic does not automatically know which data points constitute PII for a specific business context, so the customer must implement their own redaction or classification logic before calling the Messages API.

Why this answer

Understanding the Shared Responsibility Model is essential for risk management in AI deployments. While Anthropic secures the base model and underlying infrastructure, the customer remains responsible for the data they input, how they configure access to the API, and the specific ways the model's output is integrated into their business processes.

Exam trap

Candidates often assume that cloud providers or model vendors handle data privacy filtering and output correctness out of the box, confusing provider responsibilities with customer duties.

204
MCQhard

You operate a long-running research agent that maintains a scratchpad of findings across many turns. You notice that as the scratchpad grows, the agent begins ignoring recent tool results and repeating earlier conclusions. You cannot increase the context window. Which intervention most directly addresses the root cause of the recency failure?

A.Move the scratchpad out of the prompt entirely and store it in an external vector database, retrieving relevant entries only when the agent explicitly asks.
B.Append every tool result verbatim to the scratchpad so no information is lost, and instruct the agent to re-read the entire scratchpad before each decision.
C.Restructure the scratchpad into a fixed-size rolling summary that is regenerated each turn, with the most recent tool results kept verbatim in a dedicated, clearly delimited section.
D.Lower the model's temperature to zero so the agent becomes more deterministic and less likely to drift from the current evidence.
AnswerC

The root cause is that accumulated history pushes recent results into a diluted middle position. A rolling summary compresses old findings into a bounded block, while a dedicated recent-results section guarantees the newest evidence sits in a high-attention position. This keeps total context roughly constant, so recency is preserved without needing a larger window.

Why this answer

The agent is not forgetting recent results so much as losing them in an ever-growing block of text where early material dominates attention. Bounding the scratchpad with a regenerated rolling summary keeps total size stable, and reserving a clearly delimited section for the newest tool results puts current evidence in a position the model reliably attends to. This fixes the structural cause rather than the sampling or storage symptoms.

Exam trap

The trap here is diagnosing the recency failure as a memory or determinism problem and reaching for external storage or temperature changes, when the actual cause is where recent evidence sits inside a growing context.

205
MCQmedium

Refer to the exhibit. An agentic loop receives this response from the Anthropic API during a critical multi-step operation. Which strategy should the architect implement to ensure the agent completes its task successfully?

A.Immediately terminate the agent and alert the user
B.Restart the entire agentic loop from the first message
C.Implement exponential backoff with jitter in the orchestrator
D.Reduce the temperature of the next request to 0
AnswerC

This is the standard resilience pattern for distributed systems. Retrying the request after an increasing delay, combined with a small amount of randomness (jitter), helps mitigate congestion on the API server while allowing the agent to eventually proceed with its task once the service stabilizes.

Why this answer

Transient API errors like 'overloaded_error' are common in high-traffic environments. A robust agentic architecture must handle these gracefully using exponential backoff. This prevents the agent from failing the entire task due to a temporary service interruption and ensures that the long-running state of the agent's work is preserved and resumed.

Exam trap

Candidates often suggest increasing the model temperature or changing the system prompt. These do not solve transient infrastructure issues and will result in repeated failures during high-traffic periods.

206
MCQeasy

A support engineering team wants new hires to become productive with the company's internal Claude-powered assistant quickly. They need a single place where engineers can discover approved prompt patterns, see working request examples, and read guidance on handling tool-use results. Which artifact best serves this enablement goal?

A.A curated internal developer portal page containing vetted prompt templates, runnable request and response examples, and tool-use handling guidance, kept current by the platform team.
B.A generated API reference produced directly from the vendor's public documentation and mirrored nightly into the internal wiki.
C.A read-only archive of the last six months of Slack messages from the team's #claude-help channel, searchable by keyword.
D.A shared drive folder of presentation decks from past architecture reviews, organized by fiscal quarter.
AnswerA

A maintained portal consolidates discovery, approved patterns, and executable examples in one authoritative location, which is exactly what shortens onboarding time. Keeping the platform team as owners ensures the content stays aligned with the current API surface. New hires get both conceptual guidance and concrete request shapes without hunting through scattered repositories or outdated chat threads.

Why this answer

Enablement content works when it is curated, current, and executable. A maintained portal lets new hires discover vetted prompt templates, copy working request examples, and read guidance on tool-use results in one place. Ownership by the platform team keeps it aligned with the evolving API and internal conventions, which directly reduces time to first productive contribution.

Exam trap

The trap here is treating any searchable store of past communication or vendor reference material as sufficient enablement, when discovery, approval status, and runnable examples are what actually accelerate onboarding.

207
MCQhard

An enterprise is deploying Claude for high-stakes financial analysis. Which TWO governance controls should be implemented to mitigate the risk of model hallucinations and ensure factual accuracy?

A.Implement Retrieval-Augmented Generation (RAG) to ground responses in internal trusted knowledge bases.
B.Increase the temperature parameter to 1.5 to maximize response creativity.
C.Utilize a secondary model or deterministic script to validate the factual consistency of completions.
D.Require human intervention for every prompt sent to the API to guarantee zero errors.
E.Disable all safety filters to allow the model to process complex financial jargon.
AnswerA, C

RAG limits the model's knowledge scope by forcing it to answer based on provided context rather than its internal training weights. This grounding technique significantly reduces the likelihood of fabrications, ensuring that financial analyses remain consistent with internal facts and corporate data standards.

Why this answer

Mitigating hallucination risk requires a multi-layered approach involving technical constraints and validation processes. Implementing robust Retrieval-Augmented Generation (RAG) grounds the model's responses in verified source documents, while secondary verification steps add a deterministic layer to the output. These controls are essential in financial services where incorrect data can lead to severe regulatory penalties, financial loss, and significant reputational damage to the organization.

Exam trap

Candidates rely solely on increasing model parameters or prompt length to fix hallucinations, ignoring architectural solutions required for factual grounding.

208
Multi-Selecthard

You are designing a Claude agent that must complete a multi-hour research task spanning dozens of tool calls, and the transcript will eventually exceed the model's context window. You want the agent to keep making correct decisions without losing critical earlier findings. Which TWO architectural strategies best preserve decision quality across the compaction boundary? (Choose two.)

Select 2 answers
A.Summarize and discard the oldest transcript turns once a threshold is reached, retaining only the most recent turns verbatim.
B.Enable extended thinking on every turn so the model can reason through the full history internally without needing external state.
C.Raise the max_tokens parameter on every request so the model can hold more of the transcript in a single response.
D.Maintain an external structured scratchpad of confirmed findings, open questions, and decisions, and inject a curated summary of it into each new context window.
E.Persist a durable task state object and rehydrate the agent from it at each context boundary, treating the transcript as a disposable execution log.
AnswersD, E

An external scratchpad decouples durable knowledge from the ephemeral transcript, so compaction can drop raw turns without losing conclusions. Injecting a curated summary re-establishes the essential state each cycle, and because the scratchpad is structured, the agent can update specific fields rather than rewriting prose. This keeps decisions consistent even when the underlying conversation is truncated.

Why this answer

Durable continuity comes from moving authoritative state outside the transcript. A structured scratchpad preserves confirmed findings and open questions, while a persisted task state object lets the agent rehydrate deterministically at each boundary. Together they let compaction discard raw turns safely.

Token limits and internal reasoning do not expand context or survive eviction.

Exam trap

The trap here is conflating output length controls and reasoning effort with input context capacity, when none of them persists knowledge across a context reset.

209
MCQmedium

A stakeholder wants to change the project scope halfway through. How do you evaluate the impact?

A.Accept the change immediately to keep the stakeholder happy.
B.Perform a formal impact analysis and present the trade-offs.
C.Deny the request without explanation to prevent scope creep.
D.Work on the request secretly and surprise them later.
AnswerB

A formal impact analysis is the standard professional approach for managing project scope. It forces the team to consider the technical, cost, and time implications of the change. Presenting these trade-offs clearly to the stakeholder allows them to make an informed decision on whether the change is truly worth the required investment.

Why this answer

Managing scope creep involves a structured impact analysis, covering cost, timeline, and technical feasibility. The architect must ensure that the stakeholder understands the trade-offs of their request. This is vital for maintaining project alignment and ensuring that the team is not overloaded with un-resourced tasks that will derail the core objectives and negatively impact the quality of the final deliverable.

Exam trap

Candidates often agree to changes immediately or reject them outright, failing to perform the necessary formal impact analysis required to assess how scope changes affect project timelines and resources.

210
MCQmedium

A software company is using Claude to generate code snippets for internal projects. The security team is concerned that the model might inadvertently suggest code with known vulnerabilities. Which governance control should be implemented to best mitigate this risk?

A.Require developers to manually review all AI-generated code for security issues.
B.Integrate a static application security testing (SAST) tool into the CI/CD pipeline to scan all AI-generated code before merging.
C.Restrict Claude's access to only generate code for non-critical components.
D.Fine-tune Claude on a dataset of secure code examples to reduce the likelihood of generating vulnerable code.
AnswerB

SAST tools analyze code for security vulnerabilities without executing it. Integrating SAST into the CI/CD pipeline ensures that all AI-generated code is automatically scanned before it is merged, catching issues early. This is a direct and effective control to mitigate the risk of vulnerable code being deployed.

Why this answer

Integrating SAST into the CI/CD pipeline is the most effective control because it automatically scans all AI-generated code for known vulnerabilities before merging. This provides a consistent, scalable, and early detection mechanism. Manual review and fine-tuning are helpful but less reliable, and restricting scope does not address the core risk of vulnerable code.

Exam trap

The trap here is relying on manual review or fine-tuning as primary controls, when automated SAST scanning provides a more systematic and reliable mitigation for vulnerable code.

211
MCQhard

Refer to the exhibit. Which component in this API request represents the primary governance layer for preventing model bypass of organizational policies?

A.The model version string
B.The system parameter instructions
C.The metadata object fields
D.The user role in the messages array
AnswerB

The system prompt is specifically designed to provide high-priority instructions that the model prioritizes over user messages. This architectural feature allows developers to embed safety protocols and governance rules directly into the model's context, ensuring that the AI maintains its intended persona and security posture throughout the interaction.

Why this answer

The system parameter serves as the primary governing instruction set for Claude, establishing the operational boundaries and persona before user input is processed. By defining safety constraints and behavioral rules within this field, architects can implement a foundational layer of protection that limits the model's susceptibility to certain prompt injection techniques and ensures consistent adherence to enterprise safety guidelines.

Exam trap

Test-takers frequently look for external security tools or middleware in the exhibit, overlooking the direct governance role that system parameter instructions play in framing core operational rules.

212
Multi-Selecthard

To ensure long-term maintainability and performance of LLM-based applications, which THREE architectural patterns should architects recommend? (Select THREE)

Select 3 answers
A.Decouple prompt management and model selection from core application logic.
B.Cache frequent identical API requests at the application level.
C.Hardcode system prompts to ensure the model behavior cannot change over time.
D.Implement continuous monitoring of token usage, costs, and latency.
E.Use the largest available context window for every single request to maximize intelligence.
AnswersA, B, D

Separating these layers allows developers to swap models or update prompts without deploying new application code. This modularity is essential for long-term maintainability, as it enables the team to adapt to new model releases or optimization requirements without the risk of breaking existing functionality.

Why this answer

Decoupling model logic, implementing robust caching, and establishing monitoring are vital for long-term sustainability. Decoupling allows for model upgrades without massive refactoring, caching reduces latency and costs for repetitive queries, and monitoring ensures that performance degradation is caught immediately. These patterns transform 'experimental' LLM features into production-grade systems that developers can manage efficiently, reducing the technical debt typically associated with quickly-built AI integrations.

Exam trap

Candidates often select manual processes like 'hardcoding prompts' or 'frequent manual testing,' failing to recognize the need for automated, decoupled architectures necessary for production-scale LLM maintenance.

213
MCQmedium

A Claude agent performs a multi-step deployment task. Step 3 calls a `deploy_service` tool that returns success, but the subsequent verification step fails because the service is not yet healthy. The agent currently treats any tool success as completion and ends the workflow. Which change best addresses this?

A.Instruct the model in the system prompt to always wait 60 seconds and re-check health after every deploy.
B.Increase the agent's max_tokens so it has more room to notice the verification failure in its reasoning.
C.Change the `deploy_service` tool to return a boolean instead of a status string so the agent can parse it more easily.
D.Add a post-tool-use hook that polls the service health endpoint and, if unhealthy, returns a structured error to the model so it can retry or escalate.
AnswerD

A post-tool-use hook runs after the deploy call and can independently verify health, converting a false success into a structured signal the model can act on. This closes the gap between the tool's reported success and the actual desired state. It keeps the orchestration deterministic at the verification boundary while letting the model decide the next step.

Why this answer

The agent conflates tool acceptance with desired end state, so verification must be moved into a deterministic post-tool-use hook that polls health and returns a structured error when the service is unhealthy. That lets the model retry or escalate instead of ending the workflow prematurely. Prompting, return-type changes, and token limits all leave the false-success gap intact.

Exam trap

The trap here is equating a tool's successful response with the workflow's desired outcome, when asynchronous systems often report acceptance before the effect is observable.

214
MCQeasy

An engineer is onboarding to a codebase that calls Claude and needs to understand, at a glance, which model, temperature, and max_tokens values a given feature uses. The team wants this discoverable without reading application source. What is the most effective practice?

A.Store model and sampling parameters in a versioned configuration file that the application loads at startup.
B.Rely on code comments near each API call to document the chosen parameters.
C.Ask each engineer to memorize the parameters for the features they own.
D.Log the parameters at debug level so they appear in application logs when needed.
AnswerA

Externalizing model and sampling parameters into a versioned configuration file makes them discoverable without reading application code. Engineers can inspect one file to see which model and limits a feature uses, and changes are reviewable through normal pull requests. It also decouples tuning from code changes, so adjusting temperature or max_tokens does not require a code deploy, improving both clarity and iteration speed.

Why this answer

Parameters that drive model choice, cost, and behavior belong in a versioned configuration file rather than scattered through code or held in memory. This makes them discoverable at a glance, reviewable in pull requests, and changeable without a code deploy. Comments, debug logs, and tribal knowledge each fail at least one of those properties, which is why configuration-as-code is the standard practice for developer enablement.

Exam trap

The trap here is accepting a familiar but weak documentation habit, such as code comments, when the requirement is a durable and reviewable source of truth.

215
MCQmedium

During a pilot, a user discovers the AI can be 'prompt-injected' to reveal internal system instructions. What should be your immediate communication response?

A.Downplay the issue as a minor curiosity and claim it is common for all LLMs.
B.Issue an immediate apology to all users and take the system offline for a security audit.
C.Acknowledge the finding, explain the mitigation plan, and provide an updated timeline for testing.
D.Blame the user for testing the system in a way it was not intended to be used.
AnswerC

Transparency regarding vulnerabilities and clarity in the remediation plan are essential for maintaining stakeholder confidence. This approach shows that the team is proactive in identifying and fixing security flaws, which prevents loss of trust and ensures that the project remains on track despite the technical challenge encountered during the pilot.

Why this answer

Immediate, transparent, and proactive communication is the hallmark of a professional architect. By acknowledging the issue, explaining the fix (such as improved system message structure or input sanitization), and outlining the testing process, you maintain stakeholder trust. This response demonstrates that the team is on top of security and that the system is being actively hardened against threats, which is essential for maintaining project momentum during sensitive pilot phases.

Exam trap

Candidates often attempt to hide the vulnerability or downplay its severity to avoid panic, which destroys stakeholder trust; transparency about the fix and testing timeline is essential.

216
MCQhard

Midway through a Claude integration project, a business stakeholder asks you to add a feature that would let end users upload arbitrary documents and have Claude answer questions about them. The feature is not in the signed statement of work, and the delivery team is two weeks from the first production milestone. What should you do first?

A.Escalate the request to the project management office and let them decide whether to approve the change.
B.Accept the request and absorb the work into the current sprint so the stakeholder sees responsiveness.
C.Perform a lightweight impact assessment covering effort, risk, cost, and milestone impact, then present options with a recommendation to the sponsor and stakeholder.
D.Decline the request and tell the stakeholder to raise it at the next quarterly planning cycle.
AnswerC

Change requests are handled through impact assessment, not instant acceptance or refusal. Quantifying effort, new risks such as document-handling and prompt-injection exposure, incremental API cost, and the effect on the committed milestone lets the sponsor make an informed trade-off, which is the architect's proper role in lifecycle management.

Why this answer

Scope changes mid-project are normal, and the disciplined response is a fast, lightweight impact assessment that converts an informal ask into a decision the sponsor can make with eyes open. Presenting effort, risk, cost, and milestone impact alongside options respects both the signed commitment and the stakeholder's underlying need.

Exam trap

The trap here is treating a mid-project change request as either an automatic yes or an automatic no, when the architect's job is to price the change and let the accountable sponsor choose.

217
MCQeasy

Under the shared responsibility model for AI safety, which task is the primary responsibility of the customer when using Anthropic's APIs?

A.Conducting the base model's pre-training safety audits
B.Patching the underlying hardware infrastructure
C.Developing the Constitutional AI principles
D.Monitoring and filtering application-specific user inputs
AnswerD

Customers are responsible for the inputs they send to the model and the outputs they show to their users. Implementing application-level monitoring, moderation, and abuse detection is a critical customer responsibility to ensure the AI solution remains safe and compliant within its specific deployment context.

Why this answer

Anthropic manages the safety of the base model through training and infrastructure, but customers are responsible for how they implement the model in their specific context. This includes monitoring end-user behavior and ensuring that the application's specific use case complies with overall usage policies. Understanding this division is essential for establishing clear accountability and risk management procedures.

Exam trap

Candidates often assume the model provider is responsible for all safety. They fail to realize that the customer is responsible for filtering inputs specific to their unique application context.

218
MCQhard

Refer to the exhibit. The application is hitting rate limits during peak hours. What is the best architectural change to improve operational resilience?

A.Increase the timeout duration of the API calls indefinitely.
B.Implement an exponential backoff strategy with jitter.
C.Bypass the API gateway and send requests directly to the model's backend IP.
D.Disable all retries to prevent the application from crashing.
AnswerB

Exponential backoff with jitter is the recommended strategy for handling transient rate limits. By increasing the wait time between retries and adding randomness, the application avoids overwhelming the API upon recovery. This ensures a stable, resilient architecture that handles traffic spikes gracefully without persistent errors.

Why this answer

Implementing an exponential backoff strategy with jitter is the industry-standard approach for handling 429 rate-limiting errors. Unlike static retries, this approach prevents the 'thundering herd' problem, where multiple failed requests attempt to reconnect simultaneously, further stressing the service. This enhances operational stability, ensures more graceful handling of high-traffic scenarios, and improves the overall reliability of the system, which is a key requirement for professional architects.

Exam trap

Candidates often choose basic synchronous retry loops or client-side caching instead of exponential backoff with jitter, failing to realize that static retries exacerbate traffic spikes and worsen rate-limit errors during peak operational windows.

219
MCQeasy

A startup is using Claude to generate marketing copy. The legal team is concerned about potential copyright infringement if the model reproduces copyrighted text. Which governance measure should the startup implement to best mitigate this risk?

A.Include a disclaimer that any resemblance to existing works is coincidental.
B.Set the model's temperature to zero to ensure deterministic outputs.
C.Use a plagiarism detection tool to scan all generated content before publication.
D.Fine-tune Claude on the startup's own proprietary content to avoid using external data.
AnswerC

A plagiarism detection tool compares generated content against a vast database of copyrighted works and can flag potential infringements. This allows the startup to review and modify problematic outputs before publication, directly mitigating the risk of reproducing copyrighted text. It is a practical and effective control for this scenario.

Why this answer

The plagiarism detection tool is the most direct mitigation because it actively checks generated content against known copyrighted works and flags potential matches. This allows human review and modification before publication. Other options either do not prevent infringement or are ineffective, such as disclaimers or temperature adjustments.

Exam trap

The trap here is assuming that technical settings like temperature or fine-tuning can prevent copyright infringement, when in fact external verification is needed.

220
Multi-Selectmedium

Which THREE practices most effectively support a 'Prompt Engineering as Code' workflow for enterprise teams? (Select THREE)

Select 3 answers
A.Storing prompts in text files within the same repository as the application code.
B.Using hardcoded prompt strings in the production environment for maximum speed.
C.Implementing automated evaluation scripts to test prompt changes against a golden dataset.
D.Mandating manual review for every single request made by the production model.
E.Establishing a peer review process for all changes to prompt templates.
AnswersA, C, E

Treating prompts as code assets allows for version control, branching, and pull-request-based reviews. This ensures that changes to prompts are tracked, auditable, and easily reversible. Keeping them in the repo ensures that the prompt version is always aligned with the application logic that consumes it at runtime.

Why this answer

Managing prompts as versioned assets, automating evaluation pipelines, and enforcing peer reviews enable scalable and safe prompt lifecycle management. When prompts are treated like software, teams gain the ability to rollback, audit changes, and ensure that modifications do not degrade performance. This professionalizes the development process, reducing the risk of unexpected model behavior and allowing teams to deploy LLM-powered features with confidence and speed.

Exam trap

Candidates often select manual tracking methods or storing prompts in disconnected UI dashboards, ignoring software engineering best practices like repository storage and peer reviews.

221
MCQeasy

You are preparing a steering committee update for a Claude-based customer support assistant that has been live for two months. The sponsor asks for a concise way to judge whether the investment is paying off and whether the project should continue to the next phase. Which set of measures best answers that question?

A.Model parameter count and the number of prompt templates currently maintained in the repository.
B.Deflection rate, customer satisfaction for AI-handled interactions, average handling time change, and adoption among support agents.
C.Total number of API calls made and the cumulative token spend since launch.
D.Number of incidents logged and the mean time to resolve production issues over the reporting period.
AnswerB

These measures connect the assistant to business outcomes: fewer escalations, happier customers, faster resolution, and real usage by the intended users. Together they let the sponsor assess whether the investment is producing value and whether expansion is justified. They also expose risks such as high deflection with low satisfaction, which raw volume metrics would hide entirely.

Why this answer

A phase-gate decision needs outcome-oriented evidence, not consumption or engineering trivia. Deflection, satisfaction, handling time, and agent adoption together show whether the assistant improves customer service and is actually used. They also reveal the quality-versus-volume tension that sponsors must weigh, making them the right foundation for a continuation recommendation.

Exam trap

The trap here is equating activity or cost metrics with business value, when sponsors need outcome measures to justify continued investment.

222
Multi-Selectmedium

A company is integrating Claude into a high-stakes automated decision-making system. Which TWO practices should be implemented to align with Anthropic’s Responsible AI principles?

Select 2 answers
A.Allow the model to finalize decisions without human review.
B.Implement human-in-the-loop oversight for model outputs.
C.Establish a continuous monitoring and evaluation framework.
D.Only use the most advanced model available for all tasks.
E.Disable all system logs to preserve user privacy.
AnswersB, C

Human-in-the-loop (HITL) oversight is a foundational principle for responsible AI. By requiring humans to review and approve model outputs in high-stakes scenarios, organizations mitigate the risk of errors and ensure that decisions adhere to ethical standards and institutional policies, significantly improving the overall safety of the AI deployment.

Why this answer

Integrating LLMs into high-stakes environments requires a focus on human-in-the-loop (HITL) oversight and continuous monitoring. These practices help manage hallucinations and maintain accountability. Without these safeguards, automated systems can produce biased or incorrect outcomes without human correction.

Implementing these protocols ensures that AI governance remains aligned with human values and organizational safety goals, reducing the risk of unintended consequences in critical decision-making processes.

Exam trap

Test-takers might choose automated self-correction loops without human intervention, overlooking the mandate for human-in-the-loop oversight in high-stakes decisions.

223
MCQmedium

A team uses a CI/CD pipeline to deploy LLM applications. They want to ensure prompt changes do not degrade model performance. Which strategy best integrates evaluation into the development workflow?

A.Perform manual prompt testing by the QA team before every release.
B.Run automated evaluation scripts against a golden dataset during the CI process.
C.Rely on user feedback loops in production to identify and fix issues.
D.Only evaluate the application after it has been deployed to the production environment.
AnswerB

Automated evaluation against a golden dataset provides objective, repeatable metrics to validate prompt quality before deployment. This allows developers to catch regressions early in the SDLC. By integrating this into CI, teams maintain high deployment velocity without sacrificing the quality or safety of the LLM application outputs.

Why this answer

Integrating automated evaluations (Evals) into the CI/CD pipeline ensures that every code or prompt change is validated against a golden dataset. This automated gate prevents regressions from reaching production. It empowers developers to iterate quickly while maintaining a high bar for reliability, which is crucial for operational enablement in LLM-driven environments where non-deterministic model behavior can introduce subtle, hard-to-detect bugs that impact user experience.

Exam trap

Candidates often suggest periodic manual audits or post-deployment monitoring, overlooking the critical requirement to integrate automated evaluation gates directly into the CI/CD pipeline for immediate feedback.

224
MCQmedium

Refer to the exhibit. The user is attempting to trick the model into revealing sensitive information by claiming a high-clearance role. This is an example of which security threat, and how does the 'system' prompt help mitigate it?

A.Man-in-the-middle attack; the system prompt encrypts the secret code name.
B.Prompt injection (jailbreaking); the system prompt establishes a higher-priority context.
C.Denial of Service (DoS); the system prompt limits the tokens used to hide the secret.
D.Data poisoning; the system prompt cleans the training data in real-time.
AnswerB

The user is attempting a 'jailbreak' by assuming a false identity to override safety rules. The system prompt provides a separate, authoritative channel for instructions that Claude is trained to follow strictly, helping the model maintain its boundaries even when the user prompt is manipulative.

Why this answer

Social engineering and role-playing are common techniques used in prompt injection attacks to bypass security constraints. The system prompt is a powerful governance tool because it sets the foundational rules and persona for the model, which are prioritized by Claude's reasoning engine over conflicting instructions found in the user messages.

Exam trap

Candidates frequently misattribute the defense mechanism to post-processing filters or output guardrails, ignoring the structural priority given to the system prompt.

225
MCQhard

Your team is deploying an application that uses PII in prompts. A stakeholder asks how you are mitigating the risk of data leakage. How do you respond?

A.Assure them that the model is smart enough to handle PII.
B.Explain the use of PII masking and data sanitization pipelines.
C.Tell them the model does not store any data anyway.
D.Suggest moving the project to an on-premise LLM to ensure security.
AnswerB

Describing concrete architectural controls like masking or sanitization provides the stakeholder with confidence that privacy is actively managed. These techniques are standard for protecting sensitive information in LLM pipelines. This approach demonstrates a professional, risk-aware mindset that is expected of a certified architect managing complex AI deployments.

Why this answer

The correct response involves explaining a combination of data sanitization, prompt masking, and secure infrastructure design. This is critical because PII handling is a high-liability area. By detailing a defense-in-depth strategy, the architect provides the necessary assurance that privacy is treated with the highest priority, which is vital for maintaining organizational compliance and preventing severe legal or reputational damage during the application's lifecycle.

Exam trap

Candidates often suggest 'just encrypting' the data, which ignores the need for PII masking and sanitization before the data ever reaches the model's context window.

Page 2

Page 3 of 4

Page 4

All pages