CCAR-P · domain
scenario questions
Practise Claude Certified Architect - Professional scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (262)
Click any question to see the full explanation, or start a practice session above.
You are the lead architect on a Claude-powered internal knowledge assistant. Six weeks into the pilot, the executive sponsor asks for a one-page status update that will be forwarded to the CFO, who has never attended a demo. Which artifact should you produce?
Medium2A project manager is overseeing a multi-phase implementation of Claude-based automated workflows. During the transition to production, the CISO expresses concerns regarding data privacy. Which strategy best addresses the stakeholder’s requirements while maintaining project momentum?
Medium3Which mechanism best facilitates secure, ephemeral access to Anthropic API keys for developers within a containerized CI environment?
Easy4A developer enablement team is building an internal prompt playground so engineers can iterate on Claude prompts without writing API code. They want the playground to reflect production behavior and avoid surprising cost overruns. (Choose two.)
Medium5Which THREE practices assist in maintaining a robust observability strategy for Anthropic API usage?
Medium6An organization is conducting a risk assessment for an AI application. They are concerned about 'model drift' over time. Which governance action is most appropriate to manage this risk?
Medium7Your organization is scaling its use of Anthropic API across multiple business units. Which TWO actions should you take to ensure effective lifecycle management and communication of service changes to stakeholders?
Hard8Which TWO security measures are most effective at preventing 'Prompt Injection' attacks that target the arguments of tools used by an agent?
Hard9A bank is deploying a Claude agent that can call internal tools to move funds between accounts. Risk leadership wants a control that limits the blast radius if the agent is manipulated into performing unauthorized transfers. Which control best addresses this requirement?
Hard10A developer support team receives repeated reports that Claude responses in an internal tool are truncated mid-sentence. Logs show the stop_reason value is max_tokens on most affected calls. Which change most directly resolves the truncation while preserving response quality?
Hard11A developer is building an application that needs to use multiple models (e.g., Haiku for speed, Sonnet for quality). What is the best pattern to handle model selection dynamically?
Hard12What is the primary benefit of using a 'System Prompt' to define an agent's persona and constraints compared to embedding these in the user message?
Medium13When designing an agent that must perform highly sensitive operations (e.g., deleting records), what architectural pattern is mandatory?
Hard14You are the lead architect on a Claude-powered claims triage system that has been in production for six months. A newly appointed VP of Operations asks for a quarterly review of the system's lifecycle status. Which deliverable best satisfies this request while maintaining stakeholder alignment?
Medium15A company is scaling its Claude-powered applications globally. Which strategy best optimizes for both latency and cost?
Medium16A security architect is performing red-teaming on a new Claude-powered application. They are specifically testing for 'jailbreaking' attempts where a user tries to bypass safety filters by using roleplay or adversarial framing. Which TWO strategies are most effective for mitigating this specific risk at the architectural level?
Hard17An organization is deploying Claude to provide automated coding assistance. To manage the risk of generating insecure code or violating open-source licenses, which governance step is most effective?
Hard18Refer to the exhibit. The monitoring system logs these safety rejections. How should you communicate this to the product owner?
Medium19During a project, a stakeholder requests a feature that violates your established safety guidelines. What is the most professional way to handle this?
Medium20A developer enablement group is standing up a shared Claude integration library that dozens of internal teams will consume. They want to reduce duplicated work and prevent each team from re-implementing fragile request handling. Which TWO practices best improve developer productivity across those consuming teams? (Choose two.)
Medium21Which architectural pattern is best suited for long-running, multi-step agentic workflows that require human-in-the-loop intervention?
Hard22A team is building an agent that must call a payment provider's API. The API requires an idempotency key on every charge request, and the agent may retry a charge if a network error occurs mid-call. Which design correctly preserves financial correctness when retries happen?
Easy23An organization is deploying a customer-facing chatbot using Claude 3.5 Sonnet and needs to ensure the model adheres to ethical guidelines without relying solely on manual moderation. Which core Anthropic safety framework is primarily responsible for the model's ability to self-correct based on a predefined set of principles during its training phase?
Medium24A hospital network is drafting its AI risk register for a Claude-based discharge-summary assistant. The governance lead wants entries that describe residual risk after existing controls are applied, and that can be assigned an owner and a review cadence. Which TWO characteristics must each risk register entry have to meet this standard? (Choose two.)
Medium25Which architectural approach is best for handling an agent's failure to retrieve information from a database tool?
Medium26A development team is integrating Claude into a high-throughput CI/CD pipeline and notices occasional 429 Too Many Requests errors. What is the most effective architectural approach to improve system reliability while maintaining developer speed?
Medium27Which approach best aligns with the principle of 'least privilege' when providing API access to internal teams?
Medium28A developer is building a tool that lets engineers query an internal knowledge base through Claude. During testing, Claude sometimes invents plausible but nonexistent document titles when the retrieved context is thin. The team wants a systematic way to detect and reduce these hallucinations before the tool reaches general availability. Which approach is most appropriate?
Medium29A fintech company wants to use Claude to generate personalized financial advice for retail customers. The compliance team mandates that all AI-generated advice must be traceable to a specific model version and configuration for audit purposes. Which governance control best satisfies this requirement?
Medium30A platform team is standardizing how internal teams integrate Claude. Leadership wants faster onboarding, fewer production incidents, and clear accountability for cost. Which TWO practices best support these goals? (Choose two.)
Hard31An agent uses a retrieval tool that returns the top 20 chunks for any query. In production, the agent frequently cites irrelevant chunks and sometimes misses the correct answer even when it is present in the corpus. The corpus contains documents with overlapping terminology. Which architectural change most improves answer grounding without increasing the number of retrieved chunks?
Hard32A software company's internal AI review board is defining escalation criteria for its Claude-powered support assistant. The board wants a rule that reliably routes the highest-consequence cases to human specialists rather than relying on the model's own confidence statements. Which escalation design best achieves this?
Hard33A public-sector agency must demonstrate to an external auditor that its Claude-based citizen inquiry assistant was operated in line with its approved safety policy throughout the prior fiscal year. The agency has no centralized record of which policy text was in force, when it changed, or who approved each change. Which governance practice should the agency institute first?
Easy34An enterprise wants to minimize the risk of PII (Personally Identifiable Information) being processed by Claude while maintaining low latency. Which architectural approach provides the best balance of safety and performance?
Medium35An agentic system is designed to run long-lived 'background' tasks that may take several days to complete. How should the architect manage the agent's state to ensure it can resume correctly after a system reboot?
Hard36A financial services firm runs a Claude-powered agent that can call internal tools to move funds between accounts. Risk management wants a control that prevents the agent from executing a transfer above a threshold without human sign-off, and that remains effective even if the model is manipulated through injected content in a retrieved document. Which control best meets this requirement?
Hard37An enterprise client is concerned about the 'black box' nature of LLMs. Which THREE communication strategies should the architect use to build transparency and trust?
Medium38A large enterprise is setting up its governance framework for Anthropic API usage. Which THREE features provided by the Anthropic Console are essential for maintaining auditability and administrative control?
Medium39A regulated healthcare client is reviewing your Claude-based patient-intake summarization tool. Their compliance officer asks how you will handle a scenario where the model produces a clinically inaccurate summary. Which response demonstrates the strongest lifecycle and stakeholder communication practice?
Hard40Refer to the exhibit. An audit of an Anthropic API configuration reveals the policy shown. What is the primary governance concern with this implementation?
Medium41Which THREE strategies are effective for managing bias in AI-driven decision-making systems?
Hard42An organization requires strict adherence to data residency requirements for PII processed by Claude. Which strategy best ensures that customer prompts and completions remain within a specific geographic boundary while utilizing Anthropic's API?
Medium43A development team wants to optimize the latency of their prompt engineering workflow using Claude. They currently run evaluations sequentially. Which approach best improves iteration speed?
Medium44An enterprise client is integrating Claude for automated financial reporting. The stakeholders are concerned about data privacy and the potential for model hallucinations leading to inaccurate balance sheets. As the lead architect, how should you best manage these stakeholder expectations regarding output reliability?
Medium45A fintech company's risk committee is operationalizing a governance program for Claude-powered customer support agents. They must demonstrate to regulators that model behavior changes are tracked, attributable, and reversible. Which TWO practices best satisfy this requirement? (Choose two.)
Hard46A multinational corporation is using Claude to process employee feedback surveys. The data includes sensitive personal opinions. The governance team must ensure that the AI system complies with the EU's General Data Protection Regulation (GDPR). Which control is most critical to address the 'right to explanation' requirement for automated decision-making?
Hard47You are the lead architect on a Claude-powered claims triage tool. Six weeks before launch, the executive sponsor asks for a single one-page view of project health that shows schedule variance, cost variance, and scope changes at a glance. Which artifact should you produce?
Easy48A document-processing agent must extract structured fields from thousands of PDFs. Some PDFs are scanned images, some are native text, and some are encrypted. The architect wants one pipeline that routes each document to the appropriate extractor and reports per-document confidence. Which design best fits?
Medium49A stakeholder expresses concern about data privacy regarding the inputs sent to Claude. What is the most appropriate way to address this?
Medium50When planning for the long-term support of an Anthropic API deployment, what is the most important stakeholder alignment activity?
Medium51You are designing an agentic workflow that must reliably complete a multi-step refund process across an internal billing service and an external payment gateway. The workflow can fail at any step, and partial completion is unacceptable. Which two architectural mechanisms are required to guarantee that the workflow either completes fully or leaves no partial effect? (Choose two.)
Medium52Your organization is preparing to retire a legacy Claude model snapshot that several internal teams still call through their own applications. You must communicate the deprecation without disrupting business operations. (Choose two.)
Medium53A platform team wants every service to call Claude through a single internal gateway that injects the system prompt, enforces token budgets, and emits OpenTelemetry traces. A developer proposes having each service call the Anthropic Messages API directly and centralizing only the API key in a shared vault. What is the strongest architectural reason to reject the developer's proposal?
Medium54Your organization is scaling an internal library that wraps Anthropic API calls. To minimize the cognitive load on developers using this library, what is the most effective pattern to implement?
Medium55You are architecting a customer-support agent for a SaaS platform. The agent must answer billing questions using a live invoice API and general policy questions using a static knowledge base. The invoice API is fast but occasionally returns stale data; the knowledge base is large and slow to search. Your design gives the agent a dedicated 'billing' sub-agent and a 'policy' sub-agent, coordinated by a router agent. After deployment, you observe the router sending nearly every query to both sub-agents in parallel, causing high latency. Which architectural change best addresses this while preserving answer quality?
Medium56An agentic system uses a supervisor agent that delegates to specialized worker agents. During a long incident, the supervisor's own context fills with worker transcripts, and it begins losing track of which workers have completed and which are still running. Which TWO architectural changes best preserve the supervisor's ability to coordinate correctly? (Choose two.)
Hard57Refer to the exhibit. An audit team identifies that the system message lacks specific data handling instructions for sensitive reports. As the architect, what is the best approach to communicate this to the development team?
Medium58How should a development team manage sensitive system instructions that they do not want users to see or modify?
Medium59When designing a system for high-volume document analysis, what is the best strategy to maximize cost efficiency and developer velocity?
Medium60When designing an LLM application, what is the best strategy for managing 'system instructions' (system prompts) to prevent unauthorized alteration?
Medium61An organization wants to allow non-technical business users to test Claude prompts without exposing them to raw API code. What is the most productive approach to empower these users?
Medium62You are architecting a Claude agent that orchestrates a long-running approval workflow spanning hours or days, where human reviewers may intervene between steps. Which TWO mechanisms are necessary to keep the workflow correct across these interruptions? (Choose two.)
Medium63Your team operates a Claude-based internal knowledge assistant. A new compliance officer asks how the platform will handle model deprecations and capability changes over the next 24 months. Which TWO practices should be established now to give stakeholders durable lifecycle assurance? (Choose two.)
Hard64An enterprise wants to deploy an AI-powered customer service agent. What is the most important governance consideration when integrating with internal customer databases?
Hard65A research agent uses Claude with an extended thinking budget to analyze a 200-page regulatory filing. Mid-analysis it must call a `fetch_footnote` tool whose result is essential to the conclusion. The architect wants the tool result to be incorporated without discarding the model's prior reasoning. Which approach best achieves this?
Hard66An organization is evaluating the safety of an LLM-based agent. What is the 'Red Teaming' process in this context?
Medium67An architect needs to build an agent that handles complex, multi-step data migrations where each step depends on the output of the previous one. Which approach is most robust for ensuring the agent doesn't lose track of the long-term goal during execution?
Hard68A project sponsor asks for a timeline estimation for a project utilizing Claude for sentiment analysis. What is the most appropriate architectural response?
Easy69You are the lead architect on a Claude-powered contract-analysis platform. Two weeks before go-live, the General Counsel asks for written assurance that the system will not retain client contract text for model training and that all data stays within the EU. Which artifact should you produce first to satisfy this governance obligation?
Medium70A production agent uses a ReAct loop and frequently reaches its maximum step budget while still mid-task, then returns a partial answer that looks complete. Telemetry shows the agent often re-reads the same file and re-queries the same database row across consecutive steps. Which change most directly reduces wasted steps while preserving the agent's ability to finish?
Hard71When evaluating the performance of a new 'Orchestrator-Worker' agentic architecture, which THREE metrics provide the most insight into the system's efficiency and reliability?
Medium72Which THREE components are essential for a robust 'Stakeholder Communication Plan' during an LLM project rollout?
Hard73A developer support team wants to give engineers a fast way to reproduce and debug failed Claude requests without exposing API keys or requiring them to install the SDK locally. Which approach best balances speed and safety?
Medium74A business unit has been running its own Claude-powered tool outside the central platform for four months. It works well, and the unit lead wants it blessed as-is rather than migrated. As the platform architect, what is the most appropriate first step?
Hard75An engineering organization is building a shared internal Claude gateway used by many product teams. They want to enable rapid experimentation while keeping spend predictable and preventing any single team from starving others. Which TWO controls should the gateway implement to meet these goals? (Choose two.)
Hard76Which governance risk is most directly mitigated by using 'Versioned' model identifiers (e.g., 'claude-3-5-sonnet-20240620') instead of the generic 'claude-3-5-sonnet' alias in production?
Medium77Refer to the exhibit. An organization uses this configuration to prevent the model from continuing the conversation as the user. What is the governance benefit of this configuration?
Medium78A developer wants to monitor prompt effectiveness in production without logging sensitive user data. What is the best practice?
Easy79Your team is deploying an AI agent that makes automated financial decisions. What is the most critical communication to have with the legal/compliance department?
Hard80You are building a customer-support agent with Claude that must call a lookup_order tool, then a refund_order tool that depends on the order's status. During testing, the agent sometimes calls refund_order before the lookup_order result returns. Which change to your orchestration loop best enforces the required ordering?
Medium81A company is using Claude to process customer feedback. They want to ensure that if a customer mentions self-harm or illegal activities, the system immediately flags this for a human moderator. Which tool is best suited for this specific governance task?
Medium82Which TWO actions should an architect take during the 'Design Phase' to ensure long-term model governance with stakeholders?
Medium83An agentic system often experiences 'goal drift' when managing long-running, multi-step tasks. Which architectural pattern most effectively mitigates this risk during recursive reasoning chains?
Medium84A developer productivity team is building an internal coding assistant that calls the Claude Messages API. During a spike in usage, the assistant starts failing with 429 responses and users see truncated answers. The team wants the assistant to degrade gracefully under load rather than fail outright, while keeping latency predictable for interactive use. Which change best meets these goals?
Hard85A stakeholder wants to incorporate 'real-time' news data into your Claude-based assistant. What is the most important architectural communication point to convey?
Medium86Your organization is transitioning from a pilot project to an enterprise-wide deployment of Claude. A key stakeholder is worried about the impact on current staff roles. How should you frame the communication to address this?
Hard87An agent must summarize a 400-page contract that exceeds the context window. The team wants a summary that references specific clauses without losing cross-references between distant sections. Which approach best preserves cross-reference integrity?
Medium88A fintech platform runs a Claude-powered transaction summarizer in production. Latency spikes during market open, and the team suspects that requests are being retried unnecessarily when the API returns overloaded errors. They want to make retry behavior observable and tunable without redeploying each service. Which design best meets that goal?
Hard89When conducting a risk assessment for a new Claude-based customer support bot, which TWO factors should be prioritized as 'High Risk' according to Anthropic's safety guidelines?
Hard90Refer to the exhibit. An architect reviews this API request log. Despite the 'Ignore all previous safety instructions' directive, Claude refuses to provide instructions for bypassing the firewall. Which safety mechanism is primarily responsible for this refusal?
Medium91When integrating Anthropic's API with a CI/CD pipeline for automated testing, which security practice is mandatory to avoid credential leakage?
Hard92A financial services firm runs Claude-powered document review for loan applications. The CISO asks the platform team to produce evidence that every model change affecting production was reviewed and approved before deployment. Which governance mechanism most directly satisfies this requirement?
Medium93A developer is building a Claude-based tool to help support agents draft responses. They want to quickly test different prompt variations without redeploying the application. Which Anthropic feature should they use?
Easy94A multinational retailer operates Claude in three regions and must prove that customer data from each region never leaves that region, even during model upgrades. Which architectural approach best satisfies this requirement?
Hard95How should an architect manage the expectations of a stakeholder who expects 100% accuracy from an AI model?
Medium96Which THREE factors should you communicate to stakeholders when planning a production rollout of a Claude-based chatbot?
Hard97Midway through a six-month Claude deployment for a claims-processing team, the operations director tells you the team will not adopt the assistant because 'it slows us down.' Usage telemetry shows agents open the tool but abandon it after one or two interactions. What is the most effective response to this adoption risk?
Hard98An architect is designing an agent to perform administrative tasks in a corporate environment. One of the tools allows the agent to delete employee records. What is the most important architectural safeguard to implement for this specific tool?
Easy99A stakeholder wants to measure the 'return on investment' (ROI) of a Claude-based document automation system. What is the most effective approach?
Medium100A retail company is building a governance program for a customer-facing Claude agent that can issue refunds and update order records. The risk committee wants controls that limit the blast radius of a compromised or misbehaving agent. (Choose two.)
Hard101Your agent orchestrates a research task by spawning several subagents, each with its own Claude conversation, and merging their outputs. You observe that the final synthesis contradicts the subagents' findings. Which architectural change most reliably preserves fidelity when merging?
Hard102A platform team maintains a Claude-powered code review assistant. They want to roll out a new system prompt to production safely. The current process involves manually copying the prompt into a deployment script, which has led to drift and accidental overwrites. Which approach best enables safe, auditable prompt deployments?
Medium103You are presenting a quarterly progress report to executive sponsors. Which information should be highlighted to ensure continued project funding and sponsorship?
Medium104Which governance model best minimizes the risk of 'shadow AI' usage within a large corporation?
Medium105A Claude agent orchestrates three specialized subagents: one for data extraction, one for validation, and one for report generation. In production, the validation subagent sometimes receives malformed input from the extraction subagent and silently produces a passing result. You need the orchestrator to detect and contain these failures without halting the entire pipeline. Which design change is most appropriate?
Medium106A regional sales director wants the Claude assistant to answer questions about competitor pricing using 'whatever is on the internet.' You know the assistant currently uses only approved internal documents. How should you frame the trade-off for the steering committee?
Medium107A support agent built on Claude must decide whether a customer request is a billing issue, a technical issue, or a general inquiry before routing it. The categories are fixed and mutually exclusive, and the routing decision must be fast and cheap. Which approach is most appropriate?
Easy108When deploying Claude in a production environment, an architect notices that the model occasionally generates responses that are slightly biased. What is the most appropriate governance-first approach to address this?
Medium109Refer to the exhibit. An application frequently hits rate limits during peak hours. What is the most robust way to improve operational reliability?
Hard110A non-technical stakeholder asks why the Claude assistant sometimes takes several seconds to respond while other requests feel instant. Which explanation is most appropriate?
Easy111A retail client's marketing director tells you the Claude-based product description generator is 'too slow' and wants it fixed by the end of the week. Before committing engineering effort, what should you do first?
Easy112Midway through delivery of a Claude-powered contract review tool, the legal department asks you to add a new jurisdiction's regulatory rules. The change touches prompt design, evaluation sets, and the review workflow. Which action best manages this change through the project lifecycle?
Hard113A business unit wants to reuse your Claude-based document summarization service for a new internal use case. They ask what they must provide before you can onboard them. Which response best reflects a sustainable internal platform operating model?
Medium114A global financial institution must ensure that all prompt data and model responses for their Claude 3.5 Sonnet implementation remain within the European Union to comply with strict GDPR data residency requirements. Which architecture strategy best fulfills this governance mandate?
Medium115To ensure organizational security and governance when using Anthropic's API, what is the best practice for managing API keys across a team of 50 developers?
Medium116A team maintains a Claude-powered code review bot. Reviewers complain that the bot sometimes approves pull requests that clearly violate the team's security policy. The team wants to make policy violations detectable and reproducible in CI without relying on manual spot checks. What is the most effective approach?
Hard117Refer to the exhibit. The developer reports that the model is cutting off summaries for very long inputs. What is the most likely cause?
Medium118You are building a system that requires strict adherence to a specific output format. Which approach provides the highest reliability in a high-traffic agentic environment?
Hard119You are the lead architect for a Claude-powered document summarization service used by the legal department. Six weeks after launch, the department's managing partner states that the summaries 'miss the point' and that the team has lost confidence in the tool. Logs show the service is technically healthy with 99.9% availability and low latency. What is the most effective next step to restore stakeholder confidence?
Medium120Your organization is scaling its use of Claude across 20+ teams. Which THREE practices should be implemented to ensure operational efficiency and cost control?
Hard121Refer to the exhibit. The model's response to the user's request is a safety violation. How should the architecture be updated to improve safety?
Hard122When designing agentic systems that require human-in-the-loop (HITL) verification, which mechanism prevents the agent from stalling indefinitely while waiting for user input?
Medium123A claims-processing agent runs for hours and must survive process restarts without losing in-flight work. You are designing durable execution around Claude's stateless Messages API. Which TWO practices are required to make the agent resumable? (Choose two.)
Hard124An organization is deploying Claude for a customer support chatbot. They need to ensure that PII is not processed or stored by the model. Which approach best aligns with Anthropic’s safety governance standards?
Medium125Which governance practice is most effective for managing 'Third-Party Model Risk'?
Medium126Refer to the exhibit. An application developer is testing a model endpoint. Which security control should be prioritized to prevent the specific risk demonstrated in the exhibit?
Hard127When designing agents that interact with external APIs, which pattern best addresses the challenge of 'unreliable API latency' impacting the agent's reasoning chain?
Medium128Refer to the exhibit. A stakeholder reports that the output is too verbose. Which change would best address the stakeholder requirement while maintaining model performance and architectural standards?
Medium129Refer to the exhibit. Your agent is receiving this error during a high-concurrency operation. Which implementation correctly handles this scenario?
Medium130A team runs a Claude-based document summarization service. They notice that during peak hours, API requests occasionally fail with rate limit errors, causing user-visible failures. They want to improve reliability without over-provisioning. Which strategy is most effective?
Hard131A financial services firm is deploying an AI agent to handle diverse requests including balance inquiries, market analysis, and loan applications. To minimize latency and maximize precision, the architect decides to implement a pattern where a primary model classifies the intent and delegates to specialized sub-agents. Which architectural pattern is being described?
Medium132A project stakeholder expresses concern that an Anthropic-powered content moderation system is generating unexpected output bias. As the lead architect, how should you communicate the resolution strategy while managing expectations?
Medium133You are standing up a governance cadence for a Claude-based platform that will serve three business units. Which TWO practices are essential to keep stakeholders aligned across the lifecycle? (Choose two.)
Medium134A Claude agent maintains a long conversation with a user over weeks. The architect notices that the agent gradually forgets early constraints the user stated, even though the conversation is well within the model's context window. The team wants to fix this without re-summarizing the entire history on every turn. Which approach is most appropriate?
Hard135An organization discovers that their AI application is producing biased outputs on certain demographic groups. What is the correct governance step to take first?
Hard136What is the primary role of an AI Safety Committee in an enterprise architecture?
Easy137A team notices that Claude's performance fluctuates for a specific task. What is the most logical step to stabilize the output?
Hard138When designing a stakeholder status dashboard for an AI implementation project, which THREE metrics are most critical to include to demonstrate success and maintain alignment?
Medium139A developer wants to reduce the cost and latency of their LLM application, which sends repetitive, long context windows. Which optimization technique is most appropriate?
Medium140When designing a system that uses Claude for data extraction, how should a developer handle non-deterministic outputs to ensure operational reliability?
Medium141You are leading a project involving Claude integration. Which TWO of the following steps are essential for successful stakeholder expectation management during the model evaluation phase?
Medium142A firm is building a financial advisor chatbot. Which safety measure is most critical for preventing the model from providing unauthorized investment advice?
Medium143An orchestration agent runs a nightly workflow that fans out to 12 subagents, each calling a partner REST API. Partner calls intermittently return HTTP 429 with a Retry-After header. The orchestrator currently retries immediately in a tight loop, causing cascading 429s and duplicate side effects on the partner systems. Which architectural change best addresses both the throttling and the duplicate side effects?
Medium144A project stakeholder is concerned about the latency of Claude 3.5 Sonnet responses in a high-throughput production application. How should the architect manage this communication?
Medium145A developer is concerned about the high token cost and latency of an agent that has access to 50 different tools. What is the most effective architectural change to optimize this system?
Medium146When evaluating the performance of Claude for a new feature, which metric is most useful for understanding the impact on end-user experience?
Medium147A developer productivity team runs an internal Claude-powered code review assistant. During peak morning hours, many developers submit large diffs simultaneously and the assistant returns HTTP 429 responses with a retry-after header. The team wants to keep latency predictable for interactive users while still processing queued batch jobs overnight. Which design best achieves this?
Hard148You are presenting the roadmap for a multi-stage LLM implementation to non-technical stakeholders. What is the most effective approach?
Medium149A financial services firm runs a Claude-powered loan pre-screening agent that reads applicant emails and drafts a preliminary recommendation. The firm's risk committee insists that no automated decision may be finalized without a documented human review step. Which control most directly satisfies this requirement while preserving the agent's throughput?
Medium150A Claude-based customer onboarding assistant has been in production for one quarter. The steering committee asks how you will decide whether to expand it to two additional regions. Which approach best supports that lifecycle decision?
Medium151When designing an agent capable of multi-step tool use, what is the most important property to maintain across steps?
Medium152A software vendor is preparing for a customer security review of its Claude-powered support assistant. The customer asks how the vendor prevents the assistant from leaking one tenant's data into another tenant's conversation. Which architectural control most directly addresses this concern?
Easy153During a project milestone review, a stakeholder asks why the Anthropic model output occasionally varies. How do you explain this in a way that manages expectations?
Medium154A government agency wants assurance that its Claude deployment will not be used to generate content that violates Anthropic's usage policies. Which action most directly supports ongoing policy compliance?
Easy155An organization wants to enforce consistent prompt engineering standards across teams. They have a large library of prompts and need to ensure that developers use approved versions while maintaining audit trails of prompt usage. What is the most effective approach?
Medium156A team is concerned about data privacy. They want to ensure that no personally identifiable information (PII) is sent to the LLM. What is the most effective way to manage this in a developer-friendly way?
Medium157An architect needs to implement a 'Red Teaming' process for a new Claude deployment. What is the primary objective of this activity in the context of AI governance and safety?
Medium158An enterprise architect is designing a Claude deployment where a single prompt may contain data belonging to customers in the EU, Brazil, and California. The legal team requires that each data subject's rights be honored independently and that processing purposes be documented per jurisdiction. Which architectural approach best supports this requirement?
Hard159When implementing a 'Human-in-the-loop' (HITL) checkpoint, what is the best way to handle the state persistence during the wait period?
Medium160Your team is building an LLM-powered application and experiencing high latency during peak times. Which TWO actions would best improve developer productivity and operational efficiency when debugging these bottlenecks?
Hard161A media company uses Claude through the Anthropic API to draft articles. Legal counsel asks the platform team to demonstrate that every published draft can be traced to the exact model behavior that produced it, even after Anthropic deprecates older models. The team currently calls the alias claude-sonnet-4-5. Which change best satisfies counsel's requirement?
Medium162A healthcare provider is using Claude to summarize patient clinical notes. Which governance control is most critical to prevent potential HIPAA violations?
Hard163Which of the following describes the role of the 'System Prompt' in an agentic architecture?
Easy164You are preparing a go-live readiness review for a Claude-powered advisory assistant used by field staff. The steering committee wants assurance that operational ownership is clear before launch. Which two artifacts are most essential to demonstrate that the lifecycle handover from project to operations is complete? (Choose two.)
Hard165You are architecting a Claude-based agent for a regulated financial client that performs long-running portfolio rebalancing workflows. A compliance requirement mandates that no single trade instruction may be executed unless it is cryptographically traceable to the exact model-generated intent that produced it. The agent uses the Messages API with tool use, and several downstream services consume tool calls asynchronously. Which architectural mechanism best satisfies this requirement while preserving agent autonomy?
Hard166You are managing a long-term AI project. How should you handle stakeholder communication when the underlying model architecture changes (e.g., release of a new model generation)?
Hard167A logistics agent needs to fetch shipping rates from five different carriers simultaneously to find the best price. Which architecture is best suited for this requirement?
Medium168In the Anthropic tool-use workflow, what is the primary purpose of the 'system prompt' relative to tool usage?
Easy169A team is rolling out an internal Claude-powered assistant for their engineering organization. Adoption is low and developers report that they do not trust the answers for anything beyond trivial questions. The enablement lead wants to increase adoption by making the assistant's behavior more transparent and debuggable. Which change best supports that goal?
Easy170A fintech startup wants to use Claude to generate marketing copy that references competitor products by name and makes performance comparisons. Legal counsel asks the architect which governance step is most appropriate before this capability goes live.
Easy171During a project post-mortem, stakeholders feel that the technical limitations of the LLM were not clearly explained during the planning phase. What action would have best mitigated this perception?
Easy172An insurer uses a Claude-based agent that can call internal tools to look up policy details. During review, the safety team finds that a document uploaded by a claimant contains text instructing the agent to email the full policy database to an external address. The agent has an email tool available. Which control most directly prevents this class of failure?
Hard173A retail company's legal team discovers that several engineering squads have been calling the Anthropic API with personal API keys obtained on individual credit cards, outside the corporate agreement. Leadership wants a governance model that both eliminates this practice and preserves the ability to audit all Claude usage centrally. Which governance model best achieves this?
Medium174What is the primary risk associated with 'Prompt Injection' attacks in enterprise AI?
Easy175Which document is essential for an organization to maintain when preparing for an AI audit?
Medium176A platform team at a large enterprise wants to standardize how Claude is invoked across 30 internal microservices. They need to enforce prompt templates, model selection, and retry logic centrally, while still allowing service teams to customize business-specific instructions. Which approach best balances central governance with team autonomy?
Medium177An insurance company is preparing an AI risk register for its Claude-based claims triage system. The risk team must document controls that reduce the chance of biased or inconsistent decisions affecting policyholders. (Choose two.)
Medium178Which TWO metrics are most useful for evaluating developer productivity in an LLM-driven organization? (Choose TWO)
Medium179An agent is engaged in a multi-hour troubleshooting session involving dozens of tool calls and thousands of lines of log data. The architect notices that the agent is starting to 'forget' early symptoms of the problem. Which strategy best addresses this while managing token costs?
Medium180Which pattern is most suitable for an agent that must balance the need for speed (latency) versus the need for correctness in a customer support scenario?
Medium181Six months after launch, a logistics company's operations VP reports that the Claude-based exception-handling assistant 'used to be great and now gives worse answers,' though no code has changed. You confirm the application code and system prompt are untouched. What is the most likely explanation you should investigate first?
Medium182When designing an LLM-based application, what is the primary benefit of using a 'System Prompt' compared to embedding instructions in the user message?
Easy183An organization is building an internal CLI tool that uses Anthropic's API. They want to improve developer productivity by implementing robust error handling and monitoring. Which TWO strategies should they implement? (Select TWO)
Medium184A customer-support agent must sometimes escalate to a human and sometimes resolve autonomously. The compliance team requires that any action touching billing be reviewed by a human before execution, while password resets may proceed automatically. The architect wants the model to decide routing without hardcoding every rule in the prompt. Which design best satisfies the requirement?
Medium185A platform team maintains a shared prompt library used by 40 internal services. After a subtle wording change to a summarization prompt caused a 12% drop in a downstream classification F1 score, the team wants every prompt change to be reviewable, version-pinned, and automatically regression-tested before rollout. Which approach best satisfies these requirements?
Medium186An autonomous agent is designed to browse the web and perform research. Which TWO mechanisms are most critical for preventing infinite loops and excessive API consumption during autonomous tool-calling cycles?
Hard187What is the primary benefit of using a standardized Prompt Library for a large enterprise development team?
Easy188A platform team is building a shared Claude integration library used by 40 internal microservices. Each service currently hard-codes its own model ID, max_tokens, and retry logic. The team wants a single place to roll out model upgrades and enforce consistent retry behaviour without redeploying every service. What is the most effective architecture for this requirement?
Medium189You are scaling an agentic system that uses external APIs. Which THREE design patterns prevent the agent from being blocked by third-party rate limits or latency?
Hard190An organization runs a nightly batch job that uses the Claude Messages API to classify support tickets. The job currently processes tickets one at a time, taking several hours and occasionally exceeding the nightly window. The team wants to cut wall-clock time substantially without exceeding their rate limits or degrading classification quality. Which change is most effective?
Hard191A product owner asks you to add a feature that lets internal users upload customer contracts so Claude can extract renewal dates and auto-populate a CRM. During intake you learn the contracts contain personally identifiable information and commercially sensitive terms. The product owner wants to launch in three weeks with no legal review. As the architect, what is the most appropriate action?
Hard192An engineering organization wants to raise developer productivity across teams building on Claude. Leadership asks the platform team to identify interventions that reduce repeated manual work and shorten the feedback loop for prompt and integration changes. (Choose two.)
Hard193In a swarm of specialized agents, what is the primary benefit of using a 'Blackboard' pattern for inter-agent communication?
Medium194Refer to the exhibit. Your application is hitting rate limits. A stakeholder is concerned about the user impact. What is your communication strategy?
Medium195A media company wants a lightweight, recurring review of its Claude-powered content moderation assistant. The team has no dedicated compliance staff and wants the cheapest process that still produces defensible evidence of oversight. Which approach fits best?
Easy196When designing an agentic system, which TWO of these 'observability' metrics are most crucial for monitoring the health of the agent's reasoning process?
Medium197A stakeholder asks why the AI system occasionally provides different answers to the same question. How do you explain this?
Easy198A security architect is configuring the Anthropic Console for a large enterprise. Which TWO features should be implemented to enforce centralized governance and reduce the risk of unauthorized account access?
Medium199Which THREE strategies should be employed to securely manage sensitive data within an agentic workflow?
Hard200You are operating a Claude-based support agent that must follow a strict refund policy: refunds over $500 require a manager approval code that is only obtainable through a separate internal API. The agent has access to a `get_manager_code` tool, but in production it occasionally issues refunds above $500 without calling the tool. Which architectural change most reliably prevents this?
Medium201A stakeholder demands that your team integrate Anthropic models into a sensitive financial system. How do you address the 'data privacy' concern?
Hard202You are designing a long-running agent that executes a sequence of irreversible operations, such as issuing refunds and sending customer notifications. The agent runs unattended overnight. Which TWO architectural patterns best ensure that a partial failure does not leave the system in an inconsistent state? (Choose two.)
Hard203An architect is defining the Shared Responsibility Model for a company deploying Claude via the Messages API. Which THREE tasks are the sole responsibility of the customer (the 'User') rather than Anthropic?
Hard204You operate a long-running research agent that maintains a scratchpad of findings across many turns. You notice that as the scratchpad grows, the agent begins ignoring recent tool results and repeating earlier conclusions. You cannot increase the context window. Which intervention most directly addresses the root cause of the recency failure?
Hard205Refer to the exhibit. An agentic loop receives this response from the Anthropic API during a critical multi-step operation. Which strategy should the architect implement to ensure the agent completes its task successfully?
Medium206A support engineering team wants new hires to become productive with the company's internal Claude-powered assistant quickly. They need a single place where engineers can discover approved prompt patterns, see working request examples, and read guidance on handling tool-use results. Which artifact best serves this enablement goal?
Easy207An enterprise is deploying Claude for high-stakes financial analysis. Which TWO governance controls should be implemented to mitigate the risk of model hallucinations and ensure factual accuracy?
Hard208You are designing a Claude agent that must complete a multi-hour research task spanning dozens of tool calls, and the transcript will eventually exceed the model's context window. You want the agent to keep making correct decisions without losing critical earlier findings. Which TWO architectural strategies best preserve decision quality across the compaction boundary? (Choose two.)
Hard209A stakeholder wants to change the project scope halfway through. How do you evaluate the impact?
Medium210A software company is using Claude to generate code snippets for internal projects. The security team is concerned that the model might inadvertently suggest code with known vulnerabilities. Which governance control should be implemented to best mitigate this risk?
Medium211Refer to the exhibit. Which component in this API request represents the primary governance layer for preventing model bypass of organizational policies?
Hard212To ensure long-term maintainability and performance of LLM-based applications, which THREE architectural patterns should architects recommend? (Select THREE)
Hard213A Claude agent performs a multi-step deployment task. Step 3 calls a `deploy_service` tool that returns success, but the subsequent verification step fails because the service is not yet healthy. The agent currently treats any tool success as completion and ends the workflow. Which change best addresses this?
Medium214An engineer is onboarding to a codebase that calls Claude and needs to understand, at a glance, which model, temperature, and max_tokens values a given feature uses. The team wants this discoverable without reading application source. What is the most effective practice?
Easy215During a pilot, a user discovers the AI can be 'prompt-injected' to reveal internal system instructions. What should be your immediate communication response?
Medium216Midway through a Claude integration project, a business stakeholder asks you to add a feature that would let end users upload arbitrary documents and have Claude answer questions about them. The feature is not in the signed statement of work, and the delivery team is two weeks from the first production milestone. What should you do first?
Hard217Under the shared responsibility model for AI safety, which task is the primary responsibility of the customer when using Anthropic's APIs?
Easy218Refer to the exhibit. The application is hitting rate limits during peak hours. What is the best architectural change to improve operational resilience?
Hard219A startup is using Claude to generate marketing copy. The legal team is concerned about potential copyright infringement if the model reproduces copyrighted text. Which governance measure should the startup implement to best mitigate this risk?
Easy220Which THREE practices most effectively support a 'Prompt Engineering as Code' workflow for enterprise teams? (Select THREE)
Medium221You are preparing a steering committee update for a Claude-based customer support assistant that has been live for two months. The sponsor asks for a concise way to judge whether the investment is paying off and whether the project should continue to the next phase. Which set of measures best answers that question?
Easy222A company is integrating Claude into a high-stakes automated decision-making system. Which TWO practices should be implemented to align with Anthropic’s Responsible AI principles?
Medium223A team uses a CI/CD pipeline to deploy LLM applications. They want to ensure prompt changes do not degrade model performance. Which strategy best integrates evaluation into the development workflow?
Medium224Refer to the exhibit. The user is attempting to trick the model into revealing sensitive information by claiming a high-clearance role. This is an example of which security threat, and how does the 'system' prompt help mitigate it?
Medium225Your team is deploying an application that uses PII in prompts. A stakeholder asks how you are mitigating the risk of data leakage. How do you respond?
Hard226A product owner tells you the Claude assistant 'feels slow' for end users and wants to know what to tell the executive sponsor. You have measured that time-to-first-token is 400 ms but full responses take 9 seconds because outputs are long. Which communication is most accurate and useful for the sponsor?
Easy227Which THREE components are essential for building a robust 'human-in-the-loop' (HITL) approval gate within an agentic workflow?
Hard228An agentic system is struggling with 'context fragmentation' over long-running sessions. What is the most effective architectural solution?
Medium229A production agent uses the Claude Messages API with extended thinking enabled to solve multi-constraint scheduling problems. The agent must preserve its reasoning across several tool calls within a single user turn. A developer notices that after the second tool call, the model appears to forget earlier constraints it had already reasoned about. Which change best preserves the reasoning chain across tool calls?
Hard230Refer to the exhibit. An agentic workflow encounters an error immediately after this message is generated by Claude. No further messages are sent to the API. What is the most likely cause of the failure in the orchestration logic?
Hard231A platform team maintains a shared Claude API integration used by multiple product squads. Squads frequently push prompt changes that break downstream features, and nobody can tell which prompt version produced a given output in production. The team wants every API call to be traceable to an exact prompt revision and wants to gate prompt changes behind review. Which approach best satisfies both requirements?
Medium232Which THREE factors should be prioritized when selecting an Anthropic model for a production-grade application?
Medium233Your team operates a Claude agent that triages inbound customer support tickets. After several weeks in production, the agent begins approving refunds above the policy ceiling and citing outdated policy text. Investigation shows the system prompt embeds a policy document that was updated three weeks ago, but the deployed prompt was never regenerated. Which architectural practice most directly prevents this class of failure?
Medium234When implementing AI safety policies, which THREE components should be included to ensure effective operationalization?
Medium235A developer needs to log all prompt-response pairs for compliance. What is the most reliable way to implement this without impacting application performance?
Medium236Which TWO practices best improve the maintainability of large-scale prompt libraries? (Choose TWO)
Medium237A team maintains a library of internal Claude prompts used by several services. They want to update a shared system prompt once and have every service pick up the change without redeploying, while keeping a rollback path if quality regresses. Which approach best satisfies both requirements?
Hard238Why is it recommended to use structured output (like JSON) when building LLM-based applications?
Easy239An architect wants to improve the coherence of an agent that frequently makes 'leaps of logic' or misses obvious errors in its tool outputs. Which TWO techniques directly address this behavior?
Medium240Your team wants to adopt a 'Configuration-as-Code' approach for LLM prompts. Which tool is most suited for managing this?
Medium241You are building a Claude-based agent that must parse unstructured customer emails, extract line-item order data, and then call a fulfillment tool with the extracted values. During testing, the agent occasionally calls the fulfillment tool with empty or garbled line items when an email contains a forwarded message with a different formatting style. Which architectural change most directly reduces this failure?
Medium242Which THREE technical strategies best support scaling prompt engineering across a large organization?
Hard243A stakeholder group wants to use the Claude API for a new public-facing application. What is the first thing you should discuss with them?
Medium244An agent orchestrator delegates work to three specialist sub-agents: a 'search' agent that returns ranked documents, an 'extract' agent that pulls structured fields from those documents, and a 'verify' agent that checks extracted fields against source text. During evaluation you find that verify frequently approves fields that extract hallucinated, because verify receives only the extracted JSON, not the source passages. Which change to the orchestration contract most directly fixes this?
Hard245What is the primary role of a 'Model Card' in the context of enterprise AI governance?
Medium246An enterprise agentic system using Claude needs to maintain strict state isolation across multiple concurrent user sessions while executing autonomous tool loops. Which architecture best ensures security and state integrity?
Medium247A media company uses Claude to moderate user-generated comments at high volume. The risk team wants a control that detects when the moderation model's behavior drifts, for example becoming unusually permissive or aggressive, before it affects the community at scale. Which control best fits this need?
Medium248A team wants an agent to answer questions about a large internal corpus. They notice the agent invents details when the retrieved chunks are only loosely related to the question. Which change most directly reduces fabricated answers grounded in weak evidence?
Easy249Your organization is standardizing a Claude-based internal assistant across three departments with different risk tolerances and workflows. Executive sponsors want a single governance model that keeps the program aligned and auditable as it grows. Which TWO practices should you establish as part of the lifecycle governance? (Choose two.)
Medium250A stakeholder asks for a change in the model's tone to be 'more professional' for customer support. How should you translate this request into technical requirements?
Easy251Midway through a Claude deployment, the executive sponsor asks to add a new capability that would require sending customer records to a third-party retrieval service outside the approved environment. Which action best demonstrates sound stakeholder communication and lifecycle governance?
Hard252A multinational bank deploys Claude to draft internal policy summaries for staff in the EU and Singapore. Legal requires that personal data embedded in employee questions never leave its region of origin, but the bank wants a single application codebase. Which architecture most directly enforces the residency requirement?
Medium253Six months into production, a Claude-based claims-triage system shows a slow decline in acceptance of its recommendations, from 82 percent to 61 percent, with no code or model changes. The operations manager asks what to do. Which investigation best addresses the root cause?
Hard254You are the lead architect for a Claude-based claims triage assistant at an insurance company. Two weeks before the pilot goes live, the Head of Compliance asks how they will be able to demonstrate, months later, which version of the system prompt and which model snapshot produced a given claim recommendation. What should you implement to meet this requirement?
Medium255Your organization is transitioning from a legacy rule-based system to a Claude-based solution. A key stakeholder is worried about 'loss of control'. How do you address this during a steering committee meeting?
Medium256Which TWO metrics are most effective for communicating the 'value' of an Anthropic model deployment to executive stakeholders?
Medium257A team wants to transition from a proof-of-concept to a production environment. Which task should be prioritized for operational readiness?
Medium258You are preparing a kickoff briefing for a business unit adopting a Claude-based internal knowledge assistant. The sponsor asks what they should expect in the first 30 days. Which framing best sets accurate expectations and supports lifecycle alignment?
Easy259A new engineer joins a team building a Claude-powered support triage tool. She wants to iterate quickly on prompt wording without redeploying the service, but the team also needs every prompt change to be auditable and reversible. Which practice best supports both goals?
Easy260A multinational insurer wants to quantify how often its Claude-based claims assistant produces outputs that violate its internal tone and fairness policy before it expands the pilot to three new countries. The compliance team needs a repeatable, statistically defensible measurement rather than anecdotal review. Which approach best meets this need?
Hard261A developer is building an internal tool that uses Claude to answer questions about a large codebase. They want to reduce hallucinations and ensure answers are grounded in the actual code. Which technique should they use?
Medium262A multinational bank runs a Claude-powered assistant that drafts internal credit memos. Auditors require the bank to prove that every generated memo can be traced to the exact human who requested it, the data sources the model retrieved, and the decision it influenced. Which governance capability should the architect implement first to satisfy this requirement?
MediumOther domains
All CCAR-P exam domains
Frequently asked questions
- What does the scenario questions domain cover on the CCAR-P exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 262 scenario questions questions in the CCAR-P question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.