Courseiva

CCAR-P Advanced Agentic Architecture Practice Question

You are designing a long-running agent that executes a sequence of irreversible operations, such as issuing refunds and sending customer notifications. The agent runs unattended overnight. Which TWO architectural patterns best ensure that a partial failure does not leave the system in an inconsistent state? (Choose two.)

⚠ Common exam trap

The trap here is reaching for model-side knobs like temperature or token limits to solve what is fundamentally a distributed-systems durability and compensation problem.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement compensating actions so that each irreversible operation has a defined reversal or mitigation step.

Unattended agents performing irreversible actions need both a durable record of intent and a way to reverse or mitigate completed steps. Journaling provides the audit trail and restart logic, while compensating actions provide the semantic undo. Together they allow the orchestrator to detect partial completion and bring the workflow back to a consistent state after a crash or timeout.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cache all tool responses in memory so the agent can replay the session without re-calling tools after a restart.

    Why it's wrong here

    An in-memory cache does not survive a process restart, so it cannot support recovery after a crash. Even if it did, replaying cached responses would not tell the orchestrator which irreversible side effects actually occurred. The requirement is durable, auditable state, and volatile caching fails that requirement. It also risks masking real tool failures by serving stale results.

  • ✗

    Raise the max_tokens limit for each planning step so the agent can reason through more contingencies before acting.

    Why it's wrong here

    More planning tokens may improve the quality of a plan but do nothing to guarantee consistent recovery after a partial failure. The failure mode described is about durable state and reversibility, not about planning depth. A longer plan can still be interrupted mid-execution. Without journaling or compensation, the system remains vulnerable to orphaned irreversible operations regardless of how much reasoning preceded them.

  • ✓

    Implement compensating actions so that each irreversible operation has a defined reversal or mitigation step.

    Why this is correct

    Compensating actions provide a defined path to undo or mitigate an operation that succeeded but belongs to a workflow that later failed. For refunds and notifications, this might mean issuing a reversal or a correction notice. Together with journaling, compensation ensures that a partially completed sequence can be brought back to a consistent state rather than left with orphaned side effects.

  • ✗

    Increase the model's temperature so it explores alternative execution orders and avoids getting stuck on a failing step.

    Why it's wrong here

    Higher temperature increases variability in model output and is unrelated to transactional consistency. It would make an unattended agent less predictable, not more recoverable. The problem is about durable state and recovery, not about exploring alternatives. Randomizing execution order could even worsen inconsistency by changing which operations occur before a failure, without providing any mechanism to reconcile them afterward.

  • ✓

    Record each intended operation in a durable journal before executing it, and mark it complete only after the tool confirms success.

    Why this is correct

    A durable write-ahead journal lets the orchestrator determine which operations were started but not confirmed when a crash or timeout occurs. On restart, it can reconcile those entries, either retrying idempotently or escalating. This directly prevents silent partial completion because every irreversible action has a persisted intent record and a matching completion marker that can be audited and replayed.

About these practice questions

One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.