Pre-Winter Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Anthropic CCAR-P Practice Exam with Questions & Answers | Set: 3

Questions 21

A Claude architect is designing a HIPAA-compliant pipeline that processes patient records.

Which two design decisions directly support HIPAA compliance requirements? (Select two.)

Options:
A.

Setting max_tokens to a low value to minimize the volume of text generated per request.

B.

Selecting the highest-capability Claude model to maximize diagnostic accuracy.

C.

Enforcing role-based access controls so that PHI is retrievable only by authorized personnel.

D.

Ensuring patient data is never included in training feedback loops sent to the model provider without a BAA in place.

E.

Using streaming responses to reduce perceived latency for clinical users.

Anthropic CCAR-P Premium Access
Questions 22

You must present an architectural recommendation to deploy a Claude-based contract review assistant to a steering committee that includes the CFO, the general counsel, and the CIO. Each stakeholder cares about different aspects of the decision.

How should you structure the recommendation document?

Options:
A.

Lead with the technical architecture diagram and the full component list before any other section.

B.

Lead with detailed cost projections across the full multi-year horizon before the rationale section.

C.

Present the same dense narrative throughout with no stakeholder differentiation in any section.

D.

Lead with the architectural decision, then address each stakeholder’s primary concerns directly.

Questions 23

A security team is evaluating two proposed controls. Control A adds an outbound tool allow-list with destination restrictions and per-call review. Control B scores responses against a stable adversarial evaluation set after each model-version change.

Which two risk categories are correctly matched to these controls? (Select two.)

Options:
A.

Control A — prompt injection from adversarial content in retrieved data

B.

Control A — silent quality drift after a model-version upgrade

C.

Control A — data exfiltration via outbound tool calls

D.

Control B — data exfiltration via outbound tool calls

E.

Control B — silent quality drift after a model-version upgrade

Questions 24

You are defining when to introduce a project subagent versus relying on Claude Code ' s general capabilities.

Which scenario most directly justifies a dedicated subagent?

Options:
A.

The team has a recurring specialized task, such as database schema review, that requires a focused system prompt, narrow tool permissions, and a specific model selection across many sessions.

B.

The team has a one-time ad hoc question that will not recur and does not require a focused system prompt, narrow tool permissions, or dedicated model selection.

C.

The team has no recurring specialized tasks and uses Claude Code only for isolated general-purpose work that does not justify a dedicated system prompt or tool scope.

D.

The team wants every Claude Code interaction to use the same generic system prompt with no task-specific specialization, narrow tool permissions, or dedicated model selection.

Questions 25

You are auditing a procurement-assistant agent whose defined responsibility is to draft purchase requests for review.

For each tool currently configured on the agent, select yes if the tool should remain after a least-privilege audit. Otherwise, select no if it should be removed.

CCAR-P Question 25

Options:
Questions 26

A Claude Architect is reviewing a post-deployment performance report for an AI-assisted legal-document summarization system. The report includes these observations:

Average summarization time decreased from 47 minutes to 6 minutes per document.

Associates spend less time on summaries, but overall billable output has not measurably changed.

Infrastructure costs increased by 22% because redundant retry logic generated additional API calls.

Some summaries require attorney correction, adding an average of 8 minutes of review per document.

Which analysis correctly attributes each observation to the appropriate business-value pillar?

Options:
A.

Observations 1 and 2 both indicate efficiency gains; Observation 3 is a solution-cost issue; Observation 4 is a performance-SLA issue.

B.

Observation 1 is a transformation outcome; Observation 2 is an efficiency gain; Observation 3 is a performance-SLA degradation; Observation 4 is a solution-cost issue.

C.

Observations 1 and 4 together indicate a net performance-SLA improvement; Observation 2 is a transformation gap; Observation 3 is a productivity drain from over-engineering.

D.

Observation 1 indicates an efficiency gain; Observation 2 shows that productivity has not yet been realized; Observation 3 is a solution-cost issue; Observation 4 is an efficiency loss that partially offsets Observation 1.

Questions 27

You are running a discovery session with a business sponsor who asks for “an AI system to fix our customer escalations.”

Which approach best yields actionable requirements?

Options:
A.

Accept the sponsor’s original phrasing as a complete and final requirement and proceed directly to design without asking targeted questions to surface actors, triggers, or constraints.

B.

Decompose the request by asking targeted questions about who escalates, what triggers escalation, what good resolution looks like, and which constraints—latency, cost, audit, and data sensitivity—apply.

C.

Defer the discovery session indefinitely on the grounds that the sponsor must fully specify the system before the architect can ask any clarifying or scoping questions.

D.

Assume the requirement matches the architect’s previous engagement in a different industry and proceed with that context, without validating actors, triggers, or constraints for this sponsor.

Questions 28

A Claude architect is implementing safety controls for a customer-facing advice assistant that must never provide regulated investment recommendations.

Which two guardrail implementations most directly enforce this constraint? (Select two.)

Options:
A.

Increase response temperature to introduce variability that reduces the likelihood of specific recommendations.

B.

Add an output classifier that detects and blocks responses containing regulated investment-recommendation language.

C.

Limit session length to reduce the volume of queries processed per user per day.

D.

Log all user queries to a SIEM for post-hoc compliance review.

E.

Define explicit out-of-scope categories in the system prompt with fixed refusal phrasing for investment advice requests.

Questions 29

You are a platform architect designing an internal Claude-based assistant that serves both finance analysts and external auditors. Each population must access only documents permitted by its role.

Where should role-based access control be enforced in the pipeline?

Options:
A.

Inside the system prompt as a natural-language instruction for Claude to ignore unauthorized documents.

B.

At the retrieval layer, before any role-restricted content reaches the prompt-construction step or the model.

C.

Nowhere in the pipeline; rely on the model’s general refusal behavior to reject unauthorized document access without any enforced access control.

D.

After the response is generated, by post-filtering content that should not have been retrieved.

Questions 30

You are compiling factors that should drive the choice between Model Context Protocol (MCP), direct API integration, and agent-to-agent handoff.

Which two factors belong on the list? (Select two.)

Each correct answer presents a complete solution.

Options:
A.

Whether the vendor publishes detailed reference documentation for each candidate protocol.

B.

Whether the team has prior implementation experience with any of the candidate protocols.

C.

Whether the underlying transport supports encryption in transit between the integrated services.

D.

Whether the integration must be portable across multiple AI clients in the ecosystem.

E.

Whether the interaction is stateless and latency-sensitive or stateful and longer-running.

Exam Code: CCAR-P
Certification Provider: Anthropic
Exam Name: Claude Certified Architect - Professional
Last Update: Oct 7, 2026
Questions: 129