A security team is evaluating two proposed controls. Control A adds an outbound tool allow-list with destination restrictions and per-call review. Control B scores responses against a stable adversarial evaluation set after each model-version change.
Which two risk categories are correctly matched to these controls? (Select two.)
A business sponsor has requested an AI solution to “improve customer experience.” The sponsor cannot articulate which customer journey is failing, which metric reflects the failure, or which decisions the AI should support. The sponsor is asking you to begin design work next week.
Which delegation-competency action should you take first?
You are evaluating an evaluation set used to score a Claude-based hiring-support tool. The set is drawn from one geographic region and one tenure band.
Which response is most appropriate?
You are producing an architecture guide for a new deployment and must complete the planning steps before drafting each section.
Which two steps must be completed BEFORE drafting each section of the guide? (Select two.)
Each correct answer presents part of the solution.
A Claude architect is designing a HIPAA-compliant pipeline that processes patient records.
Which two design decisions directly support HIPAA compliance requirements? (Select two.)
You are distinguishing functional from non-functional requirements during discovery.
Which item is a non-functional requirement?
A Claude architect at a health services organization is defining evaluation metrics for a clinical-summary pipeline. The pipeline must remain within a per-query cost ceiling and must never surface patient data to unauthorized roles.
Which two metrics directly address these requirements? (Select two.)
You are listing characteristics of robust guardrail design for an enterprise deployment.
Which two characteristics belong on the list? (Select two.)
Each correct answer presents a complete solution.
A security audit uncovers two issues: (1) all end users share a single API key, and (2) tool calls are executed without logging the initiating user.
Which two mitigations directly address these specific findings? (Select two.)
You are designing a feedback session for a deployment in flight.
Which structure best supports productive stakeholder feedback?
A managed agent deployment for claims triage has grown from 6 tools to 34 tools over 18 months as product teams added capabilities. Triage accuracy has declined from 91 percent to 78 percent, and average tool-selection latency has increased by 2.3 seconds. A junior engineer has proposed adding a tool-router agent in front of the current agent to filter the tool list per request.
Which two findings should you present to justify capability decomposition before adding the router? (Select two.)
Each correct answer presents part of the solution.
You are compiling a diagnostic toolkit for Claude Code operational issues.
Which two diagnostic actions belong in the toolkit? (Select two.)
Each correct answer presents a complete solution.
You are classifying chunking strategies by the corpus type each is best suited to.
For each chunking strategy, select the appropriate corpus type: “Long Structured Documents,” “Heterogeneous Short Records,” or “Code or Hierarchical Specifications.”

Engineering leadership wants to roll out Claude Skills to 280 developers across 14 teams. Skills will encode internal coding standards, code-review checklists, and incident-postmortem templates. Leadership has asked how to govern Skill authorship so that Skills remain trustworthy without bottlenecking on a single central team.
Which governance model should you recommend?
You are reviewing a peer’s draft system prompt that contains contradictory instructions: one section says never to speculate beyond the supplied source, while another says to confidently fill in any gaps.
Which response is most appropriate?
You are reviewing instrumentation in a multi-agent system.
Which two findings constitute valid observability gaps in the instrumentation? (Select two.)
Each correct answer presents a complete solution.
You are supporting an EU-based deployment with GDPR obligations.
Which combination of measures best supports the deployment’s GDPR posture?
You are presenting an architectural decision to a mixed audience that includes an executive sponsor and the engineering leads who will implement the decision.
Which presentation strategy best serves both audiences?
You are investigating an MCP server that fails on first launch but succeeds on subsequent runs. System permission dialogs appeared during the first launch.
Which response is most appropriate?
A senior architect is preparing briefing materials on a new retrieval architecture. The executive sponsor has requested a summary of the architectural decision. Which framing is most appropriate for that audience?
You are designing a human-in-the-loop validation workflow for a new Claude-based deployment and must complete the design steps before piloting the workflow.
Which two steps must be completed BEFORE piloting the workflow with a representative subset of traffic? (Select two.)
Each correct answer presents part of the solution.
A platform team operates a self-hosted multi-agent system on Kubernetes that orchestrates seven specialized agents for invoice processing. The team spends approximately 40 percent of engineering capacity on infrastructure maintenance, message bus reliability, and agent state recovery. The CFO has asked you to evaluate moving to managed agent infrastructure to reclaim engineering capacity. The security officer requires that all customer financial data remain within an approved network boundary.
Which factor should most heavily influence your recommendation?
You are evaluating retrieval-strategy claims used by a peer team.
For each claim, select yes if the statement is generally accurate. Otherwise, select no.

You are integrating human review into a high-volume classification pipeline where reviewing every output is infeasible.
Which sampling strategy best balances throughput with quality oversight?
You are running a controlled experiment to compare two prompts and must complete the design steps before executing the experiment.
Which two steps must be completed BEFORE running the experiment with random assignment? (Select two.)
Each correct answer presents part of the solution.
You are rolling out a standardized Claude Code configuration to an engineering team and must complete the planning steps before piloting the configuration.
Which two steps must be completed BEFORE piloting the configuration with a small group of engineers? (Select two.)
Each correct answer presents part of the solution.
You are reviewing an integration specification for security gaps.
Which two findings constitute valid security gaps in the specification? (Select two.)
Each correct answer presents a complete solution.
A Claude architect is leading the discovery phase for a new AI-powered customer service solution.
Which two activities are characteristic of structured discovery and requirement gathering for a Claude-based deployment? (Select two.)
You are preparing a HIPAA-eligible deployment for a healthcare customer.
Which configuration supports HIPAA compliance using Anthropic-offered tools?
You are a platform architect designing an internal Claude-based assistant that serves both finance analysts and external auditors. Each population must access only documents permitted by its role.
Where should role-based access control be enforced in the pipeline?
The compliance team at a firm has approved a Claude Skill that generates client-facing investment summaries. The Skill includes the firm’s required disclaimers and prohibited-language list. A product manager has asked whether additional guardrails are needed at the application layer or whether the Skill alone is sufficient.
Which two guardrail responsibilities should remain at the application layer rather than the Skill? (Select two.)
Each correct answer presents part of the solution.
A customer support team has proposed delegating customer refund decisions to a Claude-driven workflow with no human review for refunds under 50 USD. The team ' s reasoning is that small refunds are low-risk and human review would erase the efficiency gain.
Which Delegation-competency principle should guide your response?
An engineering organization is adopting Claude Code across 200 developers. A team lead proposes that AI-generated pull requests bypass standard code review for changes under 50 lines because small changes are considered low risk and review capacity is constrained.
Which two Diligence-competency objections should you raise? (Select two.)
Each correct answer presents part of the solution.
A Claude Architect is reviewing a post-deployment performance report for an AI-assisted legal-document summarization system. The report includes these observations:
Average summarization time decreased from 47 minutes to 6 minutes per document.
Associates spend less time on summaries, but overall billable output has not measurably changed.
Infrastructure costs increased by 22% because redundant retry logic generated additional API calls.
Some summaries require attorney correction, adding an average of 8 minutes of review per document.
Which analysis correctly attributes each observation to the appropriate business-value pillar?
You are transitioning a Claude-based deployment from design into implementation.
Which handoff package most directly supports a clean transition?