8 real CCAR-P flashcards, sampled from 4 of the 7 domains the exam tests, heaviest first. Where a tempting wrong answer encodes a belief people genuinely hold, the card corrects it too - the trap most decks skip. No account, no card.
The full deck has 318 flashcards, and a free account opens 40 of them across every domain. For a domain-by-domain breakdown and a study plan, read the CCAR-P study guide.
schoolConceptIntegration
Why should an assistant get its own role-scoped credential, with the customer scope attached server-side, instead of reusing an existing broad service credential?
arrow_downward
Reusing a credential provisioned for another system silently grants the assistant every scope that system needed. Least privilege has two parts here: shrink the credential to the operations the role performs, and take the customer's account scope from the authenticated session rather than from anything the model produces. Both are enforced before a call reaches the backend API.
schoolConceptIntegration
An agent holds a write tool its role never calls. Why is removing the tool a better control than a confirmation step, logging or a prompt rule against using it?
arrow_downward
Least privilege is a structural control: a tool that is not in the agent's configuration cannot be invoked by any prompt, error or injected instruction. Confirmations, logs and prompt rules all leave the capability reachable and either add friction or act after the harm. Where the role never needs the tool, removing it costs nothing in function while removing the risk entirely.
Common misconceptionLogging every call with an alert is not equivalent to removing the tool. It is a detective control: the harmful write has already happened by the time the alert fires, and the capability itself remains.
schoolConceptSolution Design & Architecture
When a sponsor proposes a specific AI mechanism, how should an architect decide what to build and how to measure success?
arrow_downward
Separate the outcome the sponsor needs from the mechanism they proposed. Aim the solution at the step the evidence identifies as the bottleneck, and tie success to the original business problem plus an accuracy check on a labelled sample. Building the requested mechanism can leave the measured problem untouched while its own metric says nothing about that problem.
schoolConceptSolution Design & Architecture
Why should a rule-based calculation that must be reproducible and auditable run in deterministic code rather than a generative model?
arrow_downward
Deterministic code gives identical outputs for identical inputs and traces each result to the source row that produced it, by construction. Any generative calculation, however constrained or reviewed, only approximates those properties. Split the system: deterministic code for the check, and the model for work that tolerates variation, such as wording an alert.
Common misconceptionLowering temperature to zero makes outputs more consistent but does not guarantee identical results across calls, and a generated calculation still cannot be traced to a specific source row.
schoolConceptEvaluation, Testing & Optimization
When a requirement forbids omitting specific safety-critical items, what should the evaluation metric measure, and why is an aggregate quality score not enough?
arrow_downward
Derive the metric from the requirement: count the items it names. Measure recall of those items on a labelled set, with a threshold tied to the requirement, and report it separately. An overall similarity score averages over all text and over records that contain none of the items, so a high mean can coexist with exactly the omissions the requirement forbids.
schoolConceptEvaluation, Testing & Optimization
When a cost ceiling is set per completed task, what cost metric should decide whether a switch to a cheaper model tier is kept?
arrow_downward
Measure cost in the unit the requirement uses: every model request, every retry and the human rework needed for each task that completes. A cheaper model can lower the price of each call while raising the number of calls and the manual correction needed to finish the work, and cost per request hides exactly those retries and rework.
Common misconceptionA fall in cost per request does not carry through to the bill when retries multiply the requests per task, and it does not count human rework at all.
schoolConceptGovernance, Safety & Risk Management
Why must the account or tenant scope of a tool call be attached server-side from the authenticated session rather than taken from an identifier the model fills in?
arrow_downward
If the model chooses whose record is fetched, anything that persuades the model also widens access. Binding the identifier to the authenticated session in the tool handler removes that choice from the model entirely, turning a probabilistic behaviour into an enforced boundary. Prompt wording and input classifiers lower the attack rate but leave the same capability in place, and audit logs only find the breach afterwards.
schoolConceptGovernance, Safety & Risk Management
How do you enforce an absolute content rule on high-volume generated output that is published automatically and too large for humans to read in full?
arrow_downward
When the rule is an absolute property of published text, volume makes any residual error rate certain to surface. A deterministic pattern check, such as one for currency amounts and discount language, is cheap, runs on every item between generation and publication, and blocks each violation whatever the model wrote. Human review is reserved for the small queue of rejected items, which fits limited staff.
Common misconceptionClear instructions and examples usually lower the violation rate a lot, but a lower rate is not the requirement. At thousands of items a week even a small residual rate publishes violating copy, and a prompt cannot guarantee zero.
Examworthy is not affiliated with or endorsed by Anthropic. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. CCAR-P and related marks belong to their respective owners.