CCAR-P domain - 19% of the exam

Integration

Integration is 19% of the Claude Certified Architect - Professional (CCAR-P) exam. These are the objectives it covers, each with practice questions, with every answer explained.

Objectives in this domain

Sample question from this domain

Free sampleIntegrationmedium

A hospital network is piloting a discharge-summary agent that reads a patient's notes, medications and results and drafts a summary for the attending clinician to edit. The agent was built on the hospital's shared clinical tool gateway and inherited every tool on it, including place_medication_order and cancel_appointment, which the summary role never calls. Clinicians have said they will abandon the pilot if it adds interruptions to their workflow, and go-live is in three weeks. The security lead asks for a recommendation on the two write tools. What should the architect recommend?

  • ARemove both write tools from the agent's configuration so its tool set covers only the read operations the summary role uses Correct
  • BKeep both tools but require the clinician to approve each order or cancellation in a confirmation dialog before it runs
  • CKeep both tools and log every invocation to the security monitoring platform, with an alert on any call from the agent
  • DAdd a system-prompt instruction forbidding medication orders and cancellations, and verify it with a red-team test suite
When an agent holds a capability its role never uses, removing that capability beats confirming, logging or instructing against its use. Least privilege is a structural control: a tool that is not in the agent's configuration cannot be invoked by any prompt, error or injected instruction. Confirmations, logs and prompt rules all leave the capability reachable and either add friction or act after the harm. Because the summary role is read-only, removing the write tools costs nothing in function while removing the risk entirely.

Why A is correct: Correct. The summary role never places orders or cancels appointments, so removing those tools eliminates the risk outright rather than detecting or gating it. It adds no clinician interruptions, shrinks the attack surface a manipulated prompt could reach, and is a configuration change that fits the three-week timeline.

Why B is wrong: A confirmation step feels safe because a human sees every write before it lands. It is wrong because it is a compensating control on a capability the role does not need, it adds exactly the workflow interruptions clinicians said would end the pilot, and approval fatigue tends to turn confirmations into reflexive clicks.

Why C is wrong: Logging with alerting is tempting because it adds no clinician friction and gives the security team visibility. It is wrong because it is a detective control: an erroneous medication order or cancelled appointment has already happened by the time the alert fires, and the capability itself remains.

Why D is wrong: An instruction plus red-team testing looks rigorous and costs nothing at runtime. It is wrong because a prompt instruction is a soft control that injected content or an unusual input can override, and passing a test suite does not prove the model will refuse every case when the tool is still available to call.

Other domains in this exam

See also the CCAR-P cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by Anthropic. Original, blueprint-aligned practice material only.