CCAR-P - Claude Models, Prompting & Context Engineering (13% of the exam) - Section 2.2

Design system prompts, templates, and guardrails.

Writing system prompts that set role, scope and constraints, building reusable templates with clear slots for variable input, and placing guardrails in the prompt while knowing their limits. Candidates should recognise when a prompt-level guardrail is enough and when a control outside the model is required.

system prompt role and scopeprompt templatesprompt-level guardrailslimits of instruction-only controls

Practice question for this objective

Free sampleClaude Models, Prompting & Context Engineeringmedium

A homeware retailer's shopping assistant has a system prompt that restricts it to the retailer's own catalogue, orders and delivery questions. For six months a weekly review of 400 sampled conversations found fewer than 1 per cent of replies off scope. Three weeks ago the marketing team appended a block of seasonal campaign rules to the same system prompt, one of which tells the assistant to help shoppers compare gift ideas from anywhere they have seen them. The scope rule, the model and the retrieval setup are unchanged, and off-scope replies have since risen to 7 per cent, almost all of them recommending products sold by other shops. What is the most likely cause?

  • AThe scope rule now sits far from the end of a longer prompt, so the model has stopped reading it
  • BRetrieval now returns competitor product pages, which the model summarises as its suggestions
  • CThe new campaign rule conflicts with the scope rule, and the model resolves the clash unevenly Correct
  • DShoppers have learned to jailbreak the assistant, and the campaign season brought more of them
Appending instructions to a system prompt can silently contradict existing scope constraints, so prompt changes need review for conflicts and regression evals before release. A system prompt is read as a whole, and when two instructions point in different directions the model has no reliable rule for which one wins. The campaign rule invites comparison with products from anywhere, which directly undercuts the catalogue-only scope rule. The off-scope rate rose only after that block was added, and the failures match what the new rule asks for, so the conflict is the most likely mechanism rather than position, retrieval or users.

Why A is wrong: Instruction position can matter, which makes this tempting, but a positional effect would not explain why the failures are concentrated on recommending other shops' products, which is exactly what the new campaign rule invites.

Why B is wrong: Retrieval is a sensible first suspect for wrong content, but the stem states the retrieval setup is unchanged, and the timing matches the prompt edit rather than any index or data change.

Why C is correct: The scope rule did not change, but a newly added instruction now licenses talking about products from anywhere, so the prompt contains two competing directives and the model sometimes follows the newer, more specific one.

Why D is wrong: Adversarial users are a real risk, but nothing in the evidence suggests hostile input, and the failures line up with the wording of a newly added instruction rather than with unusual user behaviour.

See more CCAR-P practice questions, answers explained.

Exam traps in Claude Models, Prompting & Context Engineering

Answers that look right on this material and are not. Each one is a distractor from a different question in the CCAR-P bank for this domain.

  • A pass rate of 99.4 per cent across 5,000 conversations shows the prompt meets the agency policy on its own

    Why it is wrong: A large sample makes the rate trustworthy, which is why this is tempting, but the same sample records about 30 failures, and the policy tolerates none, so the evidence argues against the prompt alone being sufficient.

  • Whether the model has started inventing facts and should be replaced with a larger tier

    Why it is wrong: Invented hours look like a model fault, but the model is unchanged and is accurate for eleven departments, so a model-wide cause cannot explain failures confined to the one new department.

  • Add a second model call that scores each draft for length and rewrites any answer that breaks the house style

    Why it is wrong: A reviewing pass is tempting because it checks every answer explicitly. It is wrong here because it adds a model call, latency and cost to every request and new infrastructure the team has no budget for, to fix a low-stakes style problem the prompt has never even addressed.

Examworthy is not affiliated with or endorsed by Anthropic. Original, blueprint-aligned practice material only.