Curriculum
The full CCAR-F curriculum: 5 domains, 30 lessons. Every lesson covers the concept, key points to know, and exactly what the exam tests about it.
Domain 1
27% of examAgentic Architecture & Orchestration
Design and implement agentic systems using Claude's API, including loop management, orchestration patterns, guardrails, and the Claude Agent SDK.
Agentic Loops
The agentic loop is the core execution cycle: Claude receives a prompt, optionally calls tools, and the loop continues until Claude signals it is finished. Getting the termination condition right is the single most tested concept in this domain.
Multi-Agent Orchestration
The exam's multi-agent pattern is hub-and-spoke. A coordinator splits the task, passes context explicitly, and aggregates results. Subagents do not message each other and do not inherit the coordinator's history.
Subagent Invocation and Context Passing
The coordinator spawns subagents with the Task tool (Agent in current Claude Code) and must put Task or Agent in allowedTools. Each subagent receives only the prompt it is given, including structured source metadata.
Workflow Enforcement and Handoff
Task 1.4 is prompt guidance versus a programmatic gate. Money, security, and compliance need code that blocks the tool until its precondition is true. A human handoff has five fields, including the refund amount when one applies.
Agent SDK Hooks
Agent SDK hooks implement the programmatic side of the 1.4 enforcement spectrum. PreToolUse blocks or rewrites a tool call before it runs. PostToolUse normalises the result after it runs and cannot undo the side effect.
Task Decomposition Strategies
Task decomposition splits complex work into pieces an agent can handle. The exam tests choosing a fixed sequential pipeline or dynamic adaptive decomposition, and recognising attention dilution when too many items share one pass.
Session State and Resumption
Session management chooses how an agent keeps continuity. --resume continues a valid history. fork_session branches that history to compare approaches. After files change, a fresh session with summary injection is the fix, because a fork still carries the stale tool results.
Domain 2
18% of examTool Design & MCP Integration
Design effective tool schemas, implement MCP servers and clients, and integrate external services into Claude-powered applications.
Tool Interface Design
Tool descriptions are the primary mechanism LLMs use for tool selection. Minimal descriptions such as "Retrieves customer information" cannot separate overlapping tools, so the first fix is to expand those descriptions.
Structured Error Responses
When an MCP tool fails, a generic message such as "Operation failed" gives the agent nothing to recover from. Execution errors return isError: true with structured metadata so the agent can tell a transient failure from a valid empty result.
Tool Distribution & Tool Choice
How many tools an agent can see is an architectural decision. Eighteen tools on one agent degrade selection. The workable range is 4-5 tools scoped to the agent's role, with near-duplicates collapsed into one parameterised tool.
MCP Server Integration
MCP servers connect Claude to databases, APIs, development tools, and issue trackers. Project-level .mcp.json is version-controlled and shared; user-level ~/.claude.json is personal. Credentials use ${ENV_VAR} expansion, community servers come before custom builds, resources catalogue available data, and rich tool descriptions keep MCP tools competitive with built-ins.
Built-in Tools
Claude Code's six built-in tools are Read, Write, Edit, Bash, Grep, and Glob. Grep searches file contents; Glob matches file paths. Edit is the default modification. When Edit cannot find a unique anchor, the exam answer is Read + Write, while current Claude Code first widens old_string or uses replace_all.
Domain 3
20% of examClaude Code Configuration & Workflows
Configure Claude Code for development workflows, manage settings, hooks, permissions, and integrate with CI/CD pipelines.
CLAUDE.md Hierarchy, Scoping, and Modular Organisation
Claude Code loads CLAUDE.md at three levels: user (~/.claude/CLAUDE.md), project (.claude/CLAUDE.md or root CLAUDE.md), and directory. Applicable files are concatenated into context. CLAUDE.md is guidance, not a deterministic enforcement layer — use settings.json or hooks when a rule must hold every run.
Custom Slash Commands and Skills
Custom commands and skills are one Skills system. .claude/skills/<name>/SKILL.md is canonical; .claude/commands/<name>.md still works. A skill is a directory with SKILL.md. A flat .md inside .claude/skills/ does not create a command. Project .claude/ is shared; ~/.claude/ is personal.
Path-Specific Rules for Conditional Convention Loading
Path-specific rules in .claude/rules/ apply conventions only while matching files are being edited. YAML frontmatter paths globs cover a file type spread across many directories. Root CLAUDE.md loads every session, and directory-level CLAUDE.md covers one directory.
Plan Mode vs Direct Execution
Plan mode explores and designs before any files change. Direct execution applies a known, limited change immediately. The exam choice is ambiguity, not difficulty: architectural and multi-file work is plan mode, often then direct execution, and a clear single-function fix is direct execution.
Iterative Refinement Techniques
Working with Claude Code is iterative. The first output is rarely the final one. The exam checks which technique to reach for first: concrete input/output examples for inconsistent interpretation, test-driven iteration for complex transformations, and the interview pattern for unfamiliar domains.
CI/CD Integration
In CI, Claude Code is a non-interactive review and generation engine. The exam tests -p (--print) when a job hangs waiting for input, structured JSON via --output-format json and --json-schema (read structured_output), independent review sessions, incremental findings, and real-time API for blocking pre-merge checks.
Domain 4
20% of examPrompt Engineering & Structured Output
Craft effective prompts, implement structured output patterns, and apply prompt engineering techniques for production Claude applications.
System Prompts with Explicit Criteria
Vague instructions such as "be conservative" and "only report high-confidence findings" give the model no decision boundary. Explicit categorical criteria define what to flag and what to skip, severity is calibrated with code examples, and a high false-positive category is disabled until its prompt is fixed.
Few-Shot Prompting
When detailed instructions still produce inconsistent formatting, ambiguous judgement calls, or empty fields for data that exists, few-shot examples are the first technique. Use 2-4 targeted examples that include reasoning. Malformed JSON, fabricated missing fields, and sum mismatches need other techniques.
Structured Output with Tool Use
tool_use with a JSON schema eliminates JSON syntax errors. Prompt-based JSON does not. tool_choice auto may return text, any forces some tool call when the document type is unknown, and a named tool forces one step. The schema does not prevent semantic errors, and nullable fields are what stop fabrication.
Validation, Retry, and Feedback Loops
Retry-with-error-feedback sends the original document, the failed extraction, and the specific validation error. Retries fix format mismatches, structural errors, misplaced values, and mathematical mistakes. They cannot create information that is absent from the source. tool_use removes schema syntax errors; semantic checks, including Pydantic validators, feed the retry loop.
Batch Processing Strategies
The Message Batches API saves 50% against synchronous calls, with a processing window of up to 24 hours and no latency SLA. custom_id matches each request to its result. Blocking work such as a pre-merge check stays synchronous. Overnight debt reports, weekly audits, and nightly test generation use batch. Refine prompts on a sample before you submit, and resubmit only the failed items.
Multi-Instance and Multi-Pass Review
A model that reviews its own output in the same session keeps the reasoning that produced it and tends to confirm those choices. An independent instance judges the output fresh. Large reviews split into a per-file local pass plus a cross-file integration pass so attention is not diluted. Confidence scores route findings only after labelled sets calibrate the threshold.
Domain 5
15% of examContext Management & Reliability
Manage context windows effectively, implement caching strategies, handle long conversations, and build reliable production systems.
Context Window Management
Progressive summarisation drops numerical values, dates, percentages, and customer-stated expectations, so a $247.83 refund for order #8891 becomes a recent order. A persistent case facts block, included in every prompt and never summarised, holds those facts. Multi-issue sessions keep a separate structured issue layer. Key findings go at the start of aggregated inputs. Tool results are trimmed before they enter history. The Messages API is stateless, so each request carries the full conversation. Upstream agents return structured findings. Prompt caching exists; implementation details beyond knowing it exists are outside the current exam.
Escalation & Ambiguity Resolution
A support agent escalates for exactly three reasons: the customer explicitly asks for a human, the request is a policy gap or exception, or the agent has tried and cannot make progress. Honour an explicit human request on that turn. A policy violation has a documented refusal; a gap is silent and needs a human. Frustration and a self-reported confidence score are unreliable triggers. A frustrated customer with a straightforward issue gets the resolution; if they then insist on a human, escalate. Multiple customer matches require another identifier. The first fix is explicit escalation criteria with few-shot examples in the system prompt.
Error Propagation in Multi-Agent Systems
A failed subagent returns structured error context: failure type, the action it attempted, partial results, and alternative approaches. The four failure types are transient, validation, business, and permission. Silent suppression returns an empty success so the coordinator never recovers. Workflow termination throws away the subagents that finished. An access failure never executed and may be retried. A valid empty result executed and found nothing, so it is the answer. Synthesis output annotates coverage gaps. Transient failures are retried locally before they reach the coordinator.
Codebase Exploration & Context Degradation
Context degradation is an attention-quality problem: after extended codebase exploration the model cites typical patterns instead of the specific classes, methods, and paths it already found. Verbose discovery output buries earlier findings, and a larger context window does not fix that. Scratchpad files persist those findings outside the conversation and should be maintained from the start. Subagents isolate verbose exploration so the coordinator keeps structured summaries. Phase 1 summaries are injected into Phase 2 prompts to prevent a cold start. /compact is used proactively to protect context quality. A structured state manifest lets a crashed session resume without repeating the exploration.
Human Review & Confidence Calibration
A 97% aggregate accuracy figure can hide 45–60% accuracy on handwritten receipts, scanned PDFs, and international formats, because standard invoices dominate the volume. Validate accuracy by document type AND field segment before automating. Sample every stratum, including high-confidence extractions that are already automated. Raw confidence is relative: 0.90 on dates can mean 94% actual accuracy and 0.90 on amounts only 82%, so calibrate against labelled validation sets. Route fields above the calibrated threshold to automation with stratified sampling, and put the highest-uncertainty items first in a dynamic reviewer queue. Reduce human review only after that sequence, on segments that stay accurate.
Information Provenance & Multi-Source Synthesis
Every finding carries a structured mapping: claim, source URL, document name, relevant excerpt, and publication date. Attribution dies when a synthesis agent paraphrases those mappings away, so each step of the pipeline — research, analysis, synthesis, report — has to merge them forward. When two credible sources disagree, annotate both values with attribution and dates and let the reader decide. Different dates often describe a trend, such as growth moving from 8% to 12%. Render financial data as tables, news as prose, and technical findings as lists. An analysis that hits a conflict finishes with the conflict annotated for the coordinator.
Ready to practice?
Put the curriculum to work with hands-on exercises and a full mock exam.