Exam Cheat-Sheet — Rules, Values & Anti-Patterns
CCA Associate Foundations course · Page 10 of 10 (final) · ← Back to all courses · This is the rapid-recall sheet — review it right before you sit the exam.
The 3 Universal Rules
- Classify the failure before picking a fix. Prompt failure (uniform across every input), hallucination (correct docs, wrong answer), model mismatch (fails only on complex tasks), or retrieval failure (wrong docs) each has a different, non-interchangeable fix.
- Aggregate numbers hide segment failures. A 96%+ overall accuracy figure can conceal 60% on one document type, one language, or one demographic slice. Never reduce human review, or conclude a system is fair, from the aggregate number alone.
- Non-refusal ≠ compliance, and instructions ≠ guarantees. Claude not refusing a request only means it passed Claude's general safety training — it says nothing about your organization's policy. A prompt instruction is probabilistic; a programmatic gate (or grounding, or a calibrated threshold) is what actually enforces a rule.
Exam-Day Decision Table
| When you see… | Answer |
|---|---|
| "Be more conservative" / "only flag high-confidence issues" suggested as a fix | Wrong — needs explicit report/skip categories, not a hedge |
| Complex subject matter, but each item is judged independently | Zero-shot — no sequential dependency, CoT unjustified |
| Multi-step calculation, error in step 2 affects step 4 | Chain-of-thought is justified |
| Correct documents retrieved, answer still wrong | Hallucination / grounding failure — not retrieval |
| Fails only on complex, multi-step tasks | Model mismatch — test a higher tier |
| Fails uniformly across every input type | Prompt failure — rewrite criteria |
| Judge model = the same model being evaluated | Self-preference bias — use a separate judge model |
| 90%+ aggregate accuracy cited as sufficient to cut review | Wrong — validate by segment first |
| Customer sounds frustrated / agent reports low confidence | Not valid escalation triggers |
| Two credible sources give different numbers | Show both with attribution — never average or pick one |
| Non-technical team, repeated weekly workflow | Claude.ai Projects, not the API |
| Cost-constrained scenario, two options both pass the quality bar | Cheaper option wins, always |
| Switching model tiers, prompt left unchanged | Wrong — re-evaluate; prompts don't transfer 1:1 |
| Overnight bulk job, no per-request latency requirement | Batches API |
Team standard written into ~/.claude/CLAUDE.md |
Wrong — teammates never receive it; must be project-level |
| Raw API key inside a committed settings file | Always wrong — use an environment variable reference |
| "What must the system NOT do" never asked in discovery | The category stakeholders never volunteer — ask explicitly |
| Design/build starts before all five discovery outputs exist | Wrong, regardless of time pressure |
| Step ordering must be guaranteed (refund, compliance, safety) | Programmatic gate — a prompt instruction is not enough |
| Claude doesn't refuse a request | Proves nothing about org policy — check the AUP separately |
| Full record (with SSN) faithfully returned by Claude | Not a model error — the design let too much data into context |
| BAA mentioned in a scenario | Signals HIPAA specifically |
| EU resident's data, company based outside the EU | GDPR still applies — extraterritorial by design |
| Irreversible action (send, pay, delete) with no human step | Requires authorization before execution |
| Different confidence thresholds by demographic group | Disparate treatment, not a fairness fix |
| Eval suite still passes after a recent prompt change | Could be out of date — verify it matches current behavior |
| Cost rose with no usage increase | Check for model-tier creep or a caching regression |
| Subagent timeout returned as an empty result | Wrong — must return structured error context, not silent empty success |
Domain Weights (instant recall)
| Domain | Weight |
|---|---|
| 1 — Prompting and Task Execution | 14% |
| 2 — Output Evaluation and Validation | 21% (heaviest) |
| 3 — Product and Model Selection | 12% |
| 4 — Workflow Integration and Solution Design | 16% |
| 5 — Configuration and Knowledge Management | 12% |
| 6 — Governance, Risk, and Responsible Use | 15% |
| 7 — Troubleshooting and Optimization | 10% |
Values Worth Memorizing
| Prompt component order | Role → Criteria → Boundaries → Output format |
| Few-shot example count | 2–4, always including one rejection example |
| Iteration progression | Zero-shot → few-shot → chain-of-thought |
| Validation ladder (cheapest first) | Code-based grader → LLM-as-judge (separate model) → human review |
| Discovery — required outputs before design | Problem statement · constraint inventory · data access map · stakeholder map · current-process baseline |
| Regulatory frameworks | GDPR (EU residents) · HIPAA (US PHI, needs a BAA) · FedRAMP (US federal cloud) |
| Transparency — three required elements | Disclose AI involvement · explain the decision · document known limitations |
| Model tiers | Haiku (fast/cheap, high-volume) · Sonnet (default) · Opus (hardest reasoning, low volume) |
| Token estimation | ~1.3 tokens per English word; ~4 characters per token |
| Context window | One shared budget — input + output tokens together |
Suggested Study Plan (multi-session — don't try this in one sitting)
Session 1: Domains 1 and 2 (prompting + evaluation — together 35% of the exam). Session 2: Domains 3 and 4 (product selection + workflow design — another 28%). Session 3: Domains 5, 6, and 7 (configuration, governance, troubleshooting — the remaining 37%). Session 4: The 6 exam scenarios, this cheatsheet, and the 50-question practice exam. Session 5+: Work through the domain-by-domain practice quizzes (7 sets, ~38 questions each) to drill your weakest areas specifically, then finish with the second full mock exam from the same page — review every missed question against its domain page before retrying.
🎯 You've reached the end of the course. Mark this page complete to hit 100% — then take the practice exam and revisit any domain that's still shaky. Good luck!