Quick revision notes for Claude Certified Architect – Professional.
Claude Code Configuration Scopes
| Scope | Use |
|---|---|
| Managed | Organisation-wide security/compliance settings that must not be overridden. |
| Project | Team-shared configuration committed to the repository. |
| User | Personal preferences that follow an engineer across projects. |
| Local | Machine/project-specific configuration not intended for the whole team. |
Configuration Precedence
Highest → Lowest:
Managed → Command Line → Local → Project → User
Exam Memory:
Team shared → Project
Personal preference → User
Must not be overridden → Managed
MCP Servers
MCP is used when Claude needs tools or access to external/live systems.
Important exam points:
- Too many MCP tool definitions loaded upfront consume context.
- Use Tool Search to discover tools on demand.
- Do not disable useful tools just to reduce context.
- New MCP server missing? Check registration first, then reconnect/restart.
- Use least-privilege tool permissions.
Tool Search
If 50–60+ tools are loaded before the user sends a message:
Best solution: Enable Tool Search / progressive tool discovery.
This preserves available capabilities while avoiding unnecessary tool definitions in the initial context.
Least Privilege
Give an agent only the tools needed for its defined responsibility.
Good: read knowledge base + write draft queue.
Bad: unrestricted Bash, database admin access, or unrelated tools.
Prefer:
Allow-list required tools + explicit deny rules for sensitive operations.
Claude Skill vs MCP vs Subagent
| Requirement | Best Choice |
|---|---|
| Reusable procedural knowledge | Skill |
| Fixed procedure with examples | Skill |
| No live external-system calls | Skill |
| Live database/API/tool access | MCP |
| Recurring specialised task | Subagent |
| Focused prompt + narrow tools + specific model | Subagent |
When to Use a Subagent
A dedicated subagent makes sense when a task:
Recurs frequently + needs a specialised prompt + narrow permissions + specific model selection.
Do not create a subagent for a one-time generic task.
Persistent Project Context
If engineers repeatedly explain the same architecture and coding conventions:
Store them in project-scoped CLAUDE.md or equivalent project context.
Secrets
Never store API keys or credentials in version-controlled configuration.
Correct pattern:
Application → Runtime Secret Store → Credential
Fast Exam Recall
Shared config? Project.
Company security policy? Managed.
Personal preference? User.
Many MCP tools? Tool Search.
Reusable procedure? Skill.
Live external system? MCP.
Recurring specialist role? Subagent.
Credential? Secret store.