CCAO-F Prep0/30
CCAO-F cheat sheet

Everything on one page

The rules of thumb behind most correct answers, grouped by domain.

ALL

Exam at a glance

ItemDetail
Format60 questions, single answer and “choose two”, scored all-or-nothing
Time120 minutes (2 minutes per question on average)
Score100–1000 scale, pass at 720
DeliveryProctored online or at a test centre; closed book, no AI assistance
Heaviest domainsD2 Output Evaluation 21%, D4 Workflow Integration 16%, D6 Governance 15%
D1

Prompt anatomy

Prompting & Task Execution
  • Context: who it's for, why, the situation
  • Task: a clear verb and a named deliverable
  • Constraints: length, tone, format, reading level, must-include, must-avoid
  • Examples: one or two approved samples beat any description
  • Material: paste documents under clear labels, separate from the instructions
  • Fallback: “If it isn't in the documents, say so”
D1

Prompt by task type

Prompting & Task Execution
TaskAsk for
AnalysisThe business question, criteria, stated assumptions, workings; findings separate from hypotheses
ResearchSources and citations; web search for anything current; then verify
DraftingAudience, purpose, tone, length, an example; what to keep exactly
BrainstormingMany varied options first; shortlist with people; develop against criteria
ExtractionFixed schema, one worked example, blank + flag when unsure
Big jobsOutline → sections → consistency check; agree the scheme before bulk work
D2

Hallucination red flags

Output Evaluation & Validation
  • Precise statistics with vague or no source
  • Quotes attributed to named people
  • Citations: papers, court cases, analyst reports, page or clause numbers
  • Recent events, current prices, rates or rules
  • Figures for data you never provided
  • Contradictions inside the output (two dates, two totals)
D2

What counts as verification

Output Evaluation & Validation
VerifiesDoesn't verify
Primary or official sourceAsking “are you sure?”
Recalculating the numbersClaude's stated confidence
Traceable evidence (quotes, IDs) spot-checkedTwo chats giving the same answer
Independent data or expert reviewRegenerating until it looks right
Live source for current facts“It sounds professional” or “it's detailed”
D2

Human review triggers

Output Evaluation & Validation
  • Public or external: press, web, customers, funders, regulators, courts
  • Legal, regulatory, contractual or financial commitments
  • Health, safety or safeguarding content
  • Decisions or records about individuals
  • Light review only: internal brainstorms, agendas, reformatting
D2

Output format chooser

Output Evaluation & Validation
DestinationFormat
Read onceInline answer
Kept, edited, shared, reusable toolArtifact or document
Spreadsheet, CRM, ERP, HR systemTable or CSV matching the target columns, plus a separate note
ExecutivesOne page: decision, impact, risk; detail in appendix
D3

Model tiers

Product & Model Selection
TierUse when
HaikuHigh volume, simple, fast or real-time, cost-sensitive (classify, route, tag)
SonnetEveryday drafting, summarising, analysis; balanced default
OpusComplex, high-stakes reasoning over long or conflicting material
D3

Feature chooser

Product & Model Selection
NeedFeature
Same reference files and rules in every chatProject (instructions + knowledge)
Current information with citationsWeb search or research
Something to keep, revise, share or interact withArtifact
Your own docs, mail or chat toolsConnector (within your permissions)
Personal preferences across chatsMemory, styles, preferences
Hard multi-step reasoningExtended thinking + capable model
D3

Context limits

Product & Model Selection
  • Context = this chat's history + its files + instructions
  • Symptoms: forgets early decisions, repeats rejected ideas, ignores early files
  • Fix: verified summary → new chat; stable material into a Project; summarise files separately then combine
  • No model has unlimited context; switching tiers isn't the fix
D4

Workflow design

Workflow Integration & Solution Design
Good fitKeep with people
First drafts from approved materialFinal decisions about people, money, safety
Summaries for a decision-makerApprovals and sign-off
Triage and categorisingSetting policy and strategy
Research plans, question listsInventing data, quotes or results
  • Order: problem → process map → suitable steps → measures → pilot → scale
  • Metrics: time per output, error/rework rate, quality scores, downstream outcomes; never prompt or chat counts
  • Escalate APIs, automation, database access and integrations to technical teams with written requirements
D5

Instructions vs knowledge vs message

Configuration & Knowledge Management
Put inWhat
InstructionsStanding rules: role, audience, tone, format, scope, sources, fallback, escalation
KnowledgeReference: current policies, price lists, guidelines, templates, examples
MessageThis task's specifics: customer, date, funder, room
  • Replace outdated files; remove drafts; one version per source
  • Connectors only reach what the user can access; check policy first
  • Named owner, review schedule, change log; reusable skill for shared procedures
D6

Regulations quick map

Governance, Risk & Responsible Use
RuleApplies to
GDPRPersonal data of people in the EU: lawful basis, minimisation, purpose limitation, DPO
HIPAAUS protected health information: approved environment, business associate agreement
PCI DSSPayment card data
FedRAMPCloud services used by US federal agencies
Contracts and privilegeClient confidentiality, legal privilege, export controls
  • Always: classify the data → confirm the tool is approved → minimise
  • Never fixes it: deleting afterwards, personal accounts, partial masking, “just this once”
D6

Responsible use

Governance, Risk & Responsible Use
  • No automated consequential decisions about people (credit, hiring, discipline, benefits, bans)
  • No fabricated reviews, testimonials, case studies, quotes or endorsements
  • Disclose AI where policy, contract or regulation requires; AI assistants identify as AI
  • People who approve and publish stay accountable
  • Seniority doesn't override policy: decline, escalate, report incidents
D7

Symptom → fix

Troubleshooting & Optimization
SymptomMost likely fix
Generic, bland outputAdd audience, goals, specifics and examples
Ignores a ruleMake it prominent, remove conflicts, show an example
Outdated facts from a ProjectRemove old or conflicting files from knowledge
Varies by personShared template and Project; same inputs
Invents missing numbersSupply data; require “data not provided”
Hedges on legitimate workExplain purpose and audience honestly
Same edits every weekPut the fix in the template, instructions or a skill
ALL

Picking the right answer

  • Prefer options that add specific context, examples or criteria
  • Prefer independent verification against sources
  • Prefer keeping a qualified human accountable
  • Prefer fixing the root cause or the workflow, not one output
  • Prefer following policy and escalating through the proper channel
  • Be wary of: always/never/guarantee, “ask Claude if it's sure”, “regenerate until”, skipping review, personal accounts, softening a dubious claim instead of removing it