CCAO-F cheat sheet
Everything on one page
The rules of thumb behind most correct answers, grouped by domain.
ALL
Exam at a glance
| Item | Detail |
|---|---|
| Format | 60 questions, single answer and “choose two”, scored all-or-nothing |
| Time | 120 minutes (2 minutes per question on average) |
| Score | 100–1000 scale, pass at 720 |
| Delivery | Proctored online or at a test centre; closed book, no AI assistance |
| Heaviest domains | D2 Output Evaluation 21%, D4 Workflow Integration 16%, D6 Governance 15% |
D1
Prompt anatomy
Prompting & Task Execution
- Context: who it's for, why, the situation
- Task: a clear verb and a named deliverable
- Constraints: length, tone, format, reading level, must-include, must-avoid
- Examples: one or two approved samples beat any description
- Material: paste documents under clear labels, separate from the instructions
- Fallback: “If it isn't in the documents, say so”
D1
Prompt by task type
Prompting & Task Execution
| Task | Ask for |
|---|---|
| Analysis | The business question, criteria, stated assumptions, workings; findings separate from hypotheses |
| Research | Sources and citations; web search for anything current; then verify |
| Drafting | Audience, purpose, tone, length, an example; what to keep exactly |
| Brainstorming | Many varied options first; shortlist with people; develop against criteria |
| Extraction | Fixed schema, one worked example, blank + flag when unsure |
| Big jobs | Outline → sections → consistency check; agree the scheme before bulk work |
D2
Hallucination red flags
Output Evaluation & Validation
- Precise statistics with vague or no source
- Quotes attributed to named people
- Citations: papers, court cases, analyst reports, page or clause numbers
- Recent events, current prices, rates or rules
- Figures for data you never provided
- Contradictions inside the output (two dates, two totals)
D2
What counts as verification
Output Evaluation & Validation
| Verifies | Doesn't verify |
|---|---|
| Primary or official source | Asking “are you sure?” |
| Recalculating the numbers | Claude's stated confidence |
| Traceable evidence (quotes, IDs) spot-checked | Two chats giving the same answer |
| Independent data or expert review | Regenerating until it looks right |
| Live source for current facts | “It sounds professional” or “it's detailed” |
D2
Human review triggers
Output Evaluation & Validation
- Public or external: press, web, customers, funders, regulators, courts
- Legal, regulatory, contractual or financial commitments
- Health, safety or safeguarding content
- Decisions or records about individuals
- Light review only: internal brainstorms, agendas, reformatting
D2
Output format chooser
Output Evaluation & Validation
| Destination | Format |
|---|---|
| Read once | Inline answer |
| Kept, edited, shared, reusable tool | Artifact or document |
| Spreadsheet, CRM, ERP, HR system | Table or CSV matching the target columns, plus a separate note |
| Executives | One page: decision, impact, risk; detail in appendix |
D3
Model tiers
Product & Model Selection
| Tier | Use when |
|---|---|
| Haiku | High volume, simple, fast or real-time, cost-sensitive (classify, route, tag) |
| Sonnet | Everyday drafting, summarising, analysis; balanced default |
| Opus | Complex, high-stakes reasoning over long or conflicting material |
D3
Feature chooser
Product & Model Selection
| Need | Feature |
|---|---|
| Same reference files and rules in every chat | Project (instructions + knowledge) |
| Current information with citations | Web search or research |
| Something to keep, revise, share or interact with | Artifact |
| Your own docs, mail or chat tools | Connector (within your permissions) |
| Personal preferences across chats | Memory, styles, preferences |
| Hard multi-step reasoning | Extended thinking + capable model |
D3
Context limits
Product & Model Selection
- Context = this chat's history + its files + instructions
- Symptoms: forgets early decisions, repeats rejected ideas, ignores early files
- Fix: verified summary → new chat; stable material into a Project; summarise files separately then combine
- No model has unlimited context; switching tiers isn't the fix
D4
Workflow design
Workflow Integration & Solution Design
| Good fit | Keep with people |
|---|---|
| First drafts from approved material | Final decisions about people, money, safety |
| Summaries for a decision-maker | Approvals and sign-off |
| Triage and categorising | Setting policy and strategy |
| Research plans, question lists | Inventing data, quotes or results |
- Order: problem → process map → suitable steps → measures → pilot → scale
- Metrics: time per output, error/rework rate, quality scores, downstream outcomes; never prompt or chat counts
- Escalate APIs, automation, database access and integrations to technical teams with written requirements
D5
Instructions vs knowledge vs message
Configuration & Knowledge Management
| Put in | What |
|---|---|
| Instructions | Standing rules: role, audience, tone, format, scope, sources, fallback, escalation |
| Knowledge | Reference: current policies, price lists, guidelines, templates, examples |
| Message | This task's specifics: customer, date, funder, room |
- Replace outdated files; remove drafts; one version per source
- Connectors only reach what the user can access; check policy first
- Named owner, review schedule, change log; reusable skill for shared procedures
D6
Regulations quick map
Governance, Risk & Responsible Use
| Rule | Applies to |
|---|---|
| GDPR | Personal data of people in the EU: lawful basis, minimisation, purpose limitation, DPO |
| HIPAA | US protected health information: approved environment, business associate agreement |
| PCI DSS | Payment card data |
| FedRAMP | Cloud services used by US federal agencies |
| Contracts and privilege | Client confidentiality, legal privilege, export controls |
- Always: classify the data → confirm the tool is approved → minimise
- Never fixes it: deleting afterwards, personal accounts, partial masking, “just this once”
D6
Responsible use
Governance, Risk & Responsible Use
- No automated consequential decisions about people (credit, hiring, discipline, benefits, bans)
- No fabricated reviews, testimonials, case studies, quotes or endorsements
- Disclose AI where policy, contract or regulation requires; AI assistants identify as AI
- People who approve and publish stay accountable
- Seniority doesn't override policy: decline, escalate, report incidents
D7
Symptom → fix
Troubleshooting & Optimization
| Symptom | Most likely fix |
|---|---|
| Generic, bland output | Add audience, goals, specifics and examples |
| Ignores a rule | Make it prominent, remove conflicts, show an example |
| Outdated facts from a Project | Remove old or conflicting files from knowledge |
| Varies by person | Shared template and Project; same inputs |
| Invents missing numbers | Supply data; require “data not provided” |
| Hedges on legitimate work | Explain purpose and audience honestly |
| Same edits every week | Put the fix in the template, instructions or a skill |
ALL
Picking the right answer
- Prefer options that add specific context, examples or criteria
- Prefer independent verification against sources
- Prefer keeping a qualified human accountable
- Prefer fixing the root cause or the workflow, not one output
- Prefer following policy and escalating through the proper channel
- Be wary of: always/never/guarantee, “ask Claude if it's sure”, “regenerate until”, skipping review, personal accounts, softening a dubious claim instead of removing it