20+ practice questions focused on Security — one of the most tested topics on the Claude Certified Developer exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Security PracticeAn enterprise application integrates Claude via the Anthropic API. The security team mandates that no prompt data or output is stored by Anthropic for model training. Which configuration ensures this requirement is met?
Explanation: Anthropic provides a data processing addendum that disables data retention for model training when explicitly configured. By utilizing the opt-out mechanism for data collection, organizations ensure that their proprietary prompt data remains outside of the training pipeline. This is critical for maintaining compliance with data privacy regulations like GDPR and CCPA, as it guarantees that sensitive inputs are processed ephemerally without being persisted in model weight updates.
An application processes PII (Personally Identifiable Information) before sending it to Claude. Which TWO steps should the developer implement to adhere to the principle of least privilege and data minimization?
Explanation: Data minimization is foundational to AI security. By stripping PII before transmission, the developer minimizes the blast radius if an incident occurs. Implementing strict API key scoping ensures that even if credentials are compromised, the scope of damage is restricted. These practices collectively build a defense-in-depth posture, ensuring that AI models are only provided with the absolute minimum context required to perform their intended tasks effectively.
Refer to the exhibit. The system prompt is configured as shown. What is the expected behavior of the model when it receives the user's input?
Explanation: Anthropic models are trained to follow system instructions. By defining a clear boundary in the system prompt, the model is expected to evaluate the user's intent against these constraints. In this case, the instruction to reject non-geography topics acts as a security guardrail. The model should identify the request as a violation of the specified scope and refuse to provide the malicious information requested.
Which THREE practices are recommended when auditing Anthropic API usage for security compliance?
Explanation: Auditing is essential for detecting abuse and ensuring that AI interactions remain within policy boundaries. By tracking usage metrics and logs, security teams can identify anomalies such as sudden spikes in token consumption or unusual prompt patterns. These practices provide the visibility required to respond to incidents effectively and maintain an ongoing record for regulatory compliance and internal security reviews.
A developer needs to prevent 'prompt leaking' where the system prompt is revealed to the user. What is the most robust mitigation technique?
Explanation: Prompt leaking is a common vulnerability where users try to extract system instructions via adversarial questions. While no method is 100% effective, separating the system instructions from user-provided data through clear structural definition and using robust system prompts that explicitly state their own confidentiality are the industry standards. This forces the model to respect the boundary between internal logic and external user input during its generation process.
+15 more Security questions available
Practice all Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Security questions on the CCDV-F frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Security is tested as part of the Claude Certified Developer blueprint. Practicing with targeted Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CCDV-F practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Security practice session with instant scoring and detailed explanations.
Start Security Practice →