Courseiva

CCAR-F Agentic Architecture and Orchestration Practice Question

A security audit of an agentic architecture reveals a risk of 'Indirect Prompt Injection' where the agent reads a malicious email and then uses its 'delete_account' tool on itself. Which architectural change best mitigates this risk?

⚠ Common exam trap

Candidates often suggest technical fixes like prompt sanitization or input filtering, which are insufficient against sophisticated indirect injections; they overlook the necessity of human-in-the-loop for high-stakes actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Moving sensitive tools like 'delete_account' to a 'Human-in-the-Loop' approval workflow.

Indirect prompt injection occurs when a model treats untrusted data (like an email) as a set of instructions. To prevent this, architects must separate the data from the instructions, use strict tool schemas, and implement 'Human-in-the-Loop' for high-impact tools to ensure that the agent's actions are always verified.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Adding a sentence to the system prompt telling Claude to ignore instructions in emails.

    Why it's wrong here

    System prompt instructions are not a robust defense against injection. Malicious prompts can be designed to 'jailbreak' or override these instructions by using sophisticated language that confuses the model's priority of commands, making this a 'soft' defense that is easily bypassed.

  • ✗

    Implementing a separate 'Sandboxed Guardrail' agent to pre-scan all incoming data for commands.

    Why it's wrong here

    While pre-scanning is helpful, it is not foolproof, as the 'guardrail' agent is also an LLM and can be fooled by the same injection techniques. It adds latency and cost without providing a definitive security boundary for the most sensitive actions in the agentic system.

  • ✓

    Moving sensitive tools like 'delete_account' to a 'Human-in-the-Loop' approval workflow.

    Why this is correct

    The most secure architectural choice is to remove the model's autonomy for irreversible or high-risk actions. By requiring a human to click 'Approve' on a dashboard before the 'delete_account' tool actually executes, you create a physical barrier that prompt injection cannot bypass.

  • ✗

    Encoding all email text into a format like Base64 before showing it to the agent.

    Why it's wrong here

    If the agent is expected to summarize or act on the email, it will eventually need to decode or interpret the content. Once the content is interpreted by the model, any injected instructions will be processed. Base64 encoding only hides the text from simple filters, not from the model itself.

About these practice questions

One of 271 original CCAR-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.