Courseiva

CCAR-F Agentic Architecture and Orchestration Practice Question

An architect is hardening an agent that uses tools to read internal wikis and send Slack messages. Which TWO practices most directly reduce the risk that untrusted wiki content causes the agent to take unauthorized actions? (Choose two.)

⚠ Common exam trap

The trap here is assuming a single credential with both read and write scopes simplifies the agent, when in fact combining scopes is what lets injected content escalate into unauthorized actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Wrap retrieved wiki content in a clearly delimited block and instruct the model in the system prompt to treat that block as data, never as instructions.

Two complementary controls break indirect prompt injection: treating retrieved content strictly as data via delimiters and system-prompt framing, and inserting a human approval gate before irreversible actions that were influenced by that content. Together they reduce both the chance of manipulation and the blast radius if manipulation occurs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Raise the model's temperature so the agent explores alternative interpretations of the wiki text.

    Why it's wrong here

    Higher temperature increases variability and can make the agent more susceptible to creative misreadings of injected content. It does not add any security property. Injection defense comes from delimiting data, least privilege, and human approval, not from sampling diversity, which here would only degrade reliability.

  • ✓

    Wrap retrieved wiki content in a clearly delimited block and instruct the model in the system prompt to treat that block as data, never as instructions.

    Why this is correct

    Delimiting untrusted content and labeling it as data reduces the chance the model treats embedded text as commands. This is a foundational defense against indirect prompt injection, because it separates the instruction channel from the data channel. It is not a complete solution on its own, but it materially lowers risk when combined with privilege separation.

  • ✓

    Require an explicit human approval step before the agent sends any Slack message whose destination or content is derived from wiki content.

    Why this is correct

    Human-in-the-loop approval on actions influenced by untrusted content breaks the injection chain. Even if the model is manipulated into drafting a malicious message, a reviewer sees the destination and body before it is sent. This is a strong, practical control for irreversible side effects and complements input delimiting.

  • ✗

    Give the agent a single credential with read access to wikis and write access to Slack so it can complete tasks without switching identities.

    Why it's wrong here

    Combining read and write privileges in one identity means injected instructions can immediately exercise the write capability, including messages to unintended channels. Least privilege calls for separating the read path from the action path, granting the Slack write capability only after an explicit, verified decision, not by default.

  • ✗

    Rely on the wiki's own content moderation to strip malicious instructions before retrieval.

    Why it's wrong here

    The agent cannot assume upstream moderation is complete or current. Wiki pages can be edited after moderation, and injection payloads are often benign-looking prose. Defense must live in the agent architecture, through delimiting, least privilege, and approval gates, rather than depending on a third-party content pipeline.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 271 original CCAR-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.