CCAR-F Prompt Engineering and Structured Output Practice Question
Which of the following is the recommended approach for handling PII (Personally Identifiable Information) in prompts?
⚠ Common exam trap
Candidates often assume that instructing the model to 'ignore PII' or 'redact PII' is sufficient, ignoring the risk of model failure or leakage of sensitive information in the output.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Redact the PII at the application layer before sending the request to the API.
Always sanitize PII before it reaches the model to protect user privacy and comply with data governance policies. Anthropic recommends that sensitive data be redacted or masked upstream. Relying on the model to ignore or redact PII is not a secure architectural pattern, as models are not deterministic security filters. Protecting data at the application layer ensures compliance and minimizes security risks within the LLM pipeline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Tell the model in the system prompt to ignore and delete any PII found.
Why it's wrong here
Asking a model to sanitize data is unreliable and insecure. Models may fail to identify certain patterns or accidentally output PII in its raw form. Security must be implemented at the data processing layer before the prompt is constructed to guarantee that sensitive information never leaves the secure environment.
- ✓
Redact the PII at the application layer before sending the request to the API.
Why this is correct
Redacting PII before the data leaves your infrastructure is the industry standard for security. This prevents sensitive information from being processed by external services, maintaining full control over the data lifecycle. It is the most robust way to ensure that the model never encounters or outputs actual user data.
- ✗
Use a specialized system prompt that instructs the model to encrypt the data.
Why it's wrong here
LLMs are not encryption engines and cannot guarantee cryptographic integrity. Trying to use the model for security functions creates a false sense of security and does not protect data from being exposed during the request/response cycle. Data protection must be handled by established cryptographic libraries or services.
- ✗
Send the PII but add a disclaimer in the system prompt about data usage.
Why it's wrong here
A disclaimer is legally and technically insufficient for data protection. It does not prevent the model from processing or accidentally leaking the information. Data privacy requires proactive technical controls, not just descriptive policy statements, to ensure that personal information remains protected throughout the entire application's data pipeline.
About these practice questions
This CCAR-F question is part of Courseiva's 271-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.