Courseiva
Context and Reliability →hardMultiple Choice

CCAR-F Context and Reliability Practice Question

You are processing user input that might contain malicious injection attempts. Which architectural layer is best suited to handle this?

⚠ Common exam trap

Many test-takers mistakenly believe that system prompts or LLM guardrails alone provide a sufficient security boundary against malicious inputs, forgetting that code-level sanitization is mandatory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application-level code before the request is sent to the LLM.

You should never rely on the LLM as the sole security boundary. A multi-layered approach is required: first, an application-level input filter to sanitize data; second, a well-constructed system prompt that defines strict boundaries; and third, an output validator to ensure the model hasn't been successfully 'jailbroken.' Placing the primary security logic outside the model's inference loop is the only way to guarantee a reliable defense-in-depth posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The LLM's system prompt.

    Why it's wrong here

    The system prompt is a tool for instruction, not a secure container. It can be ignored or overridden by clever prompt injection attacks. Relying on it as your primary security boundary is a critical architectural flaw; security must be enforced by robust application-level filters and validation checks before the LLM even sees the data.

  • ✓

    The application-level code before the request is sent to the LLM.

    Why this is correct

    Sanitizing user input in the application layer is the first and most critical line of defense. By enforcing strict input validation, length checks, and pattern matching before the prompt is constructed, you prevent malicious payloads from reaching the model. This is the only way to establish a reliable, layered security perimeter for LLM applications.

  • ✗

    The model's fine-tuning training data.

    Why it's wrong here

    Fine-tuning does not provide security or protection against prompt injection. A model's weights are static and cannot defend against new, novel attack patterns that emerge after the training process is complete. Security requires dynamic, real-time filtering that can be updated as new threats are identified, which fine-tuning cannot provide.

  • ✗

    A secondary LLM to monitor the first LLM.

    Why it's wrong here

    Using a secondary LLM for monitoring is an expensive and complex approach that still leaves you vulnerable to the same risks as the primary LLM. It is not a substitute for standard, proven security practices like input sanitization and strict schema validation, which are far more reliable and performant.

About these practice questions

Courseiva writes every CCAR-F question from scratch — 271 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.