CCAR-P Advanced Agentic Architecture Practice Question
Which TWO security measures are most effective at preventing 'Prompt Injection' attacks that target the arguments of tools used by an agent?
⚠ Common exam trap
Candidates often rely on 'system prompt instructions' to tell the model not to be hacked. This is ineffective against sophisticated prompt injection that bypasses textual constraints to manipulate tool arguments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Strict JSON schema validation for all tool inputs
Prompt injection in tool arguments occurs when an agent processes untrusted data and passes it into a tool call that executes logic. Validating inputs against a strict schema and running the tool in an isolated environment are the primary defenses, ensuring that even if the agent is misled, the impact is contained.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Adding 'Ignore all previous instructions' to the system prompt
Why it's wrong here
This is an outdated and largely ineffective technique. Attackers can easily bypass such instructions with more sophisticated prompts. Relying on the model to police itself through simple prompt-based prohibitions is not a robust security strategy for protecting tool execution in a production environment.
- ✓
Strict JSON schema validation for all tool inputs
Why this is correct
By enforcing a rigid schema, the orchestrator ensures that the arguments passed to the tool conform to expected types and formats. This prevents attackers from injecting malicious scripts or unexpected commands into fields that should only contain simple data, such as numeric IDs or pre-defined string constants.
- ✗
Filtering the assistant's output for the word 'password'
Why it's wrong here
Keyword filtering is a reactive and easily bypassed defense. It does nothing to prevent the actual injection of logic into tool arguments. An attacker can use synonyms, encoding, or indirect methods to achieve their goal without ever triggering a simple word-based filter, making this approach highly unreliable.
- ✓
Executing tools in a sandboxed, ephemeral environment
Why this is correct
Sandboxing ensures that even if a tool call is successfully compromised via injection, the malicious action is confined to a restricted space. The attacker cannot access the broader system, sensitive data, or persistent storage, effectively neutralizing the impact of the exploit and maintaining overall system integrity.
- ✗
Using a secondary model to re-write every user query
Why it's wrong here
While query rewriting can sanitize some inputs, it introduces significant latency and cost. Moreover, the rewriting model itself is also susceptible to prompt injection. This creates an infinite regress of 'models checking models' without addressing the fundamental need for secure, code-level validation of tool arguments.
About these practice questions
This CCAR-P question is part of Courseiva's 262-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.