CCDV-F Security Practice Question
A developer builds a retrieval-augmented generation (RAG) system where Claude answers questions using documents stored in an internal knowledge base. The security team is concerned that a malicious document could contain instructions that hijack the model. Which design choice most effectively reduces this indirect prompt injection risk?
⚠ Common exam trap
The trap here is assuming that encryption at rest or retrieving more documents addresses prompt injection, when the threat is about how retrieved content is interpreted, not how it is stored.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Treat retrieved document content as data only, place it in a clearly delimited user turn, and instruct the model to never follow instructions found inside retrieved content.
Indirect prompt injection occurs when untrusted retrieved content is interpreted as instructions. The most effective design mitigation is to keep retrieved text in a clearly delimited data section and tell the model never to follow instructions found there. This changes the model's parsing context and makes injected commands less likely to be executed, while supporting output validation. Encryption and summarization do not address the trust boundary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ask the model to summarize each retrieved document before answering the user's question.
Why it's wrong here
Summarization still processes the malicious content and can propagate injected instructions into the summary. It adds latency and cost without establishing a trust boundary. The model may follow instructions embedded in the document during summarization. This does not reduce the risk and may obscure the source of the injection.
- ✗
Store all documents in a vector database encrypted at rest with AES-256.
Why it's wrong here
Encryption at rest protects data confidentiality if the storage is compromised, but it does not affect content once it is retrieved and placed in the prompt. The malicious instruction would be decrypted and delivered to the model normally. This control is unrelated to indirect prompt injection and leaves the attack path intact.
- ✗
Increase the number of retrieved documents so the malicious content is diluted among many chunks.
Why it's wrong here
Adding more documents does not remove the malicious instruction; it may even increase the attack surface and token cost. The model can still follow a single injected instruction regardless of surrounding text. Dilution is not a security control and can degrade answer quality. This option does not address the root cause of treating retrieved text as trusted instructions.
- ✓
Treat retrieved document content as data only, place it in a clearly delimited user turn, and instruct the model to never follow instructions found inside retrieved content.
Why this is correct
Delimiting retrieved content and explicitly labeling it as untrusted data reduces the chance the model interprets embedded instructions as commands. While not a complete guarantee, it is the most effective design-level mitigation because it changes how the model parses context and makes injection attempts stand out. It also supports downstream validation of outputs against expected answer patterns.
About these practice questions
This CCDV-F question is part of Courseiva's 257-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.