Courseiva
Security →mediumMultiple Choice

CCDV-F Security Practice Question

A developer is building a Claude-powered agent that calls an internal `search_customer_notes` tool. The agent runs with a system prompt that includes a user-supplied `account_id`. A security review finds that an attacker can craft a prompt injection that convinces Claude to call the tool with a different `account_id` than the one in the system prompt. Which control most directly prevents this privilege escalation while keeping the agent functional?

⚠ Common exam trap

The trap here is assuming that a stronger system prompt or a more capable model turns a model-supplied parameter into a trusted authorization input.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Pass the authenticated `account_id` from the server-side session into the tool implementation and ignore any `account_id` Claude supplies in tool arguments.

Authorization decisions must be enforced outside the model. Because Claude can be manipulated by prompt injection, any parameter that determines which records are accessible must come from a trusted server-side session rather than from model output. Binding the account_id server-side keeps the agent useful while ensuring it cannot be tricked into reading another customer's notes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the tool's rate limit so that mass enumeration of account IDs is impractical.

    Why it's wrong here

    Rate limiting changes the speed of abuse, not the authorization decision. An attacker who injects a single unauthorized account_id can still retrieve one victim's notes, which is a full confidentiality breach. The scenario asks for prevention of privilege escalation, and throttling does not validate entitlement, so it leaves the core authorization gap unresolved.

  • ✗

    Use a more capable Claude model with stronger instruction-following to reduce injection success.

    Why it's wrong here

    Model capability affects likelihood, not guarantee. Prompt injection remains a class of attack that no current model is immune to, and relying on model behavior for authorization violates defense-in-depth. The tool would still trust a model-supplied account_id, so a successful injection would still escalate privileges. This does not meet the requirement of directly preventing the escalation.

  • ✗

    Add a sentence to the system prompt instructing Claude to never change the `account_id` value.

    Why it's wrong here

    Prompt-level instructions are not a security boundary. A determined injection can override or bypass instructions, and the model has no reliable way to enforce them. This approach may reduce accidental drift but does not prevent a malicious prompt from causing the tool to be called with an unauthorized identifier, so it fails the requirement to directly prevent privilege escalation.

  • ✓

    Pass the authenticated `account_id` from the server-side session into the tool implementation and ignore any `account_id` Claude supplies in tool arguments.

    Why this is correct

    The tool should derive authorization context from the server session, not from model output. Claude can be manipulated through prompt injection, so any parameter that controls data access must be bound server-side. Ignoring the model-supplied account_id and using the authenticated session value ensures the tool can only read records the caller is entitled to, while still allowing Claude to decide when to call the tool.

About these practice questions

One of 257 original CCDV-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.