CCDV-F Security Practice Question
A developer is designing a Claude-powered application that will process user-uploaded documents. The security team is concerned about prompt injection attacks that could cause the model to leak system prompts or execute unintended actions. Which TWO practices should the developer implement to mitigate this risk? (Choose two.)
⚠ Common exam trap
The trap here is believing that model safety filters or prompt engineering alone can fully prevent prompt injection, when architectural isolation and input validation are also necessary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sanitize and validate user input to remove or escape known prompt injection patterns before sending it to the model.
The two effective practices are sanitizing user input to reduce known injection patterns and isolating the model instance that processes untrusted input so it has no access to sensitive tools or data. Together they provide defense in depth and limit the impact of any successful injection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sanitize and validate user input to remove or escape known prompt injection patterns before sending it to the model.
Why this is correct
Sanitizing and validating user input reduces the likelihood of known injection patterns reaching the model. While not foolproof, it adds a defensive layer that can catch common attacks. This practice is part of a defense-in-depth strategy and helps prevent the model from being manipulated by malicious content in uploaded documents.
- ✗
Store the system prompt in a client-side JavaScript variable so it can be easily updated without redeploying the backend.
Why it's wrong here
Storing the system prompt client-side exposes it to users, making it easier for attackers to craft targeted injections. The system prompt should be kept server-side and never sent to the client. This practice increases risk rather than mitigating it.
- ✗
Increase the model's temperature setting to make its responses less predictable and harder for attackers to exploit.
Why it's wrong here
Temperature controls randomness in output and does not mitigate prompt injection. Higher temperature could actually make behavior less predictable in undesirable ways and does not prevent an attacker from crafting effective prompts. It is not a security control.
- ✗
Rely solely on the model's built-in safety filters to block all prompt injection attempts without additional controls.
Why it's wrong here
Built-in safety filters are helpful but not sufficient to block all prompt injection attempts, especially novel ones. Relying solely on them creates a single point of failure. Defense in depth requires additional controls such as input sanitization and isolation.
- ✓
Use a separate, isolated model instance for processing untrusted user input, with no access to sensitive tools or data.
Why this is correct
Isolating the model instance that processes untrusted input limits the blast radius of a successful injection. If the model has no access to sensitive tools or data, an attacker cannot leverage it to leak secrets or perform unauthorized actions. This separation of duties is a strong architectural mitigation.
About these practice questions
This CCDV-F question is part of Courseiva's 257-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.