CCDV-F Security Practice Question
A developer is integrating Claude into a customer-facing portal where users can paste arbitrary text that is inserted into prompts. The security team wants to reduce the risk of prompt injection leading to unauthorized actions. Which TWO controls are most effective? (Choose two.)
⚠ Common exam trap
The trap here is believing that sampling parameters such as temperature or token limits function as security controls against adversarial input.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Delimit and clearly label untrusted user content within the prompt, instructing Claude to treat it as data rather than instructions.
Prompt injection defense requires both reducing the model's tendency to follow injected instructions and ensuring that no unauthorized action succeeds regardless of model output. Delimiting untrusted content addresses the first layer, while server-side authorization enforcement addresses the second and is the control that actually prevents harm when injection attempts succeed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the max_tokens setting so Claude has more room to reason about whether input is malicious.
Why it's wrong here
Token limits govern output length, not security reasoning. Giving the model more space to generate text does not create a reliable injection detector and can actually give an attacker more room to steer the conversation. This does not address the authorization gap and is not a recognized prompt injection control.
- ✗
Cache responses for identical user inputs to reduce the number of times Claude processes potentially malicious text.
Why it's wrong here
Caching changes how often the model is invoked, not whether an injected instruction is honored. A cached response could even replay a previously successful injection to other users if keys are not properly scoped. This does not reduce the risk of unauthorized actions and introduces additional data-isolation concerns, so it is not an effective control.
- ✓
Delimit and clearly label untrusted user content within the prompt, instructing Claude to treat it as data rather than instructions.
Why this is correct
Wrapping user input in explicit delimiters with a clear statement that the enclosed content is data, not instructions, reduces the chance that Claude follows injected commands. It is not a complete boundary on its own, but it is a standard, low-cost mitigation that measurably lowers injection success and preserves the intended task behavior when combined with server-side authorization.
- ✓
Enforce authorization for any action Claude proposes by validating the user's session and entitlements in the application backend before executing.
Why this is correct
Even if injection succeeds in making Claude propose an unauthorized action, server-side authorization checks the authenticated user's permissions before executing anything. This is the decisive control because it does not depend on model behavior. It converts a potential privilege escalation into a denied request, which is why it is essential alongside prompt-level mitigations.
- ✗
Lower the temperature to zero so Claude becomes deterministic and cannot be manipulated.
Why it's wrong here
Temperature affects sampling randomness, not susceptibility to adversarial instructions. A deterministic model can still reliably follow an injected command every time, which is worse for security. Determinism aids reproducibility and testing, but it is not a mitigation for prompt injection and does not prevent unauthorized actions.
About these practice questions
One of 257 original CCDV-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.