Courseiva
Security →easyMultiple Choice

CCDV-F Security Practice Question

A developer is integrating the Anthropic API into a healthcare application that processes protected health information (PHI). The compliance team requires that data is encrypted in transit and that the application authenticates to the API without embedding secrets in client-side code. Which combination of practices should the developer implement?

⚠ Common exam trap

The trap here is thinking that a VPN or client-side config file is sufficient for securing API keys, when the requirement explicitly forbids embedding secrets in client-side code and demands encryption in transit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use HTTPS with TLS 1.2 or higher for all API calls and store the Anthropic API key in a server-side secret manager, retrieving it at runtime.

The correct practices are HTTPS with TLS 1.2+ for encryption in transit and a server-side secret manager for the API key. This ensures PHI is protected during transmission and the API key is not exposed in client code, satisfying both compliance requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use HTTPS for API calls and store the API key in a client-side configuration file that is bundled with the application.

    Why it's wrong here

    While HTTPS meets the encryption requirement, storing the API key in a client-side configuration file exposes it to end users and attackers. Client-side code is not a secure secret store. The key could be extracted and abused, violating the authentication requirement and putting PHI at risk.

  • ✗

    Use a VPN for all traffic and hardcode the API key in the server application's environment variables.

    Why it's wrong here

    A VPN may encrypt traffic but does not replace HTTPS for API calls, and hardcoding keys in environment variables is less secure than a secret manager because they can be exposed in logs or process listings. This does not meet the requirement to avoid embedding secrets and lacks proper key management.

  • ✓

    Use HTTPS with TLS 1.2 or higher for all API calls and store the Anthropic API key in a server-side secret manager, retrieving it at runtime.

    Why this is correct

    HTTPS with TLS 1.2+ ensures encryption in transit, and a server-side secret manager keeps the API key out of client code. Retrieving the key at runtime avoids hardcoding and allows rotation. This combination directly satisfies both the encryption and authentication requirements for PHI handling without exposing credentials to end users.

  • ✗

    Use HTTP for internal network calls and embed the API key in the mobile app's source code for simplicity.

    Why it's wrong here

    HTTP provides no encryption in transit, violating the requirement. Embedding the API key in client code exposes it to anyone who decompiles the app, enabling unauthorized API usage and potential data breaches. This approach fails both security mandates and is unacceptable for PHI.

About these practice questions

This CCDV-F question is part of Courseiva's 257-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.