Courseiva
Security →easyMultiple Choice

CCDV-F Security Practice Question

A developer is preparing to deploy a Claude-powered internal assistant that can query a customer database through a tool. Before release, the security team asks for evidence that the assistant cannot be manipulated into returning another customer's records. Which practice provides the strongest proactive assurance?

⚠ Common exam trap

The trap here is accepting a prompt-level instruction or post-launch monitoring as proof of authorization enforcement, when only testing and enforcing the data-layer boundary provides proactive assurance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a red-team exercise with adversarial prompts and tool-call attempts, and fix any issue where the assistant returns records outside the caller's authorized scope.

The strongest proactive assurance comes from actively attempting to break the authorization boundary and verifying that the system holds. Red-teaming with adversarial prompts and tool-call attempts tests the real behavior of the assistant and its tools, and fixing any discovered access-control failures before release produces evidence the security team can rely on. Prompt instructions, larger context, and after-the-fact monitoring do not enforce or prove the boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a system prompt that says the assistant must only return records belonging to the authenticated user.

    Why it's wrong here

    A system prompt is a soft instruction that can be overridden or ignored under adversarial input. It provides no enforceable guarantee and no evidence to the security team. The underlying tool can still query whatever the database credentials permit, so cross-customer access remains possible if the database layer is not constrained.

  • ✓

    Run a red-team exercise with adversarial prompts and tool-call attempts, and fix any issue where the assistant returns records outside the caller's authorized scope.

    Why this is correct

    Adversarial testing directly exercises the assistant's behavior against attempts to cross authorization boundaries, producing concrete evidence of whether the control holds. Fixing discovered issues before release closes the gaps. This is proactive because it validates the actual system behavior rather than assuming the design is sufficient.

  • ✗

    Monitor production logs after launch and alert when the assistant returns records that look unusual.

    Why it's wrong here

    Post-launch monitoring is detective and reactive; the unauthorized disclosure has already occurred by the time an alert fires. It does not provide the proactive assurance the security team requested before release. Detection is valuable as a supplement, but it cannot substitute for validating and enforcing authorization boundaries.

  • ✗

    Increase the model's context window so it can hold all relevant customer records and reason about authorization more reliably.

    Why it's wrong here

    A larger context window changes how much text the model can process, not whether it enforces access control. Authorization is a property of the data layer and tool implementation, not of model reasoning capacity. Loading more records can actually increase exposure if the tool is not scoped to the caller.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 257 original CCDV-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.