CCDV-F Security Practice Question
A developer is using the Anthropic API to build a customer support chatbot. The chatbot must access a backend CRM to retrieve customer details. The security team requires that the chatbot only accesses records for the authenticated customer and that the CRM credentials are never exposed to the model. Which approach best satisfies these requirements?
⚠ Common exam trap
The trap here is thinking that the model can be trusted with credentials or that client-side calls are secure, when credentials must remain server-side and access must be tied to the authenticated user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a backend service that authenticates the user, retrieves the customer ID, and calls the CRM with its own credentials, then returns only the necessary data to Claude.
The best approach is a backend service that authenticates the user, retrieves the customer ID, and calls the CRM with its own credentials, returning only necessary data to Claude. This keeps credentials server-side and enforces that the chatbot only accesses records for the authenticated customer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pass the CRM API key to Claude in the system prompt so it can include the key when calling the CRM tool.
Why it's wrong here
Passing the CRM API key in the system prompt exposes it to the model and potentially to users if the model echoes it. This violates the requirement that credentials are never exposed to the model. It also creates a risk of leakage through prompt injection or logging.
- ✗
Store the CRM credentials in the model's fine-tuning data so it can learn to call the CRM securely.
Why it's wrong here
Fine-tuning data is not a secure place for credentials; it could be exposed or extracted. Moreover, fine-tuning does not grant the model the ability to call external APIs securely. This approach is insecure and does not satisfy the requirement that credentials are never exposed to the model.
- ✓
Implement a backend service that authenticates the user, retrieves the customer ID, and calls the CRM with its own credentials, then returns only the necessary data to Claude.
Why this is correct
A backend service that handles authentication and CRM access keeps credentials server-side and ensures the chatbot only receives data for the authenticated customer. Claude never sees the CRM credentials, and the service can enforce authorization based on the customer ID, satisfying both requirements.
- ✗
Have Claude generate CRM API calls and execute them directly from the client-side application using the customer's browser session.
Why it's wrong here
Executing CRM calls from the client-side exposes the CRM API to the browser and relies on the customer's session, which may not be authorized for the chatbot's actions. It also potentially exposes credentials or tokens to the client. This approach does not meet the requirement of keeping credentials away from the model and may violate security policies.
About these practice questions
Courseiva writes every CCDV-F question from scratch — 257 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.