CCDV-F Security Practice Question
A developer stores the Anthropic API key in a mobile application's source code so the app can call Claude directly from the device. A security review flags this as a critical issue. Which remediation best addresses the root cause?
⚠ Common exam trap
The trap here is treating client-side obfuscation or key rotation as equivalent to removing a secret from an untrusted environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Move the Anthropic API calls to a backend service and have the mobile app authenticate to that service instead of holding the API key.
Secrets embedded in client binaries are recoverable by anyone who obtains the app, so the only durable fix is to remove the credential from the client. A backend proxy keeps the Anthropic API key server-side, lets you enforce user-level authentication and quotas, and allows key rotation without redistributing the application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restrict the API key to a single IP address range so only the corporate network can use it.
Why it's wrong here
Mobile clients roam across cellular and Wi-Fi networks with unpredictable addresses, so IP allowlisting would break legitimate use and is impractical to maintain. It also does not prevent extraction of the key; an attacker on an allowed network could still abuse it. This does not address the fact that a long-lived privileged credential is distributed to untrusted devices.
- ✗
Obfuscate the API key using a commercial mobile app hardening tool before shipping the build.
Why it's wrong here
Obfuscation raises the effort to extract a key but does not remove it from the distributed binary. Anyone with the app can still recover the secret through dynamic analysis or memory inspection. The key remains a shared credential embedded in every install, so this mitigates only trivially and does not fix the root cause of exposing a privileged secret to untrusted clients.
- ✗
Rotate the API key on a fixed schedule and embed the new key in each app release.
Why it's wrong here
Rotation limits the useful lifetime of a leaked key but does not prevent extraction from the binary, and it forces coordinated app releases that users may not install promptly. Multiple valid keys would coexist in the wild, expanding the attack surface. The secret still ships to every device, so the fundamental design flaw remains.
- ✓
Move the Anthropic API calls to a backend service and have the mobile app authenticate to that service instead of holding the API key.
Why this is correct
Removing the key from the client eliminates the exposure entirely. The mobile app authenticates as a user to a backend that holds the Anthropic API key in a secrets manager, enforces per-user authorization and rate limits, and can rotate the key without shipping a new app build. This addresses the root cause rather than hiding the symptom.
About these practice questions
Courseiva writes every CCDV-F question from scratch — 257 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.