Courseiva
Security →hardMultiple Select

CCDV-F Security Practice Question

A fintech company deploys a Claude-powered agent that can call internal tools such as `get_transaction_history` and `initiate_transfer`. During a red-team exercise, an attacker crafts a user message that causes the agent to call `initiate_transfer` to an attacker-controlled account. Which TWO controls most directly mitigate this tool-abuse risk? (Choose two.)

⚠ Common exam trap

The trap here is believing that a strong system prompt or post-hoc logging prevents a manipulated model from invoking a dangerous tool, when only external enforcement can block the action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Validate tool arguments against a server-side allowlist of permitted destination accounts and enforce authorization checks in the tool implementation.

Tool abuse is mitigated by enforcing trust boundaries outside the model. A human approval gate for high-impact actions prevents unauthorized execution, and server-side argument validation with authorization ensures the tool only acts on permitted inputs. Prompt instructions and temperature changes are not enforceable, and logging without prevention is only detective. Together, the two preventive controls block the attack even if the model is manipulated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a system prompt that tells Claude to never call `initiate_transfer` unless the user explicitly asks for it.

    Why it's wrong here

    A system prompt is not an enforcement mechanism. Prompt injection can override or bypass instructions, and the model may still emit the tool call. Because the control lives inside the model's reasoning, it provides no hard guarantee. The scenario requires mitigation of tool abuse, which demands external enforcement rather than model-level guidance.

  • ✓

    Validate tool arguments against a server-side allowlist of permitted destination accounts and enforce authorization checks in the tool implementation.

    Why this is correct

    Server-side validation and authorization ensure that even a manipulated tool call cannot transfer to an unapproved account. The tool itself checks the caller's identity and the destination against policy, so the model's output is treated as untrusted input. This directly blocks the attacker's goal of redirecting funds to a controlled account.

  • ✗

    Log all tool calls and review them weekly for suspicious patterns.

    Why it's wrong here

    Logging and review are detective controls that occur after the fact. They can help with incident response but do not prevent a fraudulent transfer from executing. The scenario asks for mitigation of tool abuse, which requires preventive controls. Detection alone leaves the funds already moved and the attacker's objective achieved.

  • ✗

    Increase the model's temperature to make its behavior less predictable to attackers.

    Why it's wrong here

    Raising temperature increases randomness and makes outputs less reliable, which worsens security and usability. It does not prevent a tool call; it only makes behavior harder to test and reproduce. Security controls should be deterministic and external. This option neither blocks unauthorized transfers nor improves authorization.

  • ✓

    Require explicit human approval for any tool call that moves funds, and enforce it outside the model in the orchestration layer.

    Why this is correct

    Placing a human-in-the-loop gate in the orchestration layer means the model cannot unilaterally execute a high-impact action. Even if the model is manipulated, the transfer is blocked until a human confirms the details. This is a defense that does not depend on the model's judgment and directly addresses unauthorized tool invocation for financial actions.

About these practice questions

Courseiva writes every CCDV-F question from scratch — 257 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.