Courseiva
Security →hardMultiple Choice

CCDV-F Security Practice Question

A large-scale deployment of Claude is causing intermittent spikes in latency. Which security-related monitoring practice helps differentiate between a DDoS attack and legitimate heavy usage?

⚠ Common exam trap

Candidates often suggest simple rate limiting, which fails to distinguish between a heavy legitimate user and a malicious actor, potentially blocking valid high-value business traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analyze the request frequency and prompt diversity from specific origin IPs.

Differentiating between DDoS attacks and high legitimate load requires deep visibility into API request patterns. By tracking the distribution of source IPs, request frequency per token, and the complexity of prompts, security teams can identify anomalous patterns that signify an attack. This is crucial for maintaining availability without blocking legitimate users, ensuring that security measures are proportionate to the threat, rather than causing self-inflicted denial of service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check the total cost of API usage in the Anthropic dashboard.

    Why it's wrong here

    Cost is a lagging indicator. By the time you notice an anomalous cost, the damage from an attack may already be done. Cost monitoring is essential for financial management, but it is not a technical tool for distinguishing between malicious traffic patterns and legitimate high-frequency user interactions in real-time.

  • ✓

    Analyze the request frequency and prompt diversity from specific origin IPs.

    Why this is correct

    DDoS attacks typically exhibit high-frequency requests from limited sources or bots, often with low diversity in prompts. Legitimate usage is generally more varied. By analyzing the diversity of queries and the origin of traffic, you can differentiate between normal growth and a targeted attempt to exhaust resources.

  • ✗

    Limit all users to one request per minute.

    Why it's wrong here

    Setting a draconian rate limit negatively impacts the user experience and breaks legitimate applications that require high throughput. A one-size-fits-all approach is not a valid security strategy; it is a blunt instrument that hinders functionality and fails to address the nuances of modern, sophisticated traffic patterns.

  • ✗

    Disable all external access to the API immediately.

    Why it's wrong here

    Disabling access is a nuclear option that accomplishes the goal of stopping a DDoS attack, but it also stops all legitimate business. This is not a balanced or effective security practice for maintaining service availability. Effective security involves graceful mitigation, not total system shutdown in response to spikes.

About these practice questions

This CCDV-F question is part of Courseiva's 257-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.