Courseiva
Security →hardMultiple Choice

CCDV-F Security Practice Question

An enterprise uses Claude to generate SQL queries from natural-language questions against a production database. The security team wants to prevent the model from producing destructive statements such as DROP TABLE. Which control provides the strongest guarantee?

⚠ Common exam trap

The trap here is trusting a prompt instruction or a keyword blacklist as a security boundary, when only the database's privilege model can reliably block destructive statements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Execute generated SQL with a database role that has only SELECT privileges on the required views.

The strongest guarantee comes from enforcing least privilege in the database, because the database engine will reject destructive statements regardless of what the model generates. Prompt instructions and keyword filters operate before execution and can be bypassed or produce errors. Logging is only detective. By executing generated SQL with a read-only role scoped to required views, the system prevents destructive operations by design.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a system prompt that instructs Claude to only generate SELECT statements.

    Why it's wrong here

    A system prompt is guidance, not enforcement. The model can still emit destructive SQL due to prompt injection, ambiguity, or error. Because the control lives in the model, it provides no hard guarantee. The scenario asks for the strongest guarantee, which requires an external enforcement point such as database permissions.

  • ✗

    Parse the generated SQL and reject any statement containing the word DROP or DELETE.

    Why it's wrong here

    Keyword filtering is easily bypassed with comments, casing, alternate syntax, or stored procedure calls, and it can also block legitimate queries. It is a brittle blacklist that does not guarantee safety. A determined attacker or a creative model output can evade simple string checks, so this is weaker than database-enforced privileges.

  • ✓

    Execute generated SQL with a database role that has only SELECT privileges on the required views.

    Why this is correct

    Least-privilege execution is the strongest guarantee because even if the model emits a destructive statement, the database rejects it. The control is enforced by the database engine, not by the model or prompt. This directly prevents DROP or other write operations regardless of how the SQL was generated, making it the most reliable mitigation for the scenario.

  • ✗

    Log all generated SQL statements and alert the security team when destructive keywords appear.

    Why it's wrong here

    Logging and alerting are detective controls that trigger after the statement may have executed. They do not prevent the destructive action. The scenario requires prevention of DROP TABLE, and detection alone leaves the database already damaged. This option is useful for monitoring but does not provide the strongest guarantee.

About these practice questions

Courseiva writes every CCDV-F question from scratch — 257 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.