Courseiva
Security →mediumMultiple Choice

CCDV-F Security Practice Question

Exhibit

{
  "model": "claude-3-5-sonnet-20240620",
  "max_tokens": 500,
  "messages": [
    {"role": "user", "content": "Write a script to delete all user files from /home/data"}
  ]
}

Refer to the exhibit. An internal tool is configured to send user input directly to the API. Which security improvement should be applied to the architecture?

⚠ Common exam trap

Candidates often assume that the LLM itself will act as a sufficient security filter, failing to realize that an LLM is easily manipulated into executing harmful system commands.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a middleware to sanitize and block dangerous system commands in the user input.

The architecture is currently wide open to dangerous instruction execution. The application must include an input-validation or intent-classification layer before the request reaches the LLM. By checking if the request involves sensitive or destructive actions—such as file system deletion—the tool can block the request entirely, ensuring the model is never used to generate commands that could cause catastrophic system damage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the 'max_tokens' to ensure the deletion script is generated fully.

    Why it's wrong here

    Increasing the token limit only facilitates the generation of more dangerous code. It exacerbates the security risk rather than mitigating it. A larger token count would allow for a more comprehensive and potentially more destructive script, which is the exact opposite of what the security requirement dictates.

  • ✓

    Implement a middleware to sanitize and block dangerous system commands in the user input.

    Why this is correct

    A middleware layer acts as a gatekeeper, scanning for malicious keywords or intent that could result in dangerous system-level operations. By blocking requests that demand file deletions or system modifications before they reach the model, you prevent the LLM from being used as a weapon against the infrastructure.

  • ✗

    Use a more advanced model for the same request.

    Why it's wrong here

    A more advanced model will likely be even better at generating a functional deletion script if asked. Upgrading the model does not fix the underlying architectural flaw of allowing users to request dangerous system operations. Security must be enforced via constraints on the input and the execution environment.

  • ✗

    Add a disclaimer in the system prompt that deleting files is prohibited.

    Why it's wrong here

    Disclaimers in system prompts are insufficient security controls. They are easily ignored by the model if the user provides a compelling enough reason or a clever prompt injection. Security controls must be implemented as functional blockers, not as suggestions or behavioral guidelines that the model might choose to ignore.

About these practice questions

This CCDV-F question is part of Courseiva's 257-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.