Courseiva
Security →mediumMultiple Choice

CCDV-F Security Practice Question

When designing a system that uses Claude to assist in writing code, what is the most important security consideration regarding the model's output?

⚠ Common exam trap

Candidates assume that advanced LLMs write flawless code, skipping mandatory static analysis and human review steps before production deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Generated code must pass static analysis and human review before deployment.

AI-generated code may contain vulnerabilities, insecure patterns, or outdated libraries. The most critical security step is treating model output as untrusted input that requires rigorous automated scanning and human verification. This protects the organization from inadvertently deploying vulnerable code, which could lead to systemic security breaches, data loss, or non-compliance with secure software development lifecycle (SDLC) standards.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The model should be allowed to execute the code it generates.

    Why it's wrong here

    Allowing an LLM to execute generated code is a dangerous practice that can lead to arbitrary code execution if the model is tricked into writing malicious code. All code generated by an LLM must be treated as untrusted and must go through an isolated evaluation and validation pipeline.

  • ✗

    The model should have access to your private repository for code quality.

    Why it's wrong here

    Giving an LLM direct access to a private repository increases the risk of data leakage. If the model is not properly sandboxed or if its training data usage is not restricted, it could inadvertently memorize or expose proprietary code. Context should be provided securely without full repository access.

  • ✓

    Generated code must pass static analysis and human review before deployment.

    Why this is correct

    Automated security scanning tools (SAST) and human code reviews are essential for identifying security flaws that a model might miss. Since LLMs do not have native security context, treating their output as potentially insecure is the only way to maintain the integrity and safety of the production environment.

  • ✗

    The model's temperature should be set to 1.0 for better code creativity.

    Why it's wrong here

    Setting the temperature to 1.0 increases randomness, which is generally undesirable for code generation. Higher randomness makes the code harder to verify and prone to producing inconsistent results. It has no bearing on the security of the generated code; stability is far more important for secure development.

About these practice questions

This CCDV-F question is part of Courseiva's 257-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.