Courseiva
Security →hardMultiple Choice

CCDV-F Security Practice Question

Your organization is integrating Claude for sensitive internal human resources queries. What is the most effective way to ensure the model does not reveal employee salary information?

⚠ Common exam trap

Candidates frequently suggest prompt-based restrictions, which are easily bypassed by jailbreaking or indirect prompt injection, rather than using secure middleware to filter data before it reaches the model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a data-masking middleware that filters sensitive fields from the retrieved context.

The most secure way to prevent sensitive data disclosure is to prevent the model from ever 'seeing' that data during the generation phase. By implementing a logic layer that filters the information based on the user's identity before it reaches the model, you ensure that the model is only provided with authorized context. This prevents the model from acting as an unauthorized channel for sensitive PII or payroll data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Instruct the model in the system prompt to never discuss salaries.

    Why it's wrong here

    Relying on system prompts to enforce privacy is insufficient. A skilled attacker or a subtle prompt injection can easily bypass these instructions. System prompts should be used for behavioral guidelines, not as the primary control mechanism for enforcing data access policies in an enterprise environment.

  • ✓

    Implement a data-masking middleware that filters sensitive fields from the retrieved context.

    Why this is correct

    This approach enforces security at the data layer, ensuring that the LLM is never presented with salary information in the first place. By stripping sensitive fields from the context before it is passed to the Claude API, you guarantee that even if the model is compromised, it cannot reveal the data.

  • ✗

    Require the model to perform a sanity check on its own output for PII.

    Why it's wrong here

    Asking the model to self-regulate is unreliable. The model might miss the PII or be convinced by a user to ignore its own safety check. Automated security controls should always be external to the generative process, ensuring consistent enforcement that cannot be bypassed by clever user instructions.

  • ✗

    Encrypt all employee salaries using a salt and hash.

    Why it's wrong here

    Hashing salaries makes them useless for the model to perform any meaningful analysis or comparison. If the model cannot read the data, it cannot process the query. Furthermore, if the model needs to perform math or analysis, it would require the plaintext, defeating the purpose of the hashing.

About these practice questions

One of 257 original CCDV-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.