Home › Study guides › CCDV-F › Domain 7
CCDV-F · Domain 7 of 8 · 4 lessons · about 87 min
Domain 7: Security and Safety
Securing Claude apps: prompt injection and untrusted input, guardrails and least privilege, hooks as controls, and secrets management. 8.1% of CCDV-F.
This domain is 8.1% of CCDV-F, about 4 of the 53 questions. Every question in it turns on the same distinction: what the model is asked to do versus what the application enforces.
The vocabulary: prompt injection is untrusted content, such as a web page or an email, carrying instructions aimed at the model. A guardrail is a check around the model that limits what goes in or comes out. Least privilege means giving each component only the access it needs. A secret is a credential, such as an API key, that must never appear in code, prompts or logs.
The recurring test: enforce, don't ask. The official sample question has the pattern: keep untrusted content apart from trusted instructions and put limits in code or hooks so injected text cannot trigger sensitive actions. A polite line in the system prompt, a different temperature or a bigger model are the distractors.
What the exam guide tests
The official CCDV-F guide lists 4 skills for this domain. Exam questions are written against them, and so are the lessons: each row says where it is covered.
| # | Skill | Lesson |
|---|---|---|
| 7.1 | AI Application Security (3.2%) | 7.1 |
| 7.2 | Guardrails and Safe Deployment (2.3%) | 7.2 |
| 7.3 | Claude Hooks (1.0%) | 7.3 |
| 7.4 | Identity, Secrets, and Key Management (1.6%) | 7.4 |
Lessons
- 7.1 Securing a Claude application: injection, untrusted input and data leaksHow prompt injection and jailbreaks reach a Claude app, why your code must enforce access, and how to stop system prompt, cross-user and PII leaks.23 min
- 7.2 Safe deployment: layered guardrails and least privilegeHow to turn a content policy into layered checks around Claude, and why the bot, its tools and its service accounts get only the access their job needs.22 min
- 7.3 Hooks as safety controls: stopping destructive actions before they runHow PreToolUse hooks block or hold destructive commands for approval in Claude Code and the Agent SDK, what PostToolUse can check, and where hooks stop.21 min
- 7.4 Secrets and key management: API keys, identity and accessWhy a leaked API key is a live credit card, and how to store, scope, rotate and monitor Claude credentials and verify who is calling your app.21 min
Practice question
From the CCDV-F bank, tagged to this domain. Every answer option is explained. Nothing is stored, nothing to sign up for.
12 CCDV-F questions on this domain, free
The domain quiz in the question bank draws 10 random questions from the 12 tagged to Security and Safety, scores them and explains every option. Repeat it until the weak spots are gone, then sit the 53-question timed simulator.
Open the CCDV-F question bank → Start lesson 7.1 →
The question bank is free. It asks for an account only because the quiz engine has to store answers to score them and show which domains are weak. The questions on this page need nothing.