CCDV-F · Study Guide

Domain 79.0%

Glossary: Security and Safety

Definitions for this domain, taken from its topic pages. Follow the topic link for the full lesson.

Prompt injection

Untrusted content attempts to influence instructions or behavior.

Exam context: It can cause unauthorized actions or disclosure. When: Processing user input or external content. When not: Trusted application instructions that your system controls.

See also: 7.1 AI Application Security

Jailbreak

An attempt to bypass model or application safety constraints.

Exam context: It can produce unsafe or unauthorized behavior. When: Users intentionally try to circumvent restrictions. When not: Normal requests that follow the application's rules.

See also: 7.1 AI Application Security

Least privilege

Giving a user, service, or tool only the permissions it needs.

Exam context: Limits the impact of compromised or incorrect behavior. When: Designing authentication and tool access. When not: Never grant broad access simply for convenience.

See also: 7.1 AI Application Security

Layered guardrails

Multiple safety controls applied at different stages of an application.

Exam context: A single failed control should not expose the system. When: Designing safety-critical Claude applications. When not: Do not rely only on model instructions.

See also: 7.2 Guardrails and Safe Deployment

Least privilege

Giving identities and tools only the permissions they require.

Exam context: Limits potential damage from errors or compromise. When: Granting access to tools, APIs, and data. When not: Avoid broad permissions for convenience.

See also: 7.2 Guardrails and Safe Deployment

Secure by design

Building security and privacy controls into the architecture.

Exam context: Security is harder to add reliably after deployment. When: Designing and deploying Claude applications. When not: Do not treat security as only a deployment checklist.

See also: 7.2 Guardrails and Safe Deployment

Hook

An application control point that can inspect or enforce behavior around Claude activity.

Exam context: It provides deterministic enforcement for important rules. When: Before sensitive or potentially destructive actions. When not: Do not rely on hooks as the only security mechanism.

See also: 7.3 Claude Hooks

Pre-action validation

Checking whether an action is allowed before executing it.

Exam context: Prevents invalid or unauthorized operations. When: Sensitive tool calls and destructive operations. When not: Do not skip authorization because a model requested the action.

See also: 7.3 Claude Hooks

Destructive action

An operation that can delete, modify, or otherwise cause significant external impact.

Exam context: Mistakes can create irreversible consequences. When: Deleting data or changing important resources. When not: Low-impact read-only operations generally need less enforcement.

See also: 7.3 Claude Hooks

Authentication

Verifying the identity of a user or service.

Exam context: Protected resources should only be accessed by verified identities. When: Before granting access to protected resources. When not: Authentication alone does not determine permissions.

See also: 7.4 Identity, Secrets, and Key Management

Authorization

Determining what an authenticated identity is allowed to access or perform.

Exam context: Prevents users and services from exceeding their permissions. When: Before protected actions and resource access. When not: Do not confuse authorization with identity verification.

See also: 7.4 Identity, Secrets, and Key Management

Secret

Sensitive credential material such as an API key, password, or access token.

Exam context: Exposure can allow unauthorized access. When: Whenever credentials are stored, transmitted, or used. When not: Do not place secrets in source code or public configuration.

See also: 7.4 Identity, Secrets, and Key Management

Least privilege

Giving an identity only the permissions required for its task.

Exam context: Limits the impact of compromised credentials or mistakes. When: Designing access to Claude tools and external systems. When not: Avoid broad permissions simply for convenience.

See also: 7.4 Identity, Secrets, and Key Management