Prompt injection
Untrusted content attempts to influence instructions or behavior.
Exam context: It can cause unauthorized actions or disclosure. When: Processing user input or external content. When not: Trusted application instructions that your system controls.
See also: 7.1 AI Application Security
Jailbreak
An attempt to bypass model or application safety constraints.
Exam context: It can produce unsafe or unauthorized behavior. When: Users intentionally try to circumvent restrictions. When not: Normal requests that follow the application's rules.
See also: 7.1 AI Application Security
Least privilege
Giving a user, service, or tool only the permissions it needs.
Exam context: Limits the impact of compromised or incorrect behavior. When: Designing authentication and tool access. When not: Never grant broad access simply for convenience.
See also: 7.1 AI Application Security
Layered guardrails
Multiple safety controls applied at different stages of an application.
Exam context: A single failed control should not expose the system. When: Designing safety-critical Claude applications. When not: Do not rely only on model instructions.
See also: 7.2 Guardrails and Safe Deployment
Least privilege
Giving identities and tools only the permissions they require.
Exam context: Limits potential damage from errors or compromise. When: Granting access to tools, APIs, and data. When not: Avoid broad permissions for convenience.
See also: 7.2 Guardrails and Safe Deployment
Secure by design
Building security and privacy controls into the architecture.
Exam context: Security is harder to add reliably after deployment. When: Designing and deploying Claude applications. When not: Do not treat security as only a deployment checklist.
See also: 7.2 Guardrails and Safe Deployment
Hook
An application control point that can inspect or enforce behavior around Claude activity.
Exam context: It provides deterministic enforcement for important rules. When: Before sensitive or potentially destructive actions. When not: Do not rely on hooks as the only security mechanism.
See also: 7.3 Claude Hooks
Pre-action validation
Checking whether an action is allowed before executing it.
Exam context: Prevents invalid or unauthorized operations. When: Sensitive tool calls and destructive operations. When not: Do not skip authorization because a model requested the action.
See also: 7.3 Claude Hooks
Destructive action
An operation that can delete, modify, or otherwise cause significant external impact.
Exam context: Mistakes can create irreversible consequences. When: Deleting data or changing important resources. When not: Low-impact read-only operations generally need less enforcement.
See also: 7.3 Claude Hooks
Authentication
Verifying the identity of a user or service.
Exam context: Protected resources should only be accessed by verified identities. When: Before granting access to protected resources. When not: Authentication alone does not determine permissions.
Authorization
Determining what an authenticated identity is allowed to access or perform.
Exam context: Prevents users and services from exceeding their permissions. When: Before protected actions and resource access. When not: Do not confuse authorization with identity verification.
Secret
Sensitive credential material such as an API key, password, or access token.
Exam context: Exposure can allow unauthorized access. When: Whenever credentials are stored, transmitted, or used. When not: Do not place secrets in source code or public configuration.
Least privilege
Giving an identity only the permissions required for its task.
Exam context: Limits the impact of compromised credentials or mistakes. When: Designing access to Claude tools and external systems. When not: Avoid broad permissions simply for convenience.