Перейти к содержимому

CCDV-F Deep Dive 20/25: AI Application Security (Domain 7, 3.2%) | Claude Certified Developer

Core Concept Learning

0:00 / 0:00

CCDV-F Deep Dive 20/25: AI Application Security (Domain 7, 3.2%) | Claude Certified Developer

6 просмотров · 3 дн. назад
Core Concept Learning
48 подписчиков
6 просмотров · 3 дн. назад
AI Application Security explained for the CCDV-F exam: treat everything the model reads and writes as untrusted, deliver third-party content only inside tool results, enforce security in code rather than in the system prompt, give the agent least privilege so a successful injection does little harm, check authentication and authorisation before any tool runs, and protect personal data with minimisation, redaction, and the right retention and residency settings. AI Application Security carries 3.2% of the Claude Certified Developer Foundations (CCDV-F) exam weight, in Domain 7: Security and Safety (8.1%). This exam-prep deep dive is for developers preparing for the Claude Certified Developer Foundations (CCDV-F) exam who want more than the short AI Application Security lesson. It covers the trust boundary, the two threat models (jailbreaks and direct prompt injection versus indirect prompt injection), defences against a hostile user, structuring untrusted content in tool results, JSON encoding, where your own instructions belong, screening tool output, least privilege in Claude Code and the Agent SDK, authentication and authorisation, data leakage, PII handling with retention and residency, and mapping confidentiality, privacy and integrity to controls. It is an independent study video, not official Anthropic material, and the practice questions are original. What you will learn: • Why a system prompt is advice, not enforcement, and where the trust boundary sits • Jailbreaks and direct injection versus indirect prompt injection • Harmlessness screens, input validation, refusal rules, and repeat offenders • Why untrusted content belongs in tool results, labelled and JSON-encoded • Where your own instructions go, and the tool_result ordering rules • Screening tool output with a small classifier before Claude acts on it • Least privilege, sandboxing, and deny-first permission rules • Authentication, authorisation, data leakage, PII, retention, and residency CHAPTERS 00:00 AI Application Security deep dive for the CCDV-F exam 00:48 The trust boundary: a system prompt is advice, code is enforcement 01:36 Jailbreaks and direct prompt injection versus indirect prompt injection 02:22 Jailbreak defence: harmlessness screens, input validation, refusal rules 03:12 Indirect prompt injection: untrusted content only in tool results 04:04 JSON-encode untrusted text; keep your instructions out of tool results 04:53 Screening tool output for prompt injection with a small classifier 05:38 Least privilege, sandboxing, and deny-first permission rules 06:28 Authentication and authorisation before any tool runs 07:16 Data leakage prevention: context, outbound paths, output filtering 08:06 PII handling: minimise, redact, data retention and data residency 08:57 Confidentiality, privacy, integrity and authorisation mapped to controls 09:53 Defence in depth, red-teaming, monitoring, and why model choice is not a control 10:44 Practice questions and answers: AI Application Security CCDV-F deep-dive series: video 20 of 25. Each deep dive goes further than the matching short lesson in the CCDV-F full course; watch that lesson first if the topic is new. Previous: CCDV-F Deep Dive 19/25, MCP Server Development:    • CCDV-F Deep Dive 19/25: MCP Server Develop...   Go deeper on this channel: CCDV-F 20/25: AI Application Security (Domain 7, 3.2%) | Claude Certified Developer Foundations:    • CCDV-F 20/25: AI Application Security (Dom...   Exam format: 53 multiple-choice and multiple-response questions, 120 minutes, pass mark 720 of 1000 (scaled). Weights and format come from third-party summaries of Anthropic's CCDV-F Exam Guide v1.0 (July 2026); confirm them against Anthropic's official guide before you sit the exam. Subscribe to Core Concept Learning for clear, visual explanations of AI and software engineering concepts. #CCDVF #ClaudeCertifiedDeveloper #AISecurity