CCDV-F Deep Dive 20/25: AI Application Security (Domain 7, 3.2%) | Claude Certified Developer
Core Concept Learning
0:00 / 0:00
CCDV-F Deep Dive 20/25: AI Application Security (Domain 7, 3.2%) | Claude Certified Developer
6 просмотров · 3 дн. назад
Core Concept Learning
48 подписчиков
6 просмотров · 3 дн. назад
AI Application Security explained for the CCDV-F exam: treat everything the model reads and writes as untrusted, deliver third-party content only inside tool results, enforce security in code rather than in the system prompt, give the agent least privilege so a successful injection does little harm, check authentication and authorisation before any tool runs, and protect personal data with minimisation, redaction, and the right retention and residency settings.
AI Application Security carries 3.2% of the Claude Certified Developer Foundations (CCDV-F) exam weight, in Domain 7: Security and Safety (8.1%).
This exam-prep deep dive is for developers preparing for the Claude Certified Developer Foundations (CCDV-F) exam who want more than the short AI Application Security lesson. It covers the trust boundary, the two threat models (jailbreaks and direct prompt injection versus indirect prompt injection), defences against a hostile user, structuring untrusted content in tool results, JSON encoding, where your own instructions belong, screening tool output, least privilege in Claude Code and the Agent SDK, authentication and authorisation, data leakage, PII handling with retention and residency, and mapping confidentiality, privacy and integrity to controls. It is an independent study video, not official Anthropic material, and the practice questions are original.
What you will learn:
• Why a system prompt is advice, not enforcement, and where the trust boundary sits
• Jailbreaks and direct injection versus indirect prompt injection
• Harmlessness screens, input validation, refusal rules, and repeat offenders
• Why untrusted content belongs in tool results, labelled and JSON-encoded
• Where your own instructions go, and the tool_result ordering rules
• Screening tool output with a small classifier before Claude acts on it
• Least privilege, sandboxing, and deny-first permission rules
• Authentication, authorisation, data leakage, PII, retention, and residency
CHAPTERS
00:00 AI Application Security deep dive for the CCDV-F exam
00:48 The trust boundary: a system prompt is advice, code is enforcement
01:36 Jailbreaks and direct prompt injection versus indirect prompt injection
02:22 Jailbreak defence: harmlessness screens, input validation, refusal rules
03:12 Indirect prompt injection: untrusted content only in tool results
04:04 JSON-encode untrusted text; keep your instructions out of tool results
04:53 Screening tool output for prompt injection with a small classifier
05:38 Least privilege, sandboxing, and deny-first permission rules
06:28 Authentication and authorisation before any tool runs
07:16 Data leakage prevention: context, outbound paths, output filtering
08:06 PII handling: minimise, redact, data retention and data residency
08:57 Confidentiality, privacy, integrity and authorisation mapped to controls
09:53 Defence in depth, red-teaming, monitoring, and why model choice is not a control
10:44 Practice questions and answers: AI Application Security
CCDV-F deep-dive series: video 20 of 25. Each deep dive goes further than the matching short lesson in the CCDV-F full course; watch that lesson first if the topic is new.
Previous: CCDV-F Deep Dive 19/25, MCP Server Development: • CCDV-F Deep Dive 19/25: MCP Server Develop...
Go deeper on this channel:
CCDV-F 20/25: AI Application Security (Domain 7, 3.2%) | Claude Certified Developer Foundations: • CCDV-F 20/25: AI Application Security (Dom...
Exam format: 53 multiple-choice and multiple-response questions, 120 minutes, pass mark 720 of 1000 (scaled). Weights and format come from third-party summaries of Anthropic's CCDV-F Exam Guide v1.0 (July 2026); confirm them against Anthropic's official guide before you sit the exam.
Subscribe to Core Concept Learning for clear, visual explanations of AI and software engineering concepts.
#CCDVF #ClaudeCertifiedDeveloper #AISecurity