CCDV-F objective 7.1 · Domain 7 · 8.1% of the exam
AI Application Security
Two threat models worth separating: the user as adversary, and a trusted user with content that somebody else wrote. Most items are the second. Third-party text belongs in a tool result, which is the channel the model reads with suspicion, and your own instruction goes in the turn after it rather than inside the payload. Authenticating a connection establishes who is speaking and says nothing about whether what they said carries authority. Paths and commands the model produces are untrusted input to your code.
8 questions · answers and explanations shown as you go · free, no sign-up
The rest of domain 7: Security and Safety
This domain is 8.1% of a scored form, about 4 of the 53, spread across 4 objectives. Drill the whole domain or pick another objective below.
One objective is a narrow slice. A full-length timed mock is what tells you whether the whole thing holds together.
Sit a timed mock →