CCDV-F objective 7.2 · Domain 7 · 8.1% of the exam
Guardrails and Safe Deployment
Where a rule is enforced decides whether it holds. Permission rules evaluate deny, then ask, then allow, and the first match settles the question, so a narrow allow written underneath a broad deny is never reached at all. Begin from denied and opt in, because a configuration that subtracts from everything cannot exclude a capability that did not exist when it was written. Gate on reversibility rather than importance, and note that gating is possible only where the harness can see what is happening.
7 questions · answers and explanations shown as you go · free, no sign-up
The rest of domain 7: Security and Safety
This domain is 8.1% of a scored form, about 4 of the 53, spread across 4 objectives. Drill the whole domain or pick another objective below.
One objective is a narrow slice. A full-length timed mock is what tells you whether the whole thing holds together.
Sit a timed mock →