CCAR Prep

Objective 3.2 · Domain 3 · 19% of the exam

Analyze authentication and authorization requirements to identify security gaps

Authentication and authorisation across an agentic system: whose identity a tool call runs as, how credentials reach the tool, and where privilege can escalate. The recurring gap is an agent holding a single service credential broad enough to act for any user, which turns a prompt injection into a data breach. Look for answers that carry the end user's authority through to the tool and scope it down, and be suspicious of any that trust the model to restrict itself.

5 questions · answers and explanations shown as you go · free, no sign-up

The rest of domain 3: Integration

This domain is 19% of a scored form, about 12 of the 63 questions, spread across 8 objectives. Drill the whole domain or pick another objective below.

One objective is a narrow slice. A full-length timed mock is what tells you whether the whole thing holds together.

Sit a timed mock →