Anthropic CCDV-F Exam Prep
Claude Certified Developer - Foundations (Page 2 )

Updated On: 3-Oct-2026

Your team is building a multi-step document processing application that needs to extract structured data from PDFs, validate the extracted content against business rules, and then route documents to different approval workflows based on content type. You are evaluating whether to use an agent or a workflow architecture.
Which of the following factors should most strongly influence your decision toward using an agent rather than a workflow?

  1. The approval routing requires dynamic decision-making based on unpredictable document variations and emerging patterns that were not pre-defined in the system
  2. The extraction, validation, and routing steps are deterministic and always follow the same sequence regardless of document content
  3. The application needs to maintain strict audit compliance and every action must be explicitly logged and repeatable
  4. The team prefers working with declarative, step-by-step orchestration that clearly maps each stage in the document pipeline
  5. The PDF processing step is computationally expensive and should be cached and reused across multiple documents

Answer(s): A

Explanation:

Agents excel at handling dynamic, unpredictable scenarios where the system must adapt its behavior based on emerging patterns and make autonomous decisions. In this scenario, the need for dynamic routing based on document variations that weren't pre-defined is a key indicator that an agent's iterative decision-making loop would be more appropriate than a rigid workflow.
The other options point toward workflow characteristics: deterministic sequences (workflows), strict audit requirements (workflows provide better determinism and traceability), declarative step-by-step orchestration (workflows by design), and caching concerns (an optimization orthogonal to the agent vs. workflow choice). Agents are more flexible but less predictable and auditable, while workflows provide explicit control and repeatability.



You are implementing a Claude agent using a custom agent loop that needs to call external APIs, process tool outputs, and make decisions about when to stop iterating. Your team wants to ensure that certain high-risk actions—such as deleting records or transferring funds—always require explicit human approval before execution.
Which combination of approaches best implements this safety requirement within a Claude agent architecture?

  1. Use Claude hooks to intercept tool calls and pause execution before high-risk actions, combined with an approval tool that blocks further execution until a human reviews and approves the pending action
  2. Configure the system prompt to instruct Claude to never call deletion or transfer tools, and rely on the model's instruction-following to prevent these actions
  3. Remove high-risk tools from the agent's tool set entirely and only expose them through a separate, manually-triggered admin interface
  4. Log all tool calls and review the logs after the agent completes execution to ensure no dangerous actions were taken
  5. Use a sub-agent hierarchy where high-risk actions are delegated to a supervisor agent that evaluates requests before passing them to execution agents

Answer(s): A

Explanation:

Claude hooks provide a mechanism to intercept and modify agent behavior at runtime, making them ideal for implementing deterministic safety controls. Combining hooks with an approval tool ensures that high-risk actions are paused, visible to a human, and only proceed with explicit approval. This is a best-practice pattern for guardrails in agentic systems.
Relying on system prompt instructions alone is insufficient because models can be misled or jailbroken. Removing tools entirely eliminates functionality. Post-execution logging is a detective control, not preventive. Sub-agent hierarchies add organizational structure but don't inherently prevent the supervisor from approving dangerous actions without additional approval logic—hooks provide that deterministic enforcement layer.



Your team is optimizing the cost of a Claude application that makes thousands of API calls daily to process customer support tickets. The tickets often reference common company policies and product information that rarely changes. You have identified that about 40% of tokens in each request are spent transmitting this stable reference material.
Which of the following techniques would most effectively reduce costs in this scenario, and what is the primary reason?

  1. Use prompt caching to store the common policy and product reference material, because the cache will persist across multiple API calls and avoid re-transmitting the same tokens
  2. Switch from the Sonnet model to the Haiku model, because Haiku has lower per-token costs and will proportionally reduce the cost of transmitting reference material
  3. Implement batch processing for all ticket requests, because batch API calls are charged at a 50% discount regardless of token content
  4. Reduce the context window by truncating policy documents to essential summaries, because smaller context windows always cost less per request
  5. Migrate to a retrieval-augmented generation (RAG) system that fetches policies from a vector database instead of including them in prompts

Answer(s): A

Explanation:

Prompt caching is specifically designed to address this cost optimization scenario: when the same prefix of tokens appears repeatedly across requests, Claude stores a cached version and charges a significantly reduced rate (90% discount) for cache hits. With 40% of tokens being stable reference material, caching directly targets the waste and provides immediate cost savings across those thousands of daily calls.
Model switching (Haiku) reduces per-token cost but still charges full price for each token transmitted, including the reference material. Batch processing offers discount only when latency is not a concern and doesn't solve the repeated transmission problem. Truncating context either loses important information or requires sophisticated summarization logic. RAG is a valid architectural alternative but introduces database infrastructure, latency, and complexity; it's not a simple optimization for the existing prompt-based approach.



MULTIPLE CHOICE
Your Claude application needs to validate user input before sending it to the Claude API to prevent prompt injection attacks. You are designing input sanitization logic and have identified that users will provide unstructured text from various sources, including customer feedback, external emails, and user-uploaded documents.
Which of the following strategies should be part of your defense-in-depth approach? (Select all that apply.)

  1. Remove or escape special characters and delimiters that could be used to signal instruction boundaries or break out of user-content sections
  2. Validate that user input conforms to a strict whitelist of allowed characters, reducing attack surface but potentially limiting legitimate input
  3. Trust Claude's built-in safety measures to filter injection attempts, so that custom sanitization logic is unnecessary
  4. Apply role-based access controls to limit which users can submit input, combined with audit logging to track who submitted potentially malicious content
  5. Implement a machine learning classifier to detect injection patterns and block suspicious inputs before they reach Claude

Answer(s): A,B,D

Explanation:

Effective prompt injection defense requires multiple layers. Character filtering/escaping (option 1) prevents attackers from using structural delimiters.
Whitelisting (option 2) is stricter than blacklisting and reduces the attack surface, though it may constrain legitimate use cases. Role-based access control (option 4) is part of the defense-in-depth principle—limiting who can submit input and auditing submissions ensures accountability and reduces attack vectors.
Option 3 is incorrect because Claude's safety measures are content filters for output, not input validation, and they cannot be relied upon as the sole defense against prompt injection. Option 5 (ML classifiers) is not a standard recommendation for prompt injection defense because injection attacks often mimic legitimate instructions, making ML detection unreliable and adding latency without deterministic guarantees. The best approach combines explicit input validation at the application layer (sanitization, whitelisting) with identity and access controls.



You are building a Claude application that uses an MCP server to connect to a company's internal database and expose a set of tools for querying customer records. The MCP server runs as a separate process and communicates with your Claude application over stdio. During testing, you notice that database queries occasionally fail due to network timeouts or database unavailability.
Which of the following error handling and recovery strategies should be implemented at the tool level to ensure the agent can respond gracefully?

  1. Implement try-catch logic within the MCP server tool implementation to catch timeout exceptions, return descriptive error messages to Claude, and let Claude decide whether to retry, use cached data, or inform the user
  2. Configure the stdio communication channel with automatic exponential backoff retries, so that failed tool calls are retried automatically without Claude's involvement
  3. Have the MCP server implement circuit breaker logic that blocks all database queries for 10 minutes after the first timeout, preventing cascading failures
  4. Implement timeout handling exclusively in Claude's system prompt, instructing the model to wait longer before concluding a query has failed
  5. Remove the MCP server entirely and hardcode database connection strings directly into the Claude application for lower latency and fewer failure points

Answer(s): A

Explanation:

The correct approach is to handle errors at the tool layer where context about the failure is available. The MCP server tool should catch exceptions, return structured error information to Claude, and allow Claude's agentic logic to decide the best recovery strategy (retry with different parameters, use cached results, or inform the user). This maintains the separation of concerns and gives the agent visibility into what went wrong.
Automatic stdio retries without Claude awareness can cause unexpected delays and duplicate operations. Circuit breaker logic (option 3) prevents cascading failures but is typically implemented at infrastructure layers, not at the tool level, and a fixed 10-minute block may be overly aggressive. System prompt instructions (option 4) cannot reliably enforce timeouts or retry logic—the model cannot control socket-level behavior. Hardcoding connection strings (option 5) introduces security risks and tight coupling; tools are designed to abstract external system details.



Viewing page 2 of 22
Viewing questions 6 - 10 out of 103 questions


Post your Comments and Discuss Anthropic CCDV-F exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!