Claude Certification Blog

Security and safety: four items, and the smallest skill on any Claude blueprint

Security is a named domain on exactly one of the four Claude blueprints, it is worth four items there, and it contains the smallest skill weight published anywhere in the programme.

8.1% domainFour skillsOne worth 1.0%

7 min read

Security and Safety is 8.1% of CCDV-F — about 4 of 53 items — across four published skills: AI Application Security at 3.2%, Guardrails and Safe Deployment at 2.3%, Identity, Secrets and Key Management at 1.6%, and Claude Hooks at 1.0%. It is the only domain on any of the four Claude blueprints that is named for security, and the last of those four skills is the smallest published weight in the programme.

8.1%the whole domain
4of 53 items
1.0%the smallest skill
~10minutes budgeted

Four items, four skills

Four skills, and the last one is worth half an itemSHARE OF A 53-ITEM PAPERAI Application Security3.2%Guardrails and Safe Deployment2.3%Identity, Secrets and Keys1.6%Claude Hooks1.0%
The whole domain is four items. The gap between its largest and smallest skill is more than three to one, which is why a plan whose smallest unit is the domain is too coarse to act on here.
SkillWeightWhat it covers
AI Application Security3.2%Who wrote the text, and what that licenses it to do
Guardrails and Safe Deployment2.3%Which layer an authorisation is enforced at
Identity, Secrets and Keys1.6%Scope granted, and what never enters the context
Claude Hooks1.0%Half an item, on average, across the whole paper

The only exam that names it

Search the objective titles of all four blueprints for security, safety, guardrails, risk, secrets or injection and the results are lopsided. CCDV-F returns three, all inside this one domain. CCAR-P returns five, scattered over prompting, integration, evaluation and its governance domain. CCAO-F returns exactly one, about following organisational policy. CCAR-F returns none.

Security is a domain on one blueprint and absent from anotherWHERE SECURITY LIVESCCDV-FA named domain, 8.1%CCAR-PInside four domainsCCAO-FOne objectiveCCAR-FNot named at all
Four blueprints, four different answers to the same question. The architect foundations exam does not name the subject in a single objective.

That is not a claim that the architect exam ignores safety in practice, and it is not an argument about what a syllabus ought to contain. It is a scoping fact with a study consequence: reading a security chapter written for one track and assuming it is examinable on another is how candidates spend evenings on weight that is not there. The full picture of what each blueprint weighs is in Claude certification domain weights.

The one percent skill

Claude Hooks is published at 1.0%. CCDV-F is the only one of the four exams that publishes a weight for every skill rather than only for each domain, so this is also the smallest number anyone can quote about any Claude exam. On 53 items it averages to half an item, which means a given form may carry one, or may carry none at all.

The correct response to that is neither to skip it nor to study it. Learn what a hook is and where it sits relative to a model call — that it fires around the call rather than inside the model's reasoning, and that this is what makes it a place to put a rule you do not want negotiated. Ten minutes. If an item appears you will recognise it; if none does you have lost nothing.

The smallest weights are where over-study is cheapest to fix

A skill at 1.0% is not a trap, it is a budget instruction. The published figures exist precisely so that you can decide what deserves an evening, and the two lightest domains on this paper together carry three items. Time moved from them to Applications and Integration is the highest-return trade available on CCDV-F.

Where a guardrail has to live

Guardrails and Safe Deployment is 2.3%, and almost everything examinable about it reduces to one question: at which layer is the rule enforced? A constraint expressed in prompt wording is a request. The same constraint expressed as a schema, an allowlist, or a check that runs before the call is made is a boundary. Both read as responsible. Only one of them holds when the model is wrong.

This is why the plausible distractor in this domain is so often a well-written instruction. It is the answer that sounds like care, and it fails on the specific occasion it was written for — the model that misreads its own system prompt. The distinction generalises well past this domain, and the working version of it, including how injection changes the picture, is in prompt injection and guardrails on the Claude exams.

The other half of the pairing is failure reporting. A tool that fails and returns nothing hands the model an empty result it has no reason to distrust; a tool that fails and says so hands it a fact. On an exam that repeatedly asks what a system should do when something goes wrong, silence is almost never the credited answer.

Identity is decided on paper

Identity, Secrets and Key Management is 1.6%, and it is the most misread skill in the domain, because the name sounds operational and the examinable content is not. Nothing here asks you to configure a vault. It asks what scope an agent's identity should have been granted before it ran, and what should never have been inside its context in the first place.

Both of those are decisions made at design time, and both have the same shape as an answer: the smallest access that lets the task complete, and a credential that expires rather than one that sits in a file. A secret that reaches the model has already reached the logs, the traces and any summary of the conversation — which is a reason to keep it out, not a reason to redact it later.

How to spend four items

One evening, and the exam's own timing table agrees: it budgets about ten minutes of the 120 for this domain. Start with the injection classification, because it is the largest skill at 3.2% and the distinction it turns on — whether the hostile text came from the person or from something the system fetched — decides the defence rather than decorating it.

Then the enforcement-layer question, which is the highest-transfer idea in the domain and reappears wherever the paper asks how an action gets authorised. Then twenty minutes on identity and secrets, aimed at scope rather than mechanism. Then ten on hooks, aimed at recognition only.

And then stop, and put the recovered time into Applications and Integration, which is 33.1% of the same paper. Security reads as the serious subject and it is four items; the sequencing argument for all eight domains is in our Claude certification study guide, and the neighbouring domains are covered in prompt and context engineering and tools and MCPs.

Key takeaways

  • Eight percent, four items, four skills. Application security 3.2%, guardrails 2.3%, identity and secrets 1.6%, hooks 1.0%.
  • Only CCDV-F names it as a domain. CCAR-P spreads it across four, CCAO-F has one objective, CCAR-F has none.
  • Claude Hooks is 1.0%. The smallest published weight in the programme — half an item, so recognise it rather than study it.
  • Classify the injection before defending it. Direct means the person is hostile; indirect means the content is.
  • Wording requests, code constrains. The credited answer usually moves the rule to a layer the model cannot talk its way past.
  • Identity is a design decision. Least scope granted up front, and secrets kept out of context rather than redacted after.

The most serious-sounding domain on the paper is four items

Weighting is the hardest correction to apply from a blueprint alone, because a security chapter always feels like the responsible place to spend an evening. A timed paper built on the published 8/17/2/1/9/6/4/6 allocation makes the point in a way a percentage table cannot.

See the CCDV-F blueprint

Questions

Frequently asked

The follow-up questions people search next.

How much of CCDV-F is security and safety?

Domain 7 is 8.1% of the exam — about 4 of 53 items — split into AI Application Security at 3.2%, Guardrails and Safe Deployment at 2.3%, Identity, Secrets and Key Management at 1.6% and Claude Hooks at 1.0%.

Do the other Claude exams test security?

Unevenly. CCAR-P spreads it across four domains, CCAO-F carries a single governance objective, and CCAR-F names security, safety, guardrails or secrets in no objective at all. CCDV-F is the only track where it is a domain with its own weight.

Is Claude Hooks worth studying at 1.0%?

Worth recognising, not worth a session. One percent of a 53-item paper averages to half an item, so a given form may carry one or none. Learn what a hook is and where it sits relative to the model call, then move on.

What is the difference between direct and indirect prompt injection?

Who is hostile. In a direct attack the person typing is the adversary. In an indirect one the person is trusted and the hostile instruction arrives inside content the system fetched — a page, a document, a tool result. The classification comes before the defence, because the two are not defended the same way.

Why do security items so often turn on where something is enforced?

Because a rule written into prompt wording is a request and a rule written into code is a constraint. Items in this domain routinely offer a well-worded instruction as the plausible answer when the correct one places the same rule at a layer the model cannot argue with.

Keep reading

Related posts

Not affiliated with, or endorsed by, Anthropic or Pearson VUE. Details are summarised from publicly published program information and can change — always confirm against the official exam guide before booking.

We use cookies and privacy-friendly analytics to understand usage and improve Cred Farmer. Essential features work either way. See our Cookie Policy.