Security and Safety
8.1% of the published blueprint, which works out at about 4.3 items on a 53-item form. These are expected values across forms, not a promise about the form you sit.
4 published sub-domains, each separately weighted
AI Application Security
3.2% · 1.7 items1–2 itemsData privacy and security best practices, including prompt injection awareness and mitigation, jailbreak defense, untrusted input handling, data leakage prevention, PII handling, and ensuring authentication, authorization, confidentiality, privacy, and integrity.
Guardrails and Safe Deployment
2.3% · 1.2 items1–2 itemsSafe and responsible deployment practices (content policy, guardrail layering) and secure-by-design principles (privacy, identity and access management, least privilege).
Identity, Secrets, and Key Management
1.6% · 0.85 items≤1 item — may not appear at allManaging secrets, credentials, and API keys across Claude development and production environments, including identity validation and authentication, access approval and level verification, and authorized access monitoring.
Claude Hooks
1% · 0.53 items≤1 item — may not appear at allLeveraging hooks for guardrails and safety controls to prevent destructive actions within Claude applications.
3 concept cards — tap one for the example, the instinct and the trap
Primary sources for this domain
The guide’s “How to Prepare” section says to review official Anthropic documentation for the Claude API, models, prompt engineering, Claude Code, Skills and MCP. These are those pages, taken from each site’s own llms.txt manifest rather than from a search.
Working the whole blueprint? The study guide carries the eligibility rules, the exam logistics and the full sub-domain allocation table.