Claude Certified Architect, Foundations · Test 1 · question 3 of 10
Agent Architecture & Orchestrationhard
A company runs an agent built with the Claude Agent SDK that has shell access to a staging host. Policy says the agent must never run a command containing "rm -rf", and auditors need that guarantee to hold regardless of what users or retrieved documents say to the agent. The current control is a sentence in the system prompt, and a red team has bypassed it with a crafted document. What is the best fix?