nerdexam
Salesforce

AI-201 · Question #261

Universal Containers wants to implement a customer verification process where sensitive account information can only be accessed after the customer passes identity verification. The agent must…

The correct answer is C. Create a custom variable IsCustomerVerified set by a verification action, then apply a conditional. The requirement is that identity verification must be enforced 'deterministically' and the LLM must not be able to bypass it. The correct solution is to use a dedicated custom boolean/status variable (IsCustomerVerified) that is set programmatically by a verification action…

AI Features for Service (e.g., Einstein Bots, Next Best Action)

Question

Universal Containers wants to implement a customer verification process where sensitive account information can only be accessed after the customer passes identity verification. The agent must enforce this security rule deterministically without allowing the large language model (LLM) to bypass the verification requirement. What should an Agentforce Specialist recommend as the best solution?

Options

  • AUse context variables to store verification status in the messaging session and configure the
  • BInclude detailed verification instructions in the agent's topic instructions explaining when
  • CCreate a custom variable IsCustomerVerified set by a verification action, then apply a conditional

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    13% (3)
  • C
    83% (19)

Explanation

The requirement is that identity verification must be enforced 'deterministically' and the LLM must not be able to bypass it. The correct solution is to use a dedicated custom boolean/status variable (IsCustomerVerified) that is set programmatically by a verification action (e.g., a Flow or Apex action that validates OTP, knowledge-based authentication, etc.). A conditional instruction or flow gate then checks this variable before allowing any sensitive action to proceed. Because the variable is set by system logic - not by LLM interpretation - the LLM cannot reason its way past it. Option A (context variables for verification status with some configuration) is vague and incomplete - storing verification status in a session context variable without a hard conditional gate still leaves room for LLM interpretation. Option B (topic instructions explaining when to verify) is the worst option - topic instructions are natural language guidance to the LLM and are inherently non-deterministic; the LLM could potentially be prompted or confused into skipping verification.

Topics

#AI Agent Logic#Identity Verification#Conditional Actions#Security Enforcement

Community Discussion

No community discussion yet for this question.

Full AI-201 Practice