Be able to design an MCP server whose tool names, descriptions, and input schemas remove ambiguity, and to explain how tools, resources, and prompts differ. The critical skill is diagnosing why a tool call returned wrong data and fixing the definition rather than the prompt.
Start practicing
Tool Design and MCP Integration — choose a session length
Free · No account required
Domain overview
This domain covers how Claude agents discover and call external capabilities through the Model Context Protocol, plus how tool schemas are authored so the model invokes them correctly. Questions are scenario-based: you evaluate MCP server designs, diagnose tool-call failures from exhibits, and distinguish MCP primitives such as tools, resources, and prompts.
Exam objectives
Benefits of replacing hard-coded per-integration tool wiring with a shared MCP server architecture
Writing precise tool names, descriptions, and JSON input schemas so the model selects and fills tools correctly
Using MCP resources to expose readable context versus tools that perform actions
Diagnosing tool-execution failures such as ambiguous parameters, unit mismatches, or vague descriptions
Confusing MCP resources with tools: resources expose readable context, while tools perform actions the model invokes.
Assuming the model infers units or formats; vague schemas and descriptions cause wrong or hallucinated arguments during execution.
Treating MCP as only a transport change, ignoring that standardized tool definitions improve reuse and model tool selection.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which component is responsible for executing the logic associated with an MCP tool?
2An architect is concerned about prompt injection attacks targeting an MCP tool. Which strategy provides the strongest defense?
3When designing an MCP server, which TWO of these factors primarily influence the model's performance in selecting the right tool?
4An architect needs to implement a tool that allows the LLM to search a file system. What is the most secure way to present this capability?
5How should an MCP server communicate a non-recoverable error to the client?
6When designing tools for a highly regulated environment, what is the most important architectural goal?
7What is the recommended method for handling large tool outputs in MCP?
8An architect is designing an MCP server that retrieves real-time inventory levels from a legacy SQL database. The model needs to perform a partial update on specific stock quantities. Which design approach ensures the highest reliability and adherence to the Model Context Protocol standards?
9When designing an MCP tool that interacts with a high-latency external API, which strategy should be implemented to ensure a smooth interaction for the end-user?
10When designing an MCP server, what is the best practice for handling dependencies between multiple tools?
11Which of the following describes the purpose of the 'resources' feature in MCP?
12Which THREE of the following are benefits of using JSON Schema for MCP tool input definitions?
13Which approach is best for handling binary data (like images) in an MCP tool integration?
14When designing an MCP tool, why is it important to define a clear 'description' for every property in the 'inputSchema'?
15When designing a multi-step tool process, which architecture most effectively prevents the model from getting stuck in an infinite loop?
16What is the primary advantage of using a dedicated MCP server over embedding tool logic directly into the application code?
17An architect is designing a tool for Claude to interact with a corporate database. The tool needs to retrieve employee records by department. Which approach to naming and describing the tool and its parameters will most likely result in the highest model accuracy and reliability?
18In the context of the Model Context Protocol (MCP), what is the primary role of an 'MCP Host' application?
19An organization is transitioning from individual, hard-coded tool integrations to a Model Context Protocol (MCP) architecture. Which TWO benefits will they most likely realize from this change?
20When designing tools that perform destructive actions, such as deleting a cloud resource or sending a high-priority email, which architectural pattern is most recommended by Anthropic?
21The Model Context Protocol (MCP) defines three primary primitives that servers can expose to clients. Which THREE of the following are the core primitives of MCP?
22How does providing a large number of complex tool definitions in a single request impact the performance and behavior of Claude?
23Refer to the exhibit. An architect is configuring an MCP server to provide read-only access to a SQLite database. What is the primary reason for using the 'env' field in this configuration?
24An architect is designing an MCP server that retrieves real-time financial data. To ensure the model does not hallucinate during tool execution, which design pattern is most effective for tool definition?
25When implementing an MCP resource that provides large datasets, what is the best practice for managing data transmission to avoid hitting context window limits?
26Which TWO of the following are primary benefits of using the Model Context Protocol (MCP) over a proprietary REST-based tool integration?
27Refer to the exhibit. The model fails to return accurate data when the user asks for metrics over a 'five minute' interval. What is the most likely cause?
28An architect is exposing an MCP server whose 'get_account_balance' tool must never be invoked until the client has completed an OAuth token exchange, and the server must also advertise that this tool is unavailable to anonymous sessions. Which MCP capability should the architect implement to satisfy both requirements?
29During an MCP tool invocation, a user asks Claude to look up an order by its ID. The MCP server's tool handler returns a successful result, but the response payload is 12 MB of raw JSON containing nested line items, shipping events, and audit metadata. Claude's reply to the user is vague and omits key order details. Which change to the MCP tool design best addresses this?
30An architect is building an MCP server that exposes a tool for querying an PostgreSQL database. The tool's input schema defines a single property 'query' of type string. During testing, the model generates SQL statements that include multiple statements separated by semicolons, causing unintended data modifications. Which change to the tool design best mitigates this risk while preserving the tool's usefulness?
31An architect is designing an MCP server that exposes tools for a customer relationship management (CRM) system. The tools include 'get_customer', 'update_customer', and 'delete_customer'. The architect wants to ensure that tool invocations are properly authorized and audited. Which two design elements should be included in the MCP server implementation? (Choose two.)
32An architect is defining an MCP tool that returns weather data for a given city. The tool's output schema currently returns a free-text string. The architect wants to improve the model's ability to use the data in subsequent reasoning. What is the best change to the tool's output definition?
33An architect is implementing an MCP server that exposes a tool to create a new project in a project management system. The tool requires a project name, a list of team member emails, and a due date. The architect wants to minimize the chance that the model provides invalid or missing arguments. Which design choice best achieves this?
34An architect is designing an MCP server that will be used by multiple Claude clients, each with different tool requirements. The server currently exposes all tools to every client. The architect wants to reduce the risk of a client accidentally invoking a tool it should not use, while keeping the server maintainable. Which approach best fits this goal?
35An architect is designing an MCP server that exposes a tool to query a customer relationship management (CRM) system. The CRM API enforces per-tenant rate limits and returns HTTP 429 with a Retry-After header when exceeded. The architect wants the tool to behave predictably under load without the model having to reason about throttling. Which approach should the architect implement?
36An architect is building an MCP server that exposes a tool named `fetch_weather`. The tool's input schema currently defines `location` as a string with no description. During testing, the model frequently sends postal codes for cities outside the supported region, causing upstream API errors. Which change to the tool definition most directly improves the model's ability to supply valid inputs?
37An architect is building an MCP server whose tool returns large tabular results, sometimes several megabytes. Early testing shows the model truncates or ignores the data and occasionally exceeds context limits. The architect wants the model to reason over the full dataset without losing fidelity. Which design should the architect choose?
38An architect is building an MCP server that exposes a `read_file` tool. The tool's input schema currently defines `path` as a plain string. Security review requires that the tool never read outside a configured workspace root, and that the model receive a clear, machine-readable error when it attempts to do so. Which change to the tool design best satisfies this requirement?
39An MCP server exposes a `query_orders` tool whose input schema includes a `filters` object with several optional properties. The model intermittently omits required nested fields inside `filters`, and the server returns a generic 400 error. The architect wants the model to reliably produce schema-valid arguments and recover from validation failures. Which combination of MCP features should the architect implement?
40An architect is defining the input schema for an MCP tool that schedules a meeting. The schema currently accepts a free-form string for the start time, and the model frequently sends ambiguous values such as "next Tuesday afternoon." Which change best improves reliability?
41A team is exposing an internal inventory database to Claude through an MCP server. They want the model to retrieve a specific item by its SKU, and they want the tool contract to be unambiguous so the model rarely mis-calls it. Which tool definition best matches this goal?
42An architect is building an MCP server that exposes a tool for querying a customer relationship management (CRM) system. The tool accepts a free-form text parameter called 'query' and returns matching customer records. During testing, the model frequently sends malformed queries that cause the CRM API to return errors, and the model then hallucinates customer data. Which change to the MCP tool definition is the most effective way to constrain the model's input and reduce these errors?
43A team is exposing an existing internal REST API to Claude through an MCP server. The API requires an OAuth 2.0 bearer token per user, and the team wants each user's Claude session to act with that user's own permissions. Where should the per-user OAuth token be handled in the MCP architecture?
44An MCP server exposes an `execute_task` tool that can run arbitrary shell commands in a sandbox. During evaluation, the architect observes that the model sometimes calls the tool with a command that succeeds but produces no useful output, then calls it again with a nearly identical command, repeating several times. Which design change most directly addresses this loop behavior?
45An architect is reviewing an MCP server that exposes a tool to create support tickets. The tool currently returns a plain text confirmation. The architect wants to improve how the model and client application consume the result. Which two changes should the architect make? (Choose two.)
46An architect is designing an MCP server that exposes a tool to retrieve employee records from an internal HR system. The tool accepts a 'department' parameter. To prevent the model from retrieving records outside the user's authorized departments, the architect wants to enforce access control at the MCP layer. Which approach best ensures that the model cannot bypass authorization?
47An architect is reviewing an MCP server where one tool returns a 2 MB JSON payload of raw database rows. The model's responses have become slow and occasionally drop details from the middle of the payload. Which change best addresses the observed behavior while preserving the tool's usefulness?
48An architect is designing an MCP server that will be used by multiple client applications, some of which support only a subset of MCP capabilities. The architect wants tools to remain usable across clients without requiring per-client server forks. Which design principle should guide the server implementation?
49An architect is reviewing an MCP server's tool catalog before release. The team wants to reduce the chance that Claude selects the wrong tool when several tools have overlapping purposes, and to make failures easier to diagnose. Which two changes best support those goals? (Choose two.)
50An architect is preparing an MCP server for a code review tool. The tool 'review_code' takes a 'language' parameter and a 'code_snippet' parameter. The architect wants to ensure the model provides valid language values and that the snippet is not excessively large. Which combination of JSON Schema constraints should be applied to the tool definition?
51An architect is designing an MCP server that wraps a ticketing system. The design must let Claude call tools safely and must keep tool definitions maintainable as the API grows. Which two practices should the architect apply? (Choose two.)
52An MCP server wraps a ticketing API. The API accepts a `priority` field whose valid values are `low`, `medium`, and `high`. During testing, the model occasionally sends `urgent`, and the API returns a generic 400 error. The architect wants the model to self-correct on the next turn without changing the upstream API. Which change to the MCP tool best achieves this?
53An architect is integrating an MCP server with a legacy inventory system that exposes a SOAP API. The MCP server must translate tool calls into SOAP requests. The SOAP API is slow and occasionally returns faults. Which design choice best ensures that the model can recover gracefully from SOAP faults without hallucinating inventory data?
54An architect is designing an MCP server that exposes several tools for a document management system. The tools include 'create_document', 'update_document', 'delete_document', and 'search_documents'. The architect wants to minimize the risk of the model accidentally invoking destructive tools during exploratory or read-only tasks. Which two design choices should the architect implement? (Choose two.)
Be able to design an MCP server whose tool names, descriptions, and input schemas remove ambiguity, and to explain how tools, resources, and prompts differ. The critical skill is diagnosing why a tool call returned wrong data and fixing the definition rather than the prompt.
The Courseiva CCAR-F question bank contains 54 questions in the Tool Design and MCP Integration domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Tool Design and MCP Integration domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included