CCAR-F Tool Design and MCP Integration Practice Question
An architect is building an MCP server that exposes a tool for querying an PostgreSQL database. The tool's input schema defines a single property 'query' of type string. During testing, the model generates SQL statements that include multiple statements separated by semicolons, causing unintended data modifications. Which change to the tool design best mitigates this risk while preserving the tool's usefulness?
⚠ Common exam trap
The trap here is assuming that adding a boolean flag or schema constraint will prevent the model from generating multi-statement SQL, when in fact only server-side parsing and rejection provides a reliable control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Parse the SQL string and reject any input containing more than one statement before execution.
The correct approach is to validate the SQL input at the MCP server and reject any input that contains more than one statement. This enforces a strict single-statement policy regardless of how the model formats its request. It keeps the tool flexible for legitimate single-statement queries while eliminating the risk of stacked statements that could modify data unexpectedly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Parse the SQL string and reject any input containing more than one statement before execution.
Why this is correct
Parsing and rejecting multi-statement input enforces a single-statement policy at the server, independent of model behavior. It preserves the ability to run arbitrary single SELECT statements while blocking the dangerous pattern of stacked statements. This is a robust, deterministic validation that directly addresses the root cause without reducing legitimate functionality.
- ✗
Add a separate boolean input property 'allowMultipleStatements' defaulting to false.
Why it's wrong here
Exposing a boolean that the model can set to true does not prevent the model from enabling it; the model could simply set it to true when generating the tool call. This approach relies on the model's cooperation rather than enforcing a technical control. It also adds unnecessary surface area and still permits multi-statement execution if the model toggles it.
- ✗
Change the tool to accept a structured object with separate properties for table, columns, and where clause.
Why it's wrong here
Moving to a structured object may reduce flexibility and still allows injection if the where clause is a raw string. The model could embed a semicolon in the where clause to achieve multi-statement execution. This redesign does not guarantee single-statement enforcement and complicates the schema without directly solving the stated risk.
- ✗
Change the 'query' property to an enum of pre-approved SQL statement templates.
Why it's wrong here
Restricting to a fixed enum of templates eliminates the flexibility the tool needs for ad-hoc querying and may not cover all legitimate use cases. It also forces the architect to predict every possible query shape, which is impractical. The scenario calls for preserving usefulness while mitigating multi-statement risk, and an enum does not allow parameterized queries with varied predicates.
About these practice questions
Courseiva writes every CCAR-F question from scratch — 271 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.