Courseiva

CCAR-F Tool Design and MCP Integration Practice Question

An architect is concerned about prompt injection attacks targeting an MCP tool. Which strategy provides the strongest defense?

⚠ Common exam trap

Candidates rely solely on system prompt warnings to deter malicious injection attempts, neglecting the necessity of cryptographic or schema-level input controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use strict JSON Schema validation and server-side parameter sanitization.

Defending against prompt injection in MCP requires treating all LLM inputs as untrusted. By using strict schema validation, type enforcement, and server-side input sanitization, you limit the attacker's ability to manipulate backend logic. This multi-layered approach ensures that even if the model is compromised by a malicious user prompt, the tool server remains resilient against unauthorized command execution or data exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a natural language filter to detect malicious intent before tool invocation.

    Why it's wrong here

    Detecting intent via natural language filtering is notoriously unreliable and prone to false positives or bypasses. Security must be enforced at the structural level, not the semantic level. Focusing on rigid input validation and schema adherence provides much stronger, predictable protection than attempting to interpret the user's intent.

  • ✓

    Use strict JSON Schema validation and server-side parameter sanitization.

    Why this is correct

    Strict schema validation acts as a structural firewall, while parameter sanitization ensures that any dynamic data is safely handled. This combined approach is the industry-standard defense against injection. It prevents the model from injecting unintended characters or commands into the tool's backend execution logic, maintaining overall system integrity.

  • ✗

    Ask the model to verify if the user's prompt is malicious before executing.

    Why it's wrong here

    Relying on the LLM to police its own security is a flawed strategy. The model can be coerced into ignoring its security instructions. Security logic must reside in the server's code, which is independent of the model's reasoning capabilities, ensuring that defensive measures cannot be bypassed by clever prompting.

  • ✗

    Disable all tool execution if the prompt contains special characters.

    Why it's wrong here

    This approach is too restrictive and will break legitimate tool use cases. Many valid inputs require special characters, such as punctuation in names or file paths. The correct architectural approach is to sanitize inputs for the specific backend system being called, rather than implementing a blanket ban on characters.

About these practice questions

One of 271 original CCAR-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.