Courseiva

CCAR-F Tool Design and MCP Integration Practice Question

An architect is designing an MCP server that exposes a tool to retrieve employee records from an internal HR system. The tool accepts a 'department' parameter. To prevent the model from retrieving records outside the user's authorized departments, the architect wants to enforce access control at the MCP layer. Which approach best ensures that the model cannot bypass authorization?

⚠ Common exam trap

The trap here is treating schema descriptions or post-hoc filtering as security controls, when only pre-execution server-side authorization checks can reliably prevent unauthorized access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Validate the requested department against the authenticated user's permissions on the MCP server before executing the HR system query, and return an authorization error if not permitted.

Authorization must be enforced at the MCP server using the authenticated user's identity, not delegated to the model or applied after data retrieval. By validating the requested department against the user's permissions before querying the HR system, the server creates a hard boundary that the model cannot circumvent. This aligns with least privilege and zero-trust principles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Include a detailed description in the tool's JSON Schema stating that the model must only request departments the user is allowed to see.

    Why it's wrong here

    Schema descriptions are guidance, not enforcement. A model can still generate a request for an unauthorized department, and the server would process it if no runtime check exists. This approach relies on the model's compliance, which is not a security boundary. It fails to prevent bypass because the model can ignore the description.

  • ✓

    Validate the requested department against the authenticated user's permissions on the MCP server before executing the HR system query, and return an authorization error if not permitted.

    Why this is correct

    Enforcing authorization server-side, using the authenticated user's identity, ensures that even if the model requests an unauthorized department, the request is rejected. This creates a hard security boundary independent of model behavior. The model cannot bypass it because the check occurs before any data is accessed.

  • ✗

    Configure the MCP server to run with the same permissions as the HR system's service account, which has access to all departments, and rely on the model to request only allowed departments.

    Why it's wrong here

    Granting broad service-account permissions and relying on the model's discretion is a privilege escalation risk. The model could request any department, and the server would comply. This violates least privilege and provides no enforcement mechanism. The model is not a trusted security principal, so this approach is fundamentally insecure.

  • ✗

    Add a post-processing step that filters the HR system's response to remove any records from departments the model was not supposed to request.

    Why it's wrong here

    Filtering after the query still allows the HR system to be accessed for unauthorized departments, potentially leaking metadata or causing side effects. It also assumes the filter is perfectly implemented and covers all sensitive fields. This is a defense-in-depth measure at best, not a primary authorization control, and it does not prevent the model from attempting unauthorized access.

About these practice questions

This CCAR-F question is part of Courseiva's 271-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.