CCAR-F Tool Design and MCP Integration Practice Question
An architect is designing an MCP server that wraps a ticketing system. The design must let Claude call tools safely and must keep tool definitions maintainable as the API grows. Which two practices should the architect apply? (Choose two.)
⚠ Common exam trap
The trap here is favoring a single flexible passthrough tool or maximal permissions for convenience, when precise schemas and least privilege are what make tool use both safe and maintainable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Return structured, machine-readable errors from tool handlers so the model can correct invalid arguments on retry.
Safe, maintainable MCP tooling rests on precise, versioned schemas that tell the model exactly what each tool accepts, plus structured error results that let the model recover from invalid arguments. Together these raise call accuracy without widening privileges. Generic passthrough tools, over-broad service accounts, and prompt-embedded descriptions each undermine either safety or maintainability, and none of them scale cleanly as the ticketing API grows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Expose one generic `call_ticket_api` tool that accepts an arbitrary endpoint path and HTTP method as string arguments.
Why it's wrong here
A generic passthrough tool gives the model unbounded authority over the upstream API and offers no schema-level guidance about valid operations. It makes safe invocation impossible to guarantee and turns every API change into a prompt-engineering problem. This pattern maximizes risk while undermining the maintainability goal it appears to serve.
- ✓
Return structured, machine-readable errors from tool handlers so the model can correct invalid arguments on retry.
Why this is correct
Structured errors name the offending field or condition, letting the model repair its call instead of repeating the same mistake. This raises the success rate of tool use without loosening the schema or granting broader access. It also produces consistent failure semantics that are easier to maintain across many tools as the ticketing API grows.
- ✗
Inline all tool descriptions as long prose in the system prompt instead of in the tool definitions themselves.
Why it's wrong here
Descriptions placed in the system prompt are disconnected from the tool definitions the model receives, so they can drift out of sync and are not validated with the schema. Tool-specific guidance belongs in the tool's own definition, where it travels with the contract. Moving it to the prompt harms maintainability and weakens the model's ability to select and call tools correctly.
- ✓
Define each tool's `inputSchema` with precise types, enums, and descriptions, and keep the schema in version control alongside the server code.
Why this is correct
Precise schemas with types, enums, and descriptions give the model an unambiguous contract, and versioning them with the server code keeps the contract and implementation from drifting. This combination improves call accuracy and makes schema changes reviewable. It directly supports both safe invocation and long-term maintainability as the ticketing API evolves.
- ✗
Grant the server's service account full administrative scope on the ticketing system so any tool call will succeed.
Why it's wrong here
Broad administrative scope violates least privilege and means a malformed or malicious call can alter or delete data far beyond the intended operation. It removes the safety boundary that schemas and scoped credentials are meant to provide. Convenience here directly conflicts with the requirement to call tools safely.
About these practice questions
Courseiva writes every CCAR-F question from scratch — 271 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.