CCAR-F Tool Design and MCP Integration Practice Question
An architect is exposing an MCP server whose 'get_account_balance' tool must never be invoked until the client has completed an OAuth token exchange, and the server must also advertise that this tool is unavailable to anonymous sessions. Which MCP capability should the architect implement to satisfy both requirements?
⚠ Common exam trap
The trap here is assuming that a required credential field in the tool's inputSchema enforces authentication, when schemas only validate argument shape and never gate discovery or callability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Serve the tool list dynamically so that 'get_account_balance' is only returned to clients that present a valid bearer token, and omit it from tools/list responses for unauthenticated sessions.
Because MCP servers can vary the tools they advertise per session, gating the tools/list response on a validated bearer token hides the balance operation entirely from anonymous clients while presenting it normally after OAuth completes. This enforces the precondition at the discovery layer, where the client's authentication state is actually known, instead of relying on argument schemas or error handling after the model has already attempted the call.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Expose 'get_account_balance' through a resources primitive instead of a tool, since resources are read-only and therefore inherently restricted to authenticated clients.
Why it's wrong here
Resources are for context data the client can attach, not for parameterized operations that return live balances on demand. Read-only does not imply authenticated, so this changes the primitive without adding any access gate. The model would also lose the ability to call the operation with arguments, which breaks the intended balance-retrieval behaviour entirely.
- ✗
Declare the tool with an inputSchema that marks a required 'access_token' string property, and reject calls whose token fails validation inside the tool handler.
Why it's wrong here
Schema-level required fields only describe the shape of arguments the model should supply; they do not gate discovery or advertise availability. The model could still see and attempt the tool anonymously, and the server would only discover the problem after the call arrives. This also leaks the credential into model-generated arguments, which is a security anti-pattern rather than an access-control mechanism.
- ✗
Return an isError result from the tool handler whenever the session lacks a valid token, instructing the model in the error text to retry after authentication.
Why it's wrong here
Returning an error still requires the tool to be listed and callable, so anonymous clients can discover it and repeatedly trigger failed invocations. It pushes access control into the model's interpretation of error strings, which is neither deterministic nor secure. The tool also remains visible before the OAuth exchange, violating the requirement that it not be advertised to anonymous sessions.
- ✓
Serve the tool list dynamically so that 'get_account_balance' is only returned to clients that present a valid bearer token, and omit it from tools/list responses for unauthenticated sessions.
Why this is correct
MCP servers may compute tools/list results per session, so an authenticated session receives the balance tool while anonymous sessions never see it. This satisfies both requirements at once: the capability is not discoverable before the OAuth exchange completes, and the server itself advertises that the tool is unavailable to anonymous clients rather than relying on a post-hoc argument check.
About these practice questions
Courseiva writes every CCAR-F question from scratch — 271 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.