CCAR-F Tool Design and MCP Integration Practice Question
An architect needs to implement a tool that allows the LLM to search a file system. What is the most secure way to present this capability?
⚠ Common exam trap
Candidates allow the LLM to pass absolute file paths freely, exposing the system to severe directory traversal and unauthorized file access vulnerabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Design the tool to accept relative paths within a predefined server-side root.
Providing a file system tool requires strict path sandboxing to prevent directory traversal and unauthorized access. By defining a single, restricted 'base_path' and ensuring the server programmatically validates that requested paths reside within this directory, the architect creates a secure boundary. This design prevents the LLM from accessing sensitive system files or configuration data, fulfilling the security requirements necessary for professional-grade MCP tool implementation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow the model to provide any absolute path as an argument.
Why it's wrong here
Allowing absolute paths is a critical security vulnerability that enables directory traversal attacks. The model could easily be prompted to read system-critical files like '/etc/passwd'. Absolute paths must be strictly forbidden in the tool's design to maintain the security of the host environment and prevent data exfiltration.
- ✗
Implement a 'root_directory' parameter that the model can change dynamically.
Why it's wrong here
Allowing the model to change the root directory defeats the purpose of path sandboxing. It introduces an attack vector where the model can be tricked into escaping the intended root. The root directory must be hardcoded or managed by server-side configuration, never passed as an argument from the LLM.
- ✓
Design the tool to accept relative paths within a predefined server-side root.
Why this is correct
This approach uses a server-side enforced root, which prevents the LLM from accessing files outside the designated workspace. By resolving paths against a fixed base, you eliminate directory traversal risks. This design pattern ensures the tool is useful while maintaining a strict, secure boundary against unauthorized file system access.
- ✗
Provide a tool that lets the model browse all directories starting from '/'
Why it's wrong here
Exposing the entire file system to the model is inherently unsafe. It grants the LLM the ability to explore and potentially interact with sensitive files across the entire operating system. This violates the principle of least privilege and significantly increases the attack surface of the entire infrastructure.
About these practice questions
One of 271 original CCAR-F practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-F exam.