ANTHROPIC-CLAUDE-ARCHITECT-FOUNDATIONS · domain
Tool Design and MCP Integration
Practise Claude Certified Architect - Foundations Tool Design and MCP Integration practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Tool Design and MCP Integration questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Tool Design and MCP Integration
Tool Design and MCP Integration questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Tool Design and MCP Integration exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Tool Design and MCP Integration questions (54)
Click any question to see the full explanation, or start a practice session above.
An architect is designing an MCP server that exposes a tool to query a customer relationship management (CRM) system. The CRM API enforces per-tenant rate limits and returns HTTP 429 with a Retry-After header when exceeded. The architect wants the tool to behave predictably under load without the model having to reason about throttling. Which approach should the architect implement?
Medium2When implementing an MCP resource that provides large datasets, what is the best practice for managing data transmission to avoid hitting context window limits?
Medium3When designing an MCP server, which TWO of these factors primarily influence the model's performance in selecting the right tool?
Medium4When designing tools that perform destructive actions, such as deleting a cloud resource or sending a high-priority email, which architectural pattern is most recommended by Anthropic?
Medium5An architect is implementing an MCP server that exposes a tool to create a new project in a project management system. The tool requires a project name, a list of team member emails, and a due date. The architect wants to minimize the chance that the model provides invalid or missing arguments. Which design choice best achieves this?
Medium6When designing an MCP server, what is the best practice for handling dependencies between multiple tools?
Medium7An architect is designing an MCP server that retrieves real-time financial data. To ensure the model does not hallucinate during tool execution, which design pattern is most effective for tool definition?
Medium8Which THREE of the following are benefits of using JSON Schema for MCP tool input definitions?
Medium9When designing an MCP tool that interacts with a high-latency external API, which strategy should be implemented to ensure a smooth interaction for the end-user?
Easy10An architect is building an MCP server that exposes a `read_file` tool. The tool's input schema currently defines `path` as a plain string. Security review requires that the tool never read outside a configured workspace root, and that the model receive a clear, machine-readable error when it attempts to do so. Which change to the tool design best satisfies this requirement?
Medium11An architect needs to implement a tool that allows the LLM to search a file system. What is the most secure way to present this capability?
Hard12A team is exposing an internal inventory database to Claude through an MCP server. They want the model to retrieve a specific item by its SKU, and they want the tool contract to be unambiguous so the model rarely mis-calls it. Which tool definition best matches this goal?
Easy13An architect is designing an MCP server that exposes a tool to retrieve employee records from an internal HR system. The tool accepts a 'department' parameter. To prevent the model from retrieving records outside the user's authorized departments, the architect wants to enforce access control at the MCP layer. Which approach best ensures that the model cannot bypass authorization?
Hard14An architect is designing an MCP server that exposes tools for a customer relationship management (CRM) system. The tools include 'get_customer', 'update_customer', and 'delete_customer'. The architect wants to ensure that tool invocations are properly authorized and audited. Which two design elements should be included in the MCP server implementation? (Choose two.)
Hard15An architect is concerned about prompt injection attacks targeting an MCP tool. Which strategy provides the strongest defense?
Medium16An architect is reviewing an MCP server's tool catalog before release. The team wants to reduce the chance that Claude selects the wrong tool when several tools have overlapping purposes, and to make failures easier to diagnose. Which two changes best support those goals? (Choose two.)
Medium17In the context of the Model Context Protocol (MCP), what is the primary role of an 'MCP Host' application?
Easy18An architect is exposing an MCP server whose 'get_account_balance' tool must never be invoked until the client has completed an OAuth token exchange, and the server must also advertise that this tool is unavailable to anonymous sessions. Which MCP capability should the architect implement to satisfy both requirements?
Hard19The Model Context Protocol (MCP) defines three primary primitives that servers can expose to clients. Which THREE of the following are the core primitives of MCP?
Medium20An architect is building an MCP server whose tool returns large tabular results, sometimes several megabytes. Early testing shows the model truncates or ignores the data and occasionally exceeds context limits. The architect wants the model to reason over the full dataset without losing fidelity. Which design should the architect choose?
Hard21When designing an MCP tool, why is it important to define a clear 'description' for every property in the 'inputSchema'?
Easy22What is the recommended method for handling large tool outputs in MCP?
Medium23An architect is reviewing an MCP server that exposes a tool to create support tickets. The tool currently returns a plain text confirmation. The architect wants to improve how the model and client application consume the result. Which two changes should the architect make? (Choose two.)
Medium24An architect is designing an MCP server that will be used by multiple Claude clients, each with different tool requirements. The server currently exposes all tools to every client. The architect wants to reduce the risk of a client accidentally invoking a tool it should not use, while keeping the server maintainable. Which approach best fits this goal?
Hard25An architect is designing an MCP server that retrieves real-time inventory levels from a legacy SQL database. The model needs to perform a partial update on specific stock quantities. Which design approach ensures the highest reliability and adherence to the Model Context Protocol standards?
Medium26When designing a multi-step tool process, which architecture most effectively prevents the model from getting stuck in an infinite loop?
Medium27Which component is responsible for executing the logic associated with an MCP tool?
Easy28An architect is building an MCP server that exposes a tool for querying a customer relationship management (CRM) system. The tool accepts a free-form text parameter called 'query' and returns matching customer records. During testing, the model frequently sends malformed queries that cause the CRM API to return errors, and the model then hallucinates customer data. Which change to the MCP tool definition is the most effective way to constrain the model's input and reduce these errors?
Medium29An architect is defining an MCP tool that returns weather data for a given city. The tool's output schema currently returns a free-text string. The architect wants to improve the model's ability to use the data in subsequent reasoning. What is the best change to the tool's output definition?
Easy30An MCP server exposes an `execute_task` tool that can run arbitrary shell commands in a sandbox. During evaluation, the architect observes that the model sometimes calls the tool with a command that succeeds but produces no useful output, then calls it again with a nearly identical command, repeating several times. Which design change most directly addresses this loop behavior?
Hard31An architect is designing an MCP server that will be used by multiple client applications, some of which support only a subset of MCP capabilities. The architect wants tools to remain usable across clients without requiring per-client server forks. Which design principle should guide the server implementation?
Hard32An architect is designing a tool for Claude to interact with a corporate database. The tool needs to retrieve employee records by department. Which approach to naming and describing the tool and its parameters will most likely result in the highest model accuracy and reliability?
Medium33How should an MCP server communicate a non-recoverable error to the client?
Medium34What is the primary advantage of using a dedicated MCP server over embedding tool logic directly into the application code?
Medium35An architect is designing an MCP server that wraps a ticketing system. The design must let Claude call tools safely and must keep tool definitions maintainable as the API grows. Which two practices should the architect apply? (Choose two.)
Hard36Which TWO of the following are primary benefits of using the Model Context Protocol (MCP) over a proprietary REST-based tool integration?
Hard37An architect is integrating an MCP server with a legacy inventory system that exposes a SOAP API. The MCP server must translate tool calls into SOAP requests. The SOAP API is slow and occasionally returns faults. Which design choice best ensures that the model can recover gracefully from SOAP faults without hallucinating inventory data?
Medium38An architect is designing an MCP server that exposes several tools for a document management system. The tools include 'create_document', 'update_document', 'delete_document', and 'search_documents'. The architect wants to minimize the risk of the model accidentally invoking destructive tools during exploratory or read-only tasks. Which two design choices should the architect implement? (Choose two.)
Hard39An organization is transitioning from individual, hard-coded tool integrations to a Model Context Protocol (MCP) architecture. Which TWO benefits will they most likely realize from this change?
Medium40An architect is defining the input schema for an MCP tool that schedules a meeting. The schema currently accepts a free-form string for the start time, and the model frequently sends ambiguous values such as "next Tuesday afternoon." Which change best improves reliability?
Easy41Refer to the exhibit. An architect is configuring an MCP server to provide read-only access to a SQLite database. What is the primary reason for using the 'env' field in this configuration?
Hard42Refer to the exhibit. The model fails to return accurate data when the user asks for metrics over a 'five minute' interval. What is the most likely cause?
Hard43Which of the following describes the purpose of the 'resources' feature in MCP?
Easy44An architect is reviewing an MCP server where one tool returns a 2 MB JSON payload of raw database rows. The model's responses have become slow and occasionally drop details from the middle of the payload. Which change best addresses the observed behavior while preserving the tool's usefulness?
Medium45During an MCP tool invocation, a user asks Claude to look up an order by its ID. The MCP server's tool handler returns a successful result, but the response payload is 12 MB of raw JSON containing nested line items, shipping events, and audit metadata. Claude's reply to the user is vague and omits key order details. Which change to the MCP tool design best addresses this?
Medium46An architect is building an MCP server that exposes a tool named `fetch_weather`. The tool's input schema currently defines `location` as a string with no description. During testing, the model frequently sends postal codes for cities outside the supported region, causing upstream API errors. Which change to the tool definition most directly improves the model's ability to supply valid inputs?
Medium47When designing tools for a highly regulated environment, what is the most important architectural goal?
Hard48Which approach is best for handling binary data (like images) in an MCP tool integration?
Medium49An MCP server exposes a `query_orders` tool whose input schema includes a `filters` object with several optional properties. The model intermittently omits required nested fields inside `filters`, and the server returns a generic 400 error. The architect wants the model to reliably produce schema-valid arguments and recover from validation failures. Which combination of MCP features should the architect implement?
Hard50An architect is preparing an MCP server for a code review tool. The tool 'review_code' takes a 'language' parameter and a 'code_snippet' parameter. The architect wants to ensure the model provides valid language values and that the snippet is not excessively large. Which combination of JSON Schema constraints should be applied to the tool definition?
Easy51An MCP server wraps a ticketing API. The API accepts a `priority` field whose valid values are `low`, `medium`, and `high`. During testing, the model occasionally sends `urgent`, and the API returns a generic 400 error. The architect wants the model to self-correct on the next turn without changing the upstream API. Which change to the MCP tool best achieves this?
Hard52How does providing a large number of complex tool definitions in a single request impact the performance and behavior of Claude?
Medium53A team is exposing an existing internal REST API to Claude through an MCP server. The API requires an OAuth 2.0 bearer token per user, and the team wants each user's Claude session to act with that user's own permissions. Where should the per-user OAuth token be handled in the MCP architecture?
Easy54An architect is building an MCP server that exposes a tool for querying an PostgreSQL database. The tool's input schema defines a single property 'query' of type string. During testing, the model generates SQL statements that include multiple statements separated by semicolons, causing unintended data modifications. Which change to the tool design best mitigates this risk while preserving the tool's usefulness?
MediumFrequently asked questions
- What does the Tool Design and MCP Integration domain cover on the ANTHROPIC-CLAUDE-ARCHITECT-FOUNDATIONS exam?
- Tool Design and MCP Integration questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 54 Tool Design and MCP Integration questions in the ANTHROPIC-CLAUDE-ARCHITECT-FOUNDATIONS question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Tool Design and MCP Integration questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.