Courseiva

CCDV-F Tools and MCP Integration Practice Question

A developer is implementing an MCP client that connects to a remote MCP server over HTTP. The server requires authentication using an API key. The developer wants to ensure that all requests from the client include the API key in the headers. Which approach is correct for configuring the MCP client?

⚠ Common exam trap

The trap here is assuming that MCP has a custom authentication field in the JSON-RPC body or that API keys can be passed via query parameters, when in fact standard HTTP headers are used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the API key in the 'Authorization' header when establishing the HTTP connection to the MCP server.

The correct approach is to set the API key in the 'Authorization' header of the HTTP connection. MCP over HTTP relies on standard HTTP authentication mechanisms, and headers are the appropriate place for credentials. Other methods either misuse query parameters, confuse client and server roles, or attempt to embed authentication in the JSON-RPC body, which is not standard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Include the API key in the body of each MCP JSON-RPC request.

    Why it's wrong here

    MCP messages are JSON-RPC 2.0, which does not define a standard field for authentication in the request body. Adding a custom field would be non-standard and likely ignored by the server. Authentication should be handled at the transport layer, such as HTTP headers, not within the JSON-RPC payload.

  • ✓

    Set the API key in the 'Authorization' header when establishing the HTTP connection to the MCP server.

    Why this is correct

    MCP over HTTP uses standard HTTP headers for authentication. The 'Authorization' header, often with a Bearer token or API key, is the correct place to include credentials. The MCP client should be configured to add this header to all requests, ensuring the server can authenticate each call. This is consistent with common HTTP authentication practices.

  • ✗

    Pass the API key as an environment variable when starting the MCP server process.

    Why it's wrong here

    Environment variables are used for server-side configuration, not for client authentication. In this scenario, the developer is building the client that connects to a remote server. The client cannot set the server's environment variables. The API key must be sent with each request from the client to the server.

  • ✗

    Include the API key as a query parameter in the MCP server URL.

    Why it's wrong here

    Putting an API key in a query parameter is insecure because URLs can be logged or exposed in referrer headers. MCP does not standardize API key transmission via query parameters; authentication is typically handled through headers or transport-level security. This approach is not recommended and may not be supported by the server.

About these practice questions

Courseiva writes every CCDV-F question from scratch — 257 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCDV-F practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCDV-F exam.