Courseiva

CCNA Tools and MCP Integration Questions

39 questions · Tools and MCP Integration · All types, answers revealed

1
MCQeasy

A developer is defining a tool for Claude that fetches the current stock price for a ticker symbol. The tool will be called `get_stock_price`. Which `input_schema` definition best enables Claude to call the tool correctly?

A.A JSON Schema object with `type: "object"` and a free-form `additionalProperties: true` allowing any fields.
B.A JSON Schema object with `type: "object"` and a `properties` entry for `ticker`, but no `required` array and no `description`.
C.A JSON Schema object with `type: "object"`, a `properties` entry for `ticker` of `type: "string"`, and a `required` array containing `"ticker"`.
D.A JSON Schema object with `type: "string"` and a `description` explaining that the value should be a ticker symbol.
AnswerC

Claude relies on the tool's JSON Schema to decide when and how to call it. Declaring an object with a typed `ticker` property and marking it required gives the model the parameter name, type, and obligation it needs to emit a valid `tool_use` input such as `{"ticker": "AAPL"}`. This is the standard, fully specified shape expected by the Messages API.

Why this answer

Tool definitions should describe inputs as a JSON Schema object with named, typed properties and a `required` array. For a stock lookup, a required string `ticker` tells Claude exactly what to supply. Permissive schemas, non-object root types, or missing required/description fields all degrade the model's ability to produce correct tool call arguments, so the fully specified object schema is the right choice.

Exam trap

The trap here is thinking a descriptive string schema or a permissive object is enough, when Claude needs named typed properties and an explicit required list.

2
MCQmedium

A developer is building a customer-support agent using the Anthropic API with the Claude 3.5 Sonnet model. The agent exposes a `lookup_order` tool that takes an `order_id` string. During testing, a user asks 'Where is my order 88213?' and Claude returns a `tool_use` block with `name: "lookup_order"` and `input: {"order_id": "88213"}`. What must the developer send back to Claude in the next API request so it can produce a natural-language answer?

A.A new `system` message that contains the order details and instructs Claude to answer the user.
B.A `user` message containing a `tool_result` content block whose `tool_use_id` matches the `tool_use` block and whose `content` holds the lookup result.
C.An `assistant` message that echoes the `tool_use` block and appends the lookup result inside the same block.
D.A `user` message containing the raw JSON result of the order lookup, with no `tool_use_id` reference.
AnswerB

The Anthropic Messages API requires that after Claude emits a `tool_use` block, the developer replies with a `user` message containing a `tool_result` block referencing the same `tool_use_id`. This lets Claude bind the returned order data to its earlier request. Only then will the model generate the final natural-language reply about order 88213 using the actual lookup output.

Why this answer

After Claude emits a `tool_use` block, the developer must return a user message containing a `tool_result` block that carries the same `tool_use_id`. This pairing is how the model links its request to the returned data. Once the matching result is provided, Claude can generate the final answer about the order.

Any other message shape leaves the tool call unsatisfied and prevents a grounded response.

Exam trap

The trap here is assuming tool output can be sent as ordinary user text or a system message instead of a properly paired `tool_result` block.

3
MCQmedium

A developer is creating an MCP server that exposes a tool to query a PostgreSQL database. The tool definition includes a parameter 'sql_query' that accepts a raw SQL string. During a security review, it was flagged that this design could allow SQL injection if Claude generates malicious SQL. Which change should the developer make to mitigate this risk?

A.Replace the raw SQL parameter with structured parameters such as table name, columns, and filters, and construct the SQL query internally using parameterized statements.
B.Limit the database user's permissions to read-only, so even if malicious SQL is executed, it cannot modify data.
C.Add a description to the tool instructing Claude to never generate malicious SQL.
D.Validate the 'sql_query' parameter by checking that it only contains SELECT statements and no semicolons.
AnswerA

By using structured parameters and building the SQL query internally with parameterized statements, the developer prevents SQL injection because user input is not directly concatenated into the query. This approach also makes the tool easier for Claude to use correctly. It constrains the operations to safe patterns and avoids exposing raw SQL execution.

Why this answer

The best mitigation is to replace raw SQL with structured parameters and construct queries internally using parameterized statements. This eliminates the injection vector by design. Other options either rely on unreliable prompting, weak validation, or partial mitigation that does not address the core vulnerability.

Structured parameters also improve usability and safety.

Exam trap

The trap here is thinking that prompting Claude to behave or simple input validation is sufficient to prevent SQL injection, when the robust solution is to avoid raw SQL and use parameterized queries.

4
MCQmedium

A developer is building an MCP client that connects to a remote MCP server over HTTP. After the initial handshake, the client needs to discover what prompts the server exposes so they can be surfaced in a slash-command menu. Which MCP capability should the client invoke?

A.resources/list
B.prompts/list
C.tools/list
D.initialize
AnswerB

The prompts/list request is the MCP method that returns the prompts a server exposes, including each prompt's name, description, and arguments. Calling it after initialization lets the client enumerate server-provided prompt templates and render them as commands in the UI, which is exactly what this scenario requires.

Why this answer

Prompt templates are a distinct MCP primitive from tools and resources, and they are enumerated with the prompts/list request. Because the goal is to build a slash-command menu of reusable prompts, the client must call prompts/list after the initialize handshake, then optionally fetch a specific prompt with prompts/get when the user selects it.

Exam trap

The trap here is assuming that the initialize handshake already returns the concrete list of prompts, when it only advertises the prompts capability.

5
MCQhard

Refer to the exhibit. A developer is debugging an MCP integration and sees these logs in their console. What is the most likely cause of this error?

A.The MCP Server is using an outdated version of the protocol.
B.The 'get_files' tool is not correctly defined in the server's list_tools handler.
C.The path argument '/' is restricted by the server's security policy.
D.The model (Claude) generated a malformed JSON object for the arguments.
AnswerB

Every MCP server must implement a handler that lists available tools. If 'get_files' is missing from this list, the Host might still try to call it (perhaps due to cached info or hardcoding), but the Server will reject the call with a 'Method not found' error because it doesn't recognize it.

Why this answer

The error code -32601 is a standard JSON-RPC error indicating that the requested method does not exist on the server. In the context of MCP, this means the Host is trying to call a tool named 'get_files', but the Server has not registered or implemented a tool with that exact name in its tool list.

Exam trap

Candidates often blame network connectivity or syntax errors in the JSON payload, missing that the JSON-RPC -32601 error specifically points to an unregistered method.

6
MCQhard

A developer registers a tool named get_order_status with an input_schema that declares order_id as a string. During testing, Claude repeatedly emits tool_use blocks where order_id is the numeric value 10482 instead of a string. The downstream API rejects numeric IDs. Which change most reliably fixes this at the tool-definition layer?

A.Add a description to the order_id property stating it must be a string, and include a format or pattern hint in the schema.
B.Set the tool_choice parameter to force get_order_status on every turn.
C.Raise max_tokens so Claude has more room to format the argument correctly.
D.Change input_schema to declare order_id as an integer so the numeric output becomes valid.
AnswerA

Property-level descriptions and schema constraints are part of the tool definition Claude sees, so clarifying that order_id is a quoted string and adding a pattern such as ^[0-9]+ guides generation toward the correct JSON type. This addresses the root cause at the definition layer rather than patching behavior after the fact.

Why this answer

Tool argument types are steered by the tool definition itself, so the durable fix is to make the expected type explicit through property descriptions and schema constraints. Describing order_id as a quoted string with a numeric pattern gives Claude the signal it needs, and validating the payload before calling the downstream API provides defense in depth.

Exam trap

The trap here is treating a schema-clarity problem as a sampling or budget problem and tuning max_tokens instead of the tool definition.

7
MCQmedium

A developer is architecting a system where Claude must interact with a proprietary internal database. According to the Model Context Protocol (MCP) architecture, which component is responsible for surfacing the database schemas and handling the actual execution of the SQL queries?

A.MCP Client
B.MCP Server
C.MCP Transport
D.MCP Host
AnswerB

The server is the foundational block that exposes tools, resources, and prompts to the model. It contains the logic for interacting with external systems like databases or APIs. By hosting the tool definitions, it allows the model to understand how to request data or perform actions within that specific environment.

Why this answer

In the Model Context Protocol architecture, the MCP Server is the specific component designed to host tools and resources. It acts as the interface to local or remote data sources, providing the necessary context and execution environment. Understanding this separation of concerns is vital for developers to ensure that security boundaries and data access are managed correctly within the MCP ecosystem.

Exam trap

Many candidates mistakenly attribute tool execution logic to the AI model itself, forgetting that the model only requests the action while the MCP Server performs the actual database querying and schema exposure.

8
MCQhard

A developer's MCP client launches a local stdio server that exposes a `query_metrics` tool. The server process writes diagnostic log lines to standard output while handling requests. Claude's tool calls intermittently fail with JSON parse errors on the client side. Which change best resolves this?

A.Wrap every log line in a JSON object so the client can skip non-protocol entries automatically.
B.Increase the client's request timeout so slow log writes do not corrupt the response stream.
C.Switch the server to HTTP with Server-Sent Events transport so logging no longer shares a channel with protocol data.
D.Configure the server to write all diagnostic logging to standard error instead of standard output.
AnswerD

For stdio transport, standard output is reserved exclusively for JSON-RPC protocol messages; anything else corrupts the stream. Diagnostic logs must go to standard error, which the client captures separately and does not parse as protocol data. Redirecting the logging removes the interleaved text, so the client once again sees clean JSON-RPC frames and the `query_metrics` calls succeed.

Why this answer

The stdio transport dedicates standard output to JSON-RPC frames and standard error to diagnostics. When a server prints log lines to stdout, the client reads them as protocol data and fails to parse them, which matches the intermittent parse errors. Moving logging to stderr restores a clean protocol channel and lets the `query_metrics` tool calls complete normally without any transport redesign.

Exam trap

The trap here is treating the parse errors as a timing or encoding problem when the real issue is protocol data sharing standard output with log text.

9
MCQeasy

A team wants Claude to query their internal ticketing system through MCP. The operations are read-only lookups and the team wants the model to decide when a lookup is needed based on the conversation. Which MCP primitive is the appropriate choice?

A.MCP Resources exposed by the server.
B.MCP Prompts exposed by the server.
C.MCP Sampling requests initiated by the server.
D.MCP Tools exposed by the server.
AnswerD

Tools are model-invoked functions described by a name, description, and input schema. Claude selects them autonomously when the conversation calls for an action, which matches the requirement that the model decide when a ticketing lookup is needed. Read-only tools are a common and appropriate use of this primitive.

Why this answer

Because Claude must decide on its own when to look up a ticket, the capability needs to be a callable action with a described schema, which is exactly what an MCP tool provides. Resources and prompts are not model-selected actions, and sampling reverses the request direction, so a tool is the correct primitive for this read-only lookup.

Exam trap

The trap here is choosing resources because the data is read-only, when model-driven selection requires a tool rather than a resource.

10
MCQmedium

Which property in the Anthropic Messages API allows a developer to prevent Claude from generating any text before it calls a tool?

A.Set 'tool_choice' to type 'tool' with a specific name.
B.Use the 'stop_sequences' parameter to stop at the first period.
C.Set 'max_tokens' to a very low value like 10.
D.Set the 'system' prompt to 'Do not speak'.
AnswerA

By explicitly setting the tool_choice to a specific tool, you are instructing Claude that its next action must be to call that tool. This typically suppresses the generation of conversational preamble, ensuring that the response starts immediately with the tool_use block, which is ideal for programmatic integrations.

Why this answer

When forcing tool use via the 'tool_choice' parameter with the 'tool' type, the model is instructed to go straight to the tool call. This is useful for building 'router' agents where the goal is to get a structured tool request as quickly as possible without conversational filler or introductory text from the model.

Exam trap

Candidates often confuse 'tool_choice: auto' with 'tool_choice: tool', failing to realize that 'auto' allows the model to choose between text or tools, while 'tool' forces the tool call immediately.

11
Multi-Selecteasy

Which TWO benefits does the Model Context Protocol (MCP) provide to developers building AI-powered applications? (Select TWO)

Select 2 answers
A.It eliminates the need for any JSON schema definitions in tool calls.
B.It allows tools to be reused across different IDEs and AI clients.
C.It automatically converts Python code into optimized model weights.
D.It provides a standardized way to expose local data and tools to LLMs.
E.It guarantees that the model will never hallucinate tool arguments.
AnswersB, D

Because MCP is a standardized protocol, a server written for one application (like Claude Desktop) can be immediately used by any other MCP-compliant client (like a custom VS Code extension). This interoperability significantly reduces the effort required to bring specialized data and tools into different AI environments.

Why this answer

MCP solves the problem of fragmentation in AI tool integration. By providing a standard protocol, it allows developers to build a tool once and use it across different platforms. It also separates the concerns of data retrieval and model logic, making systems more modular, maintainable, and secure by design.

Exam trap

Candidates often focus on LLM performance gains, failing to recognize that MCP's primary value is architectural standardization and tool interoperability across different AI environments, rather than direct model inference speed.

12
MCQmedium

Refer to the exhibit. A developer provides this tool definition to Claude. If a user asks 'What is the tax on $100?', how will Claude likely behave based on the provided JSON schema?

A.Claude will trigger an API error because the state_code is missing from the required list.
B.Claude will call the tool with a default state_code of 'CA'.
C.Claude will likely ask the user which state they are in before calling the tool.
D.Claude will automatically extract the state from the user's IP address.
AnswerC

Since the tool description mentions the calculation depends on the state, and 'state_code' is not provided by the user, Claude's training encourages it to seek clarification. This behavior ensures that the tool is used effectively and that the results provided to the user are accurate and contextually relevant.

Why this answer

The JSON schema defines the contract between the model and the tool. In this exhibit, 'amount' is required, but 'state_code' is not. However, the description implies 'state_code' is necessary for an accurate calculation.

Claude will attempt to follow the schema first, but if it identifies that a critical piece of information for the logic is missing, it may ask for clarification.

Exam trap

Candidates frequently assume that if a property is optional in the JSON schema, Claude will fabricate a default value instead of asking the user for clarification.

13
MCQmedium

When implementing a tool use loop in a custom application, what is the correct sequence of events after the model generates a 'tool_use' content block?

A.The client sends a tool_result message, then Claude generates the final response.
B.Claude automatically executes the code and provides the result in the same turn.
C.The model generates a tool_result block internally and continues the text stream.
D.The client terminates the session and displays the raw JSON output to the user.
AnswerA

After the model outputs a tool_use block, the client application must perform the action and return a message with the tool_result. Claude then processes this new information and generates a follow-up response that integrates the tool's output into a coherent answer for the user, completing the loop.

Why this answer

The tool use loop is a multi-turn process. Once Claude identifies a tool to use, the client must pause the model's generation, execute the underlying code for that tool, and then send the result back to Claude in a new message. This allows the model to incorporate the actual data into its final response.

Exam trap

Candidates often incorrectly assume the model generates the final response immediately after the tool call, missing the mandatory step where the client must explicitly send the tool results back to Claude.

14
MCQeasy

In the Model Context Protocol (MCP) architecture, which component is responsible for providing specific resources, tools, and prompts to the rest of the ecosystem?

A.The MCP Host
B.The MCP Client
C.The MCP Server
D.The MCP Gateway
AnswerC

The MCP Server acts as the source of truth for tools and data. It implements the standard MCP primitives, allowing any compatible host to discover and utilize its specific functions. This modularity ensures that a single server can serve multiple different hosts without requiring custom code for every integration.

Why this answer

MCP is designed as a client-server architecture to standardize how AI models access external data and functions. The MCP Server is the provider in this relationship, exposing specific capabilities such as local files, database schemas, or API integrations. Understanding this role is fundamental for developers building custom integrations that extend Claude's capabilities beyond its training data.

Exam trap

Candidates often confuse the MCP Server with the MCP Client or Host, incorrectly assuming that the AI model itself acts as the provider of local resources and tools.

15
Multi-Selecthard

A developer is implementing a complex MCP Server to expose local file system operations. Which THREE security practices should be prioritized to ensure the server does not compromise the host system? (Select THREE)

Select 3 answers
A.Implement a 'root directory' restriction to prevent path traversal attacks.
B.Use the 'tool_choice' parameter to only allow read-only operations by default.
C.Require human-in-the-loop confirmation for any tool that deletes or modifies files.
D.Sanitize and validate all input parameters against a strict regex or schema.
E.Run the MCP Server with administrative or root privileges for better performance.
AnswersA, C, D

Sandboxing the server to a specific directory ensures that even if the model attempts to access sensitive system files like '/etc/passwd' or user credentials, the server logic will reject the path. This is a fundamental security practice when granting an LLM access to file system operations on a host.

Why this answer

Security in MCP is paramount because tools can perform side effects on the host. Restricting access to specific directories (sandboxing), requiring manual user approval for destructive actions, and validating all inputs against expected patterns are critical layers of defense. These measures prevent the model from accidentally or maliciously accessing sensitive files or executing harmful commands.

Exam trap

Candidates often choose general security practices like 'enable encryption' or 'use API keys', failing to identify that specific MCP risks involve file system traversal and unauthorized destructive actions on host resources.

16
MCQeasy

A company wants Claude to answer questions about their internal HR policies. They are deciding between fine-tuning a model and using a Tool-calling (RAG) approach. Why is Tool-calling usually preferred for this use case?

A.Fine-tuning cannot be used to teach a model new factual information.
B.Tool-calling allows the model to access the most up-to-date policies instantly.
C.Tool-calling is the only way to ensure Claude uses a professional tone.
D.Fine-tuned models are restricted from using tools for security reasons.
AnswerB

By using a tool to search a live policy database, Claude always has access to the most recent documents. When an HR policy is updated, the tool immediately starts returning the new version. This ensures that the model's answers are always current without requiring any retraining or redeployment of the AI.

Why this answer

Tool-calling, often used in Retrieval-Augmented Generation (RAG), is generally superior for internal knowledge bases because it allows for easy updates and provides verifiable citations. Fine-tuning is expensive, time-consuming, and results in a 'frozen' snapshot of data that becomes obsolete as soon as policies change, making it unsuitable for dynamic corporate environments.

Exam trap

Candidates frequently choose fine-tuning for dynamic corporate knowledge bases, underestimating the high cost and rapid obsolescence of baked-in static training data.

17
MCQhard

A developer's MCP client sends a tools/call request for a tool that performs a database write. The tool result comes back with is_error set to true and a message about a unique-constraint violation. What is the most appropriate way for the client to handle this result?

A.Convert the tool result into a plain assistant text message and end the turn without invoking Claude again.
B.Terminate the MCP session and reconnect before retrying the tool call.
C.Discard the result and silently retry the identical tool call up to three times.
D.Surface the error content to Claude as the tool result so it can reason about the failure and adjust its next action.
AnswerD

When is_error is true, the content still carries meaningful diagnostic text. Passing it back to Claude as the tool result lets the model see the constraint violation and decide how to proceed, such as choosing a different value or asking the user. This is the intended error-handling flow for tool calls.

Why this answer

Tool errors are delivered in-band as a tool result with is_error set to true, and the accompanying content is meant to inform the next reasoning step. Returning that result to Claude preserves the conversation loop and lets the model adapt, which is the correct handling for a recoverable data-level failure such as a constraint violation.

Exam trap

The trap here is treating an is_error tool result as a fatal protocol failure and resetting the connection instead of feeding the error back to the model.

18
MCQhard

Claude requests a tool call to 'query_database', but the database is currently down. What is the best practice for handling this error so Claude can inform the user effectively?

A.Return a 500 Internal Server Error to the Anthropic API request.
B.Send a 'tool_result' with is_error: true and a descriptive error message.
C.Omit the 'tool_result' and send a new user message saying 'The tool failed'.
D.Modify the assistant's previous tool_use block to remove the request.
AnswerB

This is the recommended approach. By including the error message in the 'tool_result' block and marking it with 'is_error: true', you provide Claude with the context of the failure. Claude can then use its reasoning capabilities to apologize to the user and offer helpful next steps.

Why this answer

Graceful error handling is vital for a good user experience. Instead of failing the entire API request, the developer should return the error message within the 'tool_result' block. By setting 'is_error' to true, the developer signals to Claude that the tool failed, allowing the model to explain the situation to the user.

Exam trap

Candidates often try to catch the error in the application code and return a standard text response, which breaks the Claude tool-use conversation loop.

19
Multi-Selectmedium

A developer is writing an MCP client that must stay responsive while a server performs a slow operation during a tool call. The client should allow the user to cancel the request without terminating the whole session, and the server should be able to stream incremental output before finishing. Which two MCP features should the developer implement? (Choose two.)

Select 2 answers
A.Request cancellation using the notifications/cancelled notification with the in-flight request ID.
B.Polling tools/list repeatedly to detect when the tool has finished executing.
C.Closing the transport and reinitializing the session to interrupt the operation.
D.Progress notifications sent from the server using the progress token supplied by the client.
E.Setting a long client-side timeout and retrying the same request until it succeeds.
AnswersA, D

A client can cancel an in-flight request by sending notifications/cancelled with the request ID it wants to abort. The server stops work on that specific request while the session and other requests continue, which matches the requirement to cancel without tearing down the whole connection.

Why this answer

Long-running MCP operations are handled with progress notifications tied to a client-supplied progress token and with out-of-band cancellation via notifications/cancelled. Together they let a server report partial progress and let a client abort one request without disturbing the session, which is precisely the behavior the scenario demands.

Exam trap

The trap here is reaching for connection teardown or retries to interrupt slow work, when MCP provides per-request progress and cancellation messages.

20
MCQhard

A developer is implementing an MCP client that connects to a remote MCP server over HTTP. The server requires authentication using an API key. The developer wants to ensure that all requests from the client include the API key in the headers. Which approach is correct for configuring the MCP client?

A.Include the API key in the body of each MCP JSON-RPC request.
B.Set the API key in the 'Authorization' header when establishing the HTTP connection to the MCP server.
C.Pass the API key as an environment variable when starting the MCP server process.
D.Include the API key as a query parameter in the MCP server URL.
AnswerB

MCP over HTTP uses standard HTTP headers for authentication. The 'Authorization' header, often with a Bearer token or API key, is the correct place to include credentials. The MCP client should be configured to add this header to all requests, ensuring the server can authenticate each call. This is consistent with common HTTP authentication practices.

Why this answer

The correct approach is to set the API key in the 'Authorization' header of the HTTP connection. MCP over HTTP relies on standard HTTP authentication mechanisms, and headers are the appropriate place for credentials. Other methods either misuse query parameters, confuse client and server roles, or attempt to embed authentication in the JSON-RPC body, which is not standard.

Exam trap

The trap here is assuming that MCP has a custom authentication field in the JSON-RPC body or that API keys can be passed via query parameters, when in fact standard HTTP headers are used.

21
MCQhard

Refer to the exhibit. Claude has generated two 'tool_use' blocks in a single response. Which approach is valid for handling these calls in the client application?

A.The client must execute them sequentially to avoid race conditions in the API.
B.The client can execute them in parallel and must return two tool_result blocks.
C.The client should combine both results into a single tool_result block.
D.The client must discard the second call and only process the first one.
AnswerB

Parallel execution is a powerful feature that allows for faster response times. The client can initiate both stock price lookups simultaneously. When the results are ready, the client must send a new message back to the API containing two distinct tool_result blocks, each referencing the correct original tool_use_id.

Why this answer

Claude supports parallel tool use, allowing it to request multiple operations at once to improve efficiency. The client can execute these calls in parallel or sequentially, but it must return a separate tool_result block for each tool_use block, ensuring the 'tool_use_id' in the result matches the 'id' provided by the model.

Exam trap

Candidates incorrectly believe that Claude must process tool calls one by one, missing the capability of the API to handle multiple 'tool_use' blocks in a single response for parallel execution.

22
MCQhard

Claude generates a response containing three separate 'tool_use' blocks in a single turn. How should the developer process these tool calls to maintain optimal performance and follow Anthropic's best practices?

A.Process each tool call sequentially to avoid race conditions in the model.
B.Only execute the first tool call and ignore the others to prevent token bloat.
C.Execute all tools in parallel and return all results in one user message.
D.Ask the user to prioritize which of the three tools should be run first.
AnswerC

This is the most efficient pattern. Parallel execution reduces latency, and providing all 'tool_result' blocks in a single follow-up 'user' message fulfills the API requirement. This ensures Claude has all the necessary information at once to synthesize the final answer for the user in the next turn.

Why this answer

Claude is capable of requesting multiple tool calls simultaneously if the user's request requires it. To minimize latency, developers should execute these calls in parallel whenever possible. Once all results are gathered, they must be returned to Claude in the same sequence and within a single user message to continue the conversation.

Exam trap

Candidates often attempt to return tool results across multiple sequential user messages or execute them serially, increasing latency and violating API guidelines.

23
MCQeasy

A developer is adding a 'calculate_shipping' tool to an existing MCP server used by a Claude-based checkout assistant. The tool needs the destination country, package weight in kilograms, and an optional express flag. Which tool definition practice will MOST reliably let Claude call the tool correctly?

A.Omit the input schema entirely and rely on the tool name 'calculate_shipping' to imply the required arguments.
B.Define an input schema with typed properties for country, weight_kg, and express, mark the first two as required, and write a description that explains units and when to use the tool.
C.Set every property as required, including express, and instruct Claude to pass false when the user does not mention express shipping.
D.Accept a single free-form 'details' string and parse it inside the tool handler, since Claude writes natural language well.
AnswerB

A clear JSON Schema with explicit types, required fields, and unit documentation gives Claude the information it needs to produce valid arguments. Marking only country and weight_kg as required reflects the optional express flag, reducing malformed calls. The description guides tool selection, while the schema enforces structure, which is the combination that most reliably yields correct invocations in an MCP tool definition.

Why this answer

Tool definitions work best when the schema encodes structure and the description encodes intent. Typed properties for country, weight_kg, and express, with only the truly necessary fields required, give Claude an unambiguous contract. Documenting units and usage in the description helps the model choose the tool and format arguments correctly, which is the most reliable path to accurate invocations.

Exam trap

The trap here is assuming a descriptive tool name or a free-form string is enough, when Claude needs a typed input schema to produce valid arguments.

24
MCQhard

Refer to the exhibit. A developer provides this tool definition to Claude. If the user asks for the weather in 'London' without specifying a unit, how will Claude's tool_use block be structured based on this JSON schema?

A.It will include only the 'location' parameter in the input object.
B.It will fail with a validation error because 'unit' is missing.
C.It will prompt the user to choose between 'celsius' and 'fahrenheit' first.
D.It will default the 'unit' to 'celsius' automatically.
AnswerA

Because 'unit' is not listed in the 'required' array, the model will omit it if the information is missing from the user's prompt. Claude generates the most concise valid JSON object that satisfies the schema requirements, ensuring that optional fields do not contain hallucinated or default values unless specifically prompted.

Why this answer

Claude follows the provided JSON schema strictly when generating tool calls. Since the 'unit' property is not included in the 'required' array, Claude is not obligated to provide it if the user does not specify it. This behavior demonstrates Claude's ability to handle optional parameters while adhering to the structure defined in the tool's input_schema field.

Exam trap

Candidates frequently assume that Claude will hallucinate or include optional parameters in the tool use block even when the user completely omits them.

25
MCQmedium

A developer is using the 'forced tool use' feature. What will be the value of the 'stop_reason' field in the API response when Claude generates the tool call?

A.end_turn
B.max_tokens
C.tool_use
D.stop_sequence
AnswerC

When Claude generates a tool_use block, it signals this by setting the 'stop_reason' to 'tool_use'. This is the programmatic trigger for the client application to parse the response, find the tool call, execute the corresponding logic, and then send the result back to the model for further processing.

Why this answer

The 'stop_reason' field indicates why the model stopped generating text. When the model is forced to use a tool, or when it naturally decides to use one, it stops its current generation turn to allow the client to execute the tool. The value 'tool_use' is the specific indicator for this state.

Exam trap

Candidates often confuse 'tool_use' with 'stop' or 'end_turn', failing to realize that the API specifically signals a tool invocation request as its own distinct stop reason during the generation process.

26
MCQmedium

A developer is implementing a weather-reporting agent using Claude 3.5 Sonnet. After Claude generates a tool_use block for the 'get_weather' tool, the developer fetches the data. What is the correct next step to ensure Claude can finalize its response to the user?

A.Append the tool results directly to the end of the previous assistant message.
B.Send a new user message containing a 'tool_result' block with the 'tool_use_id'.
C.Update the system prompt with the new weather data and restart the session.
D.Issue a second assistant message that includes the weather data as a JSON string.
AnswerB

Sending a user message with a 'tool_result' block is the mandatory way to provide data back to Claude. The 'tool_use_id' must match the ID provided by Claude in the previous turn, enabling the model to link the result to the specific request it made, ensuring logical consistency in complex workflows.

Why this answer

The tool use lifecycle requires a multi-turn interaction where the model first requests a tool execution. Once the developer executes the tool locally, they must return the result to Claude in a new 'user' message with a 'tool_result' block. This allows Claude to incorporate the external data into its final synthesis and provide an accurate answer to the original query.

Exam trap

Candidates often try to send the tool result as a new 'assistant' message or a standard user message without the required 'tool_result' block, breaking the expected tool-use protocol.

27
Multi-Selecthard

A developer is building an MCP server that exposes several tools for managing a cloud infrastructure. The server will be used by multiple Claude clients. The developer wants to ensure that tool calls are handled efficiently and that the server can scale. Which two practices should the developer implement? (Choose two.)

Select 2 answers
A.Cache the results of expensive tool calls on the server side and return cached responses for identical requests.
B.Design tools to be idempotent where possible, so that repeated calls with the same parameters produce the same result.
C.Use a single global lock to serialize all tool calls, preventing concurrent execution.
D.Implement the server to handle each tool call statelessly, so that any instance can process any request.
E.Store session state in memory on each server instance to track client interactions.
AnswersB, D

Idempotency ensures that if a tool call is retried due to network issues or client retries, it does not cause unintended side effects like creating duplicate resources. This is crucial for infrastructure management where operations like provisioning or deletion should be safe to repeat. It improves reliability and simplifies error handling, contributing to efficient scaling.

Why this answer

The two best practices are statelessness and idempotency. Statelessness allows any server instance to handle any request, enabling horizontal scaling. Idempotency ensures that retries are safe, which is important for reliable infrastructure operations.

Together, they improve efficiency and scalability. Other options like caching, global locking, or in-memory session state either introduce complexity or hinder scalability.

Exam trap

The trap here is focusing on performance optimizations like caching or session tracking, when the fundamental practices for scalable MCP servers are statelessness and idempotency.

28
Multi-Selectmedium

A developer is building an MCP client that connects to a remote MCP server over HTTP with Server-Sent Events. The server advertises tools that require user-specific permissions. Which TWO practices should the developer implement to keep the integration secure and functional? (Choose two.)

Select 2 answers
A.Validate the server's identity and TLS certificate, and reject connections that fail certificate verification.
B.Authenticate the connection using the server's supported OAuth flow and pass the resulting access token with each request.
C.Hard-code a shared service account token in the client binary so all users inherit the same permissions.
D.Disable TLS termination to reduce latency, since MCP messages are already structured JSON.
E.Cache all tool results on the client indefinitely so users avoid repeated permission checks.
AnswersA, B

Because the client sends credentials and receives tool results over the network, verifying the server's TLS certificate prevents man-in-the-middle attacks and credential theft. Rejecting connections that fail verification ensures the client only talks to the legitimate MCP server. This complements authentication by protecting the confidentiality and integrity of the session, which is essential when tools are permission-scoped.

Why this answer

Remote MCP servers with permission-scoped tools require two things: proof of who the user is, and protection of the channel carrying that proof. Completing the server's OAuth flow and sending the access token satisfies authentication, while validating TLS certificates prevents interception or impersonation. Shared credentials, plaintext transport, and indefinite caching all undermine per-user authorization and would make the integration both insecure and unreliable.

Exam trap

The trap here is treating MCP's JSON message format as if it provided security, leading to choices that skip authentication or TLS.

29
MCQmedium

A developer is building a Claude-powered assistant that uses a tool called 'search_knowledge_base'. The tool definition includes a required parameter 'query' and an optional 'max_results' parameter. During testing, Claude sometimes calls the tool without providing 'max_results'. What should the developer do to ensure the tool call is handled correctly?

A.Add a description to the tool definition instructing Claude to always include 'max_results' with a value of 10.
B.In the tool implementation, check if 'max_results' is present and apply a sensible default value if it is missing.
C.Change the tool to accept a single string parameter that combines the query and max_results, such as 'query|max_results'.
D.Make 'max_results' a required parameter in the tool definition so Claude must always provide it.
AnswerB

Since 'max_results' is optional, Claude may omit it. The tool implementation should detect its absence and use a default value, such as 5 or 10, to ensure consistent behavior. This keeps the tool definition accurate while handling the missing parameter gracefully, preventing errors and providing predictable results.

Why this answer

Because 'max_results' is optional, Claude may omit it. The tool implementation should check for its presence and apply a default value, ensuring the tool works correctly regardless. This approach maintains the intended flexibility of the tool definition and prevents runtime errors.

Other options either incorrectly change the tool contract or rely on unreliable prompting.

Exam trap

The trap here is assuming that Claude will always include optional parameters or that a description can enforce it, rather than handling missing optional parameters with defaults in the tool code.

30
MCQhard

A developer is writing a tool called `send_email` for a Claude-based assistant. The tool's description currently reads: 'Sends an email.' During testing, Claude calls the tool for tasks like drafting an email or checking inbox contents. Which revision to the tool definition most directly improves Claude's decision about when to invoke `send_email`?

A.Set `input_schema` to `type: "object"` with `additionalProperties: false` to lock down the parameter set.
B.Rename the tool from `send_email` to `email` and rely on the shorter name to signal its broader role.
C.Rewrite the description to state precisely what the tool does, when to use it, and when not to use it, such as only when the user explicitly asks to send a message.
D.Add a `required` array listing `to`, `subject`, and `body` in the input schema.
AnswerC

Tool descriptions are the primary signal Claude uses to decide whether a tool applies. Stating the exact action, the trigger conditions, and explicit exclusions such as drafting or inbox retrieval gives the model the boundaries it needs. This directly addresses the over-invocation observed in testing, because Claude now has criteria to distinguish sending from drafting or reading messages.

Why this answer

The model chooses tools primarily from their descriptions, so a vague one like 'Sends an email' invites calls for drafting or inbox checks. A description that states the exact action, the conditions that should trigger it, and explicit non-triggers such as drafting or retrieving messages gives Claude the criteria it needs. Schema changes and renaming affect argument validity or naming, not the decision of when the tool applies.

Exam trap

The trap here is assuming stricter schemas or shorter tool names fix misuse, when the real lever is the natural-language description that guides tool selection.

31
MCQeasy

Which field in the tool definition is primarily responsible for helping Claude determine when a specific tool is appropriate to use for a given user query?

A.name
B.description
C.input_schema
D.tool_choice
AnswerB

The description field provides a natural language explanation of what the tool does. Claude uses this text to perform semantic mapping between the user's request and the tool's capabilities. Providing a clear, detailed description is the most effective way to improve the reliability of tool selection by the model.

Why this answer

The 'description' field is the primary source of information for Claude's reasoning. It provides the semantic context that the model uses to match user intent to the available functions. A well-written description is crucial for accurate tool selection and helps the model understand the utility and limitations of each tool.

Exam trap

Candidates frequently assume the 'name' or 'parameters' field is the primary driver for tool selection, overlooking the fact that the 'description' is the critical semantic signal Claude uses to evaluate relevance.

32
MCQmedium

An MCP Server is connected to a Host using the Stdio transport. If the server process crashes, how does the MCP architecture generally handle the reconnection logic?

A.The MCP Client sends a 'heartbeat' signal to automatically restart the server.
B.The MCP Server uses a sidecar process to monitor its own health and restart.
C.The Host application detects the closed stream and must manage the restart.
D.The Model will identify the crash and suggest a fix to the developer.
AnswerC

In a Stdio transport configuration, the Host is the parent process that spawned the Server. When the Server crashes, the Host's read/write pipes are broken. It is the Host's responsibility to handle this exception, inform the user, and decide whether to attempt to re-initialize the server process.

Why this answer

The Stdio transport relies on standard input and output streams for communication between the host and the server. Because this is a process-level connection, a crash usually results in the termination of the stream. The responsibility for detecting this failure and initiating a recovery or restart lies with the MCP Host application.

Exam trap

Candidates often assume the MCP server automatically restarts itself or that the protocol layer handles crash recovery independently of the host application.

33
MCQhard

When using tool use with streaming enabled in the Anthropic API, how does the client receive the tool arguments?

A.As a single, complete JSON object in the first stream event.
B.Through incremental 'input_json' deltas within content block events.
C.Via a separate WebSocket channel dedicated to tool execution.
D.As a Base64 encoded string at the end of the message stream.
AnswerB

This is the correct behavior for streaming. The client must listen for 'content_block_delta' events where the delta type is 'input_json_delta'. Each delta contains a piece of the JSON string. The client concatenates these strings until the block is finished, at which point the full JSON can be safely parsed.

Why this answer

Streaming tool use involves receiving the tool call in parts. The client receives a 'content_block_start' for the tool_use, followed by multiple 'content_block_delta' events containing fragments of the JSON in the 'input_json' field. The client must accumulate these fragments and parse the final JSON string only after the 'content_block_stop' event.

Exam trap

Candidates often expect the full tool arguments to appear in a single event, failing to account for the streaming nature of the API where JSON fragments arrive incrementally via delta events.

34
MCQmedium

In the context of MCP, what is the primary purpose of the 'List Resources' capability of a server?

A.To provide a directory of available functions the model can execute.
B.To allow the client to discover data sources that can be read by the model.
C.To enumerate the hardware specifications of the host machine.
D.To list the active connections currently handled by the MCP Client.
AnswerB

Resources represent the 'data' layer of MCP. Listing resources allows an AI assistant to see what information is available in its environment. For example, a server could list all the CSV files in a folder as resources, which the model can then selectively read to answer user questions.

Why this answer

Resources in MCP are a way for servers to expose data that is not necessarily an executable tool. The 'List Resources' capability allows the client to see what data sources are available—such as log files, database tables, or documentation—so the model can then 'read' those resources to gain context for its tasks.

Exam trap

Candidates often confuse resources with executable tools, incorrectly thinking that listing resources allows Claude to run functions rather than read data.

35
Multi-Selecthard

A developer is hardening a remote MCP server that exposes a 'run_query' tool against a production analytics database. The server will be reachable over HTTP by multiple Claude clients. Which TWO practices are MOST important to prevent the tool from being abused? (Choose two.)

Select 2 answers
A.Embed the production database connection string in the tool description so Claude can decide when the query is safe to run.
B.Require authentication and authorization on the MCP server so only approved clients can invoke 'run_query', and scope the database credentials to read-only.
C.Validate and parameterize all SQL inside the tool handler instead of concatenating model-supplied strings into the query.
D.Increase the 'max_tokens' value on every Claude request so the model has enough room to reason about query safety before calling the tool.
E.Return the full database error message, including schema names and stack traces, to Claude so it can self-correct failed queries.
AnswersB, C

A remote HTTP MCP server is an API surface; without authentication, anyone who can reach it can call the tool. Pairing client authentication with least-privilege database credentials ensures that even a compromised client cannot drop tables or read unrelated schemas. This combination addresses both who may call the tool and what the tool can do once called, which is essential for a production analytics endpoint exposed to multiple clients.

Why this answer

Hardening a remote MCP tool requires controls at the trust boundary and at the data layer. Authenticating clients and scoping database credentials to read-only limits who can invoke the tool and what it can do. Parameterizing and validating SQL ensures model-supplied arguments cannot alter query structure.

Together these reduce the impact of prompt injection, hallucinated arguments, and unauthorized access to a production analytics database.

Exam trap

The trap here is treating model reasoning or token budget as a security control, when MCP tool safety must be enforced by authentication and input handling on the server.

36
MCQeasy

A developer is integrating a new MCP server that exposes a company's internal HR policy documents. The server implements the Resources capability. The developer wants Claude to access a specific policy document only when the user explicitly asks about it, rather than loading all documents into context upfront. Which MCP method should the developer use to retrieve the content of a single resource by its URI?

A.resources/list
B.resources/templates/list
C.resources/read
D.resources/subscribe
AnswerC

resources/read is the MCP method that retrieves the content of a specific resource identified by its URI. In this scenario, the developer wants to fetch only the requested HR policy document on demand, which is exactly what resources/read provides. The server returns the resource contents, and Claude can then use that information to answer the user's question without preloading all documents.

Why this answer

The correct method is resources/read because it retrieves the content of a specific resource by URI, which matches the need to fetch a single HR policy document on demand. Other resource-related methods like list, subscribe, or templates/list provide metadata or notifications, not the actual document body. Using resources/read avoids preloading all documents into context and keeps the interaction efficient.

Exam trap

The trap here is confusing resource discovery methods like resources/list or resources/templates/list with the method that actually returns resource content, which is resources/read.

37
Multi-Selecthard

A security auditor is reviewing an application that uses the Model Context Protocol (MCP). Which TWO security considerations are most important for the developer to address when implementing the MCP Server?

Select 2 answers
A.The server should strictly validate all tool arguments against its internal logic.
B.The server must use a unique API key for every tool call it receives.
C.The server should restrict resource access to specific, pre-approved directories.
D.The server must rotate its connection ID every sixty seconds for privacy.
E.All MCP tool results must be manually approved by a human operator.
AnswersA, C

Even though Claude follows the JSON schema, it can still generate malicious or unexpected inputs if prompted by a user. The MCP server must treat all model-generated arguments as untrusted input, performing rigorous validation and sanitization to prevent attacks like SQL injection, path traversal, or remote code execution.

Why this answer

Security in MCP is a shared responsibility. While the protocol facilitates communication, the server developer must ensure that the tools and resources exposed do not create vulnerabilities. This includes limiting access to the file system and ensuring that tool inputs are properly validated before being used in potentially dangerous operations like shell commands.

Exam trap

Candidates often rely solely on the AI model to sanitize inputs, forgetting that server-side validation and path restriction are critical security necessities.

38
MCQmedium

If a tool execution fails due to an external API timeout, how should the client properly communicate this error to Claude using the Anthropic API?

A.Send a tool_result with the content 'Error: Timeout' and set is_error: true.
B.Raise an HTTP 500 error in the final API response to the user.
C.Omit the tool_result block and ask the model to try again in a new prompt.
D.Return an empty tool_result content block to signal a null response.
AnswerA

Setting 'is_error: true' is the standard way to notify Claude that the tool execution failed. By providing a descriptive error message in the content, you give the model enough context to handle the failure gracefully, such as by apologizing to the user or suggesting an alternative course of action.

Why this answer

Error handling in tool use is critical for the model to understand what went wrong. The client should return a tool_result message with the 'is_error' field set to 'true'. This signals to Claude that the tool call was unsuccessful, allowing the model to either retry, explain the error to the user, or try a different approach.

Exam trap

Candidates often try to return a normal text message explaining the error or simply stop the chain, failing to use the mandatory 'is_error: true' flag required for the API to process failures.

39
MCQmedium

When using Claude's tool use features in a streaming response, how should the developer handle the 'tool_use' blocks in the stream?

A.Execute the tool as soon as the 'name' property is received in the stream.
B.Wait for the 'message_stop' event before parsing any tool_use blocks.
C.Accumulate tool_use delta events until a 'content_block_stop' event is received.
D.Streaming is not supported when using tools; use the synchronous API instead.
AnswerC

In the Anthropic streaming API, each content block (text or tool_use) is bracketed by start and stop events. By listening for the 'content_block_stop' event for a 'tool_use' block, the developer ensures they have the full, valid JSON for the tool call and can safely execute it locally.

Why this answer

Streaming with tool use requires careful handling of partial blocks. As Claude streams its response, it may start a 'tool_use' block. The developer must accumulate these fragments until the block is complete before attempting to execute the tool, as the arguments and even the tool name may be delivered across multiple chunks.

Exam trap

Candidates attempt to execute tool calls immediately upon receiving the first streaming chunk, leading to incomplete argument parsing and runtime errors.

Ready to test yourself?

Try a timed practice session using only Tools and MCP Integration questions.