These are the Check Yourself questions from each page of the module, collected in course order. Each heading links back to the page the questions test. All module quizzes →
Check yourself 0 / 4 answered
Which MCP primitive is controlled by the model rather than the application or user?
A Tools B Resources C Prompts D Roots In an MCP deployment, how many servers does one MCP client connect to?
A One B All servers configured in the host C One per tool D Any number, chosen per request Which statement about MCP is true?
A It standardises how applications discover and call tools, but trust and tool-use decisions stay with the host B It guarantees tools are safe to call C It replaces the agent loop D It is a Claude-only feature Your support agent needs to delegate a fraud investigation to another team's agent, which works for hours and asks follow-up questions. MCP or A2A?
Show answer
Check yourself 0 / 5 answered
In the 2026-07-28 revision, where does a client declare its protocol version and capabilities?
A In _meta on every request (and the MCP-Protocol-Version header on HTTP) B In an initialize request at connection start C In the Mcp-Session-Id header D In server/discover's response A tool needs the user's confirmation before a large refund. What does a 2026-07-28 server do?
A Return an InputRequiredResult with an elicitation request; the client retries the call with inputResponses B Send an elicitation/create request to the client over the open SSE stream C Return isError: true D Store the pending call in the session Why must a server treat requestState as attacker-controlled?
A It travels through the client, which could modify or replay it B It is encrypted by the client C It is visible to the model D JSON-RPC requires it Why should tools/list return tools in a deterministic order?
A So clients can cache it and the model's prompt prefix stays identical, preserving prompt caching B The model reads tools in order of importance C Alphabetical order is required by JSON-RPC D To make the list shorter What is the difference between a JSON-RPC error and a result with isError: true?
Show answer
Check yourself 0 / 5 answered
A server's tool is annotated readOnlyHint: true. What should a client do with that?
A Use it for UI hints if the server is trusted; never base security decisions on it for untrusted servers B Always auto-approve the tool C Reject the tool D Ignore annotations entirely Your server needs the user's Stripe API key to finish a request. How should it get it?
A URL-mode elicitation to a page on the server's own domain B Form-mode elicitation with a password field C Ask the model to request it in chat D Read it from the MCP access token What must accompany structuredContent for backwards compatibility?
A The same JSON serialised in a text content block B An image rendering C A resource link D Nothing Which is the recommended replacement for sampling?
A Call a model provider API directly from the server B Elicitation C Resources D Prompts Should a company style guide be a tool, a resource or a prompt?
Show answer
Check yourself 0 / 5 answered
How does an MCP client learn which authorization server protects a server it has never seen?
A From the server's Protected Resource Metadata (RFC 9728), linked in the 401 WWW-Authenticate header or at a well-known URI B It must be configured manually C From the MCP initialize response D From DNS TXT records What does the RFC 8707 resource parameter achieve?
A It binds the token to one MCP server, so it can't be replayed against another B It encrypts the token C It lists the tools the client may call D It replaces PKCE Which client registration mechanism does 2026-07-28 deprecate?
A Dynamic Client Registration (RFC 7591) B Client ID Metadata Documents C Pre-registration D PKCE Your MCP server wraps the GitHub API. Can it forward the user's MCP access token to GitHub?
A No - that is token passthrough; the server must obtain its own GitHub token for the user B Yes, if the scopes match C Yes, over HTTPS D Only for read operations A tool needs a write scope the current token lacks. Describe the exchange.
Show answer
Check yourself 0 / 4 answered
Old code does from mcp.server.fastmcp import FastMCP and fails on mcp 2.x. What is the fix?
A Use from mcp.server.mcpserver import MCPServer (and move transport options to run()), or pin mcp<2 B Install fastmcp and change nothing else C Downgrade Python D Use the low-level Server only Why does the lab's refund tool use a Resolve dependency instead of calling ctx.elicit() inside the tool?
A ctx.elicit sends a server-initiated request, which only exists on legacy connections; the resolver returns an InputRequiredResult that works on 2026-07-28 B ctx.elicit was removed from the SDK C Resolvers are faster D Elicitation needs a resource What is the quickest way to test an MCP server's tools without starting a process or a network listener?
A Pass the MCPServer object to Client(...) and call it in-process B Run it under stdio C Use a hosted connector D Only via the Inspector When would you use a provider-hosted MCP connector rather than your own client?
Show answer
Check yourself 0 / 4 answered
A server changes a tool's description two weeks after you approved it. What is this attack called, and what detects it?
A A rug pull; pinning a hash of each tool definition and re-prompting on change B Tool shadowing; OAuth scopes C SSRF; an egress proxy D Token passthrough; audience validation Which combination forms the lethal trifecta?
A Private data access, exposure to untrusted content, and external communication B Many tools, a large model and long context C OAuth, stdio and HTTP D Memory, planning and reflection In the GitHub MCP exploit, which defence would have broken the attack most reliably?
A A token scoped to the single repository being worked on B A longer system prompt telling the model to ignore issues C A bigger model D Structured output Why is 'the model is trained to resist prompt injection' not a sufficient defence?
Show answer
Check yourself 0 / 5 answered
Where does a client agent find a remote agent's skills, endpoint and auth requirements?
A Its Agent Card, typically at /.well-known/agent-card.json B Its MCP tools/list C A DNS TXT record D The first task's artifact Which task states are interrupted (the task waits for the client) rather than terminal?
A INPUT_REQUIRED and AUTH_REQUIRED B COMPLETED and FAILED C SUBMITTED and WORKING D CANCELED and REJECTED A task will take about six hours and the client may disconnect. How should it follow the task?
A Register a push-notification webhook (and poll GetTask as a fallback) B Keep a streaming connection open for six hours C Call SendMessage repeatedly D Use MCP instead What threat do signed Agent Cards address?
A A forged card that impersonates an agent and redirects traffic to an attacker B Prompt injection inside artifacts C Slow tasks D Token expiry Your planner agent calls a summarisation step that lives in the same codebase and deploys with it. Should that be A2A?
Show answer
Check yourself 0 / 3 answered
What happens on the wire when refund_item needs confirmation?
A tools/call returns an InputRequiredResult with an elicitation request; the client retries tools/call with inputResponses B The server sends an elicitation/create request over the SSE stream C The server keeps the call open until the user answers D The tool returns isError and the model asks the user Why can mcp_agent.py grade the server's database but a client of the HTTP server can't?
A It builds the server in-process and keeps a reference to its Shop object B HTTP servers don't store state C The HTTP server uses a different database D Grading requires stdio Pinning detected the poisoned description. Why is the Guard still worth having?
Show answer