Quiz 8 Question 20 of 20

An MCP server is being designed to expose a company's internal SQL database to Claude-powered agents. The server implements a run_query tool that accepts arbitrary SQL strings. During a security review, a red-teamer demonstrates that an agent can be prompted to run DROP TABLE via this tool. What MCP server-side control is the most appropriate architectural response?

Select an answer to reveal the explanation.

Motivation