Quiz 13 Question 19 of 20

A Copilot agent is given an MCP tool that executes arbitrary shell commands on a build server to run tests. The tool runs with the same user account that owns the build server's CI/CD credentials. A security engineer proposes sandboxing. Which sandboxing approach provides the strongest security boundary for this tool's execution environment?

Select an answer to reveal the explanation.

Motivation