Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft AI-500 Exam - Topic 3 Question 4 Discussion

You have a Microsoft Foundry project that contains an incident triage agent.You have a Model Context Protocol (MCP) server registered in the organizational tool catalog. The MCP server exposes two tools named docs_search and deployment_delete.You need to ensure that the agent can only invoke docs_search.What should you configure?
C) the agent tool configuration
A) the project details
B) the agent run configuration
D) the agent instructions

Microsoft AI-500 Exam - Topic 3 Question 4 Discussion

Actual exam question for Microsoft's AI-500 exam
Question #: 4
Topic #: 3
[All AI-500 Questions]

You have a Microsoft Foundry project that contains an incident triage agent.

You have a Model Context Protocol (MCP) server registered in the organizational tool catalog. The MCP server exposes two tools named docs_search and deployment_delete.

You need to ensure that the agent can only invoke docs_search.

What should you configure?

Show Suggested Answer Hide Answer
Suggested Answer: C

The restriction belongs in the agent's MCP tool configuration because Microsoft Foundry supports an `allowed_tools` allowlist that controls which tools discovered from an MCP server are exposed to the agent. Configuring the allowlist to include only `docs_search` makes `deployment_delete` unavailable for model selection. This is stronger than adding a sentence to the agent instructions because instructions influence behavior but do not remove a dangerous tool from the callable surface. Project details describe resources rather than per-agent tool exposure, and a transient run setting is not the appropriate persistent configuration boundary for the registered MCP integration. Therefore C, the agent tool configuration, is the correct answer. Least privilege remains the governing principle: grant only the identity, data, tool, or deployment access required for the specific operation. The selected answer preserves that boundary while still allowing the workflow to satisfy its functional requirement. From a security and governance perspective, the control should be enforced at the narrowest platform boundary that can deterministically block or constrain the action. Relying only on prompt text is weaker because the model can still be induced to behave unexpectedly.

Official Microsoft reference: Microsoft Foundry agents - Model Context Protocol tools


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel