Trust Boundaries
Where the boundaries lie between user, host, client, server, and external systems — and how the host enforces isolation between servers.
Exam weight: 24%
This domain covers the security model of MCP: where trust boundaries lie, how permissions and consent work, known risks and their mitigations, and how MCP deployments are audited and observed.
Trust Boundaries
Where the boundaries lie between user, host, client, server, and external systems — and how the host enforces isolation between servers.
Permissions & Consent
The spec’s security principles — user consent and control, data privacy, and tool safety — and who enforces them.
Risk & Safety Controls
Common attack vectors — prompt injection, tool poisoning, confused deputy, token passthrough — and their mitigations.
Auditability & Observability
What to log and monitor in an MCP deployment, and how to keep audit trails accurate and free of secrets.
After studying this domain you should be able to: