Skip to content
CCDV-F
Tools and MCPs
hard
Question 1 of 20

A developer creates an agent tool that executes shell commands on a Linux server. The tool passes Claude's generated command string directly to the system shell with no input validation. A user submits a prompt asking to "read the company secrets file" and Claude generates a command that reads /etc/passwd and other sensitive system files. Which vulnerability type is this, and what is the correct mitigation?

A
B
C
D

This question requires Pro

Unlock all 20 questions in this certification

Written by certified professionals · Aligned to official exam objectives

View all Pro features

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy