問題文
A security review asks whether the agent firewall protects against a malicious MCP server exfiltrating data. What is the correct answer?
選択肢
- It does once the recommended allowlist is disabled, because the default entries are what let traffic out to unvetted hosts.
- It does for locally launched servers but not for remote ones, since a remote server's traffic never enters the agent's environment in the first place.
- It does protect against this, because every piece of outbound traffic leaving the isolated environment is forced through the firewall regardless of which process opened the connection or how that process was started.
- It does not, because the firewall only applies to processes the agent starts through its shell tool and does not apply to MCP servers or processes started in the setup steps.