Marketing Cloud Software Salesforce Marketing Cloud Administrator 2 — Questions and Answers
Question 1: A Marketing Cloud Administrator needs to allow a third-party vendor to access only the Email Studio API without granting full account access. What is the correct approach?
- Create a new MID and assign the vendor as an Admin user
- Use Installed Packages to create an API integration with specific scope permissions (Correct answer)
- Share the primary account credentials with limited IP restrictions
- Configure a Server-to-Server OAuth integration under the main account user
Correct answer: Use Installed Packages to create an API integration with specific scope permissions
Installed Packages in Setup allow you to create API integrations with granular OAuth scopes, limiting vendor access to only the required functionality.
Question 2: Which setting in Marketing Cloud controls whether child Business Units can share content from the parent account's Content Builder library?
- Shared Data Extensions toggle in Email Studio
- Cross-Business-Unit Sharing enabled in Enterprise Settings
- Content Sharing configured via the parent BU's Content Builder settings (Correct answer)
- Data Sharing Policy under the Admin panel
Correct answer: Content Sharing configured via the parent BU's Content Builder settings
Content sharing across Business Units is managed within Content Builder settings on the parent BU, allowing child BUs to access shared folders.
Question 3: An administrator is troubleshooting why automated sends are failing overnight. Logs show 'Send Throttle Exceeded.' What should the admin check first?
- The From address reputation in Email Studio
- The account's hourly and daily send volume limits in Account Settings (Correct answer)
- The Automation Studio activity queue backlog
- The IP warming schedule for the sending domain
Correct answer: The account's hourly and daily send volume limits in Account Settings
Send throttle limits are configured in Account Settings and define maximum hourly/daily volumes; exceeding them causes automated sends to queue or fail.
Question 4: A company uses Marketing Cloud Connect with Salesforce CRM. After a sync, contact records are missing in the Synchronized Data Extensions. What is the MOST likely cause?
- The Marketing Cloud user lacks the 'Salesforce Integration User' profile
- The CRM org's Marketing User checkbox is not enabled on the synced user (Correct answer)
- The Data Extension's primary key does not match the CRM Contact ID field
- The Connected App token has expired and needs re-authorization
Correct answer: The CRM org's Marketing User checkbox is not enabled on the synced user
The Marketing User checkbox must be enabled on the Salesforce user whose credentials are used for MC Connect sync; without it, records are not exposed to Marketing Cloud.
Question 5: Which role in Marketing Cloud grants access to all Business Units under an Enterprise 2.0 account without needing to be added to each BU individually?
- Account Administrator
- Marketing Cloud Administrator at the parent BU level
- Enterprise Administrator (Correct answer)
- Super User
Correct answer: Enterprise Administrator
The Enterprise Administrator role provides cross-BU access across all Business Units in an Enterprise 2.0 account from a single assignment.
Question 6: An admin wants to prevent users from accidentally deleting production Data Extensions. Which feature should be configured?
- Enable Data Extension locking via the Security Policy settings
- Set the Data Extension to 'Sendable' to restrict modification rights
- Apply a Folder Permission restricting Delete access to the Admin role only (Correct answer)
- Configure a Data Retention Policy with a minimum retention window
Correct answer: Apply a Folder Permission restricting Delete access to the Admin role only
Folder Permissions in Content Builder and Data Management allow administrators to restrict delete actions to specific roles, protecting production assets.
Question 7: When configuring a SAP (Sender Authentication Package), which DNS record type is used to authorize Marketing Cloud's IP addresses to send on behalf of a domain?
- CNAME
- MX
- SPF (TXT record) (Correct answer)
- DKIM only
Correct answer: SPF (TXT record)
An SPF TXT record published in DNS lists authorized sending IP addresses, and Marketing Cloud's SAP setup requires adding Salesforce IPs to this record.
A Marketing Cloud Administrator needs to allow a third-party vendor to access only the Email Studio API without granting full account access.
What is the correct approach?