Salesforce Certified Application Architect — Questions and Answers
Question 1: What is a lookup relationship in Salesforce data architecture?
- A relationship that links records in two different Salesforce orgs.
- A relationship where records in one object are linked to a single record in another object.
- A relationship that links records from external systems.
- A relationship that enforces data integrity between objects.
A lookup relationship in Salesforce links records between two different objects, allowing one record (the child) to reference a single record in another object (the parent). It's a loosely coupled relationship, meaning the child record can exist independently if the parent record is deleted, and it doesn't automatically inherit security or ownership from the parent. This type of relationship is used when you want to associate records without enforcing strict dependencies.
Question 2: Which Salesforce API endpoint pattern should be used when a single HTTP request needs to perform a chain of dependent operations (e.g., create Account, then create Contact linked to it)?
- Bulk API job with related records
- Composite API with subrequest references (Correct answer)
- Streaming API with two channels
- Separate sequential REST calls
Correct answer: Composite API with subrequest references
The Composite API allows up to 25 subrequests in one HTTP call, and subrequests can reference the response body (like a new record ID) from earlier subrequests in the same batch.
Question 3: What does the 'Defer Sharing Calculation' option do in Salesforce, and when is it relevant?
- It delays sharing rule recalculation during large data imports to prevent system slowdowns (Correct answer)
- It converts sharing rules to manual shares for performance
- It caches sharing rule results in Platform Cache
- It permanently disables sharing rules for an object
Correct answer: It delays sharing rule recalculation during large data imports to prevent system slowdowns
Defer Sharing Calculation temporarily postpones the recalculation of sharing rules during large data operations, preventing system performance degradation, with recalculation triggered manually afterward.
Question 4: A company wants to store a subset of external ERP records directly in Salesforce without data migration, keeping data live in the ERP. What is the recommended approach?
- Periodic ETL batch loads
- Cross-Org Adapter
- Heroku Connect
- Salesforce Connect with External Objects (Correct answer)
Correct answer: Salesforce Connect with External Objects
Salesforce Connect with External Objects provides real-time, on-demand access to data stored in external systems without replicating it into Salesforce storage.
Question 5: What happens when a record lock conflict occurs during a Salesforce DML operation in Apex?
- A DmlException is thrown immediately (Correct answer)
- The transaction retries automatically three times
- The record is placed in a retry queue
- Salesforce rolls back only the conflicting record
Correct answer: A DmlException is thrown immediately
When a record lock cannot be obtained, Salesforce throws a DmlException with the UNABLE_TO_LOCK_ROW error, and the entire transaction must handle the exception.
Question 6: An architect is evaluating packaging strategies. Which statement BEST describes the difference between unlocked packages and managed packages?
- Unlocked packages lock source code from subscribers; managed packages do not
- Managed packages support upgrades and intellectual property protection; unlocked packages offer flexibility without IP protection (Correct answer)
- Managed packages are free on AppExchange; unlocked packages require licensing
- Unlocked packages can only be installed in sandboxes; managed packages can go to production
Correct answer: Managed packages support upgrades and intellectual property protection; unlocked packages offer flexibility without IP protection
Managed packages protect ISV intellectual property and support versioned upgrades, while unlocked packages give customers full control and visibility of the source.
Question 7: What is the maximum number of permission set groups a single user can be assigned in Salesforce?
- 5 permission set groups per user
- 1 permission set group per user
- No hard limit; users can belong to many permission set groups (Correct answer)
- 10 permission set groups per user
Correct answer: No hard limit; users can belong to many permission set groups
Salesforce does not impose a hard cap on the number of permission set groups assigned to a single user, though performance considerations apply.
Question 8: Which Salesforce governor limit is most critical to consider when designing integrations that use Apex callouts triggered by record saves?
- Maximum heap size per transaction
- Maximum callouts per transaction (100) (Correct answer)
- Maximum CPU time per transaction
- Maximum SOQL queries per transaction
Correct answer: Maximum callouts per transaction (100)
Salesforce limits Apex transactions to 100 callouts, so bulk trigger scenarios must be carefully architected to avoid hitting this limit when calling external services.
Question 9: What is a permission set in Salesforce?
- A permission set grants users access to specific fields.
- A permission set automatically assigns tasks to users.
- A permission set manages user roles and data access.
- A permission set allows for more granular control over user access, giving additional permissions beyond their profile. (Correct answer)
Correct answer: A permission set allows for more granular control over user access, giving additional permissions beyond their profile.
A permission set in Salesforce is a collection of settings and permissions that grant users additional access to various tools and functions. Unlike profiles, which define a user's baseline access, permission sets are used to extend permissions beyond what is provided by a user's profile. This allows administrators to grant specific, granular access to objects, fields, tabs, and system permissions to individual users or groups without altering their primary profile.
Question 10: What is the role of an admin in the deployment process?
- To manage security settings and test the changes in production after deployment. (Correct answer)
- To write Apex code for deployment.
- To develop custom applications.
- To monitor data migrations only.
Correct answer: To manage security settings and test the changes in production after deployment.
While developers focus on writing code, admins play a vital role in the deployment process by configuring the Salesforce org, managing user permissions, and ensuring security settings are correctly applied. After deployment, admins are typically responsible for validating the changes in the target environment, performing user acceptance testing, and addressing any post-deployment configuration needs. They ensure the deployed solution functions correctly for end-users and adheres to organizational policies.
Question 11: How does data sharing work in Salesforce?
- Only admins can access shared data.
- Data sharing is controlled through sharing rules and permissions. (Correct answer)
- Data is shared publicly by default.
- Data is automatically shared with all users.
Correct answer: Data sharing is controlled through sharing rules and permissions.
Salesforce employs a comprehensive data sharing model to control who sees what data. This is primarily managed through a combination of Organization-Wide Defaults (OWD), role hierarchies, sharing rules, and permission sets/profiles. These mechanisms allow administrators to define granular access levels, ensuring data is shared appropriately based on business needs and security requirements, rather than being publicly or automatically shared.
Question 12: How can you ensure data integrity in Salesforce?
- By using external tools for data cleansing.
- By storing data in spreadsheets.
- By using validation rules, triggers, and data governance practices. (Correct answer)
- By manually reviewing each record.
Correct answer: By using validation rules, triggers, and data governance practices.
Ensuring data integrity in Salesforce involves implementing various mechanisms to maintain data quality and consistency. This is primarily achieved through validation rules, which prevent users from saving records that don't meet specified criteria, and Apex triggers, which can enforce complex business logic and data transformations. Additionally, establishing strong data governance practices, including data standards and regular audits, is crucial for long-term data health and reliability.
Question 13: What ethical consideration is most relevant to incident response & disaster recovery in SAA practice?
- Avoiding all professional development activities
- Following only those rules that are convenient
- Prioritizing personal advancement over professional duties
- Maintaining confidentiality and acting in the best interest of stakeholders (Correct answer)
Correct answer: Maintaining confidentiality and acting in the best interest of stakeholders
Maintaining confidentiality and acting in the best interest of stakeholders is the cornerstone ethical consideration for incident response & disaster recovery in professional practice.
Question 14: What is the maximum number of records that a single SOQL query can return in Apex?
- 50,000 (Correct answer)
- 100,000
- 10,000
- 1,000,000
Correct answer: 50,000
A single SOQL query in Apex can return a maximum of 50,000 records; exceeding this limit throws a QueryException.
Question 15: Which documentation practice is most important for cloud infrastructure & deployment in the SAA field?
- Maintaining complete, accurate, and timely records (Correct answer)
- Recording only successful outcomes
- Using informal notes instead of official records
- Documenting only when legally required
Correct answer: Maintaining complete, accurate, and timely records
Maintaining complete, accurate, and timely records is crucial for accountability, quality assurance, and legal compliance in cloud infrastructure & deployment.
Question 16: Which Salesforce feature lets administrators see a consolidated view of all permissions a specific user has, including those from profile and permission sets?
- Permission Set Inspector
- User Access Summary on the user detail page (Correct answer)
- Security Health Check
- Profile Manager
Correct answer: User Access Summary on the user detail page
The User Access Summary (available from the user detail page) shows an aggregated view of all object and system permissions a user holds across their profile and permission sets.
Question 17: Which object-level security mechanism prevents a user from even knowing a particular object exists in Salesforce?
- Sharing rules
- Restriction Rules
- Field-Level Security
- Setting Tab visibility to 'Tab Hidden' and removing object permissions (Correct answer)
Correct answer: Setting Tab visibility to 'Tab Hidden' and removing object permissions
Removing object permissions (Read, Create, etc.) from a profile and hiding the tab prevents users from seeing or interacting with that object entirely.
Question 18: An architect discovers that an integration sends duplicate records to Salesforce because the source system retries on timeout. Which design pattern addresses this?
- Disabling retries on the source system
- Deduplication via manual review queues
- Idempotent Receiver pattern using an External ID field (Correct answer)
- Using Bulk API instead of REST API
Correct answer: Idempotent Receiver pattern using an External ID field
The Idempotent Receiver pattern uses a unique External ID field to ensure that duplicate messages result in an upsert rather than creating duplicate records.
Question 19: An architect needs to make a long-running callout from Salesforce without blocking the user. Which Apex feature supports this?
- Platform Events
- Continuation (Asynchronous Callout) (Correct answer)
- Scheduled Apex
- Future Method with callout=true
Correct answer: Continuation (Asynchronous Callout)
The Continuation class enables long-running asynchronous callouts from Visualforce and Aura/LWC, freeing the UI thread while waiting for the external response without consuming transaction CPU time.
Question 20: What is a common challenge professionals face when applying incident response & disaster recovery principles in Salesforce Application Architect Certification?
- Lack of any professional development opportunities
- Balancing theoretical knowledge with practical application (Correct answer)
- Excessive simplicity of industry regulations
- Having too much support from colleagues
Correct answer: Balancing theoretical knowledge with practical application
Balancing theoretical knowledge with practical application is a well-recognized challenge, as real-world scenarios often present complexities not covered in standard training.
Question 21: How does continuing education relate to cloud infrastructure & deployment for SAA certified professionals?
- It is only needed when changing employers
- It is optional and rarely impacts practice quality
- It ensures professionals stay current with evolving standards and best practices (Correct answer)
- It is required only for entry-level practitioners
Correct answer: It ensures professionals stay current with evolving standards and best practices
Continuing education ensures SAA professionals stay current with evolving standards, technologies, and best practices in cloud infrastructure & deployment, maintaining competency throughout their careers.
Question 22: What is the primary purpose of Salesforce integration architecture?
- To allow external systems to access Salesforce data.
- To ensure Salesforce communicates with other systems for data synchronization and functionality. (Correct answer)
- To automate reporting within Salesforce.
- To store data within Salesforce only.
Correct answer: To ensure Salesforce communicates with other systems for data synchronization and functionality.
The primary purpose of Salesforce integration architecture is to enable seamless communication and data exchange between Salesforce and other internal or external systems. This ensures that business processes can flow smoothly across different applications, data remains synchronized, and a unified view of customer information is maintained. Effective integration allows Salesforce to act as a central hub, connecting various parts of an organization's IT landscape.
Question 23: Which integration security mechanism should be used when an external application needs to call Salesforce APIs on behalf of a user without storing the user's credentials?
- Basic Authentication
- IP Whitelisting only
- Session ID passed in headers
- OAuth 2.0 JWT Bearer Token Flow (Correct answer)
Correct answer: OAuth 2.0 JWT Bearer Token Flow
The OAuth 2.0 JWT Bearer Token Flow allows server-to-server integrations to obtain access tokens without user interaction or credential storage.
Question 24: What is data modeling in Salesforce?
- Defining the structure, storage, and relationships of data in Salesforce. (Correct answer)
- Creating user interfaces for applications.
- Managing Salesforce app deployments.
- Building APIs for data integration.
Correct answer: Defining the structure, storage, and relationships of data in Salesforce.
Data modeling in Salesforce involves designing how information is organized and stored within the platform. This includes defining objects (like tables), fields (like columns), and the relationships between these objects, ensuring data integrity, efficiency, and alignment with business processes. It's the blueprint for how data interacts.
Question 25: What is the primary purpose of automation & scripting fundamentals in the context of Salesforce Application Architect Certification?
- To replace established industry guidelines
- To ensure consistent quality and professional accountability (Correct answer)
- To reduce organizational costs exclusively
- To eliminate the need for ongoing training
Correct answer: To ensure consistent quality and professional accountability
Automation & Scripting Fundamentals in Salesforce Application Architect Certification primarily ensures consistent quality and professional accountability, forming the foundation of competent practice in this field.
Question 26: A client wants to expose Salesforce data as an OData feed for consumption by Microsoft Power BI. Which Salesforce capability should an architect recommend?
- Salesforce Connect with OData 4.0 adapter (Correct answer)
- External Services
- Salesforce Bulk API 2.0
- Canvas Apps
Correct answer: Salesforce Connect with OData 4.0 adapter
Salesforce Connect with an OData adapter allows Salesforce to act as an OData producer, exposing external objects or Salesforce data as OData-compliant feeds.
Question 27: An architect is designing an integration where Salesforce must receive high-frequency sensor data (1,000 events/second) from IoT devices. Which approach is most scalable?
- Store sensor data in Salesforce Files
- Aggregate events in an IoT platform and batch-load to Salesforce via Bulk API (Correct answer)
- Direct REST API calls from each device to Salesforce
- Use Outbound Messages from Salesforce to pull IoT data
Correct answer: Aggregate events in an IoT platform and batch-load to Salesforce via Bulk API
Aggregating IoT events in an intermediary platform and batch-loading them via Bulk API prevents API governor limit exhaustion and scales to handle high-frequency data.
Question 28: A SOQL query is considered 'selective' when it uses indexed fields in the WHERE clause. Why is selectivity critical for Large Data Volume orgs?
- It prevents full table scans that degrade query performance (Correct answer)
- It bypasses sharing rules
- It reduces API call counts
- It enables skinny table creation
Correct answer: It prevents full table scans that degrade query performance
Selective queries allow Salesforce to use indexes to retrieve a small subset of records, avoiding costly full table scans that become exponentially slower as data volume grows.
Question 29: How should a SAA professional handle a situation where automation & scripting fundamentals protocols conflict with practical constraints?
- Always ignore the protocols in favor of practicality
- Make a unilateral decision without consultation
- Avoid addressing the conflict entirely
- Document the conflict and seek guidance from appropriate authorities (Correct answer)
Correct answer: Document the conflict and seek guidance from appropriate authorities
When protocols conflict with practical constraints, the professional approach is to document the conflict and seek guidance, ensuring transparency and compliance while working toward a resolution.
Question 30: What is the primary difference between a Role and a Profile in Salesforce security?
- Roles are mandatory; profiles are optional
- Roles control field visibility; profiles control record sharing
- Roles control record-level access via hierarchy; profiles control object and field-level access (Correct answer)
- Roles replace sharing rules in complex orgs
Correct answer: Roles control record-level access via hierarchy; profiles control object and field-level access
Profiles determine what objects and fields a user can access, while roles control which records a user can see through the role hierarchy.
Question 31: What is the role of Salesforce Connect in integration architecture?
- Salesforce Connect is used for batch data imports.
- Salesforce Connect allows real-time access to external data without storing it in Salesforce. (Correct answer)
- Salesforce Connect manages internal Salesforce data.
- Salesforce Connect integrates Salesforce with external applications for real-time collaboration.
Correct answer: Salesforce Connect allows real-time access to external data without storing it in Salesforce.
Salesforce Connect plays a crucial role in integration architecture by enabling real-time access to data stored in external systems directly from within Salesforce. It allows external data sources to be represented as external objects in Salesforce, meaning users can view, search, and interact with this data without it being physically stored in the Salesforce database. This 'data virtualization' approach is ideal for scenarios where data needs to reside outside Salesforce but still be accessible to users.
Question 32: Which of the following best describes a key competency required for security architecture & network defense in SAA certification?
- Delegation of all complex tasks to supervisors
- Memorization of all relevant regulations verbatim
- Ability to work independently without any oversight
- Critical thinking and evidence-based decision making (Correct answer)
Correct answer: Critical thinking and evidence-based decision making
Critical thinking and evidence-based decision making is essential for security architecture & network defense, as professionals must analyze situations and apply knowledge appropriately.
Question 33: A company wants to ensure that users can only access Salesforce from their corporate network. Which feature should an architect configure?
- Login IP Ranges on profiles (Correct answer)
- IP Whitelisting in OAuth
- Network Access in Setup
- Trusted IP Ranges in Session Settings
Correct answer: Login IP Ranges on profiles
Login IP Ranges set on a profile restrict users with that profile to logging in only from specified IP addresses.
Question 34: Which Salesforce feature allows an architect to declaratively call an external REST API and map the response to Salesforce actions without writing Apex code?
- Apex REST Callouts
- Workflow Outbound Messages
- External Services (OpenAPI) (Correct answer)
- Named Credentials only
Correct answer: External Services (OpenAPI)
External Services allow administrators to import an OpenAPI specification and then use the external API's operations as invocable actions in Flow or Process Builder without Apex.
Question 35: What is a sharing rule in Salesforce?
- A rule that defines how records are shared with users based on certain criteria. (Correct answer)
- A rule that automatically assigns records to users.
- A rule for setting up data encryption.
- A rule for managing user logins and access.
Correct answer: A rule that defines how records are shared with users based on certain criteria.
A sharing rule in Salesforce is a mechanism used to extend record access to users beyond what is granted by the Organization-Wide Defaults (OWD) and the role hierarchy. These rules are based on specific criteria (e.g., field values) or record ownership, allowing administrators to automatically share groups of records with other users, roles, or public groups. Sharing rules are crucial for implementing complex sharing requirements and ensuring appropriate data visibility across the organization.
Question 36: An architect is evaluating whether to use an External Object or replicate data into Salesforce custom objects. What is the PRIMARY advantage of External Objects?
- Data remains in the external system and is accessed in real time without storage costs (Correct answer)
- External Objects are faster to query than custom objects
- External Objects support Apex triggers
- External Objects support roll-up summary fields
Correct answer: Data remains in the external system and is accessed in real time without storage costs
External Objects use Salesforce Connect to access data in real time from external systems, eliminating the need to replicate data into Salesforce storage.
Question 37: An architect wants to allow Salesforce to send emails through an external mail server via SMTP. Where is this configured and what is a key security consideration?
- Workflow email alerts; SPF records must match the relay domain
- Email Relay in Setup; credentials must be stored securely and TLS should be enforced (Correct answer)
- Deliverability settings; sandbox-only configuration applies
- Connected Apps; OAuth must be used for mail server authentication
Correct answer: Email Relay in Setup; credentials must be stored securely and TLS should be enforced
Email Relay is configured under Setup > Email > Email Relay Activation, and TLS should be required to encrypt email traffic between Salesforce and the relay server.
Question 38: An architect wants to ensure that custom metadata changes made by one team do not break another team's work in their respective scratch orgs. What strategy BEST prevents this?
- Use a shared developer sandbox for all teams
- Implement feature branch workflows in version control with scratch orgs per feature (Correct answer)
- Deploy all metadata to production daily for synchronization
- Use partial copy sandboxes with nightly refreshes
Correct answer: Implement feature branch workflows in version control with scratch orgs per feature
Feature branch workflows with per-feature scratch orgs isolate each team's changes, preventing conflicts until branches are merged through a pull request process.
Question 39: When implementing automation & scripting fundamentals practices, what should a SAA professional prioritize first?
- Compliance with established standards and protocols (Correct answer)
- Speed of completion over thoroughness
- Cost reduction at all levels
- Personal convenience and efficiency
Correct answer: Compliance with established standards and protocols
Compliance with established standards and protocols must be the first priority, as it ensures safety, quality, and legal adherence in professional practice.
Question 40: What is the use of two-factor authentication in Salesforce?
- It ensures only administrators can access sensitive data.
- It provides backup access to Salesforce in case of forgotten passwords.
- It increases login security by requiring a second form of verification. (Correct answer)
- It automatically changes user passwords every 30 days.
Correct answer: It increases login security by requiring a second form of verification.
Two-factor authentication (2FA) significantly enhances login security in Salesforce by requiring users to provide two distinct forms of verification before gaining access. Typically, this involves something the user knows (like a password) and something the user has (like a mobile device for a verification code or a security key). This layered approach makes it much harder for unauthorized individuals to access an account, even if they manage to steal a password.
Question 41: In Salesforce Application Architect Certification, what role does security architecture & network defense play in ensuring client/stakeholder satisfaction?
- It builds trust through demonstrated competence and consistency (Correct answer)
- It only matters during initial certification
- It replaces the need for direct communication
- It has no direct impact on stakeholder satisfaction
Correct answer: It builds trust through demonstrated competence and consistency
Security Architecture & Network Defense builds trust through demonstrated competence and consistency, which directly contributes to stakeholder satisfaction and confidence in the SAA professional.
Question 42: Which Salesforce mechanism should an architect recommend to handle high-volume record inserts that trigger complex automation without hitting governor limits?
- Execute all triggers synchronously in a single transaction
- Disable all triggers during data loads
- Use Streaming API to insert records
- Use Bulk API with appropriate batch sizes and async triggers (Correct answer)
Correct answer: Use Bulk API with appropriate batch sizes and async triggers
Bulk API processes records in batches of up to 10,000 asynchronously, and combined with well-designed bulkified triggers, avoids per-transaction governor limit breaches during high-volume loads.
Question 43: What is the significance of peer review in cloud infrastructure & deployment for SAA professionals?
- It is primarily used for disciplinary purposes
- It replaces the need for self-assessment
- It promotes accountability, knowledge sharing, and quality improvement (Correct answer)
- It is only relevant for newly certified professionals
Correct answer: It promotes accountability, knowledge sharing, and quality improvement
Peer review promotes accountability, knowledge sharing, and quality improvement by allowing SAA professionals to benefit from collective expertise and identify areas for growth.
Question 44: A batch Apex job processes 10 million records nightly. The job is timing out. Which architectural change best resolves this?
- Convert the batch job to a scheduled Apex class
- Increase the batch scope size to 2000
- Use a Platform Event to trigger the batch
- Chain multiple batch jobs with reduced scope and use stateful processing (Correct answer)
Correct answer: Chain multiple batch jobs with reduced scope and use stateful processing
Chaining smaller batch jobs with a stateful interface distributes processing across multiple transactions, preventing governor limit timeouts on large datasets.
Question 45: A company has 200 custom fields on the Account object and reports are running slowly. Which architectural recommendation addresses this?
- Move rarely used fields to a related custom object (Correct answer)
- Convert all text fields to formula fields
- Increase the number of custom indexes
- Enable field history tracking on all fields
Correct answer: Move rarely used fields to a related custom object
Moving rarely used fields to a related child object reduces the width of the Account table, improving query performance for the most common use cases.
Question 46: Which Salesforce feature enables an architect to query across a parent-child relationship in a single SOQL statement?
- SOQL aggregate function
- Semi-join subquery
- Cross-object formula field
- Relationship query (nested SELECT) (Correct answer)
Correct answer: Relationship query (nested SELECT)
SOQL supports relationship queries that allow you to traverse parent-child relationships using nested SELECT statements in a single query.
Question 47: What is the maximum number of Master-Detail relationships a single custom object can have?
- 3
- 2 (Correct answer)
- 5
- 1
Correct answer: 2
A custom object can have up to 2 Master-Detail relationships, which allows it to serve as a junction object in a many-to-many relationship.
Question 48: What is a common challenge professionals face when applying cloud infrastructure & deployment principles in Salesforce Application Architect Certification?
- Lack of any professional development opportunities
- Having too much support from colleagues
- Excessive simplicity of industry regulations
- Balancing theoretical knowledge with practical application (Correct answer)
Correct answer: Balancing theoretical knowledge with practical application
Balancing theoretical knowledge with practical application is a well-recognized challenge, as real-world scenarios often present complexities not covered in standard training.
Question 49: What is the difference between a master-detail relationship and a lookup relationship?
- Master-detail relationship does not allow record sharing.
- Master-detail relationship links records with no dependencies.
- Master-detail relationship enforces a strict parent-child relationship with dependencies. (Correct answer)
- Lookup relationships require data partitioning.
Correct answer: Master-detail relationship enforces a strict parent-child relationship with dependencies.
The key difference between these relationships lies in the level of dependency and ownership. A master-detail relationship enforces a strict parent-child relationship where the detail (child) record cannot exist without its master (parent) record. This means the child inherits security and sharing settings from the parent, and deleting the parent automatically deletes all associated child records, enforcing strong data integrity.
Question 50: Which quality improvement method is most applicable to incident response & disaster recovery in Salesforce Application Architect Certification?
- Ignoring feedback and maintaining status quo
- Implementing changes without measuring outcomes
- Plan-Do-Check-Act (PDCA) continuous improvement cycle (Correct answer)
- Making changes only when mandated by regulators
Correct answer: Plan-Do-Check-Act (PDCA) continuous improvement cycle
The PDCA cycle is widely recognized as the most effective quality improvement method, allowing SAA professionals to systematically improve incident response & disaster recovery practices.
Question 51: What is the significance of peer review in incident response & disaster recovery for SAA professionals?
- It replaces the need for self-assessment
- It is only relevant for newly certified professionals
- It promotes accountability, knowledge sharing, and quality improvement (Correct answer)
- It is primarily used for disciplinary purposes
Correct answer: It promotes accountability, knowledge sharing, and quality improvement
Peer review promotes accountability, knowledge sharing, and quality improvement by allowing SAA professionals to benefit from collective expertise and identify areas for growth.
Question 52: When designing a real-time integration where an external system must query Salesforce and receive an immediate response, which API is most appropriate?
- Metadata API
- Streaming API
- Bulk API 2.0
- REST API (Correct answer)
Correct answer: REST API
The REST API supports synchronous request-reply interactions, allowing external systems to query Salesforce records and receive immediate JSON or XML responses.
Question 53: A developer must invoke an external REST API from Salesforce when a record is saved, without blocking the user's transaction. What is the recommended pattern?
- A Visualforce page performing the callout on record view
- Synchronous callout in a before-save trigger
- A @future(callout=true) method called from an after-save trigger (Correct answer)
- A Scheduled Apex job polling every minute for new records
Correct answer: A @future(callout=true) method called from an after-save trigger
A @future(callout=true) method executes asynchronously after the transaction commits, allowing HTTP callouts without blocking the user's save operation.
Question 54: Which Salesforce feature allows caching of frequently accessed data at the org, session, or partition level to reduce repeated database queries?
- Static Resources
- Platform Cache (Correct answer)
- External Cache
- Custom Settings
Correct answer: Platform Cache
Platform Cache provides a dedicated caching layer in Salesforce at org or session scope, reducing redundant SOQL queries and improving application performance.
Question 55: An architect is designing a Customer Community where external users should only see their own cases. Which OWD setting achieves this for the Case object?
- Public Read/Write
- Controlled by Parent
- Public Read Only
- Private (Correct answer)
Correct answer: Private
Setting Case OWD to Private ensures that users can only see records they own, which is the baseline for community user isolation.
Question 56: In a Large Data Volume environment, which index type must Salesforce Support enable, as it is not available through Setup by default?
- Custom Index (Correct answer)
- Composite Index
- Skinny Table Index
- Standard Index
Correct answer: Custom Index
Custom Indexes are created by Salesforce Support upon request and are applied to fields that need to be indexed to improve query selectivity on high-volume objects.
Question 57: When should an architect use Restriction Rules in Salesforce?
- To restrict login access to certain IP ranges
- To further limit record access for specific users beyond what sharing rules and OWD grant (Correct answer)
- To enforce field-level encryption on sensitive data
- To grant access to records not covered by OWD
Correct answer: To further limit record access for specific users beyond what sharing rules and OWD grant
Restriction Rules narrow record visibility for specified users or groups, ensuring they see only a subset of records they would otherwise have access to.
Question 58: What is a profile in Salesforce?
- A profile manages security settings across the organization.
- A profile determines which records a user can view and edit.
- A profile is used to define all user permissions, including access to fields and objects. (Correct answer)
- A profile defines access to reports and dashboards.
Correct answer: A profile is used to define all user permissions, including access to fields and objects.
A profile in Salesforce is a fundamental security component that defines a user's baseline permissions and access settings across the entire organization. It controls what a user can *do* (e.g., create, read, edit, delete records; run reports; modify all data) and what they can *see* (e.g., access to specific objects, fields, tabs, and applications). Every user must be assigned exactly one profile, which serves as their primary set of permissions.
Question 59: What is the purpose of data mapping in Salesforce integration?
- To create reports within Salesforce.
- To define user roles.
- To match fields between Salesforce and external systems for correct data flow. (Correct answer)
- To store data in external systems.
Correct answer: To match fields between Salesforce and external systems for correct data flow.
Data mapping in Salesforce integration is the critical process of defining how data fields from one system correspond to data fields in another system. It ensures that when data is transferred between Salesforce and an external application, each piece of information is correctly matched and placed into the appropriate field. This step is essential for maintaining data accuracy, consistency, and integrity across integrated systems.
Question 60: Which Apex governor limit applies per-transaction and is MOST commonly violated when processing large datasets in triggers?
- Maximum heap size: 6MB for synchronous transactions
- Maximum CPU time: 10,000ms for synchronous transactions (Correct answer)
- Maximum 50,000 SOQL rows returned per transaction
- Maximum 150 DML statements per transaction
Correct answer: Maximum CPU time: 10,000ms for synchronous transactions
CPU time (10,000ms for synchronous, 60,000ms for asynchronous) is the governor limit most commonly hit during complex bulk processing in triggers.
Salesforce Certified Application Architect
The Salesforce Certified Application Architect credential validates the skills and knowledge required to design and implement complex solutions on the Salesforce platform.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds