# Free Salesforce Integration Architect Practice Questions

*Last updated September 2026 · https://www.certifyforce.com/salesforce-integration-architect-practice-exam/free-questions*

18 free Integration Architect practice questions from the CertifyForce bank of 300 reviewed questions, spread across the 6 official exam sections in proportion to their weight. Each has the correct answer, an explanation, and the official documentation it was verified against.

## Evaluate the Current System Landscape (8%)

### Question 1

Universal Containers runs separate sales and service orgs. To keep Account data consistent, a developer proposes publishing an Account_Changed__e platform event from a record-triggered flow in the sales org and writing a platform event trigger in the service org that updates the matching Account. What should the integration architect point out about this design?

- A. The design works only if both orgs define the platform event with the same API name and the same fields.
- B. The design works only with high-volume platform events, because standard-volume events can't leave the org that publishes them.
- C. The design works if the service org's trigger subscribes to the sales org's change data capture channel instead, because change event triggers can subscribe to any org.
- D. Platform events can't cross orgs: the service org's trigger sees only its own events, so use middleware, Heroku Connect, Data 360, or the cross-org adapter.

**Correct answer:** D. Platform events can't cross orgs: the service org's trigger sees only its own events, so use middleware, Heroku Connect, Data 360, or the cross-org adapter.

**Explanation:** The decision guide states that platform events aren't optimal for integrating data from one Salesforce org to another because they can't listen between orgs for the same event. A subscriber inside the service org sees only its own org's event bus, so matching API names or choosing high-volume events doesn't connect the two orgs. Change data capture has the same boundary: triggers in the service org can't subscribe to the sales org's change events, which is why the guide has change events consumed by an external subscriber, such as a MuleSoft connector. For org-to-org synchronization, the guide recommends MuleSoft, Heroku Connect, native APIs, Data 360, or, when replication isn't wanted, the cross-org adapter.

**Sources:** [Data Integration with Salesforce | Decision Guides | Salesforce Architects](https://architect.salesforce.com/docs/architect/decision-guides/guide/data-integration.html)

### Question 2

Cumulus Financial's employees already log in to Salesforce through SAML single sign-on with the corporate identity provider. An internal desktop analytics tool used by the same employees must now call Salesforce REST API as the signed-in employee. The tool can obtain the same SAML response that the identity provider issues for Web SSO, and the security team wants API access to reuse the org's existing SAML configuration rather than register a new app in Salesforce or manage signing keys in the tool. Which approach should the integration architect recommend?

- A. OAuth 2.0 SAML bearer assertion flow, with the tool signing its own SAML assertion with a private key whose certificate is registered on an external client app
- B. OAuth 2.0 JWT bearer flow, with the tool signing a JWT for each employee with a certificate uploaded to an external client app
- C. OAuth 2.0 client credentials flow, with an integration user assigned to run all API calls from the tool
- D. SAML assertion flow, with the tool posting the identity provider's SAML response to the Salesforce OAuth 2.0 token endpoint in exchange for an access token

**Correct answer:** D. SAML assertion flow, with the tool posting the identity provider's SAML response to the Salesforce OAuth 2.0 token endpoint in exchange for an access token

**Explanation:** The SAML assertion flow is designed for orgs that use SAML to access Salesforce and want to access the API the same way: clients federate with the API using a SAML assertion just as they do for Web SSO, the same SAML configuration serves both, and the flow can be used without a connected app. It never issues a refresh token, and it can't be used with more than one org or with Experience Cloud sites, none of which conflicts with this scenario. The SAML bearer assertion flow requires an app with a registered X.509 certificate and an assertion signed with the matching private key, which the security team wants to avoid. The JWT bearer flow likewise requires a signing certificate and prior app approval. The client credentials flow runs every call as one integration user, so calls wouldn't run as the signed-in employee.

**Sources:** [SAML Assertion Flow for Accessing the API | Salesforce Help](https://help.salesforce.com/s/articleView?id=xcloud.remoteaccess_oauth_web_sso_flow.htm&language=en_US&type=5), [OAuth 2.0 SAML Bearer Assertion Flow for Previously Authorized Apps | Salesforce Help](https://help.salesforce.com/s/articleView?id=xcloud.remoteaccess_oauth_SAML_bearer_flow.htm&language=en_US&type=5), [OAuth Authorization Flows | Salesforce Help](https://help.salesforce.com/s/articleView?language=en_US&id=remoteaccess_oauth_flows.htm&type=5)

## Evaluate Business Needs (11%)

### Question 3

Cloud Kicks is building an integration that sends three data sets from Salesforce to an external data platform: product names and list prices shown on the public website, customer email addresses with purchase history, and stored payment card numbers. The company uses a Public, Confidential, and Secure scheme, in which Secure is the highest-sensitivity tier. How should the architect classify these data sets?

- A. Classify all three as Confidential because they will leave Salesforce through an integration.
- B. Product data as Public, emails and purchase history as Confidential, card numbers as Secure.
- C. Product data as Confidential, emails and purchase history as Public, card numbers as Secure.
- D. Product data as Public, emails and purchase history as Secure, card numbers as Confidential.

**Correct answer:** B. Product data as Public, emails and purchase history as Confidential, card numbers as Secure.

**Explanation:** Salesforce's Trust guidance classifies published catalog content as Public, personal information and sensitive business records as Confidential, and payment data as its highest regulated tier, which maps to Secure in Cloud Kicks' scheme. Salesforce's data classification setup even applies a Confidential default sensitivity to the email field. Leaving Salesforce does not change the sensitivity of the data, so classifying everything as Confidential under-protects the card numbers and over-protects the public catalog. Treating email addresses as Public ignores that they are personal information. Swapping the email and card-number classifications under-protects regulated payment data.

**Sources:** [Trust | Well-Architected](https://architect.salesforce.com/docs/architect/well-architected/guide/trust.html), [Set Up Data Classification Metadata](https://help.salesforce.com/s/articleView?id=platform.data_classification_set_up.htm&language=en_US&type=5)

### Question 4

Bloomington Caregivers will go live with Salesforce in three months. Stakeholders define success as caregivers seeing complete client histories on day one, followed by daily changes from the scheduling system. Which two requirements should the integration architect capture? Choose 2 answers.

- A. The volume and timing of the one-time historical data load, planned separately from the ongoing sync.
- B. Use the Data Import Wizard as the long-term tool for loading daily scheduling changes.
- C. Load only records created after go-live to reduce the size of the initial migration.
- D. The frequency and acceptable latency for ongoing daily changes from the scheduling system.
- E. Defer data volume analysis until after go-live, when actual usage patterns are known.

**Correct answers:** A. The volume and timing of the one-time historical data load, planned separately from the ongoing sync.; D. The frequency and acceptable latency for ongoing daily changes from the scheduling system.

**Explanation:** Salesforce's data integration decision guide asks whether you have planned ahead for bulk data loads, such as the initial data load for a new instance, so the one-time historical load needs its own volume and timing plan; it also asks how frequently data must move, which covers the ongoing daily changes. The guide says the Data Import Wizard and Data Loader are not a recommended base for a data integration strategy, so they should not be the long-term sync tool. Loading only post-go-live records fails the complete-history success criterion. Deferring volume analysis until after go-live risks hitting limits during the initial load.

**Sources:** [Data Integration with Salesforce](https://architect.salesforce.com/docs/architect/decision-guides/guide/data-integration.html)

## Translate Needs to Integration Requirements (22%)

### Question 5

AW Computing sends employee payroll records from Salesforce to a payroll provider through a third-party message broker that AW Computing doesn't control. Every connection uses TLS 1.2. The security team requires that the broker never be able to read employees' bank account numbers, even though it routes and logs every message; only the payroll provider may read them. What should the integration architect recommend?

- A. Encrypt the bank account field with Shield Platform Encryption so that the value stays encrypted in each outbound message
- B. Require mutual TLS between Salesforce and the broker so that only the authenticated broker can receive the payroll messages
- C. Send the messages through a named credential so that Salesforce encrypts each payload with the broker's credentials first
- D. Encrypt the account number in Apex with the Crypto class, using a key shared only with the payroll provider

**Correct answer:** D. Encrypt the account number in Apex with the Crypto class, using a key shared only with the payroll provider

**Explanation:** TLS protects data only between the two ends of each connection, so the broker, which terminates its connections, sees messages in clear text. Salesforce's integration security guidance describes encrypting selected data fields before the HTTPS request executes when a transaction needs more protection; the Apex Crypto class can encrypt the value with AES, for example with encryptWithManagedIV and AES256, and the payroll provider decrypts it with the shared key, so the broker only relays ciphertext. Shield Platform Encryption protects data at rest in Salesforce and doesn't affect authorized users and processes, so the outbound payload carries the readable value. Mutual TLS authenticates the broker but still delivers readable messages to it. Named credentials manage callout authentication, not payload encryption.

**Sources:** [Integration Patterns and Practices: Security Considerations](https://developer.salesforce.com/docs/atlas.en-us.integration_patterns_and_practices.meta/integration_patterns_and_practices/integ_pat_security_considerations.htm), [Apex Reference Guide: Crypto Class](https://developer.salesforce.com/docs/atlas.en-us.apexref.meta/apexref/apex_classes_restful_crypto.htm)

### Question 6

Every night, Get Cloudy Consulting's client extracts about 90 million Meter_Reading__c rows to a fraud analytics platform with a Bulk API 2.0 query job. Salesforce finishes processing the job in about 25 minutes, but the middleware then downloads the results one locator at a time, requesting each result set only after the previous one arrives, and the download takes more than five hours. The extract must finish within three hours. What should the integration architect recommend?

- A. Add the PK chunking header to the query job so that Salesforce splits the extract into chunks that download faster
- B. Use the Get Parallel Results resource, which returns up to five result URIs a call, and download them concurrently
- C. Replace the query job with REST API queries that page through nextRecordsUrl, so results start arriving without a job
- D. Run the query job with the queryAll operation so that Salesforce returns the results in fewer and larger result files

**Correct answer:** B. Use the Get Parallel Results resource, which returns up to five result URIs a call, and download them concurrently

**Explanation:** Get Parallel Results for a Query Job, the resultPages resource available in API version 58.0 and later, returns up to five result URIs, each with its own locator, plus a URI for the next set, so the client can download several result sets at once instead of waiting for each one before requesting the next. Bulk API 2.0 already chunks large query jobs automatically; the PK chunking header belongs to the original Bulk API and doesn't change how results are downloaded. REST API query paging returns results sequentially in much smaller batches, which is slower for tens of millions of rows. queryAll adds deleted and archived records to the results; it doesn't change how they're delivered.

**Sources:** [Bulk API 2.0 Developer Guide: Get Parallel Results for a Query Job](https://developer.salesforce.com/docs/atlas.en-us.api_asynch.meta/api_asynch/query_get_parallel_job_results.htm), [Best Practices for Deployments with Large Data Volumes: Extracting Data from the API](https://developer.salesforce.com/docs/atlas.en-us.salesforce_large_data_volumes_bp.meta/salesforce_large_data_volumes_bp/ldv_deployments_best_practices_api_extracting_data.htm)

### Question 7

Bloomington Caregivers is cataloging its integrations by type and coordination style. When a home visit is scheduled in Salesforce, a middleware flow acts as the central controller: it calls the fleet system to reserve a vehicle, then calls the HR system to open a timesheet, then updates the visit in Salesforce with both confirmation numbers, tracking the state of each step. How should the architect categorize this integration?

- A. Data integration coordinated by choreography
- B. Virtual integration coordinated by orchestration
- C. Process integration coordinated by orchestration
- D. Process integration coordinated by choreography

**Correct answer:** C. Process integration coordinated by orchestration

**Explanation:** A business process that must use several applications to complete its task is process integration, and a single central controller directing each step is orchestration; choreography has no central controller because each participant acts autonomously. Data integration focuses on keeping data synchronized across systems, not on coordinating a multistep business process. Virtual integration means viewing or modifying external data in real time without replicating it, which this flow doesn't do. Process integration with choreography misreads the middleware's role as the conductor of every step.

**Sources:** [Integration Patterns Overview](https://architect.salesforce.com/docs/architect/fundamentals/guide/integration-patterns.html)

### Question 8

At a Get Cloudy Consulting client, when an Opportunity is set to Closed Won, an order must be created in the ERP and the ERP order number stored on the Opportunity as soon as it's available; users don't need to wait for it. A developer's synchronous callout from the Opportunity trigger fails. Which two designs meet the requirement? Choose 2 answers.

- A. A record-triggered flow publishes a platform event, and middleware creates the ERP order and writes the order number back to the Opportunity through the REST API
- B. Keep the synchronous callout in the trigger but reduce its timeout to five seconds so the callout finishes well inside the trigger's execution limits
- C. Move the synchronous callout into an after-update trigger, since the Opportunity record has already been saved by that point
- D. Use a workflow rule outbound message, letting the ERP's acknowledgment response carry the order number it just created back to Salesforce
- E. Have the trigger enqueue a Queueable Apex job that makes the callout and updates the Opportunity once the ERP responds

**Correct answers:** A. A record-triggered flow publishes a platform event, and middleware creates the ERP order and writes the order number back to the Opportunity through the REST API; E. Have the trigger enqueue a Queueable Apex job that makes the callout and updates the Opportunity once the ERP responds

**Explanation:** Callouts made from a trigger must run asynchronously in a future or queueable method, so a Queueable job that performs the callout and then updates the Opportunity meets the requirement, as does a Fire and Forget design in which middleware processes a flow-published platform event and calls back into Salesforce. Shortening the timeout doesn't lift the restriction on synchronous callouts from triggers. An after-update trigger still runs inside the same transaction, so the same restriction applies. Workflow Rules are retired for new automation, and outbound messaging is a legacy one-way notification, so data coming back must arrive through a separate callback.

**Sources:** [Data Integration with Salesforce](https://architect.salesforce.com/docs/architect/decision-guides/guide/data-integration.html), [Integration Patterns Overview](https://architect.salesforce.com/docs/architect/fundamentals/guide/integration-patterns.html)

## Design Integration Solutions (28%)

### Question 9

AW Computing is collecting requirements for a new integration between its ERP and Salesforce. Which two requirements indicate that Batch Data Synchronization is the most appropriate pattern? Choose 2 answers.

- A. A user must see the ERP's response before saving the record they are editing.
- B. Hundreds of thousands of ERP records change daily, and Salesforce only needs them by the next business day.
- C. ERP data must not be stored in Salesforce because of data residency rules.
- D. Several downstream systems must be notified within seconds whenever a Salesforce record changes.
- E. Loads must run in a window that avoids contending with users updating the same records.

**Correct answers:** B. Hundreds of thousands of ERP records change daily, and Salesforce only needs them by the next business day.; E. Loads must run in a window that avoids contending with users updating the same records.

**Explanation:** Batch Data Synchronization addresses importing and exporting large amounts of data on a schedule, taking into account that loads can interfere with end-user operations, so high daily volumes with next-day freshness and a designated batch window both point to it. Needing to see the ERP's response before saving is a synchronous Request and Reply requirement. A prohibition on storing ERP data in Salesforce points to Data Virtualization. Notifying multiple systems within seconds of a change calls for an event-driven approach such as platform events or Change Data Capture.

**Sources:** [Integration Patterns Overview](https://architect.salesforce.com/docs/architect/fundamentals/guide/integration-patterns.html)

### Question 10

Universal Containers has a legacy on-premises SOAP application that must be notified when a Case is escalated. A long-time admin suggests an outbound message instead of building a new event-driven integration. Which two statements about outbound messaging should the architect weigh? Choose 2 answers.

- A. Outbound messages can send a custom JSON payload that combines fields from the Case and several related objects.
- B. Messages that can't be delivered stay in the queue and are retried until they are 24 hours old, and then they are dropped.
- C. Outbound messaging requires an add-on license before it can be used in production.
- D. Salesforce is actively expanding outbound messaging and recommends it for all new asynchronous integrations.
- E. The receiving application must implement a listener for the WSDL that Salesforce provides for the outbound message, which is a contract-first approach.

**Correct answers:** B. Messages that can't be delivered stay in the queue and are retried until they are 24 hours old, and then they are dropped.; E. The receiving application must implement a listener for the WSDL that Salesforce provides for the outbound message, which is a contract-first approach.

**Explanation:** Outbound messages stay in the queue until they are sent successfully or reach 24 hours old, and if the data changes before sending, only the latest version is delivered. The remote endpoint takes part in a contract-first integration: it implements a SOAP listener for the WSDL that Salesforce supplies. Outbound messages are SOAP messages with fields from a single object; the decision guide lists no multi-object support, and there are no custom JSON payloads. No extra license is needed. Salesforce will keep supporting outbound messaging as it works today but doesn't plan further investment. The integration patterns guidance calls it a legacy approach and recommends Flow with platform events and Pub/Sub API for new solutions.

**Sources:** [Data Integration with Salesforce](https://architect.salesforce.com/docs/architect/decision-guides/guide/data-integration.html), [Integration Patterns Overview](https://architect.salesforce.com/docs/architect/fundamentals/guide/integration-patterns.html)

### Question 11

Northern Trail Outfitters is building a native mobile app that lets field staff view and edit Account and Case records. Admins often change page layouts, picklist values, and field-level security, and the mobile team doesn't want to release a new app version or write custom logic every time those settings change. Which Salesforce API should the architect recommend?

- A. User Interface API
- B. REST API sObject Describe and sObject Rows resources
- C. Metadata API
- D. Tooling API

**Correct answer:** A. User Interface API

**Explanation:** User Interface API is the same API Salesforce uses to build Lightning Experience and its mobile apps. It returns data and metadata in one response that already reflects admin changes to layouts, picklists, field-level security, and sharing. REST API sObject resources can read and write records, but the mobile team would have to interpret describe results and apply layout and security rules in its own code, which is exactly what the requirement wants to avoid. Metadata API is asynchronous and manages customizations for deployment, not record data for end users. Tooling API is aimed at development tools and fine-grained metadata access, not at building end-user record screens.

**Sources:** [Which API Do I Use?](https://help.salesforce.com/s/articleView?id=platform.integrate_what_is_api.htm&type=5), [About REST API](https://developer.salesforce.com/docs/platform/api-rest/guide/intro-what-is-rest-api.html)

### Question 12

Cloud Kicks service agents view 30 million order rows from an ERP as external objects through Salesforce Connect with the OData 4.0 adapter. During seasonal peaks, agents get errors because the org hits rate limits when accessing the external objects. The order data still must not be replicated into Salesforce. What should the integration architect recommend?

- A. Replace the external objects with a nightly Bulk API 2.0 load into a custom object
- B. Enable server-driven paging on the external data source
- C. Switch the external data source to the cross-org adapter
- D. Select the High Data Volume option on the external data source after reviewing its special behaviors and limitations

**Correct answer:** D. Select the High Data Volume option on the external data source after reviewing its special behaviors and limitations

**Explanation:** If an org hits rate limits when accessing external objects through the OData adapters, Salesforce recommends considering the High Data Volume option on the external data source, which bypasses most rate limits but introduces special behaviors and limitations to evaluate first. A nightly Bulk API 2.0 load replicates the data, which the requirement forbids. Server-driven paging lets the external system control page sizes for large result sets but doesn't address rate limits. The cross-org adapter connects only to other Salesforce orgs, not to an ERP.

**Sources:** [Integration Patterns Overview](https://architect.salesforce.com/docs/architect/fundamentals/guide/integration-patterns.html)

### Question 13

Universal Containers (UC) stores signed contracts in an external document management system (DMS). Sales reps will open contracts from Salesforce through Apex callouts to the DMS REST API, which supports the OAuth 2.0 authorization code grant. Compliance requires that every DMS request be authorized with the individual rep's own DMS permissions and appear under that rep's name in the DMS audit log. Which configuration should the integration architect recommend?

- A. An external credential with a named principal that authenticates as a DMS service account, with each rep's email address sent in a custom header for auditing
- B. An external credential that uses the OAuth 2.0 browser flow with a Per User Principal enabled through a permission set, with each rep authenticating in personal settings
- C. An external credential that uses the Custom authentication protocol, with a separate API key for each rep stored on per-user principals mapped to their permission sets
- D. An external credential that uses the OAuth 2.0 JWT bearer flow with a named principal, signing each JWT with a certificate generated in Salesforce for the org

**Correct answer:** B. An external credential that uses the OAuth 2.0 browser flow with a Per User Principal enabled through a permission set, with each rep authenticating in personal settings

**Explanation:** The per user identity type provides access control at the individual user level: each Salesforce user holds their own encrypted tokens for the external system, so the DMS authorizes and audits every call as that rep. For the OAuth 2.0 browser flow, the principal is enabled on a permission set or profile, and each user authenticates to the external system from the External Credentials page in their personal settings. A named principal shares one credential across all users, so the service account's DMS permissions would apply no matter what a custom header says. The Custom authentication protocol supports only the Named Principal identity type, so per-user API keys aren't possible. A JWT bearer flow with a named principal again authenticates every callout as the same identity.

**Sources:** [Named Credential Example: OAuth 2.0 Browser Flow with a Per User Principal](https://help.salesforce.com/s/articleView?id=xcloud.nc_example_oauth_github_per_user.htm&type=5), [Named Credentials Glossary](https://help.salesforce.com/s/articleView?id=xcloud.nc_named_credentials_glossary.htm&type=5)

## Build Solution (23%)

### Question 14

Universal Containers (UC) will expose order data to a distributor through a custom Apex REST service. The distributor must see only the orders shared with its integration user and must never receive fields that field-level security hides from that user. Which three actions should the integration architect require? Choose 3 answers.

- A. Declare the Apex REST class `with sharing` so that the integration user's record-level access is applied.
- B. Enforce object and field permissions in the service code, for example with `WITH USER_MODE` in SOQL or `Security.stripInaccessible` on the results.
- C. Rely on Apex REST to apply the calling user's field-level security automatically, because REST requests run in user context.
- D. Have the distributor authenticate with OAuth 2.0 as a dedicated integration user whose permissions grant only what the service needs.
- E. Add the distributor's domain to Remote Site Settings so that Salesforce accepts its inbound requests.

**Correct answers:** A. Declare the Apex REST class `with sharing` so that the integration user's record-level access is applied.; B. Enforce object and field permissions in the service code, for example with `WITH USER_MODE` in SOQL or `Security.stripInaccessible` on the results.; D. Have the distributor authenticate with OAuth 2.0 as a dedicated integration user whose permissions grant only what the service needs.

**Explanation:** Invoking a custom Apex REST method uses system context, so object permissions, field-level security, and sharing rules are not enforced by default. Sharing is applied only when the class is declared `with sharing`, and object and field access must be enforced in code with `WITH USER_MODE`, `Security.stripInaccessible`, or describe checks. Apex REST supports OAuth 2.0 and session ID authentication, and a dedicated least-privilege integration user makes the enforced permissions meaningful. The idea that Apex REST runs in user context and applies field-level security automatically is the opposite of the documented behavior. Remote Site Settings authorize outbound callouts from Apex, not inbound requests to Salesforce.

**Sources:** [Exposing Apex Classes as REST Web Services](https://developer.salesforce.com/docs/atlas.en-us.apexcode.meta/apexcode/apex_rest.htm), [Exposing Data with Apex REST Web Service Methods](https://developer.salesforce.com/docs/atlas.en-us.apexcode.meta/apexcode/apex_rest_exposing_data.htm)

### Question 15

Northern Trail Outfitters has been notified of upcoming Salesforce maintenance on its instance, including an instance refresh. Its on-premises middleware calls Salesforce through a hard-coded instance URL, the corporate firewall allows only a few Salesforce IP addresses that were captured years ago, and large batch integrations run every night. Which three actions should the integration architect recommend to keep the integrations running through maintenance? Choose 3 answers.

- A. Replace the hard-coded instance URL with the org's My Domain login URL in every integration endpoint.
- B. Ask Salesforce for a dedicated static IP address for the instance and allow only that address through the firewall.
- C. Prefer mutual TLS over IP allowlisting, and where an allowlist is still required, allow Salesforce's complete published IP ranges and update them before maintenance activities.
- D. Store the instance_url returned by the first OAuth token response permanently in the middleware configuration so that the endpoint never changes.
- E. Subscribe to Trust status notifications for the instance and defer non-critical batch integrations during announced maintenance windows.

**Correct answers:** A. Replace the hard-coded instance URL with the org's My Domain login URL in every integration endpoint.; C. Prefer mutual TLS over IP allowlisting, and where an allowlist is still required, allow Salesforce's complete published IP ranges and update them before maintenance activities.; E. Subscribe to Trust status notifications for the instance and defer non-critical batch integrations during announced maintenance windows.

**Explanation:** Salesforce recommends the org's My Domain login URL rather than instance-specific URLs to ensure continuity during instance refreshes and org migrations. Salesforce discourages IP allowlisting because added or changed IPs interrupt connections, recommends mTLS as the preferred alternative, and advises customers who must allowlist to allow the entire published range and add new IPs in advance of instance refreshes, site switches, and org migrations. The Reliability guidance recommends subscribing to status notifications for your instance and deferring background jobs during maintenance windows. Salesforce doesn't offer static IP addresses or small IP ranges for individual instances. Persisting a one-time instance_url recreates the same hard-coded dependency that breaks when the instance changes.

**Sources:** [Message Durability | Streaming API Developer Guide](https://developer.salesforce.com/docs/atlas.en-us.api_streaming.meta/api_streaming/using_streaming_api_durability.htm), [Salesforce Core Services - IP Addresses and Domains to Allow](https://help.salesforce.com/s/articleView?id=000384438&type=1), [Reliability | Well-Architected Framework | Salesforce Architects](https://architect.salesforce.com/docs/architect/well-architected/guide/reliability.html)

### Question 16

Universal Containers is choosing between a flow-driven outbound message and a flow-published platform event to notify its warehouse system when a shipment record is updated. The integration architect must explain to stakeholders how delivery differs between the two options. Which statement is accurate?

- A. Platform events can be received only by subscribers inside the same Salesforce org, while outbound messages can reach external endpoints.
- B. Salesforce retries platform event delivery until each subscriber acknowledges it, while outbound messages are sent once without retries.
- C. Outbound messages retry until the endpoint acknowledges or they're 24 hours old; platform events publish once and subscribers replay missed events by replay ID.
- D. Outbound messages can carry a custom JSON payload with fields from related objects, while platform events can carry only fields from the record that triggered them.

**Correct answer:** C. Outbound messages retry until the endpoint acknowledges or they're 24 hours old; platform events publish once and subscribers replay missed events by replay ID.

**Explanation:** The Integration Patterns guide says that if the remote service doesn't send a positive acknowledgment, Salesforce retries the outbound message, and the data integration guide adds that messages stay queued until sent successfully or until they're 24 hours old. Platform events are published to the event bus once with no retry on the Salesforce side, and subscribers recover missed events by replay ID within the retention window, 72 hours for high-volume events. External applications subscribe to platform events through Pub/Sub API, so they aren't limited to the same org. Outbound messages are SOAP messages built from fields on the object, while platform events carry a custom-defined payload. Salesforce also lists outbound messaging as a legacy option and suggests flow-triggered platform events as its replacement.

**Sources:** [Integration Patterns Overview](https://architect.salesforce.com/docs/architect/fundamentals/guide/integration-patterns.html), [Data Integration with Salesforce](https://architect.salesforce.com/docs/architect/decision-guides/guide/data-integration.html)

### Question 17

Cumulus Financial's loan partner will subscribe to the Loan_Status__e platform event through Pub/Sub API and publish Loan_Document__e events back to Salesforce, using a dedicated integration user. The security team wants to grant only the permissions required and to understand how quickly access ends if the partner contract is terminated. Which two statements should the integration architect include in the security design? Choose 2 answers.

- A. The integration user needs the View All Data permission, because platform event subscriptions ignore object permissions.
- B. The integration user needs Read permission on Loan_Status__e to subscribe and Create permission on Loan_Document__e to publish.
- C. Access to individual event messages must be restricted with sharing rules on the platform event object.
- D. The integration user needs Modify All on Loan_Status__e so that it can acknowledge the events it receives.
- E. After the permissions are removed from the integration user, an active subscription can keep receiving events, and publishing can keep working, for up to 10 minutes before the change takes effect.

**Correct answers:** B. The integration user needs Read permission on Loan_Status__e to subscribe and Create permission on Loan_Document__e to publish.; E. After the permissions are removed from the integration user, an active subscription can keep receiving events, and publishing can keep working, for up to 10 minutes before the change takes effect.

**Explanation:** Platform events conform to the org's security model: to subscribe, a user needs read access on the event, and to publish, the user needs create permission on the event, so least privilege means granting exactly those permissions. Pub/Sub API applies permission changes to an active subscription within 10 minutes, and a user who loses create permission can't publish after 10 minutes or less, so revocation isn't instantaneous. View All Data isn't required and would violate least privilege. Event messages aren't controlled with sharing rules; access is governed by permissions on the event. No Modify All permission is needed to acknowledge events; subscribers track their position with replay IDs.

**Sources:** [Remote Process Invocation—Fire and Forget | Integration Patterns and Practices](https://developer.salesforce.com/docs/atlas.en-us.integration_patterns_and_practices.meta/integration_patterns_and_practices/integ_pat_remote_process_invocation_fire_forget.htm), [General Considerations | Pub/Sub API](https://developer.salesforce.com/docs/platform/pub-sub-api/guide/considerations.html)

## Maintain Integration (8%)

### Question 18

Bloomington Caregivers uses a record-triggered flow to send an outbound message to a scheduling system's SOAP listener whenever a visit is confirmed. The outbound message was created with the Add failures to failed outbound message related list option selected. A network outage kept the listener offline for 30 hours, so some visit messages were never acknowledged. Now that the listener is back online, what should the administrator do to recover the messages that are no longer being retried?

- A. Wait, because Salesforce keeps retrying unacknowledged outbound messages automatically for up to seven days.
- B. Replay the messages from the event bus starting from the last acknowledged Replay ID.
- C. From the Outbound Messages page in Setup, click Retry on each message in the failed outbound messages related list.
- D. Ask users to edit and save each affected visit again so that the flow sends new messages.

**Correct answer:** C. From the Outbound Messages page in Setup, click Retry on each message in the failed outbound messages related list.

**Explanation:** Salesforce retries an unacknowledged outbound message for up to 24 hours, with the interval between attempts growing each time. After that, administrators must monitor the queue and retry by hand. Because this message adds failures to the failed outbound message related list, the failed messages appear on the Outbound Messages monitoring page, and clicking Retry moves each one back into the delivery queue for another 24 hours. Automatic retries stop at 24 hours even if support extends the timeout period to seven days. Outbound messages aren't stored on the event bus and have no Replay ID. Re-saving records by hand is error-prone and can run other automation for no reason.

**Sources:** [Track the Delivery Status of an Outbound Message](https://help.salesforce.com/s/articleView?id=platform.workflow_tracking_outbound_message_delivery_status.htm&type=5), [Remote Process Invocation—Fire and Forget](https://developer.salesforce.com/docs/atlas.en-us.integration_patterns_and_practices.meta/integration_patterns_and_practices/integ_pat_remote_process_invocation_fire_forget.htm)

## Related pages

- [Salesforce Integration Architect practice exam](https://www.certifyforce.com/salesforce-integration-architect-practice-exam)
- [Practice exam packs](https://www.certifyforce.com/practice-exams)
- [Official Integration Architect exam guide](https://help.salesforce.com/s/articleView?id=005298980&language=en_US&type=1)
