Skip to main content
🎉 All exam preparation materials are available for free until 30 September 2026.

Last updated: September 2026

Practice Exam

Analytics-Arch-201 — Salesforce Certified Tableau Architect

Test your knowledge with official exam-style questions

Questions25Passing63%Exam time105 min

Questions and options are shuffled each attempt

Email me this practice set

Get a link sent to your inbox so you can pick this back up anytime.

▶Salesforce Certified Tableau Architect — Practice Set 1: All Questions & Explanations

Full question text, answer options, and explanations for this practice set — a spoiler-free alternative is the interactive quiz above for scored, shuffled practice.

  1. 1. A customer wants to license 300 Creators, 1,200 Explorers, and 5,000 Viewers, but expects to occasionally exceed these counts during quarterly business reviews when extra staff need Explorer access for a few days. Which licensing strategy should the architect recommend to address this fluctuating demand?

    • A. Purchase permanent Explorer licenses sized for the peak quarterly headcount
    • B. Recommend Authorization-to-Run (ATR) licensing to allow temporary overages that true-up at renewal(correct)
    • C. Downgrade all Explorers to Viewers during the review period and upgrade them back afterward
    • D. Create a second Tableau Cloud site solely for the quarterly reviewers

    Explanation: Authorization-to-Run (ATR) licensing is specifically designed to let a customer exceed its contracted license counts temporarily, with usage reconciled and trued-up at contract renewal, which matches this bursty, short-term demand. Buying permanent licenses for peak (A) wastes budget most of the year. Manually reassigning roles (C) is operationally disruptive and doesn't scale. Standing up a second site (D) adds unnecessary administrative overhead and doesn't solve the licensing shortfall.

  2. 2. An enterprise customer is planning a migration of an on-premises Tableau Server environment to Tableau Cloud. Which two activities should the architect include in the migration plan? (Choose 2)

    • A. Use the Tableau Content Migration Tool to move projects, workbooks, and data sources(correct)
    • B. Plan and implement Tableau Bridge for data sources that must remain on-premises(correct)
    • C. Manually recreate the coordination ensemble on the destination environment
    • D. Disable SSL encryption during the migration window to speed up content transfer

    Explanation: The Tableau Content Migration Tool is the supported approach for moving projects, workbooks, and data sources between sites/servers, and Tableau Bridge is required for live connections or scheduled refreshes against data that must stay behind a customer's firewall when moving to Tableau Cloud. A coordination ensemble (C) is a Tableau Server-only concept and does not apply to Tableau Cloud, which is fully managed. Disabling SSL (D) is never a recommended practice, even temporarily.

  3. 3. A customer requires zero data loss and near-zero downtime for its Tableau Server repository in the event of a data center outage. Which architectural recommendation best addresses this disaster recovery requirement?

    • A. Rely solely on nightly `tsm maintenance backup` exports stored offsite
    • B. Configure external PostgreSQL repository replication to a standby data center as part of the disaster recovery strategy(correct)
    • C. Increase the number of VizQL Server processes on the primary node
    • D. Enable server-side caching to reduce repository read load

    Explanation: For near-zero data loss and downtime, an architect must design a disaster recovery strategy involving an externalized repository with database-level replication to a standby environment, since native `tsm` backups only provide point-in-time recovery with data loss between backup windows. Increasing VizQL processes (C) addresses query concurrency, not resiliency. Caching (D) improves performance, not disaster recovery.

  4. 4. During requirements gathering for a new Tableau Server deployment, which factor is most important for determining the initial process topology and future node count?

    • A. The color palette preferences of the executive sponsors
    • B. The distribution of Creator, Explorer, and Viewer roles and expected growth in users and content(correct)
    • C. The number of email distribution lists used for subscriptions
    • D. The font licensing agreements of the organization

    Explanation: Evaluating requirements for users and their role distributions, along with anticipated future growth, directly drives decisions on process counts, node counts, and service placement. Color palettes, distribution lists, and font licensing have no bearing on infrastructure sizing.

  5. 5. A customer wants to give a subsidiary its own independently branded Tableau Cloud environment and site administrators, while the parent company retains a single Tableau Cloud contract. What should the architect recommend?

    • A. Create a new project within the existing site and apply a custom permission set
    • B. Plan and implement multi-site using Tableau Cloud Manager(correct)
    • C. Purchase a completely separate Tableau Cloud pod for the subsidiary
    • D. Use Tableau Bridge to isolate the subsidiary's data sources

    Explanation: Tableau Cloud Manager supports planning and implementing multiple sites under a single Tableau Cloud contract, each with independent branding and site administration, which is exactly this requirement. A single project (A) cannot provide independent branding or site-level administration. A separate pod (C) is unnecessary and costly. Tableau Bridge (D) is for data connectivity, not site isolation.

  6. 6. An architect is designing a production Tableau Server deployment that must scale file storage independently from the application nodes and support high availability. Which configuration should be implemented?

    • A. Configure an external file store(correct)
    • B. Increase the number of Backgrounder processes on each node
    • C. Configure Tableau for a load balancer only
    • D. Install additional VizQL Server processes on the initial node

    Explanation: Configuring an external file store decouples extract and data file storage from the Tableau Server nodes, enabling independent scaling and improved resiliency, which is a documented production-readiness configuration. Backgrounder and VizQL process counts affect job and query throughput, not file storage scalability. A load balancer alone addresses traffic distribution, not storage architecture.

  7. 7. A financial services customer requires SSO integration with an on-premises identity provider that supports Kerberos, plus embedded dashboards inside a custom portal that must authenticate without prompting users again. Which two authentication methods should the architect configure? (Choose 2)

    • A. Kerberos(correct)
    • B. Trusted authentication(correct)
    • C. LDAP simple bind only
    • D. Mutual SSL

    Explanation: Kerberos directly satisfies the requirement for integrated Windows/on-premises identity provider SSO, and trusted authentication (also known as trusted tickets) is the documented method for silently authenticating users into embedded views inside a custom application without a second login prompt. LDAP simple bind alone does not provide SSO. Mutual SSL authenticates client certificates and is not the standard mechanism for embedding dashboards in a portal.

  8. 8. A customer requires that data be encrypted both while stored on disk and while in transit between Tableau Server nodes. Which combination of features addresses both requirements?

    • A. SSL encryption for data in transit and database/extract encryption for data at rest(correct)
    • B. SPNs for Kerberos alone
    • C. Trusted authentication alone
    • D. Mutual SSL alone

    Explanation: SSL encryption protects inter-node and client communication (data in transit), while database and extract encryption protect stored repository and extract data (data at rest) — together they satisfy both requirements. SPNs are specifically for Kerberos service identification, not general encryption. Trusted authentication and Mutual SSL address authentication scenarios, not encryption at rest.

  9. 9. Which tool provides automated, repeatable installation and configuration of Tableau Server without manual clicks through the Installation Wizard, ideal for standing up new nodes consistently?

    • A. The Silent Installer, driven by a script(correct)
    • B. The Resource Monitoring Tool
    • C. TabJolt
    • D. The Tableau Content Migration Tool

    Explanation: The Silent Installer allows Tableau Server to be installed and configured via a script rather than the interactive Installation Wizard, which is the documented approach for automated, repeatable deployments. The Resource Monitoring Tool is for observability, TabJolt is a load-testing tool, and the Content Migration Tool moves content, not server installations.

  10. 10. During a Linux installation of Tableau Server, the installer reports it cannot bind to required ports and services fail to start. What should the architect check first?

    • A. Operating system and networking configuration, including firewall rules and port availability(correct)
    • B. The color theme applied to published workbooks
    • C. Whether Tableau Desktop is installed on the same machine
    • D. The number of dashboard extensions configured

    Explanation: Port binding and service startup failures during installation are most commonly caused by operating system and network configuration issues, such as firewall rules blocking required ports — this is an explicitly documented troubleshooting area for Linux installs. Workbook themes, Tableau Desktop presence, and dashboard extensions are unrelated to server-side installation failures.

  11. 11. A customer wants Tableau Server processes to run under a dedicated domain service account on Windows rather than the local system account, to align with their security policy. Which feature should the architect use?

    • A. The Run As service account feature(correct)
    • B. Mutual SSL configuration
    • C. The Metadata API
    • D. An unlicensed node

    Explanation: The Run As service account feature on Windows lets Tableau Server services run under a specified domain account instead of the default local system account, satisfying enterprise security policies. Mutual SSL is an authentication mechanism, the Metadata API is for querying lineage/metadata, and an unlicensed node is a topology concept unrelated to service account configuration.

  12. 12. A regulated customer must deploy Tableau Server into a network with no internet access whatsoever, including for the installer download and license activation. What deployment approach should the architect plan for?

    • A. Install in an air-gapped environment using offline installation and activation packages(correct)
    • B. Use the standard online Installation Wizard and temporarily open outbound HTTPS during setup
    • C. Configure an external gateway to proxy all license checks
    • D. Deploy Tableau Cloud instead, since it does not require internet connectivity

    Explanation: Installing in an air-gapped environment is a documented deployment scenario in which offline installation files and offline activation are used because no internet connectivity is available at all. Temporarily opening HTTPS (B) violates the stated air-gapped requirement. An external gateway (C) still assumes some connectivity path. Tableau Cloud (D) is a SaaS product that inherently requires internet access, making it the opposite of an appropriate recommendation here.

  13. 13. A customer wants to validate that their multi-node Tableau Server disaster recovery plan actually works before relying on it in production. What should the architect recommend?

    • A. Validate the disaster recovery/high availability test strategy through a planned, controlled failover test(correct)
    • B. Assume the configuration is correct because backups complete successfully every night
    • C. Review only the Tableau Server release notes for disaster recovery guidance
    • D. Skip validation and rely on the vendor's SLA documentation alone

    Explanation: Validating a disaster recovery/high availability test strategy through an actual controlled test is the documented practice for confirming a DR plan works, since successful backups alone do not prove that restoration or failover succeeds end-to-end. Reading release notes or relying solely on an SLA does not verify the customer's specific environment actually recovers correctly.

  14. 14. A customer wants to release a major Tableau Server upgrade with minimal downtime by standing up the new version alongside the old one and cutting traffic over once validated. Which deployment pattern is this?

    • A. A blue-green deployment(correct)
    • B. A rolling restart
    • C. An unlicensed node configuration
    • D. A coordination ensemble reconfiguration

    Explanation: A blue-green deployment involves running the new environment (green) in parallel with the existing production environment (blue) and switching traffic over once the new version is validated, minimizing downtime and risk — this is an explicitly named deployment technique for production-ready Tableau Server. A rolling restart only restarts existing services, an unlicensed node is a cost-saving topology role, and a coordination ensemble concerns cluster consensus services, not upgrade strategy.

  15. 15. A Tableau Server administrator wants to build a dashboard showing publish activity, login trends, and extract refresh failures across the entire site over the last quarter. Which approach should the architect recommend?

    • A. Build custom administrative views by interpreting the repository schema and relevant event types(correct)
    • B. Manually export server logs to a spreadsheet weekly
    • C. Use TabJolt to generate the report
    • D. Rely exclusively on the default Server Status page

    Explanation: Custom administrative views, built by querying and interpreting the Tableau Server repository schema and its event types, are the documented method for creating tailored operational dashboards on activity like publishing, logins, and extract failures. Manual spreadsheet exports don't scale, TabJolt is a load-testing tool, and the default Server Status page offers only basic real-time status, not historical trend analysis.

  16. 16. Before an enterprise customer moves their heaviest dashboards to production, they want to simulate 500 concurrent users and observe how the server responds under load. Which tool and step combination should the architect recommend?

    • A. Configure and use a load testing tool such as TabJolt, with an appropriate test environment and test plan(correct)
    • B. Manually ask 500 employees to log in simultaneously
    • C. Enable Admin Insights only, without any test environment
    • D. Increase Backgrounder process count and skip formal testing

    Explanation: Load testing tools such as TabJolt, combined with a properly configured test environment and test plans, are the documented approach for simulating concurrent user load and interpreting results before a production go-live. Manually coordinating real users is unreliable and not repeatable. Admin Insights provides historical usage analytics, not synthetic load simulation. Increasing process counts without testing risks masking real capacity problems.

  17. 17. Users report that a specific dashboard has become progressively slower over several weeks, but overall server CPU and memory look normal. What is the most appropriate next step for the architect?

    • A. Perform resource analysis, latency analysis, and workload analysis to determine the root cause of the performance issue(correct)
    • B. Immediately add two more worker nodes without further analysis
    • C. Delete and republish the dashboard with a new name
    • D. Ignore the report since overall server metrics look normal

    Explanation: Because normal server-wide metrics can mask a workbook-specific issue (e.g., an inefficient data source, calculation, or growing extract), the documented approach is targeted resource, latency, and workload analysis to isolate root cause before acting. Adding nodes (B) is a costly guess that may not fix a workbook-level problem. Republishing under a new name (C) doesn't address an underlying design issue. Ignoring the report (D) leaves a real user-facing problem unresolved.

  18. 18. An architect wants to establish an ongoing observability practice for a multi-node Tableau Server environment. Which two data sources should be part of the recommended strategy? (Choose 2)

    • A. Tableau Server process metrics(correct)
    • B. Operating system and hardware-related metrics(correct)
    • C. The visual theme applied to the site's default project
    • D. The number of favorited views per user

    Explanation: A sound observability strategy recommends collecting and analyzing both Tableau Server process metrics and operating system/hardware-related metrics, since performance problems can originate at either layer. Site theming and favorites counts are cosmetic/usage details with no bearing on infrastructure health monitoring.

  19. 19. A customer wants to programmatically add nodes, change topology, and automate common administrative tasks against their Tableau Server without using the web UI. Which set of tools should the architect recommend?

    • A. Tableau Services Manager (TSM), REST APIs, and tabcmd(correct)
    • B. TabJolt exclusively
    • C. The Resource Monitoring Tool exclusively
    • D. Admin Insights exclusively

    Explanation: Tableau Services Manager (TSM), the REST APIs, and tabcmd are the documented tools for managing and changing Tableau Server resources programmatically. TabJolt is a load-testing tool, the Resource Monitoring Tool is for observability, and Admin Insights is an analytics workbook for usage — none of these three provide the programmatic administrative control described.

  20. 20. A customer wants nightly cleanup of stale subscriptions and automated backups without any manual intervention. Which capability should the architect configure?

    • A. Automate maintenance tasks, such as cleanup and backup, using scheduled scripts(correct)
    • B. Manually run tsm maintenance backup every night from a laptop
    • C. Disable subscriptions entirely to avoid the need for cleanup
    • D. Rely on Tableau Support to run backups on the customer's behalf

    Explanation: Automating maintenance tasks such as cleanup and backup via scheduled scripts is the documented recommendation for eliminating manual, error-prone nightly operations. Manually running commands from a laptop is unreliable and not scalable. Disabling subscriptions removes needed functionality rather than solving the maintenance problem, and Tableau Support does not manage a customer's day-to-day backups.

  21. 21. A customer needs to upgrade a four-node production Tableau Server cluster to the newest release while minimizing user disruption. What should the architect plan for?

    • A. Plan and implement a multi-node server upgrade following the documented upgrade process(correct)
    • B. Uninstall Tableau Server on all nodes simultaneously and reinstall from scratch
    • C. Skip testing the upgrade in a non-production environment first
    • D. Upgrade only the primary node and leave worker nodes on the old version indefinitely

    Explanation: Planning and implementing a multi-node server upgrade following Tableau's documented process is the correct approach for minimizing disruption on a clustered environment. Uninstalling and reinstalling from scratch (B) causes unnecessary downtime and risk. Skipping non-production testing (C) increases the risk of an untested failure in production. Leaving worker nodes on a different version than the primary (D) is not a supported configuration.

  22. 22. A customer wants a partner application to programmatically discover the lineage between a Tableau data source and the underlying database tables it depends on. Which capability should the architect recommend configuring?

    • A. Configure and use the Metadata API(correct)
    • B. Configure trusted tickets only
    • C. Enable the Resource Monitoring Tool agent
    • D. Schedule a webhook for workbook publish events

    Explanation: The Metadata API is the documented Tableau capability specifically designed to programmatically query lineage and metadata relationships between content and underlying data sources. Trusted tickets address embedded authentication, the Resource Monitoring Tool agent supports observability metrics collection, and webhooks notify on events rather than exposing lineage data.

  23. 23. A customer wants a lightweight, embeddable widget that lets viewers filter a published dashboard using a custom web form hosted outside Tableau. Which feature should the architect recommend?

    • A. A dashboard extension(correct)
    • B. The coordination ensemble
    • C. TSM CLI commands
    • D. The Resource Monitoring Tool

    Explanation: Dashboard extensions allow embedding of custom web components that interact with a Tableau dashboard, such as a custom filter form, which is exactly the documented use case for extensions. The coordination ensemble is a Tableau Server clustering component, TSM CLI commands manage server configuration, and the Resource Monitoring Tool provides observability — none address embedding interactive custom widgets in dashboards.

  24. 24. An architect reviews six months of observability data and notices that the backgrounder queue consistently backs up every Monday morning as hundreds of scheduled extract refreshes fire at the same time. What is the most appropriate action based on this observability data?

    • A. Revise the architecture, for example by staggering schedules or adding backgrounder capacity, based on the observed pattern(correct)
    • B. Ignore the pattern since it resolves itself by Monday afternoon
    • C. Disable all extract refreshes permanently
    • D. Restart the entire Tableau Server cluster every Monday morning as a workaround

    Explanation: Revising the architecture based on observability data — such as staggering refresh schedules or increasing backgrounder process/node capacity — is the documented practice for translating monitoring insights into concrete infrastructure or process changes. Ignoring a recurring bottleneck (B) leaves recurring risk and user impact unaddressed. Disabling refreshes (C) removes needed functionality. Restarting the cluster weekly (D) is a disruptive workaround, not a root-cause fix.

  25. 25. A customer's compliance team needs a detailed, queryable record of every sign-in, content view, and permission change across their Tableau Cloud site for the past 90 days. Which feature should the architect recommend?

    • A. Configure and implement Activity Log for Tableau Cloud(correct)
    • B. Rely on the default Server Status page
    • C. Manually ask each user to self-report their activity
    • D. Use TabJolt to reconstruct historical activity

    Explanation: Configuring and implementing the Activity Log for Tableau Cloud (or Tableau Server) is the documented feature that provides a detailed, queryable record of sign-ins, content views, and permission changes for compliance and auditing purposes. The Server Status page shows current operational state, not a historical audit trail. Self-reporting is unreliable, and TabJolt is a load-testing tool with no relationship to activity auditing.