exam questions

Exam Certified Integration Architect All Questions

View all questions & answers for the Certified Integration Architect exam

Exam Certified Integration Architect topic 1 question 53 discussion

Actual exam question from Salesforce's Certified Integration Architect
Question #: 53
Topic #: 1
[All Certified Integration Architect Questions]

Northern Trail Outfitters needs to secure an integration with an external Microsoft Azure API Gateway.
Which integration security mechanism should be employed?

  • A. Use an API-only user profile and implement an external identity provider with federated API access.
  • B. Configure mutual server authentication with two way SSL using certification authority (CA) signed certificates.
  • C. Configure a connected app with an authorization endpoint of the API Gateway and configure OAuth settings.
  • D. Implement Salesforce Shield with Encryption at Rest and generate a tenant secret.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Community vote distribution
B (75%)
C (25%)

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Big_Fella
6 days, 9 hours ago
Selected Answer: B
Explanation: Two-way SSL (Mutual TLS) is a widely accepted security mechanism for securing API integrations with external systems, especially when integrating with Microsoft Azure API Gateway or other cloud services. Mutual authentication ensures that both Salesforce and the external API Gateway verify each other’s identities before allowing data exchange. CA-signed certificates provide additional security by ensuring that only authorized entities communicate with the API Gateway. Why NOT C? OAuth is great for authentication and token-based access but does not provide the same level of security as mutual TLS (mTLS) for API-to-API communications. OAuth would be more relevant for user-level authentication, while mTLS is better for securing system-level API calls.
upvoted 1 times
...
Paul421
4 months ago
Selected Answer: B
assuming your calling out
upvoted 1 times
...
Alf8
5 months, 3 weeks ago
Selected Answer: B
The way the question is formulate is ambiguous but based on "an integration with an external Microsoft Azure API Gateway" it reads this is for outbound flows - SF to API GW in which case Connected App is not applicable.
upvoted 1 times
...
u39403918
7 months, 3 weeks ago
Selected Answer: C
I think its also C
upvoted 1 times
...
deusexmorte
8 months ago
can anyone eleborate why it is B and not C?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
PT0-002
Sydney, 1 minute ago