Salesforce Certified Platform Developer II Practice Questions
Prepare for Platform Developer II with more than an answer.
Unlock the full exam and previous versions
- v1Salesforce Certified Platform Developer II 129 questions Locked
- Platform Developer IILegacy Salesforce Certified Platform Developer II 251 questions Current
- Exam fee
- $200 USD
- Level
- Professional
- Valid for
- Requires annual maintenance
Domains covered on the exam 8
- Salesforce Fundamentals10%
- Data Modeling and Management15%
- Logic and Process Automation27%
- User Interface14%
- Performance7%
- Integration13%
- Testing11%
- Debug and Deployment Tools3%
- 1
A developer needs to dynamically construct a SOQL query at runtime based on user-selected filters from a Visualforce page. The filter values are passed directly into the query string. What is the primary security vulnerability in this approach and how should it be mitigated?
Show answer details
Correct answer: B
Directly concatenating user input into a dynamic SOQL query string creates a SOQL Injection vulnerability. A malicious user could provide input that alters the query's logic, potentially exposing sensitive data. The primary mitigation technique in Apex is to sanitize any user-supplied variables by using the
String.escapeSingleQuotes()method before including them in the query string. This prevents the input from breaking out of the string literal and being interpreted as SOQL. - 2
A retail company has a requirement that
Sales_Rep__cusers should only seeOrder__crecords for their assigned region. However,Regional_Manager__cusers must be able to see allOrder__crecords within their region and the regions of all sales reps who report to them in the role hierarchy. The organization-wide default forOrder__cis Private. How can a developer programmatically grant this specific access to managers?Show answer details
Correct answer: B
This complex sharing requirement, which depends on the role hierarchy and custom logic (manager seeing their reps' regions), cannot be met with standard sharing rules. The appropriate solution is Apex Managed Sharing. A developer can write an Apex trigger on the
Order__cobject that identifies the record owner's manager and the manager's subordinates, then programmatically inserts records into theOrder__Shareobject to grant the necessary read/write access. - 3
A developer is writing an Apex trigger that fires on
after updateof theOpportunityobject. The trigger needs to perform a callout to an external web service. What is the primary issue with this design, and what is the recommended solution?Show answer details
Correct answer: B
Salesforce does not allow DML operations to be pending in the same transaction when a callout is made. Since a trigger runs in a synchronous transaction that includes DML (the update that fired it), you cannot make a direct, synchronous callout. The correct solution is to decouple the callout by invoking an asynchronous Apex method (like one annotated with
@future(callout=true)or a Queueable job) from the trigger. - 4
What are the key benefits of using a
StandardSetControllerin a Visualforce page? (Select THREE)Show answer details
Correct answer: A, C, D
- 5
Case Study:
A company has a complex process for provisioning
Service_Request__crecords. When a record is inserted, several automations fire:- A
before inserttrigger (TRG_ServiceRequest_Before) sets a defaultPriority__c. - An
after inserttrigger (TRG_ServiceRequest_After) creates a relatedService_Task__crecord. - A record-triggered Flow (after-save) updates a
Provisioning_Status__cfield on the parentAccountto 'In Progress'. This Account update causes an Account trigger to fire. - A Process Builder (on create) sends an email alert to the Account owner.
A user reports that when they create a new
Service_Request__c, theProvisioning_Status__con the Account is being set correctly, but theService_Task__crecord is not being created. Debug logs show theafter inserttrigger onService_Request__cstarts but never completes its DML operation, and no error is thrown.What is the most likely cause of this issue?
graph TD subgraph Transaction 1 (Service_Request__c Insert) A[Start] --> B(Before Trigger: Set Priority); B --> C(Database Save); C --> D(After Trigger: Create Service_Task__c); D --> E(Flow: Update Account Status); E --> F(Process Builder: Email Alert); F --> G(Commit); end subgraph Transaction 2 (Account Update from Flow) H[Start Account Update] --> I(Account Triggers Fire); I --> J(Commit Account); end E --> H;Show answer details
Correct answer: C
The entire sequence of operations resulting from the initial DML is part of a single transaction. The Flow's update to the Account happens after the
after inserttrigger onService_Request__c. This Account update then causes the Account trigger to fire. If the Account trigger has an unhandled exception (e.g., a null pointer, a failed DML), it will cause the entire transaction to roll back to its state before the initialService_Request__cinsert. This means theService_Task__cthat was created in memory by theafter inserttrigger is never committed to the database. The user sees the Account status update because it's the last thing that happened before the error, but the rollback prevents the task from being saved. - A
- 6
A financial services company uses a custom Apex REST service to receive transaction data from a third-party system. The service must process batches of up to 200 transactions, create corresponding custom
Transaction__crecords, and update the relatedAccount. If any transaction in the batch is invalid, the entire operation must be rolled back, and a specific error message must be returned. Which Apex feature is most appropriate for maintaining transactional integrity in this scenario?Show answer details
Correct answer: C
Using
Database.SavepointandDatabase.rollback()provides explicit control over the transaction. By setting a savepoint before attempting the DML operations, the developer can catch any exception, roll back all changes to the state of the database before the savepoint was set, and then return a controlled error message. A simple try-catch with a thrown exception also rolls back the transaction, but using a savepoint is the canonical and most explicit way to manage partial transaction rollbacks or full rollbacks while maintaining control over the execution flow to return a specific response. - 7
A developer is building a Lightning Web Component to display a list of related
Caserecords on anAccountpage. The component must be reusable and configurable by an administrator, allowing them to specify theStatusandPriorityto filter the cases shown. How should the developer implement this configurability for the Lightning App Builder?Show answer details
Correct answer: C
To make LWC properties configurable in the Lightning App Builder, they must be declared as public properties using the
@apidecorator in the component's JavaScript file. Additionally, these properties must be exposed in the component's configuration file (.js-meta.xml) within thesection. This allows administrators to set values for these properties directly in the App Builder's UI. - 8
Universal Containers needs to synchronize large volumes of
Product__crecords (potentially over 1 million) nightly from an external Product Information Management (PIM) system. The process involves complex transformations and enrichment logic that cannot be handled by middleware. A developer has decided to implement this using Batch Apex. To optimize performance and avoid governor limit issues, what is the best approach for thestartmethod to query the records to be processed?Show answer details
Correct answer: B
For processing large data sets (over 50,000 records),
Database.QueryLocatoris the optimal choice for thestartmethod of a Batch Apex class. It bypasses the heap size limit for the total number of records retrieved by the query because it fetches records in chunks. In contrast, returning anIterableor aListloads all records into the heap at once, which would cause a heap limit exception with over 1 million records. - 9
A developer needs to write a unit test for a method that makes an HTTP callout to an external weather service. The test must verify the logic that parses the JSON response and updates a
Forecast__crecord. Which two approaches are necessary to ensure the test runs successfully without making a real callout and properly isolates the test data? (Select TWO)Show answer details
Correct answer: A, C
- 10
A Visualforce page uses a custom controller to display a data table of
Opportunityrecords. The controller uses a large, complex SOQL query to gather the data. Users report that the page sometimes throws a 'Maximum view state size limit exceeded' error, especially when filtering results that return many rows. Which modification is the most effective way to mitigate this specific error?Show answer details
Correct answer: B
The view state error is caused by large amounts of data being stored in the controller's properties between server requests. The
transientkeyword prevents a variable from being saved as part of the view state. While this means the data will need to be re-fetched on each postback, it directly solves the 'Maximum view state size' error by removing the large data list from the view state.
