Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Salesforce Certified B2C Commerce Developer Comm-Dev-101 Exam Questions

Page: 1 / 11 Total 154 questions

Want more questions? Get Premium Access.

Question 1

Multiple shoppers report slow performance on the Product Details Page.

Which tool can a developer use to view average response times for the Product-Detail controller route?

Correct Answer: A. Pipeline Profiler
Explanation:

ThePipeline Profileris the appropriate performance-analysis tool because it reports execution statistics for storefront controllers and their underlying scripts, including hit counts, total processing time, andaverage response/run time.

Salesforce's performance troubleshooting documentation specifically recommends Pipeline Profiler for measuring deployed storefront-code performance and identifying expensive pipelines or controllers. The profiler presents high-level response-time information and allows the developer to drill down into individual scripts contributing to the controller's execution time.

This makes it appropriate for diagnosing reports that a product-details route has become slow. After identifying the expensive controller, the developer can inspect its script-level execution data to determine whether custom models, service calls, product logic, templates, or other components are contributing excessive processing time.

Request logs are useful for examining the sequence and context of individual requests but are not the principal tool for aggregating controller average processing times. The URL Request Analyzer is likewise not the intended answer for this performance metric.

Study Guide reference:Application Development --- Pipeline Profiler, controller performance, average execution time, script profiling, and storefront performance troubleshooting.


Question 2

A developer needs to show only car accessories when shoppers use the search term "car accessories" and exclude technology accessories and household accessories.

Given the above requirement, what is the recommended approach using the Search Dictionaries Dashboard?

Correct Answer: B. Create a Common Phrase Dictionary entry: car accessories. Use search mode Exact Match.
Explanation:

ACommon Phraseis specifically intended for multi-word searches whose words must be interpreted together and in sequence. Configuringcar accessoriesas a common phrase withExact Matchreduces search noise and causes the phrase to be treated as a meaningful unit rather than allowing the generic termaccessoriesto broaden results toward unrelated accessory categories.

Salesforce defines common phrases as search terms containing two to five adjacent words in a specific order and explains that they are used to provide more targeted results for multi-word queries. With Exact Match mode, only products matching the exact phrase are returned for that phrase.

Option A is inappropriate because synonym relationships expand equivalent terminology; declaring household and technology as synonyms of car accessories would increase irrelevant matches instead of eliminating them. Option C introducesNOTexpressions into the dictionary value, which isn't the required way to define this common phrase.

This use case illustrates the distinction between search dictionaries: synonyms broaden equivalent terminology, whereas common phrases preserve the semantic significance of words occurring together.

Study Guide reference:Data Management Using Business Manager Usage --- Search Dictionaries, Common Phrases, Exact Match search mode, synonyms, and storefront search relevance.


Question 3

Business Manager has the configuration:

* Active Log category is "root"

* Log level of WARN

The code below is executing:

varlog=Logger.getLogger("products");

Using this information, what will be written to the log?

Correct Answer: A. log.warn('This is a warn message'); AND log.error('This is an error message');
Explanation:

Therootcategory is the parent of all custom logger categories, includingproducts. Therefore, the WARN threshold configured at root applies to theproductslogger unless a more specific category configuration overrides it.

B2C Commerce logging severity is hierarchical: enabling a particular level also enables all higher-severity levels. Salesforce gives the explicit example that when WARN is enabled for a category,WARN and ERRORmessages are logged for that category and its subcategories. Root configuration likewise applies to all custom categories.

Consequently,log.warn()andlog.error()both qualify for persistence.log.info()does not because INFO is below WARN in the severity hierarchy. The exact text placed inside the INFO call doesn't matter; logging eligibility is determined by the API method/severity, not whether the message string contains the word 'warn.'

This hierarchical configuration allows administrators to maintain a conservative production logging threshold while selectively enabling more detailed logging for particular categories when troubleshooting.

Study Guide reference:Application Development ---dw.system.Logger, log categories, root logger hierarchy, severity thresholds, and custom logging configuration.


Question 4

In Log Center, a developer notes a number of Cross Site Request Forgery (CSRF) log entries.

After adding the token in the ISML template, which action might solve this problem?

Correct Answer: A. Add csrfProtection middleware steps in the controller.
Explanation:

Adding the CSRF token to the rendered form is only one half of the protection mechanism. The server-side controller handling the request must also validate that token. In SFRA, this is normally implemented through the CSRF protection middleware supplied with the storefront framework. Therefore, adding the appropriatecsrfProtectionmiddleware to the controller route is the correct response.

Salesforce's SFRA guidance demonstrates controller routes using CSRF middleware such ascsrfProtection.validateAjaxRequestor the appropriate request-validation middleware before processing protected form submissions. The underlying CSRF API generates and validates tokens to verify that a state-changing request originated from the expected storefront interaction.

Merely extending token validity would weaken the intended security behavior and does not correct a route that fails to perform validation correctly. Deleting a supposed allow list similarly does not implement the required request-verification sequence.

The proper architecture is therefore: generate a token, render it into the client request or form, transmit it back during submission, and validate it server-side before executing protected business logic.

Study Guide reference:Application Development --- SFRA middleware, CSRF protection, secure controller routes, forms, and request validation.


Question 5

A merchant has a new requirement to accept American Express credit cards on its Storefront. A credit card payment method already exists.

Which step must a developer take in Business Manager to achieve this?

Correct Answer: A. In Payment Methods, enable American Express as a credit card type.
Explanation:

Because the storefront already has the standard credit-card payment method, the additional requirement is to makeAmerican Express an accepted card typewithin that payment-method configuration. B2C Commerce distinguishes the general payment method (CREDIT_CARD) from the specific credit/debit card brands accepted through it.

Salesforce's Payment Methods documentation directs administrators to the Credit/Debit Cards configuration associated specifically with the defaultCREDIT_CARDpayment method. This is where supported card types are managed.

A payment processor is the technical processing implementation associated with payment methods. American Express does not need to become a completely separate payment processor merely because the merchant wants to accept that card brand. The actual processor must of course support American Express, but the storefront-facing card availability is configured under the credit-card payment-method/card-type configuration.

Option C is incorrect because card brands are not enabled by creating arbitrary Site Preferences.

This architecture keeps payment presentation and processing responsibilities separate: payment methods and accepted card types govern what the shopper can select, while payment processors govern authorization, capture, and other transaction handling.

Study Guide reference:Data Management Using Business Manager Usage --- payment methods, credit/debit card types, payment processors, and checkout configuration.


Question 6

There is a business requirement to allow a third-party warehouse management system to update the MySample.com storefront product inventory in real time. The architect decided that this is most easily accomplished by using the Open Commerce API (OCAPI). The developer needs to test the OCAPI settings in their sandbox. Assume the client ID for testing is "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa". What is the correct OCAPI setting for this?

Correct Answer: A. Type:Data,Context:Global{'_v':'20.4','clients':[{'client_id':'aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa','allowed_origins':['http://www.example.com'],'resources':[{'resource_id':'/inventory_lists/*','methods':['get','put','patch'],'read_attributes':'(**)','write_attributes':'(**)'}]}]}
Explanation:

Inventory administration is a merchant-data integration concern and belongs to theOCAPI Data API, not the shopper-oriented Shop API. In addition, most Data API resources are organization-specific and therefore useGlobalOCAPI permissions. The/inventory_lists/*resource is the relevant resource family for managing inventory lists through the Data API.

Salesforce explains that the Data API provides create/read/update/delete access to administrative system resources, while OCAPI settings define which resource paths and HTTP methods a client is allowed to use. The current Commerce API documentation likewise identifies Inventory Lists as administrative inventory resources.

Options B and C use/product/*/inventory, which is not the appropriate Data API inventory-list resource shown for this architecture. Option B additionally selects the Shop API and site context, which do not match a warehouse-management integration updating backend inventory data.

The configuredget,put, andpatchpermissions enable the external integration to retrieve inventory information and perform complete or partial updates, subject to authentication and the resource schema.

Study Guide reference:Application Development --- OCAPI Data API, inventory lists, Global OCAPI configuration, resource permissions, and warehouse integrations.


Question 7

Given the sandbox with:

* Service configured and assigned to its profile and credential

* A code version that uses that service

And given the requirement to limit the number of success or error calls the code can perform to a restricted number of calls per second. Which configuration should the developer perform?

Correct Answer: B. Set the rate limiter in the service profile and configure its values with the ones required.
Explanation:

The B2C Commerce Service Framework provides arate limiterspecifically for controlling the maximum number of outbound service calls permitted during a defined time interval. This configuration belongs to theService Profileassociated with the service. The profile exposes values equivalent to the maximum permitted calls and the rate-limit interval in milliseconds.

Salesforce documents that the Service Profile controls timeout, rate-limit, and circuit-breaker behavior. The rate limiter is evaluated before every service invocation. If the configured maximum number of calls has already been reached within the interval, B2C Commerce prevents another remote request and returns service-unavailable behavior instead.

This mechanism counts service invocations irrespective of whether the previous remote calls succeeded or failed, which directly matches the requirement to restrict overall calls per second. A circuit breaker is different: it reacts specifically to accumulated failures. Option C incorrectly treats this as a general platform quota, while option A refers to configuration that is not the standard Service Framework mechanism.

Study Guide reference:Application Development --- Service Framework, Service Profiles, rate limiting, circuit breakers, and external integration governance.


Question 8

Which snippet works correctly when updating the package.json file to point to the hook file for a cartridge?

Correct Answer: A. { 'hooks': './cartridge/scripts/hooks.json' }
Explanation:

The cartridge's root-levelpackage.jsonuses the'hooks'property to point to the hook registration file. In the standard SFRA cartridge structure, the hook-registration file resides under:

cartridge/scripts/hooks.json

Therefore, the correct relative path is:

{'hooks':'./cartridge/scripts/hooks.json'}

Salesforce's SFRA hook documentation confirms thatpackage.jsonuses thehookskeyword to identify the hook file and that the referenced hook file then maps extension-point names to script implementations.

Option B omits thecartridgeportion of the normal directory structure, so it points to the wrong location. Option C uses JavaScript-object syntax rather than valid JSON because thehooksproperty name is unquoted. Apackage.jsonfile must contain valid JSON.

Thehooks.jsonfile contains entries with the extension-pointnameand correspondingscriptmodule. Once the cartridge is deployed and active on the appropriate cartridge path, registered hooks can participate in storefront or platform extension points.

Study Guide reference:Application Development --- hook registration,package.json,hooks.json, cartridge structure, CommonJS hook modules, and extension points.


Question 9

A developer is asked to create a controller endpoint that will be used in a client-side AJAX request. Its purpose is to display updated information to the user when the request is completed, without otherwise modifying the appearance of the current page.

According to SFRA practices, which method best supports this objective?

Correct Answer: A. res.json()
Explanation:

For a client-side AJAX endpoint whose response will be consumed by JavaScript,res.json()is the standard SFRA response method. It serializes the supplied data into a JSON response, allowing the client-side callback to update only the necessary part of the existing page without performing full server-side page rendering.

Salesforce's SFRA documentation explicitly states thatres.json(data)outputs a JSON object and ishelpful for creating AJAX service endpoints executed from client-side scripts. In contrast,res.render(templateName, data)renders an ISML template and produces markup intended for page or fragment rendering.

res.print()is a low-level text-output operation and does not provide the structured response contract that JSON gives client-side application logic.

An AJAX controller commonly returns information such as success status, validation errors, updated totals, URLs, messages, or calculated values as JSON. JavaScript then selectively updates the DOM based on those fields, preserving the rest of the page.

Study Guide reference:Application Development --- SFRA controllers, AJAX endpoints, response object,res.json(),res.render(), and client/server interaction.


Question 10

What is the expected result when the code segment executes with the logger configuration?

Correct Answer: A. Logs will be written to the log file with a prefix custom-loggersFile.
Explanation:

Logger.getLogger(fileNamePrefix, category)

The first argument determines the custom named-log prefix, while the second determines the logging category used for filtering. Salesforce documents this API explicitly and states that custom named loggers use the suppliedfileNamePrefixto identify the generated custom log.

Accordingly, if the omitted code segment specifiesloggersFileas thefileNamePrefix, the generated custom-log name begins withcustom-loggersFile, matching option A.

The source question, however, omits the actual referenced logger configuration and code segment. Therefore, the file itself does not provide enough visible information to deriveloggersFileindependently; the answer depends on the configuration that was evidently present in the original question version. The selected answer is consistent with Salesforce logger naming semantics and the source's marked answer.

Study Guide reference:Application Development ---dw.system.Logger,getLogger(fileNamePrefix, category), named custom logs, categories, and custom log-file naming.


Question 11

Given this customer basket information:

* A customer has an existing basket that consists of multiple items.

* One of the items is identified as a gift item by an attribute at the product line item.

* The developer needs to write custom code to fetch the customer basket and then modify the basket based upon the items in the cart. If the basket contains any gift items, modify the basket and create a separate shipment for the gift item.

Four hooks are required to make the modification, beginning with modifyGETResponse and ending with validateBasket.

dw.ocapi.shop.basket.modifyGETResponse

-- missing hook --

-- missing hook --

dw.ocapi.shop.basket.validateBasket

What are the two missing hooks in the middle?

Correct Answer: A. dw.ocapi.shop.basket.shipment.beforePOST AND dw.ocapi.shop.basket.shipment.beforePATCH
Explanation:

The required workflow creates a new shipment for a gift item and then modifies shipment information associated with the basket. The OCAPI basket shipment hooks corresponding to those two operations aredw.ocapi.shop.basket.shipment.beforePOSTanddw.ocapi.shop.basket.shipment.beforePATCH.

Salesforce's OCAPI hook documentation definesshipment.beforePOSTas the extension point executed before creation of a shipment andshipment.beforePATCHas the extension point executed before modification of an existing shipment. Those operations align directly with the described solution: establish the separate shipment and then apply the necessary changes before final basket validation.

The alternatives involvingbeforeDELETEorafterDELETEare inconsistent with the scenario because no shipment needs to be deleted. The requirement is to separate a gift product into its own shipment, not remove a shipment from the basket.

The concludingvalidateBaskethook provides the final validation stage after the basket/shipment changes have been processed, allowing custom logic to ensure that the resulting basket remains valid.

Study Guide reference:Application Development --- OCAPI Shop API hooks, basket extension points, shipment creation and modification, and basket validation.


Question 12

The client provides the system integrator with translation messages for the newly added "French" ("fr") locale.

What is the correct folder to store the associated.propertiesfiles?

Correct Answer: A. cartridge/templates/resources
Explanation:

SFRA storestemplate resource bundlesin the cartridge'stemplates/resourcesdirectory. Locale selection is represented in the propertiesfilename, rather than by creating a separatefrsubdirectory for ordinary SFRA resource bundles.

For example, a default bundle might be:

account.properties

while its French translation would be:

account_fr.properties

Both belong under:

cartridge/templates/resources

Salesforce's localization documentation explicitly states that template resource bundles are stored in/templates/resourcesand gives examples such asaccount_en_GB.properties,account_en_US.properties, andaccount_en.properties. Thedw.web.Resourcedocumentation likewise describes resource bundles as properties files with a common name located in thetemplate/resourcesdirectory.

Option B omits the required template-resource location. Option C incorrectly assumes that locale resolution for properties bundles uses a dedicatedfrfolder. Locale-specifictemplatescan use locale directories, but localized properties bundles follow the filename-suffix convention.

This separation permits one common set of ISML templates to reference resource keys while B2C Commerce automatically resolves the appropriate translated properties bundle for the active request locale.

Study Guide reference:Application Development --- localization, template resource bundles,.propertiesfiles, locale fallback, andResource.msg().


Question 13

A developer configures the dw.json file and needs to fill in the necessary parameters to complete the task.

Which parameter is required when using npm scripts?

Correct Answer: A. Username
Explanation:

SFRA's deployment and development tooling usesdw.jsonto provide the connection and authentication information required to communicate with the B2C Commerce instance. Among the options listed,usernameis the required credential-related parameter.

Salesforce's current tooling guidance confirms thatdw.jsoncontains B2C Commerce instance credentials and that WebDAV-based code deployment/file operations require a username plus authentication credential. Salesforce's SFRA build documentation similarly explains thatdw.jsonprovides the server-connection and code-version information used by command-line upload tooling and npm-driven development workflows.

A CSRF token isn't stored indw.json; CSRF tokens protect individual storefront HTTP requests and forms. A Site ID is also not the credential needed by the cartridge-upload scripts. Upload operations target the instance/code version rather than authenticate by storefront site ID.

In contemporary environments, Salesforce recommends secure access-key/OAuth-oriented authentication mechanisms where applicable, but the underlying exam concept remains that a username is part of the connection credential configuration used by these development/deployment tools.

Study Guide reference:B2C Commerce Setup ---dw.json, SFRA development environment, npm/sgmf scripts, WebDAV authentication, and cartridge deployment.


Question 14

Given the requirements:

* To integrate with an external web service using HTTP requests.

* To create a service for this purpose with the Service framework using the LocalServiceRegistry class.

* To test the service before the external service provider makes the API available.

Which solution allows the developer to satisfy the requirements?

Correct Answer: C. Create a service and implement the mockFull callback and set the service mode to mock.
Explanation:

The B2C Commerce Service Framework provides native support for mocked services, so the developer should implement themockFullcallback and configure the service to operate in mock mode. This enables application development and testing before the external provider exposes the real endpoint.

Salesforce documents that when a service is operating in mocked mode, the framework can use its configured mock callback instead of making the live network request.mockFullis particularly useful because it can replace the full service execution sequence and return a controlledResultsuitable for testing dependent application logic.

A custom site preference is unnecessary because the Service Framework already contains an administrative mechanism for selecting mocked operation. Introducing application-specific conditionals or preferences duplicates platform functionality and makes the integration harder to administer consistently.

This approach also preserves separation of concerns: application code continues calling the same service abstraction, while environment configuration determines whether the real provider or the mock implementation is used. When the remote API becomes available, the service can be switched from mocked to live behavior without redesigning its callers.

Study Guide reference:Application Development --- LocalServiceRegistry, Service Framework callbacks, mocking external integrations, and service testing.


Question 15

A developer is working on a feature that requires the use of a third-party API. What is the best practice for handling API responses in Salesforce B2C Commerce?

Correct Answer: B. Log all responses for debugging purposes and handle errors gracefully.
Explanation:

Among the supplied choices, B is the only approach consistent with robust B2C Commerce integration design: the application must inspect service results, preserve useful diagnostic information, and implement controlled error behavior rather than blindly proceeding.

However, 'log all responses' must be interpreted according to Salesforce's secure logging practices. Raw responses mustnotbe persisted indiscriminately when they contain passwords, access tokens, personal information, payment data, or other sensitive content. B2C Commerce's Service Framework provides logging controls such as response/request filtering specifically so that sensitive information can be removed before it reaches diagnostic logs.

Ignoring a failed API response, as in A, can produce corrupt application state or misleading storefront behavior. Option C is equally problematic because silently converting failures into successful responses prevents calling code and shoppers from receiving appropriate failure handling.

A correct production implementation examines the Service Framework result, logs sanitized diagnostic context where appropriate, implements fallback behavior when the business process allows it, and returns a controlled application response.

Study Guide reference:Application Development --- Service Framework, external API integrations, service result handling, secure logging, exception management, and graceful failure behavior.