A financial services firm is deploying a new Tableau Server environment and must adhere to a strict security policy requiring all inter-process communication on the server nodes to be encrypted. Which TSM command is used to enable this feature?
Answer and explanation
Correct answer: B
The tsm security internal-ssl enable command is specifically designed to enable SSL encryption for all communication between the various processes that make up Tableau Server, such as the Repository, VizQL Server, and Data Server. This is a crucial step for environments with high security requirements.
Question 2
Multiple answers
An administrator is setting up a new three-node Tableau Server cluster designed for high concurrency and background processing workloads. The goal is to isolate user-facing processes from extract refresh tasks. Which processes should be configured to run exclusively on a dedicated backgrounder node? (Select THREE)
Answer and explanation
Correct answers: B, C, E
The Backgrounder process is the primary component for running background tasks like extract refreshes, subscriptions, and flows. It is the most critical process for a dedicated backgrounder node.
The Data Server manages connections to Tableau data sources. Placing it with the Backgrounder and Data Engine helps optimize the data flow during extract refreshes, as these processes work closely together.
The Data Engine (which creates extracts and answers queries against them) works in conjunction with the Backgrounder during extract creation and refreshes. Co-locating them on the same node is a best practice for performance.
Question 3
True or False: By default, users assigned the Explorer (can publish) site role are able to publish new workbooks to projects where they have been granted the appropriate permissions.
Answer and explanation
Correct answer: A
This is true. The Explorer (can publish) site role is specifically designed for users who need to author new content based on existing data sources but do not need to publish new data sources. This role allows them to create and publish workbooks to projects where they have the necessary publishing rights.
Question 4
An administrator needs to programmatically promote certified workbooks from a 'Development' site to a 'Production' site every week. The script must also remap the workbook's underlying data source connections during the process. Which Tableau tool is best suited for this multi-step automation task?
Answer and explanation
Correct answer: C
The REST API is the most powerful tool for this task. It allows a script to download the workbook from the Development site, query its connections, update the connection details to point to the Production data source, and then publish the modified workbook to the Production site. This provides the flexibility needed for a true CI/CD (Continuous Integration/Continuous Deployment) workflow.
Question 5
Case Study: A mid-sized hospital group is implementing Tableau Server to provide analytics to clinical and administrative staff. They have stringent data privacy requirements due to HIPAA regulations.
Company Background: The hospital has 1,000 users categorized into three main groups: Data Scientists (Creators), Clinical Analysts (Explorers), and Hospital Management (Viewers). The data resides in an on-premises SQL Server database that contains Protected Health Information (PHI).
Technical & Security Requirements:
All user authentication must be handled by the hospital's existing Active Directory.
All network traffic to and from the Tableau Server, including between server nodes, must be encrypted with SSL/TLS.
Data Scientists must be able to publish new data sources, but a specific 'PHI Certified' project must be governed by a data steward. Only the steward can publish or certify data sources in this project.
Clinical Analysts should be able to create and edit workbooks using only the data sources from the 'PHI Certified' project.
Hospital Management should only have read-only access to a specific set of dashboards in a 'Executive Dashboards' project.
Which configuration plan best meets all of the hospital's requirements?
graph TD
subgraph "Tableau Server Configuration"
Auth[Authentication: Active Directory]
Encrypt[Encryption: External & Internal SSL]
subgraph Projects
A[PHI Certified Project]
B[Clinical Analysis Project]
C[Executive Dashboards Project]
end
end
subgraph UserGroups
UG1[Data Scientists]
UG2[Clinical Analysts]
UG3[Hospital Management]
UG4[Data Steward]
end
UG1 --> A
UG2 --> B
UG3 --> C
UG4 --> A
Answer and explanation
Correct answer: C
This plan correctly addresses all requirements. It uses AD authentication and full SSL encryption. It correctly isolates publishing rights in the 'PHI Certified' project to the Data Steward by locking permissions. It gives Clinical Analysts the ability to create/edit workbooks as required, and it properly restricts Hospital Management to view-only access by locking their permissions. This demonstrates a robust, multi-layered permission strategy.
Question 6
A Tableau workbook author has published a workbook containing a connection to a local CSV file that was on their desktop. What is the state of this CSV data on Tableau Server immediately after publishing?
Answer and explanation
Correct answer: B
When connecting to file-based data sources like CSV or Excel that are local to the author's machine, Tableau automatically creates an extract and embeds it within the workbook (.twbx) upon publishing. The server has no way to access the original file, so it packages a snapshot of the data.
Question 7
A server administrator needs to change the port used by the primary gateway process from 80 to 8080 on node1. Complete the TSM command to achieve this: tsm topology set-ports --node-name node1 --port-name gateway:primary --port-value _____
Answer and explanation
Correct answer: C
The correct value is simply the integer representing the new port number. The tsm topology set-ports command is used to modify the ports for various Tableau Server processes.
Question 8
After a database credential update, several critical extract refreshes begin to fail with authentication errors. The administrator has already updated the connection information for the published data sources on Tableau Server. What is the most likely remaining cause for the failures?
Answer and explanation
Correct answer: B
This is a common and often overlooked issue. If workbooks were published with credentials embedded before they were set to use the published data source connection, they might retain the old, stale credentials. Even if the published data source is updated, the workbook's embedded credentials can override it during a refresh. The solution is to edit the workbooks' connections to remove the embedded credentials and use the published data source's credentials.
Question 9
A project's permissions are locked to the project. An administrator assigns a user the role of Project Leader for that specific project. What is the result of this action regarding the user's ability to manage content permissions within that project?
Answer and explanation
Correct answer: C
This is the correct behavior. The Project Leader role grants the ability to manage the project itself, including its default permission rules. However, when the project is 'Locked', it enforces those default rules on all content within it, and no one, not even the Project Leader, can override them on a per-workbook or per-data-source basis. The lock must be removed first.
Question 10
Multiple answers
Which of the following site roles are capable of publishing new, original content (either workbooks or data sources) to Tableau Server? (Select TWO)
Answer and explanation
Correct answers: C, D
The Explorer (can publish) role is specifically for users who need to publish new workbooks from Tableau Desktop but are restricted to using existing published data sources. They cannot publish new data sources.
The Creator role has the highest level of content permissions. Creators can connect to new data, create and publish new data sources, and create and publish new workbooks from Tableau Desktop.