• Cert++
  • Practice
  • Certle
  • Review
  • Tracks
  • Checklist
  • Guides
  • Upgrade
Cert++
  1. Home
  2. Tableau Architect

Tableau Architect

Checklist progress

0/373Learned

Tableau Architect

Study Checklist

  • Platform Administrator
  • Platform App Builder
  • Platform Foundations
  • Platform Developer
  • Platform Administrator II
  • Agentforce Sales Consultant
  • Agentforce Service Consultant
  • Platform Data Architect
  • Platform Development Lifecycle and Deployment Architect
  • Platform Identity and Access Management Architect
  • Platform Integration Architect
  • Platform Sharing and Visibility Architect
  • Heroku Architect
  • B2C Solution Architect
  • Experience Cloud Consultant
  • Agentforce Field Service and Operations Consultant
  • Agentforce Nonprofit Consultant
  • Data 360 Consultant
  • Omnistudio Consultant
  • CRM Analytics and Einstein Discovery Consultant
  • Platform User Experience Designer
  • Platform Strategy Designer
  • B2C Commerce Developer
  • JavaScript Developer
  • Omnistudio Developer
  • Platform Developer II
  • Marketing Cloud Engagement Administrator
  • Marketing Cloud Engagement Specialist
  • Marketing Cloud Engagement Consultant
  • Agentforce Sales Foundations
  • Business Analyst
  • Marketing Cloud Engagement Developer
  • Marketing Cloud Engagement Foundations
  • Agentforce Specialist
  • Agentforce Life Sciences Consultant
  • B2B Commerce Administrator AP
  • B2B Commerce Developer AP
  • Agentforce Consumer Goods AP
  • Agentforce Financial Services AP
  • Agentforce Health AP
  • Agentforce Manufacturing AP
  • MuleSoft Integration Foundations
  • MuleSoft Developer
  • MuleSoft Developer II
  • MuleSoft Platform Integration Architect
  • MuleSoft Platform Architect
  • Tableau Desktop Foundations
  • Tableau Data Analyst
  • Tableau Consultant
  • Tableau Server Administrator
  • Tableau Architect

Checklist progress

0/373Learned

  • Mapping user roles (Creator, Explorer, Viewer) to appropriate Tableau license types given a mix of analysts who build dashboards, consumers who only view published content, and power users who need full authoring and data prep capabilities
  • Determining the minimum site role that grants a user the ability to connect to data sources on Tableau Server
  • Determining the minimum site role that grants a user the ability to publish workbooks to Tableau Server
  • How user role distribution (heavy Viewer vs. Creator bias) affects the number of VizQL Server processes required in a Tableau Server deployment
  • Choosing the correct site role for a user who needs to create and publish workbooks using web authoring but must not be able to connect to external data sources directly
  • Identifying which architectural constraints must be surfaced when an organization plans to scale from 500 to 5,000 Tableau users over 18 months with a fixed hardware budget
  • Evaluating how network latency between Tableau Server nodes and a data warehouse affects the decision to use extract-based versus live data sources at scale
  • Which infrastructure considerations are most critical when an organization requires Tableau to simultaneously support on-premises data sources and cloud data sources across multiple geographic regions
  • Assessing the impact of a planned corporate acquisition on an existing Tableau Server deployment, specifically regarding additional user counts, new data sources, and potential site consolidation
  • Determining when Tableau Cloud's shared-infrastructure model makes it unable to satisfy an organization's data residency, compliance (HIPAA, FedRAMP, GDPR), or network isolation requirements that necessitate an on-premises Tableau Server deployment
  • How Authorization-to-Run (ATR) licensing differs from traditional product key licensing on Tableau Server
  • The network connectivity requirements that ATR licensing imposes on Tableau Server deployments
  • Recommending an ATR lease duration strategy for an organization whose Tableau Servers are in a DMZ with internet access only during scheduled maintenance windows
  • Choosing between role-based licensing and core-based licensing for a Tableau Server deployment accessed by an unpredictable number of external partners
  • The impact of adding a new Tableau Server node on existing licensing consumption
  • When adding a new Tableau Server node requires additional license keys or ATR re-authorization
  • Identifying which Tableau product licenses (Tableau Server, Tableau Prep Builder, Resource Monitoring Tool) require separate activation
  • How each Tableau product license interacts with the Authorization-to-Run (ATR) licensing service
  • Distinguishing between high availability and disaster recovery in Tableau Server architecture
  • Determining when high availability versus disaster recovery is appropriate given an organization's RTO and RPO requirements
  • Minimum node count and configuration required to achieve high availability for all stateful Tableau Server services
  • Identifying the single points of failure in a two-node Tableau Server deployment and recommending configuration changes to eliminate them
  • Determining whether a Tableau Server deployment qualifies as highly available when the repository has a standby but the coordination service has only one ensemble member
  • Designing a high-availability configuration for the external PostgreSQL repository used by Tableau Server, including the failover mechanism required and how Tableau Server detects and reconnects when the primary PostgreSQL node fails
  • Matching Tableau Server add-ons (Advanced Management, Data Management) to organizational requirements such as data lineage tracking, data quality warnings, and centralized catalog
  • Determining which Tableau add-on is required to enable the Tableau Catalog and field-level data lineage features
  • Identifying which Tableau Server capabilities require the Advanced Management add-on versus those included with the base Server license
  • Recommending the correct Tableau Server add-on for an organization that requires content encryption at rest, Resource Monitoring Tool access, and centralized scheduling governance
  • Identifying that Tableau Prep Conductor for server-side flow scheduling is bundled in the Data Management add-on
  • Identifying that Tableau Catalog for data lineage and impact analysis is bundled in the Data Management add-on
  • Identifying that data quality warnings and certification labels are bundled in the Data Management add-on
  • Evaluating whether an organization needs the Data Management add-on based on requirements to schedule Tableau Prep flows on the server, track field-level data lineage, and surface data quality warnings to content consumers
  • Selecting the correct Tableau Bridge deployment model when an organization must keep data sources behind a corporate firewall while publishing to Tableau Cloud
  • Planning a high-availability Tableau Bridge deployment using a Bridge pool to support concurrent extract refresh schedules across 50 or more data sources
  • Identifying which data source connection types are supported by Tableau Bridge for live queries versus extract refreshes only
  • Troubleshooting Tableau Bridge connectivity failures where the Bridge client connects successfully but scheduled refreshes consistently fail for a specific JDBC-based data source
  • Determining the network and firewall requirements for Tableau Bridge, including which ports and endpoints the Bridge client must reach on Tableau Cloud
  • Choosing the appropriate authentication method among SAML, Kerberos, LDAP, and OpenID Connect for an enterprise that uses Azure AD as its identity provider and requires SSO across multiple applications
  • Planning a Tableau Server authentication configuration that supports both internal employees via Kerberos and external contractors via local authentication on the same server instance
  • Identifying which authentication methods are available for Tableau Cloud but not for Tableau Server
  • Determining when server-wide SAML versus site-level SAML should be used in a Tableau Server deployment that serves multiple business units with different identity providers
  • Designing an automation strategy that uses Personal Access Tokens (PATs) instead of username/password credentials for REST API scripts, including PAT lifetime configuration, rotation schedule, and revocation procedures for compromised tokens
  • Planning OAuth-based credential management for published data sources that connect to OAuth-enabled data platforms, including how tokens are stored and refreshed, and the impact of token expiry on scheduled extract refreshes
  • Designing a user provisioning workflow using SCIM to automatically sync user accounts and groups from Okta to Tableau Cloud when employees join or leave the organization
  • Identifying the Tableau Cloud prerequisites and configuration steps required before enabling SCIM-based user provisioning
  • Comparing SCIM provisioning to REST API-based user management for role assignment and group membership synchronization in large-scale Tableau deployments
  • Identifying what happens to a user's Tableau content and permissions when their account is deprovisioned via SCIM
  • Diagnosing a Tableau Server configuration where VizQL processes crash under peak load after a tsm configuration set change to process counts
  • Identifying which TSM configuration settings are most likely to cause intermittent authentication failures when Tableau Server is integrated with an external identity provider
  • Using TSM CLI commands to diagnose and correct a misconfigured Tableau Server cluster where one worker node is not receiving traffic from the internal load balancer
  • Diagnosing a Tableau Server deployment where tsm configuration set changes appear successful but never take effect because tsm pending-changes apply was not run to commit and restart after the change
  • Determining how to use tsm settings export and tsm settings import to capture the full server configuration state, version-control it, and apply it consistently across development and production environments
  • Using Tableau Cloud Manager to govern a multi-site Tableau Cloud deployment where each business unit requires separate site administration and data isolation
  • Identifying what capabilities are available to organization administrators versus site administrators in a multi-site Tableau Cloud Manager deployment
  • Planning the correct sequence of migration steps when moving from Tableau Server to Tableau Cloud, including how to handle published data sources that connect to on-premises databases
  • Determining which Tableau Server content types are supported for migration to Tableau Cloud via the Content Migration Tool versus those requiring manual re-creation
  • Planning a Tableau Server to Tableau Cloud migration for an organization with 200 published data sources that use Windows-integrated authentication to on-premises SQL Server
  • Identifying the authentication method constraints that block a Tableau Server to Tableau Cloud migration when the organization uses Kerberos authentication for both user login and data source connections, and the replacement authentication path for each
  • Planning the migration of Tableau Prep flows from Tableau Server with Prep Conductor to Tableau Cloud, identifying which flow input sources require Tableau Bridge and which can connect natively
  • Identifying the key differences in configuration and file paths when migrating a Tableau Server deployment from Windows to Linux
  • How Windows-to-Linux migration differences in configuration and file paths affect Tableau Server backup and restore procedures
  • Planning a Windows-to-Linux Tableau Server migration for an organization using the Run As service account with Windows-integrated authentication to SQL Server, and the alternative authentication strategy required on Linux
  • The alternative connector and authentication approaches required when migrating Tableau Server workloads from Windows to Linux
  • Determining the supported migration path from Tableau Server on Linux to Tableau Server on Windows
  • Why a direct restore of a Linux Tableau Server backup to a Windows environment is not possible
  • Planning a Linux-to-Windows Tableau Server migration using the Content Migration Tool when a direct backup-restore is not supported, identifying the content types and configuration elements that must be migrated separately
  • Planning the steps and risk mitigations required when migrating Tableau Server from local authentication to LDAP-based authentication, ensuring existing user content ownership and permissions are preserved
  • Identifying what happens to existing workbook ownership and permissions when Tableau Server's identity store is changed from Active Directory to SAML with a different username attribute mapping
  • The role of the identity migration tool and user-mapping files when transitioning Tableau Server between identity stores with different username formats
  • Designing a site consolidation plan when merging three departmental Tableau Server sites into one, addressing namespace conflicts for projects, workbooks, and data sources
  • Identifying the risks of content duplication and permission conflicts when consolidating multiple Tableau Server sites and the tools available to detect and resolve them
  • Planning a license consolidation when merging two separately licensed Tableau Server environments into one, including how to consolidate ATR license activations and what happens to existing user licenses during the migration window
  • Planning a production cutover from an existing Tableau Server environment to new hardware, including the correct sequence of backup, configuration export, restore, and license transfer steps
  • Determining which TSM commands are required to export configuration and topology settings from a source Tableau Server environment
  • Determining which TSM commands are required to apply exported configuration and topology settings to a target Tableau Server environment during migration
  • Identifying which Tableau Server settings and configurations are included in a TSM backup versus those captured by tsm settings export
  • Why omitting either a TSM backup or a tsm settings export causes an incomplete Tableau Server migration
  • Writing a migration script using TSM CLI commands to automate the backup of the source Tableau Server, transfer of the backup file, and restoration on the target server
  • Identifying which TSM CLI commands are needed to export server configuration settings and topology for use in scripted migrations between Tableau Server environments
  • Using the Tableau Content Migration Tool to migrate a subset of workbooks from a development site to a production site while preserving data source connections and permissions
  • Identifying the limitations of the Tableau Content Migration Tool when migrating content between Tableau Server versions that differ significantly
  • The workarounds required when the Content Migration Tool cannot migrate content between significantly different Tableau Server versions
  • Configuring a Content Migration Tool migration plan to remap published data source connection strings when moving workbooks from a staging environment to production with different database hostnames
  • Deciding whether to use the Content Migration Tool or a manual backup-restore approach for migrating all content from one Tableau Server site to another when the sites are on different servers
  • Determining the appropriate number of VizQL Server processes for a Tableau Server supporting hundreds of concurrent users who primarily consume published dashboards with embedded extracts
  • Calculating the correct backgrounder process count for a Tableau Server with hundreds of scheduled extract refresh jobs that are concentrated within a narrow morning window
  • How increasing the number of Data Engine (Hyper) processes affects extract query performance on Tableau Server
  • The trade-off between adding Data Engine (Hyper) processes and available RAM when RAM is the constraining resource
  • Identifying which Tableau Server process count is most directly correlated with the number of concurrent interactive users
  • Sizing Hyper (Data Engine) process counts for a Tableau Server environment where users frequently query multi-billion-row extracts concurrently and Hyper process memory pressure causes extract query spill-to-disk
  • Determining the impact of running Tableau Prep Conductor flows on the shared backgrounder process pool and when to isolate Prep Conductor on a dedicated node to prevent flow execution from delaying extract refresh jobs
  • Recommending the minimum number of nodes required to support a Tableau Server cluster with full high availability for all stateful services
  • Determining when adding a fourth node to a three-node Tableau Server cluster provides meaningful performance improvements versus when the cost is not justified by the expected gains
  • Determining when a two-node Tableau Server deployment provides adequate capacity and high availability for a specific workload profile versus when a third node is required to satisfy both the coordination service quorum and workload requirements simultaneously
  • Designing a node role configuration that isolates backgrounder processes to a dedicated node to prevent extract refresh jobs from degrading interactive dashboard performance
  • Identifying which Tableau Server processes should never be colocated on the same node due to resource contention
  • How process colocation constraints affect the minimum node count required in a Tableau Server deployment design
  • Configuring node roles in a multi-node Tableau Server deployment to ensure the coordination service ensemble has the required quorum for high availability
  • Determining when to configure an external file store versus relying on the default internal file store, given an organization's multi-node Tableau Server and shared NAS infrastructure
  • Evaluating the conditions under which an external repository (PostgreSQL) provides operational advantages over the embedded Tableau Server repository in terms of backup control and HA
  • Determining when the Tableau external gateway should be used instead of a hardware load balancer for SSL termination and the configuration differences between the two approaches
  • Evaluating when to use an external Key Management Service (AWS KMS or Azure Key Vault) instead of Tableau-managed keys for extract encryption at rest, including the availability dependency introduced on the KMS endpoint and the compliance benefits
  • Recommending an identity store and authentication configuration for a Tableau Server deployment where the organization requires SSO, MFA enforcement, and per-user row-level security driven by AD group membership
  • Comparing LDAP and Active Directory as Tableau Server identity stores in terms of configuration requirements, user attribute mapping, and functional limitations
  • Designing a row-level security strategy using USERNAME() and ISMEMBEROF() Tableau user functions in calculated field filters to enforce per-user data visibility at query time without custom SQL or separate entitlement tables
  • Comparing entitlement-table row-level security (joining a permissions table at query time) versus workbook user filter RLS for a deployment with thousands of users across hundreds of data sources, evaluating performance, security, and maintenance trade-offs
  • The trade-off between extract refresh throughput and interactive session performance when increasing concurrent backgrounder jobs
  • Identifying the TSM configuration key used to enable guest access on a Tableau Server site
  • The security implications of enabling guest access for anonymous, unauthenticated access to published Tableau Server views
  • Configuring Tableau Server to enforce TLS for all inter-node communication and external HTTPS connections, including the specific certificate requirements and TSM configuration commands
  • Recommending the appropriate Tableau Server encryption configuration for an organization subject to PCI-DSS that requires both encryption at rest for all extracts and a minimum of TLS 1.2 for all connections
  • Identifying the TSM configuration settings that control SSL cipher suites and protocol versions and how to harden them to meet a given security baseline
  • Recommending an AWS KMS or Azure Key Vault integration for Tableau Server extract encryption to satisfy a compliance requirement that all cryptographic keys must be customer-managed and not held by the vendor
  • Designing a key rotation strategy for Tableau Server extract encryption that satisfies a 90-day key rotation policy without triggering simultaneous re-encryption of all extracts and without causing Tableau Server downtime
  • Recommending CPU, RAM, and storage specifications for an initial Tableau Server node that will serve hundreds of concurrent users with a mix of extract and live data source queries
  • Identifying the minimum network bandwidth required between Tableau Server nodes in a multi-node cluster when using an external file store backed by a network file share
  • Determining whether SSDs or spinning-disk storage is more appropriate for the Tableau Server data directory given the I/O profile of concurrent extract refreshes and interactive queries
  • Designing a Tableau Server disaster recovery strategy that achieves a four-hour RTO and a one-hour RPO, specifying the backup schedule, offsite storage strategy, and restore procedure
  • Identifying which TSM backup and configuration export commands must be run together to capture a complete, restorable Tableau Server state
  • Comparing warm-standby versus cold-backup-only Tableau Server disaster recovery in terms of achievable RTO
  • Comparing warm-standby versus cold-backup-only Tableau Server disaster recovery in terms of ongoing infrastructure cost and operational complexity
  • Designing a DR strategy for Tableau Cloud that accounts for the platform's shared-responsibility model and the limited customer control over infrastructure failover
  • Designing a virtual connection architecture to centralize row-level security policy enforcement across all workbooks connecting to a shared data source, replacing distributed per-workbook user filters with a single maintainable server-side data policy
  • The licensing and server configuration prerequisites for publishing virtual connections to Tableau Server
  • The permission model that controls who can modify virtual connection data policies versus who can only consume the virtual connection
  • Determining when virtual connections with data policies are architecturally preferable to per-workbook user filters for row-level security, weighing centralized governance against the query-time performance implications for extract-backed versus live connection scenarios
  • Designing a data policy on a virtual connection that enforces row-level access based on the authenticated Tableau user's group membership and resolving conflicts when a user belongs to multiple groups with overlapping but different access levels

2.1.7 Plan and implement automated deployment

0/2

  • Creating a Tableau Server silent installer script for Windows that pre-configures the Run As service account, port settings, and initial admin credentials via command-line arguments
  • Designing an automated Tableau Server deployment pipeline using the silent installer and TSM CLI that can be run idempotently across development, staging, and production environments

2.2.1 Configure and troubleshoot SAML

0/7

  • Configuring server-wide SAML on Tableau Server with Okta as the identity provider, including the required ACS URL, entity ID, IdP metadata import, and username attribute mapping
  • Troubleshooting a Tableau Server SAML login failure where users are redirected correctly to the IdP but receive an authentication error upon return, using SAML diagnostic logs to identify the root cause
  • Configuring site-specific SAML on Tableau Server so that different sites use different identity providers while sharing the same underlying Tableau Server instance
  • Identifying why a Tableau Server SAML configuration fails when the IdP signs assertions with SHA-1 and the server requires SHA-256
  • The correct remediation path when Tableau Server SAML fails due to SHA-1 versus SHA-256 assertion signing mismatch
  • Identifying the prerequisite configuration steps that must be completed before enabling SAML on Tableau Server
  • Why SAML cannot be enabled on Tableau Server when HTTPS is not yet configured

2.2.2 Configure and troubleshoot Kerberos

0/3

  • Configuring Tableau Server to use Kerberos for user authentication with Active Directory, including keytab file generation, SPN registration, and the TSM configuration commands
  • Troubleshooting a Kerberos constrained delegation failure where Tableau Server authenticates users correctly but cannot delegate credentials to an underlying SQL Server data source for live connections
  • Diagnosing a Tableau Server Kerberos authentication failure that begins after the Active Directory service account password is rotated, and the steps to resolve it

2.2.3 Configure and troubleshoot OpenID Connect

0/3

  • Configuring Tableau Server to use OpenID Connect with Azure AD, including the required app registration settings, redirect URIs, and TSM configuration commands
  • Troubleshooting an OpenID Connect configuration where users authenticate successfully but their Tableau usernames do not match the expected values from the id_token claim mapping
  • Whether OpenID Connect-to-local authentication fallback on Tableau Server is configurable or always disabled

2.2.4 Configure and troubleshoot Mutual SSL

0/4

  • Configuring Tableau Server for Mutual SSL client certificate authentication, including CA certificate trust configuration, certificate-to-user mapping, and the fallback authentication behavior
  • Troubleshooting a Mutual SSL configuration where certificates issued by a new internal CA are rejected by Tableau Server while certificates from the old CA continue to work
  • Identifying which Tableau Server authentication methods are incompatible with Mutual SSL
  • The specific TSM configuration constraint that prevents Mutual SSL from being enabled alongside SAML on the same Tableau Server site

2.2.5 Configure and troubleshoot trusted authentication

0/3

  • Implementing Tableau Server trusted authentication for a custom web portal, including the ticket request flow, trusted IP allowlist configuration, and the process for redeeming tickets in embedded views
  • Troubleshooting a trusted authentication setup where tickets are generated successfully by the web server but users receive an invalid ticket error when the embedded Tableau view loads
  • Identifying the security implications of Tableau Server trusted authentication's IP allowlist

2.2.6 Configure and troubleshoot Connected App authentication

0/4

  • Configuring a Tableau Connected App for embedding Tableau views in a third-party web application using JSON Web Tokens, including the required JWT claims and signing key setup
  • Troubleshooting Connected App authentication where JWTs are being rejected by Tableau Server due to token expiry or clock skew between the application server and Tableau Server
  • The difference between a direct-trust Connected App and an OAuth 2.0 trust Connected App for Tableau embedding
  • When a direct-trust versus OAuth 2.0 trust Connected App is appropriate for a Tableau embedding use case

2.2.7 Configure and troubleshoot LDAP

0/2

  • Configuring Tableau Server to use a generic LDAP directory (non-Active Directory) as its identity store, including the bind DN, user search base, group search base, and attribute mappings
  • Configuring Tableau Server to use LDAPS for encrypted LDAP communication with an Active Directory server and troubleshooting certificate trust failures when the LDAP server presents a certificate from a private CA

2.2.8 Configure and troubleshoot Azure Active Directory

0/2

  • Configuring Tableau Server to use Azure Active Directory as the identity store, including the required Azure AD application registration, API permissions, and TSM configuration steps
  • The specific Azure AD application registration permissions (Directory.Read.All, Group.Read.All) required for Tableau Server Azure AD group synchronization

2.2.9 Identify dependencies between authentication methods and Tableau environments, including Tableau Cloud

0/4

  • Identifying which Tableau Server authentication methods are compatible with Tableau Cloud and which require fundamentally different configuration when users must access both environments
  • Determining how Kerberos delegation dependencies differ between Tableau Server on-premises and Tableau Cloud when connecting to Kerberos-protected data sources
  • Identifying which Tableau Server authentication methods prevent users from publishing content to Tableau Cloud or connecting to Tableau Cloud resources from Tableau Desktop
  • Identifying how Personal Access Token availability and configuration differences between Tableau Server and Tableau Cloud affect REST API automation scripts that must authenticate to both environments in a hybrid deployment

2.3.1 Implement SSL encryption

0/3

  • Configuring Tableau Server to use a custom SSL certificate from an internal CA for HTTPS, including certificate format requirements and the TSM configuration commands
  • Enabling internal SSL for Tableau Server inter-process communication and identifying which processes require certificate updates when the SSL certificate is renewed
  • Troubleshooting an SSL certificate renewal on Tableau Server where users receive certificate errors after the new certificate is applied due to a missing intermediate CA in the certificate chain

2.3.2 Implement database encryption

0/5

  • Configuring encryption of the Tableau Server internal PostgreSQL repository
  • The operational implications of enabling or disabling Tableau Server internal repository encryption after initial deployment
  • Identifying when database encryption on Tableau Server provides compliance value and when the performance trade-off is not justified by the security posture
  • The operational steps required to disable Tableau Server internal database encryption after it has been enabled
  • The service restart impact on active user sessions when disabling Tableau Server internal database encryption

2.3.3 Implement extract encryption

0/7

Configuring Tableau Server to encrypt extracts at rest using Tableau-managed keys

Learn this concept
Unseen

The impact of extract encryption at rest on Tableau Server extract refresh performance

Learn this concept
Unseen

The key rotation process for Tableau-managed extract encryption on Tableau Server

Learn this concept
Unseen

Distinguishing site-level extract encryption enforcement from workbook- or data-source-level extract encryption settings on Tableau Server

Learn this concept
Unseen

Distinguishing site-level extract encryption enforcement from workbook- or data-source-level extract encryption settings on Tableau Cloud

Learn this concept
Unseen

Determining the behavior of Tableau Server extract encryption when a workbook owner publishes an extract-backed workbook and later changes the encryption policy at the site level

Learn this concept
Unseen

Whether previously encrypted Tableau Server extracts are retroactively re-keyed when the site-level encryption policy changes

Learn this concept
Unseen

2.3.4 Set up service principal names (SPNs) for Kerberos

0/3

  • Creating the HTTP SPN in Active Directory required for Tableau Server user Kerberos authentication
  • Diagnosing a Kerberos authentication failure caused by duplicate SPNs registered to multiple service accounts in Active Directory and the steps to identify and resolve the conflict
  • Determining which SPNs must be registered and to which service account when Tableau Server is deployed behind a load balancer with a virtual hostname

2.4.1 Install Tableau Server on Linux by using CLI or the Installation Wizard

0/3

  • Performing a fresh Tableau Server installation on RHEL using the CLI, including the package install, TSM initialization, activation, and initial admin account creation steps
  • Identifying the pre-installation prerequisites for Tableau Server on Linux including supported distributions, minimum kernel version, ulimit requirements, and required system packages
  • Identifying the correct tsm register and tsm activate command sequence to license a Tableau Server on Linux after successful package installation and TSM initialization

2.4.2 Identify and resolve issues with installation on Linux

0/2

  • Identifying the common Tableau Server installation failure modes specific to Linux that do not occur on Windows
  • The diagnostic steps used to distinguish between Linux-specific Tableau Server installation failure modes

2.4.3 Identify and resolve issues with operating system and networking configurations

0/4

  • Troubleshooting a multi-node Tableau Server on Linux where worker nodes cannot communicate with the primary node due to firewall rules blocking required inter-node ports
  • Identifying the required network ports that must be open between Tableau Server nodes on Linux
  • Identifying the required network ports that must be open between Tableau Server and external services on Linux
  • Diagnosing Tableau Server on Linux where hostname resolution failures cause inter-node communication errors in a multi-node cluster

2.4.4 Identify and resolve issues with interfaces and interactions with external systems

0/5

  • Troubleshooting Tableau Server on Linux that cannot connect to an external data source after installation due to missing JDBC drivers in the expected driver directory
  • Identifying why Tableau Server on Linux fails to connect to an external LDAP server when the LDAP host uses LDAPS and the server certificate is from a private CA not trusted by the OS
  • Troubleshooting Tableau Server on Linux that connects successfully to a database for ad-hoc queries from Tableau Desktop but fails for server-side extract refreshes due to a JDBC driver path misconfiguration or an unsupported driver version in the server's driver directory
  • Determining the correct directory path and file naming convention for installing custom JDBC or ODBC database drivers on Tableau Server running on Linux
  • Verifying that a custom JDBC or ODBC driver installed on Linux Tableau Server is recognized by the server after restart

2.4.5 Identify and resolve issues with proxy issues

0/3

  • Configuring Tableau Server on Linux to route outbound traffic through an HTTP forward proxy and troubleshooting SSL inspection proxy issues that break Tableau's HTTPS connections
  • Determining whether ATR license validation traffic on Tableau Server for Linux is affected by a forward proxy
  • Identifying the TSM bypass list entries required to prevent proxy interference with internal data source connections on Linux Tableau Server

2.4.6 Identify appropriate operating system logs and Tableau logs for troubleshooting

0/4

  • Identifying which Linux system logs and Tableau Server process logs are most useful for diagnosing a VizQL Server process crash on Linux
  • Locating the Tableau Server log directory structure on Linux
  • Identifying the specific Linux log files for the backgrounder, gateway, and vizqlserver processes
  • Using the tsm maintenance ziplogs command to collect a diagnostic bundle on Linux and selecting the correct log scope for a specific type of failure

2.4.7 Verify system groups and file system permissions

0/1

  • Identifying the specific Linux user accounts (tableau, run-as user, tsm admin) and their required group memberships for Tableau Server

2.5.1 Install Tableau Server on Windows by using CLI or the Installation Wizard

0/2

  • Performing a Tableau Server installation on Windows Server using the graphical Installation Wizard, including the TSM configuration, activation, and initial admin account creation steps
  • Identifying the correct post-installation sequence using TSM Web UI or CLI to configure the initial admin account, apply a product key, and perform the first pending-changes apply on a fresh Windows Tableau Server installation

2.5.2 Identify and resolve issues with installation on Windows

0/2

  • Diagnosing a Tableau Server Windows installation failure where TSM initialization fails because Windows Firewall blocks required ports that the installer does not automatically configure
  • Resolving a Tableau Server Windows installation failure caused by insufficient disk space on the system drive where TSM writes its working and log files

2.5.5 Identify and resolve proxy issues

0/2

  • Configuring Tableau Server on Windows to bypass a corporate proxy for internal data source connections while routing Tableau-to-internet traffic through the proxy for ATR licensing
  • Identifying why Tableau Server on Windows fails to reach Tableau's licensing service through an authenticated proxy and how to provide proxy credentials to TSM

2.5.6 Identify appropriate operating system logs and Tableau logs for troubleshooting

0/2

  • Locating the Tableau Server log directory on Windows
  • Distinguishing between ProgramData logs and Tableau Server data directory logs for Windows troubleshooting

2.5.7 Verify system groups and file system permissions

0/3

  • Verifying that the Tableau Server Run As service account has the required Windows file system permissions and local group memberships after initial installation
  • Diagnosing Tableau Server process failures on Windows caused by a Group Policy Object that periodically removes the service account from required local security groups or strips file system permissions from the data directory
  • Verifying that the Tableau Server Run As service account on Windows has the correct NTFS permissions on the data directory, the installation directory, and any UNC path used for the external file store after a permission audit removes inherited ACEs

2.5.8 Use the Run As service account

0/5

  • Configuring the Tableau Server Run As service account on Windows, including the required Active Directory permissions, local security policy rights, and TSM configuration steps
  • Troubleshooting a Tableau Server deployment where Windows-integrated data source authentication succeeds for some users but fails for others due to Run As service account delegation settings
  • Identifying the implications of changing the Tableau Server Run As service account after initial deployment, including which permissions, SPNs, and configurations must be updated
  • Determining the minimum Active Directory permissions the Tableau Server Run As account requires
  • Why granting the Tableau Server Run As account local administrator rights creates a security risk

2.1.8 Configure and troubleshoot Tableau Prep Conductor

0/5

  • Enabling Tableau Prep Conductor on Tableau Server by activating the Data Management add-on license and configuring flow schedules with the correct input credentials, output types (published data source, database table, or file), and failure notification settings
  • Troubleshooting a Tableau Prep flow that runs successfully in Tableau Prep Builder on the desktop but fails when executed by Prep Conductor on the server due to missing embedded input data source credentials or a connector version mismatch between Desktop and Server
  • Configuring a Tableau Prep flow to output incrementally to an existing published Tableau data source and identifying when incremental append versus full refresh output mode is correct for a given source data change pattern
  • Determining how Tableau Prep Conductor flows compete with extract refresh jobs for backgrounder process capacity and the configuration required to assign Prep Conductor workloads to a dedicated backgrounder node
  • Identifying the flow run history, error messages, and log locations available in Tableau Server for diagnosing why a Prep Conductor flow fails consistently on the server but succeeds in Tableau Prep Builder

2.2.10 Configure and troubleshoot analytics extensions

0/7

  • Configuring Tableau Server to connect to an external TabPy server as an analytics extension, specifying the host, port, SSL settings, and authentication token, and verifying the connection using the TSM configuration test workflow
  • Troubleshooting analytics extension SCRIPT_REAL() and SCRIPT_STR() calculated fields that return null on Tableau Server but return correct results in Tableau Desktop, diagnosing connection configuration, required Python package availability on TabPy, and function vectorization requirements
  • The security risks of deploying a TabPy analytics extension server accessible from Tableau Server without SSL or token authentication
  • The TSM configuration settings required to enforce a secured connection between Tableau Server and a TabPy analytics extension
  • Determining when analytics extensions should be configured at the site level versus the server level in Tableau Server, and the implications for author access, performance isolation, and administrator control at each configuration scope
  • Configuring an Rserve-based R analytics extension as an external service for Tableau Server
  • The configuration parameter differences between an Rserve analytics extension and a TabPy Python extension on Tableau Server

2.3.5 Configure Key Management Service (KMS) for extract encryption

0/2

  • Configuring Tableau Server to use AWS KMS as the key management service for extract encryption at rest, including the required IAM role permissions, Customer Master Key ARN configuration in TSM, and the activation commands
  • Comparing AWS KMS, Azure Key Vault, and Tableau-managed keys for extract encryption at rest, evaluating customer key control, availability dependency, key rotation capability, and operational complexity of each option

2.3.6 Configure and troubleshoot virtual connections and data policies

0/3

  • Publishing a virtual connection to Tableau Server and configuring data policy row-level security rules that filter rows based on the authenticated Tableau user's username and group membership using the USERNAME() and ISMEMBEROF() functions
  • Configuring permissions on a published virtual connection so that data analysts can connect to it and build workbooks without being able to view or edit the underlying row-level security data policy rules
  • Determining how extract refreshes interact with virtual connection data policies and whether row-level security filtering is applied at extract creation time or at query time when a workbook connects to a virtual connection-backed extract

2.1.1 Deploy and configure Tableau Server 2.1.1.1 Configure an external file store

0/4

  • Configuring Tableau Server to use an external file store backed by a network file share (NFS or SMB) and the TSM commands required to activate and validate the configuration
  • Determining when an external file store is required versus optional in a multi-node Tableau Server deployment
  • The performance and high-availability prerequisites for enabling an external file store on Tableau Server
  • Troubleshooting a Tableau Server deployment where extract refreshes fail after enabling the external file store due to file system permission errors on the NAS share

2.1.1.2 Configure an external repository

0/3

  • Configuring Tableau Server to use an external PostgreSQL repository, including PostgreSQL version requirements, connection parameters, and the required TSM configuration commands
  • Identifying the operational advantages of using an external repository when an organization requires its own backup schedule and high-availability policy for the Tableau Server database
  • Diagnosing a Tableau Server configuration error where the server fails to start after switching to an external repository due to a missing or misconfigured SSL certificate for the PostgreSQL connection

2.1.1.3 Configure an external gateway

0/3

  • Configuring Tableau Server to use an external gateway to offload SSL termination and act as the public-facing entry point while Tableau's internal gateway handles cluster traffic
  • Determining the correct TSM configuration parameters and Apache virtual host settings to integrate an external Apache gateway with Tableau Server in a DMZ-based architecture
  • Troubleshooting a Tableau Server deployment where users accessing the server through an external Apache gateway receive redirect loops or authentication failures due to incorrect X-Forwarded-For header configuration or missing trusted proxy settings

2.1.1.4 Configure an unlicensed node

0/3

  • Identifying which Tableau Server processes can run on an unlicensed node
  • Adding an unlicensed Tableau Server node to host coordination service instances in a high-availability ensemble without consuming an additional Tableau Server license
  • Determining the network and hardware requirements for an unlicensed node hosting only a coordination service ensemble member

2.1.1.5 Configure a coordination ensemble

0/3

  • Configuring a Tableau Server coordination service ensemble across three nodes
  • Why an odd number of coordination service ensemble members is required to maintain a functional quorum on Tableau Server
  • Identifying the TSM commands used to deploy, redeploy, and verify the status of the Tableau Server coordination service ensemble

2.1.1.6 Configure a backgrounder process with a specific node role

0/3

  • Assigning backgrounder processes to a dedicated node role in Tableau Server to prevent extract refresh jobs from competing with interactive user sessions for CPU and memory resources
  • Using TSM to configure a Tableau Server node as a backgrounder-only node and verifying the node role assignment is correctly applied across the cluster
  • Configuring separate extract refresh and Tableau Prep Conductor workloads on distinct backgrounder nodes using node role assignments to prevent flow execution from blocking time-sensitive extract refresh jobs

2.1.1.7 Configure Tableau for a load balancer

0/1

  • Configuring Tableau Server to work correctly behind a hardware load balancer, including the required gateway allowlist configuration to prevent redirect loops and authentication failures

2.1.2 Install in an air-gapped environment

0/4

  • Planning a Tableau Server installation in an air-gapped environment with no internet access, including how to handle ATR licensing offline and pre-stage driver and dependency packages
  • Identifying which Tableau Server installer components require internet access by default
  • How to pre-stage Tableau Server installer components for air-gapped deployments with no internet access
  • Configuring ATR offline activation for a Tableau Server in an air-gapped environment and the manual steps required when the server cannot reach Tableau's licensing service

2.1.3 Validate a disaster recovery/high availability test strategy

0/2

  • Identifying the metrics and verification checks that confirm a successful Tableau Server high-availability failover test
  • Identifying the signs of a partial Tableau Server HA recovery that leaves the deployment in a degraded state after failover testing

2.1.4 Perform a blue-green deployment

0/4

  • Executing a blue-green Tableau Server major version upgrade, including the traffic routing cutover procedure and the rollback steps if critical issues are detected post-cutover
  • Identifying the content synchronization steps required to keep the green (new) Tableau Server environment current with production content before traffic is switched
  • Managing Tableau Server license transfer during a blue-green deployment cutover, including deactivating the license on the blue environment and activating it on the green environment without triggering an ATR violation
  • Configuring DNS and load balancer cutover for a blue-green Tableau Server deployment and identifying the session drain period required to allow in-flight user sessions to complete before decommissioning the blue environment

2.1.5 Locate and interpret Tableau Server installation logs

0/2

  • Locating the correct Tableau Server installation log to diagnose why the TSM initialization process failed during a fresh install on a Linux server
  • What information the Tableau Server bootstrap log provides about installation and initialization failures

2.1.6 Install and configure Resource Monitoring Tool server and agents

0/3

  • Installing and configuring the Tableau Resource Monitoring Tool master server and deploying RMT agents to each node in a multi-node Tableau Server cluster
  • Determining the hardware requirements for an RMT master server that will monitor a five-node Tableau Server cluster with high view load and frequent extract refresh activity
  • Troubleshooting an RMT agent that is installed on a Tableau Server worker node but is not reporting metrics to the RMT master server
  • Querying the Tableau Server repository to identify the most frequently accessed workbooks and their peak usage times using the historical views tables
  • Identifying which repository tables contain information about background task execution, extract refresh history, and job failure details for operational monitoring
  • Querying the Tableau Server repository's http_requests table to identify workbooks generating consistently long server-side render times and correlating request duration data with specific users, views, or time-of-day patterns
  • Building a Tableau admin dashboard that monitors extract refresh job queue depth and failure rates over a rolling 30-day window using published data sources connected to the Tableau Server repository
  • Designing an admin dashboard that shows per-node VizQL Server memory usage, active sessions, and request queuing to surface capacity problems before users are impacted
  • Identifying the Tableau Server repository views and tables that expose the data needed to build a content governance dashboard showing stale workbooks and orphaned data sources
  • Building an admin dashboard that tracks license utilization by role type over time using repository data, identifying Creator licenses that have been inactive for more than 60 days and are candidates for downgrade to Explorer
  • Using Tableau Cloud Admin Insights to identify underutilized Creator licenses that could be downgraded to Explorer based on actual usage patterns over the past quarter
  • Identifying what observability data is available in Tableau Cloud Admin Insights that is not available through Tableau Server repository queries in on-premises deployments
  • Using Admin Insights to build a report showing which Tableau Cloud data sources have not been refreshed in over 30 days and are consuming storage unnecessarily
  • Using Tableau Cloud Admin Insights flow run history data to identify Tableau Prep Conductor flows with consistently high failure rates and the correlated timing, input source, and error type data needed to prioritize remediation
  • Designing a load testing strategy to validate that a Tableau Server cluster can sustain 1,000 simultaneous users rendering dashboards during a planned peak business event
  • Comparing a sustained load test to a spike test approach when validating Tableau Server capacity before a go-live with unpredictable user concurrency patterns
  • Determining whether load testing should be conducted against a production environment or a separate test environment and the configuration requirements for a valid test environment
  • Interpreting TabJolt output metrics (response time percentiles, throughput, error rate) to determine whether Tableau Server is under-provisioned for the expected concurrent load
  • Configuring a representative Tableau Server test environment for load testing that mirrors the production configuration including process counts, data sources, and hardware ratios
  • Identifying the risks of using a non-representative test environment for load testing and how differences in node count, process configuration, or data volume affect the validity of test results
  • Creating a Tableau Server load test plan that covers realistic user workflows including login, workbook open, filter interaction, and dashboard navigation across multiple concurrent users
  • Determining the appropriate think time and ramp-up period settings for a TabJolt test plan intended to simulate 500 concurrent users without triggering an artificial thundering-herd effect at test start
  • Determining when load test results indicate that adding VizQL Server processes is the correct action versus when adding an additional node is required
  • Diagnosing slow workbook load times that only occur for specific users by correlating performance recording data with server-side VizQL log entries and session context
  • Troubleshooting an extract refresh job that exceeds its SLA after a data volume increase, identifying whether the bottleneck is in live query execution, data transfer, or Hyper serialization
  • Identifying why a Tableau workbook with complex LOD expressions performs acceptably with a smaller extract but degrades significantly with a large extract on the same hardware
  • Identifying analytics extension SCRIPT function calls as the root cause of slow workbook render times when functions execute row-by-row without batching, and recommending vectorized implementations to eliminate per-row network round-trip overhead to TabPy or Rserve
  • Using Tableau Server process logs and OS metrics to distinguish between a VizQL Server memory pressure problem and a Data Engine query execution bottleneck during peak concurrent load
  • Breaking down Tableau Server request latency from gateway receipt to rendered response, quantifying the contribution of VizQL processing time versus data source query time
  • Determining whether Tableau Server CPU saturation during peak hours is caused by concurrent extract refreshes or interactive rendering requests, and which tool to use to diagnose each
  • Using the Tableau Server Resource Monitoring Tool alongside OS-level disk I/O metrics to determine whether persistent slow extract refresh times are caused by Hyper process CPU saturation or by insufficient I/O throughput on the storage subsystem
  • Interpreting a Tableau Desktop performance recording that shows 'Generating extract queries' as the dominant time category and recommending the correct optimization action
  • Using a Tableau Server-side performance recording to identify rendering events consuming disproportionate time and prescribing a workbook layout or mark-count reduction to address it
  • Identifying when a performance recording shows that geocoding is the primary bottleneck and determining the correct Tableau Server configuration change to address it
  • Configuring Tableau Server's VizQL caching policy to balance fresh data delivery against server load, choosing between low, balanced, and maximum cache settings based on data refresh frequency and user expectations
  • Troubleshooting Tableau Server high memory usage caused by excessive cache retention and the configuration changes used to constrain cache size per process
  • Selecting which RMT dashboards and alert configurations are appropriate for an SRE team that requires notification of Tableau process failures within five minutes of occurrence
  • Distinguishing when the Tableau Resource Monitoring Tool versus the Tableau Server repository is the better source for hardware resource utilization monitoring
  • Distinguishing when the Tableau Resource Monitoring Tool versus the Tableau Server repository is the better source for content usage and user activity monitoring
  • Identifying which RMT capabilities require the Advanced Management add-on and what monitoring alternatives exist for organizations that do not have that license
  • Designing a log management strategy for a multi-node Tableau Server cluster that ships logs to a centralized SIEM in near real time and retains them for 90 days for compliance
  • Using the tsm maintenance ziplogs command to collect a diagnostic bundle for Tableau support
  • Selecting the correct log types to include in a tsm maintenance ziplogs bundle for a specific failure investigation
  • Determining the log rotation and retention policy that balances disk space constraints on Tableau Server nodes against the need to retain sufficient history for incident investigation
  • Recommending a process metrics collection strategy that tracks VizQL Server memory usage and backgrounder queue depth over time to detect capacity issues before they impact users
  • Identifying which Tableau Server process metrics are most predictive of user-facing degradation and should be used to set alerting thresholds in a monitoring system
  • Designing a time-series monitoring strategy using the Tableau Server repository or RMT to track per-process memory and CPU utilization over a 30-day baseline period to establish normal thresholds before setting alerting rules
  • Designing an OS-level monitoring strategy for Tableau Server nodes that captures CPU, memory, disk I/O, and network throughput with alert thresholds correlated to Tableau process behavior
  • Identifying which hardware metrics are most predictive of Tableau Server performance degradation and should be prioritized in an automated alerting strategy
  • Identifying the OS-level metrics that most reliably predict Tableau Server user-facing degradation before end-user complaints
  • Designing collection intervals appropriate for each OS-level metric type used in Tableau Server capacity alerting
  • Interpreting RMT and OS metrics showing 100% CPU utilization on the backgrounder node during extract refresh windows and determining whether the correct action is adding processes, adding nodes, or redistributing schedules
  • Using observability data showing persistent backgrounder saturation during business hours to justify adding a dedicated backgrounder node and redistributing extract schedules to off-peak windows
  • Recommending a Tableau Server architecture revision based on observability data showing that external file store I/O is the primary bottleneck during concurrent extract refreshes
  • Deciding whether to increase VizQL Server process counts or add a node based on observability data showing high CPU usage on the VizQL node with available memory headroom
  • Configuring the Tableau Cloud Activity Log to capture user authentication and content access events and routing them to an external SIEM for security monitoring and audit purposes
  • Using the Tableau Activity Log to detect anomalous data access patterns such as mass bulk content downloads or unexpected bulk permission changes that may indicate a compromised account or an insider threat
  • Implementing a zero-downtime Personal Access Token rotation strategy for service accounts that use the Tableau REST API, provisioning the replacement PAT and updating dependent systems before revoking the expiring token
  • Identifying the failure notification requirements for a scheduled TSM backup script
  • Recommending an automated deployment approach for rolling out Tableau Desktop updates to hundreds of endpoints in a managed enterprise environment using endpoint management tooling
  • The differences between deploying Tableau Desktop via MSI with transform files versus using a package manager
  • Identifying the automation limitations of Tableau Server DR processes that require manual steps and designing compensating controls to maintain RTO compliance despite those limitations
  • Identifying which components of the Tableau Server disaster recovery process cannot be fully automated, such as manual license re-activation in certain environments
  • Designing compensating manual runbook steps that preserve the overall RTO target despite non-automatable Tableau Server DR components
  • Planning the correct upgrade sequence for a three-node Tableau Server cluster, including which node must be upgraded first and the required TSM commands at each stage
  • Designing a Tableau Server major version upgrade plan for a production cluster that minimizes downtime by staging a blue-green parallel environment before traffic cutover
  • Determining the impact on end users of performing a rolling Tableau Server upgrade versus a maintenance-window full-cluster upgrade, and when each approach is appropriate
  • Scripting a Tableau Server maintenance workflow using TSM commands to run cleanup, backup, and log rotation on a weekly schedule with email notification on failure
  • Designing a Tableau Server backup automation strategy that rotates backups, verifies restore integrity periodically, and stores copies offsite without requiring manual steps
  • Using the Tableau Metadata API to query data lineage and identify all workbooks and data sources that depend on a specific database table before that table is decommissioned
  • Constructing the correct GraphQL query structure for the Tableau Metadata API to retrieve field-level lineage information for a published data source
  • Determining when the Tableau Metadata API should be used over the REST API for content discovery and governance tasks
  • Which Tableau Metadata API governance capabilities require the Data Management add-on
  • Designing a content automation workflow that uses Tableau Webhooks to trigger a downstream process whenever an extract refresh completes, processing the event payload to update an external data catalog
  • Using the Tableau Hyper API to programmatically append new rows to a published extract without triggering a full refresh, and the conditions under which this approach is more efficient than a full refresh
  • Implementing event-driven monitoring using Tableau Webhooks to trigger an external incident management system when extract refresh failures exceed a defined threshold within a rolling time window
  • Using the Tableau Hyper API to programmatically build and update Hyper extract files in a custom ETL pipeline and publish them to Tableau Server, identifying when this approach is more efficient than relying on server-side extract refreshes
  • Configuring the Tableau Server Extension Gallery safe list to allow a specific dashboard extension from a known URL while blocking all others in a security-hardened environment
  • Troubleshooting a web data connector that works in Tableau Desktop but fails when the workbook is published to Tableau Server due to network access restrictions or CORS policies
  • The security configuration differences between full-access and sandboxed dashboard extensions in Tableau Server
  • When full-access versus sandboxed dashboard extension trust levels are appropriate in a security-hardened Tableau Server environment
  • Determining the administrator steps required to allow a new WDC to be used in published workbooks on Tableau Server, including allowlist configuration and version pinning
  • Verifying that sandbox restrictions are appropriate for a dashboard extension's data access requirements after adding it to the Tableau Server safe list
  • Implementing a custom embedded analytics portal using Tableau Connected Apps with JWT authentication, specifying the required JWT claims (iss, sub, aud, exp, jti) and the Tableau Embedding API integration
  • Choosing between Tableau trusted authentication and Connected Apps for a new embedded analytics project, evaluating the security implications, implementation complexity, and long-term support lifecycle of each
  • Troubleshooting a Tableau embedded view that loads correctly for administrators but shows an authorization error for regular users due to a misconfigured Connected App user filter claim
  • Identifying when a Connected App with user impersonation is the correct approach for an embedding use case where the portal must enforce row-level security based on the authenticated portal user's identity
  • Implementing Tableau Embedded Analytics using the Tableau Embedding API v3 JavaScript library, identifying the differences from the legacy embedding approach in initialization syntax, event model, filter API, and lifecycle management
  • Restricting embedded Tableau content to only load when accessed from approved domains using the Connected App allow-domain configuration, preventing unauthorized embedding of published views on external sites
  • Monitoring Tableau Cloud storage utilization using Admin Insights to identify which sites and published data sources consume the most storage and designing a governance policy to archive or remove stale content before storage limits are reached
  • Comparing the storage impact of publishing large extracts as standalone published data sources versus embedding them inside workbooks, and recommending the strategy that minimizes Tableau Cloud storage consumption while maintaining acceptable refresh performance
  • Designing an automated content promotion pipeline using the Tableau REST API to migrate validated workbooks from a development site to production, including data source connection remapping, tag assignment, and permission configuration as part of the deployment script
  • Integrating the Tableau Content Migration Tool into a CI/CD pipeline triggered by a version control merge to automatically promote approved workbooks from the staging environment to production with connection string remapping and project placement
  • Identifying the Tableau REST API endpoints and request sequence required to publish a workbook, update its embedded data source credentials, apply a certification badge, and assign project permissions in a single idempotent deployment script
  • Designing a branching strategy for Tableau workbook development where feature branches in version control map to Tableau Server development sites and merges to main trigger automated promotion through staging to production
  • Designing a Tableau Server project permission hierarchy using nested projects with locked permissions to enforce a content governance model where project leaders can manage their own team's content without requiring server-administrator privileges
  • How permission locking at a parent project level affects the ability of nested project owners to set custom permissions on child content
  • When locked versus unlocked permission propagation is the correct governance architecture for nested Tableau Server projects
  • Designing a data certification and quality warning workflow using Tableau Catalog so that content consumers can reliably distinguish trusted, certified data sources from unreviewed or potentially stale ones across the organization
  • Configuring a gated promotion workflow where workbooks must be reviewed and approved before they can be moved from a Draft project to the Published project, using project permissions and the Tableau REST API to enforce the gating logic
  • Configuring Tableau Server SMTP settings and site-level subscription defaults to enable scheduled view subscriptions
  • The administrator controls for restricting subscription creation by site or user role on Tableau Server
  • Troubleshooting Tableau Server subscription emails that are not delivered to recipients despite the subscription appearing active, diagnosing SMTP relay authentication failures, spam filter blocking, and extract data staleness as candidate root causes
  • Configuring data-driven alerts on Tableau Server and the conditions that trigger alert delivery
  • The minimum extract or live-query refresh cadence required for Tableau Server data-driven alerts to evaluate correctly
  • The role of data-driven alert ownership in downstream permission enforcement on Tableau Server
  • Diagnosing a data-driven alert that fires continuously even after the alert condition is no longer met and identifying the alert acknowledgment and reset mechanism that clears the trigger state in Tableau Server

Prepare for the Exam

Play Today's Certle
Back to track

Study Community

Ask questions and get the latest info from other Tableau Architect studiers. 595 members and growing.

Go to Discord

Determining the behavior of Tableau Server extract encryption when a workbook owner publishes an extract-backed workbook and later changes the encryption policy at the site level

Explainer

Learn More

Practice Question

Keep going

Next conceptWhether previously encrypted Tableau Server extracts are retroactively re-keyed when the site-level encryption policy changes

Checklist progress

0/373 (0%)

0 of 373 concepts learned

Tip: You can filter concepts by status.

Prepare for the Exam

Play Today's Certle
Back to track

Study Community

Ask questions and get the latest info from other Tableau Architect studiers. 595 members and growing.

Go to Discord

Explainer

Extract encryption at rest protects .hyper data files stored on Tableau Server by encrypting them while they sit on disk. Administrators control the feature through a site-level policy that dictates whether users can choose encryption, whether all extracts must be encrypted, or whether encryption is completely disabled. Changing that policy automatically triggers background jobs that re-encrypt or decrypt all existing extracts to match the new setting.

Core information
  • Tableau Server encrypts .hyper extracts at rest to secure stored data, while workbook files, cache files, and temporary files remain unencrypted.
More details and nuances
  • Switching the site policy to Enforce or Disable triggers a batch encryption or decryption process that runs on the backgrounder, which can significantly increase CPU and memory load depending on the volume of extracts.