Slack-Dev-201 Sample Questions & Answers
Designing an app's interactive flow takes the biggest share, next to OAuth installation and scope security, choosing between the Web and Events APIs, growing into Enterprise Grid, Bolt and the Block Kit builder, admin and SCIM APIs, and app distribution.
Launch the full Slack-Dev-201 simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Design for Security · Identify the steps you could take to make your app communicate securely in Slack
During a security audit, a vulnerability is identified in how your Slack app verifies incoming requests. The auditor notes that while you are checking the signature, you are not preventing replay attacks. Which specific header must be validated alongside the signature to mitigate this risk, and what is the standard tolerance window?
Show answer & explanation
Correct answer: B
To prevent replay attacks, apps must validate the
X-Slack-Request-Timestampheader. If the timestamp is too old (Slack recommends a tolerance of 5 minutes), the request should be ignored, even if the signature matches. This prevents an attacker from capturing a valid request and re-sending it later. - Question 2Beginner
Tools · Recommend when to use the Bolt development framework to build Slack apps
You are developing a Slack app using the Bolt framework for Python. You need to handle a specific Slash Command
/ticket. Which decorator should you use to register a listener for this command?Show answer & explanation
Correct answer: D
In Bolt for Python, the
@app.command()decorator is used to listen for slash command events. The argument passed to the decorator is the name of the command (e.g., "/ticket"). - Question 3Intermediate
APIs for Managing Your Slack · Recommend when to use the Discovery API for data-loss prevention, compliance archiving or eDiscovery
A multinational corporation uses Enterprise Grid with over 500 workspaces. An administrator needs to perform a data loss prevention (DLP) scan across all public channels in the organization to identify messages containing credit card numbers. Which API is specifically designed for this compliance use case?
Show answer & explanation
Correct answer: B
The Discovery API is purpose-built for eDiscovery and Data Loss Prevention (DLP) solutions. It allows authorized apps to search and retrieve messages and files across an entire Enterprise Grid organization, regardless of channel membership, specifically for compliance purposes.
- Question 4Intermediate
APIs for Managing Your Slack · Use the SCIM API to manage Slack users and user groups
You are building a custom integration that needs to provision and deprovision users from an external HR system into Slack. The integration must also manage user group memberships (e.g., adding new hires to 'Engineering' and 'San Francisco' groups). Which API standard and Slack implementation should you use?
Show answer & explanation
Correct answer: B
Slack supports the SCIM 2.0 (System for Cross-domain Identity Management) standard. The SCIM API is the designated tool for automated user provisioning, deprovisioning, and managing user group memberships programmatically from identity providers or HR systems.
- Question 5Advanced
Design for Scale · Design your app to match the unique platform architecture, features and roles of Enterprise Grid impact your app’s design
Case Study:
Company Background
'TechStream' is a software company using Slack Enterprise Grid. They have 10 separate workspaces for different product lines.Current Situation
TechStream is building an 'Incident Commander' app. This app needs to be installed once at the organization level but must be usable inside every workspace. When an incident is declared in the #incidents channel of any workspace, the app should create a dedicated channel in that specific workspace and invite on-call engineers.Constraint
The security team requires that the app does not have access to private channels unless explicitly invited.Requirement
You need to configure the app distribution and token management.Which configuration strategy is correct for this scenario?
Show answer & explanation
Correct answer: A
While Org-wide installation exists, apps on Enterprise Grid still operate with a unique bot token per workspace. Even if 'installed' at the org level, the app must handle the OAuth flow or installation event to generate and store a distinct token for each workspace (Team ID) it operates in. To manage channels within a specific workspace, the app must use the token corresponding to that workspace.
- Question 6Beginner
Apps in the Slack Platform · Recommend when to use Slack’s different surfaces (user touchpoints including App home, modals and messages) for a range of use cases
A developer wants to create a personalized dashboard for every user that displays their pending tasks assigned from Jira. This dashboard should be accessible anytime the user clicks on the app's name in the sidebar. Which Slack surface is appropriate for this persistent, user-specific view?
Show answer & explanation
Correct answer: D
The App Home tab is a persistent, private, one-to-one surface between a user and an app. It is the ideal place for dashboards, personal settings, and user-specific data like pending tasks.
Ready for the real thing?
The full Slack-Dev-201 simulator has every exam-style question, timed mode, and instant scoring.