SF-PD2 User Interface Practice Question
A developer is building a Lightning Web Component that contains an iframe hosting an external web application. The external application needs to send a message back to the Lightning Web Component when a user completes a task. Which mechanism should the developer use to receive that message securely?
⚠ Common exam trap
The trap here is assuming that Salesforce messaging features such as Lightning Message Service extend into third-party iframes, when browser cross-origin rules require the postMessage API instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a window message event listener in the component and validate the event origin against the expected external domain before processing the payload.
Cross-origin communication with an embedded external application is handled through the browser's postMessage API. The component adds a window message listener and validates event.origin against the trusted domain before acting on the payload. Lightning Message Service, @api properties, and polling contentWindow cannot bridge the same-origin boundary that isolates the external iframe.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Register a Lightning Message Service message channel and subscribe to it from the component; the iframe publishes to the same channel.
Why it's wrong here
Lightning Message Service operates within the Salesforce application's Lightning runtime and does not bridge to arbitrary external pages inside an iframe. An external application cannot publish to a Lightning message channel because it lacks access to the Lightning Message Service APIs and the required context. This approach would work only for communication between Salesforce components, not for an external iframe.
- ✗
Use the Lightning Web Component's @api property to bind directly to a variable exposed by the iframe's document object.
Why it's wrong here
Cross-origin iframes are isolated by the browser's same-origin policy, so the host component cannot access the iframe's document or its variables. The @api decorator only exposes component members to Salesforce parents, not to external documents. This approach is blocked by browser security and would not receive any messages from the external application.
- ✗
Poll the iframe element's contentWindow property on an interval and read a status variable set by the external application.
Why it's wrong here
The same-origin policy prevents reading contentWindow properties of an iframe served from a different origin, so polling would throw a security error or return nothing. Even for same-origin frames, polling is inefficient and introduces latency. It is neither secure nor functional for cross-origin communication and ignores the browser-provided messaging API designed for this case.
- ✓
Add a window message event listener in the component and validate the event origin against the expected external domain before processing the payload.
Why this is correct
The browser's postMessage API is the standard way for an iframe and its host to exchange data across origins. Listening for the message event on window and verifying event.origin against the trusted external domain prevents malicious pages from injecting forged messages. This is the secure, supported pattern for cross-origin communication with an embedded external application.
About these practice questions
One of 226 original SF-PD2 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Salesforce exam blueprint
This SF-PD2 practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-PD2 exam.