A security audit requires an organization to implement strict login controls for users assigned to the Field Auditor role. The administrator must ensure that:
1. Users attempting to log in from outside the corporate VPN subnet are completely blocked from authenticating.
2. Users currently logged in have their active session forcibly terminated as soon as their defined shift ends.
Which two configuration actions must the System Administrator perform to meet these requirements? (Select 2 answers)
- Add the corporate VPN subnet to the Login IP Ranges section on the Field Auditor profile.Answer
- Enable 'When login hours expire, terminate the session immediately' in Session Settings.Answer
- CAdd the corporate VPN subnet to Network Access under Organization-Wide Security Controls.
- DCreate a Permission Set with restricted Login IP Ranges and assign it to the Field Auditor users.
Answer
The administrator must add the corporate VPN subnet to the Login IP Ranges section on the user profile and enable immediate session termination upon login hours expiration in Session Settings.
Adding IP ranges to a user profile restricts login access strictly to those IP addresses, denying any attempt outside the range. Additionally, selecting the immediate session termination option under Session Settings ensures that active user sessions end immediately when profile Login Hours expire rather than allowing passive view access.
Step-by-Step Solution
Key Concept
Profile IP Restrictions vs. Org Network Access and Session Setting Expiration Policies