Question

Difficulty: MediumLogin Security, Login IP Ranges, and Login Hours

A Salesforce Administrator is configuring security settings for customer support representatives assigned to a custom profile. The administrator needs to implement IP security controls using both Profile Login IP Ranges and Organization-Wide Network Access settings. Which two statements accurately describe how Salesforce enforces these login IP restrictions? (Select 2 answers)

  1. Users attempting to log in from an IP address outside their defined Profile Login IP Ranges are completely denied access.Answer
  2. Users attempting to log in from an IP address outside the Organization-Wide Network Access ranges are prompted for identity verification rather than being denied access.Answer
  3. C
    Users attempting to log in from an IP address outside their defined Profile Login IP Ranges can gain entry by successfully completing multi-factor authentication.
  4. D
    Configuring Organization-Wide Network Access ranges automatically blocks all login attempts originating from unlisted IP addresses.

Answer

The correct statements are that Profile Login IP Ranges enforce absolute restriction (hard denial) for logins outside the range, while Organization-Wide Network Access ranges determine whether identity verification is required.
Profile Login IP Ranges enforce a strict security policy where any login request outside the specified range is immediately denied. Conversely, Organization-Wide Network Access defines trusted IP ranges across the organization; logging in from outside these trusted ranges requires users to complete identity verification rather than preventing them from logging in.

Step-by-Step Solution

1
Analyze the function of Profile Login IP Ranges
Profile-level IP restrictions act as a hard security boundary. Logins outside the specified range are completely denied.
Profile security settings dictate mandatory access rules for all assigned users.
2
Analyze the function of Organization-Wide Network Access (Trusted IP Ranges)
Org-wide trusted IP ranges specify network locations where multi-factor/identity verification is bypassed.
Logins from outside org trusted ranges trigger an activation prompt rather than blocking the user.
3
Compare both mechanisms to select the correct statements
Statements highlighting profile hard denial and org-wide verification prompting are correct.
This accurately distinguishes between access restriction and identity verification controls in Salesforce.

Key Concept

Profile Login IP Ranges vs. Organization-Wide Network Access IP Ranges
Estimated Time:1m 30s
Rate this question