An administrator at Apex Global Financial configures security settings for users assigned to the Compliance Auditor profile. The organization-wide Network Access settings contain a trusted IP range of 198.51.100.0 to 198.51.100.255. On the Compliance Auditor profile, the administrator sets a Login IP Range of 198.51.100.50 to 198.51.100.100 and Login Hours from Monday through Friday, 08:00 AM to 05:00 PM. A user assigned to this profile attempts to log in under two separate conditions:
Condition 1: Saturday at 10:00 AM from IP address 198.51.100.75.
Condition 2: Tuesday at 02:00 PM from IP address 198.51.100.200.
Which outcome correctly describes the system behavior for these two login attempts?
- Both login attempts are denied because Profile Login Hours block Condition 1 and Profile Login IP Ranges block Condition 2.Cevap
- BCondition 1 is denied due to Profile Login Hours, while Condition 2 succeeds after requiring identity verification because the IP address is within Network Access.
- CCondition 1 is denied due to Profile Login Hours, while Condition 2 succeeds without identity verification because the IP address falls inside the trusted Network Access range.
- DCondition 1 succeeds after requiring identity verification, while Condition 2 is denied due to Profile Login IP Ranges.
Cevap
Both login attempts are denied because Profile Login Hours block Condition 1 and Profile Login IP Ranges block Condition 2.
Profile-level restrictions (Login Hours and Login IP Ranges) operate as absolute access controls. In Condition 1, logging in on Saturday violates the profile's allowed hours (Monday–Friday), resulting in denial. In Condition 2, logging in from IP 198.51.100.200 violates the profile's defined IP range (198.51.100.50 to 198.51.100.100). Even though this IP is listed in organization-wide Network Access, profile IP restrictions take precedence and completely block access rather than triggering identity verification.
Adım Adım Çözüm
Anahtar Kavram
Profile Login IP Ranges and Profile Login Hours enforce hard access denials. Org-wide Network Access trusted IP ranges merely relax identity verification (MFA/SMS prompts) for allowed logins and never override profile-level restrictions.