Soru

Zorluk: ZorSession Settings and Password Policies

An organization's compliance policy requires that when any user's session expires due to inactivity, the active session token must be immediately invalidated and the user redirected to the main login page, forcing a full re-authentication from scratch. During an internal audit, an administrator notices that when sessions time out, users are presented with a pop-up modal on their current page prompting for password re-entry rather than terminating the session entirely. Which configuration change must the administrator make to comply with the policy?

  1. Select the 'Force logout on session timeout' setting in Organization-Wide Session Settings.Cevap
  2. B
    Create and assign a Permission Set that enables strict session termination rules for all active users.
  3. C
    Define corporate subnet limits under Profile Login IP Ranges to enforce session re-authentication upon expiration.
  4. D
    Add the organization's IP address block to Network Access to automatically invalidate idle session tokens.

Cevap

Select the 'Force logout on session timeout' setting in Organization-Wide Session Settings.
In Salesforce, navigating to Setup > Session Settings provides a global configuration option called 'Force logout on session timeout'. When this setting is enabled, session expiration completely invalidates the session token and redirects the browser to the login page. When left unchecked, Salesforce retains the session context and displays a lock overlay requesting credential re-entry.

Adım Adım Çözüm

1
Analyze the compliance requirement
The requirement demands full session invalidation and redirection to the main login page upon inactivity timeout.
By default, Salesforce locks the session without terminating it, allowing users to re-enter credentials via an inline prompt to resume their work.
2
Evaluate Salesforce administrative settings controlling session timeout behaviors
Organization-Wide Session Settings contain the checkbox 'Force logout on session timeout'.
When checked, this setting ensures that an expired session cannot be unlocked in-place and forces a complete logout and page redirect.
3
Eliminate invalid control locations
Permission Sets, Profile Login IP Ranges, and Network Access do not control session termination modal behavior.
Session Settings are controlled centrally in Setup or overridden at the Profile level, whereas IP ranges control network entry points.

Anahtar Kavram

Session Settings and Password Policies
Bu soruyu puanla