Soru

Zorluk: OrtaProfiles and Object/Field-Level Security

Vanguard Global Tech needs to restrict access to a sensitive custom field, Base_Salary__c, on the Employee__c object so that only two HR Specialists out of fifty HR team members can view and edit it. Additionally, compliance mandates that all users assigned to the Standard HR Profile must be blocked from logging into Salesforce if they are outside the corporate network IP range. Which two administrative actions should the Salesforce Administrator take to satisfy these security requirements? (Choose 2 answers)

  1. Create a Permission Set granting Read and Edit access for the Base_Salary__c field and assign it exclusively to the two HR Specialists.Cevap
  2. Specify the corporate network IP range in the Login IP Ranges settings of the Standard HR Profile.Cevap
  3. C
    Use Dynamic Forms component visibility rules on the Employee record page to hide the Base_Salary__c field from unauthorized users.
  4. D
    Add the corporate network IP range to Network Access under Organization-Wide Security Settings.

Cevap

The correct administrative actions are creating a Permission Set granting Read and Edit access to the sensitive field for the two HR Specialists, and defining the corporate network IP range under Login IP Ranges on the Standard HR Profile.
Creating a Permission Set allows the administrator to selectively grant Read and Edit Field-Level Security (FLS) to the two HR Specialists without altering the access of other users on the Standard HR Profile. Configuring Login IP Ranges directly on the Standard HR Profile enforces hard restrictions that prevent any user with that profile from logging in outside the designated corporate network IPs.

Adım Adım Çözüm

1
Evaluate field-level security requirements for a subset of users on the same profile.
Keep field-level security restricted (no access) on the base profile for all fifty HR team members, and create a Permission Set with Read and Edit access assigned only to the two HR Specialists.
Permission sets provide additive permissions for specific users, avoiding profile proliferation.
2
Evaluate login restriction requirements for all users on the Standard HR Profile.
Configure the corporate IP range within the Login IP Ranges section of the Standard HR Profile.
Profile-level Login IP Ranges enforce strict login blocking outside the designated ranges.

Anahtar Kavram

Profiles control base restrictions (such as Login IP Ranges), while Permission Sets extend additive access (such as Field-Level Security) to subset user groups.
Tahmini Süre:1m 30s
Bu soruyu puanla