Soru

Zorluk: OrtaSession Settings and Password Policies

A security audit reveals that remote employees can initiate a Salesforce session while connected to an authorized corporate network and continue using the active session token after switching to an untrusted network. Which setting in Session Settings should the administrator configure to prevent a session from remaining valid when a user's IP address changes?

  1. Lock sessions to the IP address from which they originatedCevap
  2. B
    Add the corporate network range to Network Access in Security Controls
  3. C
    Assign a Permission Set with restricted Login IP Ranges to all remote users
  4. D
    Enforce Session Security Level Required at Login to High Assurance on all user profiles

Cevap

The administrator should enable 'Lock sessions to the IP address from which they originated' in Session Settings.
Enabling 'Lock sessions to the IP address from which they originated' in Setup > Session Settings forces Salesforce to verify that every HTTP request originates from the IP address associated with the initial login. If the IP address changes, the session is invalidated immediately.

Adım Adım Çözüm

1
Identify the security requirement.
The requirement is to invalidate active session tokens if a user shifts from one network IP to another.
Preventing session reuse across different IP addresses mitigates session hijacking risks.
2
Evaluate Salesforce Session Settings options.
The setting 'Lock sessions to the IP address from which they originated' explicitly forces session termination when the client IP changes.
This setting directly evaluates the origin IP of incoming requests against the initial login IP.

Anahtar Kavram

Session IP Locking in Salesforce Session Settings
Bu soruyu puanla