Soru

Zorluk: OrtaOrganization-Wide Defaults (OWD)

An administrator at Cloud Kicks needs to configure access security for a custom object called Project__c. Business requirements mandate that sales representatives must only be able to view and edit Project records that they own. However, managers must automatically inherit read and edit access to Project records owned by their subordinates in the role hierarchy. Which configuration of Organization-Wide Defaults (OWD) and hierarchy settings fulfills these requirements with the most restrictive baseline access?

  1. Set the Organization-Wide Default to Private and ensure 'Grant Access Using Hierarchies' is selected.Cevap
  2. B
    Set the Organization-Wide Default to Public Read-Only and create a permission set that restricts access for sales representatives.
  3. C
    Set the Organization-Wide Default to Private and deselect 'Grant Access Using Hierarchies', assuming custom object access does not propagate up the role hierarchy automatically.
  4. D
    Set the Organization-Wide Default to Private and deselect 'Grant Access Using Hierarchies', then assign a profile with 'Modify All' object permissions to sales managers.

Cevap

Setting the Organization-Wide Default to Private while leaving 'Grant Access Using Hierarchies' selected provides the required restrictive baseline access while allowing managers to access records owned by their direct reports.
The baseline access requirement is for users to access only records they own, which mandates a Private Organization-Wide Default setting. Selecting 'Grant Access Using Hierarchies' ensures that users higher in the role hierarchy automatically gain access to records owned by or shared with their subordinates.

Adım Adım Çözüm

1
Determine the baseline visibility requirement for general users.
Sales representatives should only access records they own, so the baseline OWD must be set to Private.
Organization-Wide Defaults specify the baseline level of access for records users do not own.
2
Evaluate access requirements for higher roles in the role hierarchy.
Managers need automatic access to subordinates' records.
The 'Grant Access Using Hierarchies' checkbox for custom objects ensures users higher in the role hierarchy inherit the same level of access as users below them.
3
Verify security principle constraints.
Do not attempt to restrict access via profiles or permission sets.
In Salesforce, permissions in profiles/permission sets are additive and cannot revoke baseline access granted by OWD.

Anahtar Kavram

Organization-Wide Defaults (OWD) establish the baseline record-level security in Salesforce. Settings in profiles or permission sets can only expand access, never restrict it beyond OWD.
Tahmini Süre:1m 30s
Bu soruyu puanla