Soru

Zorluk: Çok zorPermission Sets and Permission Set Groups

An administrator at Cloud Kicks is designing an enterprise access control architecture using Permission Sets and Permission Set Groups. Match each specific administrative requirement on the left with the correct Salesforce configuration mechanism on the right.

  • Granting temporary access to manage sensitive financial fields for a 14-day audit project without modifying baseline profile settings.Permission Set Expiration Date Assignment
  • Restricting 'Delete' access on the Account object for users assigned a bundled set of permissions, without modifying the underlying component permission sets.Muting Permission Set
  • Combining multiple distinct permission sets ('Lead Manager', 'Opportunity Approver', and 'Contract Editor') into a single reusable package for simplified user assignment.Permission Set Group
  • Providing additive 'Read' and 'Create' permissions on a custom 'Audit Log' object to a select group of users spanning multiple departments.Standalone Permission Set

Cevap

The correct matches pair temporary financial field access with Permission Set Expiration Date Assignment, restricting delete access within a bundle with a Muting Permission Set, combining permission sets into a single package with a Permission Set Group, and extending custom object permissions with a Standalone Permission Set.
Each administrative requirement aligns with a specific Salesforce security feature: temporary access requires assignment expiration dates; masking permissions within an aggregated bundle requires a muting permission set; packaging multiple permission sets together requires a permission set group; and granting incremental permissions across different roles requires a standalone permission set.

Adım Adım Çözüm

1
Evaluate requirement 1 regarding time-bound access for a 14-day audit project.
Identify that setting an expiration date on a permission set assignment automatically handles temporary access revocation.
Salesforce natively supports assignment expiration dates on user permission set assignments.
2
Evaluate requirement 2 regarding turning off a specific permission within bundled permission sets.
Identify Muting Permission Sets as the mechanism to suppress permissions inside a Permission Set Group.
Muting permission sets selectively negate permissions within the context of the group in which they are placed.
3
Evaluate requirement 3 regarding aggregating multiple permission sets into one assignable unit.
Identify Permission Set Groups as the solution for combining related permission sets.
Permission Set Groups streamline user assignment by bundling separate permission sets together.
4
Evaluate requirement 4 regarding granting additional object access to specific cross-departmental users.
Identify a Standalone Permission Set as the proper tool for additive user permissions.
Profiles define baseline access, whereas standalone permission sets addively grant object/field permissions to specific users.

Anahtar Kavram

Permission Sets, Permission Set Groups, Muting Permission Sets, and User Assignment Expiration
Tahmini Süre:2m 0s
Bu soruyu puanla