Soru

Zorluk: OrtaPermission Sets and Permission Set Groups

An enterprise software company has 50 Account Executives assigned to a baseline profile named 'Sales Representative'. To support an upcoming project, 5 of these Account Executives temporarily require Read and Edit access to a custom object named 'Compliance Audit Log' for 90 days. The administrator needs to grant this access while adhering to security best practices and minimizing administrative overhead. Which configuration approach should the administrator implement?

  1. Create a Permission Set granting Read and Edit permissions on the Compliance Audit Log object, assign it to the 5 Account Executives with an expiration date of 90 days, and leave the baseline profile unchanged.Cevap
  2. B
    Clone the 'Sales Representative' profile, add Read and Edit permissions for the Compliance Audit Log object to the new profile, and reassign the 5 Account Executives to it.
  3. C
    Modify the baseline 'Sales Representative' profile to grant Read and Edit permissions on the Compliance Audit Log object for all 50 Account Executives.
  4. D
    Create a Permission Set Group with a Muting Permission Set that enables Read and Edit permissions on the Compliance Audit Log object, and assign it to the 5 Account Executives.

Cevap

Create a Permission Set granting Read and Edit permissions on the Compliance Audit Log object, assign it to the 5 Account Executives with an expiration date of 90 days, and leave the baseline profile unchanged.
Permission Sets are designed to grant additive permissions to specific users beyond what their baseline profile provides. By assigning a Permission Set with an expiration date, the administrator ensures principle of least privilege, avoids creating redundant profiles, and automates access revocation after 90 days.

Adım Adım Çözüm

1
Analyze access requirements
Identify that 5 users require additive object permissions for a limited time (90 days).
Profiles define baseline access shared by all assigned users, whereas permission sets extend access to specific subsets of users.
2
Evaluate configuration tools
Select a Permission Set with an assigned expiration date.
Permission Sets provide additive security control without altering the shared profile or requiring manual cleanup after the temporary duration expires.

Anahtar Kavram

Using Permission Sets and Assignment Expiration for Additive and Temporary Access
Tahmini Süre:1m 30s
Bu soruyu puanla