An enterprise software company has 50 Account Executives assigned to a baseline profile named 'Sales Representative'. To support an upcoming project, 5 of these Account Executives temporarily require Read and Edit access to a custom object named 'Compliance Audit Log' for 90 days. The administrator needs to grant this access while adhering to security best practices and minimizing administrative overhead. Which configuration approach should the administrator implement?
- Create a Permission Set granting Read and Edit permissions on the Compliance Audit Log object, assign it to the 5 Account Executives with an expiration date of 90 days, and leave the baseline profile unchanged.Cevap
- BClone the 'Sales Representative' profile, add Read and Edit permissions for the Compliance Audit Log object to the new profile, and reassign the 5 Account Executives to it.
- CModify the baseline 'Sales Representative' profile to grant Read and Edit permissions on the Compliance Audit Log object for all 50 Account Executives.
- DCreate a Permission Set Group with a Muting Permission Set that enables Read and Edit permissions on the Compliance Audit Log object, and assign it to the 5 Account Executives.
Cevap
Create a Permission Set granting Read and Edit permissions on the Compliance Audit Log object, assign it to the 5 Account Executives with an expiration date of 90 days, and leave the baseline profile unchanged.
Permission Sets are designed to grant additive permissions to specific users beyond what their baseline profile provides. By assigning a Permission Set with an expiration date, the administrator ensures principle of least privilege, avoids creating redundant profiles, and automates access revocation after 90 days.
Adım Adım Çözüm
Anahtar Kavram
Using Permission Sets and Assignment Expiration for Additive and Temporary Access
Tahmini Süre:1m 30s