Soru

Zorluk: OrtaProfiles and Object/Field-Level Security

A Salesforce Administrator needs to configure appropriate access controls and security settings for several distinct operational requirements. Match each business security requirement to the correct Salesforce administrative feature.

  • Completely deny login access to users of a specific profile when they attempt to log in outside approved shift hours.Profile Login Hours
  • Hide a sensitive custom field on the Contact record from all users assigned to a profile regardless of page layout assignments.Field-Level Security (FLS)
  • Restrict profile users from logging in from unrecognized IP addresses by denying access completely rather than prompting for identity verification.Profile Login IP Ranges
  • Grant Read and Edit object permissions on a custom Project object to two specific sales reps without modifying their existing profile.Permission Set

Cevap

Each security requirement matches its dedicated security control: Shift hour login restriction matches Profile Login Hours; sensitive field hiding matches Field-Level Security (FLS); strict IP login restriction with total denial matches Profile Login IP Ranges; and granting extra permissions to specific users matches Permission Sets.
Matching security requirements to Salesforce administrative capabilities requires evaluating the layer of security targeted: Profile Login Hours control authentication timeframes; Field-Level Security (FLS) controls field access globally regardless of layout; Profile Login IP Ranges enforce strict network boundary denials; and Permission Sets provide flexible, targeted permission extensions without profile duplication.

Adım Adım Çözüm

1
Analyze time-based access control requirement
Identified Profile Login Hours as the feature that enforces hard login window boundaries per profile.
Profile Login Hours prevent users from authenticating outside specified schedules.
2
Analyze data sensitivity requirement for specific fields
Identified Field-Level Security (FLS) as the authoritative control for hiding fields across all interfaces.
Page layouts only control layout visibility, whereas FLS enforces security across API, reports, and detail pages.
3
Evaluate network security restriction mechanisms
Identified Profile Login IP Ranges as the feature that denies access outside specified IP bounds.
Organization-wide Network Access allows logins outside IP ranges via identity verification, whereas Profile Login IP Ranges explicitly deny access.
4
Determine method for granting selective access expansion
Identified Permission Sets as the mechanism to add object access to selected users.
Profiles establish baseline access; permission sets grant incremental access to specific individual users adhering to the principle of least privilege.

Anahtar Kavram

Salesforce Security Layering: Profiles, Permission Sets, FLS, and Login Restrictions
Bu soruyu puanla