Soru

Zorluk: Çok zorOrganization-Wide Defaults (OWD)

Apex Global Logistics manages compliance operations in Salesforce. The security team mandates two strict data access requirements:

1. Access to a custom object named Audit_Inspection__c must be restricted strictly to record owners and explicitly shared users. Managers and executives must NOT automatically inherit access to records owned by their subordinates.
2. Default access to the standard Account object must prevent sales representatives from viewing accounts owned by other teams, while still permitting managers higher in the role hierarchy to maintain view and edit access to accounts owned by their subordinates.

Which two configuration actions must the Salesforce Administrator take to meet these security requirements? (Select TWO answers.)

  1. Set the Organization-Wide Default for Audit_Inspection__c to Private and deselect Grant Access Using Hierarchies.Cevap
  2. Set the Organization-Wide Default for Account to Private.Cevap
  3. C
    Deselect Grant Access Using Hierarchies on the Account Organization-Wide Default setting.
  4. D
    Create a permission set with explicit Revoke Read rules on Audit_Inspection__c and assign it to management roles.

Cevap

The administrator must set the Organization-Wide Default for Audit_Inspection__c to Private while deselecting Grant Access Using Hierarchies, and set the Organization-Wide Default for Account to Private.
For custom objects, Organization-Wide Defaults can be set to Private, and administrators have the option to deselect 'Grant Access Using Hierarchies' to prevent managers from automatically viewing subordinate records. For standard objects such as Account, setting the OWD to Private restricts peer-level access, but Grant Access Using Hierarchies is permanently enabled and cannot be unchecked.

Adım Adım Çözüm

1
Analyze the access requirement for the custom object Audit_Inspection__c.
Set OWD to Private and uncheck Grant Access Using Hierarchies.
Custom objects allow administrators to deselect Grant Access Using Hierarchies to prevent automatic access propagation up the role hierarchy.
2
Analyze the access requirement for the standard Account object.
Set the Account OWD to Private.
Standard objects automatically grant access to higher roles in the hierarchy; this hierarchy access behavior is non-configurable for standard objects.
3
Evaluate alternative claims regarding permission sets and standard object hierarchy toggles.
Reject options attempting to restrict permissions via permission sets or deselecting hierarchy access on Accounts.
Permission sets are strictly additive and cannot revoke access. Standard object hierarchy access is always enabled.

Anahtar Kavram

Organization-Wide Defaults (OWD) and Hierarchy Access Control for Standard vs. Custom Objects
Bu soruyu puanla