Soru

Zorluk: ZorUser Management and Provisioning

Universal Containers is updating its user governance procedures. An administrator must fulfill two specific operational requirements:

1. A senior operations manager who is currently designated as the default user in active lead assignment rules and referenced in custom user hierarchy fields is taking a 6-month sabbatical.
2. A group of external auditors requires temporary access to confidential risk assessment records for a strict 30-day timeframe.

Which TWO administrative actions should the Salesforce Administrator take to address these requirements without disrupting system processes or compromising security? (Select TWO)

  1. Freeze the senior operations manager's user account to prevent logins during the sabbatical.Cevap
  2. Assign the external auditors a standard profile with base permissions and grant temporary access to risk assessment records via a permission set with an expiration date.Cevap
  3. C
    Deactivate the senior operations manager's user account to release their assigned user license during their sabbatical.
  4. D
    Add the external auditors' IP range under Organization-Wide Network Access to restrict their login attempts strictly to corporate networks.

Cevap

The administrator should freeze the manager's user account to block access while preserving automated system references, and provision the external auditors using a standard profile combined with a permission set that has a defined expiration date.
Freezing the account of the manager on sabbatical immediately blocks authentication without breaking active lead assignment rules or hierarchy references that would prevent deactivation. Using permission sets with expiration dates for the external auditors enables time-bound temporary access to specialized objects without modifying base profile assignments or requiring manual revocation.

Adım Adım Çözüm

1
Analyze the account status requirement for the manager on sabbatical.
Identified that deactivation will fail or break automated lead assignment rules and hierarchy fields because the user is actively referenced across automation settings.
Freezing blocks authentication immediately without removing license allocations or invalidating automated background process dependencies.
2
Evaluate access provisioning for the short-term risk assessment auditors.
Determined that assigning a permission set with an expiration date on top of a minimal base profile satisfies temporary privilege elevation.
Permission set expiration feature automatically revokes access after 30 days without requiring custom profile creation or manual administrative cleanup.
3
Evaluate wrong options regarding deactivation and network security.
Confirmed that deactivation disrupts process dependencies, and Network Access trusted IP ranges do not restrict login capability outside specified ranges.
Profile IP ranges restrict access strictly, whereas Network Access settings only control multi-factor/identity verification challenges.

Anahtar Kavram

User Lifecycle Management and Temporary Access Provisioning
Bu soruyu puanla