Soru

Zorluk: OrtaOrganization-Wide Defaults (OWD)

An administrator is configuring security access for a custom object named Vehicle_Inspection__c. The organization requires that users should only see their own inspection records by default. Furthermore, upper-level managers must not automatically receive access to records owned by employees below them in the role hierarchy. Which two actions must the administrator take within Organization-Wide Defaults to satisfy these requirements? (Select two answers.)

  1. Set the Default Internal Access for Vehicle_Inspection__c to Private.Cevap
  2. Deselect the Grant Access Using Hierarchies checkbox for Vehicle_Inspection__c.Cevap
  3. C
    Create a custom profile for managers that revokes Read access to Vehicle_Inspection__c records owned by subordinates.
  4. D
    Modify the Manager role in the Role Hierarchy to disable automatic record access inheritance.

Cevap

The administrator must set the Default Internal Access for Vehicle_Inspection__c to Private and deselect the Grant Access Using Hierarchies setting for the custom object in Organization-Wide Defaults.
Setting Default Internal Access to Private ensures that non-owners cannot view or edit inspection records by default, which enforces the most restrictive baseline. Deselecting the Grant Access Using Hierarchies setting on a custom object stops automatic record access from extending up the role hierarchy to managers and executives.

Adım Adım Çözüm

1
Determine the baseline access required for non-owner users.
Identify that setting Default Internal Access to Private ensures users can only see records they own.
Organization-Wide Defaults define the default baseline access level for records an employee does not own.
2
Evaluate the requirement regarding manager access inheritance via the role hierarchy.
Identify that the Grant Access Using Hierarchies option must be unchecked for Vehicle_Inspection__c.
For custom objects, disabling Grant Access Using Hierarchies prevents superior roles from implicitly receiving access to records owned by subordinates.

Anahtar Kavram

Organization-Wide Defaults baseline security and role hierarchy access controls for custom objects.
Tahmini Süre:1m 15s
Bu soruyu puanla