Soru

Zorluk: OrtaPermission Sets and Permission Set Groups

A digital media agency has 80 content creators assigned to a single baseline profile named 'Content Creator'. The company recently introduced a custom object named 'Sponsor Contracts'. The system administrator needs to grant Read and Edit access for 'Sponsor Contracts' to a subset of 15 creators who manage corporate sponsorships, while keeping their base profile unchanged. Additionally, the administrator wants to simplify ongoing management by grouping these sponsorship permissions with existing specialized media permissions. Which two administrative configuration steps should the administrator take to fulfill these requirements? (Select 2 answers)

  1. Create a Permission Set granting Read and Edit permissions on the Sponsor Contracts object.Cevap
  2. B
    Clone the 'Content Creator' profile to create a 'Sponsorship Creator' profile with Read and Edit access on Sponsor Contracts, and reassign the 15 users.
  3. Add the newly created Permission Set into a Permission Set Group that consolidates relevant specialized permissions and assign the group to the 15 sponsorship creators.Cevap
  4. D
    Modify the baseline 'Content Creator' profile to grant Read and Edit permissions on Sponsor Contracts for all 80 content creators.

Cevap

The administrator should create a Permission Set granting Read and Edit permissions on Sponsor Contracts and include it in a Permission Set Group assigned to the 15 users.
Creating a focused Permission Set grants additive Read and Edit access on the Sponsor Contracts custom object without affecting other users on the baseline profile. Including this Permission Set in a Permission Set Group consolidates permissions for cleaner, scalable user assignment.

Adım Adım Çözüm

1
Determine the strategy for additive permissions.
Identify that a Permission Set should be created for object-level access on Sponsor Contracts to avoid modifying baseline profile settings.
Profiles provide baseline access, whereas Permission Sets grant additive permissions to specific user subsets according to least privilege.
2
Consolidate permissions into a Permission Set Group.
Combine the new Sponsor Contracts Permission Set with existing specialized Permission Sets into a single Permission Set Group.
Permission Set Groups enable scalable management by bundling related permission sets into a single assignment for users.
3
Assign the Permission Set Group to the targeted users.
Assign the consolidated group to the 15 creators who handle corporate sponsorships.
This grants all required permissions in a structured manner while leaving the 65 other creators with only baseline access.

Anahtar Kavram

Additive permissions via Permission Sets and scalable management using Permission Set Groups
Bu soruyu puanla