Soru

Zorluk: OrtaUser Management and Provisioning

A company administrator needs to provision temporary access for a Customer Support Representative who is joining an internal audit task force for three months. The user must retain their current access to customer cases while gaining Read-only access to custom financial audit records. Which two actions should the administrator take to meet these requirements while adhering to the principle of least privilege?

  1. Assign a permission set to the user that grants Read access to the custom financial audit objects.Cevap
  2. Maintain the user's current Support Representative profile assignment.Cevap
  3. C
    Change the user's profile to Compliance Auditor and assign a permission set for support case access.
  4. D
    Deactivate the current user record and create a new user account assigned to the Compliance Auditor profile.

Cevap

The administrator should assign a permission set granting Read access to the custom financial audit objects and maintain the user's current Support Representative profile assignment.
In Salesforce, profiles define the core baseline permissions, while permission sets are used to grant additional permissions on an ad-hoc or temporary basis. Retaining the user's primary Support Representative profile maintains necessary ongoing case access, while applying a permission set grants the supplemental Read-only access to audit records in compliance with least privilege principles.

Adım Adım Çözüm

1
Analyze baseline profile requirements
Identify that the user continues to require their primary job function access (Support Representative).
Profiles define standard baseline access per user role.
2
Determine mechanism for temporary/additional permissions
Select a permission set for the financial audit object access.
Permission sets allow flexible, additive access extensions without profile proliferation.

Anahtar Kavram

User Provisioning and Additive Access via Permission Sets
Tahmini Süre:1m 30s
Bu soruyu puanla