Tüm alıştırma soruları

1784 soru

Soru 1741Soru

An administrator is configuring regional support settings in Salesforce. Which two statements correctly describe the behavior of Business Hours and Holidays? (Choose 2 answers)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Holidays can be associated with multiple Business Hours schedules to pause target resolution times during non-working days.; Multiple Business Hours can be created to support different global time zones and operating schedules.

Cevap

Holidays can be associated with multiple Business Hours schedules to pause target resolution times during non-working days, and multiple Business Hours can be created to support different global time zones and operating schedules.
Holidays can be explicitly associated with specific Business Hours to prevent entitlement and escalation timers from counting holiday dates. Additionally, administrators can configure multiple Business Hours to accommodate various operating time zones across global support teams.

Adım Adım Çözüm

1
Identify the relationship between Business Hours and Holidays.
Holidays are linked to specific Business Hours to ensure SLA time calculations pause on designated holiday dates.
Without linking a holiday to a business hours schedule, escalation timers continue running.
2
Evaluate regional operational setup options.
Salesforce supports creating custom Business Hours for different time zones and regional schedules.
Global support organizations require distinct business hours to accurately track case age and escalation rules per region.

Anahtar Kavram

Business Hours and Holiday Configuration
Soru 1742Soru

A Salesforce Administrator at Cloud Heights Logistics is configuring login security controls for users assigned to the Support Specialist profile. The administrator configures specific IP ranges on the Support Specialist Profile and separate IP ranges under Organization-Wide Network Access.

Which two statements accurately describe how Salesforce enforces these IP restrictions? (Select 2 answers)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Users attempting to log in from an IP address outside the Profile IP Ranges are completely blocked from accessing Salesforce.; Users logging in from an IP address within the Profile IP Ranges are granted access without receiving an identity verification prompt.

Cevap

Profile IP Ranges strictly deny login attempts from IP addresses outside the specified range. In addition, users logging in from IP addresses defined within Profile IP Ranges bypass identity verification prompts.
Profile IP Ranges enforce hard access restrictions. If an IP is outside the profile's allowed ranges, access is denied. If an IP is inside the profile's allowed ranges, the login is trusted and identity verification prompts are bypassed.

Adım Adım Çözüm

1
Analyze the restriction behavior of Profile IP Ranges.
Profile IP Ranges act as a hard login boundary. If an IP address falls outside the specified profile ranges, Salesforce denies login completely.
Profile-level IP restrictions take precedence and enforce strict access control.
2
Analyze the identity verification behavior of Profile IP Ranges versus Organization-Wide Network Access.
If a user's IP address is within the Profile IP Ranges, login is allowed without requiring an identity verification prompt (such as SMS or email verification codes).
Organization-Wide Network Access (Trusted IP Ranges) only controls whether activation codes/MFA prompts are issued when profile restrictions are not blocking the login.

Anahtar Kavram

Profile IP Ranges enforce strict login denial for unlisted IP addresses and bypass identity verification for listed IPs, whereas Organization-Wide Network Access only controls identity verification prompts.
Soru 1743Soru

A Salesforce administrator is configuring access management for users with varied operational responsibilities. Match each administrative requirement on the left to the corresponding security component on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Bundle multiple permission sets into a single logical assignment unit for users in specific job roles.
Grant extra object and field access to selected users without modifying their assigned profile.
Selectively disable specific permissions for a subgroup of users within a consolidated permission set group.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Bundling multiple permission sets corresponds to Permission Set Group; granting additive permissions corresponds to Permission Set; selectively disabling specific permissions within a group corresponds to Muting Permission Set.
Each administrative requirement aligns directly with its primary Salesforce security feature: Permission Set Groups consolidate multiple permission sets into a single assignment, Permission Sets add specific permissions beyond profile baselines, and Muting Permission Sets restrict specific access granted by a Permission Set Group.

Adım Adım Çözüm

1
Identify the component designed to combine multiple permission sets for role-based assignment.
Permission Set Group consolidates related permission sets.
Combining permission sets into groups streamlines assignment by job role.
2
Identify the component used to grant incremental object or field permissions.
Permission Set provides flexible, additive access.
Best practices dictate keeping baseline profiles minimal and extending access through permission sets.
3
Identify the construct used to remove permissions within a grouped assignment.
Muting Permission Set selectively suppresses permissions within a Permission Set Group.
Muting allows fine-tuning access within a group without creating duplicate permission sets.

Anahtar Kavram

Permission Sets, Permission Set Groups, and Muting Permission Sets
Soru 1744Soru

Universal Containers created a custom object named Asset_Inspection__c to track safety audits. Business requirements dictate that all internal employees must be able to view, edit, and report on every Asset_Inspection__c record, regardless of who owns the record. Which Organization-Wide Default (OWD) setting should the administrator select for the Asset_Inspection__c object?

Cevabı ve açıklamayı göster

Cevap: Public Read/Write

Cevap

Public Read/Write
Selecting Public Read/Write as the Organization-Wide Default grants all internal users default read and write permissions to all records of the custom object, fulfilling the requirement for universal view and edit access.

Adım Adım Çözüm

1
Analyze the access requirement
All internal users need both Read and Edit access to all records of Asset_Inspection__c regardless of ownership.
Organization-Wide Defaults establish the baseline record-level access for all users in Salesforce.
2
Evaluate the standard OWD setting levels
Public Read/Write provides full access to read and edit all records across the organization without requiring additional sharing rules.
Setting OWD to Public Read/Write directly satisfies the baseline access requirement in the simplest, most maintainable way.

Anahtar Kavram

Organization-Wide Defaults (OWD) Baseline Access
Soru 1745Soru

An administrator at Northern Trail Outfitters is configuring regional customer support schedules. The organization uses custom Business Hours for North American and European support teams, alongside a shared holiday schedule. Which two statements accurately describe how Salesforce processes Business Hours, Holidays, and Case Escalation Rules in this environment? (Choose 2 options)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: A single Holiday record can be added to multiple Business Hours schedules to suspend time calculations across different regional teams.; If Business Hours are assigned to a specific Case, Case Escalation Rules prioritize the Case's Business Hours over the Organization Default Business Hours when determining escalation action triggers.

Cevap

A single Holiday record can be added to multiple Business Hours schedules, and Case Escalation Rules prioritize the Business Hours assigned to a Case over the Organization Default Business Hours.
Holidays in Salesforce can be linked to multiple Business Hours schedules, allowing administrators to reuse holiday definitions across different regional teams. Furthermore, during Case Escalation Rule execution, Salesforce evaluates target times using the specific Business Hours assigned to the individual Case record, overriding the Organization Default Business Hours.

Adım Adım Çözüm

1
Analyze how Holidays interact with Business Hours schedules.
Confirm that Holiday records can be associated with one or more Business Hours schedules so non-working hours are excluded from SLA and escalation timing.
Salesforce requires explicit linking between Holidays and Business Hours schedules; holidays do not apply globally by default.
2
Evaluate the order of precedence for Business Hours during Case Escalation Rule evaluation.
Determine that Case-level Business Hours take precedence over the Organization Default Business Hours.
Escalation rules respect custom SLAs assigned directly to records or escalation entries before falling back to org-wide defaults.
3
Verify time zone evaluation for Case Escalation calculations.
Confirm that escalation timers depend on the Business Hours time zone setting, not the viewing user's time zone.
Using the Business Hours time zone ensures consistent SLA timing across global support operations regardless of who views the case.

Anahtar Kavram

Business Hours, Holidays, and Case Escalation Rule Precedence
Soru 1746Soru

An organization is configuring Delegated Administration to decentralize user management and custom maintenance tasks while adhering to strict security boundaries. Match each administrative capability or requirement on the left with its correct Delegated Administration configuration rule or system limitation on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Delegating custom field creation, page layout modifications, and picklist management for a custom object named Project__c.
Allowing delegated administrators to assign the 'Sales Operations Manager' permission set to users within their assigned roles.
Permitting delegated administrators to log in as any user within their delegated role hierarchy who has granted administrator login access.
Delegating field-level security updates and page layout administration for standard Account and Contact objects.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Delegating custom object management for Project__c requires adding it under Custom Object Administration in the Delegated Group. Delegating permission set assignment requires explicitly listing the permission set under Assignable Permission Sets. Logging in as users in delegated roles requires enabling 'Enable Login as Any User' on the Delegated Group. Attempting to delegate standard object management is unsupported because Delegated Administration only permits object administration for custom objects.
Each administrative action correctly aligns with Salesforce Delegated Administration capabilities. Managing custom objects requires adding them to Custom Object Administration. Permission set assignment requires designated Assignable Permission Sets. Logging in as users in assigned roles is enabled via 'Enable Login as Any User'. Standard object administration cannot be delegated using Delegated Administration Groups.

Adım Adım Çözüm

1
Evaluate custom object delegation capabilities.
Delegated Administration permits managing custom fields, tab visibility, page layouts, and record types for custom objects specified in the Custom Object Administration section.
This establishes the appropriate configuration path for the Project__c custom object.
2
Evaluate permission set delegation capabilities.
Delegated administrators cannot assign arbitrary permission sets; they can only assign permission sets explicitly designated under Assignable Permission Sets.
This enforces privilege boundaries for permission set assignment.
3
Evaluate user login impersonation privileges.
Delegated group settings include an option 'Enable Login as Any User' allowing delegated admins to log in as users within their delegated roles.
This matches the requirement for logging in as managed users.
4
Evaluate standard object administration limitations.
Delegated Administration does not support administrative modifications (fields, layouts) for standard objects like Account and Contact.
Standard object schema management requires full system administrator privileges or higher-level administrative permissions.

Anahtar Kavram

Delegated Administration Configuration Scope and Limits
Tahmini Süre:3m 0s
Soru 1747Soru

A Salesforce Administrator at Meridian Retail is reviewing organization settings in Setup to prepare for corporate expansion. The executive team wants to understand how updating corporate default settings and fiscal year configurations will affect system behavior. Which TWO statements accurately describe the administrative behavior and impact of settings on the Company Information page? (Select 2 options)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Modifying the Organization Default Time Zone sets the default time zone for newly created users without changing the personal time zone settings of existing users.; Enabling Custom Fiscal Years is an irreversible feature activation that permanently disables standard fiscal year structures and impacts standard forecasting.; Enabling Custom Fiscal Years can be temporarily deactivated or reverted back to Standard Fiscal Year settings if financial reporting requirements change.

Cevap

The correct statements are that modifying the Organization Default Time Zone sets defaults for newly created users without altering existing user time zones, and enabling Custom Fiscal Years is an irreversible change that permanently disables standard fiscal years.
Updating the Organization Default Time Zone defines the initial default for new user provisions while leaving existing user settings intact. Additionally, enabling Custom Fiscal Years is a one-way operation that cannot be reverted.

Adım Adım Çözüm

1
Evaluate the impact of changing the Organization Default Time Zone.
The org-level Default Time Zone acts as a baseline template for new user creation; existing users retain their explicit time zone settings.
Salesforce isolates user-level locale/time zone customizations from org-level administrative defaults.
2
Evaluate the constraints of Custom Fiscal Year activation.
Enabling Custom Fiscal Years cannot be reverted or turned off once enabled.
Custom fiscal year structures rewrite underlying forecasting and reporting calendar definitions.

Anahtar Kavram

Company Information settings establish organization-wide default settings for new users, while enabling Custom Fiscal Years represents a permanent, irreversible change to corporate reporting schedules.
Soru 1748Soru

A Salesforce Administrator is configuring security settings for customer support representatives assigned to a custom profile. The administrator needs to implement IP security controls using both Profile Login IP Ranges and Organization-Wide Network Access settings. Which two statements accurately describe how Salesforce enforces these login IP restrictions? (Select 2 answers)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Users attempting to log in from an IP address outside their defined Profile Login IP Ranges are completely denied access.; Users attempting to log in from an IP address outside the Organization-Wide Network Access ranges are prompted for identity verification rather than being denied access.

Cevap

The correct statements are that Profile Login IP Ranges enforce absolute restriction (hard denial) for logins outside the range, while Organization-Wide Network Access ranges determine whether identity verification is required.
Profile Login IP Ranges enforce a strict security policy where any login request outside the specified range is immediately denied. Conversely, Organization-Wide Network Access defines trusted IP ranges across the organization; logging in from outside these trusted ranges requires users to complete identity verification rather than preventing them from logging in.

Adım Adım Çözüm

1
Analyze the function of Profile Login IP Ranges
Profile-level IP restrictions act as a hard security boundary. Logins outside the specified range are completely denied.
Profile security settings dictate mandatory access rules for all assigned users.
2
Analyze the function of Organization-Wide Network Access (Trusted IP Ranges)
Org-wide trusted IP ranges specify network locations where multi-factor/identity verification is bypassed.
Logins from outside org trusted ranges trigger an activation prompt rather than blocking the user.
3
Compare both mechanisms to select the correct statements
Statements highlighting profile hard denial and org-wide verification prompting are correct.
This accurately distinguishes between access restriction and identity verification controls in Salesforce.

Anahtar Kavram

Profile Login IP Ranges vs. Organization-Wide Network Access IP Ranges
Tahmini Süre:1m 30s
Soru 1749Soru

An administrator at a biotechnology firm is configuring custom fields on a custom object named Clinical_Trial__c. The business requires tracking total trial participant counts by aggregating patient numbers from child records on a custom object named Trial_Site__c. Currently, Trial_Site__c is linked to Clinical_Trial__c using a Lookup relationship. The administrator attempts to create a Roll-Up Summary field on Clinical_Trial__c to calculate total participants, but the Roll-Up Summary data type is unavailable in the field creation wizard. Which administrative action is required to enable the creation of the Roll-Up Summary field?

Cevabı ve açıklamayı göster

Cevap: Convert the existing Lookup relationship field on Trial_Site__c to a Master-Detail relationship after verifying that all Trial_Site__c records have a populated lookup value.

Cevap

Convert the existing Lookup relationship field on Trial_Site__c to a Master-Detail relationship after verifying that all Trial_Site__c records have a populated lookup value.
To create a native Roll-Up Summary field in Salesforce, the parent object must be the master in a Master-Detail relationship. Because Trial_Site__c is currently connected to Clinical_Trial__c via a Lookup relationship, the Roll-Up Summary option is disabled. Converting the lookup field on Trial_Site__c to a Master-Detail relationship enables the Roll-Up Summary field type on Clinical_Trial__c. This conversion requires that all existing Trial_Site__c records have a value in the lookup field prior to conversion.

Adım Adım Çözüm

1
Identify why the Roll-Up Summary data type option is disabled in the wizard.
Roll-Up Summary fields require a Master-Detail relationship between parent and child objects; they cannot be created across Lookup relationships.
Salesforce limits declarative roll-up summary functionality strictly to master objects in Master-Detail relationships.
2
Verify data integrity prerequisites before converting the field data type.
Ensure all existing Trial_Site__c child records contain a non-null reference to a Clinical_Trial__c parent record.
Master-Detail fields are mandatory on detail records; Salesforce blocks data type conversion if any existing record has a blank lookup field.
3
Convert the relationship field data type on the child object.
Change the relationship field data type from Lookup to Master-Detail on Trial_Site__c.
This establishes Clinical_Trial__c as the Master object and Trial_Site__c as the Detail object.
4
Create the Roll-Up Summary field on the parent object.
The Roll-Up Summary field data type becomes active on Clinical_Trial__c to aggregate participant counts from Trial_Site__c records.
Master objects in valid Master-Detail relationships support native Roll-Up Summary field creation.

Anahtar Kavram

Roll-Up Summary Field Eligibility and Relationship Type Conversion
Soru 1750Soru

A Salesforce Administrator needs to manually provision a new sales executive user account in a complex enterprise Salesforce org. The user requires access to standard CRM features, specialized custom object permissions, and specific data access defined by organizational hierarchy. What is the correct sequence of administrative steps to configure and provision this user account following Salesforce best practices?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence for provisioning a new enterprise user is: 1) Select the User License and assign a minimal base Profile, 2) Assign the designated Role within the Role Hierarchy, 3) Assign Permission Sets or Permission Set Groups for specialized access, and 4) Save the user record to trigger activation and send the welcome notification.
The correct sequence follows Salesforce provisioning best practices: first establish base identity and license limits via the User License and base Profile, set up data access hierarchy via the Role, extend specific functional access using Permission Sets, and finally save the record to initiate activation and dispatch access credentials.

Adım Adım Çözüm

1
Define core user credentials and baseline license settings.
User License is bound to the record, which governs available profiles.
User License selection is mandatory upon user record creation and cannot be changed to an incompatible profile type later.
2
Assign the Role location in the organizational hierarchy.
Record-level access rules and hierarchy sharing rollups are established.
Roles control record visibility, which should be configured alongside base identity settings.
3
Grant granular object and field permissions via Permission Sets.
Elevated permissions are granted without broadening base profile permissions.
Modern Salesforce architecture emphasizes least-privilege profiles paired with permission set assignments.
4
Save and dispatch welcome credentials.
The user account transitions to active state and the login URL email is sent.
Account activation and user notification complete the administrative provisioning workflow.

Anahtar Kavram

User Provisioning & Least Privilege Permissioning Workflow
Soru 1751Soru

An administrator is setting up record sharing for two custom objects: Project_Milestone__c and Internal_Audit__c. The business requires that users only see their own Project_Milestone__c records, but managers in the role hierarchy must automatically inherit access to records owned by their subordinates. Conversely, for Internal_Audit__c, baseline access must be restricted so that record access does NOT automatically propagate up the role hierarchy to managers above the record owner.

Which two security configurations should the administrator implement to satisfy these requirements?

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Set the Organization-Wide Default for Project_Milestone__c to Private and ensure 'Grant Access Using Hierarchies' is selected.; Set the Organization-Wide Default for Internal_Audit__c to Private and deselect 'Grant Access Using Hierarchies'.

Cevap

The administrator must set the Organization-Wide Default for Project_Milestone__c to Private with 'Grant Access Using Hierarchies' selected, and set the Organization-Wide Default for Internal_Audit__c to Private while deselecting 'Grant Access Using Hierarchies'.
Organization-Wide Defaults establish baseline record access for non-owners. Setting OWD to Private restricts visibility to record owners. For custom objects, 'Grant Access Using Hierarchies' is enabled by default, propagating access up the role hierarchy. To prevent managers from inheriting access to custom object records, an administrator must deselect 'Grant Access Using Hierarchies'.

Adım Adım Çözüm

1
Determine the baseline Organization-Wide Default (OWD) setting for Project_Milestone__c.
Because users must only view their own records, the baseline access must be set to Private.
OWD sets the most restrictive baseline access for records not owned by a given user.
2
Configure role hierarchy access propagation for Project_Milestone__c.
Keep 'Grant Access Using Hierarchies' enabled.
Enabling hierarchy access allows managers in the role hierarchy to inherit access to records owned by their subordinates.
3
Determine the OWD and role hierarchy settings for Internal_Audit__c.
Set OWD to Private and deselect 'Grant Access Using Hierarchies'.
Deselecting 'Grant Access Using Hierarchies' on custom objects prevents automatic access propagation to managers higher up the role hierarchy.

Anahtar Kavram

Organization-Wide Defaults and Role Hierarchy Access Control for Custom Objects
Soru 1752Soru

A system administrator needs to grant a small group of support representatives access to a newly deployed custom object and the ability to export reports. The administrator must grant these extra privileges without altering the baseline profile shared by all support representatives. Which two actions should the administrator perform to achieve this requirement? (Choose 2)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Create permission sets containing the required custom object permissions and export report system permission.; Bundle the permission sets into a Permission Set Group and assign the group to the specific support representatives.

Cevap

The administrator should create permission sets containing the required custom object and report export permissions, and bundle these permission sets into a Permission Set Group to assign to the targeted support representatives.
Permission sets are designed to grant additive permissions on top of a user's baseline profile without creating duplicate profiles. Grouping related permission sets into a Permission Set Group allows administrators to assign multiple permission sets as a single unit, streamlining user access management.

Adım Adım Çözüm

1
Identify the additive access requirements
Determine that specific users require extra permissions (custom object access and report export) beyond their baseline profile capabilities.
Baseline profiles should maintain minimum necessary access, while extra privileges are added modularly.
2
Create dedicated Permission Sets
Build permission sets that grant the object-level and system-level permissions needed.
Permission sets extend user access without affecting other users on the same profile.
3
Consolidate into a Permission Set Group and assign to users
Combine the permission sets into a single Permission Set Group and assign it to the selected support representatives.
Permission Set Groups organize related permission sets for efficient user assignment and administrative scalability.

Anahtar Kavram

Additive Security Architecture with Permission Sets and Permission Set Groups
Soru 1753Soru

A compliance audit at a healthcare company requires that users with the 'Patient Support Representative' role adhere to a 15-minute inactivity session timeout and a 30-day password expiration policy. The default organization-wide settings are configured for a 2-hour session timeout and a 90-day password expiration. An administrator attempts to enforce these restrictive security limits by creating a new Permission Set to avoid proliferating custom profiles, but discovers that session timeout and password policy configurations are unavailable within the Permission Set interface. How should the administrator properly enforce these specific security requirements for the Patient Support team?

Cevabı ve açıklamayı göster

Cevap: Configure the 15-minute session timeout and 30-day password expiration policies directly within the custom Profile assigned to the Patient Support team.

Cevap

Configure the 15-minute session timeout and 30-day password expiration policies directly within the custom Profile assigned to the Patient Support team.
In Salesforce, Password Policies and Session Settings are established at the Organization-Wide level and can be selectively overridden on individual Profiles. Because Permission Sets and Permission Set Groups cannot store or enforce session inactivity timeouts or password expiration rules, modifying the custom Profile assigned to the user group is the correct and only way to enforce stricter requirements for specific users.

Adım Adım Çözüm

1
Analyze where Session Settings and Password Policies are stored and overridden in Salesforce.
Identify that global defaults exist under Session Settings and Password Policies in Setup, and can only be overridden on individual Profiles.
Salesforce security architecture limits session duration and password expiration controls to Org-Wide defaults and Profile-level settings.
2
Evaluate the feasibility of using Permission Sets or Permission Set Groups for session and password management.
Recognize that Permission Sets and Permission Set Groups cannot manage session timeout values or password complexity/expiration policies.
Permission Sets are designed for additive functional access (fields, objects, permissions), not administrative governance policies like session duration.
3
Determine the proper administrative action to satisfy the compliance requirement.
Edit the custom Profile assigned to the target user group and adjust the Profile's Password Policies and Session Settings sections.
Profile-level configurations override Organization-Wide defaults for all users assigned to that specific profile.

Anahtar Kavram

Profile-Level Overrides for Session Settings and Password Policies
Soru 1754Soru

An administrator is configuring record-level access for a custom object named Project__c. The Organization-Wide Default (OWD) sharing setting for Project__c is set to Private. To restrict access, the administrator deselects the 'Grant Access Using Hierarchies' option for Project__c. User A is assigned to the 'Project Executive' role, which sits directly above User B's role ('Project Coordinator') in the Role Hierarchy. Both users have a profile that grants Read, Create, Edit, and Delete permissions on the Project__c object. User B creates a new Project__c record. Based on this configuration, which statement correctly describes access to User B's record?

Cevabı ve açıklamayı göster

Cevap: Only User B (the record owner) has access to the record, because disabling Grant Access Using Hierarchies stops automatic upward access inheritance through the Role Hierarchy for custom objects.

Cevap

Only the record owner (User B) has access to the record, because deselecting 'Grant Access Using Hierarchies' stops automatic upward access inheritance through the Role Hierarchy for custom objects.
For standard objects, access is always granted through the Role Hierarchy. However, for custom objects, administrators can deselect the 'Grant Access Using Hierarchies' checkbox. Doing so prevents users in higher roles (like User A) from automatically inheriting access to custom object records owned by or shared with users in subordinate roles (like User B). Since OWD is Private and no sharing rules are active, only the record owner has access.

Adım Adım Çözüm

1
Evaluate Organization-Wide Defaults (OWD)
OWD for Project__c is Private, meaning users do not get automatic access to records owned by others unless shared.
OWD sets the baseline level of access for all records of an object across the organization.
2
Check the status of Grant Access Using Hierarchies
The setting is deselected (disabled) for the Project__c custom object.
For custom objects, administrators can uncheck 'Grant Access Using Hierarchies', which revokes implicit record access propagation up the Role Hierarchy.
3
Differentiate Profile Object Permissions (CRUD) from Record-Level Sharing
User A's profile Edit permission allows editing records User A can access, but does not grant visibility to unshared Private records owned by User B.
Profile object permissions specify what operations users can perform, while sharing rules/hierarchy determine which specific records users can see.

Anahtar Kavram

Grant Access Using Hierarchies behavior on Custom Objects
Soru 1755Soru

Match each Salesforce security and access control requirement on the left with the correct Permission Set feature or architecture component on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Grant elevated 'Modify All' access on Account records to a third-party auditor, ensuring access is automatically revoked after 30 days without manual intervention.
Combine individual permission sets for 'Create Custom Reports', 'Export Reports', and 'Manage Dashboards' into a single reusable container to streamline user provisioning for sales directors.
Explicitly remove the 'Delete' permission on Contracts for contractor users who are assigned a broader administrative bundle that grants Contract deletion capabilities.
Require users to establish an active, authenticated session (such as via a Flow or web callout) before administrative permissions are temporarily enabled.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

1. Granting temporary access with auto-revocation matches Permission Set Assignment Expiration. 2. Combining multiple permission sets into a reusable container matches Permission Set Group. 3. Explicitly suppressing permissions within a group matches Muting Permission Set. 4. Activating permissions dynamically based on an authenticated user session matches Session-Based Permission Set.
Each access control requirement directly corresponds to a specific native feature of Salesforce permission architecture: temporary time-bound assignments utilize Expiration Dates; permission bundling uses Permission Set Groups; permission suppression within groups uses Muting Permission Sets; and condition/session-triggered access relies on Session-Based Permission Sets.

Adım Adım Çözüm

1
Analyze requirement 1 regarding temporary 30-day auditor access.
Identify that automatic revocation upon date threshold is handled natively by setting an Expiration Date on the Permission Set Assignment.
Eliminates the need for manual admin tracking or scheduled Apex scripts.
2
Analyze requirement 2 regarding bundling report and dashboard permissions into a single unit.
Match this to a Permission Set Group (PSG).
PSGs consolidate discrete permission sets into logical role-based groups for simplified assignment management.
3
Analyze requirement 3 regarding turning off Contract deletion for contractors in a broad group.
Match this to a Muting Permission Set within the Permission Set Group.
Muting permission sets allow admins to override and suppress specific permissions included in a PSG without altering the underlying standalone permission sets.
4
Analyze requirement 4 regarding enabling permissions only during an active session context.
Match this to a Session-Based Permission Set.
Session-based permission sets require explicit session activation via Flow or API and deactivate when the session ends.

Anahtar Kavram

Salesforce Permission Set Architecture and Advanced Access Control
Soru 1756Soru

An administrator needs to grant three users in the Sales department the ability to export reports. These users share the same base profile as twenty other sales representatives who do not require export capabilities. Which Salesforce security feature should the administrator use to grant this additional capability?

Cevabı ve açıklamayı göster

Cevap: Create a permission set that enables report exporting and assign it to the three users.

Cevap

The administrator should create a permission set with the required export permission and assign it to the three specific users.
Permission sets are used to grant additional permissions to specific users on an ad-hoc basis without changing their underlying profile assignments or affecting other users.

Adım Adım Çözüm

1
Analyze the access requirement
Identify that only 3 out of 23 users sharing a profile require an extra privilege.
Profiles determine base permissions for groups of users, whereas selective additive privileges require permission sets.
2
Select the appropriate Salesforce access mechanism
Choose Permission Sets for additive administrative access.
Permission sets extend user functionality without requiring profile proliferation or over-granting access.

Anahtar Kavram

Using Permission Sets for Additive Access Management
Soru 1757Soru

Match each complex administrative access requirement to the appropriate Salesforce security configuration mechanism.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Grant a temporary 30-day window for a financial analyst to execute mass data export and delete invoice records during a fiscal audit without altering their base profile.
Suppress the 'Delete' permission on standard Account records for a specific subset of service agents who are assigned to a comprehensive Tier 2 Support permissions bundle.
Combine disparate permission sets for API integration access, custom report creation, and object management into a single assignable package for expedited user onboarding.
Provide Read and Edit access to sensitive executive compensation custom fields exclusively for three HR managers whose baseline profile restricts field visibility.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Matching pairs: 1 matches with assigning a standalone Permission Set configured with an Expiration Date; 2 matches with including a Muting Permission Set within the assigned Permission Set Group; 3 matches with creating and assigning a Permission Set Group bundling the individual permission sets; 4 matches with assigning a dedicated standalone Permission Set with Field-Level Security enabled.
Each administrative scenario aligns precisely with Salesforce security capabilities: temporary access utilizes Permission Set Expiration; selective permission suppression within bundled access utilizes Muting Permission Sets; permission consolidation utilizes Permission Set Groups; and targeted field visibility utilizes standalone Permission Sets with Field-Level Security.

Adım Adım Çözüm

1
Evaluate the requirement for temporary elevated permissions (mass export and deletion) during an audit window.
Match with a standalone Permission Set configured with an Expiration Date.
Salesforce allows setting expiration dates on direct permission set assignments, ensuring automatic permission revocation without manual administrative intervention.
2
Evaluate the requirement to selectively disable Account delete capabilities within a bundled set of permissions.
Match with adding a Muting Permission Set inside the Permission Set Group.
Permission sets are strictly additive. The only supported mechanism to suppress or mute permissions within a Permission Set Group is by configuring a Muting Permission Set.
3
Evaluate the requirement to consolidate multiple discrete permission sets into one assignment container for user onboarding.
Match with creating a Permission Set Group.
Permission Set Groups organize related permission sets into a unified bundle, simplifying user provisioning while maintaining component modularity.
4
Evaluate the requirement to grant sensitive field-level visibility exclusively to a select group of HR managers.
Match with assigning a dedicated standalone Permission Set with Field-Level Security.
Profiles set baseline field security; granting selective field access to specific users requires additive Field-Level Security configured in a dedicated Permission Set.

Anahtar Kavram

Configuring Permission Sets, Permission Set Groups, Expiration Dates, and Muting Permission Sets to fulfill complex, additive, and selective access requirements.
Soru 1758Soru

A logistics company uses a standard profile to grant baseline read-only access to all Customer Service Representatives. During a quarterly system audit, five specific representatives need temporary administrative access to create and modify Vehicle Maintenance Log records. The administrator wants to grant these extended permissions without altering the access rights of the remaining representatives assigned to the standard profile. Which configuration approach should the administrator implement to grant these additional permissions?

Cevabı ve açıklamayı göster

Cevap: Create a Permission Set with Create and Edit access on Vehicle Maintenance Logs and assign it to the five selected representatives.

Cevap

The administrator should create a Permission Set with Create and Edit permissions on Vehicle Maintenance Logs and assign it to the five representatives who require the additional access.
Creating a dedicated Permission Set and assigning it specifically to the five representatives allows the administrator to additively grant Create and Edit access on Vehicle Maintenance Logs without modifying the shared base profile or affecting other users.

Adım Adım Çözüm

1
Identify the base security model and administrative requirement.
All representatives share a base profile, but only a subset requires extra capabilities (Create and Edit access on Vehicle Maintenance Logs).
Profiles define baseline access, whereas targeted additions should be managed independently.
2
Select the appropriate Salesforce access mechanism for additive permissions.
A Permission Set is chosen to grant the additional object permissions.
Permission Sets extend user permissions additively without altering the underlying profile assigned to other users.
3
Assign the Permission Set to the affected users.
Only the five specific representatives receive the required Create and Edit access on Vehicle Maintenance Logs.
This maintains least privilege access for all other representatives on the base profile.

Anahtar Kavram

Profiles provide foundational access, while Permission Sets are used to grant additive object, field, and system permissions to individual users or subsets of users.
Soru 1759Soru

An administrator at a real estate agency wants to create a field on the custom Property object to automatically count the total number of related inspection records. However, the Property object and Inspection object are linked using a lookup relationship. Which statement explains why the administrator cannot create a Roll-Up Summary field to meet this requirement?

Cevabı ve açıklamayı göster

Cevap: Roll-up summary fields can only be created on the parent object of a master-detail relationship, not a lookup relationship.

Cevap

Roll-up summary fields can only be created on the parent object of a master-detail relationship, not a lookup relationship.
Roll-up summary fields are a native feature restricted exclusively to the master side of a master-detail relationship. Because the Property and Inspection objects are connected via a lookup relationship, declarative roll-up summary functionality is unavailable.

Adım Adım Çözüm

1
Identify the relationship type between the parent (Property) and child (Inspection) objects.
The objects are connected via a lookup relationship.
Salesforce feature availability for aggregate fields depends strictly on the underlying relationship architecture.
2
Evaluate the capabilities and constraints of Roll-Up Summary fields.
Roll-Up Summary fields are exclusively supported on the master object in master-detail relationships.
Lookup relationships do not enforce the strict parent-child data dependency required for declarative roll-up calculations.

Anahtar Kavram

Roll-Up Summary Field Capabilities and Limitations
Soru 1760Soru

A company requires all standard Salesforce users to change their passwords every 60 days by default. Which location in Setup allows a system administrator to set this organization-wide password expiration period?

Cevabı ve açıklamayı göster

Cevap: Password Policies

Cevap

Password Policies in Setup allows administrators to set the organization-wide password expiration period.
The Password Policies node in Setup provides the centralized interface to define organization-wide password limits, including password duration, complexity requirements, minimum length, and lockout thresholds.

Adım Adım Çözüm

1
Navigate to Setup in Salesforce and search for Password Policies.
Access the organization-wide password security configuration page.
Global password lifecycle policies such as expiration frequency are managed under Password Policies.
2
Locate the User Password Expiration picklist field.
Select 60 days to enforce the requirement.
This updates the default baseline expiration period across all users who do not have profile-level password policy overrides.

Anahtar Kavram

Organization-Wide Password Policies Configuration
ÖncekiSayfa 88 / 90Sonraki
Tüm alıştırma soruları — Salesforce Certified Administrator | Examkin