CSA Organization Setup & User Management 2 — Questions and Answers
Question 1: A Salesforce admin needs to prevent users from logging in outside of business hours. Which feature should they configure?
- Login IP Ranges
- Login Hours (Correct answer)
- Session Settings
- Password Policies
Correct answer: Login Hours
Login Hours, set on profiles, restrict when users can log into Salesforce.
Question 2: Which statement is TRUE about Salesforce usernames?
- Usernames must match the user's email address
- Usernames must be unique across all Salesforce orgs globally (Correct answer)
- Usernames can be reused after a user is deactivated
- Usernames are case-sensitive
Correct answer: Usernames must be unique across all Salesforce orgs globally
Salesforce usernames must be globally unique across every Salesforce org, not just within one org.
Question 3: What happens to records owned by a user when their account is deactivated?
- Records are deleted automatically
- Records are reassigned to the admin
- Records remain owned by the deactivated user (Correct answer)
- Records are moved to a recycle bin
Correct answer: Records remain owned by the deactivated user
Deactivating a user does not change record ownership; the records remain assigned to the deactivated user.
Question 4: An org has users who should see all records but never modify them. Which profile permission best meets this need?
- Read All
- View All Data (Correct answer)
- Modify All Data
- Read Only license
Correct answer: View All Data
'View All Data' is a profile-level permission that grants read access to all records regardless of sharing rules.
Question 5: A user receives the error 'You do not have permission to log in' despite having the correct credentials. What should the admin check first?
- The user's role
- Login Hours and Login IP Ranges on the profile (Correct answer)
- The user's sharing settings
- The org's My Domain configuration
Correct answer: Login Hours and Login IP Ranges on the profile
Login Hour and IP Range restrictions on a profile are the most common cause of this login error.
Question 6: Which User Management setting allows an admin to grant one user the ability to log in as another user for troubleshooting?
- Login As User in Setup
- Delegated Administrator
- Grant Login Access (Correct answer)
- User Impersonation
Correct answer: Grant Login Access
'Grant Login Access' allows a user to authorize Salesforce support or their admin to log in as them.
Question 7: A company wants to enforce that all users in a specific profile must use two-factor authentication. Where is this configured?
- Session Settings in the org
- The profile's Login IP Ranges
- Two-Factor Authentication in Company Information
- Session Security Level in the profile (Correct answer)
Correct answer: Session Security Level in the profile
The 'Session Security Level Required at Login' setting on a profile enforces MFA (high-assurance) for that profile.
A Salesforce admin needs to prevent users from logging in outside of business hours.
Which feature should they configure?