CSA Security & Access Management 3 — Questions and Answers
Question 1: Which Salesforce feature allows an admin to group multiple Permission Sets together and assign them all to a user at once?
- Profile Groups
- Permission Set Groups (Correct answer)
- Role Bundles
- Access Packages
Correct answer: Permission Set Groups
Permission Set Groups let admins bundle multiple permission sets and assign the group as a single unit to users.
Question 2: When Salesforce OWD for Accounts is set to 'Private,' which users can still see all Account records?
- All users with the Standard User profile
- Only the System Administrator profile
- Users higher in the role hierarchy than the record owner (Correct answer)
- Users with a Permission Set granting Read on Account
Correct answer: Users higher in the role hierarchy than the record owner
With Private OWD, the role hierarchy grants access upward, so managers and executives above the owner in the hierarchy can view those records.
Question 3: What does the 'Modify All Data' system permission allow a user to do?
- Read all records regardless of sharing settings
- Read, edit, delete, transfer, and mass delete all records regardless of sharing (Correct answer)
- Only bypass field-level security
- Delete records owned by other users only within their role
Correct answer: Read, edit, delete, transfer, and mass delete all records regardless of sharing
'Modify All Data' is a powerful system permission that bypasses all sharing rules and record-level security, granting full CRUD access to all records.
Question 4: An admin sets up a Salesforce community. Which permission is required on a user's profile to allow them to log in to the Experience Cloud site?
- API Enabled
- Enable as Community User
- Access Experience Cloud Sites (Correct answer)
- External User Access
Correct answer: Access Experience Cloud Sites
The 'Access Experience Cloud Sites' permission (formerly 'Access Sites') must be enabled on a user's profile to allow login to Experience Cloud portals.
Question 5: Which of the following is a feature of Salesforce Shield's Platform Encryption?
- Encrypts data at the field level while keeping it searchable via deterministic encryption (Correct answer)
- Replaces field-level security for sensitive data
- Automatically encrypts all standard fields
- Encrypts only files and attachments
Correct answer: Encrypts data at the field level while keeping it searchable via deterministic encryption
Shield Platform Encryption can encrypt field data at rest; deterministic encryption allows exact-match searching on encrypted fields.
Question 6: A user reports they cannot see the 'Salary' field on the Employee record page, even though it is on the page layout. What is the most likely cause?
- The field is not on the search layout
- Field-Level Security for the user's profile restricts visibility of that field (Correct answer)
- The record's OWD is set to Private
- The user's role is too low in the hierarchy
Correct answer: Field-Level Security for the user's profile restricts visibility of that field
Field-Level Security overrides page layout visibility; if FLS hides a field from a profile, it won't appear even if it's on the layout.
Question 7: What is the purpose of a 'Muting Permission Set' in Salesforce?
- Temporarily deactivates a user's entire permission set group
- Removes specific permissions from a Permission Set Group without editing individual permission sets (Correct answer)
- Mutes email notifications for users in the group
- Prevents permission sets from being assigned to new users
Correct answer: Removes specific permissions from a Permission Set Group without editing individual permission sets
A Muting Permission Set is assigned within a Permission Set Group to suppress specific permissions that other sets in the group would otherwise grant.
Which Salesforce feature allows an admin to group multiple Permission Sets together and assign them all to a user at once?