HCT Security & Access Management 2 — Questions and Answers
Question 1: A HubSpot admin wants to prevent a sales rep from deleting contact records. Which permission setting should they adjust?
- Remove the rep from all teams
- Disable the rep's 'Delete' object permission for Contacts (Correct answer)
- Set the rep's role to 'View Only'
- Revoke the rep's CRM access entirely
Correct answer: Disable the rep's 'Delete' object permission for Contacts
HubSpot's granular object permissions allow admins to disable Delete access on specific CRM objects like Contacts without removing broader access.
Question 2: What is the purpose of 'Property-level permissions' in HubSpot?
- To restrict which users can create new properties
- To hide or make specific contact properties read-only for certain users (Correct answer)
- To prevent properties from being exported in reports
- To lock properties from being edited by workflows
Correct answer: To hide or make specific contact properties read-only for certain users
Property-level permissions let admins control which users can view or edit specific contact, company, or deal properties.
Question 3: In HubSpot, which user role automatically has access to all settings and cannot have permissions restricted?
- Sales Manager
- Super Admin
- Account Owner (Correct answer)
- Primary Admin
Correct answer: Account Owner
The Account Owner in HubSpot has unrestricted access to all portal settings and permissions by default.
Question 4: A trainer is setting up access so that each regional sales team can only see their own deals. Which HubSpot feature enables this?
- Contact Lists
- Teams with object permissions scoped to 'Team only' (Correct answer)
- Workflows with deal assignment actions
- Custom reports filtered by owner
Correct answer: Teams with object permissions scoped to 'Team only'
Setting object permissions to 'Team only' ensures users can only view and edit records owned by members of their assigned team.
Question 5: What happens when a HubSpot user is removed from a team that had 'Team only' deal access?
- They immediately lose access to all deals in the portal
- They retain access only to deals they personally own
- They lose access to deals owned by former teammates but keep their own (Correct answer)
- They are downgraded to a view-only user automatically
Correct answer: They lose access to deals owned by former teammates but keep their own
When removed from a team, a user's access scoping reverts to their own records; they lose visibility into deals owned by team members.
Question 6: Which HubSpot feature allows an admin to require that all users log in through an identity provider like Okta or Google Workspace?
- Two-factor authentication enforcement
- Single Sign-On (SSO) (Correct answer)
- Domain-based user provisioning
- SCIM directory sync
Correct answer: Single Sign-On (SSO)
SSO integration in HubSpot forces users to authenticate through a configured identity provider instead of a HubSpot username/password.
Question 7: A HubSpot trainer notices a client's portal has users with 'Super Admin' permissions who only need to run reports. What is the best remediation?
- Create a custom permission set with only reporting access and reassign those users (Correct answer)
- Remove the users and recreate them with standard roles
- Enable read-only mode for the entire portal
- Ask HubSpot support to downgrade the permissions automatically
Correct answer: Create a custom permission set with only reporting access and reassign those users
Creating a least-privilege custom permission set ensures users have only the access they need, reducing security risk.
A HubSpot admin wants to prevent a sales rep from deleting contact records.
Which permission setting should they adjust?