← All SAA Flashcard Decks

Security & Access Management Flashcards

7 cards from real SAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Access Management flashcards as text
  1. A company wants to ensure that users can only access Salesforce from their corporate network. Which feature should an architect configure?

    Answer: Login IP Ranges on profiles

    Login IP Ranges set on a profile restrict users with that profile to logging in only from specified IP addresses.

  2. Which Salesforce feature allows an administrator to automatically log out inactive users after a specified period?

    Answer: Session Timeout policy in Security Settings

    Session Timeout settings in Security Settings define how long an inactive session persists before automatic logout.

  3. A Salesforce org uses Territory Management. How does territory assignment affect record access?

    Answer: Territories grant access to accounts and related records beyond role hierarchy

    Enterprise Territory Management extends account and related record access to users assigned to matching territories, independent of the role hierarchy.

  4. What is the purpose of the 'Grant Login Access' feature in Salesforce?

    Answer: Allows users to delegate login access to administrators or partners for support

    Grant Login Access lets users authorize administrators or Salesforce Support to log in as them for troubleshooting purposes.

  5. Which object-level security mechanism prevents a user from even knowing a particular object exists in Salesforce?

    Answer: Setting Tab visibility to 'Tab Hidden' and removing object permissions

    Removing object permissions (Read, Create, etc.) from a profile and hiding the tab prevents users from seeing or interacting with that object entirely.

  6. An architect needs to allow a specific set of users to bypass sharing rules and see all records of a particular object. What is the most appropriate approach?

    Answer: Create a permission set with 'View All' for that object and assign it to those users

    'View All' object permission on a permission set grants unrestricted read access to all records of that object regardless of sharing settings.

  7. When should an architect use Restriction Rules in Salesforce?

    Answer: To further limit record access for specific users beyond what sharing rules and OWD grant

    Restriction Rules narrow record visibility for specified users or groups, ensuring they see only a subset of records they would otherwise have access to.