← All SAA Flashcard Decks

Security & Access Management Flashcards

7 cards from real SAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Access Management flashcards as text
  1. Which type of Salesforce license gives external community users the least access and is typically used for unauthenticated guest access?

    Answer: Guest User license

    The Guest User license is automatically created with each community site and allows unauthenticated public access with highly restricted permissions.

  2. An architect needs to ensure that the 'Social Security Number' field is never stored in plaintext in Salesforce. Which feature should be used?

    Answer: Salesforce Shield Platform Encryption

    Salesforce Shield Platform Encryption encrypts data at rest using tenant-specific keys, providing the strongest protection for sensitive fields like SSNs.

  3. A user has 'Read' access to Account through OWD, but a manual share grants them 'Edit' on a specific account record. What is the user's effective access to that record?

    Answer: Edit, because manual shares can grant higher access than OWD on specific records

    Manual sharing and sharing rules can open up access beyond the OWD baseline, so the user gains Edit on that specific record through the manual share.

  4. What is the maximum number of permission set groups a single user can be assigned in Salesforce?

    Answer: No hard limit; users can belong to many permission set groups

    Salesforce does not impose a hard cap on the number of permission set groups assigned to a single user, though performance considerations apply.

  5. Which Salesforce feature lets administrators see a consolidated view of all permissions a specific user has, including those from profile and permission sets?

    Answer: User Access Summary on the user detail page

    The User Access Summary (available from the user detail page) shows an aggregated view of all object and system permissions a user holds across their profile and permission sets.

  6. An org stores health data and must comply with HIPAA. Which Salesforce add-on is specifically designed to help with encryption and audit requirements?

    Answer: Salesforce Shield

    Salesforce Shield includes Platform Encryption, Event Monitoring, and Field Audit Trail — the three pillars typically needed for HIPAA and other compliance frameworks.

  7. What happens to a child record's sharing access when the Account (parent) OWD is set to 'Controlled by Parent' for Contact?

    Answer: Contact access mirrors the user's access to the parent Account record

    When Contact OWD is 'Controlled by Parent,' a user's access to a Contact record is determined by their access to the associated Account.