(Security and Access 13%) Explain various organization security controls Flashcards

Describe how to use various password policies to implement restrictions related to password requirements Identify the ways of controlling where and when users can log in to Salesforce Identify different ways of confirming the identity of users through a second form of authentication Explain the usage of login forensics and security health check

1
Q

Four levels of security in order

A

Organization security controls > Objects>Object Record>Fields on a Record

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are some examples for every security level

A

Organization Security Controls: Login Hours, IP restrictions, Password Policies
Objects: Profiles, Permission sets
Object record: Org-wide defaults, Role Hierarchy, Sharing rules, Teams
Fields on a record: Field Level Security, Page Layouts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What can an administrator configure to ensure that users passwords are strong and secure

A

Password policies, Password Expiration, Password resets, Login attempts and lockout periods

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Where can password policies be set at?

A

the profile and organization level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the default password requirements

A

at least 8 characters including one alpha one num, security question cant contain users password, if user changes their password they cannot reuse last three passwords

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Password expiration defaults

A

expire for all users, except for those who have passwords never expires permission, default is 90 days but can be changed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

when happens to access if your inside or outside a trusted IP range

A

if outside: most be verified/challenged

if inside: allowed to login without verification

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what all must be true to login with no verification

A

must be within login time, users IP is within range defined in profile, users IP must be within range defined by org

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

where can login hours be set at org, profile or both?

A

profile level only

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what are the methods of verification in order of highest priority to least

A

Salesforce Authenticator App>U2F Security Key>One-Time Password Generator>SMS Text Message>Email

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what are the ranges for high risk, medium risk, and low risk in health check categories

A

High:0-33%
Medium:34%-66%
Low:67%-100%

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

My domain capabilities

A
  1. Adding a subdomain
  2. Highlighting company brand for better security
  3. better management of login and authentication
  4. Replaces default URL
  5. Required for SSO
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Single Sign On (SSO)

A

removes the need to login in to every single application every time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is federated Authentication?

A

affiliated but unrelated web services to share authentication data. this is a default.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

what is delegated authentication

A

allows usage of preferred authentication provider, stronger user authentication that is private and only accessible behind a corporate fire wall.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly