(Security and Access 13%) Review Flashcards
What checks are done when users try to access a salesforce organization?
Profile level login hours, Profile Level IP ranges, Company Level Trusted IP Ranges, Activation Code Validation
What are examples of standard profiles?
Standard user, Solution Manager, Marketing user, Contract Manger, Read Only, System Administrator
Why and how are custom profiles created?
There’s restrictions on what can be changed in a standard profile. Custom Profiles are created by cloning a standard profile to be able to customize profile settings.
How is object access controlled?
Object access is controlled at the profile-level, including permission sets and visibility to the tab
What are permission sets?
A group of permissions and settings that can be assigned to one or more users that grant additional privileges beyond the profile
What do profile permissions grant?
Permissions to app-specific actions customized actions built, or system- wide actions
How is the role hierarchy related to record access?
Users will have access to other users’ records if they have a role above the record owner in the role hierarchy and grant access through hierarchies is enabled
What do organization-wide defaults settings do?
Determine access to records the user does not own and sets base record access for the org
How do sharing rules work?
Rules can be created to grant access to groups of users for certain records based on record owner criteria
What does field-level security control?
Controls if a field is visible or read only at the profile level
What should be considered when changing OWD settings?
If increasing default access, changes will take effect immediately if decreasing, changes may take significant time depending on data volumes.
What is Manual Sharing?
Manual sharing allows a user to use ‘Sharing’ button to grant access to a specific record to other users, roles, roles & subordinates, territories, territories & subordinates, and public groups
How does the security health check work?
measures setting values in password policies, Network Access config and session settings against baseline values and calculates a percentage score to indicate risk. 100% means all settings meet or exceed the standard
what is the purpose of a public group?
It’s a way of grouping users, roles, and territories so that sharing settings and permissions can be granted efficiently
When is identity verification invoked?
when a user logs in from an unrecognized (based on cookies) browser or device, and outside the trusted IP range
what can be enabled that helps the administrator spot suspicious login activity
login forensics
How can folder access be controlled
Folder can be private or shared. Permissions and visibility can be set for users, roles, territories, or public groups
What are folders used for?
To store and organize reports documents, dashboards and email templates
What are two methods to find a folder quickly in the salesforce org?
folders can be favorited or searched for in global search