Security and Access Flashcards

• Explain the various organization security controls (e.g., passwords, IP restrictions, identity confirmation, network settings). • Given a user request scenario, apply the appropriate security controls based on the features and capabilities of the Salesforce sharing model (e.g., organization-wide defaults, roles and the role hierarchy, manual sharing, sharing rules and public groups). • Given a scenario, determine the appropriate use of a custom profile or permission set using the various pro

1
Q

What checks are done when users try to access a Salesforce Organization?

A

Profile Level Login Hours, Profile Level IP Ranges, Company Level Trusted IP Ranges, Activation Code Validation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the Standard Profiles?

A

Standard User, Solution Manager, Marketing User, Contract Manager, Read Only, System Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How and why are Custom Profiles created?

A

There are restrictions on what can be changed on a standard profile. Custom profiles are created by cloning a standard profile.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How is Object Access controlled?

A

Object access is controlled at the profile level including permissions and visibility to the tab.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are Permission Sets?

A

A group of permissions and settings that can be assigned to one or more users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What do Organization Wide Default Settings do?

A

Determine access to records the user does not own.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How is the Role Hierarchy related to record access?

A

Users will have access to other users records if they have a role above the record owner in the role hierarchy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does Field Level Security control?

A

Controls if a field is visible or read only at the profile level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How do Sharing Rules work?

A

Rules can be created to grant access to groups of users for certain records based on record owner or criteria.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Manual Sharing?

A

Manual Sharing allows a user to use the ‘Sharing’ button to grant access to a specific record to other users, roles or public groups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What should be considered when changing OWD settings?

A

If increasing default access, changes will take effect immediately. If decreasing, changes may take significant time depending on data volumes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How does the Security Health Check work?

A

Security Health Check measures setting values in Password Policies, Network Access Config and Session Settings against baseline values and calculates a percentage score to indicate risk. 100% means all settings meet or exceed the standard.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are some considerations regarding Platform Encryption?

A

Only works on certain standard objects. Some apps and functionality will not work with encrypted fields. Extra cost as it is an add on subscription.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When is identity verification invoked?

A

When a user logs in from an unrecognized (based on cookies) browser or device and outside the trusted IP range.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are Folders used for?

A

To store and organize reports, documents, dashboards and email templates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How can Folder access be controlled?

A

Folders can be private or shared. Permissions and visibility can be set for users, roles and public groups.

17
Q

What are the different access levels that can be granted to a folder?

A

Viewer, Editor (edit, move, save, and delete) or Manager (share and rename folder)