Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Salesforce B2B Commerce for Developers Accredited Professional (AP-202) Exam - Topic 4 Question 94 Discussion

Although Salesforce B2B Commerce and Salesforce recommend against using"without sharing classes" whenever possible, sometimes it is unavoidable. Which threeitems will open up a major security hole? (3 answers)
A) Executing dynamic SOQL inside a without sharing class with a bind variable fromPageReference.getParameters(). and C) Executing dynamic SOQL inside a without sharing class with a bind variable fromPageReference.getCookies(). and D) Executing dynamic SOQL inside a without sharing class with a bind variable fromcc_RemoteActionContentex class.
B) Executing dynamic SOQL inside a without sharing class with a bind variable from theUserInfo class.
E) Executing dynamic SOQL inside a without sharing class with a bind variable fromccAPI.CURRENT_VERSION.

Salesforce B2B Commerce for Developers Accredited Professional (AP-202) Exam - Topic 4 Question 94 Discussion

Actual exam question for Salesforce's B2B Commerce for Developers Accredited Professional (AP-202) exam
Question #: 94
Topic #: 4
[All B2B Commerce for Developers Accredited Professional (AP-202) Questions]

Although Salesforce B2B Commerce and Salesforce recommend against using

"without sharing classes" whenever possible, sometimes it is unavoidable. Which three

items will open up a major security hole? (3 answers)

Show Suggested Answer Hide Answer
Suggested Answer: A, C, D

Executing dynamic SOQL inside a without sharing class with a bind variable from PageReference.getParameters(), PageReference.getCookies(), or cc_RemoteActionContext class will open up a major security hole because these sources of input are not sanitized and can be manipulated by malicious users to inject SOQL queries that bypass the sharing rules and access data that they are not supposed to see. For example, a user can modify the URL parameters or cookies to include a SOQL query that returns sensitive data from the database. To prevent this, it is recommended to use static SOQL or escape the bind variables before executing dynamic SOQL.


Contribute your Thoughts:

0/2000 characters
Kristal
4 days ago
A) is definitely a big no-no!
upvoted 0 times
...
Leonardo
9 days ago
I recall that using PageReference parameters can expose data, so I’d lean towards A and C being correct, but I need to double-check my notes on that.
upvoted 0 times
...
Arlene
14 days ago
I’m a bit confused about the implications of using UserInfo as a bind variable. Is it really that risky in a "without sharing" context?
upvoted 0 times
...
Harrison
19 days ago
I think options A and C sound familiar, but I'm not entirely sure about D. I feel like we practiced a similar question before.
upvoted 0 times
...
Ronna
24 days ago
I remember discussing how using dynamic SOQL in "without sharing" classes can lead to security risks, especially with user input.
upvoted 0 times
...

Save Cancel