Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Salesforce Plat-Arch-204 Exam - Topic 4 Question 16 Discussion

Northern Trail Outfitters (NTO) has a requirement to encrypt a few widely-used standard fields. NTO also wants to be able to use these fields in record-triggered flows.Which security solution should an integration architect recommend to fulfill the business use case?
A) Shield Platform Encryption
B) Classic Encryption
C) Data Masking

Salesforce Plat-Arch-204 Exam - Topic 4 Question 16 Discussion

Actual exam question for Salesforce's Plat-Arch-204 exam
Question #: 16
Topic #: 4
[All Plat-Arch-204 Questions]

Northern Trail Outfitters (NTO) has a requirement to encrypt a few widely-used standard fields. NTO also wants to be able to use these fields in record-triggered flows.

Which security solution should an integration architect recommend to fulfill the business use case?

Show Suggested Answer Hide Answer
Suggested Answer: A

To satisfy the requirement of encrypting standard fields while maintaining their functionality within record-triggered flows, Shield Platform Encryption is the recommended architectural solution.1

Shield Platform Encryption is a modern security layer that allows for encryption at rest while 2preserving critical platform features. Unlike Classic Encryption (Option B)---which is limited to a specific 'Encrypted Text' custom field type and often breaks platform features like search and automation---Shield is designed to work with standard fields such as Name, Email, and Phone.

Key architectural considerations for Shield include:

Compatibility with Automation: Shield fields can be used in Flows, Apex triggers, and validation rules. This allows NTO to implement the required record-triggered business logic without needing to decrypt the data manually in code.

Search and Filtering: By using Deterministic Encryption, Shield allows users to filter and search for records based on encrypted fields, which is often a requirement for 'widely-used' standard fields.

Compliance and Governance: Shield provides advanced key management (Bring Your Own Key - BYOK) and auditing, ensuring that NTO meets corporate security guidelines while data is being processed by the platform.

Data Masking (Option C) is primarily used for sandboxes to obfuscate PII during testing and is not a production encryption-at-rest solution. By recommending Shield, the architect provides a transparent security model that protects sensitive data without sacrificing the declarative power of Flow Builder.


Contribute your Thoughts:

0/2000 characters
Justine
3 days ago
A) Shield Platform Encryption is the best choice for this.
upvoted 0 times
...
Alaine
8 days ago
I practiced a similar question where Shield Platform Encryption was the recommended solution, but I’m still a bit confused about its compatibility with flows.
upvoted 0 times
...
Floyd
13 days ago
Data Masking seems like a good choice for protecting data, but I don't think it actually encrypts the fields, so it might not meet NTO's requirements.
upvoted 0 times
...
Vivienne
18 days ago
I think Classic Encryption might be easier to implement, but I recall it has limitations on which fields can be encrypted.
upvoted 0 times
...
Andra
23 days ago
I remember studying that Shield Platform Encryption is the most robust option for encrypting standard fields, but I'm not entirely sure if it allows for use in record-triggered flows.
upvoted 0 times
...

Save Cancel