Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Salesforce Plat-Arch-205 Exam - Topic 4 Question 2 Discussion

Universal Containers (UC) has a custom object to track the internal net promoter score (NPS) for all of its employees. The manager is in the role above the owner and there are no sharing rules on the object. How should UC ensure that NPS records cannot be accessed by the owner's manager?
B) Set organization-wide default to Private and uncheck the Access Using Hierarchies option for the NPS object.
A) Use Apex sharing to remove NPS object share records for Manager profiles.
C) Remove Create, Read, Edit, and Delete from Manager profiles and permission sets.

Salesforce Plat-Arch-205 Exam - Topic 4 Question 2 Discussion

Actual exam question for Salesforce's Plat-Arch-205 exam
Question #: 2
Topic #: 4
[All Plat-Arch-205 Questions]

Universal Containers (UC) has a custom object to track the internal net promoter score (NPS) for all of its employees. The manager is in the role above the owner and there are no sharing rules on the object. How should UC ensure that NPS records cannot be accessed by the owner's manager?

Show Suggested Answer Hide Answer
Suggested Answer: B

Comprehensive and Detailed 150 to 250 words of Explanation From Platform Sharing and Visibility Architect/Course Guide/topics:

For custom objects, Salesforce allows the administrator to disable automatic upward access through the role hierarchy by clearing Grant Access Using Hierarchies. With the NPS object's OWD set to Private and hierarchy access disabled, a manager does not gain access simply because the manager occupies a role above the record owner. This is the correct pattern for sensitive employee information when the reporting hierarchy itself must not imply visibility. Apex sharing should not be used to subtract access that is granted by another mechanism; Salesforce sharing is fundamentally additive. Removing all object permissions from managers would be too broad because it would block every NPS record, including records a manager might legitimately need through another explicit authorization process. The secure design establishes a restrictive baseline and then opens only the records that a specific business requirement justifies. Study Guide reference: Access to Records - Private OWD, Grant Access Using Hierarchies, custom-object hierarchy behavior, sensitive-record isolation, and least-privilege sharing.

===============


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel