certified-sharing-and-visibility-architect Sample Questions

certified-sharing-and-visibility-architect Sample Questions & Answers

Weighted toward object, field and record-level permissions, the single biggest weight, plus org-wide defaults and role hierarchy tied with programmatic Apex sharing, security health checks, report visibility, and large-data-volume considerations.

Launch the full certified-sharing-and-visibility-architect simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Large Data Volume (LDV) Considerations · Data Skew Issues

    A large e-commerce company is implementing Salesforce for order management. The Order__c object is the child in a master-detail relationship to Account. The company has several massive B2B accounts, one of which has over 50,000 order records. During a batch job that reassigns ownership of this parent Account record, the job fails with UNABLE_TO_LOCK_ROW errors. What is the most likely cause of this issue?

    Show answer & explanation

    Correct answer: C

    This is a classic example of Account Data Skew (or parent-child skew). When an operation like an ownership change occurs on a parent record with a very large number of child records (typically >10,000), Salesforce must lock the parent record while it updates all child records to reflect the change. This long-held lock leads to contention, resulting in UNABLE_TO_LOCK_ROW errors for any other transaction trying to access that parent record or its children. The solution often involves re-architecting the data model to avoid such heavily skewed parent-child relationships.

  2. Question 2Intermediate

    Declarative Sharing · OWD Settings and Impact

    A user's access to a specific record is determined by multiple layers of the security model. An architect is analyzing the final effective permissions. What is the correct order of evaluation that Salesforce uses to determine record access, from the most restrictive baseline to the most permissive overrides?

    Show answer & explanation

    Correct answer: B

    Salesforce record access is built upon a foundation of opening up access progressively. It starts with the most restrictive setting, the Organization-Wide Defaults (OWD). Then, the Role Hierarchy opens up vertical access. After that, Sharing Rules (both criteria-based and ownership-based) open up lateral access. Finally, Manual Sharing and Team Sharing allow for flexible, ad-hoc access on individual records. Object permissions (Profiles/Permission Sets) are checked first to see if a user can see the object at all, but for record-level access, this is the correct sequence.

  3. Question 3Intermediate

    Declarative Sharing · Territory Management

    A technology company has a sales model where a single Account can be managed by multiple sales representatives across different product lines (e.g., Hardware, Software, Services). A user's access to an Account should be based on their assignment to one or more of these product lines for that specific Account. The company also needs to forecast sales revenue based on this product line structure. Which Salesforce feature is best suited to model this complex, matrix-based sharing requirement?

    Show answer & explanation

    Correct answer: B

    Enterprise Territory Management 2.0 is specifically designed for complex, matrix-based sharing models where a single record (like an Account) can belong to multiple territories, and users can be assigned to multiple territories. This directly addresses the need for users to have access based on different product lines for the same account. Furthermore, Territory Management integrates with forecasting, fulfilling the second requirement. While sharing rules or Account Teams could partially solve this, they become unmanageable at scale and do not offer the integrated forecasting capabilities of ETM 2.0.

  4. Question 4AdvancedSelect 2

    Programmatic Sharing · Enforcing Security in Code

    A developer is writing a batch Apex class that de-duplicates and merges millions of Contact records. The process requires system-level access to query all Contacts, regardless of the running user's visibility. However, during the update phase, the merge must not overwrite any fields on the master record that the running user does not have edit permission for. Which two keywords or methods are essential for the batch class to meet these requirements? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    To meet the requirement of querying all contacts, the class must run in system context, which is achieved with the without sharing keyword. To ensure FLS is respected during the update, Security.stripInaccessible() should be used on the SObject records before the DML operation. This method will remove any fields from the records that the running user does not have update access to, preventing the DML from failing or writing to unauthorized fields. WITH SECURITY_ENFORCED would restrict the initial query, violating the first requirement.

  5. Question 5Intermediate

    Reporting on the Data · Dashboard Security

    The executive team at a company needs a dashboard that shows company-wide sales performance. The team members have profiles that limit their record visibility to only their own regions. To protect the confidentiality of individual deals, executives should not be able to click through the dashboard components to see the underlying reports or records. What is the most secure and effective way to configure this dashboard?

    Show answer & explanation

    Correct answer: C

    This approach meets all requirements. Setting the running user to someone with full visibility (like a VP of Sales or an integration user) ensures the dashboard shows company-wide data. Storing the source reports in a private folder that the executives cannot access prevents them from clicking through to see the detailed record data. This allows them to see the aggregated view on the dashboard without granting them underlying record access. Granting 'View All Data' is excessive, and running as the viewer would restrict the data they see.

  6. Question 6Advanced

    Declarative Sharing · Experience Cloud Sharing

    Case Study: MedCare Solutions

    MedCare Solutions is developing a comprehensive health management platform on Salesforce. They have two main external user groups: Patients and Partner Physicians. The platform uses a custom object, Medical_Record__c, which is the child of the standard Contact object. The OWD for Medical_Record__c is Private.

    Requirements:

    1. Patients: Must only see their own Medical_Record__c records. They should not see records of any other patient, even within the same household (Account).
    2. Partner Physicians: Must see the Medical_Record__c records for all Patients who are associated with the Physician's primary clinic (a custom Clinic__c object linked to the Physician's User record and the Patient's Contact record).
    3. Data Volume: MedCare expects millions of patients and thousands of physicians, so the solution must be highly scalable and avoid programmatic sharing for this core requirement.

    Which combination of Experience Cloud licenses and declarative sharing features should the architect recommend?

    graph TD subgraph "External Users" Patient[Patient User] Physician[Physician User] end subgraph "Salesforce Objects" Account --|> Contact Contact --|> Medical_Record__c Physician -- "Manages" --> Clinic__c Contact -- "Treated At" --> Clinic__c end Patient -->|Access| Medical_Record__c Physician -->|Access| Medical_Record__c
    Show answer & explanation

    Correct answer: C

    This is the most scalable and declarative solution. Customer Community licenses are ideal for high-volume Patient users. A Sharing Set for their profile can easily grant them access to their own Medical Records by mapping User.ContactId = Medical_Record__c.Contact__c. Customer Community Plus licenses are suitable for Physicians who need more advanced sharing. A second Sharing Set can be created for the Physician profile that grants access to Medical Records by mapping the User.Clinic__c = Contact.Clinic__c relationship, effectively giving them access to all records of patients treated at their clinic. This avoids Apex and scales well for high volumes.

  7. Question 7Intermediate

    Security Audit and Testing · Security Review and Auditing

    An internal audit team requires proof that a sensitive custom field, SSN__c on the Contact object, has not been viewed in any report by users outside of the HR profile over the past year. Standard field history tracking is enabled but does not track report views. Which Salesforce feature is required to capture this specific type of user activity for auditing purposes?

    Show answer & explanation

    Correct answer: C

    Salesforce Shield Event Monitoring is the only feature that can provide this level of detail. It captures granular user activity events, including the 'Report Export' and 'Report Run' events. These event log files can be analyzed to see which users ran which reports, providing the necessary evidence for auditors. The Setup Audit Trail tracks metadata changes, Login History tracks logins, and Field History Tracking tracks data value changes, none of which capture report execution details.

  8. Question 8Intermediate

    Large Data Volume (LDV) Considerations · Sharing Calculation Performance

    A company with a very deep and complex role hierarchy is experiencing multi-hour delays in sharing rule recalculation after administrators make changes to roles or public groups. This is causing significant disruption to business operations. What standard feature can an architect enable to postpone these intensive recalculation processes to off-peak hours?

    Show answer & explanation

    Correct answer: C

    The 'Defer Sharing Calculations' feature is designed specifically for this scenario. When enabled, Salesforce does not immediately initiate a full sharing rule recalculation when roles, territories, or groups are modified. Instead, an administrator can suspend the calculations, make all necessary changes, and then resume and run the recalculation process during a planned maintenance window (e.g., overnight). This prevents performance degradation during business hours.

  9. Question 9Intermediate

    Declarative Sharing · Implicit and Built-in Sharing

    A custom object Project__c has a lookup relationship to Account. The Organization-Wide Default for Account is Private, and for Project__c it is Public Read-Only. If a user owns an Account record, what level of access will they implicitly have to the related Project__c records, assuming they are not the owner of the projects?

    Show answer & explanation

    Correct answer: B

    Even though there is a lookup relationship, the Project__c object's OWD is Public Read-Only. This setting is the baseline and grants all users Read-Only access to all Project__c records, regardless of their relationship to the parent Account. Implicit sharing from parent to child only applies when the child's OWD is more restrictive (e.g., Private or Controlled by Parent). In this case, the more permissive OWD on the child object takes precedence.

  10. Question 10IntermediateSelect 2

    Permissions and Access · Profiles and Permission Sets

    A consultant needs to grant a user temporary access to a custom process that involves updating a protected custom setting and running a specific batch Apex job. This access should be granted without changing the user's base profile, which does not have 'Customize Application' permissions. What are the two most appropriate tools to grant this specific, granular access? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    A Permission Set is the correct tool to grant additional permissions (like access to specific Apex classes and custom settings) to a user without changing their profile. To make the solution robust and declarative, a Custom Permission should be created to represent the abstract concept of 'Can Run Dupe Job'. This Custom Permission can then be included in the Permission Set. The Apex code can then check for this Custom Permission (FeatureManagement.checkPermission('Can_Run_Dupe_Job')) before executing, decoupling the logic from specific profiles or users.

Ready for the real thing?

The full certified-sharing-and-visibility-architect simulator has every exam-style question, timed mode, and instant scoring.