Plat-Admn-301 Sample Questions & Answers
Record and field access security ties with intricate automation for the biggest share, alongside stretching objects and the interface further, keeping watch with monitoring dashboards, Sales Cloud capabilities, tools for clean data, and deploying metadata changes.
Launch the full Plat-Admn-301 simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Security and Access · Record and Field Data Access Implications
Cloud Kicks uses a 'Private' sharing model for Cases. They have set up Account Teams to allow account managers to work together. However, users added to an Account Team are reporting they cannot see the Cases related to that Account, even though they have 'Read/Write' access to the Account. What configuration is missing?
Show answer & explanation
Correct answer: A
When enabling Account Teams, granting access to the Account does not automatically grant access to related objects like Cases or Opportunities if those objects are set to Private. You must explicitly configure the 'Case Access' level (Read Only or Read/Write) within the Account Team settings or when adding team members.
- Question 2Advanced
Security and Access · Custom Profiles, Permission Sets, and Delegated Administration
An Administrator is configuring a Permission Set Group for a new 'Sales Lead' role. This role requires the 'Sales User' and 'Marketing User' permission sets, but must NOT have the 'Delete' permission on the Lead object, which is included in the 'Sales User' permission set. How should the Administrator achieve this requirement?
Show answer & explanation
Correct answer: B
Muting Permission Sets are specifically designed for this scenario. They allow you to include broad permission sets in a Permission Set Group but 'mute' (disable) specific permissions for that group only, without altering the original permission sets which might be used elsewhere.
- Question 3Advanced
Security and Access · User Authentication
A multinational corporation requires Multi-Factor Authentication (MFA) for all internal users. However, they want to allow a simplified login experience for users connecting from the corporate office network (trusted IP range) by not requiring the second factor. Which feature should the Administrator configure to satisfy this requirement?
Show answer & explanation
Correct answer: B
According to Salesforce's official MFA requirements and best practices, MFA should be enforced for every login. While you can use 'Trusted IP Ranges' to bypass email verification for browser activation, Salesforce does not support bypassing the strong MFA requirement (like Salesforce Authenticator) based solely on IP address for internal users, as IP spoofing is a security risk. The correct stance for the exam is that MFA is required regardless of location for compliance.
- Question 4Intermediate
Security and Access · Record and Field Data Access Implications
The CIO of a healthcare company has mandated that all 'Patient_Data__c' records must be visible to the 'Medical Staff' profile, but the 'SSN__c' field on that object must be hidden from everyone except the 'Compliance Officer' user. The 'Patient_Data__c' object OWD is Public Read/Write. Which combination of settings achieves this?
Show answer & explanation
Correct answer: C
Field-Level Security (FLS) is the correct tool to restrict visibility of specific fields. By setting the field to hidden (unchecked Visible) at the profile level for everyone, no one can see it. Since permission sets extend access, creating a Permission Set granting Read access to that specific field and assigning it to the Compliance Officer is the standard way to handle exception-based field access.
- Question 5IntermediateSelect 2
Security and Access · Custom Profiles, Permission Sets, and Delegated Administration
Which TWO statements regarding the 'View All Data' and 'Modify All Data' system permissions are correct? (Select TWO)
Show answer & explanation
Correct answers: B, C
Like other system permissions, View All Data and Modify All Data can be granted via Permission Sets, allowing for granular assignment to specific users without giving them a full Admin profile.
View All Data and Modify All Data are 'super permissions' that ignore all sharing rules, role hierarchy, and OWD settings, giving the user access to every record of that object type in the org.
- Question 6Advanced
Security and Access · Record and Field Data Access Implications
A sales organization is implementing Enterprise Territory Management. They want to ensure that when a sales rep is assigned to a territory, they automatically gain access to the Accounts in that territory, as well as the related Opportunities and Cases. Which configuration step is required to achieve this for Cases?
Show answer & explanation
Correct answer: A
In Enterprise Territory Management settings, you can define default access levels for Accounts, Opportunities, Cases, and Contacts. To ensure reps get access to Cases associated with Accounts in their territory, the Administrator must configure the Case Access level (e.g., Read/Write) in the Territory Settings.
Ready for the real thing?
The full Plat-Admn-301 simulator has every exam-style question, timed mode, and instant scoring.