โ† All SAA Flashcard Decks

Security & Access Management Flashcards

7 cards from real SAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Access Management flashcards as text
  1. A Salesforce org has multiple business units that should not see each other's data. Which feature is purpose-built to enforce this separation?

    Answer: Multi-org architecture with separate Salesforce instances

    When strict data separation is required between business units that cannot share any data, separate Salesforce orgs provide the cleanest isolation with no risk of cross-unit data leakage.

  2. Which Salesforce Security Health Check score category indicates that a setting is more permissive than Salesforce's recommended baseline?

    Answer: High Risk

    Settings flagged as 'High Risk' in Health Check are significantly more permissive than Salesforce's recommended security baseline and should be remediated immediately.

  3. An architect wants to allow Salesforce to send emails through an external mail server via SMTP. Where is this configured and what is a key security consideration?

    Answer: Email Relay in Setup; credentials must be stored securely and TLS should be enforced

    Email Relay is configured under Setup > Email > Email Relay Activation, and TLS should be required to encrypt email traffic between Salesforce and the relay server.

  4. What distinguishes a 'Muting Permission Set' from a standard permission set in Salesforce?

    Answer: A Muting Permission Set removes specific permissions granted by other permission sets within the same group

    Muting Permission Sets are used inside Permission Set Groups to revoke specific permissions that other member permission sets would otherwise grant.

  5. When using Salesforce as an Identity Provider (IdP) for SSO to external applications, which protocol does Salesforce support natively for this purpose?

    Answer: SAML 2.0 and OpenID Connect

    Salesforce natively supports SAML 2.0 for federated SSO and OpenID Connect for identity delegation to external service providers.

  6. A developer stores a third-party API key in a Custom Setting and uses it in Apex code. Why is this a security concern and what is the preferred approach?

    Answer: Custom Settings are visible to admins and exportable; Named Credentials or Protected Custom Metadata should store secrets

    Custom Settings are accessible to any admin and can be exported; sensitive credentials should use Named Credentials or Protected Custom Metadata Types which limit visibility.

  7. Which of the following correctly describes how 'Login Flows' enhance security in a Salesforce org?

    Answer: Login Flows execute custom logic (e.g., MFA prompts, policy checks) after credential validation but before granting access

    Login Flows are screen flows that run after a user's credentials are verified, enabling custom steps like additional MFA challenges, consent screens, or policy acknowledgment before session creation.

Security & Access Management Flashcards โ€” SAA Study Cards with Answers