Skip to content

Plat-Arch-205 Salesforce Certified Platform Sharing and Visibility Architect Practice Questions

Prepare for Plat-Arch-205 with more than an answer.

136 questions in the full set12 sample questionsUpdated Mar 12, 2026

Unlock the full exam and previous versions

  • v1Salesforce Certified Platform Sharing and Visibility Architect 136 questions Current
  • certified-sharing-and-visibility-architectLegacy Salesforce Certified Platform Sharing and Visibility Architect 164 questions Locked
Exam fee
$400 USD
Level
Architect
Valid for
Requires annual maintenance modules on Trailhead
Domains covered on the exam 4
  1. Permissions to Standard Objects, Custom Objects, and Fields27%
  2. Access to Records39%
  3. Access to Other Data16%
  4. Implications of Security Model Choice18%
  1. 1

    Universal Containers has a strict requirement that the 'Salary__c' field on the 'Employee__c' object must never be visible to users with the 'Intern' profile, even if a permission set is accidentally assigned. How can this be enforced structurally?

    Show answer details

    Correct answer: B

    While setting FLS on the profile is a good start, a permission set could accidentally grant access back. A Muting Permission Set within a Permission Set Group effectively 'blocks' that permission, ensuring that even if another permission set in the group tries to grant it, the muting set overrides it within the context of that group.

  2. 2

    A company wants to automate the assignment of the 'Payment_Processing' Permission Set to users who have the Department field set to 'Finance' and are Active. Which feature should the architect recommend?

    Show answer details

    Correct answer: A

    User Access Policies (Beta/GA depending on release) allow admins to define criteria-based rules to automatically assign or remove permission sets, package licenses, and other access mechanisms when a user record is created or updated.

  3. 3

    An architect is reviewing the security of a custom 'Commission__c' object. The Organization-Wide Default (OWD) is Private. A user with the 'Sales User' profile has Read, Create, and Edit permissions on the object. However, when this user attempts to edit a record owned by a subordinate in the role hierarchy, they receive an 'Insufficient Privileges' error. What is the most likely cause?

    Show answer details

    Correct answer: F

    For Custom Objects, 'Grant Access Using Hierarchies' can be unchecked. If it is unchecked, the role hierarchy does not grant access to records owned by subordinates. The user would need a Sharing Rule or manual share to access the record.

  4. 4

    A multinational financial services firm utilizes Permission Set Groups to manage user access based on job functions. The 'European Sales' group includes permission sets for 'Sales Core', 'GDPR Compliance', and 'Contract Editing'. However, a subset of interns within the European Sales team must not have the ability to delete Contracts, which is currently granted by the 'Contract Editing' permission set included in the group. How should the architect fulfill this requirement using the principle of least privilege without creating excessive new permission sets?

    Show answer details

    Correct answer: D

    Muting Permission Sets are specific to the Permission Set Group they are contained in. You cannot assign a Muting Permission Set directly to a user; it modifies the group itself. Therefore, to have a version of the group without Delete access, you must create a separate Permission Set Group for the interns and apply a Muting Permission Set to that specific group.

  5. 5

    Universal Containers creates a custom Lightning Web Component that allows users to search for and view 'Confidential_Project__c' records. The component uses a custom Apex controller to perform the SOQL query. A developer realizes that users can see fields in the component that their profile restricts via Field-Level Security (FLS). Which Apex feature should be implemented in the query to strictly enforce FLS and object permissions within the SOQL statement?

    Show answer details

    Correct answer: C

    The WITH SECURITY_ENFORCED clause in SOQL checks for both field-level and object-level security permissions for the fields and objects selected in the query. If the user lacks permission, the query throws a System.QueryException. with sharing only enforces record-level sharing (visibility), not FLS.

  6. 6

    A healthcare organization stores patient SSNs in a custom field SSN__c. For compliance, this field must be encrypted at rest, but specific compliance officers need to search for patients using the last 4 digits of the SSN. Which encryption strategy supports this requirement?

    Show answer details

    Correct answer: C

    Shield Platform Encryption with Deterministic Encryption allows users to filter and search on encrypted data because it generates the same ciphertext for a given piece of data every time. Probabilistic encryption (the default) does not support filtering/searching. Classic Encryption allows masking but has limitations on standard search functionality compared to Shield.

Create an account to continue.