certified-sharing-and-visibility-architect Salesforce Certified Platform Sharing and Visibility Architect Practice Questions
Prepare for certified-sharing-and-visibility-architect with more than an answer.
Unlock the full exam and previous versions
- v1Salesforce Certified Platform Sharing and Visibility Architect 136 questions Locked
- certified-sharing-and-visibility-architectLegacy Salesforce Certified Platform Sharing and Visibility Architect 164 questions Current
- Exam fee
- $400 USD
- Level
- Architect
Domains covered on the exam 6
- Permissions and Access27%
- Declarative Sharing17%
- Programmatic Sharing17%
- Reporting on the Data12%
- Security Audit and Testing15%
- Large Data Volume (LDV) Considerations12%
- 1
True or False: Using the
inherited sharingkeyword in an Apex class causes the class to run inwith sharingmode when invoked from another class that iswith sharing, and inwithout sharingmode when invoked from a class that iswithout sharing.Show answer details
Correct answer: A
This statement is true. The
inherited sharingkeyword makes the sharing context of a class dependent on its calling context. If the calling class or execution context (like an Aura component controller) is runningwith sharing, theinherited sharingclass will also runwith sharing. If the calling context iswithout sharing, it will runwithout sharing. This provides flexibility and ensures that a utility class, for example, respects the security context of whatever code invokes it. - 2
A report on the
Invoice__ccustom object is stored in a public folder accessible to all internal users. A user from the Marketing department, whose profile has no object permissions (no CRUD) forInvoice__c, attempts to run this report. What will the user see?Show answer details
Correct answer: C
Object-level permissions are the first gate of security. If a user's profile and permission sets do not grant at least 'Read' access to an object, they cannot view any records of that object, including in reports. Even if the report is in a public folder, the user lacks the fundamental permission to see the
Invoice__cobject, so Salesforce will block the report from running and display an 'Insufficient Privileges' error. - 3
During a data audit, an architect discovers that several sensitive Account records are being shared with an incorrect public group due to a misconfigured criteria-based sharing rule. The architect corrects the rule's criteria and saves it. However, a day later, the audit shows the incorrect access still exists. The org has over 10 million accounts. What is the most probable reason for the persistence of the incorrect access?
Show answer details
Correct answer: B
In organizations with Large Data Volumes (LDV), recalculating sharing rules after a change is not instantaneous. The process runs as an asynchronous background job. For millions of records, this recalculation can take several hours or even more than a day to complete. During this time, the old sharing grants will persist until the recalculation process has finished evaluating all records against the new criteria. The other options are incorrect; manual refreshes are not required, another user's share doesn't affect this, and a read-only field wouldn't prevent the rule from running.
- 4
An architect is designing a data model for a new Salesforce org. A single integration user will be the owner of approximately 80% of all Account records, which is expected to reach 10 million. Many ownership-based sharing rules are planned to grant access to these Accounts. What is the most critical design consideration to prevent severe lock contention on the
AccountSharetable?Show answer details
Correct answer: C
This scenario describes ownership skew, which is a major cause of performance issues in LDV orgs. When a single user owns a vast number of records, any changes to that user's role, group membership, or related sharing rules can cause massive recalculations and lock contention on the share table. The best practice is to avoid using this skewed user directly in sharing rules. Instead, use criteria-based rules that do not depend on the owner. Assigning the user to a public group and then using ownership-based sharing on that group does not solve the underlying problem.
- 5
Case Study: Apex Financial
Apex Financial uses a custom object,
Financial_Plan__c, with an OWD of Private. Access to these plans is highly dynamic and depends on the user's role on a related junction object,Client_Team_Member__c, which links a User to aFinancial_Plan__c.Requirements:
- If a user's
Role__con theClient_Team_Member__crecord is 'Primary Advisor', they need Read/Write access to theFinancial_Plan__c. - If their
Role__cis 'Analyst', they need Read-Only access. - Access must be updated automatically and immediately whenever a
Client_Team_Member__crecord is created, updated, or deleted. - The solution must be able to handle thousands of updates per day without hitting governor limits or causing performance issues.
What is the most scalable and maintainable solution to implement this dynamic sharing model?
flowchart TD subgraph Trigger on Client_Team_Member__c A[On Insert/Update/Delete] --> B{What is User Role?} B -->|Primary Advisor| C[Grant Read/Write Access] B -->|Analyst| D[Grant Read-Only Access] B -->|Other/Deleted| E[Revoke Access] end subgraph Financial_Plan__c Share Table F(Financial_Plan__Share) end C --> F D --> F E --> FShow answer details
Correct answer: B
This requirement is a classic use case for Apex Managed Sharing. Because the sharing logic is based on a related object's field values and requires different access levels (Read vs. Write), declarative sharing rules are insufficient. An Apex trigger on the junction object is the correct pattern. It can create
Financial_Plan__Sharerecords with the appropriateAccessLevel('Edit' or 'Read') and a customRowCauseto identify the shares. The trigger must also handle updates (e.g., role change) and deletions to correctly revoke access. This provides immediate, granular, and automated control over the sharing. - If a user's
- 6
A global logistics company is experiencing significant performance degradation during territory realignment. Their Enterprise Territory Management 2.0 model includes a 7-level territory hierarchy and over 500 assignment rules that run on Account updates. During peak hours, updates to Account records frequently time out. The org contains 15 million Account records. An architect has been tasked with optimizing the sharing model to improve performance without compromising the complex access requirements. Which approach should the architect prioritize?
Show answer details
Correct answer: D
In Large Data Volume (LDV) scenarios involving Enterprise Territory Management, the complexity and efficiency of assignment rules are the most common cause of performance issues. Simplifying rules by using indexed fields (like Record IDs, Owner IDs, custom fields marked as External ID) and reducing the total number of rules will have the most significant impact on performance. Replacing the standard feature with a custom solution is a massive undertaking and should be a last resort. Increasing batch size could exacerbate timeouts, and while archiving data is a valid LDV strategy, optimizing the active rule set is the most direct solution to the described problem.
- 7
A developer at a financial services firm has created a custom Visualforce page to display sensitive client portfolio information. The associated Apex controller class must be declared
without sharingto aggregate data from multiple related objects that the running user may not directly own. However, the firm's security policy mandates that Field-Level Security (FLS) for all fields on the primaryPortfolio__cobject must be strictly enforced. Which Apex code snippet correctly ensures FLS is respected before displaying the data?Show answer details
Correct answer: B
The
Security.stripInaccessible()method is the most efficient and recommended way to enforce FLS for read access on a list of SObjects. It removes fields from the SObject records that the user cannot access, preventing them from being displayed on the Visualforce page. While looping withisAccessible()works, it is far more verbose and less performant for multiple records and fields.WITH SECURITY_ENFORCEDenforces sharing rules and FLS at the query level, but the requirement is to run the initial querywithout sharing. Checking object permissions withisReadable()doesn't solve the field-level requirement. - 8
A manufacturing company is setting up a new Partner Community. Partners need to see all
Caserecords associated with theAccountthey belong to, regardless of who owns the Case. They also need to collaborate onOpportunityrecords where they are explicitly added as a Partner User in a custom lookup field on the Opportunity. The Organization-Wide Default for both Case and Opportunity is Private. Which two features must be configured to meet these requirements? (Select TWO)Show answer details
Correct answer: A, E
A Sharing Set is used to grant high-volume community users (like Partner Community users) access to records that are associated with their account or contact record. This perfectly fits the requirement for Cases. For the Opportunity requirement, a criteria-based sharing rule can be created to share Opportunity records with a specific Partner Role or Group when the custom lookup field contains a user from that partner account. Share Groups are for sharing records owned by high-volume users, not for sharing records with them.
- 9
A junior administrator reports that a user in the Sales team can see an Opportunity record they should not have access to. The Opportunity's owner is in a different region, and there are no apparent criteria-based sharing rules that would grant access. The architect needs to quickly determine the exact mechanism that granted the user access. What is the most direct and effective method to diagnose the source of this user's access to the specific record?
Show answer details
Correct answer: C
The 'Sharing' button on a record detail page (in Classic, or the 'Sharing Hierarchy' action in Lightning) is the most direct tool for troubleshooting access to a single record. It provides a detailed list of every user, group, and role that has access and, crucially, the 'Reason' for that access (e.g., 'Manual Share', 'Owner', 'Sharing Rule: [Rule Name]'). This immediately pinpoints the exact mechanism. 'Login As' confirms access but doesn't explain the reason. Health Check is for org-wide issues, not specific records. The Setup Audit Trail shows changes but not the current state of access.
- 10
True or False: A dashboard is configured with the running user set to a System Administrator. A sales user who views this dashboard will see all data aggregated from the underlying reports, even if their profile and sharing settings prevent them from accessing the individual records that make up the data.
Show answer details
Correct answer: A
This statement is true. The dashboard's running user determines the data context for all viewers of that dashboard. If the running user is a System Administrator (who can see all data), the dashboard components will display aggregated data from all records, effectively bypassing the viewing user's personal record-level security. This is a critical security consideration when designing dashboards.
