Security-and-Privacy-Accredited-Professional Exam Questions

Total 104 Questions


Last Updated On : 16-Jan-2025

Salesforce does not allow email or SMS text messages as verification methods for MFA.
Which two reasons explain this? (2 options)


A. Entering codes from text messages is error-prone


B. Mobile devices can be lost or broken


C. Email account credentials can be compromised


D. SIM cards can be hacked





A.
  Entering codes from text messages is error-prone

D.
  SIM cards can be hacked

Which two reasons explain this?


A. Entering codes from text messages is error-prone


B. Mobile devices can be lost or broken


C. Email account credentials can be compromised


D. SIM cards can be hacked





A.
  Entering codes from text messages is error-prone

C.
  Email account credentials can be compromised

Which three standard authentication protocols does Salesforce support to integrate external applications using APIs?


A. OpenID Connect


B. Single Sign On (SSO)


C. OMFA


D. Security Assertion Markup Language (SAML)


E. OAuth





A.
  OpenID Connect

D.
  Security Assertion Markup Language (SAML)

E.
  OAuth

You need to limit when and where from users can access Salesforce- to help reduce the risks of unauthorized access. How should you go about this.


A. Restrict Access based on Login IP Addresses but login hairs can't be set up in conjunction with this feature


B. Use MFA to help ensure users are using a more secure login process


C. Restrict Access based on Login IP Addresses and use the Login Hours feature together


D. Do not allow users to access Salesforce from outside the office.





B.
  Use MFA to help ensure users are using a more secure login process

MFA is enabled at which level for Marketing Cloud-Email Studio, Mobile Studio, and Journey Builder?


A. User level


B. Top-level account


C. Role level


D. Business unit level





B.
  Top-level account

When is data from a newly connected tenant updated in the Security Center App?


A. Upon triggering the refresh


B. During the next daily update


C. Immediately


D. When the API is called





B.
  During the next daily update

By which method can Data Classification fields such as Compliance Categorization and Data


A. Sensitivity Level be accessed?


B. Field History Archive


C. Bulk API


D. Custom Metadata Types


E. Apex





E.
  Apex

Which of the following is a blocker to rolling out MFA?


A. Licensing for Transaction Security Policies


B. Users refusing to install applications on their personal phones


C. Shared accounts or credentials


D. Licensing for Login Flows





C.
  Shared accounts or credentials

The Admin wants to make Salesforce applications more secure. Which set of security settings should be enabled to achieve this?


A. Enable ClickJack protection, Lightning Lockdown, Enable User Certificates


B. Enable ClickJack protection, Health Check, Enable User Certificates


C. Enable Click Jack protection, Require HTTPS, Enable Cross-Site Scripting (XSS) Protection


D. Run Health Check, Require HTTPS, Salesforce Shield





C.
  Enable Click Jack protection, Require HTTPS, Enable Cross-Site Scripting (XSS) Protection

Where would the user go to connect a new tenant to the Security Center app?


A. Setup/Manage Tenants


B. Setup/Security Center


C. Manage Security Tab


D. Connected Tenants Tab





D.
  Connected Tenants Tab


Page 2 out of 11 Pages
Previous