Salesforce Security Real Interview Questions Quiz – 30 Questions

Salesforce Security Real Interview Questions Quiz

30 Salesforce Security questions, built from real interview experiences shared on this site (Wipro, PwC, Cloud Peritus, EPAM, Amazon, Cognizant and more), supplemented with core security concepts from official Salesforce documentation. Click an option to instantly see if you got it right.

Topics: SSO, MFA, OAuth, Named Credentials, Remote Site Settings, FLS and CRUD enforcement in Apex/SOQL, Salesforce Shield, Clickjack/CSRF/XSS protection, Lightning Web Security, Health Check, Data Mask and Guest User security.

Score: 0 / 30
Question 1 of 30
What is Single Sign-On (SSO) in Salesforce?
Question 2 of 30
How is Single Sign-On typically configured in Salesforce?
Question 3 of 30
What does Salesforce require for direct UI logins as a baseline security measure today?
Question 4 of 30
What is a Named Credential used for in Salesforce?
Question 5 of 30
What is a Remote Site Setting used for?
Question 6 of 30
What is the key difference between a Remote Site Setting and a Named Credential?
Question 7 of 30
Which OAuth version does Salesforce support for its authentication flows?
Question 8 of 30
What is a Connected App used for in Salesforce?
Question 9 of 30
What do Login IP Ranges, set on a Profile or at the org level, control?
Question 10 of 30
What do Login Hours on a Profile control?
Question 11 of 30
What is the purpose of a High Assurance session security level in Salesforce?
Question 12 of 30
What is Salesforce Shield?
Question 13 of 30
What does Shield Platform Encryption primarily do?
Question 14 of 30
What is a Transaction Security Policy used for?
Question 15 of 30
What does Field-Level Security (FLS) control?
Question 16 of 30
Does Apex automatically respect Field-Level Security (FLS) and object CRUD permissions by default?
Question 17 of 30
What does adding WITH SECURITY_ENFORCED to a SOQL query do?
Question 18 of 30
How does WITH USER_MODE in SOQL generally differ from WITH SECURITY_ENFORCED?
Question 19 of 30
What does Security.stripInaccessible() do in Apex?
Question 20 of 30
What is Clickjack Protection, configured under Session Settings, meant to prevent?
Question 21 of 30
What is Cross-Site Request Forgery (CSRF) protection designed to prevent?
Question 22 of 30
How does Visualforce help protect against Cross-Site Scripting (XSS) by default?
Question 23 of 30
What is a CSP Trusted Site used for in Salesforce?
Question 24 of 30
What is the purpose of Lightning Web Security (and its predecessor, Lightning Locker)?
Question 25 of 30
What does the Health Check tool in Salesforce Setup do?
Question 26 of 30
What is Data Mask used for in Salesforce sandboxes?
Question 27 of 30
What is an Auth. Provider used for in Salesforce?
Question 28 of 30
In the Salesforce security model, what is the first layer that determines whether a user can access an object at all (regardless of individual records)?
Question 29 of 30
By default, what access level do Guest Users (unauthenticated Experience Cloud visitors) have to an object's records, regardless of the object's Organization-Wide Default?
Question 30 of 30
What explicitly grants a Guest User access to specific records in an Experience Cloud site beyond the object's baseline restriction?

Leave a Reply