nerdexam
Salesforce

ADM-201 · Question #131

Universal Containers wants to ensure that Its org Is secure and has asked an Administrator to configure password requirements for its users. Which three actions are Administrators able to configure?…

The correct answer is B. Set the length of time before passwords expire. C. Set maximum invalid login attempts. D. Set password complexity requirements. Salesforce administrators can configure password requirements by setting expiration times, limiting invalid login attempts, and defining complexity rules to enhance organizational security.

Submitted by ashley.k· Apr 18, 2026Configuration and Setup

Question

Universal Containers wants to ensure that Its org Is secure and has asked an Administrator to configure password requirements for its users. Which three actions are Administrators able to configure? Choose 3 answers

Options

  • ASet requirement that passwords must be unique for each user.
  • BSet the length of time before passwords expire.
  • CSet maximum invalid login attempts.
  • DSet password complexity requirements.
  • ESet prohibited password values.

How the community answered

(18 responses)
  • B
    94% (17)
  • E
    6% (1)

Why each option

Salesforce administrators can configure password requirements by setting expiration times, limiting invalid login attempts, and defining complexity rules to enhance organizational security.

ASet requirement that passwords must be unique for each user.

While users should use unique passwords, Salesforce provides password history checks for a single user, but not an administrative setting to enforce uniqueness across all users in the org.

BSet the length of time before passwords expire.Correct

Administrators can define how frequently passwords must be changed by setting an expiration period, such as every 90 days, to enforce regular password updates.

CSet maximum invalid login attempts.Correct

To prevent unauthorized access attempts, administrators can specify the maximum number of invalid login attempts allowed before a user's account is temporarily locked.

DSet password complexity requirements.Correct

Administrators can enforce strong password practices by setting complexity requirements, including minimum length, required character types (e.g., uppercase, numbers), and restrictions on repetitive characters.

ESet prohibited password values.

Salesforce does not offer a direct administrative setting to define a list of specific prohibited password values (e.g., 'password123') at the organization level.

Concept tested: Password policies and security settings

Source: https://help.salesforce.com/s/articleView?id=sf.security_password_policies.htm&type=5

Topics

#Password Policies#Security Settings#User Management

Community Discussion

No community discussion yet for this question.

Full ADM-201 Practice