nerdexam
Salesforce

ADM-201 · Question #28

Universal Containers has a public read only sharing model on accounts. A new sales team has been created that will be dealing with high-security customers. The administrator has been asked to hide…

The correct answer is A. Create ownership-based sharing rules C. Change the new team role to be outside the company hierarchy. To effectively hide specific accounts from users outside a high-security team while maintaining existing access for other teams, the Organization-Wide Defaults (OWD) for accounts must first be set to Private, then specific configurations for roles and sharing rules are applied.

Submitted by yuriko_h· Apr 18, 2026Configuration and Setup

Question

Universal Containers has a public read only sharing model on accounts. A new sales team has been created that will be dealing with high-security customers. The administrator has been asked to hide these accounts from anyone NOT on this team. Which two steps must be taken to hide these accounts without impacting access to the rest of the Sales team? Choose 2 answers

Options

  • ACreate ownership-based sharing rules
  • BCreate a new account type to separate both teams.
  • CChange the new team role to be outside the company hierarchy.
  • DChange organization-wide default on account to private.

How the community answered

(32 responses)
  • A
    81% (26)
  • B
    6% (2)
  • D
    13% (4)

Why each option

To effectively hide specific accounts from users outside a high-security team while maintaining existing access for other teams, the Organization-Wide Defaults (OWD) for accounts must first be set to Private, then specific configurations for roles and sharing rules are applied.

ACreate ownership-based sharing rulesCorrect

Once OWD is Private, ownership-based sharing rules can be used to selectively grant read access to the 'rest of the Sales team' for the non-high-security accounts, ensuring their access is not entirely removed.

BCreate a new account type to separate both teams.

Creating a new account type helps categorization but does not inherently control data visibility or security.

CChange the new team role to be outside the company hierarchy.Correct

Changing the new team's role to be outside the existing company hierarchy, in conjunction with a Private OWD, isolates the high-security accounts they own, preventing users in other roles from automatically seeing them through the role hierarchy.

DChange organization-wide default on account to private.

While changing the OWD to Private is a necessary prerequisite to hide records, the question asks for two specific steps that represent configuration aspects after the baseline is established, rather than the initial OWD change itself.

Concept tested: Salesforce sharing model: OWD, roles, sharing rules

Source: https://help.salesforce.com/s/articleView?id=sf.security_owd.htm&type=5

Topics

#Salesforce Sharing Model#Role Hierarchy#Sharing Rules#Data Access Control

Community Discussion

No community discussion yet for this question.

Full ADM-201 Practice