ADM-201 · Question #371
Northern Trail Outfitters wants to encourage employees to choose secure and appropriate passwords for their Salesforce accounts. Which three password policies should an administrator configure?…
The correct answer is A. Maximum invalid login attempts D. Password complexity requirements E. Number of days until expiration. To encourage secure and appropriate passwords, an administrator should configure Salesforce password policies for maximum invalid login attempts, password complexity requirements, and the number of days until expiration.
Question
Northern Trail Outfitters wants to encourage employees to choose secure and appropriate passwords for their Salesforce accounts. Which three password policies should an administrator configure? Choose 3 answers
Options
- AMaximum invalid login attempts
- BProhibited password values
- CRequire use of Password Manager App
- DPassword complexity requirements
- ENumber of days until expiration
How the community answered
(33 responses)- A88% (29)
- B3% (1)
- C9% (3)
Why each option
To encourage secure and appropriate passwords, an administrator should configure Salesforce password policies for maximum invalid login attempts, password complexity requirements, and the number of days until expiration.
Setting a maximum for invalid login attempts helps prevent brute-force attacks by locking out user accounts after a specified number of failed login attempts.
While a good security practice, 'Prohibited password values' is not a standard, configurable password policy option directly available within Salesforce's built-in password policy settings.
Salesforce's built-in password policies do not include an option to 'Require use of Password Manager App'; this is typically a client-side or organizational policy beyond direct Salesforce configuration.
Password complexity requirements enforce the use of a combination of uppercase letters, lowercase letters, numbers, and special characters, making passwords significantly harder to guess or crack.
Enforcing password expiration forces users to regularly change their passwords, reducing the risk of compromised passwords remaining active indefinitely.
Concept tested: Salesforce password policy configuration
Source: https://help.salesforce.com/s/articleView?id=sf.security_password_policies.htm&type=5
Topics
Community Discussion
No community discussion yet for this question.