AI-201 · Question #231
Universal Containers (UC) is setting up a new Agentforce Service Agent. The company has sensitive medical product research stored internally and wants to ensure the agent cannot access it. What…
The correct answer is C. Follow the principle of least privilege and avoid granting permission to view the Medical Product. The AgentForce Security and Access Control Best Practices Guide emphasizes the principle of least privilege, which means granting each agent only the permissions strictly necessary to perform its defined tasks. To prevent unauthorized access to sensitive data such as medical…
Question
Universal Containers (UC) is setting up a new Agentforce Service Agent. The company has sensitive medical product research stored internally and wants to ensure the agent cannot access it. What should UC da?
Options
- AAssign the Agentforce Service Agent user the lowest possible role in the organization's hierarchy
- BDisable the Agentforce Service Agent's ability to use any Salesforce custom object or related
- CFollow the principle of least privilege and avoid granting permission to view the Medical Product
How the community answered
(27 responses)- A7% (2)
- B15% (4)
- C78% (21)
Explanation
The AgentForce Security and Access Control Best Practices Guide emphasizes the principle of least privilege, which means granting each agent only the permissions strictly necessary to perform its defined tasks. To prevent unauthorized access to sensitive data such as medical research, administrators should exclude permissions for the Medical Product object and related records from the AgentForce Service Agent's permission set group. This approach ensures that even if the reasoning engine processes a related query, it cannot retrieve or expose data it lacks access to.
Topics
Community Discussion
No community discussion yet for this question.