nerdexam
Salesforce

CRT-101 · Question #152

An administrator at Universal Containers has been asked to prevent users from accessing Salesforce from outside of their network. What are two considerations for this configuration? Choose 2 answers

The correct answer is A. IP address restrictions are set on the profile or globally for the org. C. Enforce Login IP Ranges on Every Request must be selected to enforce IP restrictions. Two valid considerations for restricting access to a specific corporate network: (A) Login IP Ranges can be configured at the profile level to restrict login by IP address, and global trusted IP ranges can be set under Setup > Network Access for the entire org. (C) The 'Enforce…

Configuration and Setup

Question

An administrator at Universal Containers has been asked to prevent users from accessing Salesforce from outside of their network. What are two considerations for this configuration? Choose 2 answers

Options

  • AIP address restrictions are set on the profile or globally for the org.
  • BAssign single sign-on to a permission set to allow users to log in when outside the network.
  • CEnforce Login IP Ranges on Every Request must be selected to enforce IP restrictions.
  • DRestrict U2F Security Keys on the user's profile to enforce login hours.

How the community answered

(26 responses)
  • A
    92% (24)
  • B
    4% (1)
  • D
    4% (1)

Explanation

Two valid considerations for restricting access to a specific corporate network: (A) Login IP Ranges can be configured at the profile level to restrict login by IP address, and global trusted IP ranges can be set under Setup > Network Access for the entire org. (C) The 'Enforce Login IP Ranges on Every Request' setting must be explicitly enabled; without it, IP restrictions are only checked at the moment of login, not for every subsequent page request during an active session. Option B is incorrect because assigning SSO to a permission set does not bypass network-level IP restrictions. Option D is incorrect because U2F Security Keys are multi-factor authentication devices, not a mechanism for enforcing network-based login restrictions.

Topics

#Security Settings#Login IP Ranges#Profile Management#Access Control

Community Discussion

No community discussion yet for this question.

Full CRT-101 Practice