nerdexam
Salesforce

CRT-211 · Question #177

The Cloud Kicks security team has seen an increase in unattended device attacks, where hackers can view sensitive information when users leave devices unlocked in public settings. The security team…

The correct answer is D. Force logout on session timeout. Force logout on session timeout is the recommended security setting to configure because it prevents users from resuming their sessions after they time out due to inactivity, which reduces the risk of unauthorized access to Salesforce data from unattended devices.

Security and Access

Question

The Cloud Kicks security team has seen an increase in unattended device attacks, where hackers can view sensitive information when users leave devices unlocked in public settings. The security team wants to ensure Salesforce data cannot be viewed after 10 minutes of inactivity. What is the recommended security setting to configure?

Options

  • AEnforce login IP ranges on every request.
  • BLock sessions to the domain in which they were first used.
  • CRequire a high assurance session.
  • DForce logout on session timeout.

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    19% (6)
  • C
    3% (1)
  • D
    71% (22)

Explanation

Force logout on session timeout is the recommended security setting to configure because it prevents users from resuming their sessions after they time out due to inactivity, which reduces the risk of unauthorized access to Salesforce data from unattended devices.

Topics

#session timeout#session security#inactivity lock#force logout

Community Discussion

No community discussion yet for this question.

Full CRT-211 Practice