CRT-211 · Question #177
The Cloud Kicks security team has seen an increase in unattended device attacks, where hackers can view sensitive information when users leave devices unlocked in public settings. The security team…
The correct answer is D. Force logout on session timeout. Force logout on session timeout is the recommended security setting to configure because it prevents users from resuming their sessions after they time out due to inactivity, which reduces the risk of unauthorized access to Salesforce data from unattended devices.
Question
The Cloud Kicks security team has seen an increase in unattended device attacks, where hackers can view sensitive information when users leave devices unlocked in public settings. The security team wants to ensure Salesforce data cannot be viewed after 10 minutes of inactivity. What is the recommended security setting to configure?
Options
- AEnforce login IP ranges on every request.
- BLock sessions to the domain in which they were first used.
- CRequire a high assurance session.
- DForce logout on session timeout.
How the community answered
(31 responses)- A6% (2)
- B19% (6)
- C3% (1)
- D71% (22)
Explanation
Force logout on session timeout is the recommended security setting to configure because it prevents users from resuming their sessions after they time out due to inactivity, which reduces the risk of unauthorized access to Salesforce data from unattended devices.
Topics
Community Discussion
No community discussion yet for this question.