nerdexam
Salesforce

PLAT-ADMN-201 · Question #154

Cloud Kicks has an administrator team that manages the org. The company has asked for a small subset of leadership users to have Modify All access, like the administrators have. How should the…

The correct answer is C. Assign the standard User profile to the leadership users and add a custom permission set with. Salesforce best practices dictate the Principle of Least Privilege, which means users should only be given the minimum level of access required to do their jobs. Assigning leadership users the "System Administrator" profile (Option B) is dangerous because it grants them the…

Submitted by skyler.x· Apr 18, 2026Configuration and Setup

Question

Cloud Kicks has an administrator team that manages the org. The company has asked for a small subset of leadership users to have Modify All access, like the administrators have. How should the administrator team accomplish this?

Options

  • AAssign the standard Platform User profile to the leadership users and edit the permissions to
  • BAssign the standard System Administrator profile to the leadership users that includes the Modify
  • CAssign the standard User profile to the leadership users and add a custom permission set with
  • DClone the standard User profile to the leadership users and assign a Modify All role to grant

How the community answered

(54 responses)
  • A
    4% (2)
  • B
    4% (2)
  • C
    83% (45)
  • D
    9% (5)

Explanation

Salesforce best practices dictate the Principle of Least Privilege, which means users should only be given the minimum level of access required to do their jobs. Assigning leadership users the "System Administrator" profile (Option B) is dangerous because it grants them the ability to change the system configuration, delete fields, and manage users. Instead, the administrator should keep the leadership users on their standard functional profile and grant the "Modify All Data" permission via a Permission Set. This approach provides the users with the data visibility they need the ability to view and edit all records across the org) without giving them administrative control over the backend setup. Option A is incorrect because you cannot edit standard profiles directly. Option D is incorrect because "Roles" control record visibility and hierarchy, but they do not grant administrative permissions like "Modify All Data." Using a Permission Set is the most secure and flexible way to elevate data access for a specific group.

Topics

#Permissions#Profiles#Permission Sets#Security Model

Community Discussion

No community discussion yet for this question.

Full PLAT-ADMN-201 Practice