Suggested answer

For record access, I declare classes with sharing unless there is a documented reason not to. For object and field permissions, I use user mode database operations, such as WITH USER_MODE in SOQL and AccessLevel.USER_MODE for DML, or Security.stripInaccessible to remove fields the user cannot access.

I also review code in security scans and write tests that run as users with limited permissions using System.runAs.

What interviewers look for

The interviewer looks for a clear distinction between sharing (records) and CRUD/FLS (objects and fields), plus current enforcement techniques. A pitfall is believing that with sharing also enforces field-level security.

Original practice content; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.