Suggested answer

The single most common mistake is believing that with sharing covers everything. It does not — it enforces record-level sharing only. Object CRUD and field-level security are entirely separate and must be enforced explicitly.

The tools I would expect a developer to use:

1. Sharing keywords: with sharing, without sharing, and inherited sharing, which takes the caller's context and is the right default for a reusable service class.
2. User-mode operations: WITH USER_MODE in SOQL, and AccessLevel.USER_MODE with Database.query and DML, which apply CRUD, FLS, and sharing together.
3. Security.stripInaccessible(): Removes fields the user cannot access from a result set or an inbound payload, without throwing.
4. WITH SECURITY_ENFORCED: Throws when an inaccessible field is referenced — appropriate when you want to fail loudly.
5. Describe checks such as isAccessible() and isUpdateable() for conditional logic.

The second common mistake is Visualforce and Aura controllers: pages on a standard controller enforce sharing, CRUD, and FLS, but a custom controller runs in system context until the developer says otherwise.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.