Suggested answer

Session settings (Setup > Session Settings) control how user sessions behave. Key security settings:

1. Session Timeout: Time of inactivity before automatic logout (15 min to 24 hours — shorter is more secure).
2. Lock sessions to the IP address: Prevents session hijacking by binding the session to the originating IP.
3. Lock sessions to the domain: Prevents cross-domain session reuse.
4. Force re-login after Login-As-User: Requires admins to re-authenticate after using Login-As.
5. Require secure connections (HTTPS): Ensures all traffic is encrypted.
6. Clickjack Protection: Prevents Salesforce pages from being embedded in iframes on external sites.
7. Enable HSTS: HTTP Strict Transport Security header to force HTTPS. Most of these settings contribute to the Health Check score.

Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.

Community comments (0)

No comments yet.

Sign in or create a free account to add a comment. Comments are moderated before they appear.

Plain text only, 3–2000 characters. A moderator reviews every comment before it is published.