What is CRUD and FLS enforcement in Apex and how is it implemented?
Suggested answer
By default, Apex runs in system context — it bypasses CRUD (object-level) and FLS (field-level) security. To enforce security: CRUD checks: Use Schema methods — Schema.sObjectType.Account.isCreateable(), isReadable(), isUpdateable(), isDeletable() before DML/queries. FLS checks: Schema.sObjectType.Account.fields.Name.isAccessible(), isUpdateable(). Simplified approach: Use Security.stripInaccessible() to automatically strip fields the user cannot access from query results or DML inputs — cleaner than manual field-by-field checks. with sharing: Enforces record-level sharing rules (OWD/role hierarchy) but NOT FLS/CRUD. Always pair sharing enforcement with explicit FLS checks for full security compliance.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.