SF-Admin Agentforce AI Practice Question
A large financial services company is implementing an Agentforce Service Agent to handle customer inquiries about account balances and recent transactions. The administrator must ensure the agent can securely access customer data and provide accurate responses. Which two configurations are required to enable the agent to retrieve data from Salesforce objects? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse external authentication mechanisms like Named Credentials with internal data access, or assuming that broad permissions like 'Modify All Data' are needed instead of least-privilege access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the objects as data sources in the agent's Topic configuration and define the relevant fields.
To enable an Agentforce agent to retrieve data from Salesforce objects, the administrator must ensure the agent's running user has read access via a permission set, and the objects and fields must be added as data sources in the agent's Topic configuration. These two steps work together: the permission set grants the underlying access, while the Topic configuration tells the agent what data it can use.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add the objects as data sources in the agent's Topic configuration and define the relevant fields.
Why this is correct
In Agent Builder, each Topic can include data sources that specify which Salesforce objects and fields the agent can use to answer questions. By adding the necessary objects (e.g., Account, Contact) and their fields to the Topic, the agent can retrieve and reason over that data. This configuration is essential for the agent to know what data is available and how to query it.
- ✗
Configure a Named Credential for each Salesforce object the agent needs to access.
Why it's wrong here
Named Credentials are used for external callouts to authenticate to third-party services, not for accessing internal Salesforce data. The agent accesses Salesforce objects directly through the platform, so Named Credentials are unnecessary and would not enable data retrieval. They are relevant only when the agent needs to call external APIs.
- ✗
Enable the Einstein Trust Layer and set data masking rules for all fields.
Why it's wrong here
The Einstein Trust Layer provides data masking and zero-data retention to protect sensitive information, but it does not grant access to data. Enabling it is a security best practice, but it does not enable the agent to retrieve data from objects. Data masking rules would actually restrict the data shown, so they are not a requirement for access.
- ✗
Assign the agent's running user a profile with the 'Modify All Data' permission.
Why it's wrong here
The 'Modify All Data' permission grants broad access to edit all data, which is excessive and violates the principle of least privilege. The agent only needs read access to specific objects and fields. Assigning this permission would not only be a security risk but also unnecessary for enabling data retrieval. Proper access is achieved through targeted permission sets.
- ✓
Create a permission set that grants the agent's running user read access to the necessary objects and fields.
Why this is correct
Agentforce agents operate under the context of a running user. To access data from Salesforce objects, the running user must have the appropriate object and field-level permissions. Creating a permission set with read access and assigning it to the running user ensures the agent can query the data. Without these permissions, the agent's data retrieval actions will fail due to insufficient access.
About these practice questions
One of 202 original SF-Admin practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Salesforce exam blueprint
This SF-Admin practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-Admin exam.