Courseiva
Agentforce AI →hardMultiple Select

SF-Admin Agentforce AI Practice Question

An administrator at Cosmic Enterprises is preparing an Agentforce Service Agent for a new return policy topic. Before activation, the security team requires that the agent never expose customer payment card digits and that every interaction be traceable for compliance review. (Choose two.)

⚠ Common exam trap

The trap here is accepting data-hygiene measures such as validation rules or narrower topics as substitutes for runtime masking and interaction auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the Einstein Trust Layer audit trail to capture prompts, responses, and masking events.

Meeting the security team's demands requires two distinct controls: masking to keep raw card digits away from the model, and auditing to prove what happened in each interaction. Data Masking rules in the Einstein Trust Layer handle the first, while the Trust Layer audit trail handles the second. Broad permissions, validation rules, and topic narrowing address adjacent concerns but provide neither the runtime protection nor the traceability the scenario specifies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduce the agent's topic scope so it only answers questions about store hours and shipping times.

    Why it's wrong here

    Narrowing topics limits what the agent attempts to answer, which can reduce risk incidentally, but it does not mask card digits when payment data does enter context and it generates no compliance record of interactions. The security team's requirements are technical controls, and scope reduction is a design choice that leaves both controls absent.

  • ✓

    Enable the Einstein Trust Layer audit trail to capture prompts, responses, and masking events.

    Why this is correct

    The audit trail records interactions between Salesforce, the model, and connected systems, including which masking rules fired. This creates the traceability the security team demands, allowing reviewers to reconstruct what the agent was asked, what it returned, and whether sensitive data was masked, which is precisely the compliance visibility the scenario requires.

  • ✗

    Assign the agent user a profile with Modify All Data so it can retrieve any record a customer references.

    Why it's wrong here

    Granting Modify All Data would let the agent read and change virtually every record, which expands exposure instead of limiting it and violates least privilege. Broader access does nothing to prevent raw card digits from reaching the model or to create an audit record, so it works against both security requirements rather than satisfying either of them.

  • ✗

    Create a validation rule on the payment object that blocks saving records containing full card numbers.

    Why it's wrong here

    A validation rule restricts what users and integrations can persist, which is useful data hygiene, but it does not govern what an agent sends to or receives from a model at runtime. Existing records with digits would still be retrievable and could appear in responses, and the rule produces no interaction trace, so neither requirement is met.

  • ✓

    Configure Data Masking rules in the Einstein Trust Layer for the fields that hold card digits.

    Why this is correct

    The Einstein Trust Layer Data Masking capability replaces sensitive values with masked tokens before data leaves Salesforce for the model, and rehydrates them only where appropriate. Applying masking to card-number fields ensures the large language model never receives the raw digits, directly satisfying the requirement that the agent cannot expose payment card data in its responses or prompts.

About these practice questions

Courseiva writes every SF-Admin question from scratch — 202 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Salesforce exam blueprint

This SF-Admin practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-Admin exam.