SF-Admin Configuration and Setup Practice Question
Cloud Kicks' administrator needs to ensure that sales reps can only view and edit Opportunity records that belong to them, while their manager can view and edit all Opportunities owned by the team. The organization uses a role hierarchy. Which sharing setting should the administrator configure to meet this requirement?
⚠ Common exam trap
The trap here is assuming that the manager needs a sharing rule or permission set, when the role hierarchy already provides access when the OWD is Private.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the organization-wide default for Opportunity to Private, and grant the manager access via the role hierarchy.
The correct configuration is to set Opportunity to Private, which restricts access to owners and users above them in the role hierarchy. The manager, being above the sales reps, automatically gains access. This satisfies the requirement without granting unnecessary access to others. Public Read/Write or Public Read Only would allow all users to see all records, which is not desired. Using View All Data is over-permissive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the organization-wide default for Opportunity to Private, and create a permission set that grants View All Data to the manager.
Why it's wrong here
View All Data grants the manager access to all records, including those not owned by their team, which is excessive. The role hierarchy already provides the necessary access without granting global permissions. This approach violates least privilege and is unnecessary.
- ✓
Set the organization-wide default for Opportunity to Private, and grant the manager access via the role hierarchy.
Why this is correct
Setting Opportunity to Private ensures that only the owner and users above them in the role hierarchy can access records. The manager, being above the sales reps in the role hierarchy, automatically receives access. This meets the requirement without granting unnecessary access to other users.
- ✗
Set the organization-wide default for Opportunity to Public Read/Write, and remove the manager from the role hierarchy.
Why it's wrong here
Public Read/Write allows all users to edit all Opportunities, violating the principle of least privilege. Removing the manager from the role hierarchy would not restrict access but would prevent them from inheriting access, which is not needed. This configuration is overly permissive and does not meet the requirement.
- ✗
Set the organization-wide default for Opportunity to Public Read Only, and create a sharing rule to grant edit access to the sales reps.
Why it's wrong here
Public Read Only allows all users to view all Opportunities, which violates the requirement that reps only see their own. Granting edit access to reps via sharing rules would not prevent them from viewing others' records. This does not meet the need for restricted visibility.
About these practice questions
This SF-Admin question is part of Courseiva's 202-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Salesforce exam blueprint
This SF-Admin practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-Admin exam.