Courseiva
Agentforce AI →easyMultiple Choice

SF-Admin Agentforce AI Practice Question

Universal Containers is preparing to activate an Agentforce Service Agent for a customer-facing help site. Before activation, the administrator must ensure the agent only surfaces knowledge articles that the requesting customer is permitted to see. Which configuration should the administrator verify?

⚠ Common exam trap

Test-takers frequently confuse Einstein Trust Layer data masking, which protects sensitive values in prompts, with record-level access control that determines which knowledge articles the agent can retrieve.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The running user's sharing settings and object permissions for the knowledge articles the agent retrieves.

Knowledge retrieval by an agent respects the permissions and sharing of the context in which the retrieval runs. To prevent customers from seeing articles they are not entitled to, the administrator must verify sharing settings and object and field permissions for the knowledge records the agent can return. Masking, response length, and audit retention do not govern record-level access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The running user's sharing settings and object permissions for the knowledge articles the agent retrieves.

    Why this is correct

    When an agent retrieves knowledge on behalf of a customer, the records returned honor the access of the context in which the action runs. Verifying sharing settings and object and field permissions ensures the agent cannot surface articles the customer is not entitled to see. This is the correct control for record-level access.

  • ✗

    The agent's Einstein Trust Layer data masking rules for the knowledge object.

    Why it's wrong here

    Data masking in the Einstein Trust Layer protects sensitive data in prompts and responses, but it does not enforce record-level access to knowledge articles. Masking would not stop the agent from retrieving an article the customer cannot see. Access control for articles is governed by sharing and permissions, not masking rules.

  • ✗

    The Einstein Trust Layer audit trail retention period for the agent.

    Why it's wrong here

    Audit trail retention governs how long interactions are logged for compliance and review. It does not influence what the agent retrieves or displays to a customer. Retaining logs longer or shorter does not enforce article-level access control.

  • ✗

    The agent's response length limit in the Agent Builder settings.

    Why it's wrong here

    Response length controls how verbose the generated answer is; it has no effect on which knowledge records are retrieved. A shorter or longer answer does not change record access. This setting is unrelated to ensuring customers only see permitted articles.

About these practice questions

Courseiva writes every SF-Admin question from scratch — 202 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Salesforce exam blueprint

This SF-Admin practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-Admin exam.