Courseiva

SF-Data-Arch Salesforce Data Management Practice Question

A data architect at a healthcare company needs to ensure that only authorized users can view sensitive patient information stored in custom fields on the Patient__c object. The organization uses a role hierarchy and profiles. Which feature should the architect use to restrict access to these fields?

⚠ Common exam trap

A common mix-up: candidates confuse record-level security features like organization-wide defaults and sharing rules with field-level security, which is specifically designed to control field visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Field-level security

Field-level security is the correct feature to restrict access to sensitive fields based on profiles. It allows administrators to hide fields from users who should not see them, regardless of record access. This ensures compliance with privacy regulations by limiting field visibility to authorized personnel only.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Organization-wide defaults

    Why it's wrong here

    Organization-wide defaults (OWD) control record-level access, not field-level access. They determine the default sharing setting for objects, such as Private or Public Read/Write. While OWD can restrict who can see records, they do not hide specific fields on a record that a user can access. Therefore, OWD alone cannot protect sensitive fields.

  • ✗

    Permission sets

    Why it's wrong here

    Permission sets grant additional permissions to users but do not restrict access. They can be used to grant field-level access, but to restrict, you would need to ensure the base profile does not have access and then use permission sets to grant it selectively. However, permission sets alone are not a restriction mechanism; they are additive. Field-level security is the primary tool for restriction.

  • ✓

    Field-level security

    Why this is correct

    Field-level security (FLS) allows administrators to control which profiles can view or edit specific fields. By setting the sensitive fields to hidden for unauthorized profiles, the architect ensures that only authorized users can see the patient information. FLS is the standard mechanism for field-level access control in Salesforce and works in conjunction with page layouts and permission sets.

  • ✗

    Sharing rules

    Why it's wrong here

    Sharing rules extend record access to users beyond OWD, but they do not control field-level visibility. They are used to open up access to records for groups or roles. Sharing rules cannot hide fields; they only grant additional record access. Thus, they are not suitable for restricting access to specific sensitive fields.

About these practice questions

This SF-Data-Arch question is part of Courseiva's 222-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Salesforce exam blueprint

This SF-Data-Arch practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-Data-Arch exam.