SF-PD2 Process Automation, Logic, and Integration Practice Question
A developer is building an Apex REST service that external systems will call to create records in Salesforce. The service must enforce field-level security (FLS) and sharing rules for the running user. Which approach should the developer take to ensure these security requirements are met?
⚠ Common exam trap
The trap here is assuming that 'with sharing' alone enforces FLS, or that Apex REST services automatically enforce security, when in fact FLS must be manually enforced.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the 'with sharing' keyword on the Apex class and manually enforce FLS using the Schema.DescribeFieldResult class.
To enforce sharing and FLS in an Apex REST service, the class must be declared 'with sharing' to respect sharing rules, and FLS must be manually enforced using Schema methods or Security.stripInaccessible. Apex runs in system mode by default, so explicit measures are required. The other options either ignore sharing, assume automatic FLS, or use an inappropriate sharing keyword.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the 'without sharing' keyword and rely on the external system to send only authorized data.
Why it's wrong here
'without sharing' explicitly ignores sharing rules, which violates the requirement to enforce sharing. Relying on the external system to send authorized data is not a security best practice; the service must enforce security regardless of the caller. This option fails to meet the requirement and could lead to data exposure.
- ✗
Use the 'inherited sharing' keyword to automatically apply the sharing mode of the calling class.
Why it's wrong here
'inherited sharing' is used when a class is called from another class and should inherit its sharing setting. For an Apex REST service, which is the entry point, 'inherited sharing' defaults to 'without sharing' if not called from another class. It does not enforce FLS. This option does not meet the requirement to enforce sharing and FLS.
- ✗
Use the 'with sharing' keyword and assume that FLS is automatically enforced for Apex REST services.
Why it's wrong here
While 'with sharing' enforces sharing rules, FLS is not automatically enforced in Apex, including Apex REST services. Developers must explicitly enforce FLS using methods like Schema.DescribeFieldResult or Security.stripInaccessible. Assuming automatic FLS enforcement is a common misconception that can lead to security vulnerabilities.
- ✓
Use the 'with sharing' keyword on the Apex class and manually enforce FLS using the Schema.DescribeFieldResult class.
Why this is correct
Apex REST services run in system mode by default, ignoring sharing rules and FLS. To enforce sharing, the class must be declared with 'with sharing'. To enforce FLS, developers must manually check field accessibility using Schema.DescribeFieldResult and the isAccessible, isCreateable, etc., methods, or use Security.stripInaccessible. This combination ensures both sharing and FLS are respected.
About these practice questions
Courseiva writes every SF-PD2 question from scratch — 226 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Salesforce exam blueprint
This SF-PD2 practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-PD2 exam.