Courseiva

SF-PD2 Testing, Debugging, and Deployment Practice Question

A developer is writing a test class that requires a user with a specific profile. How should the developer handle the user creation process?

⚠ Common exam trap

Candidates often assume they can use existing users from the org or rely on the running user, forgetting that tests must be isolated and explicitly define their security context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new user within the test method and use System.runAs().

Tests must create their own data, including Users, to ensure they remain self-contained and environment-independent. Using the 'RunAs' method in combination with user creation allows the developer to simulate specific security and permission contexts. This ensures that the logic is tested exactly as it would be for the target user, confirming that the code respects the platform's security model consistently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Query an existing user from the production environment.

    Why it's wrong here

    Querying existing users is a poor practice because it creates a hard dependency on the environment. The test might pass in one sandbox but fail in another because the user doesn't exist or has different permissions. Tests must create their own user records to be truly portable and reliable.

  • ✓

    Create a new user within the test method and use System.runAs().

    Why this is correct

    Creating a new user ensures the test is self-contained. Using System.runAs() allows the test to execute as that specific user, which is necessary to test code that relies on user permissions, record sharing, or profile-specific logic, ensuring the code behaves correctly under the expected security context for end users.

  • ✗

    Hardcode the username of a system administrator.

    Why it's wrong here

    Hardcoding usernames is fragile and insecure. It creates dependencies on specific org configurations that are likely to change. This practice is a major anti-pattern that leads to brittle tests that break frequently, requiring constant manual updates whenever the environment changes or the admin user is modified.

  • ✗

    Grant the test user the 'Modify All Data' permission via a PermissionSet.

    Why it's wrong here

    Granting excessive permissions to a test user defeats the purpose of testing security and permission-based logic. The test user should have the minimum permissions required to execute the code, reflecting real-world scenarios. Over-privileged test users mask potential security flaws that could lead to production access issues.

About these practice questions

One of 226 original SF-PD2 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Salesforce exam blueprint

This SF-PD2 practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-PD2 exam.