Courseiva

SF-PD2 Advanced Developer Fundamentals Practice Question

A developer needs a custom Apex controller method to return a filtered list of Opportunities for a Visualforce page. The method must respect the running user's record-level access so that users cannot see Opportunities they are not permitted to view. Which approach should the developer use?

⚠ Common exam trap

The trap here is conflating WITH SECURITY_ENFORCED with record-level sharing enforcement, when it only validates object and field permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Query with WITH USER_MODE so the query executes in the running user's context and respects sharing and permissions.

Running the SOQL with WITH USER_MODE executes the query in the running user's context, so object permissions, field-level security, and record-level sharing all apply automatically. This is the intended declarative mechanism for respecting a user's access in Apex. WITH SECURITY_ENFORCED covers only field and object permissions, an unqualified query runs in system mode and ignores sharing, and WITH SYSTEM_MODE deliberately bypasses access checks, so none of those options meet the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Query with WITH USER_MODE so the query executes in the running user's context and respects sharing and permissions.

    Why this is correct

    WITH USER_MODE runs the SOQL in the context of the running user, applying object permissions, field-level security, and record-level sharing rules. This is the modern, declarative way to ensure the query respects the user's access without manually checking each rule. It directly satisfies the requirement that users cannot see Opportunities they are not permitted to view, and it fails safely when access is insufficient.

  • ✗

    Query with WITH SECURITY_ENFORCED and rely on it to apply record-level sharing rules for the running user.

    Why it's wrong here

    WITH SECURITY_ENFORCED enforces field- and object-level permissions by throwing an error if the query references fields or objects the user cannot access. It does not apply record-level sharing rules, so a user could still receive rows they should not see based on sharing. Using it here gives a false sense of security because the scenario specifically requires record-level access enforcement.

  • ✗

    Query with WITH SYSTEM_MODE to guarantee access to all Opportunities, then rely on the Visualforce page's permissions to hide rows.

    Why it's wrong here

    WITH SYSTEM_MODE explicitly bypasses the running user's access checks, returning all rows the code can read. Visualforce page permissions control page and field visibility, not row-level filtering of a controller-returned collection, so the user could still receive unauthorized records through the controller. This is the opposite of what the scenario requires and would create a data exposure risk.

  • ✗

    Query normally without any mode clause and then filter the results in Apex using a manual sharing check.

    Why it's wrong here

    A query without a mode clause runs in system mode by default in Apex, so it returns rows regardless of the running user's sharing rules. Manually reimplementing sharing logic in Apex is error-prone and will drift from the platform's sharing model as roles, territories, and manual shares change. This approach risks exposing records the user should not see, which violates the scenario's requirement.

About these practice questions

This SF-PD2 question is part of Courseiva's 226-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Salesforce exam blueprint

This SF-PD2 practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-PD2 exam.