SF-PD2 Testing, Debugging, and Deployment Practice Question
Which TWO statements are true regarding the use of 'System.debug()' in a production environment?
⚠ Common exam trap
Candidates often assume System.debug statements are harmless in production, failing to realize they count against log file size limits and potentially expose sensitive data to unauthorized users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
They can expose sensitive information if not properly filtered.
System.debug() statements are generally discouraged in production because they consume log space and can inadvertently expose sensitive data. While they are useful for debugging, they should be removed or wrapped in conditional logic. Efficient log management is vital for maintaining high performance and ensuring that production environment overhead remains minimal during peak business hours and critical transactional windows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
They have no performance impact on the execution time of the transaction.
Why it's wrong here
While the impact is often negligible, generating large volumes of logs still consumes CPU time and I/O resources. In high-frequency transactional environments, excessive debug statements can cumulatively lead to performance degradation. Developers should always strive to keep production code clean of unnecessary debug statements to maintain optimal platform performance.
- ✓
They can expose sensitive information if not properly filtered.
Why this is correct
Debug statements are often written during development without considering security implications. If they log record contents that include PII or sensitive business data, those logs become a security risk when stored in Salesforce. Proper code reviews must ensure that no debug statements log sensitive information before being committed to production.
- ✗
They should always be left in the code to assist with future support cases.
Why it's wrong here
Leaving debug statements in production code is a bad practice that leads to cluttered logs, making it harder to find useful diagnostic information. Furthermore, it creates potential security vulnerabilities. Support cases should be handled via proper logging frameworks or by dynamically enabling debug logs only when a specific issue occurs.
- ✓
They count against the overall log file size limits.
Why this is correct
Salesforce has strict limits on the size of debug logs. Excessively verbose debug logs can quickly consume this allocation, leading to truncated logs that prevent proper root-cause analysis when an error actually occurs. Maintaining clean, concise logging is essential for effective production support and troubleshooting when issues arise in the wild.
- ✗
They are automatically stripped by the Salesforce compiler in production.
Why it's wrong here
The Salesforce compiler does not remove or strip System.debug() statements from your Apex code. They remain part of the compiled bytecode and will execute normally. The developer is solely responsible for ensuring that debug statements are removed or managed appropriately before code is deployed to the production org.
About these practice questions
One of 226 original SF-PD2 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Salesforce exam blueprint
This SF-PD2 practice question is part of Courseiva's free Salesforce certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SF-PD2 exam.