A (Field Audit Trail); D (Platform Encryption). This is the lowest-customization answer that still satisfies the business, security, and lifecycle requirements.
The Core Concept Explained: Public-sector implementations must treat confidentiality, auditability, and legal retention as architecture requirements. The control must be applied at the platform layer that actually prevents unauthorized access or processing.
Step-by-Step Technical Analysis: Classify the protected data first, then apply the least-privilege control at the correct layer: object access, sharing, field security, encryption, event monitoring, or audit retention. Validate the design with a real external or internal user profile and confirm that reporting and integrations do not bypass the intended restriction. Use Field Audit Trail and Platform Encryption. For exam preparation, validate the answer by tracing the record lifecycle, the user persona, and the automation owner from intake through reporting.
Why the Incorrect Options Are Wrong: B does not meet the implementation-quality bar for security, scale, auditability, or maintainability in this scenario. C does not meet the implementation-quality bar for security, scale, auditability, or maintainability in this scenario.
Submit