ある非営利団体は、Salesforceのデータセキュリティに関するベストプラクティスに完全に準拠することを目指しており、コンサルタントに評価を依頼しました。コンサルタントは、この評価を行うためにどのツールを使用すべきでしょうか?
正解:A
To provide a comprehensive assessment of data security best practices, the consultant should use the native Salesforce Health Check.
What Salesforce Health Check provides:
* Security Baseline: It compares the organization's current security settings against the Salesforce Recommended Baseline.
* Scoring: It provides an overall "Health Score" (0-100%).
* Specific Evaluations: It analyzes critical security settings, including:
* Password Policies: Complexity, expiration, and lockout settings.
* Session Settings: Timeout values and whether "secure cookies" are required.
* Network Security: IP ranges and multi-factor authentication requirements.
* File Settings: Restrictions on file types and downloads.
* Actionable Advice: For every setting that does not meet the baseline, it provides a "Fix It" link or instructions on how to bring the setting into compliance.
Why other options are incorrect:
* Salesforce Optimizer (Option C): This is a general "maintenance" tool. It checks for unused fields, limits, and technical debt. While it has some security checks, it is not a dedicated security assessment tool.
* NPSP Health Check (Option D): This is specifically for data integrity within NPSP (e.g., checking if rollups are working or if households have addresses). It does not evaluate the underlying Salesforce platform security settings.
* Shield (Option B): This is a product (a set of security features) you can buy, not an assessment tool to evaluate current compliance.