Apex
Apex security interview questions
Distinguish record sharing from object and field access, with API-version awareness.
By Vishal Verma · Reviewed October 5, 2026
Practice these questions aloud. Give the principle, explain a concrete example, and finish with how you would verify the result.
1. Does with sharing enforce field-level security?
Suggested answer: The sharing declaration concerns record access; it is not a substitute for checking object and field permissions. Review the class API version and database access mode. Current defaults can differ from older Apex code.
Scenario / follow-up: Avoid saying that every Apex class always runs with the same security defaults.
2. How can you enforce data access?
Suggested answer: Use suitable user-mode database operations where applicable, or explicit checks and Security.stripInaccessible when graceful field removal is required. Understand whether the operation fails or sanitizes data.
Scenario / follow-up: A UI must show accessible fields without exposing restricted values.
3. Why test with different users?
Suggested answer: Administrative success does not prove standard-user access. Test permitted and denied paths, including class access, record sharing, object access, and field restrictions.
Scenario / follow-up: Use realistic permissions and assert the intended access outcome.
Reviewed October 5, 2026. Check the linked documentation for your org’s API version and supported features.