1. Case Teams: Salesforce Help, "Set Up Case Teams."
Section: "Case Team Roles" and "Add a Case Team." The documentation states, "Case teams help groups of people work together to solve cases... When you set up case teams, you can create roles to determine each team member’s level of access to a case, such as Read/Write or Read-Only." This directly supports using Case Teams for differentiated record-level access.
2. Field-Level Security: Salesforce Help, "Field-Level Security."
Section: "Set Field-Level Security for a Single Field on a Profile" or "Set Field Permissions in Permission Sets." The documentation explains, "Field-level security settings let you restrict what fields users can view and edit based on their profiles and permission sets." This confirms FLS is the correct mechanism for controlling visibility of the PII field.
3. Object Permissions: Salesforce Help, "Object Permissions."
Section: "Standard Object Permissions." The documentation clarifies that the "View All" permission on an object allows a user to "View all records associated with this object, regardless of sharing settings." This highlights why option A is incorrect, as it's a broad permission, not a record-specific one.
4. Salesforce Shield: Salesforce Help, "Salesforce Shield."
Section: "Platform Encryption." The documentation specifies, "Shield Platform Encryption gives your data a whole new layer of security while preserving critical platform functionality. It enables you to encrypt sensitive data at rest..." This confirms that Shield's purpose is encryption, not controlling UI visibility, making option C incorrect.