Free 2021 Salesforce Identity and Access Management Designer Identity-and-Access-Management-Designer dumps are available by NewPassLeader [Q16-Q35]

Share

Free 2021 Salesforce Identity and Access Management Designer Identity-and-Access-Management-Designer dumps are available on Google Drive shared by NewPassLeader

Welcome to download the newest NewPassLeader Identity-and-Access-Management-Designer PDF dumps: https://www.newpassleader.com/Salesforce/Identity-and-Access-Management-Designer-exam-preparation-materials.html ( 192  Q&As)

NEW QUESTION 16
A leading fitness tracker company is getting ready to launch a customer community. The company wants its customers to login to the community and connect their fitness device to their profile. Customers should be able to obtain exercise details and fitness recommendation In the community.
Which should be used to satisfy this requirement?

  • A. OAuth Device Plow
  • B. Named Credentials
  • C. Single Sign-On Settings
  • D. Login Flows

Answer: A

 

NEW QUESTION 17
The security team at Universal containers(UC) has identified exporting reports as a high-risk action and would like to require users to be logged into salesforce with their active directory (AD) credentials when doing so. For all other uses of Salesforce, Users should be allowed to use AD credentials or salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with salesforce credentials?

  • A. Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.
  • B. Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.
  • C. Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.
  • D. Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.

Answer: C

 

NEW QUESTION 18
Which three are features of federated Single sign-on solutions? Choose 3 Answers

  • A. It enables quick and easy provisioning and deactivating of users.
  • B. It establishes trust between Identity Store and Service Provider.
  • C. It federates credentials control to authorized applications.
  • D. It improves affiliated applications adoption rates.
  • E. It solves all identity and access management problems.

Answer: A,D,E

 

NEW QUESTION 19
Universal Containers wants to implement SAML SSO for their internal Salesforce users using a third-party IdP. After some evaluation, UC decides not to set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?

  • A. Neither SP- nor IdP-initiated SSO will work.
  • B. IdP-initiated SSO will not work.
  • C. SP-initiated SSO will not work.
  • D. Either SP- or IdP-initiated SSO will work.

Answer: A

 

NEW QUESTION 20
Universal containers (UC) does my domain enable in the context of a SAML SSO configuration? Choose 2 answers

  • A. Resource deep linking
  • B. App launcher
  • C. Login forensics
  • D. SSO from salesforce1 mobile app.

Answer: A,D

 

NEW QUESTION 21
Universal Containers (UC) has implemented a multi-org architecture in their company. Many users have licences across multiple orgs, and they are complaining about remembering which org and credentials are tied to which business process. Which two recommendations should the Architect make to address the Complaints? Choose 2 answers

  • A. Implement Delegated Authentication from each org to the LDAP provider.
  • B. Activate My Domain to Brand each org to the specific business use case.
  • C. Implement IdP-Initiated Single Sign-on flows to allow deep linking.
  • D. Implement SP-Initiated Single Sign-on flows to allow deep linking.

Answer: B,D

 

NEW QUESTION 22
In a typical SSL setup involving a trusted party and trusting party, what consideration should an Architect take into account when using digital certificates?

  • A. Use of self-signed certificate leads to higher maintenance for trusting party because the cert needs to be added to their truststore.
  • B. Use of self-signed certificate leads to lower maintenance for trusting party because there is no trusted CA cert to maintain.
  • C. Use of self-signed certificate leads to lower maintenance for trusted party because multiple self-signed certs need to be maintained.
  • D. Use of self-signed certificate leads to higher maintenance for trusted party because they have to act as the trusted CA

Answer: B

 

NEW QUESTION 23
Universal Containers uses Salesforce as an identity provider and Concur as the Employee Expense management system. The HR director wants to ensure Concur accounts for employees are created only after the appropnate approval in the Salesforce org.
Which three steps should the identity architect use to implement this requirement?
Choose 3 answers

  • A. Enable User Provisioning for the connected app.
  • B. Create an approval process for user object associated with the provisioning flow.
  • C. Create an approval process for UserProvisionlngRequest object associated with the provisioning flow.
  • D. Create an approval process for a custom object associated with the provisioning flow.
  • E. Create a connected app for Concur in Salesforce.

Answer: A,C,E

 

NEW QUESTION 24
Universal containers(UC) has decided to build a new, highly sensitive application on Force.com platform. The security team at UC has decided that they want users to provide a fingerprint in addition to username/Password to authenticate to this application. How can an architect support fingerprints as a form of identification for salesforce Authentication?

  • A. Use an appexchange product that does fingerprint scanning with native salesforce identity confirmation.
  • B. Use Delegated Authentication with callouts to a third-party fingerprint scanning application.
  • C. Use custom login flows with callouts to a third-party fingerprint scanning application.
  • D. Use salesforce Two-factor Authentication with callouts to a third-party fingerprint scanning application.

Answer: C

 

NEW QUESTION 25
Universal Containers (UC) has built a custom token-based Two-factor authentication (2FA) system for their existing on-premise applications. They are now implementing Salesforce and would like to enable a Two-factor login process for it, as well. What is the recommended solution as Architect should consider?

  • A. Use the custom 2FA system for on-premise applications and native 2FA for Salesforce.
  • B. Replace the custom 2FA system with an AppExchange App that supports on premise application and salesforce.
  • C. Use Custom Login Flows to connect to the existing custom 2FA system for use in Salesforce.
  • D. Replace the custom 2FA system with Salesforce 2FA for on-premise applications and Salesforce.

Answer: D

 

NEW QUESTION 26
A client is planning to rollout multi-factor authentication (MFA) to its internal employees and wants to understand which authentication and verification methods meet the Salesforce criteria for secure authentication.
Which three functions meet the Salesforce criteria for secure mfa?
Choose 3 answers

  • A. Certificate-based Authentication
  • B. Username and password + secunty key
  • C. username and password + SMS passcode
  • D. Lightning Login
  • E. Third-party single sign-on with Mobile Authenticator app

Answer: B,D,E

 

NEW QUESTION 27
Universal Containers (UC) is building an integration between Salesforce and a legacy web applications using the canvas framework. The security for UC has determined that a signed request from Salesforce is not an adequate authentication solution for the Third-Party app. Which two options should the Architect consider for authenticating the third-party app using the canvas framework? Choose 2 Answers

  • A. Utilize Authorization Providers to allow the third-party appliction to authenticate itself against Salesforce as the Idp.
  • B. Utilize the SAML Single Sign-on flow to allow the third-party to authenticate itself against UC's IdP.
  • C. Utilize Canvas OAuth flow to allow the third-party appliction to authenticate itself against Salesforce as the Idp.
  • D. Create a registration handler Apex class to allow the third-party appliction to authenticate itself against Salesforce as the Idp.

Answer: B,C

 

NEW QUESTION 28
Universal containers (UC) has implemented SAML SSO to enable seamless access across multiple applications. UC has regional salesforce orgs and wants it's users to be able to access them from their main Salesforce org seamless. Which action should an architect recommend?

  • A. Configure the main salesforce org as an Authentication provider.
  • B. Configure the main salesforce org as the Identity provider.
  • C. Configure the main Salesforce org as a service provider.
  • D. Configure the regional salesforce orgs as Identity Providers.

Answer: B

 

NEW QUESTION 29
Universal Containers (UC) has a mobile application for its employees that uses data from Salesforce as well as uses Salesforce for Authentication purposes. UC wants its mobile users to only enter their credentials the first time they run the app. The application has been live for a little over 6 months, and all of the users who were part of the initial launch are complaining that they have to re-authenticate. UC has also recently changed the URI Scheme associated with the mobile app. What should the Architect at UC first investigate?Universal Containers (UC) has a mobile application for its employees that uses data from Salesforce as well as uses Salesforce for Authentication purposes. UC wants its mobile users to only enter their credentials the first time they run the app. The application has been live for a little over 6 months, and all of the users who were part of the initial launch are complaining that they have to re-authenticate. UC has also recently changed the URI Scheme associated with the mobile app. What should the Architect at UC first investigate?

  • A. Check the Refresh Token policy defined in the Salesforce Connected App.
  • B. Confirm that the access Token's Time-To-Live policy has been set appropriately.
  • C. Verify that the Callback URL is correctly pointing to the new URI Scheme.
  • D. Validate that the users are checking the box to remember their passwords.

Answer: A

 

NEW QUESTION 30
Universal containers (UC) uses a legacy Employee portal for their employees to collaborate and post their ideas. UC decides to use salesforce ideas for voting and better tracking purposes. To avoid provisioning users on Salesforce, UC decides to push ideas posted on the Employee portal to salesforce through API. UC decides to use an API user using Oauth Username - password flow for the connection. How can the connection to salesforce be restricted only to the employee portal server?

  • A. Use a digital certificate signed by the employee portal Server.
  • B. Add the employee portals IP address to the login IP range on the user profile.
  • C. Use a dedicated profile for the user the Employee portal uses.
  • D. Add the Employee portals IP address to the Trusted IP range for the connected App

Answer: D

 

NEW QUESTION 31
The security team at Universal containers(UC) has identified exporting reports as a high-risk action and would like to require users to be logged into salesforce with their active directory (AD) credentials when doing so.
For all other uses of Salesforce, Users should be allowed to use AD credentials or salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with salesforce credentials?

  • A. Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.
  • B. Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.
  • C. Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.
  • D. Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.

Answer: C

 

NEW QUESTION 32
Universal Containers (UC) has implemented SAML-based SSO solution for use with their multi-org Salesforce implementation, utilizing one of the the orgs as the Identity Provider. One user is reporting that they can log in to the Identity Provider org but get a generic SAML error message when accessing the other orgs. Which two considerations should the architect review to troubleshoot the issue? Choose 2 answers

  • A. The Federation ID must be a valid Salesforce Username
  • B. The Federation ID must be in the form of an email address.
  • C. The Federation ID must is case sensitive
  • D. The Federation ID must be populated on the user record.

Answer: C,D

 

NEW QUESTION 33
Universal containers (UC) has decided to use salesforce as an identity provider for multiple external applications. UC wants to use the salesforce app launcher to control the apps that are available to individual users. Which three steps are required to make this happen?

  • A. Set up salesforce as a SAML IDP with my domain.
  • B. Create a connected App for each external application.
  • C. Add each connected App to the app launcher with a start URL
  • D. Set up an Auth provider for each external application.
  • E. Set up identity connect to synchronize user data.

Answer: A,B,C

 

NEW QUESTION 34
Universal containers (UC) is setting up Delegated Authentication to allow employees to log in using their corporate credentials. UC's security team is concerned about the risk of exposing the corporate login service on the Internet and has asked that a reliable trust mechanism be put in place between the login service and salesforce. What mechanism should an architect put in place to enable a trusted connection between the login services and salesforce?

  • A. Set up a proxy server for the login service in the DMZ.
  • B. Include client ID and client secret in the login header callout.
  • C. Enforce mutual Authentication between systems using SSL.
  • D. Require the use of Salesforce security Tokens on password.

Answer: D

 

NEW QUESTION 35
......

Tested Material Used To Identity-and-Access-Management-Designer: https://www.newpassleader.com/Salesforce/Identity-and-Access-Management-Designer-exam-preparation-materials.html

Following are some new Identity-and-Access-Management-Designer Real Exam Questions!: https://drive.google.com/open?id=1lWvLmgCqAPd-lj5bfaobiIBZSgdyjxOo