The Best Salesforce Identity-and-Access-Management-Designer Study Guides and Dumps of 2023
Top Salesforce Identity-and-Access-Management-Designer Exam Audio Study Guide! Practice Questions Edition
NEW QUESTION 83
Universal containers (UC) wants to implement Delegated Authentication for a certain subset of Salesforce users. Which three items should UC take into consideration while building the Web service to handle the Delegated Authentication request? Choose 3 answers
- A. The web service can be written using either the soap or rest protocol.
- B. The return type of the Web service method should be a Boolean value
- C. UC should whitelist all salesforce ip ranges on their corporate firewall.
- D. The web service needs to include Source IP as a method parameter.
- E. Delegated Authentication is enabled for the system administrator profile.
Answer: B,C,D
NEW QUESTION 84
architect is troubleshooting some SAML-based SSO errors during testing. The Architect confirmed that all of the Salesforce SSO settings are correct. Which two issues outside of the Salesforce SSO settings are most likely contributing to the SSO errors the Architect is encountering? Choose 2 Answers
- A. The default language for the Identity Provider and Salesforce are Different.
- B. The Issuer Certificate from the Identity Provider expired two weeks ago.
- C. The clock on the Identity Provider server is twenty minutes behind Salesforce.
- D. The Identity Provider is also used to SSO into five other applications.
Answer: B,C
NEW QUESTION 85
Universal containers (UC) has multiple salesforce orgs and would like to use a single identity provider to access all of their orgs. How should UC'S architect enable this behavior?
- A. Ensure that users have the same Federation ID value in their user records in all of UC's salesforce orgs.
- B. Ensure that users have the same email value in their user records in all of UC's salesforce orgs.
- C. Ensure the same username is allowed in multiple orgs by contacting salesforce support.
- D. Ensure that users have the same alias value in their user records in all of UC's salesforce orgs.
Answer: A
NEW QUESTION 86
Universal containers (UC) wants users to authenticate into their salesforce org using credentials stored in a custom identity store. UC does not want to purchase or use a third-party Identity provider. Additionally, UC is extremely wary of social media and does not consider it to be trust worthy. Which two options should an architect recommend to UC? Choose 2 answers
- A. Use a professional social media such as LinkedIn as an Authentication provider
- B. Build a custom Web service that is supported by Delegated Authentication.
- C. Implement the Openid protocol and configure an Authentication provider
- D. Build a custom web page that uses the identity store and calls frontdoor.jsp
Answer: B,C
NEW QUESTION 87
Universal Containers wants to allow its customers to log in to its Experience Cloud via a third party authentication provider that supports only the OAuth protocol.
What should an identity architect do to fulfill this requirement?
- A. Configure OpenID Connect authentication provider.
- B. Use certificate-based authentication.
- C. Create a custom external authentication provider.
- D. Contact Salesforce Support and enable delegate single sign-on.
Answer: C
NEW QUESTION 88
Universal Containers (UC) wants to integrate a third-party Reward Calculation system with Salesforce to calculate Rewards. Rewards will be calculated on a schedule basis and update back into Salesforce. The integration between Salesforce and the Reward Calculation System needs to be secure. Which are two recommended practices for using OAuth flow in this scenario. choose 2 answers
- A. OAuth Refresh Token FLow
- B. OAuth SAML Bearer Assertion FLow
- C. OAuth JWT Bearer Token FLow
- D. OAuth Username-Password Flow
Answer: C,D
NEW QUESTION 89
A company wants to provide its employees with a custom mobile app that accesses Salesforce. Users are required to download the internal native IOS mobile app from corporate intranet on their mobile device. The app allows flexibility to access other Non Salesforce internal applications once users authenticate with Salesforce. The apps self-authorize, and users are permitted to use the apps once they have logged into Salesforce.
How should an identity architect meet the above requirements with the privately distributed mobile app?
- A. Create a new hybrid mobile app and use the connected app with OAuth to authenticate users for Salesforce and non-Salesforce internal apps.
- B. Use Salesforce as an identity provider (IdP) to access the mobile app and use the external IdP for other non-Salesforce internal apps.
- C. Use connected app with OAuth and Security Assertion Markup Language (SAML) to access other Non Salesforce internal apps.
- D. Configure Mobile App settings in connected app and Salesforce as identity provider for non-Salesforce internal apps.
Answer: D
NEW QUESTION 90
Universal Containers (UC) is successfully using Delegated Authentication for their Salesforce users. The service supporting Delegated Authentication is written in Java. UC has a new CIO that is requiring all company web services be REST-ful and written in .Net.
Which two considerations should the UC Architect provide to the new CIO? (Choose two.)
- A. Delegated Authentication will not work with REST services.
- B. Delegated Authentication will not work with a .Net service.
- C. Delegated Authentication will continue to work with REST services.
- D. Delegated Authentication will continue to work with a .Net service.
Answer: A,D
NEW QUESTION 91
Universal containers (UC) built a customer Community for customers to buy products, review orders, and manage their accounts. UC has provided three different options for customers to log in to the customer Community: salesforce, Google, and Facebook. Which two role combinations are represented by the systems in the scenario? Choose 2 answers
- A. Google is the service provider and Facebook is the identity provider
- B. Salesforce is the service provider and Google is the identity provider
- C. Salesforce is the service provider and Facebook is the identity provider
- D. Facebook is the service provider and salesforce is the identity provider
Answer: B,C
NEW QUESTION 92
Universal containers (UC) has an e-commerce website while customers can buy products, make payments, and manage their accounts. UC decides to build a customer Community on Salesforce and wants to allow the customers to access the community for their accounts without logging in again. UC decides to implement ansp-Initiated SSO using a SAML-BASED complaint IDP. In this scenario where salesforce is the service provider, which two activities must be performed in salesforce to make sp-Initiated SSO work? Choose 2 answers
- A. Create a connected App
- B. Configure SAML SSO settings.
- C. Configure Delegated Authentication
- D. Set up my domain
Answer: B,D
NEW QUESTION 93
Universal Containers (UC) has implemented SAML-based Single Sign-On to provide seamless access to its Salesforce Orgs, financial system, and CPQ system. Below is the SSO implementation landscape.
What role combination is represented by the systems in this scenario''
- A. Salesforce Org1 and PingFederate are acting as Identity Providers.
- B. Salesforce Org1 and Salesforce Org2 are acting as Identity Providers.
- C. Salesforce Org1 and Salesforce Org2 are the only Service Providers.
- D. Financial System and CPQ System are the only Service Providers.
Answer: A
NEW QUESTION 94
After a recent audit, universal containers was advised to implement Two-factor Authentication for all of their critical systems, including salesforce. Which two actions should UC consider to meet this requirement? Choose 2 answers
- A. Require users to enter a second password after the first Authentication
- B. Require users to provide their RSA token along with their credentials.
- C. Require users to supply their email and phone number, which gets validated.
- D. Require users to use a biometric reader as well as their password
Answer: B,D
NEW QUESTION 95
Northern Trail Outfitters (NTO) wants its customers to use phone numbers to log in to their new digital portal, which was designed and built using Salesforce Experience Cloud. In order to access the portal, the user will need to do the following:
1. Enter a phone number and/or email address
2. Enter a verification code that is to be sent via email or text.
What is the recommended approach to fulfill this requirement?
- A. Create a Login Discovery page and provide a Login Discovery Handler Apex class.
- B. Create a custom login flow that uses an Apex controller to verify the phone numbers with the company's verification service.
- C. Create an Authentication provider and implement a self-registration handler class.
- D. Create a custom login page with an Apex controller. The controller has logic to send and verify the identity.
Answer: A
NEW QUESTION 96
Northern Trail Outfitters (NTO) leverages Microsoft Active Directory (AD) for management of employee usernames, passwords, permissions, and asset access. NTO also owns a third-party single sign-on (SSO) solution. The third-party party SSO solution is used for all corporate applications, including Salesforce.
NTO has asked an architect to explore Salesforce Identity Connect for automatic provisioning and deprovisiorung of users in Salesforce.
What role does identity Connect play in the outlined requirements?
- A. Service Provider
- B. Single Sign-On
- C. Identity Provider
- D. User Management
Answer: D
NEW QUESTION 97
Universal Containers (UC) uses Salesforce to allow customers to keep track of the order status. The customers can log in to Salesforce using external authentication providers, such as Facebook and Google. UC is also leveraging the App Launcher to let customers access an of platform application for generating shipping labels. The label generator application uses OAuth to provide users access. What license type should an Architect recommend for the customers?
- A. Identity license
- B. Customer Community Plus license
- C. External Identity license
- D. Customer Community license
Answer: A
NEW QUESTION 98
Universal Containers (UC) implemented SSO to a third-party system for their Salesforce users to access the App Launcher. UC enabled "User Provisioning" on the Connected App so that changes to user accounts can be synched between Salesforce and the third party system. However, UC quickly notices that changes to user roles in Salesforce are not getting synched to the third-party system. What is the most likely reason for this behaviour?
- A. User Provisioning for Connected Apps does not support role sync.
- B. Salesforce roles have more than three levels in the role hierarchy.
- C. Required operation(s) was not mapped in User Provisioning Settings.
- D. The Approval queue for User Provisioning Requests is unmonitored.
Answer: A
NEW QUESTION 99
Universal Containers (UC) uses a home-grown Employee portal for their employees to collaborate. UC decides to use Salesforce Ideas to allow the employees to post ideas from the Employee portal. When clicking some links in the Employee portal, the users should be redirected to Salesforce, authenticated, and presented with relevant pages.
What scope should be requested when using the OAuth token to meet this requirement?
- A. web
- B. full
- C. Visualforce
- D. api
Answer: A
Explanation:
Explanation
NEW QUESTION 100
How should an Architect force users to authenticate with Two-factor Authentication (2FA) for Salesforce only when NOT connected to an internal company network?
- A. Add the company's list of network IP addresses to the Login Range list under 2FA Setup.
- B. Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA if needed.
- C. Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.
- D. Apply the "Two-factor Authentication for User Interface Logins" permission and Login IP Ranges for all Profiles.
Answer: B
NEW QUESTION 101
A manufacturer wants to provide registration for an Internet of Things (IoT) device with limited display input or capabilities.
Which Salesforce OAuth authorization flow should be used?
- A. OAuth 2.0 Asset Token Flow
- B. OAuth 2.0 Device Flow
- C. OAuth 2.0 User-Agent Flow
- D. OAuth 2.0 JWT Bearer How
Answer: B
NEW QUESTION 102
Northern Trail Outfitters (NTO) has an existing custom business-to-consumer (B2C) website that does NOT support single sign-on standards, such as Security Assertion Markup Language (SAMi) or OAuth. NTO wants to use Salesforce Identity to register and authenticate new customers on the website.
Which two Salesforce features should an identity architect use in order to provide username/password authentication for the website?
Choose 2 answers
- A. Connected Apps
- B. Delegated Authentication
- C. Embedded Login
- D. Identity Connect
Answer: B,C
NEW QUESTION 103
Universal Containers (UC) is building an integration between Salesforce and a legacy web applications using the canvas framework. The security for UC has determined that a signed request from Salesforce is not an adequate authentication solution for the Third-Party app. Which two options should the Architect consider for authenticating the third-party app using the canvas framework? Choose 2 Answers
- A. UtilizeAuthorization Providers to allow the third-party appliction to authenticate itself against Salesforce as the Idp.
- B. Utilize Canvas OAuth flow to allow the third-party appliction to authenticate itself against Salesforce as the Idp.
- C. Create a registration handler Apex class to allow the third-party appliction to authenticate itself against Salesforce as the Idp.
- D. Utilize the SAML Single Sign-on flow to allow the third-party to authenticate itself against UC's IdP.
Answer: B,D
NEW QUESTION 104
Universal containers (UC) has decided to use salesforce as an identity provider for multiple external applications. UC wants to use the salesforce app launcher to control the apps that are available to individual users. Which three steps are required to make this happen?
- A. Create a connected App for each external application.
- B. Set up an Auth provider for each external application.
- C. Add each connected App to the app launcher with a start URL
- D. Set up salesforce as a SAML IDP with my domain.
- E. Set up identity connect to synchronize user data.
Answer: A,C,D
NEW QUESTION 105
Universal Containers (UC) is both a Salesforce and Google Apps customer. The UC IT team would like to manage the users for both systems in a single place to reduce administrative burden.
Which two recommended ways can the IT team provision users and allow Single Sign-on between Salesforce and Google Apps? (Choose two.)
- A. Build a custom app running on Heroku as the Identity Provider that can sync user information between Salesforce and Google Apps.
- B. Use a third-party product as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
- C. Use Salesforce as the Identity Provider and Google Apps as a Service Provider and configure User Provisioning for Connected Apps.
- D. Use Identity Connect as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
Answer: B,C
NEW QUESTION 106
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers will utilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?
- A. Use SAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
- B. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
- C. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML to allow SSO.
- D. Use a nightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
Answer: C
NEW QUESTION 107
......
Valid Identity-and-Access-Management-Designer Exam Updates - 2023 Study Guide: https://www.newpassleader.com/Salesforce/Identity-and-Access-Management-Designer-exam-preparation-materials.html
Identity-and-Access-Management-Designer Certification - The Ultimate Guide: https://drive.google.com/open?id=1Ju39PMqAJyCKh4kMBZjTETPVPH-gfkTT