
Latest Identity-and-Access-Management-Designer Study Guides 2023 - With Test Engine PDF
Get New Identity-and-Access-Management-Designer Practice Test Questions Answers
NEW QUESTION # 99
Which two capabilities does My Domain enable in the context of a SAML SSO configuration? Choose 2 answers
- A. Login Forensics
- B. SSO from Salesforce Mobile App
- C. Resource deep linking
- D. App Launcher
Answer: B
NEW QUESTION # 100
Universal Containers (UC) would like to enable SAML based SSO for a Salesforce Partner Community. UC has an existing LDAP identity store and a third-party portal. They would like to use the existing portal as the primary site these users access, but also want to allow seamless access to the partner community. What SSO flow should an Architect recommend?
- A. User- Agent.
- B. SP-Initiated.
- C. Idp-Initiated.
- D. Web Server.
Answer: B
NEW QUESTION # 101
Universal Containers (UC) is implementing Salesforce and would like to establish SAML SSO for its users to log in. UC stores its corporate user identities in a Custom Database. The UC IT Manager has heard good things about Salesforce Identity Connect as an Idp, and would like to understand what limitations they may face if they decided to use Identity Connect in their current environment. What limitation Should an Architect inform the IT Manager about?
- A. Identity connect is not compatible with UC's current identity environment.
- B. Identity Connect will only support SP-initiated SAML flows in UC's current environment.
- C. Identity Connect will only support Idp-initiated SAML flows in UC's current environment.
- D. Identity Connect will not support user provisioning in UC's current environment.
Answer: D
NEW QUESTION # 102
Universal containers (UC) is concerned that having a self-registration page will provide a means for "bots" or unintended audiences to create user records, thereby consuming licences and adding dirty dat a. Which two actions should UC take to prevent unauthorised form submissions during the self-registration process? Choose 2 answers
- A. Use hidden fields populated via java script events in the self-registration page.
- B. Primarily use lookup and picklist fields on the self registration page.
- C. Use open-ended security questions and complex password requirements
- D. Require a captcha at the end of the self-registration process.
Answer: A,D
NEW QUESTION # 103
A security architect is rolling out a new multi-factor authentication (MFA) mandate, where all employees must go through a secure authentication process before accessing Salesforce. There are multiple Identity Providers (IdP) in place and the architect is considering how the "Authentication Method Reference" field (AMR) in the Login History can help.
Which two considerations should the architect keep in mind?
Choose 2 answers
- A. AMR field shows the authentication methods used at IdP.
- B. Dependency on what is supported by OpenID Connect (OIDC) implementation at IdP.
- C. High-assurance sessions must be configured under Session Security Level Policies.
- D. Both OIDC and Security Assertion Markup Language (SAML) are supported but AMR must be implemented at IdP.
Answer: A,D
NEW QUESTION # 104
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers will utilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?
- A. Use a nightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
- B. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
- C. Use SAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
- D. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML to allow SSO.
Answer: D
NEW QUESTION # 105
Uwversal Containers (UC) is building a custom employee hut) application on Amazon Web Services (AWS) and would like to store their users' credentials there. Users will also need access to Salesforce for internal operations. UC has tasked an identity architect with evaluating Afferent solutions for authentication and authorization between AWS and Salesforce.
How should an identity architect configure AWS to authenticate and authorize Salesforce users?
- A. Configure AWS as an OpenID Connect Provider.
- B. Create a custom external authentication provider.
- C. Develop a custom Auth server in AWS.
- D. Configure the custom employee app as a connected app.
Answer: A
NEW QUESTION # 106
Universal Containers (UC) is building an integration between Salesforce and a legacy web application using the Canvas framework. The security team for UC has determined that a signed request from Salesforce is not an adequate authentication solution for the third-party app. Which two options should the Architect consider for authenticating the third-party app using the Canvas framework? Choose 2 answers
- A. Utilize the SAML Single Sign-on flow to allow the third-party to authenticate itself against UC's IdP.
- B. Utilize Authorization Providers to allow the third-party application to authenticate itself against Salesforce as the IdP.
- C. Utilize the Canvas OAuth flow to allow the third-party application to authenticate itself against Salesfore as the IdP
- D. Create a registration handler Apex class to allow the third-party application to authenticate itself against Salesforce as the IdP.
Answer: A,C
NEW QUESTION # 107
Universal Containers uses Salesforce as an identity provider and Concur as the Employee Expense management system. The HR director wants to ensure Concur accounts for employees are created only after the appropnate approval in the Salesforce org.
Which three steps should the identity architect use to implement this requirement?
Choose 3 answers
- A. Create an approval process for UserProvisionlngRequest object associated with the provisioning flow.
- B. Enable User Provisioning for the connected app.
- C. Create an approval process for user object associated with the provisioning flow.
- D. Create an approval process for a custom object associated with the provisioning flow.
- E. Create a connected app for Concur in Salesforce.
Answer: A,B,E
NEW QUESTION # 108
How should an identity architect automate provisioning and deprovisioning of users into Salesforce from an external system?
- A. Use Security Assertion Markup Language Just-in-Time (SAML JIT) on incoming SAML assertions.
- B. Call SOAP API upsertQ on user object.
- C. Run registration handler on incoming OAuth responses.
- D. Call OpenID Connect (OIDC)-userinfo endpoint with a valid access token.
Answer: C
NEW QUESTION # 109
The security team at Universal Containers (UC) has identified exporting reports as a high-risk action and would like to require users to be logged into Salesforce with their Active Directory (AD) credentials when doing so. For all other users of Salesforce, users should be allowed to use AD Credentials or Salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with Salesforce credentials?
- A. Use SAML Federated Authentication and block access to reports when accessed through a Standard Assurance session.
- B. Use SAML federated Authentication with a Login Flow to dynamically add or remove a Permission Set that grants the Export Reports Permission.
- C. Use SAML Federated Authentication and Custom SAML JIT Provisioning to dynamically and or remove a permission set that grants the Export Reports Permission.
- D. Use SAML federated Authentication, treat SAML Sessions as High Assurance, and raise the session level required for exporting reports.
Answer: A
NEW QUESTION # 110
Which three are features of federated Single sign-on solutions? Choose 3 Answers
- A. It federates credentials control to authorized applications.
- B. It solves all identity and access management problems.
- C. It enables quick and easy provisioning and deactivating of users.
- D. It improves affiliated applications adoption rates.
- E. It establishes trust between Identity Store and Service Provider.
Answer: B,C,D
NEW QUESTION # 111
The CIO of Universal Containers (UC) wants to start taking advantage of the refresh token capability for the UC applications that utilize OAuth 2.0. UC has enlisted an Architect to analyze all of the applications that use OAuth flows to see where refresh tokens can be applied.
Which two OAuth flows should the Architect consider in their evaluation? (Choose two.)
- A. User-Agent
- B. Web Server
- C. JWT Bearer Token
- D. Username-Password
Answer: A,B
Explanation:
Explanation/Reference:
NEW QUESTION # 112
Universal containers wants salesforce inbound Oauth-enabled integration clients to use SAML-BASED single Sign-on for authentication. What Oauth flow would be recommended in this scenario?
- A. User-Token Oauth flow
- B. SAML assertion Oauth flow
- C. Web server Oauth flow
- D. User-Agent Oauth flow
Answer: B
NEW QUESTION # 113
Universal Containers (UC) wants to build a few applications that leverage the Salesforce REST API. UC has asked its Architect to describe how the API calls will be authenticated to a specific user. Which two mechanisms can the Architect provide? Choose 2 Answers
- A. Authentication Token
- B. Access Token
- C. Session ID
- D. Refresh Token
Answer: B,D
NEW QUESTION # 114
Which two are valid choices for digital certificates when setting up two-way SSL between Salesforce and an external system. Choose 2 answers
- A. Use a self-signed certificate for salesforce and a trusted CA-signed cert for the external system
- B. Use a trusted CA-signed certificate for salesforce and a self-signed cert for the external system
- C. Use a self-signed certificate for salesforce and a self-signed cert for the external system
- D. Use a trusted CA-signed certificate for salesforce and a trusted CA-signed cert for the external system
Answer: A,C
NEW QUESTION # 115
A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APAC. The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS . The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.
What is recommended to ensure these requirements are met ?
- A. Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.
- B. Add a central identity system that federates between the ADFS systems and integrate with Salesforce for single sign-on.
- C. Configure Each ADFS system under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce-
- D. Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.
Answer: D
NEW QUESTION # 116
Universal Containers (UC) has a Customer Community that uses Facebook for Authentication. UC would like to ensure that Changes in the Facebook profile are reflected on the appropriate Customer Community user:
How can this requirement be met?
- A. Develop a scheduled job that calls out to Facebook on a nightly basis.
- B. Use the updateUser method on the registration Handler Class.
- C. Use SAML Just-In-Time Provisioning between Facebook and Salesforce.
- D. Use information in the signed Request that is received from facebook.
Answer: B
NEW QUESTION # 117
Universal Containers (UC) wants to build a custom mobile app for their field reps to create orders in salesforce. After the first time the users log in, they must be able to access salesforce upon opening the mobile app without being prompted to log in again. What Oauth flows should be considered to support this requirement?
- A. SAML Assertion flow with a Bearer Token.
- B. Web Server flow with a Refresh Token.
- C. User Agent flow with a Refresh Token.
- D. Mobile Agent flow with a Bearer Token.
Answer: C
NEW QUESTION # 118
In an SP-Initiated SAML SSO setup where the user tries to access a resource on the Service Provider, What HTTP param should be used when submitting a SAML Request to the Idp to ensure the user is returned to the intended resourse after authentication?
- A. DisplayState
- B. RedirectURL
- C. StartURL
- D. RelayState
Answer: D
NEW QUESTION # 119
Universal Containers (UC) is building an authenticated Customer Community for its customers. UC does not want customer credentials stored in Salesforce and is confident its customers would be willing to use their social media credentials to authenticate to the community. Which two actions should an Architect recommend UC to take?
- A. Use Delegated Authentication to call the Twitter login API to authenticate users.
- B. Configure an Authentication Provider for LinkedIn Social Media Accounts.
- C. Configure SSO Settings For Facebook to serve as a SAML Identity Provider.
- D. Create a Custom Apex Registration Handler to handle new and existing users.
Answer: B,D
NEW QUESTION # 120
Universal Containers is using OpenID Connect to enable a connection from their new mobile app to its production Salesforce org.
What should be done to enable the retrieval of the access token status for the OpenID Connect connection?
- A. A Leverage OpenID Connect Token Introspection.
- B. Enable cross-origin resource sharing (CORS) for the /services/oauth2/token endpoint.
- C. Create a custom OAuth scope.
- D. Query using OpenID Connect discovery endpoint.
Answer: A
NEW QUESTION # 121
......
Salesforce Certified Identity and Access Management Designer certification exam consists of 60 multiple-choice questions that must be completed within 120 minutes. Identity-and-Access-Management-Designer exam covers a variety of topics related to identity and access management in Salesforce, including access control and authentication, user provisioning and deprovisioning, security and compliance, and identity federation. Candidates are required to demonstrate their understanding of these topics and their ability to apply best practices to design and implement effective identity and access management solutions in Salesforce.
Identity-and-Access-Management-Designer Dumps and Exam Test Engine: https://passitsure.itcertmagic.com/Salesforce/real-Identity-and-Access-Management-Designer-exam-prep-dumps.html