Identity-and-Access-Management-Designer Exam Practice Questions prepared by Salesforce Professionals [Q11-Q27]

Share

Identity-and-Access-Management-Designer Exam Practice Questions prepared by Salesforce Professionals

Use Valid New Identity-and-Access-Management-Designer Questions - Top choice Help You Gain Success

NEW QUESTION # 11
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to 65 set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?

  • A. IdP-initiated SSO will NOT work.
  • B. Either SP- or IdP-initiated SSO will work.
  • C. SP-initiated SSO will NOT work
  • D. Neither SP- nor IdP-initiated SSO will work.

Answer: D


NEW QUESTION # 12
Northern Trail Outfitters (NTO) uses the Customer 360 Platform implemented on Salesforce Experience Cloud. The development team in charge has learned of a contactless user feature, which can reduce the overhead of managing customers and partners by creating users without contact information.
What is the potential impact to the architecture if NTO decides to implement this feature?

  • A. If contactless user is upgraded to Community license, the contact record is automatically created and linked to the user record, but not associated with an Account.
  • B. Custom registration handler is needed to correctly assign External Identity or Community license for the newly registered contactless user.
  • C. Contactless user feature is available only with the External Identity license, which can restrict the Experience Cloud functionality available to the user.
  • D. Passwordless authentication can not be supported because the mobile phone receiving one-time password (OTP) needs to match the number on the contact record.

Answer: C


NEW QUESTION # 13
Universal Containers (UC) has built a custom time tracking app for its employee. UC wants to leverage Salesforce Identity to control access to the custom app.
At a minimum, which Salesforce license is required to support this requirement?

  • A. Identity Only
  • B. External Identity
  • C. Identity Connect
  • D. Identity Verification

Answer: A


NEW QUESTION # 14
Universal containers wants to implement single Sign-on for a salesforce org using an external identity provider and corporate identity store. What type of Authentication flow is required to support deep linking?

  • A. Service-provider-initiated SSO
  • B. Start URL on identity provider
  • C. Identity-provider-initiated SSO
  • D. Web server Oauth SSO flow.

Answer: A


NEW QUESTION # 15
Universal containers (UC) uses a legacy Employee portal for their employees to collaborate and post their ideas. UC decides to use salesforce ideas for voting and better tracking purposes. To avoid provisioning users on Salesforce, UC decides to push ideas posted on the Employee portal to salesforce through API. UC decides to use an API user using Oauth Username - password flow for the connection. How can the connection to salesforce be restricted only to the employee portal server?

  • A. Add the Employee portals IP address to the Trusted IP range for the connected App
  • B. Use a digital certificate signed by the employee portal Server.
  • C. Add the employee portals IP address to the login IP range on the user profile.
  • D. Use a dedicated profile for the user the Employee portal uses.

Answer: A


NEW QUESTION # 16
An Enterprise is using a Lightweight Directory Access Protocol (LDAP ) server as the only point for user authentication with a username/password. Salesforce delegated authentication is configured to integrate Salesforce under single sign-on (SSO).
Mow can end users change their password?

  • A. Users once logged In, can go to the Change Password screen in Salesforce.
  • B. Users can change it on the enterprise LDAP authentication portal.
  • C. Users can click on the "Forgot your Password" link on the Salesforce.com login page.
  • D. Users can request the Salesforce Admin to reset their password.

Answer: D


NEW QUESTION # 17
Universal Containers (UC) has implemented a multi-org architecture in their company. Many users have licenses across multiple orgs, and they are complaining about remembering which org and credentials are tied to which business process.
Which two recommendations should the Architect make to address the complaints? (Choose two.)

  • A. Activate My Domain to brand each org to the specific business use case.
  • B. Implement IdP-Initiated Single Sign-on flows to allow deep linking.
  • C. Implement Delegated Authentication from each org to the LDAP provider.
  • D. Implement SP-Initiated Single Sign-on flows to allow deep linking.

Answer: A,D


NEW QUESTION # 18
Universal Containers is implementing Salesforce Identity to broker authentication from its enterprise single sign-on (SSO) solution through Salesforce to third party applications using SAML.
What rote does Salesforce Identity play in its relationship with the enterprise SSO system?

  • A. Service Provider (SP)
  • B. Resource Server
  • C. Identity Provider (IdP)
  • D. Client Application

Answer: A


NEW QUESTION # 19
Universal Containers (UC) uses an internal company portal for their employees to collaborate. UC decides to use Salesforce Ideas and provide the ability for employees to post ideas from the company portal. They use SAML-based SSO to get into the Company portal and would like to leverage it to access Salesforce.
Most of the users don't exist in Salesforce and they would like the user records created in Salesforce Communities the first time they try to access Salesforce.
What recommendation should an Architect make to meet this requirement?

  • A. Use Identity Connect to sync users.
  • B. Use On-the-Fly provisioning.
  • C. Use Just-in-Time provisioning.
  • D. Use Salesforce APIs to create users on the fly.

Answer: C


NEW QUESTION # 20
Which three capabilities does SAML-based Federated authentication provide? (Choose three.)

  • A. Web applications with no passwords are more secure and stronger against hacks.
  • B. Centralized federation provides single point of access, control and auditing.
  • C. SAML tokens can be in XML or JSON format and can be used interchangeably.
  • D. Access tokens are used to access resources on the server once the user is authenticated.
  • E. Trust relationships between Identity Provider and Service Provider are required.

Answer: B,D,E


NEW QUESTION # 21
An identity architect's client has a homegrown identity provider (IdP). Salesforce is used as the service provider (SP). The head of IT is worried that during a SP initiated single sign-on (SSO), the Security Assertion Markup Language (SAML) request content will be altered.
What should the identity architect recommend to make sure that there is additional trust between the SP and the IdP?

  • A. Ensure that there is an HTTPS connection between IDP and SP.
  • B. Encrypt the SAML Request using certification authority (CA) signed certificate and decrypt on IdP.
  • C. Ensure that on the SSO settings page, the "Request Signing Certificate" field has a self-signed certificate.
  • D. Ensure that the Issuer and Assertion Consumer service (ACS) URL is property configured between SP and IDP.

Answer: B


NEW QUESTION # 22
Universal Containers (UC) uses Active Directory (AD) as their identity store for employees and must continue to do so for network access. UC is undergoing a major transformation program and moving all of their enterprise applications to cloud platforms including Salesforct, Workday, and SAP HANA.
UC needs to implement an SSO solution for accessing all of the third-party cloud applications and the CIO is inclined to use Salesforce for all of their identity and access management needs.
Which two Salesforce license types does UC need for its employees'
Choose 2 answers

  • A. Company Community and Identity licenses
  • B. Identity and Identity Connect licenses
  • C. Chatter Only and Identity licenses
  • D. Salesforce and Identity Connect licenses

Answer: B,D


NEW QUESTION # 23
Sales users at Universal containers use salesforce for Opportunity management. Marketing uses a third-party application called Nest for Lead nurturing that is accessed using username/password. The VP of sales wants to open up access to nest for all sales uses to provide them access to lead history and would like SSO for better adoption. Salesforce is already setup for SSO and uses Delegated Authentication. Nest can accept username/Password or SAML-based Authentication. IT teams have received multiple password-related issues for nest and have decided to set up SSO access for Nest for Marketing users as well. The CIO does not want to invest in a new IDP solution and is considering using Salesforce for this purpose. Which are appropriate license type choices for sales and marketing users, giving salesforce is using Delegated Authentication? Choose 2 answers

  • A. Salesforce license for sales users and Identity license for Marketing users
  • B. Salesforce license for sales users and External Identity license for Marketing users
  • C. Identity license for sales users and Identity connect license for Marketing users
  • D. Salesforce license for sales users and platform license for Marketing users.

Answer: A,D


NEW QUESTION # 24
Universal Containers wants to set up SSO for a selected group of users to access external applications from Salesforce through App Launcher.
Which three steps must be completed in Salesforce to accomplish the goal? (Choose three.)

  • A. Associate User profiles with the Connected Apps.
  • B. Create Connected Apps for the external applications.
  • C. Create Named Credentials for each external system.
  • D. Complete Single Sign-on Settings in Security Controls.
  • E. Complete My Domain and Identity Provider setup.

Answer: A,D,E

Explanation:
Explanation/Reference:


NEW QUESTION # 25
Universal Containers (UC) is building an authenticated Customer Community for its customers. UC does not want customer credentials stored in Salesforce and is confident its customers would be willing to use their social media credentials to authenticate to the Community.
Which two actions should an Architect recommend UC to take? (Choose two.)

  • A. Configure SSO settings for Facebook to serve as a SAML Identity Provider.
  • B. Create a custom Apex Registration Handler to handle new and existing users.
  • C. Use Delegated Authentication to call the Twitter login API to authenticate users.
  • D. Configure an Authentication Provider for LinkedIn social media accounts.

Answer: B,D


NEW QUESTION # 26
Universal Containers is creating a web application that will be secured by Salesforce Identity using the OAuth 2.0 Web Server Flow uses the OAuth 2.0 authorization code grant type).
Which three OAuth concepts apply to this flow?
Choose 3 answers

  • A. Client Secret
  • B. Verification URL
  • C. Scopes
  • D. Access Token

Answer: A,C,D


NEW QUESTION # 27
......


Salesforce Identity-and-Access-Management-Designer certification exam is an essential credential for IT professionals who work with Salesforce and are responsible for designing and implementing IAM solutions. Salesforce Certified Identity and Access Management Designer certification demonstrates a candidate's expertise in the field of IAM and provides a competitive advantage in the job market. Identity-and-Access-Management-Designer exam is comprehensive and covers various aspects of the Salesforce platform's IAM capabilities. Candidates must have a deep understanding of the platform and experience designing and implementing IAM solutions in real-world scenarios to pass the exam.

 

Identity-and-Access-Management-Designer Exam Practice Materials Collection: https://www.itexamreview.com/Identity-and-Access-Management-Designer-exam-dumps.html

Get Latest and 100% Accurate Identity-and-Access-Management-Designer Exam Questions: https://drive.google.com/open?id=1V83Zj3Nr60SeRhigwqtkpYZO-RJP7s0k