Try Before You Buy

Download a free sample of any of our exam questions and answers

  • 24/7 customer support, Secure shopping site
  • Free One year updates to match real exam scenarios
  • If you failed your exam after buying our products we will refund the full amount back to you.

Actual Identity-and-Access-Management-Designer Exam Recently Updated Questions with Free Demo [Q99-Q117]

Share

Actual Identity-and-Access-Management-Designer Exam Recently Updated Questions with Free Demo

Free Salesforce Identity-and-Access-Management-Designer Exam Questions Self-Assess Preparation


Salesforce Identity-and-Access-Management-Designer exam is part of the Salesforce Certified Technical Architect (CTA) track, which is the highest level of certification offered by Salesforce. This means that individuals who pass Identity-and-Access-Management-Designer exam have demonstrated a high level of technical expertise in the field of identity and access management, and are well-equipped to design and implement solutions that meet the needs of even the most complex organizations.


The Salesforce Identity-and-Access-Management-Designer exam covers various topics related to identity and access management, including authentication, authorization, single sign-on, and identity federation. It also focuses on the integration of Salesforce with external identity providers and the configuration of user access to Salesforce resources. Passing Identity-and-Access-Management-Designer exam demonstrates a deep understanding of identity and access management concepts and the ability to design and implement secure solutions that meet the specific needs of an organization.

 

NEW QUESTION # 99
Universal Container's (UC) identity architect needs to recommend a license type for their new Experience Cloud site that will be used by external partners (delivery providers) for reviewing and updating their accounts, downloading files provided by UC and obtaining scheduled pickup dates from their calendar.
UC is using their Salesforce production org as the identity provider for these users and the expected number of individual users is 2.5 million with 13.5 million unique logins per month.
Which of the following license types should be used to meet the requirement?

  • A. Partner Community Login License
  • B. Partner Community License
  • C. External Apps License
  • D. Customer Community plus Login License

Answer: D


NEW QUESTION # 100
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers willutilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?

  • A. UseSAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
  • B. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
  • C. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML toallow SSO.
  • D. Use anightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.

Answer: A


NEW QUESTION # 101
Universal containers wants salesforce inbound Oauth-enabled integration clients to use SAML-BASED single Sign-on for authentication. What Oauth flow would be recommended in this scenario?

  • A. Web server Oauth flow
  • B. SAML assertion Oauth flow
  • C. User-Token Oauth flow
  • D. User-Agent Oauth flow

Answer: B


NEW QUESTION # 102
Universal Containers (UC) has built a custom time tracking app for its employee. UC wants to leverage Salesforce Identity to control access to the custom app.
At a minimum, which Salesforce license is required to support this requirement?

  • A. Identity Connect
  • B. Identity Only
  • C. Identity Verification
  • D. External Identity

Answer: B


NEW QUESTION # 103
What are threecapabilitiesof Delegated Authentication? Choose 3 answers

  • A. It can be assigned by Custom Permissions.
  • B. It can be assigned by Profiles.
  • C. It can connect to REST services.
  • D. It can be assigned by Permission Sets.
  • E. It can connect to SOAP services.

Answer: C,D,E


NEW QUESTION # 104
Universal Containers (UC) employees have Salesforce access from restricted IP ranges only, to protect against unauthorized access. UC wants to roll out the Salesforce mobile app and make it accessible from any location.
Which two options should an Architect recommend? (Choose two.)

  • A. Remove existing restrictions on IP ranges for all types of user access.
  • B. Relax the IP restriction in the Connect App settings for the Salesforce mobile app.
  • C. Relax the IP restriction with a second factor in the Connect App settings for Salesforce mobile app.
  • D. Use Login Flow to bypass IP range restriction for the mobile app.

Answer: B,C


NEW QUESTION # 105
Universal containers (UC) has implemented ansp-Initiated SAML flow between an external IDP and salesforce. A user at UC is attempting to login to salesforce1 for the first time and is being prompted for salesforce credentials instead of being shown the IDP login page. What is the likely cause of the issue?

  • A. The user has not configured the salesforce1 mobile app to use my domain for login
  • B. The user has notbeen granted the "Enable single Sign-on" permission
  • C. The "Redirect to Identity Provider" option has been selected in the my domain configuration.
  • D. The "Redirect to identity provider" option has not been selected the SAML configuration.

Answer: A


NEW QUESTION # 106
Universal Containers is creating a web application that will be secured by Salesforce Identity using the OAuth 2.0 Web Server Flow uses the OAuth 2.0 authorization code grant type).
Which three OAuth concepts apply to this flow?
Choose 3 answers

  • A. Scopes
  • B. Access Token
  • C. Client Secret
  • D. Verification URL

Answer: A,B,C


NEW QUESTION # 107
Universal Containers (UC) would like to enable self-registration for their Salesforce Partner Community Users. UC wants to capture some custom data elements from the partner user, and based on these data elements, wants to assign the appropriate Profile and Account values.
Which two actions should the Architect recommend to UC1
Choose 2 answers

  • A. Modify the SelfRegistration trigger to assign Profile and Account.
  • B. Configure Registration for Communities to use a custom Visualforce Page.
  • C. Modify the CommunitiesSelfRegController to assign the Profile and Account.
  • D. Configure Registration for Communities to use a custom Apex Controller.

Answer: B,C


NEW QUESTION # 108
universal containers wants to build a custom mobile app connecting to salesforce using Oauth, and would like to restrict the types of resources mobile users can access. What Oauth feature of Salesforce should be used to achieve the goal?

  • A. Scopes
  • B. Refresh Tokens
  • C. Access Tokens
  • D. Mobile PINS

Answer: C


NEW QUESTION # 109
The security team at Universal Containers has identified exporting reports as a high-risk action and would like to require users to be logged into Salesforce with their Active Directory (AD) credentials when doing so.
For all other uses of Salesforce, users should be allowed to use AD credentials or Salesforce credentials.
What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with Salesforce credentials?

  • A. Use SAML Federated Authentication and block access to reports when accessed through a Standard Assurance session.
  • B. Use SAML Federated Authentication with a Login Flow to dynamically add or remove a Permission Set that grants the Export Reports permission.
  • C. Use SAML Federated Authentication, treat SAML Sessions as High Assurance, and raise the session level required for exporting reports.
  • D. Use SAML Federated Authentication and Custom SAML JIT Provisioning to dynamically add or remove a Permission Set that grants the Export Reports permission.

Answer: C


NEW QUESTION # 110
Universal containers (UC) is setting up Delegated Authentication to allow employees to log in using their corporate credentials. UC's security team is concerned about the risk of exposing the corporate login service on the Internet and has asked that a reliable trust mechanism be put in place between the login service and salesforce. What mechanism should an architect put in place to enable a trusted connection between the login services and salesforce?

  • A. Set up a proxy server for the login service in the DMZ.
  • B. Enforce mutual Authentication between systems using SSL.
  • C. Include client ID and client secret in the login header callout.
  • D. Require the use of Salesforce security Tokens on password.

Answer: D


NEW QUESTION # 111
A group of users try to access one of Universal Containers' Connected Apps and receive the following error message: " Failed: Not approved for access." What is the most likely cause of this issue?

  • A. The Users do not have the correct permission set assigned to them.
  • B. The Salesforce Administrators have revoked the OAuth authorization.
  • C. The User of High Assurance sessions are required for the Connected App.
  • D. The Connected App settings "All users may self-authorize" is enabled.

Answer: A


NEW QUESTION # 112
Universal Containers (UC) employees have Salesforce access from restricted IP ranges only, to protect against unauthorised access. UC wants to roll out the Salesforce1 mobile app and make it accessible from any location. Which two options should an Architect recommend? Choose 2 answers

  • A. Use Login Flow to bypass IP range restriction for the mobile app.
  • B. Relax the IP restrictions in the Connect App settings for the Salesforce1 mobile app.
  • C. Relax the IP restriction with a second factor in the Connect App settings for Salesforce1 mobile app.
  • D. Remove existing restrictions on IP ranges for all types of user access.

Answer: A,D


NEW QUESTION # 113
Universal Containers (UC) has implemented SAML-based Single Sign-on for their Salesforce application and is planning to use the Salesforce mobile app. UC wants to ensure that Single Sign-on is used for accessing the Salesforce mobile app.
Which two recommendations should the Architect make? (Choose two.)

  • A. Use the existing SAML SSO flow along with User Agent Flow.
  • B. Use the existing SAML SSO flow along with Web Server Flow.
  • C. Configure the Salesforce App to use the My Domain URL.
  • D. Configure the Embedded Web Browser to use My Domain URL.

Answer: A,C


NEW QUESTION # 114
Universal Containers (UC) wants to build a few applications that leverage the Salesforce REST API. UC has asked its Architect to describe how the API calls will be authenticated to a specific user. Which two mechanisms can the Architect provide? Choose 2 Answers

  • A. Access Token
  • B. Authentication Token
  • C. Session ID
  • D. Refresh Token

Answer: A,B


NEW QUESTION # 115
Universal containers (UC) has a mobile application that calls the salesforce REST API. In order to prevent users from having to enter their credentials everytime they use the app, UC has enabled the use of refresh Tokens as part of the salesforce connected App and updated their mobile app to take advantage of the refresh token. Even after enabling the refresh token, Users are still complaining that they have to enter their credentials once a day. What is the most likely cause of the issue?

  • A. The users forget to check the box to remember their credentials.
  • B. The refresh token expiration policy is set incorrectly in salesforce
  • C. The app is requesting too many access Tokens in a 24-hour period
  • D. The Oauth authorizations are being revoked by a nightly batch job.

Answer: B


NEW QUESTION # 116
Universal containers(UC) wants to integrate a third-party reward calculation system with salesforce to calculate rewards. Rewards will be calculated on a schedule basis and update back into salesforce. The integration between Salesforce and the reward calculation system needs to be secure. Which are the recommended best practices for using Oauth flows in this scenario? Choose 2 answers

  • A. Oauth SAML bearer assertion flow
  • B. Oauth Username-password flow
  • C. Oauth refresh token flow
  • D. Oauthjwt bearer token flow

Answer: A,D


NEW QUESTION # 117
......

Identity-and-Access-Management-Designer Free Sample Questions to Practice One Year Update: https://passguide.braindumpsit.com/Identity-and-Access-Management-Designer-latest-dumps.html