Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 1 out of 8 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which three are capabilities of SAML-based Federated authentication? Choose 3 answers

Options:

A.

Trust relationships between Identity Provider and Service Provider are required.


B.

SAML tokens can be in XML or JSON format and can be used interchangeably.


C.

Web applications with no passwords are more secure and stronger against attacks.


D.

Access tokens areused to access resources on the server once the user is authenticated.


E.

Centralized federation provides single point of access, control and auditing.


Expert Solution
Questions # 2:

A farming enterprise offers smart farming technology to its farmer customers, which includes a variety of sensors for livestock tracking, pest monitoring, climate monitoring etc. They plan to store all thedata in Salesforce. They would also like to ensure timely maintenance of the Installed sensors. They have engaged a salesforce Architect to propose an appropriate way to generate sensor Information In Salesforce.

Which OAuth flow should the architect recommend?

Options:

A.

OAuth 2.0 Asset Token Flow


B.

OAuth 2.0 Device Authentication Row


C.

OAuth 2.0 JWT Bearer Token Flow


D.

OAuth 2.0 SAML Bearer Assertion Flow


Expert Solution
Questions # 3:

Universal Containers (UC) uses Salesforce for its customer service agents. UC has a proprietary system for order tracking which supports Security Assertion Markup Language (SAML) based single sign-on. The VP of customer service wants to ensure only active Salesforce users should be able to access the order tracking system which is only visible within Salesforce.

What should be done to fulfill the requirement?

Choose 2 answers

Options:

A.

Setup Salesforce as an identity provider (IdP) for order Tracking.


B.

Set up the Corporate Identity store as an identity provider (IdP) for Order Tracking,


C.

Customize Order Tracking to initiate a REST call to validate users in Salesforce after login.


D.

Setup Order Tracking as a Canvas app in Salesforce to POST IdPinitiated SAML assertion.


Expert Solution
Questions # 4:

Universal containers (UC) wants users to authenticate into their salesforceorg using credentials stored in a custom identity store. UC does not want to purchase or use a third-party Identity provider. Additionally, UC is extremely wary of social media and does not consider it to be trust worthy. Which two options should an architect recommend to UC? Choose 2 answers

Options:

A.

Use a professional social media such as LinkedIn as an Authentication provider


B.

Build a custom web page that uses the identity store and calls frontdoor.jsp


C.

Build a custom Web service that is supported byDelegated Authentication.


D.

Implement the Openid protocol and configure an authentication provider


Expert Solution
Questions # 5:

A university is planningto set up an identity solution for its alumni. A third-party identity provider will be used for single sign-on Salesforce will be the system of records. Users are getting error messages when logging in.

Which Salesforce feature should be used to debug theissue?

Options:

A.

Apex Exception Email


B.

View Setup Audit Trail


C.

Debug Logs


D.

Login History


Expert Solution
Questions # 6:

Universal Containers (UC) has implemented SAML-based Single Sign-On to provide seamless access to its Salesforce Orgs, financial system, and CPQ system. Below is the SSO implementationlandscape.

What role combination is represented by the systems in this scenario''

Options:

A.

Financial System and CPQ System are the only Service Providers.


B.

Salesforce Org1 and Salesforce Org2 are the only Service Providers.


C.

Salesforce Org1 and Salesforce Org2 are acting as Identity Providers.


D.

Salesforce Org1 and PingFederate are acting as Identity Providers.


Expert Solution
Questions # 7:

Universal Containers is using OpenID Connect to enable a connection from their new mobile app to its production Salesforce org.

What should be done to enable the retrieval of the access token status for the OpenID Connect connection?

Options:

A.

Query using OpenIDConnect discovery endpoint.


B.

A Leverage OpenID Connect Token Introspection.


C.

Create a custom OAuth scope.


D.

Enable cross-origin resource sharing (CORS) for the /services/oauth2/token endpoint.


Expert Solution
Questions # 8:

What are three capabilities of Delegated Authentication? Choose 3 answers

Options:

A.

It can be assigned by Custom Permissions.


B.

It can connect to SOAP services.


C.

It can be assigned by Permission Sets.


D.

It can be assigned by Profiles.


E.

It can connect to REST services.


Expert Solution
Questions # 9:

Universal Containers (UC) has a mobile application for its employees that usesdata from Salesforce as well as uses Salesforce for Authentication purposes. UC wants its mobile users to only enter their credentials the first time they run the app. Theapplication has been live for a little over 6 months, and all of the users who werepart of the initial launch are complaining that they have to re-authenticate. UC has also recently changed the URI Scheme associated with the mobile app. What should the Architect at UC first investigate?Universal Containers (UC) has a mobile applicationfor its employees that uses data from Salesforce as well as uses Salesforce for Authentication purposes. UC wants its mobile users to only enter their credentials the first time they run the app. The application has been live for a little over 6 months, and all of the users who were part of the initial launch are complaining that they have to re-authenticate. UC has also recently changed the URI Scheme associated with the mobile app. What should the Architect at UC first investigate?

Options:

A.

Check the Refresh Token policy defined in the Salesforce Connected App.


B.

Validate that the users are checking the box to remember their passwords.


C.

Verify that the Callback URL is correctly pointing to the new URI Scheme.


D.

Confirm that the access Token's Time-To-Livepolicy has been set appropriately.


Expert Solution
Questions # 10:

A service provider (SP) supportsboth Security Assertion Markup Language (SAML) and OpenID Connect (OIDC).

When integrating this SP with Salesforce, which use case is the determining factor when choosing OIDC or SAML?

Options:

A.

OIDC is more secure than SAML and therefore is the obvious choice.


B.

B. The SP needs to perform API calls back to Salesforce on behalf of the user after the user logs in to the service provider.


C.

If the user has a session on Salesforce, you do not want them to be prompted for a username and password when they login to theSP.


D.

They are equivalent protocols and there is no real reason to choose one over the other.


Expert Solution
Viewing page 1 out of 8 pages
Viewing questions 1-10 out of questions