New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 1 out of 8 pages
Viewing questions 1-10 out of questions
Questions # 1:

An identity architect is setting up an integration between Salesforce and a third-party system. The third-party system needs to authenticate to Salesforce and then make API calls against the REST API.

One of the requirements is that the solution needs to ensure the third party service providers connected app in Salesforce mini need for end user interaction and maximizes security.

Which OAuth flow should be used to fulfill the requirement?

Options:

A.

JWT Bearer Flow


B.

Web Server Flow


C.

User Agent Flow


D.

Username-Password Flow


Expert Solution
Questions # 2:

Northern Trail Outfitters wants to implement a partner community. Active community users will need to review and accept the community rules, and update key contact information for each community member before their annual partner event.

Which approach will meet this requirement?

Options:

A.

Create tasks for users who need toupdate their data or accept the new community rules.


B.

Create a custom landing page and email campaign asking all community members to login and verify their data.


C.

Create a login flow that conditionally prompts users who have not accepted the newcommunity rules and who have missing or outdated information.


D.

Add a banner to the community Home page asking users to update their profile and accept the new community rules.


Expert Solution
Questions # 3:

customer service representatives at Universal containers (UC) are complaining that whenever they click on links to case records and are asked to login with SAML SSO, they are beingredirected to the salesforce home tab and not the specific case record. What item should an architect advise the identity team at UC to investigate first?

Options:

A.

My domain is configured and active within salesforce.


B.

The salesforce SSO settings are using http post


C.

The identity provider is correctly preserving the Relay state


D.

The users have the correct Federation ID within salesforce.


Expert Solution
Questions # 4:

A global fitness equipment manufacturer uses Salesforce to manage its sales cycle. The manufacturer has a custom order fulfillment app that needs to request order data from Salesforce. The order fulfillment app needs to integrate with the Salesforce API using OAuth 2.0 protocol.

What should an identity architect use to fulfill this requirement?

Options:

A.

Canvas App Integration


B.

OAuth Tokens


C.

Authentication Providers


D.

Connected App and OAuth scopes


Expert Solution
Questions # 5:

Universal Containers (UC) wants its closed Won opportunities to be synced to a Data warehouse in near real time.UC has implemented Outbound Message to enable near real-time data sync. UC wants to ensure that communication between Salesforce and Target System is secure. What certificate is sent along with the Outbound Message?

Options:

A.

The Self-signed Certificates from the Certificate & Key Management menu.


B.

The default client Certificate from the Develop--> API menu.


C.

The default client Certificate or the Certificate and Key Management menu.


D.

The CA-signed Certificate from the Certificate and Key Management Menu.


Expert Solution
Questions # 6:

A global company is using the Salesforce Platform as an Identity Provider and needs to integrate a third-party application with its Experience Cloud customer portal.

Which two features should be utilized to provide users with loginand identity services for the third-party application?

Choose 2 answers

Options:

A.

Use the App Launcher with single sign-on (SSO).


B.

External a Data source with Named Principal identity type.


C.

Use a connected app.


D.

Use Delegated Authentication.


Expert Solution
Questions # 7:

Universal containers (UC) would like to enable SSO between their existing Active Directory infrastructure and salesforce. The it team prefers to manage all users in Active Directory and would like to avoid doing any initial setup of users in salesforce directly,including the correct assignment of profiles, roles and groups. Which two optimal solutions should UC use to provision users in salesforce? Choose 2 answers

Options:

A.

Use the salesforce REST API to sync users from active directory to salesforce


B.

Use an app exchange product to sync users from Active Directory to salesforce.


C.

Use Active Directory Federation Services to sync users from active directory to salesforce.


D.

Use Identity connect to sync users from Active Directory to salesforce


Expert Solution
Questions # 8:

Universal Containers (UC) built an integration for their employees to post, view, and vote for ideas in Salesforce from an internal Company portal. When ideas are posted in Salesforce, links to the ideas are created in the company portal pages as part of the integration process. The Company portal connects to Salesforce using OAuth. Everything is working fine, except when users click on links to existing ideas, they are always taken to the Ideas home page rather than the specific idea, after authorization.Which OAuth URL parameter can be used to retain the original requested page so that a user can be redirected correctly after OAuth authorization?

Options:

A.

Redirect_uri


B.

State


C.

Scope


D.

Callback_uri


Expert Solution
Questions # 9:

Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for to give its customers the ability to login with their Facebook and Twitter credentials.

Which two actions should an identity architect recommend to meet these requirements?

Choose 2 answers

Options:

A.

Create a custom external authentication provider for Facebook.


B.

Configure a predefined authentication provider for Facebook.


C.

Create a custom external authentication provider for Twitter.


D.

Configure a predefined authentication provider for Twitter.


Expert Solution
Questions # 10:

Which three are capabilities of SAML-based Federated authentication? Choose 3 answers

Options:

A.

Trust relationships between Identity Provider and Service Provider are required.


B.

SAML tokens can be in XML or JSON format and can be used interchangeably.


C.

Web applications with no passwords are more secure and stronger against attacks.


D.

Access tokens areused to access resources on the server once the user is authenticated.


E.

Centralized federation provides single point of access, control and auditing.


Expert Solution
Viewing page 1 out of 8 pages
Viewing questions 1-10 out of questions