New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions
Questions # 11:

Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the OAuth 2.0 user-agent flow (this flow uses the OAuth 2.0 implicit grant type).

Which three OAuth concepts apply to this flow?

Choose 3 answers

Options:

A.

Client ID


B.

Refresh Token


C.

Authorization Code


D.

Verification Code


E.

Scopes


Expert Solution
Questions # 12:

Universal containers(UC) wants to integrate a third-party reward calculation system with salesforce to calculate rewards. Rewards will be calculated on a schedule basis and update back into salesforce. The integration between Salesforce and the reward calculation system needs to be secure. Which are the recommended best practices for using Oauth flows in this scenario? Choose 2 answers

Options:

A.

Oauth refresh token flow


B.

Oauth SAML bearer assertion flow


C.

Oauthjwt bearer token flow


D.

Oauth Username-password flow


Expert Solution
Questions # 13:

Universal Containers (UC) has an Experience Cloud site (Customer Community) where customers can authenticate andplace orders, view the status of orders, etc. UC allows guest checkout.

Mow can a guest register using data previously collected during order placement?

Options:

A.

Enable Security Assertion Markup Language Sign-On and use a login flow to collect only order detailsto retrieve customer data.


B.

Enable Facebook as an authentication provider and use a registration handler to collect only order details to retrieve customer data.


C.

Use a Connected App Handler Apex Plugin class to collect only order details to retrievecustomer data.


D.

Enable self-registration and customize a self-registration page to collect only order details to retrieve customer data.


Expert Solution
Questions # 14:

Containers (UC) uses a legacy Employee portal for their employees to collaborate. Employees access theportal from their company’s internal website via SSO. It is set up to work with SiteMinder and Active Directory. The Employee portal has features to support posing ideas. UC decides to use Salesforce Ideas for voting and better tracking purposes. To avoidprovisioning users on Salesforce, UC decides to integrate Employee portal ideas with Salesforce idea through the API. What is the role of Salesforce in the context of SSO, based on this scenario?

Options:

A.

Service Provider, because Salesforce is the applicationfor managing ideas.


B.

Connected App, because Salesforce is connected with Employee portal via API.


C.

Identity Provider, because the API calls are authenticated by Salesforce.


D.

An independent system, because Salesforce is not part of the SSO setup.


Expert Solution
Questions # 15:

A global company has built an external application that uses data from its Salesforce org via an OAuth 2.0 authorization flow. Upon logout, the existing Salesforce OAuth token must be invalidated.

Which action will accomplish this?

Options:

A.

Use a HTTP POST to request the refresh token for the current user.


B.

Use a HTTP POST to the System for Cross-domain Identity Management (SCIM) endpoint, including the current OAuth token.


C.

Use a HTTP POST to make a call to the revoke token endpoint.


D.

Enable Single Logout with a secure logout URL.


Expert Solution
Questions # 16:

Universal Containers (UC) is implementing Salesforce and would like to establish SAML SSO for its users to log in. UC stores its corporate user identities in a Custom Database. The UC IT Manager has heard good things about Salesforce Identity Connect as an Idp, and would like to understand what limitations they may face if they decided to use Identity Connect in their current environment. What limitation Should an Architect inform the IT Manager about?

Options:

A.

Identity Connect will not support user provisioning in UC's current environment.


B.

Identity Connect will only support Idp-initiated SAML flows in UC'scurrent environment.


C.

Identity Connect will only support SP-initiated SAML flows in UC's current environment.


D.

Identity connect is not compatible with UC's current identity environment.


Expert Solution
Questions # 17:

Universal containers (UC) is concerned that having a self-registration page will provide a means for "bots" or unintended audiences to create user records, thereby consuming licences and adding dirty data. Which two actions should UC take to prevent unauthorised form submissions during theself-registration process? Choose 2 answers

Options:

A.

Use open-ended security questions and complex password requirements


B.

Primarily use lookup and picklist fields on the self registration page.


C.

Require a captcha at the end of the self-registration process.


D.

Use hidden fields populated via java script events in the self-registration page.


Expert Solution
Questions # 18:

Universal containers (UC) wants to implement a partner community. As part of their implementation, UC would like to modify both the Forgot password and change password experience with custom branding for their partner community users. Which 2 actions should an architect recommend to UC? Choose 2 answers

Options:

A.

Build a community builder page for the change password experience and Custom Visualforce page for the Forgot password experience.


B.

Build acustom visualforce page for both the change password and Forgot password experiences.


C.

Build a custom visualforce page for the change password experience and a community builder page for the Forgot password experience.


D.

Build a community builder page for both the change password and Forgot password experiences.


Expert Solution
Questions # 19:

Sales users at Universal containers use salesforce for Opportunity management. Marketing uses a third-party application called Nestfor Lead nurturing that is accessed using username/password. The VP of sales wants to open up access to nest for all sales uses to provide them access to lead history and would like SSO for better adoption. Salesforce is already setup for SSO and uses Delegated Authentication. Nest can accept username/Password or SAML-based Authentication. IT teams have received multiple password-related issues for nest and have decided to set up SSO access for Nest for Marketing users as well. The CIO does not want to invest in a new IDP solution and is considering using Salesforce for this purpose. Which are appropriate license typechoices for sales and marketing users, giving salesforce is using Delegated Authentication? Choose 2 answers

Options:

A.

Salesforce license for sales users and Identity license for Marketing users


B.

Salesforce license for sales users and External Identity license for Marketing users


C.

Identity license for sales users and Identity connect license for Marketing users


D.

Salesforce license for sales usersand platform license for Marketing users.


Expert Solution
Questions # 20:

What is oneof the roles of an Identity Provider in a Single Sign-on setup using SAML?

Options:

A.

Validate token


B.

Create token


C.

Consume token


D.

Revoke token


Expert Solution
Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions