Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions
Questions # 11:

Universal Containers (UC) has implemented SAML-based SSO solution for use with their multi-org Salesforce implementation, utilizing one ofthe the orgs as the Identity Provider. One user is reporting that they can log in to the Identity Provider org but get a generic SAML error message when accessing the other orgs. Which two considerations should the architect review to troubleshoot the issue? Choose 2 answers

Options:

A.

The Federation ID must be a valid Salesforce Username


B.

The Federation ID must is case sensitive


C.

The Federation ID must be in the form of an email address.


D.

The Federation ID must be populated on the user record.


Expert Solution
Questions # 12:

Universal Containers (UC) is setting up delegated authentication to allow employees to log in using their corporate credentials. UC's security team is concerned about the risks of exposing the corporate login service on the internet and has asked that a reliable trust mechanism be put in place between the login service and Salesforce.

What mechanism should an Architect put in place to enable a trusted connection between the login service and Salesforce?

Options:

A.

Require the use of Salesforce security tokens on passwords.


B.

Enforce mutual authentication between systems using SSL.


C.

Include Client Id andClient Secret in the login header callout.


D.

Set up a proxy service for the login service in the DMZ.


Expert Solution
Questions # 13:

Universal containers (UC) wants to integrate a Web application with salesforce. The UC team hasimplemented the Oauth web-server Authentication flow for authentication process. Which two considerations should an architect point out to UC? Choose 2 answers

Options:

A.

The web application should be hosted on a secure server.


B.

The web server must be able to protect consumer privacy


C.

The flow involves passing the user credentials back and forth.


D.

The flow will not provide an Oauth refresh token back to the server.


Expert Solution
Questions # 14:

Universal Containers would like its customers to register and log in to a portal built on Salesforce Experience Cloud. Customers should be able to use their Facebook or Linkedln credentials for ease of use.

Which three steps should an identity architect take to implement social sign-on?

Choose 3 answers

Options:

A.

Register both Facebook and Linkedln as connected apps.


B.

Create authentication providers for both Facebook and Linkedln.


C.

Check "Facebook" and "Linkedln" under Login Page Setup.


D.

Enable "Federated Single Sign-On Using SAML".


E.

Update the default registration handlers to create and update users.


Expert Solution
Questions # 15:

Universal Containers (UC) is rolling out its new Customer Identity and Access Management Solution built on top of its existing Salesforce instance. UC wants to allow customers to login using Facebook, Google, and other social sign-on providers.

How should this functionality be enabled for UC, assuming ail social sign-on providers support OpenID Connect?

Options:

A.

Configure an authentication provider and a registration handler for each social sign-on provider.


B.

Configure a single sign-on settingand a registration handler for each social sign-on provider.


C.

Configure an authentication provider and a Just-In-Time (JIT) handler for each social sign-on provider.


D.

Configure a single sign-on setting and a JIT handler for each social sign-on provider.


Expert Solution
Questions # 16:

Universal Containers (UC) uses Salesforce as a CRM and identity provider (IdP) for their Sales Team to seamlessly login to intemaJ portals. The IT team at UC is now evaluating Salesforce to act as an IdP for its remaining employees.

Which Salesforce license is required to fulfill this requirement?

Options:

A.

External Identity


B.

IdentityVerification


C.

Identity Connect


D.

Identity Only


Expert Solution
Questions # 17:

Universal containers (UC) has decided to use identity connect as it's identity provider. UC uses active directory(AD) and has a team that is very familiar and comfortable with managing ad groups. UC would like to use AD groups to help configure salesforce users. Which three actions can AD groups control through identity connect? Choose 3 answers

Options:

A.

Public Group Assignment


B.

Granting report folder access


C.

Role Assignment


D.

Custom permission assignment


E.

Permission sets assignment


Expert Solution
Questions # 18:

Universal containers (UC) is building a mobile application that will make calls to the salesforce RESTAPI. Additionally, UC would like to provide the optimal experience for its mobile users. Which two OAuth scopes should UC configure in the connected App? Choose 2 answers

Options:

A.

Refresh token


B.

API


C.

full


D.

Web


Expert Solution
Questions # 19:

Which two things should be done to ensure end users can only use single sign-on (SSO) to login in to Salesforce?

Choose 2 answers

Options:

A.

Enable My Domain and select "Prevent login from https://login.salesforce.com ".


B.

Request Salesforce Support to enable delegated authentication.


C.

Once SSO is enabled, users are only able to login using Salesforce credentials.


D.

Assign user "is Single Sign-on Enabled" permission via profile or permission set.


Expert Solution
Questions # 20:

An Identity architect works for a multinational, multi-brand organization. As they work with the organization to understand their Customer Identity and Access Management requirements, the identity architect learns that the brand experience is different for each of the customer's sub-brands and each of these branded experiences must be carried through the login experience depending on which sub-brand the user is logging into.

Which solution should the architect recommend to support scalability and reduce maintenance costs, if the organization has more than 150sub-brands?

Options:

A.

Assign each sub-brand a unique Experience ID and use the Experience ID to dynamically brand the login experience.


B.

Use Audiences to customize the login experience for each sub-brand and pass an audience ID to the community during the OAuthand Security Assertion Markup Language (SAML) flows.


C.

Create a community subdomain for each sub-brand and customize the look and feel of the Login page for each community subdomain to match the brand.


D.

Create a separate Salesforce org for each sub-brand so that each sub-brand has complete control over the user experience.


Expert Solution
Viewing page 2 out of 8 pages
Viewing questions 11-20 out of questions