Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions
Questions # 21:

Universal Containers is using OpenID Connect to enable a connection from their new mobile app to its production Salesforce org.

What should be done to enable the retrieval of the access token status for the OpenID Connect connection?

Options:

A.

Leverage OpenID Connect Token Introspection.


B.

Query using OpenID Connect discovery endpoint.


C.

Enable cross-origin resource sharing (CORS) for the /services/oauth2/token endpoint.


D.

Create a custom OAuth scope.


Expert Solution
Questions # 22:

Universal Containers (UC) is planning to add Wi-Fi enabled GPS tracking devices to its shipping containers so that the GPS coordinates data can be sent from the tracking device to its Salesforce production org via a custom API. The GPS devices have no direct user input or output capabilities.

Which OAuth flow should the identity architect recommend to meet the requirement?

Options:

A.

OAuth 2.0 Asset Token Flow for Securing Connected Devices


B.

OAuth 2.0 Web Server Flow for Web App Integration


C.

OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration


D.

OAuth 2.0 Username-Password Flow for Special Scenarios


Expert Solution
Questions # 23:

Northern Trail Outfitters (NTO) uses Salesforce for Sales Opportunity Management. Okta was recently brought in to Just-in-Time (JIT) provision and authenticate NTO users to applications. Salesforce users also use Okta to authorize a Forecasting web application to access Salesforce records on their behalf.

Which two roles are being performed by Salesforce?

Choose 2 answers

Options:

A.

OAuth Resource Server


B.

SAML Service Provider


C.

OAuth Client


D.

SAML Identity Provider


Expert Solution
Questions # 24:

Universal Containers is implementing a new Experience Cloud site and the identity architect wants to use dynamic branding features as part of the login process.

Which two options should the identity architect recommend to support dynamic branding for the site?

Choose 2 answers

Options:

A.

To use dynamic branding, the community must be built with the Audience + Salesforce Tabs template.


B.

Do use dynamic branding, the community must be built with the Customer Account Portal template.


C.

An external content management system (CMS) must be used for dynamic branding on Experience Cloud sites.


D.

An experience ID (expid) or placeholder parameter must be used in the URL to represent the brand.


Expert Solution
Questions # 25:

Universal Containers (UC) is rolling out its new Customer Identity and Access Management Solution built on top of its existing Salesforce instance. UC wants to allow customers to login using Facebook, Google, and other social sign-on providers.

How should this functionality be enabled for UC, assuming all social sign-on providers support OpenID Connect?

Options:

A.

configure a single sign-on setting and a JTT handler for each social sign-on provider.


B.

configure an authentication provider and a Auto-Time Unit handler for each social sign-on provider.


C.

configure an authentication provider and a registration handler for each social sign-on provider.


D.

configure a single sign-on setting and a registration handler for each social sign-on provider.


Expert Solution
Questions # 26:

Northern Trail Outfitters (NTO) is planning to roll out a partner portal for its distributors using Experience Cloud. NTO would like to use an external identity provider (IdP) and for partners to register for access to the portal. Each partner should be allowed to register only once to avoid duplicate accounts with Salesforce.

What should a identity architect recomend to create partners?

Options:

A.

Create a custom page in Experience Cloud to self register partner with Experience Cloud and Ping Identity store.


B.

On successful creation of Partners using Self Registration page in Experience Cloud, create Identity in Ping.


C.

Create a custom web page in the Portal and create users in the IdP and Experience Cloud

using published APIs.


D.

Allow partners to register through the IdP and create partner users in Salesforce through an API.


Expert Solution
Questions # 27:

Northern Trail Outfitters (NTO) is launching a new sportswear brand on its existing consumer portal built on Salesforce Experience Cloud. As part of the launch, emails with promotional links will be sent to existing customers to log in and claim a discount. The marketing manager would like the portal dynamically branded so that users will be directed to the brand link they clicked on; otherwise, users will view a recognizable NTO-branded page.

The campaign is launching quickly, so there is no time to procure any additional licenses.

However, the development team is available to apply any required changes to the portal.

Which approach should the identity architect recommend?

Options:

A.

Create a full audience to replicate the portal and set up these the branding accordingly.


B.

Use tutorials to build the new brand site and embedded login for some identities.


C.

Configure an additional community site on the same way that is dedicated for the new brand.


D.

Implement Experiences ID in the code and extend the URLs and endpoints, as required.


Expert Solution
Questions # 28:

A consumer products company uses Salesforce to maintain consumer information, including orders. The company implemented a portal solution using Salesforce Experience Cloud for its consumers where the consumers can log in using their credentials. The company is considering allowing users to login with their Facebook or LinkedIn credentials.

Once enabled, what role will Salesforce play?

Options:

A.

Facebook and LinkedIn will be this SPs.


B.

Facebook and LinkedIn will act as the LIPS and SPs.


C.

Salesforce will be the service provider (SP).


D.

Salesforce will be the identity provider (LIP).


Expert Solution
Questions # 29:

Universal Containers want users to be able to log in to the Salesforce mobile app with their Active Directory password. Employees are unable to use mobile VPN.

Which two options should an identity architect recommend to meet the requirement?

Choose 2 answers

Options:

A.

Active Directory Password Since Plugin


B.

Salesforce Identity Connect


C.

Salesforce Trigger & Field on Contact Object


D.

Configure Cloud Provider Load Balancer


Expert Solution
Questions # 30:

Northern Trail Outfitters (NTO) would like to use a portal built on Salesforce Experience Cloud for customer self-service. Guests of the portal should be able to self-register, but be unable to automatically be assigned to a contact record until verified. External Identity licenses have been purchased for the project.

After registered guests complete an onboarding process, a flow will create the appropriate account and contact records for the user.

Which three steps should an identity architect follow to implement the outlined requirements?

Choose 3 answers

Options:

A.

Customize the self-registration Apps handler to create only the user record.


B.

Select the “Configurable Self-Reg Page” option under Login & Registration.


C.

Set up an external login page and call Salesforce APIs for user creation.


D.

Select new customers and partners to self-register.


E.

Customize the self-registration Apps handler to temporarily associate the user to a shared single contact record.


Expert Solution
Viewing page 3 out of 4 pages
Viewing questions 21-30 out of questions