New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 3 out of 8 pages
Viewing questions 21-30 out of questions
Questions # 21:

Universal containers (UC) wants users to authenticate into their salesforceorg using credentials stored in a custom identity store. UC does not want to purchase or use a third-party Identity provider. Additionally, UC is extremely wary of social media and does not consider it to be trust worthy. Which two options should an architect recommend to UC? Choose 2 answers

Options:

A.

Use a professional social media such as LinkedIn as an Authentication provider


B.

Build a custom web page that uses the identity store and calls frontdoor.jsp


C.

Build a custom Web service that is supported byDelegated Authentication.


D.

Implement the Openid protocol and configure an authentication provider


Expert Solution
Questions # 22:

Universal containers (UC) built a customer Community for customers to buy products, review orders, and manage their accounts. UC has provided three different options for customers to log in to the customer Community: salesforce, Google, and Facebook. Which two role combinations are represented by the systems in the scenario? Choose 2 answers

Options:

A.

Google is the service provider and Facebook is the identity provider


B.

Salesforceis the service provider and Google is the identity provider


C.

Facebook is the service provider and salesforce is the identity provider


D.

Salesforce is the service provider and Facebook is the identity provider


Expert Solution
Questions # 23:

Universal Containers (UC) uses middleware to integrate multiple systems with Salesforce. UC has a strict, new requirement that usernames and passwords cannot be stored in any UC system. How can UC’s middleware authenticate to Salesforce while adhering to this requirement?

Options:

A.

Create a Connected App that supports the JWT Bearer Token OAuth Flow.


B.

Create a Connected App that supportsthe Refresh Token OAuth Flow


C.

Create a Connected App that supports the Web Server OAuth Flow.


D.

Create a Connected App that supports the User-Agent OAuth Flow.


Expert Solution
Questions # 24:

N NO: 161

An identity architect has built a native mobile application and plans to integrate it with a Salesforce Identity solution. The following are the requirements for the solution:

1. Users should not have to login every time they use the app.

2. The app should be able to make calls to the Salesforce REST API.

3. End users should NOT see the OAuth approval page.

How should the identity architect configure the Salesforce connected app to meet the requirements?

Options:

A.

Enable the API Scope and Offline Access Scope, upload a certificate so JWT Bearer Flow can be used and then set the connected app access settings to "Admin Pre-Approved".


B.

Enable the API Scope and Offline Access Scope on the connected app, and then set the connected app to access settings to 'Admin Pre-Approved".


C.

Enable the Full Access Scope and then set the connected app access settings to "Admin Pre-Approved".


D.

Enable the API Scope and Offline Access Scope on the connected app, and then set the Connected App access settings to "User may self authorize".


Expert Solution
Questions # 25:

Universal Containers would like its customers to register and log in to a portal built on Salesforce Experience Cloud. Customers should be able to use their Facebook or Linkedln credentials for ease of use.

Which three steps should an identity architect take to implement social sign-on?

Choose 3 answers

Options:

A.

Register both Facebook and Linkedln as connected apps.


B.

Create authentication providers for both Facebook and Linkedln.


C.

Check "Facebook" and "Linkedln" under Login Page Setup.


D.

Enable "Federated Single Sign-On Using SAML".


E.

Update the default registration handlers to create and update users.


Expert Solution
Questions # 26:

Containers (UC) has an existing Customer Community. UC wants to expand the self-registration capabilities such that customers receive a different community experience based on the data they provide during the registration process. What is the recommended approach an Architect Should recommend to UC?

Options:

A.

Create an After Insert Apextrigger on the user object to assign specific custom permissions.


B.

Create separate login flows corresponding to the different community user personas.


C.

Modify the Community pages to utilize specific fields on the User and Contact records.


D.

Modify theexisting Communities registration controller to assign different profiles.


Expert Solution
Questions # 27:

Universal containers(UC) has implemented SAML-BASED single Sign-on for their salesforce application and is planning to provide access to salesforce on mobile devices using the salesforce1 mobile app. UC wants to ensure that single Sign-on is used for accessing the salesforce1 mobile app. Which two recommendations should the architect make? Choose 2 answers

Options:

A.

Use the existing SAML SSO flow along with user agent flow.


B.

Configure the embedded Web browser to use my domain URL.


C.

Use the existing SAML SSO flow along withWeb server flow


D.

Configure the salesforce1 app to use the my domain URL


Expert Solution
Questions # 28:

Universal Containerswants to implement Single Sign-on for a Salesforce org using an external Identity Provider and corporate identity store.

What type of authentication flow is required to support deep linking'

Options:

A.

Web Server OAuth SSO flow


B.

Service-Provider-Initiated SSO


C.

C. Identity-Provider-initiated SSO


D.

StartURL on Identity Provider


Expert Solution
Questions # 29:

Northern Trail Outfitters want to allow its consumer to self-register on it business-to-consumer (B2C) portal that is built on Experience Cloud. The identity architect has recommended to use Person Accounts.

Which three steps need to be configured to enable self-registration using person accounts?

Choose 3 answers

Options:

A.

Enable access to person and business account record types under Public Access Settings.


B.

Contact Salesforce Support to enable business accounts.


C.

Under Login and Registration settings, ensure that the default account field isempty.


D.

Contact Salesforce Support to enable person accounts.


E.

Set organization-wide default sharing for Contact to Public Read Only.


Expert Solution
Questions # 30:

A consumer products company uses Salesforce to maintain consumer information, including orders. The company implemented a portal solution using SalesforceExperience Cloud for its consumers where the consumers can log in using their credentials. The company is considering allowing users to login with their Facebook or Linkedln credentials.

Once enabled, what role will Salesforce play?

Options:

A.

Facebook and Linkedln will be the SPs.


B.

Salesforce will be the service provider (SP).


C.

Salesforce will be the identity provider (IdP).


D.

Facebook and Linkedln will act as the IdPs and SPs.


Expert Solution
Viewing page 3 out of 8 pages
Viewing questions 21-30 out of questions