New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 4 out of 8 pages
Viewing questions 31-40 out of questions
Questions # 31:

Universal containers (UC) has an e-commerce website while customers can buy products, make payments, and manage their accounts. UC decides to build a customer Community on Salesforce and wants to allow the customers to access the community for their accounts without logging in again. UC decides to implement ansp-Initiated SSO using a SAML-BASED complaint IDP. In this scenario where salesforce is the service provider, which two activities must be performed in salesforce to make sp-Initiated SSO work? Choose 2 answers

Options:

A.

Configure SAML SSO settings.


B.

Configure Delegated Authentication


C.

Create a connected App


D.

Set up my domain


Expert Solution
Questions # 32:

Universal Containers is implementing a new Experience Cloud site and the identity architect wants to use dynamic branding features as of the login process.

Which two options should the identity architect recommend to support dynamic branding for the site?

Choose 2 answers

Options:

A.

To use dynamic branding, the community must be built with the Visuaiforce + Salesforce Tabs template.


B.

To use dynamic branding, the community must be built with the Customer Account Portal template.


C.

An experience ID (expid) or placeholder parametermust be used in the URL to represent the brand.


D.

An external content management system (CMS) must be used for dynamic branding on Experience Cloud sites.


Expert Solution
Questions # 33:

An Enterprise is using a Lightweight Directory Access Protocol (LDAP ) server as the only point for user authentication with a username/password. Salesforce delegated authentication is configured to integrate Salesforce under single sign-on (SSO).

Mow can end users change their password?

Options:

A.

Users once logged In, can go to the Change Password screen in Salesforce.


B.

Users can click on the "Forgot your Password" link on the Salesforce.com login page.


C.

Users can request the Salesforce Admin to reset their password.


D.

Users can change it on the enterprise LDAP authentication portal.


Expert Solution
Questions # 34:

Universal Containers (UC) operates in Asia, Europe and North America regions. There is one Salesforce org for each region. UC is implementing Customer 360 in Salesforce and has procured External Identity and Customer Community licenses in all orgs.

Customers of UC use Community to track orders and create inquiries. Customers also tend to move across regions frequently.

What should an identity architect recommend to optimize license usage and reduce maintenance overhead?

Options:

A.

Merge three orgs into one instance of Salesforce. This will no longer require maintaining three separate copies of the same customer.


B.

Delete contact/account records and deactivate user if user moves from a specific region; Sync will no longer be required.


C.

Contacts are required since Community access needs to be enabled. Maintenance is a necessary overhead that must be handled via data integration.


D.

D. Enable Contactless User in all orgs and downgrade users from Experience Cloud license to External Identity license once users have moved out of that region.


Expert Solution
Questions # 35:

Northern Trail Outfitters manages application functional permissions centrally as ActiveDirectory groups. The CRM_Superllser and CRM_Reportmg_SuperUser groups should respectively give the user the SuperUser and Reportmg_SuperUser permission set in Salesforce. Salesforce is the service provider to a Security Assertion Markup Language (SAML) identity provider.

Mow should an identity architect ensure the Active Directory groups are reflected correctly when a user accesses Salesforce?

Options:

A.

Use the Apex Just-in-Time handler to query standard SAML attributes and set permission sets.


B.

Use the ApexJust-in-Time handler to query custom SAML attributes and set permission sets.


C.

Use a login flow to query custom SAML attributes and set permission sets.


D.

Use a login flow to query standard SAML attributes and set permission sets.


Expert Solution
Questions # 36:

Universal containers (UC) would like to enable SAML-BASED SSO for asalesforce partner community. UC has an existing ldap identity store and a third-party portal. They would like to use the existing portal as the primary site these users’ access, but also want to allow seamless access to the partner community. What SSO flow should an architect recommend?

Options:

A.

User-Agent


B.

IDP-initiated


C.

Sp-Initiated


D.

Web server


Expert Solution
Questions # 37:

Universal Containers uses Salesforce as an identity provider and Concur as the Employee Expense management system. The HR director wants to ensure Concur accounts for employees are created only after the apocopate approval in the Salesforce org.

Which three steps should theidentity architect use to implement this requirement?

Choose 3 answers

Options:

A.

Create an approval process for a custom object associated with the provisioning flow.


B.

Create a connected app for Concur in Salesforce.


C.

Enable User Provisioning for theconnected app.


D.

Create an approval process for user object associated with the provisioning flow.


E.

Create an approval process for UserProvisionlngRequest object associated with the provisioning flow.


Expert Solution
Questions # 38:

Universal Containers (UC) is setting up delegated authentication to allow employees to log in using their corporate credentials. UC's security team is concerned about the risks of exposing the corporate login service on the internet and has asked that a reliable trust mechanism be put in place between the login service and Salesforce.

What mechanism should an Architect put in place to enable a trusted connection between the login service and Salesforce?

Options:

A.

Require the use of Salesforce security tokens on passwords.


B.

Enforce mutual authentication between systems using SSL.


C.

Include Client Id andClient Secret in the login header callout.


D.

Set up a proxy service for the login service in the DMZ.


Expert Solution
Questions # 39:

Universal Containers (UC) has an existing web application that itwould like to access from Salesforce without requiring users to re-authenticate. The web application is owned UC and the UC team that is responsible for it is willing to add new javascript code and/or libraries to the application. What implementation should an Architect recommend to UC?

Options:

A.

Create a Canvas app and use Signed Requests to authenticate the users.


B.

Rewrite the web application as a set of Visualforce pages and Apex code.


C.

Configure the web application as an item in the Salesforce App Launcher.


D.

Add the web application as a ConnectedApp using OAuth User-Agent flow.


Expert Solution
Questions # 40:

A web service is developed that allows secure access to customer order status on the Salesforce Platform. The service connects to Salesforce through a connected app with the web server flow. The following are the required actions for the authorization flow:

1. User Authenticates and Authorizes Access

2. Request an Access Token

3. Salesforce Grantsan Access Token

4. Request an Authorization Code

5. Salesforce Grants Authorization Code

What is the correct sequence for the authorization flow?

Options:

A.

1, 4, 5, 2, 3


B.

4, 1, 5, 2, 3


C.

2, 1, 3, 4, 5


D.

4,5,2, 3, 1


Expert Solution
Viewing page 4 out of 8 pages
Viewing questions 31-40 out of questions