Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 4 out of 8 pages
Viewing questions 31-40 out of questions
Questions # 31:

A division of a Northern Trail Outfitters (NTO) purchased Salesforce. NTO uses a third party identity provider (IdP) to validate user credentials against Its corporate Lightweight Directory Access Protocol (LDAP) directory. NTO wants to help employees remember as passwords as possible.

What should an identity architect recommend?

Options:

A.

Setup Salesforce as a Service Provider to the existing IdP.


B.

SetupSalesforce as an IdP to authenticate against the LDAP directory.


C.

Use Salesforce connect to synchronize LDAP passwords to Salesforce.


D.

Setup Salesforce as an Authentication Provider to the existing IdP.


Expert Solution
Questions # 32:

A global company is using the Salesforce Platform as an Identity Provider and needs to integrate a third-party application with its Experience Cloud customer portal.

Which two features should be utilized to provide users with loginand identity services for the third-party application?

Choose 2 answers

Options:

A.

Use the App Launcher with single sign-on (SSO).


B.

External a Data source with Named Principal identity type.


C.

Use a connected app.


D.

Use Delegated Authentication.


Expert Solution
Questions # 33:

Which two capabilities does My Domain enable in the context of a SAML SSOconfiguration? Choose 2 answers

Options:

A.

App Launcher


B.

Resource deep linking


C.

SSO from Salesforce Mobile App


D.

Login Forensics


Expert Solution
Questions # 34:

The security team at Universal containers(UC) has identified exporting reports as a high-risk action and would like to require users to be logged into salesforce with their active directory (AD) credentialswhen doing so. For all other uses of Salesforce, Users should be allowed to use AD credentials or salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with salesforce credentials?

Options:

A.

Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.


B.

Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.


C.

Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.


D.

Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.


Expert Solution
Questions # 35:

Universal containers (UC) has a customer Community that uses Facebook for authentication. UC would like to ensure that changes in the Facebook profile are reflected on the appropriate customer Community user. How can this requirement be met?

Options:

A.

Use the updateuser() method on the registration handler class.


B.

Use SAML just-in-timeprovisioning between Facebook and Salesforce


C.

Use information in the signed request that is received from Facebook.


D.

Develop a schedule job that calls out to Facebook on a nightly basis.


Expert Solution
Questions # 36:

Universal containers (UC) wants to implement Delegated Authentication for a certainsubset of Salesforce users. Which three items should UC take into consideration while building the Web service to handle the Delegated Authentication request? Choose 3 answers

Options:

A.

The web service needs to include Source IP as a method parameter.


B.

UC should whitelist all salesforce ip ranges on their corporate firewall.


C.

The web service can be written using either the soap or rest protocol.


D.

Delegated Authentication is enabled for the system administrator profile.


E.

The return type of the Web service method should be a Boolean value


Expert Solution
Questions # 37:

Northern Trail Outfitters (NTO) uses Salesforce Experience Cloud sites (previously known as Customer Community) to provide a digital portal where customers can login using theirGoogle account.

NTO would like to automatically create a case record for first time users logging into Salesforce Experience Cloud.

What should an Identity architect do to fulfill the requirement?

Options:

A.

Configure an authentication provider for Social Login using Google and a custom registration handler.


B.

Implement a Just-in-Time handler class that has logic to create cases upon first login.


C.

Create an authentication provider for Social Login using Google and leverage standard registration handler.


D.

Implement a login flow with a record create component for Case.


Expert Solution
Questions # 38:

architect is troubleshooting some SAML-based SSO errors during testing. The Architect confirmed that all of the Salesforce SSO settings are correct. Which two issues outside of the Salesforce SSO settings are most likely contributing to the SSO errors the Architect is encountering? Choose 2 Answers

Options:

A.

The Identity Provider is also used to SSO into five other applications.


B.

The clock on the Identity Provider server is twenty minutes behind Salesforce.


C.

The Issuer Certificate from the Identity Provider expired two weeks ago.


D.

The default language for the Identity Provider and Salesforce are Different.


Expert Solution
Questions # 39:

Universal containers (UC) has an e-commerce website while customers can buy products, make payments, and manage their accounts. UC decides to build a customer Community on Salesforce and wants to allow the customers to access the community for their accounts without logging in again. UC decides to implement ansp-Initiated SSO using a SAML-BASED complaint IDP. In this scenario where salesforce is the service provider, which two activities must be performed in salesforce to make sp-Initiated SSO work? Choose 2 answers

Options:

A.

Configure SAML SSO settings.


B.

Configure Delegated Authentication


C.

Create a connected App


D.

Set up my domain


Expert Solution
Questions # 40:

Which two statements are capable of Identity Connect? Choose 2 answers

Options:

A.

Synchronization of Salesforce Permission Set Licence Assignments.


B.

Supports both Identity-Provider-Initiated and Service-Provider-Initiated SSO.


C.

Support multiple orgs connecting to multiple Active Directory servers.


D.

Automated user synchronization and de-activation.


Expert Solution
Viewing page 4 out of 8 pages
Viewing questions 31-40 out of questions