New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions
Questions # 41:

Northern Trail Outfitters (NTO) is launching a new sportswear brand on its existing consumer portal built on Salesforce Experience Cloud. As part of the launch, emails with promotional links will be sent to existing customers to log in and claim a discount. The marketing manager would like the portal dynamically branded so that users will be directed to the brand link they clicked on; otherwise, users will view a recognizable NTO-branded page.

The campaign is launching quickly, so there is no time to procure any additional licenses. However, the development team is available to apply any required changes to the portal.

Which approach should the identity architect recommend?

Options:

A.

Create a full sandbox to replicate the portal site and update the branding accordingly.


B.

Implement Experience ID in the code and extend the URLs and endpoints, as required.


C.

Use Heroku to build the new brand site and embedded login to reuse identities.


D.

Configure an additional community site on the same org that is dedicated for the new brand.


Expert Solution
Questions # 42:

A global company's Salesforce Identity Architect is reviewing its Salesforce production org login history and is seeing some intermittent Security Assertion Markup Language (SAML SSO) 'Replay Detected and Assertion Invalid' login errors.

Which two issues would cause these errors?

Choose 2 answers

Options:

A.

The subject element ismissing from the assertion sent to salesforce.


B.

The certificate loaded into SSO configuration does not match the certificate used by the IdP.


C.

The current time setting of the company's identity provider (IdP) and Salesforce platform is out of sync by more than eight minutes.


D.

The assertion sent to 5alesforce contains an assertion ID previously used.


Expert Solution
Questions # 43:

Universal Containers (UC) is looking to purchase a third-party applicationas an Identity Provider. UC is looking to develop a business case for the purchase in general and has enlisted an Architect for advice. Which two capabilities of an Identity Provider should the Architect detail to help strengthen the business case? Choose2 answers

Options:

A.

The Identity Provider can authenticate multiple applications.


B.

The Identity Provider can authenticate multiple social media accounts.


C.

The Identity provider can store credentials for multiple applications.


D.

The Identity Provider can centralize enterprise password policy.


Expert Solution
Questions # 44:

Universal Containers (UC) has built a custom time tracking app for its employee. UC wants to leverage Salesforce Identity to control access to the custom app.

At a minimum, which Salesforce license is required to support this requirement?

Options:

A.

Identity Verification


B.

Identity Connect


C.

Identity Only


D.

External Identity


Expert Solution
Questions # 45:

Northern Trail Outfitters (NTO) has a number of employees who do NOT need access Salesforce objects. Trie employees should sign in to a custom Benefits web app using their Salesforce credentials.

Which license should the identity architect recommend tofulfill this requirement?

Options:

A.

Identity Only License


B.

External Identity License


C.

Identity Verification Credits Add-on License


D.

Identity Connect License


Expert Solution
Questions # 46:

A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APAC. The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS . The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.

What is recommended to ensure these requirements are met ?

Options:

A.

Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.


B.

Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.


C.

Add a central identity system that federates between the ADFS systems and integrate with Salesforce for single sign-on.


D.

Configure Each ADFSsystem under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce-


Expert Solution
Questions # 47:

Which two capabilities does My Domain enable in the context of a SAML SSOconfiguration? Choose 2 answers

Options:

A.

App Launcher


B.

Resource deep linking


C.

SSO from Salesforce Mobile App


D.

Login Forensics


Expert Solution
Questions # 48:

An architect needsto set up a Facebook Authentication provider as login option for a salesforce customer Community. What portion of the authentication provider setup associates a Facebook user with a salesforce user?

Options:

A.

Consumer key and consumer secret


B.

Federation ID


C.

User info endpoint URL


D.

Apex registration handler


Expert Solution
Questions # 49:

Universal containers (UC) has a customer Community that uses Facebook for authentication. UC would like to ensure that changes in the Facebook profile are reflected on the appropriate customer Community user. How can this requirement be met?

Options:

A.

Use the updateuser() method on the registration handler class.


B.

Use SAML just-in-timeprovisioning between Facebook and Salesforce


C.

Use information in the signed request that is received from Facebook.


D.

Develop a schedule job that calls out to Facebook on a nightly basis.


Expert Solution
Questions # 50:

Northern Trail Outfitters (NTO) recently purchased Salesforce Identity Connect to streamline user provisioning across Microsoft Active Directory (AD) and Salesforce Sales Cloud.

NTO has asked an identity architect to identify which salesforce security configurations can map to AD permissions.

Which three Salesforce permissions are available to map to AD permissions?

Choose 3 answers

Options:

A.

Public Groups


B.

Field-Level Security


C.

Roles


D.

Sharing Rules


E.

Profiles and Permission Sets


Expert Solution
Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions