Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions
Questions # 41:

Northern Trail Outfitters manages application functional permissions centrally as ActiveDirectory groups. The CRM_Superllser and CRM_Reportmg_SuperUser groups should respectively give the user the SuperUser and Reportmg_SuperUser permission set in Salesforce. Salesforce is the service provider to a Security Assertion Markup Language (SAML) identity provider.

Mow should an identity architect ensure the Active Directory groups are reflected correctly when a user accesses Salesforce?

Options:

A.

Use the Apex Just-in-Time handler to query standard SAML attributes and set permission sets.


B.

Use the ApexJust-in-Time handler to query custom SAML attributes and set permission sets.


C.

Use a login flow to query custom SAML attributes and set permission sets.


D.

Use a login flow to query standard SAML attributes and set permission sets.


Expert Solution
Questions # 42:

Universal Containers (UC) has decided touse Salesforce as an Identity Provider for multiple external applications. UC wants to use the salesforce App Launcher to control the Apps that are available to individual users. Which three steps are required to make this happen?

Options:

A.

Add each connected Appto the App Launcher with a Start URL.


B.

Set up an Auth Provider for each External Application.


C.

Set up Salesforce as a SAML Idp with My Domain.


D.

Set up Identity Connect to Synchronize user data.


E.

Create a Connected App for each external application.


Expert Solution
Questions # 43:

Universal containers (UC) has implemented ansp-Initiated SAML flow between an external IDP and salesforce. A user at UC is attempting to login to salesforce1 for the first time and is being prompted for salesforce credentials instead of being shown the IDP login page. What is the likely cause of the issue?

Options:

A.

The "Redirect to IdentityProvider" option has been selected in the my domain configuration.


B.

The user has not configured the salesforce1 mobile app to use my domain for login


C.

The "Redirect to identity provider" option has not been selected the SAML configuration.


D.

The userhas not been granted the "Enable single Sign-on" permission


Expert Solution
Questions # 44:

Which two roles of the systems are involved in an environment where salesforce users are enabled to access Google Apps from withinsalesforce through App launcher and connected App set up? Choose 2 answers

Options:

A.

Google is the identity provider


B.

Salesforce is the identity provider


C.

Google is the service provider


D.

Salesforce is the service provider


Expert Solution
Questions # 45:

A manufacturer wants to provide registration for an Internet of Things (IoT) device with limited display input or capabilities.

WhichSalesforce OAuth authorization flow should be used?

Options:

A.

OAuth 2.0 JWT Bearer How


B.

OAuth 2.0 Device Flow


C.

OAuth 2.0 User-Agent Flow


D.

OAuth 2.0 Asset Token Flow


Expert Solution
Questions # 46:

Containers (UC) has implemented SAML-based single Sign-on for their Salesforce application and is planning to provide access to Salesforce on mobile devices using the Salesforce1 mobile app. UC wants to ensure that Single Sign-on is used for accessing the Salesforce1 mobile App. Which two recommendations should the Architect make? Choose 2 Answers

Options:

A.

Configure the Embedded Web Browser to use My Domain URL.


B.

Configure the Salesforce1 App to use the MY Domain URL.


C.

Use the existing SAML-SSO flow along with User Agent Flow.


D.

Use the existing SAML SSO flow along with Web Server Flow.


Expert Solution
Questions # 47:

NorthernTrail Outfitters (NTO) leverages Microsoft Active Directory (AD) for management of employee usernames, passwords, permissions, and asset access. NTO also owns a third-party single sign-on (SSO) solution. The third-party party SSO solution is used for all corporate applications, including Salesforce.

NTO has asked an architect to explore Salesforce Identity Connect for automatic provisioning and deprovisioning of users in Salesforce.

What role does identity Connect play in the outlined requirements?

Options:

A.

Service Provider


B.

Single Sign-On


C.

Identity Provider


D.

User Management


Expert Solution
Questions # 48:

Universal Containers (UC) has implemented SSO according to the diagram below. uses SAML while Salesforce Org1 uses OAuth 2.0. Users usually start their day by first attempting to log into Salesforce Org 2 and then later in the day, they will log into either the Financial System or CPQ system depending upon their job position. Which two systems are acting as Identity Providers?

Options:

A.

Financial System


B.

Pingfederate


C.

Salesforce Org 2


D.

Salesforce Org 1


Expert Solution
Questions # 49:

Northern Trail Outfitters (NTO) is launching a new sportswear brand on its existing consumer portal built on Salesforce Experience Cloud. As part of the launch, emails with promotional links will be sent to existing customers to log in and claim a discount. The marketing manager would like the portal dynamically branded so that users will be directed to the brand link they clicked on; otherwise, users will view a recognizable NTO-branded page.

The campaign is launching quickly, so there is no time to procure any additional licenses. However, the development team is available to apply any required changes to the portal.

Which approach should the identity architect recommend?

Options:

A.

Create a full sandbox to replicate the portal site and update the branding accordingly.


B.

Implement Experience ID in the code and extend the URLs and endpoints, as required.


C.

Use Heroku to build the new brand site and embedded login to reuse identities.


D.

Configure an additional community site on the same org that is dedicated for the new brand.


Expert Solution
Questions # 50:

customer service representatives at Universal containers (UC) are complaining that whenever they click on links to case records and are asked to login with SAML SSO, they are beingredirected to the salesforce home tab and not the specific case record. What item should an architect advise the identity team at UC to investigate first?

Options:

A.

My domain is configured and active within salesforce.


B.

The salesforce SSO settings are using http post


C.

The identity provider is correctly preserving the Relay state


D.

The users have the correct Federation ID within salesforce.


Expert Solution
Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions