New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 6 out of 8 pages
Viewing questions 51-60 out of questions
Questions # 51:

A group of userstry to access one of universal containers connected apps and receive the following error message: "Failed : Not approved for access". what is most likely to cause of the issue?

Options:

A.

The use of high assurance sections are required for the connected App.


B.

The users do not have the correct permission set assigned to them.


C.

The connected App setting "All users may self-authorize" is enabled.


D.

The salesforce administrators gave revoked the Oauth authorization.


Expert Solution
Questions # 52:

Universal containers (UC) have a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a connected App in salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properlysecure access to the app. Which two are recommendations to make the UC? Choose 2 answers

Options:

A.

Disallow the use of single Sign-on for any users of the mobile app.


B.

Require high assurance sessions in order to use the connected App


C.

Use Google Authenticator as an additional part of the logical processes.


D.

Set login IP ranges to the internal network for all of the app users profiles.


Expert Solution
Questions # 53:

Universal Containers (UC) has implemented a multi-org architecture in their company. Many users have licences across multiple orgs, and they are complaining about remembering which org and credentials are tied to which business process. Which two recommendations should the Architect make to address the Complaints? Choose 2 answers

Options:

A.

Activate My Domain to Brand each org to the specific business use case.


B.

Implement SP-Initiated Single Sign-on flows to allow deep linking.


C.

ImplementIdP-Initiated Single Sign-on flows to allow deep linking.


D.

Implement Delegated Authentication from each org to the LDAP provider.


Expert Solution
Questions # 54:

A security architect is rolling out a new multi-factor authentication (MFA) mandate, where all employees must go through a secure authentication process before accessing Salesforce. There are multiple Identity Providers (IdP) in place and the architect is considering how the "Authentication Method Reference" field (AMR) in the Login History can help.

Which two considerations should the architect keep in mind?

Choose 2 answers

Options:

A.

AMR field shows the authentication methods used at IdP.


B.

Both OIDC and Security Assertion Markup Language (SAML) are supported but AMR must be implemented at IdP.


C.

High-assurance sessions must be configured under Session Security Level Policies.


D.

Dependency on what is supported by OpenID Connect (OIDC) implementation at IdP.


Expert Solution
Questions # 55:

Universal Containers want users to be able to log in to the Salesforce mobile app with their Active Directory password. Employees are unable to use mobile VPN.

Which two options should an identity architect recommend to meet therequirement?

Choose 2 answers

Options:

A.

Active Directory Password Sync Plugin


B.

Configure Cloud Provider Load Balancer


C.

Salesforce Trigger & Field on Contact Object


D.

Salesforce Identity Connect


Expert Solution
Questions # 56:

Northern Trail Outfitters (NTO) is setting up Salesforce to authenticate users with an external identity provider. The NTO Salesforce Administrator is having trouble getting things setup.

What should an identity architect use to show which part of the login assertion is fading?

Options:

A.

SAML Metadata file importer


B.

Identity Provider Metadata download


C.

Connected App Manager


D.

Security Assertion Markup Language Validator


Expert Solution
Questions # 57:

A division of a Northern Trail Outfitters (NTO) purchased Salesforce. NTO uses a third party identity provider (IdP) to validate user credentials against Its corporate Lightweight Directory Access Protocol (LDAP) directory. NTO wants to help employees remember as passwords as possible.

What should an identity architect recommend?

Options:

A.

Setup Salesforce as a Service Provider to the existing IdP.


B.

SetupSalesforce as an IdP to authenticate against the LDAP directory.


C.

Use Salesforce connect to synchronize LDAP passwords to Salesforce.


D.

Setup Salesforce as an Authentication Provider to the existing IdP.


Expert Solution
Questions # 58:

ON NO: 126

Universal containers (UC) is successfully using Delegated Authentication for their salesforce users. The service supporting Delegated Authentication is written in Java. UC has a new CIO that is requiring all company Web services be RESR-ful andwritten in. NET. Which two considerations should the UC Architect provide to the new CIO? Choose 2 answers

Options:

A.

Delegated Authentication will not work with a.net service.


B.

Delegated Authentication will continue to work with rest services.


C.

Delegated Authentication will continue to work with a.net service.


D.

Delegated Authentication will not work with rest services.


Expert Solution
Questions # 59:

Universal Containers (UC) is building a custom Innovation platform on their Salesforce instance. The Innovation platform willbe written completely in Apex and Visualforce and will use custom objects to store the Data. UC would like all users to be able to access the system without having to log in with Salesforce credentials. UC will utilize a third-party idp using SAML SSO. What is the optimal Salesforce licence type for all of the UC employees?

Options:

A.

Identity Licence.


B.

Salesforce Licence.


C.

External Identity Licence.


D.

Salesforce Platform Licence.


Expert Solution
Questions # 60:

Universal containers (UC) has decided to use identity connect as it's identity provider. UC uses active directory(AD) and has a team that is very familiar and comfortable with managing ad groups. UC would like to use AD groups to help configure salesforce users. Which three actions can AD groups control through identity connect? Choose 3 answers

Options:

A.

Public Group Assignment


B.

Granting report folder access


C.

Role Assignment


D.

Custom permission assignment


E.

Permission sets assignment


Expert Solution
Viewing page 6 out of 8 pages
Viewing questions 51-60 out of questions