Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 6 out of 8 pages
Viewing questions 51-60 out of questions
Questions # 51:

Universal containers (UC) has a classifiedinformation system that it's call centre team uses only when they are working on a case with a record type of "classified". They are only allowed to access the system when they own an open "classified" case, and their access to the system is removed at allother times. They would like to implement SAML SSO with salesforce as the IDP, and automatically allow or deny the staff's access to the classified information system based on whether they currently own an open "classified" case record when they try to access the system using SSO. What is the recommended solution for automatically allowing or denying access to the classified information system based on the open "classified" case record criteria?

Options:

A.

Use a custom connected App handler using apex to dynamically allow access to the system based on whether the staff owns any open "classified" cases.


B.

Use apex trigger on case to dynamically assign permission sets that grant access when a user is assigned with an open "classified" case, and remove it when the case is closed.


C.

Use custom SAML jit provisioning to dynamically query the user's open "classified" cases when attempting to access the classified information system


D.

Use salesforce reports to identify users that currently owns open "classified" cases and should be granted access to the classified information system.


Expert Solution
Questions # 52:

Which three different attributes can be used to identify the user in a SAML 65> assertion when Salesforce is acting as a Service Provider? Choose 3 answers

Options:

A.

Federation ID


B.

Salesforce User ID


C.

User Full Name


D.

User Email Address


E.

Salesforce Username


Expert Solution
Questions # 53:

Universal Container's (UC) is using Salesforce Experience Cloud site for its containerwholesale business. The identity architect wants to an authentication provider for the new site.

Which two options should be utilized in creating an authentication provider?

Choose 2 answers

Options:

A.

A custom registration handier can be set.


B.

A custom error URL can be set.


C.

The default login user can be set.


D.

The default authentication provider certificate can be set.


Expert Solution
Questions # 54:

Universal Containers (UC) operates in Asia, Europe and North America regions. There is one Salesforce org for each region. UC is implementing Customer 360 in Salesforce and has procured External Identity and Customer Community licenses in all orgs.

Customers of UC use Community to track orders and create inquiries. Customers also tend to move across regions frequently.

What should an identity architect recommend to optimize license usage and reduce maintenance overhead?

Options:

A.

Merge three orgs into one instance of Salesforce. This will no longer require maintaining three separate copies of the same customer.


B.

Delete contact/account records and deactivate user if user moves from a specific region; Sync will no longer be required.


C.

Contacts are required since Community access needs to be enabled. Maintenance is a necessary overhead that must be handled via data integration.


D.

D. Enable Contactless User in all orgs and downgrade users from Experience Cloud license to External Identity license once users have moved out of that region.


Expert Solution
Questions # 55:

Universal containers(UC) has decided to build a new, highly sensitive application on Force.com platform. The security team at UC has decided that they want users toprovide a fingerprint in addition to username/Password to authenticate to this application.How can an architect support fingerprint as a form of identification for salesforce Authentication?

Options:

A.

Use salesforce Two-factor Authentication with callouts to a third-party fingerprint scanning application.


B.

Use Delegated Authentication with callouts to a third-party fingerprint scanning application.


C.

Use an AppExchange product that does fingerprint scanning with native salesforce identity confirmation.


D.

Use custom login flows with callouts to a third-party fingerprint scanning application.


Expert Solution
Questions # 56:

Universal containers (UC) has built a custom based Two-factorAuthentication (2fa) system for their existing on-premise applications. Thru are now implementing salesforce and would like to enable a Two-factor login process for it, as well. What is the recommended solution an architect should consider?

Options:

A.

Replace thecustom 2fa system with salesforce 2fa for on-premise application and salesforce.


B.

Use the custom 2fa system for on-premise applications and native 2fa for salesforce.


C.

Replace the custom 2fa system with an app exchange app that supports on-premise applications and salesforce.


D.

Use custom login flows to connect to the existing custom 2fa system for use in salesforce.


Expert Solution
Questions # 57:

Universal Containers (UC) has built a custom time tracking app for its employee. UC wants to leverage Salesforce Identity to control access to the custom app.

At a minimum, which Salesforce license is required to support this requirement?

Options:

A.

Identity Verification


B.

Identity Connect


C.

Identity Only


D.

External Identity


Expert Solution
Questions # 58:

Universal Containers (UC) has an e-commerce website where customers can buy products, make payments, and manage their accounts. UC decides tobuild a Customer Community on Salesforce and wants to allow the customers to access the community from their accounts without logging in again. UC decides to implement an SP-initiated SSO using a SAML-compliant Idp. In this scenario where Salesforce is theService Provider, which two activities must be performed in Salesforce to make SP-initiated SSO work? Choose 2 answers

Options:

A.

Configure SAML SSO settings.


B.

Create a Connected App.


C.

Configure Delegated Authentication.


D.

Set up My Domain.


Expert Solution
Questions # 59:

Northern Trail Outfitters (NTO) wants to improve its engagement with existing customers to boost customer loyalty. To get a better understanding of its customers, NTO establishes a single customer view including their buying behaviors, channel preferences and purchasing history. All of this information exists but is spread across different systems and formats.

NTO has decided to use Salesforce as the platform to build a 360 degree view. The company already uses Microsoft Active Directory (AD) to manage its users and company assets.

What should an Identity Architect do to provision, deprovision and authenticate users?

Options:

A.

Salesforce Identity is not needed since NTO uses Microsoft AD.


B.

Salesforce Identity can be included but NTO will be required to build a custom integration with Microsoft AD.


C.

Salesforce Identity is included in the Salesforce licenses so it does not need to be considered separately.


D.

A Salesforce Identity can be included but NTO will require Identity Connect.


Expert Solution
Questions # 60:

Universal Containers (UC) is building an authenticated Customer Community for its customers. UC does not want customer credentialsstored in Salesforce and is confident its customers would be willing to use their social media credentials to authenticate to the community. Which two actions should an Architect recommend UC to take?

Options:

A.

Use Delegated Authentication to call the Twitter login API to authenticate users.


B.

Configure an Authentication Provider for LinkedIn Social Media Accounts.


C.

Create a Custom Apex Registration Handler to handle new and existing users.


D.

Configure SSO Settings For Facebook to serve as a SAML Identity Provider.


Expert Solution
Viewing page 6 out of 8 pages
Viewing questions 51-60 out of questions