New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Salesforce Identity and Access Management Designer Identity-and-Access-Management-Architect Questions and answers with CertsForce

Viewing page 7 out of 8 pages
Viewing questions 61-70 out of questions
Questions # 61:

In a typical SSL setup involving a trusted party and trusting party, what consideration should an Architect take into account when using digital certificates?

Options:

A.

Use of self-signed certificate leads to lower maintenance for trusted party because multiple self-signed certs need to be maintained.


B.

Use of self-signed certificate leads to higher maintenance for trusted party because they have to act as the trusted CA


C.

Use of self-signed certificate leads to lowermaintenance for trusting party because there is no trusted CA cert to maintain.


D.

Use of self-signed certificate leads to higher maintenance for trusting party because the cert needs to be added to their truststore.


Expert Solution
Questions # 62:

architect is troubleshooting some SAML-based SSO errors during testing. The Architect confirmed that all of the Salesforce SSO settings are correct. Which two issues outside of the Salesforce SSO settings are most likely contributing to the SSO errors the Architect is encountering? Choose 2 Answers

Options:

A.

The Identity Provider is also used to SSO into five other applications.


B.

The clock on the Identity Provider server is twenty minutes behind Salesforce.


C.

The Issuer Certificate from the Identity Provider expired two weeks ago.


D.

The default language for the Identity Provider and Salesforce are Different.


Expert Solution
Questions # 63:

An architect has successfully configuredSAML-BASED SSO for universal containers. SSO has been working for 3 months when Universal containers manually adds a batch of new users to salesforce. The new users receive an error from salesforce when trying to use SSO. Existing users are still able to successfully use SSO to access salesforce. What is the probable cause of this behaviour?

Options:

A.

The administrator forgot to reset the new user's salesforce password.


B.

The Federation ID field on the new user records is not correctly set


C.

The my domaincapability is not enabled on the new user's profile.


D.

The new users do not have the SSO permission enabled on their profiles.


Expert Solution
Questions # 64:

Northern Trail Outfitters (NTO) believes a specific user account may have been compromised. NTO inactivated the user account and needs U perform a forensic analysis and identify signals that could Indicate a breach has occurred.

What should NTO's first step be in gathering signals that could indicate account compromise?

Options:

A.

Review the User record and evaluate the login and transaction history.


B.

Download the Setup Audit Trail and review all recent activities performed by the user.


C.

Download the Identity Provider Event Log and evaluate the details of activities performed by the user.


D.

Download the Login History and evaluate the details of logins performed by the user.


Expert Solution
Questions # 65:

UniversalContainers (UC) wants to build a few applications that leverage the Salesforce REST API. UC has asked its Architect to describe how the API calls will be authenticated to a specific user. Which two mechanisms can the Architect provide? Choose 2 Answers

Options:

A.

Authentication Token


B.

Session ID


C.

Refresh Token


D.

Access Token


Expert Solution
Questions # 66:

Universal containers (UC) has multiple salesforce orgs and would like to use a single identity provider to access all of their orgs. How should UC'S architect enable this behavior?

Options:

A.

Ensure that users have the same email value in their user records in all of UC's salesforce orgs.


B.

Ensure the same username is allowed in multiple orgs by contacting salesforce support.


C.

Ensure that users have the same Federation ID value in their user recordsin all of UC's salesforce orgs.


D.

Ensure that users have the same alias value in their user records in all of UC's salesforce orgs.


Expert Solution
Questions # 67:

Universal containers (UC) would like to enable self - registration for their salesforce partner community users. UC wants to capture some custom data elements from the partner user,and based on these data elements, wants to assign the appropriate profile and account values. Which two actions should the architect recommend to UC? Choose 2 answers

Options:

A.

Modify the communitiesselfregcontroller to assign the profile and account.


B.

Modify the selfregistration trigger to assign profile and account.


C.

Configure registration for communities to use a custom visualforce page.


D.

Configure registration for communities to use a custom apex controller.


Expert Solution
Questions # 68:

Universal Containers (UC) employees have Salesforce access from restricted IP ranges only, to protect against unauthorized access. UC wants to roll out the Salesforce1 mobile app and make it accessible from any location. Which two options should an Architect recommend? Choose 2 answers

Options:

A.

Relax the IP restriction with a second factor in the Connect App settings for Salesforce1 mobile app.


B.

Remove existing restrictions on IP ranges for all types of user access.


C.

Relax the IP restrictions in the Connect App settings for the Salesforce1 mobile app.


D.

Use Login Flow to bypass IP range restriction for the mobile app.


Expert Solution
Questions # 69:

Universal Containers is budding a web application that will connect with the Salesforce API using JWT OAuth Flow.

Which two settings need to be configured in the connect app to support this requirement?

Choose 2 answers

Options:

A.

The Use Digital Signature option in the connected app.


B.

The "web" OAuth scope in theconnected app,


C.

The "api" OAuth scope in the connected app.


D.

The "edair_api" OAuth scope m the connected app.


Expert Solution
Questions # 70:

An identity architect has been asked to recommend a solution that allows administrators to configure personalized alert messages to users before they land on the Experience Cloud site (formerly known as Community) homepage.

What is recommended to fulfill this requirement with the least amount of customization?

Options:

A.

Customize the registration handler Apex class to create a routing logic navigating to different home pages based on the user profile.


B.

Use Login Flows to add a screen that shows personalized alerts.


C.

Build aLightning web Component (LWC) for a homepage that shows custom alerts.


D.

Create custom metadata that stores user alerts and use a LWC to display alerts.


Expert Solution
Viewing page 7 out of 8 pages
Viewing questions 61-70 out of questions