
Pass Your Identity-and-Access-Management-Designer Dumps as PDF Updated on 2021 With 192 Questions
Salesforce Identity-and-Access-Management-Designer Real Exam Questions and Answers FREE
Identity-and-Access-Management-Designer Exam topics
Candidates must know the exam topics before they start of preparation. Because it will really help them in hitting the core. Our Salesforce Identity-and-Access-Management-Designer dumps will include the following topics:
- Salesforce Identity 7%
- Identity Management Concepts 28%
- Access Management Best Practices 15%
- Community (Partner and Customer) 5%
- Salesforce as an Identity Provider 23%
- Accepting Third-Party Identity in Salesforce 22%
NEW QUESTION 70
Universal Containers (UC) would like its community users to be able to register and log in with Linkedin or Facebook Credentials. UC wants users to clearly see Facebook &Linkedin Icons when they register and login.
What are the two recommended actions UC can take to achieve this Functionality? Choose 2 answers
- A. Store the Linkedin or Facebook user IDs in the Federation ID field on the Salesforce User record.
- B. Create custom Registration Handlers to link Linkedin and facebook accounts to user records.
- C. Enable Facebook and Linkedin as Login options in the login section of the Community configuration.
- D. Create custom buttons for Facebook and inkedin using JAVAscript/CSS on a custom Visualforce page.
Answer: B,C
NEW QUESTION 71
Universal Containers (UC) has a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a connected App in Salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properly secure access to the app. Which two are recommendations to make the UC? Choose 2 answers
- A. Set Login IP Ranges to the internal network for all of the app users Profiles.
- B. Disallow the use of Single Sign-on for any users of the mobile app.
- C. Require High Assurance sessions in order to use the Connected App.
- D. Use Google Authenticator as an additional part of the login process
Answer: C,D
NEW QUESTION 72
An Architect needs to advise the team that manages the Identity Provider how to differentiate Salesforce from other Service Providers. What SAML SSO setting in Salesforce provides this capability?
- A. Issuer.
- B. SAML Identity Location.
- C. Identity Provider Login URL.
- D. Entity Id
Answer: B
NEW QUESTION 73
Universal containers (UC) has implemented a multi-org strategy and would like to centralize the management of their salesforce user profiles. What should the architect recommend to allow salesforce profiles to be managed from a central system of record?
- A. Implement an Oauthjwt flow to pass the profile credentials between systems.
- B. Implement Delegated Authentication that will update the user profiles as necessary.
- C. Create an apex scheduled job in one org that will synchronize the other orgs profile.
- D. Implement jit provisioning on the SAML IDP that will pass the profile id in each assertion.
Answer: D
NEW QUESTION 74
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers will utilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?
- A. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
- B. Use SAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
- C. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML to allow SSO.
- D. Use a nightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
Answer: C
NEW QUESTION 75
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers will utilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?
- A. Use SAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
- B. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
- C. Use a nightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
- D. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML to allow SSO.
Answer: A
NEW QUESTION 76
Universal Containers (UC) is setting up delegated authentication to allow employees to log in using their corporate credentials. UC's security team is concerned about the risks of exposing the corporate login service on the internet and has asked that a reliable trust mechanism be put in place between the login service and Salesforce.
What mechanism should an Architect put in place to enable a trusted connection between the login service and Salesforce?
- A. Enforce mutual authentication between systems using SSL.
- B. Include Client Id and Client Secret in the login header callout.
- C. Require the use of Salesforce security tokens on passwords.
- D. Set up a proxy service for the login service in the DMZ.
Answer: C
NEW QUESTION 77
Universal containers (UC) has built a custom based Two-factor Authentication (2fa) system for their existing on-premise applications. Thru are now implementing salesforce and would like to enable a Two-factor login process for it, as well. What is the recommended solution an architect should consider?
- A. Use the custom 2fa system for on-premise applications and native 2fa for salesforce.
- B. Use custom login flows to connect to the existing custom 2fa system for use in salesforce.
- C. Replace the custom 2fa system with an app exchange app that supports on-premise applications and salesforce.
- D. Replace the custom 2fa system with salesforce 2fa for on-premise application and salesforce.
Answer: B
NEW QUESTION 78
The CIO of universal containers(UC) wants to start taking advantage of the refresh token capability for the UC applications that utilize Oauth 2.0. UC has listed an architect to analyze all of the applications that use Oauth flows to. See where refresh Tokens can be applied. Which two OAuth flows should the architect consider in their evaluation? Choose 2 answers
- A. Jwt bearer token
- B. Web server
- C. User-Agent
- D. Username-password
Answer: B,C
NEW QUESTION 79
Universal containers (UC) would like to enable SAML-BASED SSO for a salesforce partner community. UC has an existing ldap identity store and a third-party portal. They would like to use the existing portal as the primary site these users access, but also want to allow seamless access to the partner community. What SSO flow should an architect recommend?
- A. User-Agent
- B. Sp-Initiated
- C. IDP-initiated
- D. Web server
Answer: C
NEW QUESTION 80
How should an identity architect automate provisioning and deprovisioning of users into Salesforce from an external system?
- A. Run registration handler on incoming OAuth responses.
- B. Call SOAP API upsertQ on user object.
- C. Call OpenID Connect (OIDC)-userinfo endpoint with a valid access token.
- D. Use Security Assertion Markup Language Just-in-Time (SAML JIT) on incoming SAML assertions.
Answer: A
NEW QUESTION 81
Universal Containers (UC) uses Active Directory (AD) as their identity store for employees and must continue to do so for network access. UC is undergoing a major transformation program and moving all of their enterprise applications to cloud platforms including Salesforct, Workday, and SAP HANA.
UC needs to implement an SSO solution for accessing all of the third-party cloud applications and the CIO is inclined to use Salesforce for all of their identity and access management needs.
Which two Salesforce license types does UC need for its employees'
Choose 2 answers
- A. Identity and Identity Connect licenses
- B. Salesforce and Identity Connect licenses
- C. Chatter Only and Identity licenses
- D. Company Community and Identity licenses
Answer: A,B
NEW QUESTION 82
Universal Containers (UC) wants to build a mobile application that twill be making calls to the Salesforce REST API. UC's Salesforce implementation relies heavily on custom objects and custom Apex code. UC does not want its users to have to enter credentials every time they use the app. Which two scope values should an Architect recommend to UC? Choose 2 answers.
- A. Custom_permissions
- B. Refresh_token
- C. Api
- D. Full
Answer: B,C
NEW QUESTION 83
A leading fitness tracker company is getting ready to launch a customer community. The company wants its customers to login to the community and connect their fitness device to their profile. Customers should be able to obtain exercise details and fitness recommendation In the community.
Which should be used to satisfy this requirement?
- A. Login Flows
- B. Named Credentials
- C. OAuth Device Plow
- D. Single Sign-On Settings
Answer: C
NEW QUESTION 84
Universal Containers (UC) has decided to replace the homegrown customer portal with Salesforce Experience Cloud. UC will continue to use its third-party single sign-on (SSO) solution that stores all of its customer and partner credentials.
The first time a customer logs in to the Experience Cloud site through SSO, a user record needs to be created automatically.
Which solution should an identity architect recommend in order to automatically provision users in Salesforce upon login?
- A. Third-party AppExchange solution
- B. Just-in-Time (JIT) provisioning
- C. Custom middleware and web services
- D. Custom login flow and Apex handler
Answer: B
NEW QUESTION 85
Universal containers (UC) has multiple salesforce orgs and would like to use a single identity provider to access all of their orgs. How should UC'S architect enable this behavior?
- A. Ensure that users have the same alias value in their user records in all of UC's salesforce orgs.
- B. Ensure that users have the same Federation ID value in their user records in all of UC's salesforce orgs.
- C. Ensure the same username is allowed in multiple orgs by contacting salesforce support.
- D. Ensure that users have the same email value in their user records in all of UC's salesforce orgs.
Answer: B
NEW QUESTION 86
Universal Containers (UC) employees have Salesforce access from restricted IP ranges only, to protect against unauthorised access. UC wants to roll out the Salesforce1 mobile app and make it accessible from any location. Which two options should an Architect recommend? Choose 2 answers
- A. Remove existing restrictions on IP ranges for all types of user access.
- B. Use Login Flow to bypass IP range restriction for the mobile app.
- C. Relax the IP restrictions in the Connect App settings for the Salesforce1 mobile app.
- D. Relax the IP restriction with a second factor in the Connect App settings for Salesforce1 mobile app.
Answer: A,B
NEW QUESTION 87
The security team at Universal containers(UC) has identified exporting reports as a high-risk action and would like to require users to be logged into salesforce with their active directory (AD) credentials when doing so. For all other uses of Salesforce, Users should be allowed to use AD credentials or salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with salesforce credentials?
- A. Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.
- B. Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.
- C. Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.
- D. Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.
Answer: B
NEW QUESTION 88
Universal Containers has implemented a multi-org strategy and would like to centralize the management of their Salesforce user profiles.
What should the Architect recommend to allow Salesforce profiles to be managed from a central system of record?
- A. Implement Delegated Authentication that will update the user profiles as necessary.
- B. Create an Apex scheduled job in one org that will synchronize the other org's profiles.
- C. Implement an OAuth JWT flow to pass the profile credentials between systems.
- D. Implement JIT provisioning on the SAML IdP that will pass the ProfileID in each assertion.
Answer: D
NEW QUESTION 89
Universal Containers wants to allow its customers to log in to its Experience Cloud via a third party authentication provider that supports only the OAuth protocol.
What should an identity architect do to fulfill this requirement?
- A. Use certificate-based authentication.
- B. Contact Salesforce Support and enable delegate single sign-on.
- C. Configure OpenID Connect authentication provider.
- D. Create a custom external authentication provider.
Answer: D
NEW QUESTION 90
The security team at Universal Containers (UC) has identified exporting reports as a high-risk action and would like to require users to be logged into Salesforce with their Active Directory (AD) credentials when doing so. For all other users of Salesforce, users should be allowed to use AD Credentials or Salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with Salesforce credentials?
- A. Use SAML Federated Authentication and block access to reports when accessed through a Standard Assurance session.
- B. Use SAML federated Authentication with a Login Flow to dynamically add or remove a Permission Set that grants the Export Reports Permission.
- C. Use SAML federated Authentication, treat SAML Sessions as High Assurance, and raise the session level required for exporting reports.
- D. Use SAML Federated Authentication and Custom SAML JIT Provisioning to dynamically and or remove a permission set that grants the Export Reports Permission.
Answer: A
NEW QUESTION 91
In a typical SSL setup involving a trusted party and trusting party, what consideration should an Architect take into account when using digital certificates?
- A. Use of self-signed certificate leads to lower maintenance for trusted party because multiple self-signed certs need to be maintained.
- B. Use of self-signed certificate leads to higher maintenance for trusting party because the cert needs to be added to their truststore.
- C. Use of self-signed certificate leads to lower maintenance for trusting party because there is no trusted CA cert to maintain.
- D. Use of self-signed certificate leads to higher maintenance for trusted party because they have to act as the trusted CA
Answer: C
NEW QUESTION 92
The security team at Universal Containers has identified exporting reports as a high-risk action and would like to require users to be logged into Salesforce with their Active Directory (AD) credentials when doing so.
For all other uses of Salesforce, users should be allowed to use AD credentials or Salesforce credentials.
What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with Salesforce credentials?
- A. Use SAML Federated Authentication and Custom SAML JIT Provisioning to dynamically add or remove a Permission Set that grants the Export Reports permission.
- B. Use SAML Federated Authentication and block access to reports when accessed through a Standard Assurance session.
- C. Use SAML Federated Authentication with a Login Flow to dynamically add or remove a Permission Set that grants the Export Reports permission.
- D. Use SAML Federated Authentication, treat SAML Sessions as High Assurance, and raise the session level required for exporting reports.
Answer: D
NEW QUESTION 93
......
Pass Salesforce Identity-and-Access-Management-Designer Exam Info and Free Practice Test: https://www.dumpsking.com/Identity-and-Access-Management-Designer-testking-dumps.html
New 2021 Latest Questions Identity-and-Access-Management-Designer Dumps - Use Updated Salesforce Exam: https://drive.google.com/open?id=1qRL-OuByHzmK5JcQfkzSm-hetOD295ge
