[Jun 24, 2023] Get Latest and 100% Accurate Identity-and-Access-Management-Architect Exam Questions [Q78-Q101]

Share

[Jun 24, 2023] Get Latest and 100% Accurate Identity-and-Access-Management-Architect Exam Questions

Maximum Grades By Making ready With Identity-and-Access-Management-Architect Dumps


The Salesforce Certified Identity and Access Management Architect is a certification exam that tests an individual's knowledge of Salesforce's identity and access management (IAM) architecture. This certification is designed for professionals who are responsible for designing and implementing IAM solutions for their organizations. The exam covers a range of topics, including user authentication, authorization, identity federation, and single sign-on (SSO).


The Salesforce Identity-and-Access-Management-Architect exam is a challenging test that requires a thorough understanding of the Salesforce platform and its IAM features. Candidates must have a deep knowledge of the different types of users and the permissions and roles associated with them. They must also be able to design IAM solutions that meet the needs of different types of organizations, from small businesses to large enterprises.

 

NEW QUESTION # 78
A client is planning to rollout multi-factor authentication (MFA) to its internal employees and wants to understand which authentication and verification methods meet the Salesforce criteria for secure authentication.
Which three functions meet the Salesforce criteria for secure mfa?
Choose 3 answers

  • A. username and password + SMS passcode
  • B. Certificate-based Authentication
  • C. Username and password + secunty key
  • D. Lightning Login
  • E. Third-party single sign-on with Mobile Authenticator app

Answer: C,D,E


NEW QUESTION # 79
Northern Trail Outfitters is implementing a busmess-to-business (B2B) collaboration site using Salesforce Experience Cloud. The partners will authenticate with an existing identity provider and the solution will utilize Security Assertion Markup Language (SAML) to provide single sign-on to Salesforce. Delegated administration will be used in the Expenence Cloud site to allow the partners to administer their users' access.
How should a partner identity be provisioned in Salesforce for this solution?

  • A. Create a contactless user.
  • B. Create only a contact.
  • C. Create a person account.
  • D. Create a user and a related contact.

Answer: D


NEW QUESTION # 80
Universal Containers is creating a web application that will be secured by Salesforce Identity using the OAuth
2.0 Web Server Flow uses the OAuth 2.0 authorization code grant type).
Which three OAuth concepts apply to this flow?
Choose 3 answers

  • A. Access Token
  • B. Verification URL
  • C. Client Secret
  • D. Scopes

Answer: A,C,D


NEW QUESTION # 81
IT security at Unversal Containers (UC) us concerned about recent phishing scams targeting its users and wants to add additional layers of login protection. What should an Architect recommend to address the issue?

  • A. Implement Single Sign-on using a corporate Identity store.
  • B. Use the Salesforce Authenticator mobile app with two-step verification
  • C. Lock sessions to the IP address from which they originated.
  • D. Increase Password complexity requirements in Salesforce.

Answer: B


NEW QUESTION # 82
Northern Trail Outfitters (NTO) uses Salesforce for Sales Opportunity Management. Okta was recently brought in to Just-in-Time (JIT) provision and authenticate NTO users to applications. Salesforce users also use Okta to authorize a Forecasting web application to access Salesforce records on their behalf.
Which two roles are being performed by Salesforce?
Choose 2 answers

  • A. SAML Identity Provider
  • B. OAuth Resource Server
  • C. SAML Service Provider
  • D. OAuth Client

Answer: C,D


NEW QUESTION # 83
Universal containers (UC) uses a home-grown employee portal for their employees to collaborate. UC decides to use salesforce ideas to allow the employees to post ideas from the employee portal. When clicking some links in the employee portal, the users should be redirected to salesforce, authenticated, and presented with relevant pages. What scope should be requested when using the Oauth token to meet this requirement?

  • A. Full
  • B. API
  • C. Visualforce
  • D. Web

Answer: D


NEW QUESTION # 84
A financial enterprise is planning to set up a user authentication mechanism to login to the Salesforce system.
Due to regulatory requirements, the CIO of the company wants user administration, including passwords and authentication requests, to be managed by an external system that is only accessible via a SOAP webservice.
Which authentication mechanism should an identity architect recommend to meet the requirements?

  • A. Delegated Authentication
  • B. OAuth Web-Server Flow
  • C. Just-in-Time Provisioning
  • D. Identity Connect

Answer: A


NEW QUESTION # 85
Universal Container's (UC) is using Salesforce Experience Cloud site for its container wholesale business. The identity architect wants to an authentication provider for the new site.
Which two options should be utilized in creating an authentication provider?
Choose 2 answers

  • A. The default authentication provider certificate can be set.
  • B. A custom error URL can be set.
  • C. A custom registration handier can be set.
  • D. The default login user can be set.

Answer: B,C


NEW QUESTION # 86
A group of users try to access one of Universal Containers' Connected Apps and receive the following error message: " Failed: Not approved for access." What is the most likely cause of this issue?

  • A. The Users do not have the correct permission set assigned to them.
  • B. The Connected App settings "All users may self-authorize" is enabled.
  • C. The User of High Assurance sessions are required for the Connected App.
  • D. The Salesforce Administrators have revoked the OAuth authorization.

Answer: A


NEW QUESTION # 87
A university is planning to set up an identity solution for its alumni. A third-party identity provider will be used for single sign-on Salesforce will be the system of records. Users are getting error messages when logging in.
Which Salesforce feature should be used to debug the issue?

  • A. Apex Exception Email
  • B. View Setup Audit Trail
  • C. Debug Logs
  • D. Login History

Answer: D


NEW QUESTION # 88
Universal containers (UC) wants users to authenticate into their salesforce org using credentials stored in a custom identity store. UC does not want to purchase or use a third-party Identity provider. Additionally, UC is extremely wary of social media and does not consider it to be trust worthy. Which two options should an architect recommend to UC? Choose 2 answers

  • A. Build a custom web page that uses the identity store and calls frontdoor.jsp
  • B. Use a professional social media such as LinkedIn as an Authentication provider
  • C. Build a custom Web service that is supported by Delegated Authentication.
  • D. Implement the Openid protocol and configure an Authentication provider

Answer: C,D


NEW QUESTION # 89
A financial services company uses Salesforce and has a compliance requirement to track information about devices from which users log in. Also, a Salesforce Security Administrator needs to have the ability to revoke the device from which users log in.
What should be used to fulfill this requirement?

  • A. Use Login Flows to capture device from which users log in and store device and user information in a custom object.
  • B. Use the Activations feature to meet the compliance requirement to track device information.
  • C. Use the Login History object to track information about devices from which users log in.
  • D. Use multi-factor authentication (MFA) to meet the compliance requirement to track device information.

Answer: B


NEW QUESTION # 90
Universal Containers (UC) built an integration for their employees to post, view, and vote for ideas in Salesforce from an internal Company portal. When ideas are posted in Salesforce, links to the ideas are created in the company portal pages as part of the integration process. The Company portal connects to Salesforce using OAuth. Everything is working fine, except when users click on links to existing ideas, they are always taken to the Ideas home page rather than the specific idea, after authorization. Which OAuth URL parameter can be used to retain the original requested page so that a user can be redirected correctly after OAuth authorization?

  • A. Redirect_uri
  • B. Scope
  • C. State
  • D. Callback_uri

Answer: A


NEW QUESTION # 91
Universal containers (UC) has an e-commerce website while customers can buy products, make payments, and manage their accounts. UC decides to build a customer Community on Salesforce and wants to allow the customers to access the community for their accounts without logging in again. UC decides to implement ansp-Initiated SSO using a SAML-BASED complaint IDP. In this scenario where salesforce is the service provider, which two activities must be performed in salesforce to make sp-Initiated SSO work? Choose 2 answers

  • A. Configure SAML SSO settings.
  • B. Set up my domain
  • C. Create a connected App
  • D. Configure Delegated Authentication

Answer: A,B


NEW QUESTION # 92
Universal Containers (UC) has implemented SAML-based Single Sign-On to provide seamless access to its Salesforce Orgs, financial system, and CPQ system. Below is the SSO implementation landscape.

What role combination is represented by the systems in this scenario''

  • A. Salesforce Org1 and Salesforce Org2 are acting as Identity Providers.
  • B. Salesforce Org1 and Salesforce Org2 are the only Service Providers.
  • C. Salesforce Org1 and PingFederate are acting as Identity Providers.
  • D. Financial System and CPQ System are the only Service Providers.

Answer: C


NEW QUESTION # 93
Universal Containers (UC) wants to build a custom mobile app for their field reps to create orders in salesforce. After the first time the users log in, they must be able to access salesforce upon opening the mobile app without being prompted to log in again. What Oauth flows should be considered to support this requirement?

  • A. SAML Assertion flow with a Bearer Token.
  • B. Web Server flow with a Refresh Token.
  • C. User Agent flow with a Refresh Token.
  • D. Mobile Agent flow with a Bearer Token.

Answer: C


NEW QUESTION # 94
A company's external application is protected by Salesforce through OAuth. The identity architect for the project needs to limit the level of access to the data of the protected resource in a flexible way.
What should be done to improve security?

  • A. Define a permission set that grants access to the app and assign to authorized users.
  • B. Create custom scopes and assign to the connected app.
  • C. Leverage external objects and data classification policies.
  • D. Select "Admin approved users are pre-authonzed" and assign specific profiles.

Answer: B


NEW QUESTION # 95
Universal containers(UC) has implemented SAML-BASED single Sign-on for their salesforce application and is planning to provide access to salesforce on mobile devices using the salesforce1 mobile app. UC wants to ensure that single Sign-on is used for accessing the salesforce1 mobile app. Which two recommendations should the architect make? Choose 2 answers

  • A. Use the existing SAML SSO flow along with Web server flow
  • B. Configure the salesforce1 app to use the my domain URL
  • C. Use the existing SAML SSO flow along with user agent flow.
  • D. Configure the embedded Web browser to use my domain URL.

Answer: B,C


NEW QUESTION # 96
A service provider (SP) supports both Security Assertion Markup Language (SAML) and OpenID Connect (OIDC).
When integrating this SP with Salesforce, which use case is the determining factor when choosing OIDC or SAML?

  • A. The SP needs to perform API calls back to Salesforce on behalf of the user after the user logs in to the service provider.
  • B. They are equivalent protocols and there is no real reason to choose one over the other.
  • C. If the user has a session on Salesforce, you do not want them to be prompted for a username and password when they login to the SP.
  • D. OIDC is more secure than SAML and therefore is the obvious choice.

Answer: A


NEW QUESTION # 97
A web service is developed that allows secure access to customer order status on the Salesforce Platform, The service connects to Salesforce through a connected app with the web server flow. The following are the required actions for the authorization flow:
1. User Authenticates and Authorizes Access
2. Request an Access Token
3. Salesforce Grants an Access Token
4. Request an Authorization Code
5. Salesforce Grants Authorization Code
What is the correct sequence for the authorization flow?

  • A. 4,5,2, 3, 1
  • B. 4, 1, 5, 2, 3
  • C. 1, 4, 5, 2, 3
  • D. 2, 1, 3, 4, 5

Answer: A


NEW QUESTION # 98
An architect has successfully configured SAML-BASED SSO for universal containers. SSO has been working for 3 months when Universal containers manually adds a batch of new users to salesforce. The new users receive an error from salesforce when trying to use SSO. Existing users are still able to successfully use SSO to access salesforce. What is the probable cause of this behaviour?

  • A. The new users do not have the SSO permission enabled on their profiles.
  • B. The administrator forgot to reset the new user's salesforce password.
  • C. The Federation ID field on the new user records is not correctly set
  • D. The my domain capability is not enabled on the new user's profile.

Answer: C


NEW QUESTION # 99
A technology enterprise is planning to implement single sign-on login for users. When users log in to the Salesforce User object custom field, data should be populated for new and existing users.
Which two steps should an identity architect recommend?
Choose 2 answers

  • A. Implement RegistrationHandler Interface.
  • B. Implement SesslonManagement Class.
  • C. Create and update methods.
  • D. Implement Auth.SamlJitHandler Interface.

Answer: C,D


NEW QUESTION # 100
Universal containers (UC) would like to enable self - registration for their salesforce partner community users.
UC wants to capture some custom data elements from the partner user, and based on these data elements, wants to assign the appropriate profile and account values. Which two actions should the architect recommend to UC? Choose 2 answers

  • A. Configure registration for communities to use a custom visualforce page.
  • B. Modify the communitiesselfregcontroller to assign the profile and account.
  • C. Configure registration for communities to use a custom apex controller.
  • D. Modify the selfregistration trigger to assign profile and account.

Answer: A,B


NEW QUESTION # 101
......

Give push to your success with Identity-and-Access-Management-Architect exam questions: https://examboost.latestcram.com/Identity-and-Access-Management-Architect-exam-cram-questions.html