Study HIGH Quality Identity-and-Access-Management-Designer Free Study Guides and Exams Tutorials
Download Salesforce Identity-and-Access-Management-Designer Exam Dumps to Pass Exam Easily
NEW QUESTION # 59
Universal Containers (UC) uses a home-grown Employee portal for their employees to collaborate. UC decides to use Salesforce Ideas to allow the employees to post ideas from the Employee portal. When clicking some links in the Employee portal, the users should be redirected to Salesforce, authenticated, and presented with relevant pages.
What scope should be requested when using the OAuth token to meet this requirement?
- A. web
- B. Visualforce
- C. api
- D. full
Answer: A
Explanation:
Explanation
NEW QUESTION # 60
A group of users try to access one of Universal Containers' Connected Apps and receive the following error message: " Failed: Not approved for access." What is the most likely cause of this issue?
- A. The User of High Assurance sessions are required for the Connected App.
- B. The Salesforce Administrators have revoked the OAuth authorization.
- C. The Connected App settings "All users may self-authorize" is enabled.
- D. The Users do not have the correct permission set assigned to them.
Answer: D
NEW QUESTION # 61
Universal Containers (UC) uses Active Directory (AD) as their identity store for employees and must continue to do so for network access. UC is undergoing a major transformation program and moving all of their enterprise applications to cloud platforms including Salesforct, Workday, and SAP HANA. UC needs to implement an SSO solution for accessing all of the third-party cloud applications and the CIO is inclined to use Salesforce for all of their identity and access management needs.
Which two Salesforce license types does UC need for its employees'
Choose 2 answers
- A. Identity and Identity Connect licenses
- B. Company Community and Identity licenses
- C. Salesforce and Identity Connect licenses
- D. Chatter Only and Identity licenses
Answer: A,C
NEW QUESTION # 62
Universal containers (UC) would like to enable SSO between their existing Active Directory infrastructure and salesforce. The it team prefers to manage all users in Active Directory and would like to avoid doing any initial setup of users in salesforce directly, including the correct assignment of profiles, roles and groups. Which two optimal solutions should UC use to provision users in salesforce? Choose 2 answers
- A. Use Identity connect to sync users from Active Directory to salesforce
- B. Use Active Directory Federation Services to sync users from active directory to salesforce.
- C. Use the salesforce REST API to sync users from active directory to salesforce
- D. Use an app exchange product to sync users from Active Directory to salesforce.
Answer: A,D
NEW QUESTION # 63
Universal Containers (UC) rolling out a new Customer Identity and Access Management Solution will be built on top of their existing Salesforce instance.
Several service providers have been setup and integrated with Salesforce using OpenlD Connect to allow for a seamless single sign-on experience. UC has a requirement to limit user access to only a subset of service providers per customer type.
Which two steps should be done on the platform to satisfy the requirement?
Choose 2 answers
- A. Use Profiles and Permission Sets to assign user access to Admin Pre-Approved Connected Apps.
- B. Assign the connected app to the customer community, and enable the users profile in the Community settings.
- C. Set each of the Connected App access settings to Admin Pre-Approved.
- D. Manage which connected apps a user has access to by assigning authentication providers to the users profile.
Answer: A,C
NEW QUESTION # 64
Universal Containers (UC) would like to enable self-registration for their Salesforce Partner Community Users.
UC wants to capture some custom data elements from the partner user, and based on these data elements, wants to assign the appropriate Profile and Account values.
Which two actions should the Architect recommend to UC? (Choose two.)
- A. Configure Registration for Communities to use a custom Apex Controller.
- B. Modify the SelfRegistration trigger to assign Profile and Account.
- C. Modify the CommunitiesSelfRegController to assign the Profile and Account.
- D. Configure Registration for Communities to use a custom Visualforce Page.
Answer: C,D
NEW QUESTION # 65
Northern Trail Outfitters (NTO) uses Salesforce Experience Cloud sites (previously known as Customer Community) to provide a digital portal where customers can login using their Google account.
NTO would like to automatically create a case record for first time users logging into Salesforce Experience Cloud.
What should an Identity architect do to fulfill the requirement?
- A. Configure an authentication provider for Social Login using Google and a custom registration handler.
- B. Implement a login flow with a record create component for Case.
- C. Implement a Just-in-Time handler class that has logic to create cases upon first login.
- D. Create an authentication provider for Social Login using Google and leverage standard registration handler.
Answer: B
NEW QUESTION # 66
Northern Trail Outfitters (NTO) is planning to implement a community for its customers using Salesforce Experience Cloud . Customers are not able to self-register. NTO would like to have customers set their own passwords when provided access to the community.
Which two recommendations should an identity architect make to fulfill this requirement?
Choose 2 answers
- A. Add customers as contacts and add them to Experience Cloud site.
- B. Use Login Flows to allow users to reset password in Experience Cloud site.
- C. Allow Password reset using the API to update Experience Cloud site membership.
- D. Enable Welcome emails while configuring the Experience Cloud site.
Answer: B,C
NEW QUESTION # 67
Universal Containers (UC) uses Salesforce to allow customers to keep track of the order status. The customers can log in to Salesforce using external authentication providers, such as Facebook and Google. UC is also leveraging the App Launcher to let customers access an of platform application for generating shipping labels.
The label generator application uses OAuth to provide users access. What license type should an Architect recommend for the customers?
- A. Customer Community license
- B. External Identity license
- C. Identity license
- D. Customer Community Plus license
Answer: C
NEW QUESTION # 68
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP.
After some evaluation, UC decides NOT to 65 set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?
- A. Either SP- or IdP-initiated SSO will work.
- B. IdP-initiated SSO will NOT work.
- C. Neither SP- nor IdP-initiated SSO will work.
- D. SP-initiated SSO will NOT work
Answer: C
NEW QUESTION # 69
A technology enterprise is planning to implement single sign-on login for users. When users log in to the Salesforce User object custom field, data should be populated for new and existing users.
Which two steps should an identity architect recommend?
Choose 2 answers
- A. Create and update methods.
- B. Implement RegistrationHandler Interface.
- C. Implement SesslonManagement Class.
- D. Implement Auth.SamlJitHandler Interface.
Answer: A,D
NEW QUESTION # 70
An organization has a central cloud-based Identity and Access Management (IAM) Service for authentication and user management, which must be utilized by all applications as follows:
1 - Change of a user status in the central IAM Service triggers provisioning or deprovisioining in the integrated cloud applications.
2 - Security Assertion Markup Language single sign-on (SSO) is used to facilitate access for users authenticated at identity provider (Central IAM Service).
Which approach should an IAM architect implement on Salesforce Sales Cloud to meet the requirements?
- A. A Configure Salesforce as a SAML Service Provider, and enable SCIM (System for Cross-Domain Identity Management) for provisioning and deprovisioning of users.
- B. Configure Salesforce as a SAML service provider, and enable Just-in Time (JIT) provisioning and deprovisioning of users.
- C. Configure central IAM Service as an authentication provider and extend registration handler to manage provisioning and deprovisioning of users.
- D. Deploy Identity Connect component and set up automated provisioning and deprovisioning of users, as well as SAML-based SSO.
Answer: A
NEW QUESTION # 71
Universal Containers has implemented a multi-org strategy and would like to centralize the management of their Salesforce user profiles.
What should the Architect recommend to allow Salesforce profiles to be managed from a central system of record?
- A. Implement JIT provisioning on the SAML IdP that will pass the ProfileID in each assertion.
- B. Implement an OAuth JWT flow to pass the profile credentials between systems.
- C. Create an Apex scheduled job in one org that will synchronize the other org's profiles.
- D. Implement Delegated Authentication that will update the user profiles as necessary.
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION # 72
Universal Containers (UC) has implemented SAML-based Single Sign-On to provide seamless access to its Salesforce Orgs, financialsystem, and CPQ system. Below is the SSO implementation landscape.
What role combination is represented by the systems in this scenario''
- A. Salesforce Org1 and Salesforce Org2 are acting as Identity Providers.
- B. Salesforce Org1 and Salesforce Org2 are the only Service Providers.
- C. Financial System and CPQ System are the only Service Providers.
- D. Salesforce Org1 and PingFederate are acting as Identity Providers.
Answer: D
NEW QUESTION # 73
Ttie executive sponsor for an organization has asked if Salesforce supports the ability to embed a login widget into its service providers in order to create a more seamless user experience.
What should be used and considered before recommending it as a solution on the Salesforce Platform?
- A. OpenID Connect Web Server Flow. Determine if the service provider is secure enough to store the client secret on.
- B. Salesforce REST apis. Ensure that Secure Sockets Layer (SSL) connection for the integration is used.
- C. Embedded Login. Identify what level of UI customization will be required to make it match the service providers look and feel.
- D. Embedded Login. Consider whether or not it relies on third party cookies which can cause browser compatibility issues.
Answer: B
NEW QUESTION # 74
Universal containers (UC) is concerned that having a self-registration page will provide a means for "bots" or unintended audiences to create user records, thereby consuming licences and adding dirty data. Which two actions should UC take to prevent unauthorised form submissions during the self-registration process? Choose
2 answers
- A. Use hidden fields populated via java script events in the self-registration page.
- B. Use open-ended security questions and complex password requirements
- C. Primarily use lookup and picklist fields on the self registration page.
- D. Require a captcha at the end of the self-registration process.
Answer: A,D
NEW QUESTION # 75
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to 65« set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?
- A. Either SP- or IdP-initiated SSO will work.
- B. IdP-initiated SSO will NOT work.
- C. Neither SP- nor IdP-initiated SSO will work.
- D. SP-initiated SSO will NOT work
Answer: C
NEW QUESTION # 76
......
Get 100% Real Free Salesforce Identity and Access Management Designer Identity-and-Access-Management-Designer Sample Questions: https://www.dumpsactual.com/Identity-and-Access-Management-Designer-actualtests-dumps.html
Accurate Identity-and-Access-Management-Designer Questions with Free and Fast Updates: https://drive.google.com/open?id=1HenDNQ4ZUj8b05nu3h269g6Y1q09Xm9g
