Get The Most Updated Identity-and-Access-Management-Architect Dumps To Identity and Access Management Designer Certification [Q117-Q137]

Share

Get The Most Updated Identity-and-Access-Management-Architect Dumps To Identity and Access Management Designer Certification

Salesforce Certified Identity-and-Access-Management-Architect  Dumps Questions Valid Identity-and-Access-Management-Architect Materials


Salesforce Identity-and-Access-Management-Architect Exam Syllabus Topics:

TopicDetails
Topic 1
  • Identify the ways that users can be provisioned in Salesforce to enable SSO and apply access rights
  • Identify the auditing and monitoring approaches available on the platform
Topic 2
  • Describe the various implementation concepts of OAuth
  • Describe the building blocks that are part of an identity solution
Topic 3
  • Given a requirement, understand the advantages and limitations of External Identity solutions and associated licenses
  • Identify the role Identity Connect product plays in a Salesforce Identity implementation
Topic 4
  • Describe common authentication patterns and understand the differences between each one
  • Given a scenario, identify the configuration settings for a Connected app
Topic 5
  • Given a scenario, describe what tools you can apply to audit and verify the activity
  • user during and after login
  • Describe how trust is established between two systems
Topic 6
  • Describe the capabilities for customizing the user experience for Experience Cloud
  • Given a scenario, identify the most appropriate OAuth flow
Topic 7
  • Given a scenario identify if Salesforce Customer 360 Identity fits into a fully developed Customer 360 solution
  • Given a use case, describe when Salesforce is used as a Service Provider

 

NEW QUESTION 117
An identity architect is setting up an integration between Salesforce and a third-party system. The third-party system needs to authenticate to Salesforce and then make API calls against the REST API.
One of the requirements is that the solution needs to ensure the third party service providers connected app in Salesforce mini need for end user interaction and maximizes security.
Which OAuth flow should be used to fulfill the requirement?

  • A. JWT Bearer Flow
  • B. User Agent Flow
  • C. Web Server Flow
  • D. Username-Password Flow

Answer: A

 

NEW QUESTION 118
What is one of the roles of an Identity Provider in a Single Sign-on setup using SAML?

  • A. Consume token
  • B. Create token
  • C. Validate token
  • D. Revoke token

Answer: B

 

NEW QUESTION 119
An Architect has configured a SAML-based SSO integration between Salesforce and an external Identity provider and is ready to test it. When the Architect attempts to log in to Salesforce using SSO, the Architect receives a SAML error. Which two optimal actions should the Architect take to troubleshoot the issue?

  • A. Paste the SAML Assertion Validator in Salesforce.
  • B. Use a browser that has an add-on/extension that can inspect SAML.
  • C. Use the browser's Development tools to view the Salesforce page's markup.
  • D. Ensure the Callback URL is correctly set in the Connected Apps settings.

Answer: A,B

 

NEW QUESTION 120
Universal containers (UC) would like to enable self - registration for their salesforce partner community users.
UC wants to capture some custom data elements from the partner user, and based on these data elements, wants to assign the appropriate profile and account values. Which two actions should the architect recommend to UC? Choose 2 answers

  • A. Configure registration for communities to use a custom visualforce page.
  • B. Configure registration for communities to use a custom apex controller.
  • C. Modify the communitiesselfregcontroller to assign the profile and account.
  • D. Modify the selfregistration trigger to assign profile and account.

Answer: A,C

 

NEW QUESTION 121
A company with 15,000 employees is using Salesforce and would like to take the necessary steps to highlight or curb fraudulent activity.
Which tool should be used to track login data, such as the average number of logins, who logged in more than the average number of times and who logged in during non-business hours?

  • A. Login History
  • B. Login Report
  • C. Login Inspector
  • D. Login Forensics

Answer: D

 

NEW QUESTION 122
Universal Containers (UC) wants its closed Won opportunities to be synced to a Data Warehouse in near real time. UC has implemented Outbound Message to enable near real-time data sync. UC wants to ensure that communication between Salesforce and Target System is Secure. What Certificate is sent along with the Outbound Message?

  • A. The default Client Certificate or a Certificate from Certificate and Key Management menu.
  • B. The default Client Certificate from the Develop--> API Menu.
  • C. The Self-Signed Certificates from the Certificate & Key Management menu.
  • D. The CA-Signed Certificate from the Certificate and Key Management menu.

Answer: B

 

NEW QUESTION 123
Universal Containers (UC) wants to provide single sign-on (SSO) for a business-to-consumer (B2C) application using Salesforce Identity.
Which Salesforce license should UC utilize to implement this use case?

  • A. Salesforce Platform
  • B. Identity Only
  • C. External Identity
  • D. Partner Community

Answer: C

 

NEW QUESTION 124
Universal Containers is considering using Delegated Authentication as the sole means of Authenticating of Salesforce users. A Salesforce Architect has been brought in to assist with the implementation. What two risks Should the Architect point out? Choose 2 answers

  • A. Delegated Authentication is enabled or disabled for the entire Salesforce org.
  • B. Salesforce users will be locked out of Salesforce if the web service goes down.
  • C. UC will be required to develop and support a custom SOAP web service.
  • D. The web service must reside on a public cloud service, such as Heroku.

Answer: B,C

 

NEW QUESTION 125
Universal Containers (UC) is using its production org as the identity provider for a new Experience Cloud site and the identity architect is deciding which login experience to use for the site.
Which two page types are valid login page types for the site?
Choose 2 answers

  • A. Experience Builder Page
  • B. Embedded Login Page
  • C. lightning Experience Page
  • D. Login Discovery Page

Answer: B,D

 

NEW QUESTION 126
Which two security risks can be mitigated by enabling Two-Factor Authentication (2FA) in Salesforce?
Choose 2 answers

  • A. Users leaving laptops unattended and not logging out of Salesforce.
  • B. Users choosing passwords that are the same as their Facebook password.
  • C. Users accessing Salesforce from a public Wi-Fi access point.
  • D. Users creating simple-to-guess password reset questions.

Answer: B,C

 

NEW QUESTION 127
Universal Containers (UC) has Active Directory (AD) as their enterprise identity store and would like to use it for Salesforce user authentication. UC expects to synchronize user data between Salesforce and AD and Assign the appropriate Profile and Permission Sets based on AD group membership. What would be the optimal way to implement SSO?

  • A. Use Active Directory with Reverse Proxy as the Identity Provider.
  • B. Use Microsoft Access control Service as the Authentication provider.
  • C. Use Active Directory Federation Service (ADFS) as the Identity Provider.
  • D. Use Salesforce Identity Connect as the Identity Provider.

Answer: D

 

NEW QUESTION 128
A consumer products company uses Salesforce to maintain consumer information, including orders. The company implemented a portal solution using Salesforce Experience Cloud for its consumers where the consumers can log in using their credentials. The company is considering allowing users to login with their Facebook or Linkedln credentials.
Once enabled, what role will Salesforce play?

  • A. Facebook and Linkedln will act as the IdPs and SPs.
  • B. Facebook and Linkedln will be the SPs.
  • C. Salesforce will be the service provider (SP).
  • D. Salesforce will be the identity provider (IdP).

Answer: C

 

NEW QUESTION 129
Universal Containers (UC) is considering a Customer 360 initiative to gain a single source of the truth for its customer data across disparate systems and services. UC wants to understand the primary benefits of Customer
360 Identity and how it contributes ato successful Customer 360 Truth project.
What are two are key benefits of Customer 360 Identity as it relates to Customer 360?
Choose 2 answers

  • A. Customer 360 Identity supports multiple brands so you can deliver centralized identity services and correlation of user activity, even if it spans multiple corporate brands and user experiences.
  • B. Customer 360 Identity automatically integrates with Customer 360 Data Manager and Customer 360 Audiences to seamlessly populate all user data.
  • C. Customer 360 Identity not only provides a unified sign up and sign in experience, but also tracks anonymous user activity prior to signing up so organizations can understand user activity before and after the users identify themselves.
  • D. Customer 360 Identity enables an organization to build a single login for each of its customers, giving the organization an understanding of the user's login activity across all its digital properties and applications.

Answer: A,D

 

NEW QUESTION 130
A technology enterprise is planning to implement single sign-on login for users. When users log in to the Salesforce User object custom field, data should be populated for new and existing users.
Which two steps should an identity architect recommend?
Choose 2 answers

  • A. Create and update methods.
  • B. Implement RegistrationHandler Interface.
  • C. Implement SesslonManagement Class.
  • D. Implement Auth.SamlJitHandler Interface.

Answer: A,D

 

NEW QUESTION 131
Universal Containers (UC) uses middleware to integrate multiple systems with Salesforce. UC has a strict, new requirement that usernames and passwords cannot be stored in any UC system. How can UC's middleware authenticate to Salesforce while adhering to this requirement?

  • A. Create a Connected App that supports the User-Agent OAuth Flow.
  • B. Create a Connected App that supports the Refresh Token OAuth Flow
  • C. Create a Connected App that supports the Web Server OAuth Flow.
  • D. Create a Connected App that supports the JWT Bearer Token OAuth Flow.

Answer: D

 

NEW QUESTION 132

A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APAC. The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS . The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.
What is recommended to ensure these requirements are met ?

  • A. Configure Each ADFS system under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce-
  • B. Add a central identity system that federates between the ADFS systems and integrate with Salesforce for single sign-on.
  • C. Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.
  • D. Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.

Answer: D

 

NEW QUESTION 133
Northern Trail Outfitters (NTO) is setting up Salesforce to authenticate users with an external identity provider. The NTO Salesforce Administrator is having trouble getting things setup.
What should an identity architect use to show which part of the login assertion is fading?

  • A. Identity Provider Metadata download
  • B. Security Assertion Markup Language Validator
  • C. Connected App Manager
  • D. SAML Metadata file importer

Answer: B

 

NEW QUESTION 134
customer service representatives at Universal containers (UC) are complaining that whenever they click on links to case records and are asked to login with SAML SSO, they are being redirected to the salesforce home tab and not the specific case record. What item should an architect advise the identity team at UC to investigate first?

  • A. The users have the correct Federation ID within salesforce.
  • B. The salesforce SSO settings are using http post
  • C. The identity provider is correctly preserving the Relay state
  • D. My domain is configured and active within salesforce.

Answer: C

 

NEW QUESTION 135
Which three types of attacks would a 2-Factor Authentication solution help garden against?

  • A. Man-in-the-middle attacks
  • B. Key logging attacks
  • C. Phishing attacks
  • D. Dictionary attacks
  • E. Network perimeter attacks

Answer: B,D,E

 

NEW QUESTION 136
Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for to give its customers the ability to login with their Facebook and Twitter credentials.
Which two actions should an identity architect recommend to meet these requirements?
Choose 2 answers

  • A. Configure a predefined authentication provider for Facebook.
  • B. Create a custom external authentication provider for Twitter.
  • C. Configure a predefined authentication provider for Twitter.
  • D. Create a custom external authentication provider for Facebook.

Answer: A,C

 

NEW QUESTION 137
......

Identity-and-Access-Management-Architect Premium PDF & Test Engine Files with 245 Questions & Answers: https://www.validdumps.top/Identity-and-Access-Management-Architect-exam-torrent.html

Current Identity-and-Access-Management-Architect Exam Dumps [2023] Complete Salesforce Exam Smoothly: https://drive.google.com/open?id=1i7B9HFQrMqmIr29O5ql5wL_xbojqV_ZC