Identity-and-Access-Management-Designer Exam Questions Get Updated [2022] with Correct Answers [Q88-Q104]

Share

Identity-and-Access-Management-Designer Exam Questions Get Updated [2022] with Correct Answers

Practice Identity-and-Access-Management-Designer Questions With Certification guide Q&A from Training Expert Actual4dump


For more info visit:

Identity-and-Access-Management-Designer Exam Reference


What is the duration of the Identity-and-Access-Management-Designer Exam

  • Number of Questions: 60
  • Passing Score: 65%
  • Format: Multiple choices, multiple answers
  • Length of Examination: 120 minutes

NEW QUESTION 88
Universal Containers is considering using Delegated Authentication as the sole means of Authenticating of Salesforce users. A Salesforce Architect has been brought in to assist with the implementation. What two risks Should the Architect point out? Choose 2 answers

  • A. UC will be required to develop and support a custom SOAP web service.
  • B. Salesforce users will be locked out of Salesforce if the web service goes down.
  • C. The web service must reside on a public cloud service, such as Heroku.
  • D. Delegated Authentication is enabled or disabled for the entire Salesforce org.

Answer: C,D

 

NEW QUESTION 89
Universal containers (UC) built a customer Community for customers to buy products, review orders, and manage their accounts. UC has provided three different options for customers to log in to the customer Community: salesforce, Google, and Facebook. Which two role combinations are represented by the systems in the scenario? Choose 2 answers

  • A. Facebook is the service provider and salesforce is the identity provider
  • B. Google is the service provider and Facebook is the identity provider
  • C. Salesforce is the service provider and Google is the identity provider
  • D. Salesforce is the service provider and Facebook is the identity provider

Answer: C,D

 

NEW QUESTION 90
Northern Trail Outfitters (NTO) uses a Security Assertion Markup Language (SAML)-based Identity Provider (idP) to authenticate employees to all systems. The IdP authenticates users against a Lightweight Directory Access Protocol (LDAP) directory and has access to user information. NTO wants to minimize Salesforce license usage since only a small percentage of users need Salesforce.
What is recommended to ensure new employees have immediate access to Salesforce using their current IdP?

  • A. Configure Just-in-Time provisioning using SAML attributes to create new Salesforce users as necessary when a new user attempts to login to Salesforce.
  • B. Build an integration that queries LDAP periodically and creates new active users in Salesforce.
  • C. Build an integration that queries LDAP and creates new inactive users in Salesforce and use a login flow to activate the user at first login.
  • D. Install Salesforce Identity Connect to automatically provision new users in Salesforce the first time they attempt to login.

Answer: A

 

NEW QUESTION 91
Universal containers wants to implement single Sign-on for a salesforce org using an external identity provider and corporate identity store. What type of Authentication flow is required to support deep linking?

  • A. Start URL on identity provider
  • B. Web server Oauth SSO flow.
  • C. Service-provider-initiated SSO
  • D. Identity-provider-initiated SSO

Answer: C

 

NEW QUESTION 92
After a recent audit, universal containers was advised to implement Two-factor Authentication for all of their critical systems, including salesforce. Which two actions should UC consider to meet this requirement?
Choose 2 answers

  • A. Require users to enter a second password after the first Authentication
  • B. Require users to provide their RSA token along with their credentials.
  • C. Require users to supply their email and phone number, which gets validated.
  • D. Require users to use a biometric reader as well as their password

Answer: C,D

 

NEW QUESTION 93
An Architect has successfully configured SAML-based SSO for Universal Containers. SSO has been working for 3 months when Universal Containers manually adds a batch of new users to Salesforce. The new users receive an error from Salesforce when trying to use SSO. Existing users are still able to successfully use SSO to access Salesforce.
What is the likely cause of this behavior?

  • A. The new users do NOT have the SSO permission enabled on their profiles.
  • B. The administrator forgot to reset the new user's Salesforce password.
  • C. The My Domain capability is NOT enabled on the new user's profile.
  • D. The Federation ID field on the new User records is NOT correctly set.

Answer: D

 

NEW QUESTION 94
Universal Containers (UC) implemented SSO to a third-party system for their Salesforce users to access the App Launcher. UC enabled "User Provisioning" on the Connected App so that changes to user accounts can be synched between Salesforce and the third party system. However, UC quickly notices that changes to user roles in Salesforce are not getting synched to the third-party system. What is the most likely reason for this behaviour?

  • A. User Provisioning for Connected Apps does not support role sync.
  • B. The Approval queue for User Provisioning Requests is unmonitored.
  • C. Required operation(s) was not mapped in User Provisioning Settings.
  • D. Salesforce roles have more than three levels in the role hierarchy.

Answer: A

 

NEW QUESTION 95
Which two security risks can be mitigated by enabling Two-Factor Authentication (2FA) in Salesforce?
Choose 2 answers

  • A. Users leaving laptops unattended and not logging out of Salesforce.
  • B. Users accessing Salesforce from a public Wi-Fi access point.
  • C. Users choosing passwords that are the same as their Facebook password.
  • D. Users creating simple-to-guess password reset questions.

Answer: B,C

 

NEW QUESTION 96
In an SP-Initiated SAML SSO setup where the user tries to access a resource on the Service Provider, What HTTP param should be used when submitting a SAML Request to the Idp to ensure the user is returned to the intended resourse after authentication?

  • A. StartURL
  • B. RelayState
  • C. RedirectURL
  • D. DisplayState

Answer: A

 

NEW QUESTION 97
Universal Containers (UC) uses Salesforce to allow customers to keep track of the order status. The customers can log in to Salesforce using external authentication providers, such as Facebook and Google.
UC is also leveraging the App Launcher to let customers access an off-platform application for generating shipping labels. The label generator application uses OAuth to provide users access.
What license type should an Architect recommend for the customers?

  • A. Identity license
  • B. External Identity license
  • C. Customer Community Plus license
  • D. Customer Community license

Answer: A

 

NEW QUESTION 98
Universal Containers (UC) uses Active Directory (AD) as their identity store for employees and must continue to do so for network access. UC is undergoing a major transformation program and moving all of their enterprise applications to cloud platforms including Salesforct, Workday, and SAP HANA. UC needs to implement an SSO solution for accessing all of the third-party cloud applications and the CIO is inclined to use Salesforce for all of their identity and access management needs.
Which two Salesforce license types does UC need for its employees'
Choose 2 answers

  • A. Company Community and Identity licenses
  • B. Salesforce and Identity Connect licenses
  • C. Identity and Identity Connect licenses
  • D. Chatter Only and Identity licenses

Answer: B,C

 

NEW QUESTION 99
Universal Containers (UC) wants to build a few applications that leverage the Salesforce REST API. UC has asked its Architect to describe how the API calls will be authenticated to a specific user. Which two mechanisms can the Architect provide? Choose 2 Answers

  • A. Access Token
  • B. Authentication Token
  • C. Refresh Token
  • D. Session ID

Answer: A,B

 

NEW QUESTION 100
Universal Containers has implemented a multi-org strategy and would like to centralize the management of their Salesforce user profiles.
What should the Architect recommend to allow Salesforce profiles to be managed from a central system of record?

  • A. Implement Delegated Authentication that will update the user profiles as necessary.
  • B. Implement JIT provisioning on the SAML IdP that will pass the ProfileID in each assertion.
  • C. Implement an OAuth JWT flow to pass the profile credentials between systems.
  • D. Create an Apex scheduled job in one org that will synchronize the other org's profiles.

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 101
Universal Containers (UC) is building an integration between Salesforce and a legacy web application using the Canvas framework. The security team for UC has determined that a signed request from Salesforce is not an adequate authentication solution for the third-party app. Which two options should the Architect consider for authenticating the third-party app using the Canvas framework? Choose 2 answers

  • A. Create a registration handler Apex class to allow the third-party application to authenticate itself against Salesforce as the IdP.
  • B. Utilize Authorization Providers to allow the third-party application to authenticate itself against Salesforce as the IdP.
  • C. Utilize the SAML Single Sign-on flow to allow the third-party to authenticate itself against UC's IdP.
  • D. Utilize the Canvas OAuth flow to allow the third-party application to authenticate itself against Salesfore as the IdP

Answer: C,D

 

NEW QUESTION 102
Sales users at Universal containers use salesforce for Opportunity management. Marketing uses a third-party application called Nest for Lead nurturing that is accessed using username/password. The VP of sales wants to open up access to nest for all sales uses to provide them access to lead history and would like SSO for better adoption. Salesforce is already setup for SSO and uses Delegated Authentication. Nest can accept username/Password or SAML-based Authentication. IT teams have received multiple password-related issues for nest and have decided to set up SSO access for Nest for Marketing users as well. The CIO does not want to invest in a new IDP solution and is considering using Salesforce for this purpose. Which are appropriate license type choices for sales and marketing users, giving salesforce is using Delegated Authentication? Choose 2 answers

  • A. Salesforce license for sales users and platform license for Marketing users.
  • B. Salesforce license for sales users and Identity license for Marketing users
  • C. Salesforce license for sales users and External Identity license for Marketing users
  • D. Identity license for sales users and Identity connect license for Marketing users

Answer: A,B

 

NEW QUESTION 103
Containers (UC) has multiple Salesforce Orgs and would like to use a single Identity Provider to access all of their orgs. How should UC's Architect enable this behaviour?

  • A. Ensure the same username is allowed in multiple orgs by contacting Salesforce Support.
  • B. Ensure that users have the same Email Value in their user records in all of UC's Salesforce orgs.
  • C. Ensure that users have the same Federation ID value in their User records in all of UC's Salesforce orgs
  • D. Ensure that users have the same Alias value in their user records in all of UC's Salesforce orgs.

Answer: C

 

NEW QUESTION 104
......


How much Identity-and-Access-Management-Designer Exam Cost

The price of the Salesforce Identity-and-Access-Management-Designer exam is $400 USD.

Prepare Top Salesforce Identity-and-Access-Management-Designer Exam Audio Study Guide Practice Questions Edition: https://www.actual4dump.com/Salesforce/Identity-and-Access-Management-Designer-actualtests-dumps.html

Free Salesforce Identity-and-Access-Management-Designer Test Practice Test Questions Exam Dumps: https://drive.google.com/open?id=1KjViYoYB6x2g0uE5q6tqNvC06GjCXer-