
Salesforce Identity-and-Access-Management-Architect Exam Prep Guide: Prep guide for the Identity-and-Access-Management-Architect Exam
2023 New Preparation Guide of Salesforce Identity-and-Access-Management-Architect Exam
NEW QUESTION 22
A manufacturer wants to provide registration for an Internet of Things (IoT) device with limited display input or capabilities.
Which Salesforce OAuth authorization flow should be used?
- A. OAuth 2.0 User-Agent Flow
- B. OAuth 2.0 Device Flow
- C. OAuth 2.0 Asset Token Flow
- D. OAuth 2.0 JWT Bearer How
Answer: B
NEW QUESTION 23
Universal Containers (UC) is planning to add Wi-Fi enabled GPS tracking devices to its shipping containers so that the GPS coordinates data can be sent from the tracking device to its Salesforce production org via a custom API. The GPS devices have no direct user input or output capabilities.
Which OAuth flow should the identity architect recommend to meet the requirement?
- A. OAuth 2.0 Asset Token Flow for Securing Connected Devices
- B. OAuth 2.0 Username-Password Flow for Special Scenarios
- C. OAuth 2.0 Web Server Flow for Web App Integration
- D. OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration
Answer: A
NEW QUESTION 24
How should an identity architect automate provisioning and deprovisioning of users into Salesforce from an external system?
- A. Call SOAP API upsertQ on user object.
- B. Run registration handler on incoming OAuth responses.
- C. Call OpenID Connect (OIDC)-userinfo endpoint with a valid access token.
- D. Use Security Assertion Markup Language Just-in-Time (SAML JIT) on incoming SAML assertions.
Answer: B
NEW QUESTION 25
What are three capabilities of Delegated Authentication? Choose 3 answers
- A. It can be assigned by Custom Permissions.
- B. It can be assigned by Permission Sets.
- C. It can be assigned by Profiles.
- D. It can connect to SOAP services.
- E. It can connect to REST services.
Answer: B,D,E
NEW QUESTION 26
Universal Containers is implementing a new Experience Cloud site and the identity architect wants to use dynamic branding features as of the login process.
Which two options should the identity architect recommend to support dynamic branding for the site?
Choose 2 answers
- A. To use dynamic branding, the community must be built with the Customer Account Portal template.
- B. An external content management system (CMS) must be used for dynamic branding on Experience Cloud sites.
- C. To use dynamic branding, the community must be built with the Visuaiforce + Salesforce Tabs template.
- D. An experience ID (expid) or placeholder parameter must be used in the URL to represent the brand.
Answer: A,D
NEW QUESTION 27
Universal Containers (UC) uses a home-grown Employee portal for their employees to collaborate. UC decides to use Salesforce Ideas to allow employees to post Ideas from the Employee portal. When users click on some of the links in the Employee portal, the users should be redirected to Salesforce, authenticated, and presented with the relevant pages. What OAuth flow is best suited for this scenario?
- A. Web Server flow
- B. User-Agent flow
- C. SAML Bearer Assertion flow
- D. Web Application flow
Answer: A
NEW QUESTION 28
Universal Containers (UC) wants to build a custom mobile app for their field reps to create orders in salesforce. After the first time the users log in, they must be able to access salesforce upon opening the mobile app without being prompted to log in again. What Oauth flows should be considered to support this requirement?
- A. User Agent flow with a Refresh Token.
- B. Web Server flow with a Refresh Token.
- C. Mobile Agent flow with a Bearer Token.
- D. SAML Assertion flow with a Bearer Token.
Answer: A
NEW QUESTION 29
Universal Containers (UC) uses Active Directory (AD) as their identity store for employees and must continue to do so for network access. UC is undergoing a major transformation program and moving all of their enterprise applications to cloud platforms including Salesforct, Workday, and SAP HANA. UC needs to implement an SSO solution for accessing all of the third-party cloud applications and the CIO is inclined to use Salesforce for all of their identity and access management needs.
Which two Salesforce license types does UC need for its employees'
Choose 2 answers
- A. Chatter Only and Identity licenses
- B. Company Community and Identity licenses
- C. Identity and Identity Connect licenses
- D. Salesforce and Identity Connect licenses
Answer: C,D
NEW QUESTION 30
What is one of the roles of an Identity Provider in a Single Sign-on setup using SAML?
- A. Create token
- B. Consume token
- C. Validate token
- D. Revoke token
Answer: A
NEW QUESTION 31
Which tool should be used to track login data, such as the average number of logins, who logged in more than the average number of times and who logged in during non-business hours?
- A. Login Report
- B. Login Inspector
- C. Login History
- D. Login Forensics
Answer: D
NEW QUESTION 32
Universal containers (UC) has implemented SAML SSO to enable seamless access across multiple applications. UC has regional salesforce orgs and wants it's users to be able to access them from their main Salesforce org seamless. Which action should an architect recommend?
- A. Configure the main salesforce org as the Identity provider.
- B. Configure the main Salesforce org as a service provider.
- C. Configure the regional salesforce orgs as Identity Providers.
- D. Configure the main salesforce org as an Authentication provider.
Answer: A
NEW QUESTION 33
Universal Containers (UC) has an e-commerce website where customers can buy products, make payments and manage their accounts. UC decides to build a Customer Community on Salesforce and wants to allow the customers to access the community from their accounts without logging in again. UC decides to implement an SP-initiated SSO using a SAML-compliant Idp. In this scenario where Salesforce is the Service Provider, which two activities must be performed in Salesforce to make SP-initiated SSO work? Choose 2 answers
- A. Set up My Domain.
- B. Create a Connected App.
- C. Configure Delegated Authentication.
- D. Configure SAML SSO settings.
Answer: A,D
NEW QUESTION 34
Universal Containers is implementing Salesforce Identity to broker authentication from its enterprise single sign-on (SSO) solution through Salesforce to third party applications using SAML.
What rote does Salesforce Identity play in its relationship with the enterprise SSO system?
- A. Service Provider (SP)
- B. Identity Provider (IdP)
- C. Client Application
- D. Resource Server
Answer: A
NEW QUESTION 35
Universal containers (UC) has a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a connected App in salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properly secure access to the app. Which two are recommendations to make the UC? Choose 2 answers
- A. Require high assurance sessions in order to use the connected App
- B. Set login IP ranges to the internal network for all of the app users profiles.
- C. Disallow the use of single Sign-on for any users of the mobile app.
- D. Use Google Authenticator as an additional part of the logical processes.
Answer: A,D
NEW QUESTION 36
Northern Trail Outfitters (NTO) is planning to implement a community for its customers using Salesforce Experience Cloud . Customers are not able to self-register. NTO would like to have customers set their own passwords when provided access to the community.
Which two recommendations should an identity architect make to fulfill this requirement?
Choose 2 answers
- A. Use Login Flows to allow users to reset password in Experience Cloud site.
- B. Enable Welcome emails while configuring the Experience Cloud site.
- C. Add customers as contacts and add them to Experience Cloud site.
- D. Allow Password reset using the API to update Experience Cloud site membership.
Answer: A,D
NEW QUESTION 37
An Identity and Access Management (IAM) architect is tasked with unifying multiple B2C Commerce sites and an Experience Cloud community with a single identity. The solution needs to support more than 1,000 logins per minute.
What should the IAM do to fulfill this requirement?
- A. Configure community as a Security Assertion Markup Language (SAML) identity provider and enable Just-in-Time Provisioning to B2C Commerce.
- B. Configure both the community and the commerce sites as OAuth2 RPs (relying party) with an external identity provider.
- C. Confirm performance considerations with Salesforce Customer Support due to high peaks.
- D. Create a default account for capturing all ecommerce contacts registered on the community because personAccount is not supported for this case.
Answer: C
NEW QUESTION 38
Universal Containers (UC) uses Global Shipping (GS) as one of their shipping vendors. Regional leads of GS need access to UC's Salesforce instance for reporting damage of goods using Cases. The regional leads also need access to dashboards to keep track of regional shipping KPIs. UC internally uses a third-party cloud analytics tool for capacity planning and UC decided to provide access to this tool to a subset of GS employees.
In addition to regional leads, the GS capacity planning team would benefit from access to this tool. To access the analytics tool, UC IT has set up Salesforce as the Identity provider for Internal users and would like to follow the same approach for the GS users as well. What are the most appropriate license types for GS Tregional Leads and the GS Capacity Planners? Choose 2 Answers
- A. Identity Licence for GS Regional Leads and External Identity license for GS capacity Planners.
- B. Customer Community Plus license for GS Regional Leads and External Identity for GS Capacity Planners.
- C. Customer Community license for GS Regional Leads and Identity license for GS Capacity Planners.
- D. Customer Community Plus license for GS Regional Leads and Customer Community license for GS Capacity Planners.
Answer: C,D
NEW QUESTION 39
An identity architect's client has a homegrown identity provider (IdP). Salesforce is used as the service provider (SP). The head of IT is worried that during a SP initiated single sign-on (SSO), the Security Assertion Markup Language (SAML) request content will be altered.
What should the identity architect recommend to make sure that there is additional trust between the SP and the IdP?
- A. Ensure that there is an HTTPS connection between IDP and SP.
- B. Ensure that the Issuer and Assertion Consumer service (ACS) URL is property configured between SP and IDP.
- C. Ensure that on the SSO settings page, the "Request Signing Certificate" field has a self-signed certificate.
- D. Encrypt the SAML Request using certification authority (CA) signed certificate and decrypt on IdP.
Answer: D
NEW QUESTION 40
A group of users try to access one of Universal Containers' Connected Apps and receive the following error message: " Failed: Not approved for access." What is the most likely cause of this issue?
- A. The User of High Assurance sessions are required for the Connected App.
- B. The Connected App settings "All users may self-authorize" is enabled.
- C. The Users do not have the correct permission set assigned to them.
- D. The Salesforce Administrators have revoked the OAuth authorization.
Answer: C
NEW QUESTION 41
Northern Trail Outfitters (NTO) is setting up Salesforce to authenticate users with an external identity provider. The NTO Salesforce Administrator is having trouble getting things setup.
What should an identity architect use to show which part of the login assertion is fading?
- A. Connected App Manager
- B. SAML Metadata file importer
- C. Security Assertion Markup Language Validator
- D. Identity Provider Metadata download
Answer: C
NEW QUESTION 42
Universal Containers wants to allow its customers to log in to its Experience Cloud via a third party authentication provider that supports only the OAuth protocol.
What should an identity architect do to fulfill this requirement?
- A. Configure OpenID Connect authentication provider.
- B. Create a custom external authentication provider.
- C. Contact Salesforce Support and enable delegate single sign-on.
- D. Use certificate-based authentication.
Answer: B
NEW QUESTION 43
......
Latest Questions Identity-and-Access-Management-Architect Guide to Prepare Free Practice Tests: https://www.exam4labs.com/Identity-and-Access-Management-Architect-practice-torrent.html
Identity-and-Access-Management-Architect Practice Exam - 245 Unique Questions: https://drive.google.com/open?id=1H_oOKxo48N63p9lhsDVVeLH_gVkoKsvQ