Get Ready to Boost your Prepare for your Identity-and-Access-Management-Architect Exam with 245 Questions [Q56-Q72]

Share

Get Ready to Boost your Prepare for your Identity-and-Access-Management-Architect Exam with 245 Questions

Use Free Identity-and-Access-Management-Architect Exam Questions that Stimulates Actual EXAM

NEW QUESTION 56
Northern Trail Outfitters (NTO) has an off-boarding process where a terminated employee is first disabled in the Lightweight Directory Act Protocol (LDAP) directory, then requests are sent to the various application support teams to finish user deactivations. A terminated employee recently was able to login to NTO's Salesforce instance 24 hours after termination, even though the user was disabled in the corporate LDAP directory.
What should an identity architect recommend to prevent this from happening in the future?

  • A. Create a Just-in-Time provisioning registration handler to ensure users are deactivated in Salesforce as they are disabled in LDAP.
  • B. Setup an identity provider (IdP) to authenticate users using LDAP, set up single sign-on to Salesforce and disable Login Form authentication.
  • C. use a login flow to make a callout to the LDAP directory before authenticating the user to Salesforce.
  • D. Configure an authentication provider to delegate authentication to the LDAP directory.

Answer: D

 

NEW QUESTION 57
Universal containers (UC) is concerned that having a self-registration page will provide a means for "bots" or unintended audiences to create user records, thereby consuming licences and adding dirty data. Which two actions should UC take to prevent unauthorised form submissions during the self-registration process? Choose
2 answers

  • A. Use hidden fields populated via java script events in the self-registration page.
  • B. Require a captcha at the end of the self-registration process.
  • C. Use open-ended security questions and complex password requirements
  • D. Primarily use lookup and picklist fields on the self registration page.

Answer: A,B

 

NEW QUESTION 58
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to SSO set up My Domain for their Salesforce org.
How does that decision impact their SSO implementation?

  • A. Either SP- or IdP-initiated SSO will work.
  • B. Neither SP- nor IdP-initiated SSO will work.
  • C. SP-initiated SSO will NOT work
  • D. IdP-initiated SSO will NOT work.

Answer: B

 

NEW QUESTION 59
A web service is developed that allows secure access to customer order status on the Salesforce Platform, The service connects to Salesforce through a connected app with the web server flow. The following are the required actions for the authorization flow:
1. User Authenticates and Authorizes Access
2. Request an Access Token
3. Salesforce Grants an Access Token
4. Request an Authorization Code
5. Salesforce Grants Authorization Code
What is the correct sequence for the authorization flow?

  • A. 1, 4, 5, 2, 3
  • B. 4, 1, 5, 2, 3
  • C. 2, 1, 3, 4, 5
  • D. 4,5,2, 3, 1

Answer: D

 

NEW QUESTION 60
A financial enterprise is planning to set up a user authentication mechanism to login to the Salesforce system.
Due to regulatory requirements, the CIO of the company wants user administration, including passwords and authentication requests, to be managed by an external system that is only accessible via a SOAP webservice.
Which authentication mechanism should an identity architect recommend to meet the requirements?

  • A. Just-in-Time Provisioning
  • B. Delegated Authentication
  • C. OAuth Web-Server Flow
  • D. Identity Connect

Answer: B

 

NEW QUESTION 61
Universal Containers (UC) wants to use Salesforce for sales orders and a legacy of system for order fulfillment. The legacy system must update the status of orders in 65* Salesforce in real time as they are fulfilled. UC decides to use OAuth for connecting the legacy system to Salesforce. What OAuth flow should be considered that doesn't require storing credentials, client secret or refresh tokens?

  • A. User Agent flow
  • B. Username-Password flow
  • C. Web Server flow
  • D. JWT Bearer Token flow

Answer: D

 

NEW QUESTION 62
Northern Trail Outfitters would like to use a portal built on Salesforce Experience Cloud for customer self-service. Guests of the portal be able to self-register, but be unable to automatically be assigned to a contact record until verified. External Identity licenses have bee purchased for the project.
After registered guests complete an onboarding process, a flow will create the appropriate account and contact records for the user.
Which three steps should an identity architect follow to implement the outlined requirements?
Choose 3 answers

  • A. Customize the self-registration Apex handler to temporarily associate the user to a shared single contact record.
  • B. Select the "Configurable Self-Reg Page" option under Login & Registration.
  • C. Customize me self-registration Apex handler to create only the user record.
  • D. Enable "Allow customers and partners to self-register".
  • E. Set jp an external login page and call Salesforce APIs for user creation.

Answer: B,C,D

 

NEW QUESTION 63
Universal Containers (UC) has an e-commerce website where customers can buy products, make payments and manage their accounts. UC decides to build a Customer Community on Salesforce and wants to allow the customers to access the community from their accounts without logging in again. UC decides to implement an SP-initiated SSO using a SAML-compliant Idp. In this scenario where Salesforce is the Service Provider, which two activities must be performed in Salesforce to make SP-initiated SSO work? Choose 2 answers

  • A. Configure SAML SSO settings.
  • B. Configure Delegated Authentication.
  • C. Set up My Domain.
  • D. Create a Connected App.

Answer: A,C

 

NEW QUESTION 64
Northern Trail Outfitters (NTO) wants to improve its engagement with existing customers to boost customer loyalty. To get a better understanding of its customers, NTO establishes a single customer view including their buying behaviors, channel preferences and purchasing history. All of this information exists but is spread across different systems and formats.
NTO has decided to use Salesforce as the platform to build a 360 degree view. The company already uses Microsoft Active Directory (AD) to manage its users and company assets.
What should an Identity Architect do to provision, deprovision and authenticate users?

  • A. Salesforce Identity is included in the Salesforce licenses so it does not need to be considered separately.
  • B. Salesforce Identity can be included but NTO will be required to build a custom integration with Microsoft AD.
  • C. A Salesforce Identity can be included but NTO will require Identity Connect.
  • D. Salesforce Identity is not needed since NTO uses Microsoft AD.

Answer: C

 

NEW QUESTION 65
Universal containers wants salesforce inbound Oauth-enabled integration clients to use SAML-BASED single Sign-on for authentication. What Oauth flow would be recommended in this scenario?

  • A. User-Token Oauth flow
  • B. User-Agent Oauth flow
  • C. Web server Oauth flow
  • D. SAML assertion Oauth flow

Answer: D

 

NEW QUESTION 66
Northern Trail Outfitters (NTO) is planning to build a new customer service portal and wants to use passwordless login, allowing customers to login with a one-time passcode sent to them via email or SMS.
How should the quantity of required Identity Verification Credits be estimated?

  • A. Identity Verification Credits are a direct add-on license based on the number of existing member-based or login-based Community licenses.
  • B. Each community comes with 10,000 Identity Verification Credits per month and only customers with more than 10,000 logins a month should estimate additional SMS verifications needed.
  • C. Identity Verification Credits are consumed with each verification sent and should be estimated based on the number of logins that will incur a verification challenge.
  • D. Identity Verification Credits are consumed with each SMS (text message) sent and should be estimated based on the number of login verification challenges for SMS verification users.

Answer: D

 

NEW QUESTION 67
Containers (UC) uses an internal system for recruiting and would like to have the candidates' info available in the Salesforce automatically when they are selected. UC decides to use OAuth to connect to Salesforce from the recruiting system and would like to do the authentication using digital certificates. Which two OAuth flows should be considered to meet the requirement? Choose 2 answers

  • A. Web Service flow
  • B. SAML Bearer Assertion flow
  • C. Refresh Token flow
  • D. JWT Bearer Token flow

Answer: B,D

 

NEW QUESTION 68
Universal Containers (UC) is building a customer community and will allow customers to authenticate using Facebook credentials. The First time the user authenticating using facebook, UC would like a customer account created automatically in their Accounting system. The accounting system has a web service accessible to Salesforce for the creation of accounts. How can the Architect meet these requirements?

  • A. Add an Apex callout in the registration handler of the authorization provider.
  • B. Use JIT Provisioning to automatically create the account in the accounting system.
  • C. Use OAuth JWT flow to pass the data from Salesforce to the Accounting System.
  • D. Create a custom application on Heroku that manages the sign-on process from Facebook.

Answer: A

 

NEW QUESTION 69
Which two capabilities does My Domain enable in the context of a SAML SSO configuration? Choose 2 answers

  • A. Resource deep linking
  • B. SSO from Salesforce Mobile App
  • C. App Launcher
  • D. Login Forensics

Answer: A,B

 

NEW QUESTION 70
Universal Containers would like its customers to register and log in to a portal built on Salesforce Experience Cloud. Customers should be able to use their Facebook or Linkedln credentials for ease of use.
Which three steps should an identity architect take to implement social sign-on?
Choose 3 answers

  • A. Enable "Federated Single Sign-On Using SAML".
  • B. Check "Facebook" and "Linkedln" under Login Page Setup.
  • C. Update the default registration handlers to create and update users.
  • D. Create authentication providers for both Facebook and Linkedln.
  • E. Register both Facebook and Linkedln as connected apps.

Answer: B,C,D

 

NEW QUESTION 71
Universal containers (UC) wants to implement a partner community. As part of their implementation, UC would like to modify both the Forgot password and change password experience with custom branding for their partner community users. Which 2 actions should an architect recommend to UC? Choose 2 answers

  • A. Build a community builder page for the change password experience and Custom Visualforce page for the Forgot password experience.
  • B. Build a community builder page for both the change password and Forgot password experiences.
  • C. Build a custom visualforce page for both the change password and Forgot password experiences.
  • D. Build a custom visualforce page for the change password experience and a community builder page for the Forgot password experience.

Answer: C,D

 

NEW QUESTION 72
......


Salesforce Identity-and-Access-Management-Architect Exam Syllabus Topics:

TopicDetails
Topic 1
  • Troubleshoot common points of failure that may be encountered in a single sign-on solution
  • Describe the tools that are available to diagnose IdP issues
Topic 2
  • Given a scenario identify if Salesforce Customer 360 Identity fits into a fully developed Customer 360 solution
  • Given a use case, describe when Salesforce is used as a Service Provider
Topic 3
  • Given a scenario, recommend appropriate Scope and Configuration of the connected App for Authorization
  • Given a scenario, determine when to use embedded login
Topic 4
  • Describe the capabilities for customizing the user experience for Experience Cloud
  • Given a scenario, identify the most appropriate OAuth flow
Topic 5
  • Given a requirement, understand the advantages and limitations of External Identity solutions and associated licenses
  • Identify the role Identity Connect product plays in a Salesforce Identity implementation
Topic 6
  • Describe the various implementation concepts of OAuth
  • Describe the building blocks that are part of an identity solution
Topic 7
  • Given a scenario, describe what tools you can apply to audit and verify the activity
  • user during and after login
  • Describe how trust is established between two systems
Topic 8
  • Describe common authentication patterns and understand the differences between each one
  • Given a scenario, identify the configuration settings for a Connected app
Topic 9
  • Given a scenario, recommend the most appropriate way to provision users from identity stores in B2E and B2C scenarios
  • Recommend the appropriate method for provisioning users in Salesforce

 

BEST Verified Salesforce Identity-and-Access-Management-Architect Exam Questions (2023) : https://www.validtorrent.com/Identity-and-Access-Management-Architect-valid-exam-torrent.html

Get 100% Real Identity-and-Access-Management-Architect Free Online Practice Test: https://drive.google.com/open?id=1mKQJ-CS5osnGpWhwoQ17YEz11BA_LlSq