Most UptoDate Salesforce Identity-and-Access-Management-Designer Exam Dumps PDF 2021 [Q89-Q109]

Share

Most UptoDate Salesforce Identity-and-Access-Management-Designer Exam Dumps PDF 2021

100% Free Salesforce Identity and Access Management Designer Identity-and-Access-Management-Designer Dumps PDF Demo Cert Guide Cover

NEW QUESTION 89
What is one of the roles of an Identity Provider in a Single Sign-on setup using SAML?

  • A. Create token
  • B. Revoke token
  • C. Consume token
  • D. Validate token

Answer: A

 

NEW QUESTION 90
Universal containers (UC) has a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a connected App in salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properly secure access to the app. Which two are recommendations to make the UC? Choose 2 answers

  • A. Set login IP ranges to the internal network for all of the app users profiles.
  • B. Use Google Authenticator as an additional part of the logical processes.
  • C. Require high assurance sessions in order to use the connected App
  • D. Disallow the use of single Sign-on for any users of the mobile app.

Answer: B,C

 

NEW QUESTION 91
Universal containers (UC) has implemented SAML SSO to enable seamless access across multiple applications. UC has regional salesforce orgs and wants it's users to be able to access them from their main Salesforce org seamless. Which action should an architect recommend?

  • A. Configure the regional salesforce orgs as Identity Providers.
  • B. Configure the main salesforce org as an Authentication provider.
  • C. Configure the main salesforce org as the Identity provider.
  • D. Configure the main Salesforce org as a service provider.

Answer: C

 

NEW QUESTION 92
Universal Containers (UC) wants to use Salesforce for sales orders and a legacy of system for order fulfillment. The legacy system must update the status of orders in 65* Salesforce in real time as they are fulfilled. UC decides to use OAuth for connecting the legacy system to Salesforce. What OAuth flow should be considered that doesn't require storing credentials, client secret or refresh tokens?

  • A. JWT Bearer Token flow
  • B. User Agent flow
  • C. Web Server flow
  • D. Username-Password flow

Answer: A

 

NEW QUESTION 93
Which two statements are capable of Identity Connect? Choose 2 answers

  • A. Supports both Identity-Provider-Initiated and Service-Provider-Initiated SSO.
  • B. Support multiple orgs connecting to multiple Active Directory servers.
  • C. Synchronization of Salesforce Permission Set Licence Assignments.
  • D. Automated user synchronization and de-activation.

Answer: A,C

 

NEW QUESTION 94
Universal Containers (UC) is rolling out its new Customer Identity and Access Management Solution built on top of its existing Salesforce instance. UC wants to allow customers to login using Facebook, Google, and other social sign-on providers.
How should this functionality be enabled for UC, assuming ail social sign-on providers support OpenID Connect?

  • A. Configure an authentication provider and a registration handler for each social sign-on provider.
  • B. Configure a single sign-on setting and a JIT handler for each social sign-on provider.
  • C. Configure an authentication provider and a Just-In-Time (JIT) handler for each social sign-on provider.
  • D. Configure a single sign-on setting and a registration handler for each social sign-on provider.

Answer: A

 

NEW QUESTION 95
Universal containers (UC) has a classified information system that it's call centre team uses only when they are working on a case with a record type of "classified". They are only allowed to access the system when they own an open "classified" case, and their access to the system is removed at all other times. They would like to implement SAML SSO with salesforce as the IDP, and automatically allow or deny the staff's access to the classified information system based on whether they currently own an open "classified" case record when they try to access the system using SSO. What is the recommended solution for automatically allowing or denying access to the classified information system based on the open "classified" case record criteria?

  • A. Use a custom connected App handler using apex to dynamically allow access to the system based on whether the staff owns any open "classified" cases.
  • B. Use salesforce reports to identify users that currently owns open "classified" cases and should be granted access to the classified information system.
  • C. Use apex trigger on case to dynamically assign permission sets that grant access when a user is assigned with an open "classified" case, and remove it when the case is closed.
  • D. Use custom SAML jit provisioning to dynamically query the user's open "classified" cases when attempting to access the classified information system

Answer: A

 

NEW QUESTION 96
An Architect has successfully configured SAML-based SSO for Universal Containers. SSO has been working for 3 months when Universal Containers manually adds a batch of new users to Salesforce. The new users receive an error from Salesforce when trying to use SSO. Existing users are still able to successfully use SSO to access Salesforce.
What is the likely cause of this behavior?

  • A. The new users do NOT have the SSO permission enabled on their profiles.
  • B. The administrator forgot to reset the new user's Salesforce password.
  • C. The My Domain capability is NOT enabled on the new user's profile.
  • D. The Federation ID field on the new User records is NOT correctly set.

Answer: D

 

NEW QUESTION 97
universal containers wants to build a custom mobile app connecting to salesforce using Oauth, and would like to restrict the types of resources mobile users can access. What Oauth feature of Salesforce should be used to achieve the goal?

  • A. Access Tokens
  • B. Scopes
  • C. Refresh Tokens
  • D. Mobile PINS

Answer: A

 

NEW QUESTION 98
Universal Containers (UC) uses a home-grown Employee portal for their employees to collaborate. UC decides to use Salesforce Ideas to allow the employees to post ideas from the Employee portal. When clicking some links in the Employee portal, the users should be redirected to Salesforce, authenticated, and presented with relevant pages.
What scope should be requested when using the OAuth token to meet this requirement?

  • A. api
  • B. web
  • C. full
  • D. Visualforce

Answer: B

 

NEW QUESTION 99
Which two considerations should be made when implementing Delegated Authentication?
Choose 2 answers

  • A. The authentication web service can include custom attributes.
  • B. Salesforce servers receive but do not validate a user's credentials.
  • C. Just-in-time Provisioning can be configured for new users.
  • D. It requires trusted IP ranges at the User Profile level.
  • E. It can be used to authenticate API clients and mobile apps.

Answer: C,E

 

NEW QUESTION 100
Universal Containers (UC) uses Salesforce to allow customers to keep track of the order status. The customers can log in to Salesforce using external authentication providers, such as Facebook and Google. UC is also leveraging the App Launcher to let customers access an of platform application for generating shipping labels.
The label generator application uses OAuth to provide users access. What license type should an Architect recommend for the customers?

  • A. Customer Community Plus license
  • B. Customer Community license
  • C. External Identity license
  • D. Identity license

Answer: C

 

NEW QUESTION 101
A pharmaceutical company has an on-premise application (see illustration) that it wants to integrate with Salesforce.
The IT director wants to ensure that requests must include a certificate with a trusted certificate chain to access the company's on-premise application endpoint.
What should an Identity architect do to meet this requirement?

  • A. Configure the company firewall to allow traffic from Salesforce IP ranges.
  • B. Use open SSL to generate a Self-signed Certificate and upload it to the on-premise app.
  • C. Upload a third-party certificate from Salesforce into the on-premise server.
  • D. Generate a certificate authority-signed certificate in Salesforce and uploading it to the on-premise application Truststore.

Answer: A

 

NEW QUESTION 102
Universal Containers (UC) has implemented SSO according to the diagram below. uses SAML while Salesforce Org 1 uses OAuth 2.0. Users usually start their day by first attempting to log into Salesforce Org 2 and then later in the day, they will log into either the Financial System or CPQ system depending upon their job position. Which two systems are acting as Identity Providers?

  • A. Financial System
  • B. Salesforce Org 2
  • C. Pingfederate
  • D. Salesforce Org 1

Answer: C,D

 

NEW QUESTION 103
After a recent audit, universal containers was advised to implement Two-factor Authentication for all of their critical systems, including salesforce. Which two actions should UC consider to meet this requirement? Choose 2 answers

  • A. Require users to provide their RSA token along with their credentials.
  • B. Require users to enter a second password after the first Authentication
  • C. Require users to supply their email and phone number, which gets validated.
  • D. Require users to use a biometric reader as well as their password

Answer: A,D

 

NEW QUESTION 104
Universal Containers (UC) is building an integration between Salesforce and a legacy web application using the Canvas framework. The security team for UC has determined that a signed request from Salesforce is not an adequate authentication solution for the third-party app. Which two options should the Architect consider for authenticating the third-party app using the Canvas framework? Choose 2 answers

  • A. Create a registration handler Apex class to allow the third-party application to authenticate itself against Salesforce as the IdP.
  • B. Utilize Authorization Providers to allow the third-party application to authenticate itself against Salesforce as the IdP.
  • C. Utilize the SAML Single Sign-on flow to allow the third-party to authenticate itself against UC's IdP.
  • D. Utilize the Canvas OAuth flow to allow the third-party application to authenticate itself against Salesfore as the IdP

Answer: C,D

 

NEW QUESTION 105
Universal Containers (UC) is building an integration between Salesforce and a legacy web application using the Canvas framework. The security team for UC has determined that a signed request from Salesforce is not an adequate authentication solution for the third-party app.
Which two options should the Architect consider for authenticating the third-party app using the Canvas framework? (Choose two.)

  • A. Create a registration handler Apex class to allow the third-party application to authenticate itself against Salesforce as the IdP.
  • B. Utilize Authorization Providers to allow the third-party application to authenticate itself against Salesforce as the IdP.
  • C. Utilize the Canvas OAuth flow to allow the third-party application to authenticate itself against Salesforce as the IdP.
  • D. Utilize the SAML Single Sign-on flow to allow the third-party to authenticate itself against UC's IdP.

Answer: C,D

 

NEW QUESTION 106
Which three different attributes can be used to identify the user in a SAML 65> assertion when Salesforce is acting as a Service Provider? Choose 3 answers

  • A. Salesforce User ID
  • B. User Full Name
  • C. Federation ID
  • D. Salesforce Username
  • E. User Email Address

Answer: B,C,E

 

NEW QUESTION 107
Universal Containers is considering using Delegated Authentication as the sole means of Authenticating of Salesforce users. A Salesforce Architect has been brought in to assist with the implementation. What two risks Should the Architect point out? Choose 2 answers

  • A. UC will be required to develop and support a custom SOAP web service.
  • B. Salesforce users will be locked out of Salesforce if the web service goes down.
  • C. The web service must reside on a public cloud service, such as Heroku.
  • D. Delegated Authentication is enabled or disabled for the entire Salesforce org.

Answer: C,D

 

NEW QUESTION 108
Which two things should be done to ensure end users can only use single sign-on (SSO) to login in to Salesforce?
Choose 2 answers

  • A. Request Salesforce Support to enable delegated authentication.
  • B. Assign user "is Single Sign-on Enabled" permission via profile or permission set.
  • C. Enable My Domain and select "Prevent login from https://login.salesforce.com".
  • D. Once SSO is enabled, users are only able to login using Salesforce credentials.

Answer: B,C

 

NEW QUESTION 109
......


What is the duration of the Identity-and-Access-Management-Designer Exam

  • Format: Multiple choices, multiple answers
  • Number of Questions: 60
  • Passing Score: 65%
  • Length of Examination: 120 minutes

Updated Salesforce Identity-and-Access-Management-Designer Dumps – PDF & Online Engine: https://www.free4torrent.com/Identity-and-Access-Management-Designer-braindumps-torrent.html

PDF Exam Material 2021 Realistic Identity-and-Access-Management-Designer Dumps Questions: https://drive.google.com/open?id=16fOo-jrVX4kwbNDJ0Qdxsoc3bPB3B_Va