Get Real Identity-and-Access-Management-Designer Quesions Pass Salesforce Certification Exams Easily [Q93-Q111]

Share

Get Real Identity-and-Access-Management-Designer Quesions Pass Salesforce Certification Exams Easily

Identity-and-Access-Management-Designer Dumps are Available for Instant Access


Salesforce Identity-and-Access-Management-Designer certification exam is a valuable credential for professionals who are responsible for designing and implementing secure access solutions in Salesforce. It validates the skills and knowledge required to ensure that Salesforce is configured to meet the needs of the organization and its users while maintaining the highest level of security.


Salesforce Identity-and-Access-Management-Designer Exam

Salesforce Identity-and-Access-Management-Designer Exam is related to Salesforce Certified Identity and Access Management Designer (WI19) Certification. This exam validates the Candidate ability in assessing identity architecture and designing secure, high-performance access management solutions on the Lightning Platform.

 

NEW QUESTION # 93
Northern Trail Outfitters (NTO) leverages Microsoft Active Directory (AD) for management of employee usernames, passwords, permissions, and asset access. NTO also owns a third-party single sign-on (SSO) solution. The third-party party SSO solution is used for all corporate applications, including Salesforce.
NTO has asked an architect to explore Salesforce Identity Connect for automatic provisioning and deprovisiorung of users in Salesforce.
What role does identity Connect play in the outlined requirements?

  • A. Single Sign-On
  • B. Service Provider
  • C. Identity Provider
  • D. User Management

Answer: D


NEW QUESTION # 94
Universal containers wants salesforce inbound Oauth-enabled integration clients to use SAML-BASED single Sign-on for authentication. What Oauth flow would be recommended in this scenario?

  • A. User-Token Oauth flow
  • B. Web server Oauth flow
  • C. SAML assertion Oauth flow
  • D. User-Agent Oauth flow

Answer: B


NEW QUESTION # 95
Northern Trail Outfitters (NTO) recently purchased Salesforce Identity Connect to streamline user provisioning across Microsoft Active Directory (AD) and Salesforce Sales Cloud.
NTO has asked an identity architect to identify which salesforce security configurations can map to AD permissions.
Which three Salesforce permissions are available to map to AD permissions?
Choose 3 answers

  • A. Roles
  • B. Sharing Rules
  • C. Public Groups
  • D. Field-Level Security
  • E. Profiles and Permission Sets

Answer: A,C,E


NEW QUESTION # 96
A leading fitness tracker company is getting ready to launch a customer community. The company wants its customers to login to the community and connect their fitness device to their profile. Customers should be able to obtain exercise details and fitness recommendation in the community.
Which should be used to satisfy this requirement?

  • A. Login Flows
  • B. OAuth Device Flow
  • C. Named Credentials
  • D. Single Sign-On Settings

Answer: B


NEW QUESTION # 97
Universal Containers built a custom mobile app for their field reps to create orders in Salesforce. OAuth is used for authenticating mobile users. The app is built in such a way that when a user session expires after Initial login, a new access token is obtained automatically without forcing the user to log in again. While that improved the field reps' productivity, UC realized that they need a "logout" feature.
What should the logout function perform in this scenario, where user sessions are refreshed automatically?

  • A. Invoke the revocation URL and pass the access token.
  • B. Clear out all the tokens to stop auto session refresh.
  • C. Clear out the client Id to stop auto session refresh.
  • D. Invoke the revocation URL and pass the refresh token.

Answer: D


NEW QUESTION # 98
Universal Containers (UC) uses Salesforce to allow customers to keep track of the order status. The customers can log in to Salesforce using external authentication providers, such as Facebook and Google. UC is also leveraging the App Launcher to let customers access an of platform application for generating shipping labels.
The label generator application uses OAuth to provide users access. What license type should an Architect recommend for the customers?

  • A. External Identity license
  • B. Customer Community Plus license
  • C. Customer Community license
  • D. Identity license

Answer: D


NEW QUESTION # 99
Universal Containers (UC) operates in Asia, Europe and North America regions. There is one Salesforce org for each region. UC is implementing Customer 360 in Salesforce and has procured External Identity and Customer Community licenses in all orgs.
Customers of UC use Community to track orders and create inquiries. Customers also tend to move across regions frequently.
What should an identity architect recommend to optimize license usage and reduce maintenance overhead?

  • A. Contacts are required since Community access needs to be enabled. Maintenance is a necessary overhead that must be handled via data integration.
  • B. Delete contact/ account records and deactivate user if user moves from a specific region; Sync will no longer be required.
  • C. Enable Contactless User in all orgs and downgrade users from Experience Cloud license to External Identity license once users have moved out of that region.
  • D. Merge three orgs into one instance of Salesforce. This will no longer require maintaining three separate copies of the same customer.

Answer: A


NEW QUESTION # 100
A leading fitness tracker company is getting ready to launch a customer community. The company wants its customers to login to the community and connect their fitness device to their profile. Customers should be able to obtain exercise details and fitness recommendation In the community.
Which should be used to satisfy this requirement?

  • A. OAuth Device Plow
  • B. Login Flows
  • C. Named Credentials
  • D. Single Sign-On Settings

Answer: A


NEW QUESTION # 101
Universal Containers (UC) is setting up delegated authentication to allow employees to log in using their corporate credentials. UC's security team is concerned about the risks of exposing the corporate login service on the internet and has asked that a reliable trust mechanism be put in place between the login service and Salesforce.
What mechanism should an Architect put in place to enable a trusted connection between the login service and Salesforce?

  • A. Require the use of Salesforce security tokens on passwords.
  • B. Set up a proxy service for the login service in the DMZ.
  • C. Include Client Id and Client Secret in the login header callout.
  • D. Enforce mutual authentication between systems using SSL.

Answer: A


NEW QUESTION # 102
Universal Containers (UC) uses an internal company portal for their employees to collaborate. UC decides to use Salesforce Ideas and provide the ability for employees to post ideas from the company portal. They use SAML-based SSO to get into the Company portal and would like to leverage it to access Salesforce.
Most of the users don't exist in Salesforce and they would like the user records created in Salesforce Communities the first time they try to access Salesforce.
What recommendation should an Architect make to meet this requirement?

  • A. Use Salesforce APIs to create users on the fly.
  • B. Use Just-in-Time provisioning.
  • C. Use Identity Connect to sync users.
  • D. Use On-the-Fly provisioning.

Answer: B


NEW QUESTION # 103
Universal Containers (UC) would like to enable SAML based SSO for a Salesforce Partner Community. UC has an existing LDAP identity store and a third-party portal. They would like to use the existing portal as the primary site these users access, but also want to allow seamless access to the partner community. What SSO flow should an Architect recommend?

  • A. User- Agent.
  • B. Idp-Initiated.
  • C. Web Server.
  • D. SP-Initiated.

Answer: D


NEW QUESTION # 104
Universal Containers (UC) has implemented SAML-based Single Sign-on for their Salesforce application and is planning to use the Salesforce mobile app. UC wants to ensure that Single Sign-on is used for accessing the Salesforce mobile app.
Which two recommendations should the Architect make? (Choose two.)

  • A. Use the existing SAML SSO flow along with Web Server Flow.
  • B. Configure the Embedded Web Browser to use My Domain URL.
  • C. Configure the Salesforce App to use the My Domain URL.
  • D. Use the existing SAML SSO flow along with User Agent Flow.

Answer: C,D


NEW QUESTION # 105
An administrator created a connected app for a custom wet) application in Salesforce which needs to be visible as a tile in App Launcher The tile for the custom web application is missing in the app launcher for all users in Salesforce. The administrator requested assistance from an identity architect to resolve the issue.
Which two reasons are the source of the issue?
Choose 2 answers
StartURL for the connected app is not set in Connected App settings.

  • A. OAuth scope does not include "openid*.
  • B. The connected app is not set in the App menu as 'Visible in App Launcher".
  • C. Session Policy is set as 'High Assurance Session required' for this connected app.

Answer: A,B


NEW QUESTION # 106
Uwversal Containers (UC) is building a custom employee hut) application on Amazon Web Services (AWS) and would like to store their users' credentials there. Users will also need access to Salesforce for internal operations. UC has tasked an identity architect with evaluating Afferent solutions for authentication and authorization between AWS and Salesforce.
How should an identity architect configure AWS to authenticate and authorize Salesforce users?

  • A. Configure AWS as an OpenID Connect Provider.
  • B. Develop a custom Auth server in AWS.
  • C. Create a custom external authentication provider.
  • D. Configure the custom employee app as a connected app.

Answer: A


NEW QUESTION # 107
IT security at Unversal Containers (UC) us concerned about recent phishing scams targeting its users and wants to add additional layers of login protection. What should an Architect recommend to address the issue?

  • A. Increase Password complexity requirements in Salesforce.
  • B. Lock sessions to the IP address from which they originated.
  • C. Use the Salesforce Authenticator mobile app with two-step verification
  • D. Implement Single Sign-on using a corporate Identity store.

Answer: C


NEW QUESTION # 108
Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for to give its customers the ability to login with their Facebook and Twitter credentials.
Which two actions should an identity architect recommend to meet these requirements?
Choose 2 answers

  • A. Configure a predefined authentication provider for Twitter.
  • B. Create a custom external authentication provider for Facebook.
  • C. Configure a predefined authentication provider for Facebook.
  • D. Create a custom external authentication provider for Twitter.

Answer: A,C


NEW QUESTION # 109
Universal Containers (UC) employees have Salesforce access from restricted IP ranges only, to protect against unauthorised access. UC wants to roll out the Salesforce1 mobile app and make it accessible from any location. Which two options should an Architect recommend? Choose 2 answers

  • A. Remove existing restrictions on IP ranges for all types of user access.
  • B. Relax the IP restriction with a second factor in the Connect App settings for Salesforce1 mobile app.
  • C. Use Login Flow to bypass IP range restriction for the mobile app.
  • D. Relax the IP restrictions in the Connect App settings for the Salesforce1 mobile app.

Answer: B,D


NEW QUESTION # 110
Universal containers (UC) is successfully using Delegated Authentication for their salesforce users. The service supporting Delegated Authentication is written in Java. UC has a new CIO that is requiring all company Web services be RESR-ful and written in . NET. Which two considerations should the UC Architect provide to the new CIO? Choose 2 answers

  • A. Delegated Authentication will not work with rest services.
  • B. Delegated Authentication will not work with a.net service.
  • C. Delegated Authentication will continue to work with a.net service.
  • D. Delegated Authentication will continue to work with rest services.

Answer: A,C


NEW QUESTION # 111
......

Get Instant Access REAL Identity-and-Access-Management-Designer DUMP Pass Your Exam Easily: https://www.easy4engine.com/Identity-and-Access-Management-Designer-test-engine.html

Practice with these Identity-and-Access-Management-Designer dumps Certification Sample Questions: https://drive.google.com/open?id=1m0gmBiUECKTD4JCq_0pbVm26iGym8rC2