Salesforce Identity-and-Access-Management-Designer Exam Dumps - PDF Questions and Testing Engine [Q18-Q38]

Share

Salesforce Identity-and-Access-Management-Designer Exam Dumps - PDF Questions and Testing Engine

Latest Identity-and-Access-Management-Designer Exam Dumps for Pass Guaranteed


How to study the Identity-and-Access-Management-Designer Exam

There are two main types of resources for preparation of certification exams first there are the study guides and the books that are detailed and suitable for building knowledge from ground up then there are video tutorial and lectures that can somehow ease the pain of through study and are comparatively less boring for some candidates yet these demand time and concentration from the learner. Smart Candidates who want to build a solid foundation in all exam topics and related technologies usually combine video lectures with study guides to reap the benefits of both but there is one crucial preparation tool as often overlooked by most candidates the practice exams. Practice exams are built to make students comfortable with the real exam environment. Statistics have shown that most students fail not due to that preparation but due to exam anxiety the fear of the unknown. Easy4Engine expert team recommends you to prepare some notes on these topics along with it don’t forget to practice Salesforce Identity-and-Access-Management-Designer dumps which been written by our expert team, Both these will help you a lot to clear this exam with good marks.

 

NEW QUESTION 18
Universal containers (UC) employees have salesforce access from restricted ip ranges only, to protect against unauthorised access. UC wants to rollout the salesforce1 mobile app and make it accessible from any location.
Which two options should an architect recommend? Choose 2 answers

  • A. Relax the ip restriction in the connect app settings for the salesforce1 mobile app
  • B. Relax the ip restriction with a second factor in the connect app settings for salesforce1 mobile app
  • C. Remove existing restrictions on ip ranges for all types of user access.
  • D. Use login flow to bypass ip range restriction for the mobile app.

Answer: A,D

 

NEW QUESTION 19
Universal Containers (UC) wants to build a mobile application that twill be making calls to the Salesforce REST API. UC's Salesforce implementation relies heavily on custom objects and custom Apex code. UC does not want its users to have to enter credentials every time they use the app. Which two scope values should an Architect recommend to UC? Choose 2 answers.

  • A. Full
  • B. Api
  • C. Custom_permissions
  • D. Refresh_token

Answer: B,D

 

NEW QUESTION 20
A leading fitness tracker company is getting ready to launch a customer community. The company wants its customers to login to the community and connect their fitness device to their profile. Customers should be able to obtain exercise details and fitness recommendation In the community.
Which should be used to satisfy this requirement?

  • A. Single Sign-On Settings
  • B. OAuth Device Plow
  • C. Login Flows
  • D. Named Credentials

Answer: B

 

NEW QUESTION 21
Universal containers wants to implement SAML SSO for their internal salesforce users using a third-party IDP. After some evaluation, UC decides not to set up my domain for their salesforce.org. How does thatdecision impact their SSO implementation?

  • A. Either sp - or IDP - initiated SSO will work
  • B. Sp-Initiated SSO will not work
  • C. IDP - initiated SSO will not work
  • D. Neithersp - nor IDP - initiated SSO will work

Answer: B

 

NEW QUESTION 22
Universal containers (UC) uses an internal company portal for their employees to collaborate. UC decides to use salesforce ideas and provide the ability for employees to post ideas from the company portal. They use SAML-BASED SSO to get into the company portal and would like to leverage it to access salesforce. Most of the users don't exist in salesforce and they would like the user records created in salesforce communities the first time they try to access salesforce. What recommendation should an architect make to meet this requirement?

  • A. Use on-the-fly provisioning
  • B. Use just-in-time provisioning
  • C. Use Identity connect to sync users
  • D. Use salesforce APIs to create users on the fly

Answer: B

 

NEW QUESTION 23
Universal Containers (UC) has a desktop application to collect leads for marketing campaigns. UC wants to extend this application to integrate with Salesforce to create leads. Integration between the desktop application and Salesforce should be seamless. What Authorization flow should the Architect recommend?

  • A. Web Server Authentication Flow
  • B. User Agent Flow
  • C. JWT Bearer Token Flow
  • D. Username and Password Flow

Answer: B

 

NEW QUESTION 24
Universal Containers (UC) has a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a connected App in Salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properly secure access to the app. Which two are recommendations to make the UC? Choose 2 answers

  • A. Use Google Authenticator as an additional part of the login process
  • B. Require High Assurance sessions in order to use the Connected App.
  • C. Disallow the use of Single Sign-on for any users of the mobile app.
  • D. Set Login IP Ranges to the internal network for all of the app users Profiles.

Answer: B,D

 

NEW QUESTION 25
The security team at Universal containers(UC) has identified exporting reports as a high-risk action and would like to require users to be logged into salesforce with their active directory (AD) credentials when doing so. For all other uses of Salesforce, Users should be allowed to use AD credentials or salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with salesforce credentials?

  • A. Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.
  • B. Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.
  • C. Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.
  • D. Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.

Answer: D

 

NEW QUESTION 26
The security team at Universal Containers has identified exporting reports as a high-risk action and would like to require users to be logged into Salesforce with their Active Directory (AD) credentials when doing so.
For all other uses of Salesforce, users should be allowed to use AD credentials or Salesforce credentials.
What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with Salesforce credentials?

  • A. Use SAML Federated Authentication and Custom SAML JIT Provisioning to dynamically add or remove a Permission Set that grants the Export Reports permission.
  • B. Use SAML Federated Authentication, treat SAML Sessions as High Assurance, and raise the session level required for exporting reports.
  • C. Use SAML Federated Authentication with a Login Flow to dynamically add or remove a Permission Set that grants the Export Reports permission.
  • D. Use SAML Federated Authentication and block access to reports when accessed through a Standard Assurance session.

Answer: B

 

NEW QUESTION 27
Universal Containers (UC) uses middleware to integrate multiple systems with Salesforce. UC has a strict, new requirement that usernames and passwords cannot be stored in any UC system.
How can UC's middleware authenticate to Salesforce while adhering to this requirement?

  • A. Create a Connected App that supports the User-Agent OAuth Flow.
  • B. Create a Connected App that supports the Web Server OAuth Flow.
  • C. Create a Connected App that supports the JWT Bearer Token OAuth Flow.
  • D. Create a Connected App that supports the Refresh Token OAuth Flow.

Answer: C

 

NEW QUESTION 28
Universal Containers (UC) currently uses Salesforce Sales Cloud and an external billing application. Both Salesforce and the billing application are accessed several times a day to manage customers. UC would like to configure single sign-on and leverage Salesforce as the identity provider. Additionally, UC would like the billing application to be accessible from Salesforce. A redirect is acceptable.
Which two Salesforce tools should an identity architect recommend to satisfy the requirements?
Choose 2 answers

  • A. salesforce Canvas
  • B. Connected Apps
  • C. Identity Connect
  • D. App Launcher

Answer: A,D

 

NEW QUESTION 29
The security team at Universal Containers (UC) hasidentified exporting reports as a high-risk action and would like to require users to be logged into Salesforce with their Active Directory (AD) credentials when doing so.
For all other users of Salesforce, users should be allowed to use AD Credentials orSalesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with Salesforce credentials?

  • A. Use SAML federated Authentication with a Login Flow to dynamically add or remove a Permission Set that grants the Export Reports Permission.
  • B. Use SAML Federated Authentication and Custom SAML JIT Provisioning to dynamically and or remove a permission set that grants the Export Reports Permission.
  • C. Use SAML Federated Authentication and block access to reports when accessed through a Standard Assurance session.
  • D. Use SAML federated Authentication, treat SAML Sessions as High Assurance, and raise the session level required for exporting reports.

Answer: D

 

NEW QUESTION 30
Universal Containers is setting up their Customer Community self-registration process. They are uncomfortable with the idea of assigning new users to a default Account record.
What will happen when customers self-register in the Community?

  • A. The self-registration page will ask users to select an Account.
  • B. The self-registration page will create a new Account record.
  • C. The self-registration process will create a Person Account record.
  • D. The self-registration process will produce an error to the user.

Answer: D

 

NEW QUESTION 31
Universal containers wants salesforce inbound Oauth-enabled integration clients to use SAML-BASED single Sign-on for authentication. What Oauth flow would be recommended in this scenario?

  • A. User-Agent Oauth flow
  • B. User-Token Oauth flow
  • C. SAML assertion Oauth flow
  • D. Web server Oauth flow

Answer: C

 

NEW QUESTION 32
Universal Containers (UC) has a classified information system that its call center team uses only when they are working on a case with a record type "Classified". They are only allowed to access the system when they own an open "Classified" case, and their access to the system is removed at all other times. They would like to implement SAML SSO eith Salesforce as the Idp, and automatically allow or deny the staff's access to the classified information system based on whether they currently own an open "Classified" case record when they try to access the system using SSO. What is the recommended solution for automatically allowing or denying the access to the classified information system based on the open "classified" case record criteria?

  • A. Use Custom SAML JIT Provisioning to dynamically query the user's open "Classified" cases when attempting to access the classified information system.
  • B. Use Apex trigger on case to dynamically assign permission Sets that Grant access when an user is assigned with an open "Classified" case, and remove it when the case is closed.
  • C. Use Salesforce reports to identify users that currently owns open "Classified" cases and should be granted access to the Classified information system.
  • D. Use a Common Connected App Handler using Apex to dynamically allow access to the system based on whether the staff owns any open "Classified" Cases.

Answer: D

 

NEW QUESTION 33
The security team at Universal Containers (UC) has identified exporting reports as a high-risk action and would like to require users to be logged into Salesforce with their Active Directory (AD) credentials when doing so. For all other users of Salesforce, users should be allowed to use AD Credentials or Salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with Salesforce credentials?

  • A. Use SAML federated Authentication with a Login Flow to dynamically add or remove a Permission Set that grants the Export Reports Permission.
  • B. Use SAML Federated Authentication and Custom SAML JIT Provisioning to dynamically and or remove a permission set that grants the Export Reports Permission.
  • C. Use SAML Federated Authentication andblock access to reports when accessed through a Standard Assurance session.
  • D. Use SAML federatedAuthentication, treat SAML Sessions as High Assurance, and raise the session level required for exporting reports.

Answer: D

 

NEW QUESTION 34
Universal containers (UC) uses a home-grown employee portal for their employees to collaborate. UC decides to use salesforce ideas to allow the employees to post ideas from the employee portal. When clicking some links in the employee portal, the users should be redirected to salesforce, authenticated, and presented with relevant pages. What scope should be requested when using the Oauth token to meet this requirement?

  • A. Full
  • B. API
  • C. Web
  • D. Visualforce

Answer: C

 

NEW QUESTION 35
The security team at Universal containers(UC) has identified exporting reports as a high-risk action and would like to require users to be logged into salesforce with their active directory (AD) credentials when doing so.
For all other uses of Salesforce, Users should be allowed to use AD credentials or salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with salesforce credentials?

  • A. Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.
  • B. Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.
  • C. Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.
  • D. Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.

Answer: D

 

NEW QUESTION 36
An Identity and Access Management (IAM) architect is tasked with unifying multiple B2C Commerce sites and an Experience Cloud community with a single identity. The solution needs to support more than 1,000 logins per minute.
What should the IAM do to fulfill this requirement?

  • A. Configure both the community and the commerce sites as OAuth2 RPs (relying party) with an external identity provider.
  • B. Configure community as a Security Assertion Markup Language (SAML) identity provider and enable Just-in-Time Provisioning to B2C Commerce.
  • C. Confirm performance considerations with Salesforce Customer Support due to high peaks.
  • D. Create a default account for capturing all ecommerce contacts registered on the community because personAccount is not supported for this case.

Answer: C

 

NEW QUESTION 37
After a recent audit, universal containers was advised to implement Two-factor Authentication for all of their critical systems, including salesforce. Which two actions should UC consider to meet this requirement? Choose 2 answers

  • A. Require users to provide their RSA token along with their credentials.
  • B. Require users to enter a second password after the first Authentication
  • C. Require users to supply their email and phone number, which gets validated.
  • D. Require users to use a biometric reader as well as their password

Answer: A,D

 

NEW QUESTION 38
......

Reliable Salesforce Identity and Access Management Designer Identity-and-Access-Management-Designer Dumps PDF Dec 18, 2021 Recently Updated Questions: https://www.easy4engine.com/Identity-and-Access-Management-Designer-test-engine.html

Pass Your Salesforce Identity-and-Access-Management-Designer Exam with Correct 192 Questions and Answers: https://drive.google.com/open?id=1jHZkMqfK5r6JiGKGARnaSsXRtGKfFbe2