[Jul-2021] Updated Salesforce Identity and Access Management Designer Identity-and-Access-Management-Designer Exam Questions BUNDLE PACK
Master The Salesforce Content Identity-and-Access-Management-Designer EXAM DUMPS WITH GUARANTEED SUCCESS!
NEW QUESTION 110
universal containers wants to build a custom mobile app connecting to salesforce using Oauth, and would like to restrict the types of resources mobile users can access. What Oauth feature of Salesforce should be used to achieve the goal?
- A. Mobile PINS
- B. Refresh Tokens
- C. Access Tokens
- D. Scopes
Answer: C
NEW QUESTION 111
Universal Containers (UC) wants to use Salesforce for sales orders and a legacy of system for order fulfillment. The legacy system must update the status of orders in 65* Salesforce in real time as they are fulfilled. UC decides to use OAuth for connecting the legacy system to Salesforce. What OAuth flow should be considered that doesn't require storing credentials, client secret or refresh tokens?
- A. JWT Bearer Token flow
- B. Username-Password flow
- C. Web Server flow
- D. User Agent flow
Answer: A
NEW QUESTION 112
Universal Containers (UC) has built a custom token-based Two-factor authentication (2FA) system for their existing on-premise applications. They are now implementing Salesforce and would like to enable a Two-factor login process for it, as well. What is the recommended solution as Architect should consider?
- A. Use the custom 2FA system for on-premise applications and native 2FA for Salesforce.
- B. Replace the custom 2FA system with an AppExchange App that supports on premise application and salesforce.
- C. Use Custom Login Flows to connect to the existing custom 2FA system for use in Salesforce.
- D. Replace the custom 2FA system with Salesforce 2FA for on-premise applications and Salesforce.
Answer: D
NEW QUESTION 113
Universal containers (UC) uses a home-grown employee portal for their employees to collaborate. UC decides to use salesforce ideas to allow the employees to post ideas from the employee portal. When clicking some links in the employee portal, the users should be redirected to salesforce, authenticated, and presented with relevant pages. What scope should be requested when using the Oauth token to meet this requirement?
- A. Web
- B. Full
- C. Visualforce
- D. API
Answer: A
NEW QUESTION 114
What information does the 'Relaystate' parameter contain in sp-Initiated Single Sign-on?
- A. Reference to a URL redirect parameter at the service provider.
- B. Reference to a URL redirect parameter at the identity provider.
- C. Reference to the login address URL of the identity Provider.
- D. Reference to the login address URL of the service provider.
Answer: B
NEW QUESTION 115
Northern Trail Outfitters (NTO) is planning to build a new customer service portal and wants to use passwordless login, allowing customers to login with a one-time passcode sent to them via email or SMS.
How should the quantity of required Identity Verification Credits be estimated?
- A. Identity Verification Credits are a direct add-on license based on the number of existing member-based or login-based Community licenses.
- B. Identity Verification Credits are consumed with each verification sent and should be estimated based on the number of logins that will incur a verification challenge.
- C. Each community comes with 10,000 Identity Verification Credits per month and only customers with more than 10,000 logins a month should estimate additional SMS verifications needed.
- D. Identity Verification Credits are consumed with each SMS (text message) sent and should be estimated based on the number of login verification challenges for SMS verification users.
Answer: D
NEW QUESTION 116
In a typical SSL setup involving a trusted party and trusting party, what consideration should an Architect take into account when using digital certificates?
- A. Use of self-signed certificate leads to higher maintenance for trusting party because the cert needs to be added to their truststore.
- B. Use of self-signed certificate leads to lower maintenance for trusting party because there is no trusted CA cert to maintain.
- C. Use of self-signed certificate leads to lower maintenance for trusted party because multiple self-signed certs need to be maintained.
- D. Use of self-signed certificate leads to higher maintenance for trusted party because they have to act as the trusted CA
Answer: B
NEW QUESTION 117
universal container plans to develop a custom mobile app for the sales team that will use salesforce for authentication and access management. The mobile app access needs to be restricted to only the sales team.
What would be the recommended solution to grant mobile app access to sales users?
- A. Use connected apps Oauth policies to restrict mobile app access to authorized users.
- B. Use a custom attribute on the user object to control access to the mobile app
- C. Add a new identity provider to authenticate and authorize mobile users.
- D. Use the permission set license to assign the mobile app permission to sales users
Answer: A
NEW QUESTION 118
Northern Trail Outfitters is implementing a busmess-to-business (B2B) collaboration site using Salesforce Experience Cloud. The partners will authenticate with an existing identity provider and the solution will utilize Security Assertion Markup Language (SAML) to provide single sign-on to Salesforce. Delegated administration will be used in the Expenence Cloud site to allow the partners to administer their users' access.
How should a partner identity be provisioned in Salesforce for this solution?
- A. Create a person account.
- B. Create only a contact.
- C. Create a contactless user.
- D. Create a user and a related contact.
Answer: D
NEW QUESTION 119
Universal containers (UC) wants to integrate a Web application with salesforce. The UC team has implemented the Oauth web-server Authentication flow for authentication process. Which two considerations should an architect point out to UC? Choose 2 answers
- A. The web server must be able to protect consumer privacy
- B. The flow will not provide an Oauth refresh token back to the server.
- C. The web application should be hosted on a secure server.
- D. The flow involves passing the user credentials back and forth.
Answer: A,C
NEW QUESTION 120
Universal Containers (UC) has implemented SAML-based Single Sign-On to provide seamless access to its Salesforce Orgs, financialsystem, and CPQ system. Below is the SSO implementation landscape.
What role combination is represented by the systems in this scenario''
- A. Financial System and CPQ System are the only Service Providers.
- B. Salesforce Org1 and Salesforce Org2 are acting as Identity Providers.
- C. Salesforce Org1 and Salesforce Org2 are the only Service Providers.
- D. Salesforce Org1 and PingFederate are acting as Identity Providers.
Answer: D
NEW QUESTION 121
Which three types of attacks would a 2-Factor Authentication solution help garden against?
- A. Phishing attacks
- B. Dictionary attacks
- C. Man-in-the-middle attacks
- D. Network perimeter attacks
- E. Key logging attacks
Answer: A,D,E
NEW QUESTION 122
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP.
After some evaluation, UC decides NOT to 65 set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?
- A. Neither SP- nor IdP-initiated SSO will work.
- B. Either SP- or IdP-initiated SSO will work.
- C. IdP-initiated SSO will NOT work.
- D. SP-initiated SSO will NOT work
Answer: A
NEW QUESTION 123
Universal containers wants to set up SSO for a selected group of users to access external applications from salesforce through App launcher. Which three steps must be completed in salesforce to accomplish the goal?
- A. Create connected apps for the external applications.
- B. Complete single Sign-on settings in security controls.
- C. Create named credentials for each external system.
- D. Associate user profiles with the connected Apps.
- E. Complete my domain and Identity provider setup.
Answer: A,D,E
NEW QUESTION 124
Universal Containers (UC) would like its community users to be able to register and log in with Linkedin or Facebook Credentials. UC wants users to clearly see Facebook &Linkedin Icons when they register and login.
What are the two recommended actions UC can take to achieve this Functionality? Choose 2 answers
- A. Create custom Registration Handlers to link Linkedin and facebook accounts to user records.
- B. Store the Linkedin or Facebook user IDs in the Federation ID field on the Salesforce User record.
- C. Create custom buttons for Facebook and inkedin using JAVAscript/CSS on a custom Visualforce page.
- D. Enable Facebook and Linkedin as Login options in the login section of the Community configuration.
Answer: A,D
NEW QUESTION 125
......
Pass Salesforce Identity-and-Access-Management-Designer Exam – Experts Are Here To Help You: https://www.passsureexam.com/Identity-and-Access-Management-Designer-pass4sure-exam-dumps.html
Get Latest Salesforce Identity and Access Management Designer Identity-and-Access-Management-Designer Practice Test For Quick Preparation: https://drive.google.com/open?id=1xE52lKOso6pQ5dmzB17gewfF04713Cb0