
Identity-and-Access-Management-Architect 100% Guarantee Download Identity-and-Access-Management-Architect Exam PDF Q&A [Jun 22, 2023]
Get Identity-and-Access-Management-Architect Actual Free Exam Q&As to Prepare for Your Salesforce Certification
To prepare for this exam, candidates should have a solid understanding of Salesforce's identity and access management solutions, including Single Sign-On (SSO), Identity Provider (IdP), and Security Assertion Markup Language (SAML). They should also have experience with data security and compliance, and be familiar with industry best practices for identity and access management.
The Salesforce Identity-and-Access-Management-Architect Certification Exam is designed for individuals who are interested in becoming experts in managing access and identities within the Salesforce platform. The certification exam is intended for experienced administrators, developers, and architects who have a deep understanding of the Salesforce platform and its security model. To earn this certification, candidates must demonstrate their ability to design and implement complex identity and access management solutions that meet the needs of their organization.
NEW QUESTION # 67
Northern Trail Outfitters (NTO) is planning to roll out a partner portal for its distributors using Experience Cloud. NTO would like to use an external identity provider (idP) and for partners to register for access to the portal. Each partner should be allowed to register only once to avoid duplicate accounts with Salesforce.
What should a identity architect recommend to create partners?
- A. Allow partners to register through the IdP and create partner users in Salesforce through an API.
- B. On successful creation of Partners using Self Registration page in Experience Cloud, create identity in Ping.
- C. Create a custom page m Experience Cloud to self register partner with Experience Cloud and Ping identity store.
- D. Create a custom web page in the Portal and create users in the IdP and Experience Cloud using published APIs.
Answer: C
NEW QUESTION # 68
Universal containers (UC) has a mobile application that calls the salesforce REST API. In order to prevent users from having to enter their credentials everytime they use the app, UC has enabled the use of refresh Tokens as part of the salesforce connected App and updated their mobile app to take advantage of the refresh token. Even after enabling the refresh token, Users are still complaining that they have to enter their credentials once a day. What is the most likely cause of the issue?
- A. The Oauth authorizations are being revoked by a nightly batch job.
- B. The users forget to check the box to remember their credentials.
- C. The refresh token expiration policy is set incorrectly in salesforce
- D. The app is requesting too many access Tokens in a 24-hour period
Answer: C
NEW QUESTION # 69
Universal containers (UC) built a customer Community for customers to buy products, review orders, and manage their accounts. UC has provided three different options for customers to log in to the customer Community: salesforce, Google, and Facebook. Which two role combinations are represented by the systems in the scenario? Choose 2 answers
- A. Salesforce is the service provider and Google is the identity provider
- B. Salesforce is the service provider and Facebook is the identity provider
- C. Google is the service provider and Facebook is the identity provider
- D. Facebook is the service provider and salesforce is the identity provider
Answer: A,B
NEW QUESTION # 70
Northern Trail Outfitters (NTO) wants its customers to use phone numbers to log in to their new digital portal, which was designed and built using Salesforce Experience Cloud. In order to access the portal, the user will need to do the following:
1. Enter a phone number and/or email address
2. Enter a verification code that is to be sent via email or text.
What is the recommended approach to fulfill this requirement?
- A. Create a custom login flow that uses an Apex controller to verify the phone numbers with the company's verification service.
- B. Create a Login Discovery page and provide a Login Discovery Handler Apex class.
- C. Create an Authentication provider and implement a self-registration handler class.
- D. Create a custom login page with an Apex controller. The controller has logic to send and verify the identity.
Answer: B
NEW QUESTION # 71
The executive sponsor for an organization has asked if Salesforce supports the ability to embed a login widget into its service providers in order to create a more seamless user experience.
What should be used and considered before recommending it as a solution on the Salesforce Platform?
- A. Embedded Login. Consider whether or not it relies on third party cookies which can cause browser compatibility issues.
- B. Embedded Login. Identify what level of UI customization will be required to make it match the service providers look and feel.
- C. Salesforce REST apis. Ensure that Secure Sockets Layer (SSL) connection for the integration is used.
- D. OpenID Connect Web Server Flow. Determine if the service provider is secure enough to store the client secret on.
Answer: A
NEW QUESTION # 72
Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the OAuth 2.0 user-agent flow. Application users will authenticate using username and password. They should not be forced to approve API access in the mobile app or reauthenticate for 3 months.
Which two connected app options need to be configured to fulfill this use case?
Choose 2 answers
- A. Set Permitted Users to "All users may self-authorize".
- B. Set Permitted Users to "Admin approved users are pre-authorized".
- C. Set the Session Timeout value to 3 months.
- D. Set the Refresh Token Policy to expire refresh token after 3 months.
Answer: A,D
NEW QUESTION # 73
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers will utilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?
- A. Use a nightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
- B. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML to allow SSO.
- C. Use SAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
- D. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
Answer: C
NEW QUESTION # 74
Universal Containers (UC) wants to provide single sign-on (SSO) for a business-to-consumer (B2C) application using Salesforce Identity.
Which Salesforce license should UC utilize to implement this use case?
- A. Salesforce Platform
- B. External Identity
- C. Identity Only
- D. Partner Community
Answer: B
NEW QUESTION # 75
A multinational industrial products manufacturer is planning to implement Salesforce CRM to manage their business. They have the following requirements:
1. They plan to implement Partner communities to provide access to their partner network .
2. They have operations in multiple countries and are planning to implement multiple Salesforce orgs.
3. Some of their partners do business in multiple countries and will need information from multiple Salesforce communities.
4. They would like to provide a single login for their partners.
How should an Identity Architect solution this requirement with limited custom development?
- A. Allow partners to choose the Salesforce org they need information from and use login flows to authenticate access.
- B. Register partners in one org and access information from other orgs using APIs.
- C. Create a partner login for the country of their operation and use SAML federation to provide access to other orgs.
- D. Consolidate Partner related information in a single org and provide access through Salesforce community.
Answer: C
NEW QUESTION # 76
Universal Containers (UC) uses middleware to integrate multiple systems with Salesforce. UC has a strict, new requirement that usernames and passwords cannot be stored in any UC system. How can UC's middleware authenticate to Salesforce while adhering to this requirement?
- A. Create a Connected App that supports the JWT Bearer Token OAuth Flow.
- B. Create a Connected App that supports the User-Agent OAuth Flow.
- C. Create a Connected App that supports the Web Server OAuth Flow.
- D. Create a Connected App that supports the Refresh Token OAuth Flow
Answer: A
NEW QUESTION # 77
Universal Containers (UC) is looking to purchase a third-party application as an Identity Provider. UC is looking to develop a business case for the purchase in general and has enlisted an Architect for advice. Which two capabilities of an Identity Provider should the Architect detail to help strengthen the business case?
Choose 2 answers
- A. The Identity Provider can authenticate multiple social media accounts.
- B. The Identity Provider can centralize enterprise password policy.
- C. The Identity Provider can authenticate multiple applications.
- D. The Identity provider can store credentials for multiple applications.
Answer: B,C
NEW QUESTION # 78
Northern Trail Outfitters (NTO) wants to improve its engagement with existing customers to boost customer loyalty. To get a better understanding of its customers, NTO establishes a single customer view including their buying behaviors, channel preferences and purchasing history. All of this information exists but is spread across different systems and formats.
NTO has decided to use Salesforce as the platform to build a 360 degree view. The company already uses Microsoft Active Directory (AD) to manage its users and company assets.
What should an Identity Architect do to provision, deprovision and authenticate users?
- A. Salesforce Identity can be included but NTO will be required to build a custom integration with Microsoft AD.
- B. Salesforce Identity is not needed since NTO uses Microsoft AD.
- C. A Salesforce Identity can be included but NTO will require Identity Connect.
- D. Salesforce Identity is included in the Salesforce licenses so it does not need to be considered separately.
Answer: C
NEW QUESTION # 79
A farming enterprise offers smart farming technology to its farmer customers, which includes a variety of sensors for livestock tracking, pest monitoring, climate monitoring etc. They plan to store all the data in Salesforce. They would also like to ensure timely maintenance of the Installed sensors. They have engaged a salesforce Architect to propose an appropriate way to generate sensor Information In Salesforce.
Which OAuth flow should the architect recommend?
- A. OAuth 2.0 Asset Token Flow
- B. OAuth 2.0 Device Authentication Row
- C. OAuth 2.0 SAML Bearer Assertion Flow
- D. OAuth 2.0 JWT Bearer Token Flow
Answer: A
NEW QUESTION # 80
Universal Containers (UC) is both a Salesforce and Google Apps customer. The UC IT team would like to manage the users for both systems in a single place to reduce administrative burden. Which two optimal ways can the IT team provision users and allow Single Sign-on between Salesforce and Google Apps ? Choose 2 answers
- A. Use Identity Connect as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
- B. Use Salesforce as the Identity Provider and Google Apps as a Service Provider and configure User Provisioning for Connected Apps.
- C. Build a custom app running on Heroku as the Identity Provider that can sync user information between Salesforce and Google Apps.
- D. Use a third-party product as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
Answer: B,D
NEW QUESTION # 81
Universal containers(UC) has a customer Community that uses Facebook for authentication. UC would like to ensure that changes in the Facebook profile are reflected on the appropriate customer Community user. How can this requirement be met?
- A. Develop a schedule job that calls out to Facebook on a nightly basis.
- B. Use information in the signed request that is received from Facebook.
- C. Use SAML just-in-time provisioning between Facebook and Salesforce
- D. Use the updateuser() method on the registration handler class.
Answer: D
NEW QUESTION # 82
......
Identity-and-Access-Management-Architect Questions Truly Valid For Your Salesforce Exam: https://pass4sure.dumpstorrent.com/Identity-and-Access-Management-Architect-exam-prep.html