
Pass Exam With Full Sureness - Identity-and-Access-Management-Designer Dumps with 192 Questions
Verified Identity-and-Access-Management-Designer dumps Q&As - 100% Pass from RealVCE
Difficulty in writing Identity-and-Access-Management-Designer Exam
This is exam is very difficult for those candidates who don’t practice during preparation and candidates need a lab for practicing. Then practical exposure is much required to understand the contents of the exam. So, if anyone is associated with some kinds of an organization where he has opportunities to practice but if you can’t afford the lab and don’t have time to practice. So, RealVCE is the solution to this problem. We provide the best Salesforce Identity-and-Access-Management-Designer dumps and practice test for your preparation. Salesforce Identity-and-Access-Management-Designer dumps to ensure your success in the Salesforce Identity-and-Access-Management-Designer Certification Exam at first attempt. Our Salesforce Identity-and-Access-Management-Designer dumps are updated on regular basis. RealVCE has given option to download some test papers questions in PDF format, alongwith, this candidates can practice test papers online using our test engine. RealVCE provides verified questions with answers which you can expect in the exam. So, it makes easier for candidates to clear it in the first attempt itself..
For more info visit:
Identity-and-Access-Management-Designer Exam Reference
Identity-and-Access-Management-Designer Exam topics
Candidates must know the exam topics before they start of preparation. Because it will really help them in hitting the core. Our Salesforce Identity-and-Access-Management-Designer dumps will include the following topics:
- Identity Management Concepts 28%
- Access Management Best Practices 15%
- Salesforce as an Identity Provider 23%
- Salesforce Identity 7%
- Community (Partner and Customer) 5%
- Accepting Third-Party Identity in Salesforce 22%
NEW QUESTION 105
Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the OAuth 2.0 user-agent flow (this flow uses the OAuth 2.0 implicit grant type).
Which three OAuth concepts apply to this flow?
Choose 3 answers
- A. Client ID
- B. Refresh Token
- C. Authorization Code
- D. Scopes
- E. Verification Code
Answer: A,B,D
NEW QUESTION 106
A global fitness equipment manufacturer uses Salesforce to manage its sales cycle. The manufacturer has a custom order fulfillment app that needs to request order data from Salesforce. The order fulfillment app needs to integrate with the Salesforce API using OAuth 2.0 protocol.
What should an identity architect use to fulfill this requirement?
- A. Connected App and OAuth scopes
- B. Authentication Providers
- C. Canvas App Integration
- D. OAuth Tokens
Answer: A
NEW QUESTION 107
Universal Containers (UC) implemented SSO to a third-party system for their Salesforce users to access the App Launcher. UC enabled "User Provisioning" on the Connected App so that changes to user accounts can be synched between Salesforce and the third party system. However, UC quickly notices that changes to user roles in Salesforce are not getting synched to the third-party system. What is the most likely reason for this behaviour?
- A. User Provisioning for Connected Apps does not support role sync.
- B. Salesforce roles have more than three levels in the role hierarchy.
- C. The Approval queue for User Provisioning Requests is unmonitored.
- D. Required operation(s) was not mapped in User Provisioning Settings.
Answer: A
NEW QUESTION 108
The security team at Universal containers(UC) has identified exporting reports as a high-risk action and would like to require users to be logged into salesforce with their active directory (AD) credentials when doing so.
For all other uses of Salesforce, Users should be allowed to use AD credentials or salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with salesforce credentials?
- A. Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.
- B. Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.
- C. Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.
- D. Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.
Answer: B
NEW QUESTION 109
How should an Architect force users to authenticate with Two-factor Authentication(2FA) for Salesforce only when not connected to an internal company network?
- A. Apply the "Two-factor Authentication for User Interfae Logins" permission and Login IP Ranges for all Profiles.
- B. Add the company's list of network IP addresses to the Login Range list under 2FA Setup.
- C. Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA in needed.
- D. Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.
Answer: A
NEW QUESTION 110
A pharmaceutical company has an on-premise application (see illustration) that it wants to integrate with Salesforce.
The IT director wants to ensure that requests must include a certificate with a trusted certificate chain to access the company's on-premise application endpoint.
What should an Identity architect do to meet this requirement?
- A. Configure the company firewall to allow traffic from Salesforce IP ranges.
- B. Use open SSL to generate a Self-signed Certificate and upload it to the on-premise app.
- C. Upload a third-party certificate from Salesforce into the on-premise server.
- D. Generate a certificate authority-signed certificate in Salesforce and uploading it to the on-premise application Truststore.
Answer: A
NEW QUESTION 111
Which two capabilities does My Domain enable in the context of a SAML SSO configuration? Choose 2 answers
- A. App Launcher
- B. Login Forensics
- C. Resource deep linking
- D. SSO from Salesforce Mobile App
Answer: C,D
NEW QUESTION 112
Universal Containers (UC) wants to build a few applications that leverage the Salesforce REST API. UC has asked its Architect to describe how the API calls will be authenticated to a specific user. Which two mechanisms can the Architect provide? Choose 2 Answers
- A. Refresh Token
- B. Session ID
- C. Access Token
- D. Authentication Token
Answer: A,C
NEW QUESTION 113
A client is planning to rollout multi-factor authentication (MFA) to its internal employees and wants to understand which authentication and verification methods meet the Salesforce criteria for secure authentication.
Which three functions meet the Salesforce criteria for secure mfa?
Choose 3 answers
- A. username and password + SMS passcode
- B. Certificate-based Authentication
- C. Third-party single sign-on with Mobile Authenticator app
- D. Lightning Login
- E. Username and password + secunty key
Answer: C,D,E
NEW QUESTION 114
Universal containers(UC) has implemented SAML-BASED single Sign-on for their salesforce application and is planning to provide access to salesforce on mobile devices using the salesforce1 mobile app. UC wants to ensure that single Sign-on is used for accessing the salesforce1 mobile app. Which two recommendations should the architect make? Choose 2 answers
- A. Use the existing SAML SSO flow along with Web server flow
- B. Configure the embedded Web browser to use my domain URL.
- C. Configure the salesforce1 app to use the my domain URL
- D. Use the existing SAML SSO flow along with user agent flow.
Answer: C,D
NEW QUESTION 115
Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for NTO to give its customers the ability to login with their Amazon credentials.
What should an identity architect recommend to meet these requirements?
- A. Configure a predefined authentication provider for Amazon.
- B. Configure Amazon as a connected app.
- C. Configure an OpenID Connect Authentication Provider for Amazon.
- D. Create a custom external authentication provider for Amazon.
Answer: C
NEW QUESTION 116
Universal Containers wants to set up SSO for a selected group of users to access external applications from Salesforce through App Launcher.
Which three steps must be completed in Salesforce to accomplish the goal? (Choose three.)
- A. Create Connected Apps for the external applications.
- B. Complete My Domain and Identity Provider setup.
- C. Create Named Credentials for each external system.
- D. Complete Single Sign-on Settings in Security Controls.
- E. Associate User profiles with the Connected Apps.
Answer: B,D,E
Explanation:
Explanation/Reference:
NEW QUESTION 117
Universal containers (UC) does my domain enable in the context of a SAML SSO configuration? Choose 2 answers
- A. Login forensics
- B. App launcher
- C. SSO from salesforce1 mobile app.
- D. Resource deep linking
Answer: C,D
NEW QUESTION 118
Universal Containers (UC) employees have Salesforce access from restricted IP ranges only, to protect against unauthorised access. UC wants to roll out the Salesforce1 mobile app and make it accessible from any location. Which two options should an Architect recommend? Choose 2 answers
- A. Remove existing restrictions on IP ranges for all types of user access.
- B. Use Login Flow to bypass IP range restriction for the mobile app.
- C. Relax the IP restrictions in the Connect App settings for the Salesforce1 mobile app.
- D. Relax the IP restriction with a second factor in the Connect App settings for Salesforce1 mobile app.
Answer: A,B
NEW QUESTION 119
Universal containers (UC) built a customer Community for customers to buy products, review orders, and manage their accounts. UC has provided three different options for customers to log in to the customer Community: salesforce, Google, and Facebook. Which two role combinations are represented by the systems in the scenario? Choose 2 answers
- A. Google is the service provider and Facebook is the identity provider
- B. Salesforce is the service provider and Facebook is the identity provider
- C. Salesforce is the service provider and Google is the identity provider
- D. Facebook is the service provider and salesforce is the identity provider
Answer: B,C
NEW QUESTION 120
Universal Containers has implemented a multi-org strategy and would like to centralize the management of their Salesforce user profiles.
What should the Architect recommend to allow Salesforce profiles to be managed from a central system of record?
- A. Implement Delegated Authentication that will update the user profiles as necessary.
- B. Create an Apex scheduled job in one org that will synchronize the other org's profiles.
- C. Implement an OAuth JWT flow to pass the profile credentials between systems.
- D. Implement JIT provisioning on the SAML IdP that will pass the ProfileID in each assertion.
Answer: D
NEW QUESTION 121
Universal Containers (UC) uses Active Directory (AD) as their identity store for employees and must continue to do so for network access. UC is undergoing a major transformation program and moving all of their enterprise applications to cloud platforms including Salesforct, Workday, and SAP HANA. UC needs to implement an SSO solution for accessing all of the third-party cloud applications and the CIO is inclined to use Salesforce for all of their identity and access management needs.
Which two Salesforce license types does UC need for its employees'
Choose 2 answers
- A. Identity and Identity Connect licenses
- B. Salesforce and Identity Connect licenses
- C. Chatter Only and Identity licenses
- D. Company Community and Identity licenses
Answer: A,B
NEW QUESTION 122
Universal Containers (UC) is building an integration between Salesforce and a legacy web application using the Canvas framework. The security team for UC has determined that a signed request from Salesforce is not an adequate authentication solution for the third-party app.
Which two options should the Architect consider for authenticating the third-party app using the Canvas framework? (Choose two.)
- A. Utilize the Canvas OAuth flow to allow the third-party application to authenticate itself against Salesforce as the IdP.
- B. Utilize Authorization Providers to allow the third-party application to authenticate itself against Salesforce as the IdP.
- C. Create a registration handler Apex class to allow the third-party application to authenticate itself against Salesforce as the IdP.
- D. Utilize the SAML Single Sign-on flow to allow the third-party to authenticate itself against UC's IdP.
Answer: A,D
NEW QUESTION 123
A global company's Salesforce Identity Architect is reviewing its Salesforce production org login history and is seeing some intermittent Security Assertion Markup Language (SAML SSO) 'Replay Detected and Assertion Invalid' login errors.
Which two issues would cause these errors?
Choose 2 answers
- A. The certificate loaded into SSO configuration does not match the certificate used by the IdP.
- B. The current time setting of the company's identity provider (IdP) and Salesforce platform is out of sync by more than eight minutes.
- C. The subject element is missing from the assertion sent to salesforce.
- D. The assertion sent to 5alesforce contains an assertion ID previously used.
Answer: C,D
NEW QUESTION 124
Universal Containers (UC) wants to use Salesforce for sales orders and a legacy of system for order fulfillment. The legacy system must update the status of orders in 65* Salesforce in real time as they are fulfilled. UC decides to use OAuth for connecting the legacy system to Salesforce. What OAuth flow should be considered that doesn't require storing credentials, client secret or refresh tokens?
- A. User Agent flow
- B. Username-Password flow
- C. JWT Bearer Token flow
- D. Web Server flow
Answer: C
NEW QUESTION 125
Universal Containers (UC) uses a home-grown Employee portal for their employees to collaborate. UC decides to use Salesforce Ideas to allow the employees to post ideas from the Employee portal. When clicking some links in the Employee portal, the users should be redirected to Salesforce, authenticated, and presented with relevant pages.
What scope should be requested when using the OAuth token to meet this requirement?
- A. full
- B. api
- C. web
- D. Visualforce
Answer: C
NEW QUESTION 126
......
Identity-and-Access-Management-Designer Dumps Full Questions - Exam Study Guide: https://www.realvce.com/Identity-and-Access-Management-Designer_free-dumps.html
Pass Identity-and-Access-Management-Designer Exam in First Attempt Guaranteed 2021 Dumps: https://drive.google.com/open?id=1-jfIzdpb9EbYBNbDLgSuo1ZdZXkwJ5wS