First Attempt Guaranteed Success in Identity-and-Access-Management-Designer Exam 2023 [Q56-Q78]

Share

First Attempt Guaranteed Success in Identity-and-Access-Management-Designer Exam 2023

Real Identity-and-Access-Management-Designer Exam Questions are the Best Preparation Material

NEW QUESTION # 56
Universal containers (UC) would like to enable SSO between their existing Active Directory infrastructure and salesforce. The it team prefers to manage all users in Active Directory and would like to avoid doing any initial setup of users in salesforce directly, including the correct assignment of profiles, roles and groups.
Which two optimal solutions should UC use to provision users in salesforce? Choose 2 answers

  • A. Use Identity connect to sync users from Active Directory to salesforce
  • B. Use the salesforce REST API to sync users from active directory to salesforce
  • C. Use Active Directory Federation Services to sync users from active directory to salesforce.
  • D. Use an app exchange product to sync users from Active Directory to salesforce.

Answer: A,D


NEW QUESTION # 57
Northern Trail Outfitters (NTO) is setting up Salesforce to authenticate users with an external identity provider. The NTO Salesforce Administrator is having trouble getting things setup.
What should an identity architect use to show which part of the login assertion is fading?

  • A. Identity Provider Metadata download
  • B. SAML Metadata file importer
  • C. Connected App Manager
  • D. Security Assertion Markup Language Validator

Answer: D


NEW QUESTION # 58
Universal Containers (UC) has a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a Connected App in Salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properly secure access to the app.
Which two solutions should be recommended? (Choose two.)

  • A. Require High Assurance sessions in order to use the Connected App.
  • B. Disallow the use of Single Sign-on for any users of the mobile app.
  • C. Set Login IP Ranges to the internal network for all of the app users' Profiles.
  • D. Use Google Authenticator as an additional part of the login process.

Answer: A,D


NEW QUESTION # 59
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to 65* set up My Domain for their Salesforce org.
How does that decision impact their SSO implementation?

  • A. Either SP- or IdP-initiated SSO will work.
  • B. SP-initiated SSO will NOT work
  • C. IdP-initiated SSO will NOT work.
  • D. Neither SP- nor IdP-initiated SSO will work.

Answer: D


NEW QUESTION # 60
Which three types of attacks would a 2-Factor Authentication solution help garden against?

  • A. Key logging attacks
  • B. Phishing attacks
  • C. Dictionary attacks
  • D. Network perimeter attacks
  • E. Man-in-the-middle attacks

Answer: A,C,D


NEW QUESTION # 61
customer service representatives at Universal containers (UC) are complaining that whenever they click on links to case records and are asked to login with SAML SSO, they are being redirected to the salesforce home tab and not the specific case record. What item should an architect advise the identity team at UC to investigate first?

  • A. My domain is configured and active within salesforce.
  • B. The users have the correct Federation ID within salesforce.
  • C. The salesforce SSO settings are using http post
  • D. The identity provider is correctly preserving the Relay state

Answer: D


NEW QUESTION # 62
Sales users at Universal containers use salesforce for Opportunity management. Marketing uses a third-party application called Nest for Lead nurturing that is accessed using username/password. The VP of sales wants to open up access to nest for all sales uses to provide them access to lead history and would like SSO for better adoption. Salesforce is already setup for SSO and uses Delegated Authentication. Nest can accept username/Password or SAML-based Authentication. IT teams have received multiple password-related issues for nest and have decided to set up SSO access for Nest for Marketing users as well. The CIO does not want to invest in a new IDP solution and is considering using Salesforce for this purpose. Which are appropriate license type choices for sales and marketing users, giving salesforce is using Delegated Authentication? Choose 2 answers

  • A. Salesforce license for sales users and External Identity license for Marketing users
  • B. Salesforce license for sales users and platform license for Marketing users.
  • C. Salesforce license for sales users and Identity license for Marketing users
  • D. Identity license for sales users and Identity connect license for Marketing users

Answer: B,C


NEW QUESTION # 63
Universal Containers want users to be able to log in to the Salesforce mobile app with their Active Directory password. Employees are unable to use mobile VPN.
Which two options should an identity architect recommend to meet the requirement?
Choose 2 answers

  • A. Salesforce Identity Connect
  • B. Salesforce Trigger & Field on Contact Object
  • C. Active Directory Password Sync Plugin
  • D. Configure Cloud Provider Load Balancer

Answer: A,C


NEW QUESTION # 64
Northern Trail Outfitters (NTO) uses Salesforce for Sales Opportunity Management. Okta was recently brought in to Just-in-Time (JIT) provision and authenticate NTO users to applications. Salesforce users also use Okta to authorize a Forecasting web application to access Salesforce records on their behalf.
Which two roles are being performed by Salesforce?
Choose 2 answers

  • A. SAML Service Provider
  • B. SAML Identity Provider
  • C. OAuth Client
  • D. OAuth Resource Server

Answer: A,C


NEW QUESTION # 65
A financial enterprise is planning to set up a user authentication mechanism to login to the Salesforce system. Due to regulatory requirements, the CIO of the company wants user administration, including passwords and authentication requests, to be managed by an external system that is only accessible via a SOAP webservice.
Which authentication mechanism should an identity architect recommend to meet the requirements?

  • A. OAuth Web-Server Flow
  • B. Just-in-Time Provisioning
  • C. Delegated Authentication
  • D. Identity Connect

Answer: C


NEW QUESTION # 66
Universal Containers (UC) would like to enable SAML based SSO for a Salesforce Partner Community. UC has an existing LDAP identity store and a third-party portal. They would like to use the existing portal as the primary site these users access, but also want to allow seamless access to the partner community. What SSO flow should an Architect recommend?

  • A. Idp-Initiated.
  • B. SP-Initiated.
  • C. User- Agent.
  • D. Web Server.

Answer: B


NEW QUESTION # 67
How should an Architect force users to authenticate with Two-factor Authentication (2FA) for Salesforce only when not connected to an internal company network?

  • A. Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.
  • B. Apply the "Two-factor Authentication for User Interface Logins" permission and Login IP Ranges for all Profiles.
  • C. Add the list of company's network IP addresses to the Login Range list under 2FA Setup.
  • D. Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA if needed.

Answer: D


NEW QUESTION # 68
An organization has a central cloud-based Identity and Access Management (IAM) Service for authentication and user management, which must be utilized by all applications as follows:
1 - Change of a user status in the central IAM Service triggers provisioning or deprovisioining in the integrated cloud applications.
2 - Security Assertion Markup Language single sign-on (SSO) is used to facilitate access for users authenticated at identity provider (Central IAM Service).
Which approach should an IAM architect implement on Salesforce Sales Cloud to meet the requirements?

  • A. Configure central IAM Service as an authentication provider and extend registration handler to manage provisioning and deprovisioning of users.
  • B. Configure Salesforce as a SAML service provider, and enable Just-in Time (JIT) provisioning and deprovisioning of users.
  • C. Deploy Identity Connect component and set up automated provisioning and deprovisioning of users, as well as SAML-based SSO.
  • D. A Configure Salesforce as a SAML Service Provider, and enable SCIM (System for Cross-Domain Identity Management) for provisioning and deprovisioning of users.

Answer: D


NEW QUESTION # 69
What are threecapabilitiesof Delegated Authentication? Choose 3 answers

  • A. It can be assigned by Permission Sets.
  • B. It can be assigned by Custom Permissions.
  • C. It can connect to SOAP services.
  • D. It can connect to REST services.
  • E. It can be assigned by Profiles.

Answer: A,C,D


NEW QUESTION # 70
Universal Containers (UC) is building an authenticated Customer Community for its customers. UC does not want customer credentials stored in Salesforce and is confident its customers would be willing to use their social media credentials to authenticate to the Community.
Which two actions should an Architect recommend UC to take? (Choose two.)

  • A. Configure SSO settings for Facebook to serve as a SAML Identity Provider.
  • B. Configure an Authentication Provider for LinkedIn social media accounts.
  • C. Use Delegated Authentication to call the Twitter login API to authenticate users.
  • D. Create a custom Apex Registration Handler to handle new and existing users.

Answer: B,D


NEW QUESTION # 71
An architect has successfully configured SAML-BASED SSO for universal containers. SSO has been working for 3 months when Universal containers manually adds a batch of new users to salesforce. The new users receive an error from salesforce when trying to use SSO. Existing users are still able to successfully use SSO to access salesforce. What is the probable cause of this behaviour?

  • A. The my domain capability is not enabled on the new user's profile.
  • B. The Federation ID field on the new user records is not correctly set
  • C. The new users do not have the SSO permission enabled on their profiles.
  • D. The administrator forgot to reset the new user's salesforce password.

Answer: B


NEW QUESTION # 72
Sales users at Universal containers use salesforce for Opportunity management. Marketing uses a third-party application called Nest for Lead nurturing that is accessed using username/password. The VP of sales wants to open up access to nest for all sales uses to provide them access to lead history and would like SSO for better adoption. Salesforce is already setup for SSO and uses Delegated Authentication. Nest can accept username/Password or SAML-based Authentication. IT teams have received multiple password-related issues for nest and have decided to set up SSO access for Nest for Marketing users as well. The CIO does not want to invest in a new IDP solution and is considering using Salesforce for this purpose. Which are appropriate license type choices for sales and marketing users, giving salesforce is using Delegated Authentication?
Choose 2 answers

  • A. Salesforce license for sales users and External Identity license for Marketing users
  • B. Salesforce license for sales users and platform license for Marketing users.
  • C. Salesforce license for sales users and Identity license for Marketing users
  • D. Identity license for sales users and Identity connect license for Marketing users

Answer: B,C


NEW QUESTION # 73
A group of users try to access one of Universal Containers' Connected Apps and receive the following error message: "Failed: Not approved for access." What is the probable cause of this issue?

  • A. The Connected App setting "All users may self-authorize" is enabled.
  • B. The use of High Assurance sessions are required for the Connected App.
  • C. The users do NOT have the correct permission set assigned to them.
  • D. The Salesforce Administrators have revoked the OAuth authorization.

Answer: C


NEW QUESTION # 74
Universal Containers (UC) has a strict requirement to authenticate users to Salesforce using their mainframe credentials. The mainframe user store cannot be accessed from a SAML provider. UC would also like to have users in Salesforce created on the fly if they provide accurate mainframe credentials.
How can the Architect meet these requirements?

  • A. Use the SOAP API to create the user when created on the mainframe; implement Delegated Authentication.
  • B. Use a Salesforce Login Flow to call out to a web service and create the user on the fly.
  • C. Implement Just-In-Time Provisioning on the mainframe to create the user on the fly.
  • D. Implement OAuth User-Agent Flow on the mainframe; use a Registration Handler to create the user on the fly.

Answer: C


NEW QUESTION # 75
Universal Containers (UC) wants to integrate a third-party Reward Calculation system with Salesforce to calculate Rewards. Rewards will be calculated on a schedule basis and update back into Salesforce. The integration between Salesforce and the Reward Calculation System needs to be secure. Which are two recommended practices for using OAuth flow in this scenario. choose 2 answers

  • A. OAuth Refresh Token FLow
  • B. OAuth SAML Bearer Assertion FLow
  • C. OAuth JWT Bearer Token FLow
  • D. OAuth Username-Password Flow

Answer: B,C


NEW QUESTION # 76
A leading fitness tracker company is getting ready to launch a customer community. The company wants its customers to login to the community and connect their fitness device to their profile. Customers should be able to obtain exercise details and fitness recommendation In the community.
Which should be used to satisfy this requirement?

  • A. Named Credentials
  • B. Login Flows
  • C. Single Sign-On Settings
  • D. OAuth Device Plow

Answer: D


NEW QUESTION # 77
Containers (UC) uses an internal system for recruiting and would like to have the candidates' info available in the Salesforce automatically when they are selected. UC decides to use OAuth to connect to Salesforce from the recruiting system and would like to do the authentication using digital certificates. Which two OAuth flows should be considered to meet the requirement? Choose 2 answers

  • A. JWT Bearer Token flow
  • B. SAML Bearer Assertion flow
  • C. Web Service flow
  • D. Refresh Token flow

Answer: A,B


NEW QUESTION # 78
......

Practice LATEST Identity-and-Access-Management-Designer Exam Updated 245 Questions: https://www.vceprep.com/Identity-and-Access-Management-Designer-latest-vce-prep.html

Download Latest Identity-and-Access-Management-Designer Dumps with Authentic Real Exam QA's: https://drive.google.com/open?id=1WgRZVD2wQDn54FvQdtYn187UND275sc4