Unique Top-selling Identity-and-Access-Management-Architect Exams - New 2023 Salesforce Pratice Exam
Identity and Access Management Designer Dumps Identity-and-Access-Management-Architect Exam for Full Questions - Exam Study Guide
Salesforce Identity-and-Access-Management-Architect (Salesforce Certified Identity and Access Management Architect) Exam is a certification exam designed for individuals who have expertise in designing and implementing identity and access management solutions using Salesforce technologies. Identity-and-Access-Management-Architect exam is aimed at architects, engineers, and developers who have experience in designing, building, and deploying solutions to manage user authentication, authorization, and identity federation in complex Salesforce environments. Salesforce Certified Identity and Access Management Architect certification validates the skills and knowledge required to implement and manage a secure and efficient identity and access management strategy.
NEW QUESTION # 97
An identity architect is setting up an integration between Salesforce and a third-party system. The third-party system needs to authenticate to Salesforce and then make API calls against the REST API.
One of the requirements is that the solution needs to ensure the third party service providers connected app in Salesforce mini need for end user interaction and maximizes security.
Which OAuth flow should be used to fulfill the requirement?
- A. JWT Bearer Flow
- B. Username-Password Flow
- C. Web Server Flow
- D. User Agent Flow
Answer: A
NEW QUESTION # 98
Universal Containers is implementing Salesforce Identity to broker authentication from its enterprise single sign-on (SSO) solution through Salesforce to third party applications using SAML.
What rote does Salesforce Identity play in its relationship with the enterprise SSO system?
- A. Identity Provider (IdP)
- B. Client Application
- C. Service Provider (SP)
- D. Resource Server
Answer: C
NEW QUESTION # 99
A technology enterprise is setting up an identity solution with an external vendors wellness application for its employees. The user attributes need to be returned to the wellness application in an ID token.
Which authentication mechanism should an identity architect recommend to meet the requirements?
- A. JWT Bearer Token Flow
- B. Web Server Flow
- C. User Agent Flow
- D. OpenID Connect
Answer: B
NEW QUESTION # 100
Northern Trail Outfitters (NTO) has an existing custom business-to-consumer (B2C) website that does NOT support single sign-on standards, such as Security Assertion Markup Language (SAMi) or OAuth. NTO wants to use Salesforce Identity to register and authenticate new customers on the website.
Which two Salesforce features should an identity architect use in order to provide username/password authentication for the website?
Choose 2 answers
- A. Connected Apps
- B. Embedded Login
- C. Delegated Authentication
- D. Identity Connect
Answer: B,C
NEW QUESTION # 101
Uwversal Containers (UC) is building a custom employee hut) application on Amazon Web Services (AWS) and would like to store their users' credentials there. Users will also need access to Salesforce for internal operations. UC has tasked an identity architect with evaluating Afferent solutions for authentication and authorization between AWS and Salesforce.
How should an identity architect configure AWS to authenticate and authorize Salesforce users?
- A. Configure AWS as an OpenID Connect Provider.
- B. Create a custom external authentication provider.
- C. Configure the custom employee app as a connected app.
- D. Develop a custom Auth server in AWS.
Answer: A
NEW QUESTION # 102
Universal Containers (UC) has five Salesforce orgs (UC1, UC2, UC3, UC4, UC5). of Every user that is in UC2, UC3, UC4, and UC5 is also in UC1, however not all users 65* have access to every org. Universal Containers would like to simplify the authentication process such that all Salesforce users need to remember one set of credentials. UC would like to achieve this with the least impact to cost and maintenance. What approach should an Architect recommend to UC?
- A. Purchase a third-party Identity Provider for all five Salesforce orgs to use, but don't set up JIT user provisioning for other orgs.
- B. Configure UC1 as the Identity Provider to the other four Salesforce orgs, but don't set up JIT user provisioning for other orgs.
- C. Configure UC1 as the Identity Provider to the other four Salesforce orgs and set up JIT user provisioning on all other orgs.
- D. Purchase a third-party Identity Provider for all five Salesforce orgs to use and set up JIT user provisioning on all other orgs.
Answer: A
NEW QUESTION # 103
An Identity and Access Management (IAM) Architect is recommending Identity Connect to integrate Microsoft Active Directory (AD) with Salesforce for user provisioning, deprovisioning and single sign-on (SSO).
Which feature of Identity Connect is applicable for this scenano?
- A. When configured, Identity Connect acts as an identity provider to both Active Directory and Salesforce, thus providing SSO as a default feature.
- B. Identity Connect can be deployed as a managed package on salesforce org, leveraging High Availability of Salesforce Platform out-of-the-box.
- C. When Identity Connect is in place, if a user is deprovisioned in an on-premise AD, the user's Salesforce session Is revoked Immediately.
- D. If the number of provisioned users exceeds Salesforce licence allowances, identity Connect will start disabling the existing Salesforce users in First-in, First-out (FIFO) fashion.
Answer: C
NEW QUESTION # 104
Universal Containers (UC) wants to use Salesforce for sales orders and a legacy of system for order fulfillment. The legacy system must update the status of orders in 65* Salesforce in real time as they are fulfilled. UC decides to use OAuth for connecting the legacy system to Salesforce. What OAuth flow should be considered that doesn't require storing credentials, client secret or refresh tokens?
- A. JWT Bearer Token flow
- B. Username-Password flow
- C. Web Server flow
- D. User Agent flow
Answer: A
NEW QUESTION # 105
Universal Containers (UC) is using a custom application that will act as the Identity Provider and will generate SAML assertions used to log in to Salesforce. UC is considering including custom parameters in the SAML assertion. These attributes contain sensitive data and are needed to authenticate the users. The assertions are submitted to salesforce via a browser form post. The majority of the users will only be able to access Salesforce via UC's corporate network, but a subset of admins and executives would be allowed access from outside the corporate network on their mobile devices. Which two methods should an Architect consider to ensure that the sensitive data cannot be tampered with, nor accessible to anyone while in transit?
- A. Use a custom login flow to retrieve sensitive data using an Apex callout without including the attributes in the assertion.
- B. Use the Identity provider's certificate to digitally Sign and the Identity provider's certificate to encrypt the payload.
- C. Use Salesforce's Certificate to digitally sign the SAML Assertion and a Mobile Device Management client on the users' mobile devices.
- D. Use the Identity Provider's certificate to digitally sign and Salesforce's Certificate to encrypt the payload.
Answer: B,D
NEW QUESTION # 106
A web service is developed that allows secure access to customer order status on the Salesforce Platform, The service connects to Salesforce through a connected app with the web server flow. The following are the required actions for the authorization flow:
1. User Authenticates and Authorizes Access
2. Request an Access Token
3. Salesforce Grants an Access Token
4. Request an Authorization Code
5. Salesforce Grants Authorization Code
What is the correct sequence for the authorization flow?
- A. 1, 4, 5, 2, 3
- B. 4,5,2, 3, 1
- C. 2, 1, 3, 4, 5
- D. 4, 1, 5, 2, 3
Answer: B
NEW QUESTION # 107
Containers (UC) has decided to implement a federated single Sign-on solution using a third-party Idp. In reviewing the third-party products, they would like to ensure the product supports the automated provisioning and deprovisioning of users. What are the underlining mechanisms that the UC Architect must ensure are part of the product?
- A. Provisioning API for both Provisioning and Deprovisioning.
- B. SOAP API for provisioning; Just-in-Time (JIT) for Deprovisioning.
- C. Just-In-time (JIT) for Provisioning; SOAP API for Deprovisioning.
- D. Just-in-Time (JIT) for both Provisioning and Deprovisioning.
Answer: D
NEW QUESTION # 108
Universal Containers (UC) wants to build a few applications that leverage the Salesforce REST API. UC has asked its Architect to describe how the API calls will be authenticated to a specific user. Which two mechanisms can the Architect provide? Choose 2 Answers
- A. Refresh Token
- B. Access Token
- C. Authentication Token
- D. Session ID
Answer: A,B
NEW QUESTION # 109
Universal containers (UC) has a mobile application that calls the salesforce REST API. In order to prevent users from having to enter their credentials everytime they use the app, UC has enabled the use of refresh Tokens as part of the salesforce connected App and updated their mobile app to take advantage of the refresh token. Even after enabling the refresh token, Users are still complaining that they have to enter their credentials once a day. What is the most likely cause of the issue?
- A. The app is requesting too many access Tokens in a 24-hour period
- B. The refresh token expiration policy is set incorrectly in salesforce
- C. The users forget to check the box to remember their credentials.
- D. The Oauth authorizations are being revoked by a nightly batch job.
Answer: B
NEW QUESTION # 110
Universal Containers (UC) is implementing Salesforce and would like to establish SAML SSO for its users to log in. UC stores its corporate user identities in a Custom Database. The UC IT Manager has heard good things about Salesforce Identity Connect as an Idp, and would like to understand what limitations they may face if they decided to use Identity Connect in their current environment. What limitation Should an Architect inform the IT Manager about?
- A. Identity Connect will only support SP-initiated SAML flows in UC's current environment.
- B. Identity Connect will only support Idp-initiated SAML flows in UC's current environment.
- C. Identity connect is not compatible with UC's current identity environment.
- D. Identity Connect will not support user provisioning in UC's current environment.
Answer: D
NEW QUESTION # 111
A security architect is rolling out a new multi-factor authentication (MFA) mandate, where all employees must go through a secure authentication process before accessing Salesforce. There are multiple Identity Providers (IdP) in place and the architect is considering how the "Authentication Method Reference" field (AMR) in the Login History can help.
Which two considerations should the architect keep in mind?
Choose 2 answers
- A. Both OIDC and Security Assertion Markup Language (SAML) are supported but AMR must be implemented at IdP.
- B. Dependency on what is supported by OpenID Connect (OIDC) implementation at IdP.
- C. AMR field shows the authentication methods used at IdP.
- D. High-assurance sessions must be configured under Session Security Level Policies.
Answer: A,C
NEW QUESTION # 112
Refer to the exhibit.
Outfitters (NTO) is using Experience Cloud as an Identity for its application on Heroku. The application on Heroku should be able to handle two brands, Northern Trail Shoes and Northern Trail Shirts.
A user should select either of the two brands in Heroku before logging into the community. The app then performs Authorization using OAuth2.0 with the Salesforce Experience Cloud site.
NTO wants to make sure it renders login page images dynamically based on the user's brand preference selected in Heroku before Authorization.
what should an identity architect do to fulfill the above requirements?
- A. Authorize third-party service by sending authorization requests to the community-url/services/oauth2/authonze/expid_value.
- B. Authorize third-party service by sending authorization requests to the community-url/services/oauth2/authorize/cookie_value.
- C. Create multiple login screens using Experience Builder and use Login Flows at runtime to route to different login screens.
- D. For each brand create different communities and redirect users to the appropriate community using a custom Login controller written in Apex.
Answer: A
NEW QUESTION # 113
Northern Trail Outfitters (NTO) wants its customers to use phone numbers to log in to their new digital portal, which was designed and built using Salesforce Experience Cloud. In order to access the portal, the user will need to do the following:
1. Enter a phone number and/or email address
2. Enter a verification code that is to be sent via email or text.
What is the recommended approach to fulfill this requirement?
- A. Create a custom login flow that uses an Apex controller to verify the phone numbers with the company's verification service.
- B. Create an Authentication provider and implement a self-registration handler class.
- C. Create a custom login page with an Apex controller. The controller has logic to send and verify the identity.
- D. Create a Login Discovery page and provide a Login Discovery Handler Apex class.
Answer: D
NEW QUESTION # 114
Which three different attributes can be used to identify the user in a SAML 65> assertion when Salesforce is acting as a Service Provider? Choose 3 answers
- A. User Full Name
- B. Federation ID
- C. User Email Address
- D. Salesforce Username
- E. Salesforce User ID
Answer: A,B,C
NEW QUESTION # 115
Universal Containers (UC) has an existing web application that it would like to access from Salesforce without requiring users to re-authenticate. The web application is owned UC and the UC team that is responsible for it is willing to add new javascript code and/or libraries to the application. What implementation should an Architect recommend to UC?
- A. Rewrite the web application as a set of Visualforce pages and Apex code.
- B. Create a Canvas app and use Signed Requests to authenticate the users.
- C. Add the web application as a ConnectedApp using OAuth User-Agent flow.
- D. Configure the web application as an item in the Salesforce App Launcher.
Answer: B
NEW QUESTION # 116
An Identity architect works for a multinational, multi-brand organization. As they work with the organization to understand their Customer Identity and Access Management requirements, the identity architect learns that the brand experience is different for each of the customer's sub-brands and each of these branded experiences must be carried through the login experience depending on which sub-brand the user is logging into.
Which solution should the architect recommend to support scalability and reduce maintenance costs, if the organization has more than 150 sub-brands?
- A. Use Audiences to customize the login experience for each sub-brand and pass an audience ID to the community during the OAuth and Security Assertion Markup Language (SAML) flows.
- B. Assign each sub-brand a unique Experience ID and use the Experience ID to dynamically brand the login experience.
- C. Create a separate Salesforce org for each sub-brand so that each sub-brand has complete control over the user experience.
- D. Create a community subdomain for each sub-brand and customize the look and feel of the Login page for each community subdomain to match the brand.
Answer: B
NEW QUESTION # 117
Universal Containers (UC) is building an authenticated Customer Community for its customers. UC does not want customer credentials stored in Salesforce and is confident its customers would be willing to use their social media credentials to authenticate to the community. Which two actions should an Architect recommend UC to take?
- A. Configure SSO Settings For Facebook to serve as a SAML Identity Provider.
- B. Create a Custom Apex Registration Handler to handle new and existing users.
- C. Configure an Authentication Provider for LinkedIn Social Media Accounts.
- D. Use Delegated Authentication to call the Twitter login API to authenticate users.
Answer: B,C
NEW QUESTION # 118
......
Best way to practice test for Salesforce Identity-and-Access-Management-Architect: https://www.dumpsmaterials.com/Identity-and-Access-Management-Architect-real-torrent.html
Identity-and-Access-Management-Architect Dump Ready - Exam Questions and Answers: https://drive.google.com/open?id=1PPgcHfn6uYzfEQ736OGVDz_0F64I1zEE
