
(2023) PASS Identity-and-Access-Management-Designer exam with Salesforce Identity-and-Access-Management-Designer Real Exam Questions
Real exam questions are provided for Salesforce Identity and Access Management Designer tests, which can make sure you 100% pass
NEW QUESTION # 116
Northern Trail Outfitters (NTO) is planning to build a new customer service portal and wants to use passwordless login, allowing customers to login with a one-time passcode sent to them via email or SMS.
How should the quantity of required Identity Verification Credits be estimated?
- A. Identity Verification Credits are a direct add-on license based on the number of existing member-based or login-based Community licenses.
- B. Identity Verification Credits are consumed with each verification sent and should be estimated based on the number of logins that will incur a verification challenge.
- C. Each community comes with 10,000 Identity Verification Credits per month and only customers with more than 10,000 logins a month should estimate additional SMS verifications needed.
- D. Identity Verification Credits are consumed with each SMS (text message) sent and should be estimated based on the number of login verification challenges for SMS verification users.
Answer: D
NEW QUESTION # 117
An Identity architect works for a multinational, multi-brand organization. As they work with the organization to understand their Customer Identity and Access Management requirements, the identity architect learns that the brand experience is different for each of the customer's sub-brands and each of these branded experiences must be carried through the login experience depending on which sub-brand the user is logging into.
Which solution should the architect recommend to support scalability and reduce maintenance costs, if the organization has more than 150 sub-brands?
- A. Assign each sub-brand a unique Experience ID and use the Experience ID to dynamically brand the login experience.
- B. Create a separate Salesforce org for each sub-brand so that each sub-brand has complete control over the user experience.
- C. Use Audiences to customize the login experience for each sub-brand and pass an audience ID to the community during the OAuth and Security Assertion Markup Language (SAML) flows.
- D. Create a community subdomain for each sub-brand and customize the look and feel of the Login page for each community subdomain to match the brand.
Answer: A
NEW QUESTION # 118
An insurance company has a connected app in its Salesforce environment that is used to integrate with a Google Workspace (formerly knot as G Suite).
An identity and access management (IAM) architect has been asked to implement automation to enable users, freeze/suspend users, disable users, and reactivate existing users in Google Workspace upon similar actions in Salesforce.
Which solution is recommended to meet this requirement?
- A. Configure user Provisioning for Connected Apps.
- B. Update the Security Assertion Markup Language Just-in-Time (SAML JIt; handler in Salesforce for user provisioning and de-provisioning.
- C. Build an Apex trigger on the useriogin object to make asynchronous callouts to Google APIs.
- D. Build a custom REST endpoint in Salesforce that Google Workspace can poll against.
Answer: A
NEW QUESTION # 119
Under which scenario Web Server flow will be used?
- A. Used for verifying Access protected resources.
- B. Used for web applications when server-side code needs to interact with APIS.
- C. Used for mobile applications and testing legacy Integrations.
- D. Used for server-side components when page needs to be rendered.
Answer: B
NEW QUESTION # 120
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers will utilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?
- A. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML to allow SSO.
- B. Use SAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
- C. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
- D. Use a nightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
Answer: A
NEW QUESTION # 121
Universal Containers (UC) wants its closed Won opportunities to be synced to a Data warehouse in near real time. UC has implemented Outbound Message to enable near real-time data sync. UC wants to ensure that communication between Salesforce and Target System is secure. What certificate is sent along with the Outbound Message?
- A. The default client Certificate from the Develop--> API menu.
- B. The default client Certificate or the Certificate and Key Management menu.
- C. The CA-signed Certificate from the Certificate and Key Management Menu.
- D. The Self-signed Certificates from the Certificate & Key Management menu.
Answer: A
NEW QUESTION # 122
Which two statements are capable of Identity Connect? Choose 2 answers
- A. Automated user synchronization and de-activation.
- B. Support multiple orgs connecting to multiple Active Directory servers.
- C. Supports both Identity-Provider-Initiated and Service-Provider-Initiated SSO.
- D. Synchronization of Salesforce Permission Set Licence Assignments.
Answer: C,D
NEW QUESTION # 123
universal container plans to develop a custom mobile app for the sales team that will use salesforce for authentication and access management. The mobile app access needs to be restricted to only the sales team.
What would be the recommended solution to grant mobile app access to sales users?
- A. Use the permission set license to assign the mobile app permission to sales users
- B. Use a custom attribute on the user object to control access to the mobile app
- C. Add a new identity provider to authenticate and authorize mobile users.
- D. Use connected apps Oauth policies to restrict mobile app access to authorized users.
Answer: D
NEW QUESTION # 124
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers willutilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?
- A. Use anightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
- B. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML toallow SSO.
- C. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
- D. UseSAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
Answer: D
NEW QUESTION # 125
Universal Containers (UC) wants its closed Won opportunities to be synced to a Data Warehouse in near real time. UC has implemented Outbound Message to enable near real-time data sync. UC wants to ensure that communication between Salesforce and Target System is Secure. What Certificate is sent along with the Outbound Message?
- A. The CA-Signed Certificate from the Certificate and Key Management menu.
- B. The Self-Signed Certificates from the Certificate & Key Management menu.
- C. The default Client Certificate from the Develop--> API Menu.
- D. The default Client Certificate or a Certificate from Certificate and Key Management menu.
Answer: C
NEW QUESTION # 126
Universal Containers is budding a web application that will connect with the Salesforce API using JWT OAuth Flow.
Which two settings need to be configured in the connect app to support this requirement?
Choose 2 answers
- A. The "api" OAuth scope in the connected app.
- B. The Use Digital Signature option in the connected app.
- C. The "web" OAuth scope in the connected app,
- D. The "edair_api" OAuth scope m the connected app.
Answer: A,B
NEW QUESTION # 127
The security team at Universal containers(UC) has identified exporting reports as a high-risk action and would like to require users to be logged into salesforce with their active directory (AD) credentials when doing so. For all other uses of Salesforce, Users should be allowed to use AD credentials or salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with salesforce credentials?
- A. Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.
- B. Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.
- C. Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.
- D. Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.
Answer: C
NEW QUESTION # 128
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP.
After some evaluation, UC decides NOT to 65 set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?
- A. SP-initiated SSO will NOT work
- B. Either SP- or IdP-initiated SSO will work.
- C. IdP-initiated SSO will NOT work.
- D. Neither SP- nor IdP-initiated SSO will work.
Answer: D
NEW QUESTION # 129
Universal containers (UC) would like to enable SAML-BASED SSO for a salesforce partner community. UC has an existing ldap identity store and a third-party portal. They would like to use the existing portal as the primary site these users access, but also want to allow seamless access to the partner community. What SSO flow should an architect recommend?
- A. IDP-initiated
- B. Web server
- C. Sp-Initiated
- D. User-Agent
Answer: A
NEW QUESTION # 130
Universal containers (UC) is concerned that having a self-registration page will provide a means for "bots" or unintended audiences to create user records, thereby consuming licences and adding dirty data. Which two actions should UC take to prevent unauthorised form submissions during the self-registration process? Choose
2 answers
- A. Use hidden fields populated via java script events in the self-registration page.
- B. Primarily use lookup and picklist fields on the self registration page.
- C. Require a captcha at the end of the self-registration process.
- D. Use open-ended security questions and complex password requirements
Answer: A,C
NEW QUESTION # 131
Universal Containers is creating a web application that will be secured by Salesforce Identity using the OAuth 2.0 Web Server Flow uses the OAuth 2.0 authorization code grant type).
Which three OAuth concepts apply to this flow?
Choose 3 answers
- A. Verification URL
- B. Client Secret
- C. Access Token
- D. Scopes
Answer: B,C,D
NEW QUESTION # 132
......
Latest Identity-and-Access-Management-Designer Pass Guaranteed Exam Dumps Certification Sample Questions: https://braindumps2go.actualpdf.com/Identity-and-Access-Management-Designer-real-questions.html
