Provide Valid Identity-and-Access-Management-Architect Dumps To Help You Prepare For Salesforce Certified Identity and Access Management Architect Exam Apr 07, 2024 [Q36-Q61]

Share

Provide Valid Identity-and-Access-Management-Architect Dumps To Help You Prepare For Salesforce Certified Identity and Access Management Architect Exam Apr 07, 2024

Salesforce Identity-and-Access-Management-Architect Dumps Questions [2024] Pass for Identity-and-Access-Management-Architect Exam


Salesforce Certified Identity and Access Management Architect certification exam is ideal for professionals who work with Salesforce and want to specialize in the field of identity and access management. Identity-and-Access-Management-Architect exam is also suitable for professionals who want to enhance their skills and knowledge in the areas of identity and access management. Candidates who successfully pass Identity-and-Access-Management-Architect exam will be able to demonstrate their expertise in the areas of identity and access management and their ability to design, implement, and manage identity and access management solutions.


Salesforce Certified Identity and Access Management Architect certification is an essential certification for architects who want to demonstrate their expertise in designing and implementing IAM solutions using Salesforce. Salesforce Certified Identity and Access Management Architect certification validates an individual's knowledge of core IAM concepts and their ability to configure and use Salesforce's IAM tools effectively. If you are an experienced architect looking to advance your career in IAM, then the Salesforce Certified Identity and Access Management Architect certification is the right choice for you.


Salesforce Certified Identity and Access Management Architect exam is intended for architects who specialize in designing and implementing IAM solutions for Salesforce customers. Identity-and-Access-Management-Architect exam evaluates the candidate's expertise in various areas such as Salesforce access control, authentication and authorization, external identity, single sign-on, and identity federation. Candidates who take Identity-and-Access-Management-Architect exam should have hands-on experience with Salesforce IAM solutions and a deep understanding of the Salesforce platform.

 

NEW QUESTION # 36
Universal containers (UC) has multiple salesforce orgs and would like to use a single identity provider to access all of their orgs. How should UC'S architect enable this behavior?

  • A. Ensure that users have the same Federation ID value in their user records in all of UC's salesforce orgs.
  • B. Ensure the same username is allowed in multiple orgs by contacting salesforce support.
  • C. Ensure that users have the same email value in their user records in all of UC's salesforce orgs.
  • D. Ensure that users have the same alias value in their user records in all of UC's salesforce orgs.

Answer: A


NEW QUESTION # 37
How should an Architect force users to authenticate with Two-factor Authentication (2FA) for Salesforce only when not connected to an internal company network?

  • A. Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA if needed.
  • B. Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.
  • C. Add the list of company's network IP addresses to the Login Range list under 2FA Setup.
  • D. Apply the "Two-factor Authentication for User Interface Logins" permission and Login IP Ranges for all Profiles.

Answer: A


NEW QUESTION # 38
An administrator created a connected app for a custom wet) application in Salesforce which needs to be visible as a tile in App Launcher The tile for the custom web application is missing in the app launcher for all users in Salesforce. The administrator requested assistance from an identity architect to resolve the issue.
Which two reasons are the source of the issue?
Choose 2 answers

  • A. Session Policy is set as 'High Assurance Session required' for this connected app.
  • B. StartURL for the connected app is not set in Connected App settings.
  • C. OAuth scope does not include "openid".
  • D. The connected app is not set in the App menu as 'Visible in App Launcher".

Answer: B,D

Explanation:
Explanation
The StartURL for the connected app is required to specify the landing page for the app. The connected app must also be set as visible in the App Launcher to appear as a tile for users. References: Connected App Basics, Manage Connected Apps


NEW QUESTION # 39
An identity architect is implementing a mobile-first Consumer Identity Access Management (CIAM) for external users. User authentication is the only requirement. The users email or mobile phone number should be supported as a username.
Which two licenses are needed to meet this requirement?
Choose 2 answers

  • A. Email Verification Credits
  • B. Identity Connect Licenses
  • C. External Identity Licenses
  • D. SMS verification Credits

Answer: C,D

Explanation:
Explanation
External Identity Licenses are required to enable external users to access Salesforce resources via a CIAM solution. Email Verification Credits and SMS Verification Credits are required to enable email or mobile phone number verification for user authentication. Identity Connect Licenses are not required for this scenario, as Identity Connect is a tool for synchronizing user data between Salesforce and Active Directory.
References: External Identity Implementation Guide, Identity Connect Implementation Guide


NEW QUESTION # 40
Universal Containers (UC) has decided to use Salesforce as an Identity Provider for multiple external applications. UC wants to use the salesforce App Launcher to control the Apps that are available to individual users. Which three steps are required to make this happen?

  • A. Set up Identity Connect to Synchronize user data.
  • B. Create a Connected App for each external application.
  • C. Set up Salesforce as a SAML Idp with My Domain.
  • D. Set up an Auth Provider for each External Application.
  • E. Add each connected App to the App Launcher with a Start URL.

Answer: B,C,E


NEW QUESTION # 41
Northern Trail Outfitters (NTO) has a number of employees who do NOT need access Salesforce objects. Trie employees should sign in to a custom Benefits web app using their Salesforce credentials.
Which license should the identity architect recommend to fulfill this requirement?

  • A. Identity Connect License
  • B. Identity Only License
  • C. External Identity License
  • D. Identity Verification Credits Add-on License

Answer: B


NEW QUESTION # 42
A group of users try to access one of universal containers connected apps and receive the following error message : "Failed : Not approved for access". what is most likely to cause of the issue?

  • A. The connected App setting "All users may self-authorize" is enabled.
  • B. The salesforce administrators gave revoked the Oauth authorization.
  • C. The use of high assurance sections are required for the connected App.
  • D. The users do not have the correct permission set assigned to them.

Answer: D


NEW QUESTION # 43

An organization has a central cloud-based Identity and Access Management (IAM) Service for authentication and user management, which must be utilized by all applications as follows:
1 - Change of a user status in the central IAM Service triggers provisioning or deprovisioining in the integrated cloud applications.
2 - Security Assertion Markup Language single sign-on (SSO) is used to facilitate access for users authenticated at identity provider (Central IAM Service).
Which approach should an IAM architect implement on Salesforce Sales Cloud to meet the requirements?

  • A. Deploy Identity Connect component and set up automated provisioning and deprovisioning of users, as well as SAML-based SSO.
  • B. Configure Salesforce as a SAML service provider, and enable Just-in Time (JIT) provisioning and deprovisioning of users.
  • C. Configure central IAM Service as an authentication provider and extend registration handler to manage provisioning and deprovisioning of users.
  • D. A Configure Salesforce as a SAML Service Provider, and enable SCIM (System for Cross-Domain Identity Management) for provisioning and deprovisioning of users.

Answer: D


NEW QUESTION # 44
universal container plans to develop a custom mobile app for the sales team that will use salesforce for authentication and access management. The mobile app access needs to be restricted to only the sales team.
What would be the recommended solution to grant mobile app access to sales users?

  • A. Use the permission set license to assign the mobile app permission to sales users
  • B. Add a new identity provider to authenticate and authorize mobile users.
  • C. Use a custom attribute on the user object to control access to the mobile app
  • D. Use connected apps Oauth policies to restrict mobile app access to authorized users.

Answer: D

Explanation:
Explanation
The recommended solution to grant mobile app access to sales users is to use connected apps OAuth policies to restrict mobile app access to authorized users. A connected app is a configuration in Salesforce that allows an external application, such as a mobile app, to connect to Salesforce using OAuth. OAuth is a protocol that allows the mobile app to obtain an access token from Salesforce after the user grants permission. The access token can then be used by the mobile app to access Salesforce data and features. OAuth policies are settings that control how users can access a connected app, such as who can use the app, how long the access token is valid, and what level of access the app requests. By configuring OAuth policies in the connected app settings, Universal Containers can restrict the mobile app access to only the sales team and protect against unauthorized or excessive access.
References: [Connected Apps], [OAuth Authorization Flows], [OAuth Policies]


NEW QUESTION # 45
Universal Containers (UC) has a mobile application for its employees that uses data from Salesforce as well as uses Salesforce for Authentication purposes. UC wants its mobile users to only enter their credentials the first time they run the app. The application has been live for a little over 6 months, and all of the users who were part of the initial launch are complaining that they have to re-authenticate. UC has also recently changed the URI Scheme associated with the mobile app. What should the Architect at UC first investigate?Universal Containers (UC) has a mobile application for its employees that uses data from Salesforce as well as uses Salesforce for Authentication purposes. UC wants its mobile users to only enter their credentials the first time they run the app. The application has been live for a little over 6 months, and all of the users who were part of the initial launch are complaining that they have to re-authenticate. UC has also recently changed the URI Scheme associated with the mobile app. What should the Architect at UC first investigate?

  • A. Validate that the users are checking the box to remember their passwords.
  • B. Confirm that the access Token's Time-To-Live policy has been set appropriately.
  • C. Check the Refresh Token policy defined in the Salesforce Connected App.
  • D. Verify that the Callback URL is correctly pointing to the new URI Scheme.

Answer: C

Explanation:
Explanation
The first thing that the architect at UC should investigate is the refresh token policy defined in the Salesforce connected app. A refresh token is a credential that allows an application to obtain new access tokens without requiring the user to re-authenticate. The refresh token policy determines how long a refresh token is valid and under what conditions it can be revoked. If the refresh token policy is set to expire after a certain period of time or after a change in IP address or device ID, then the users may have to re-authenticate after using the app for a while or from a different location or device. Option B is not a good choice because validating that the users are checking the box to remember their passwords may not be relevant, as the app uses SSO with a third-party identity provider and does not rely on Salesforce credentials. Option C is not a good choice because verifying that the callback URL is correctly pointing to the new URI scheme may not be necessary, as the callback URL is used for redirecting the user back to the app after authentication, but it does not affect how long the user can stay authenticated. Option D is not a good choice because confirming that the access token's time-to-live policy has been set appropriately may not be effective, as the access token's time-to-live policy determines how long an access token is valid before it needs to be refreshed by a refresh token, but it does not affect how long a refresh token is valid or when it can be revoked. References: [Connected Apps Developer Guide], [Digging Deeper into OAuth 2.0 on Force.com]


NEW QUESTION # 46
Universal Containers (UC) is setting up delegated authentication to allow employees to log in using their corporate credentials. UC's security team is concerned about the risks of exposing the corporate login service on the internet and has asked that a reliable trust mechanism be put in place between the login service and Salesforce.
What mechanism should an Architect put in place to enable a trusted connection between the login service and Salesforce?

  • A. Set up a proxy service for the login service in the DMZ.
  • B. Include Client Id and Client Secret in the login header callout.
  • C. Enforce mutual authentication between systems using SSL.
  • D. Require the use of Salesforce security tokens on passwords.

Answer: C

Explanation:
Explanation
To enable a trusted connection between the login service and Salesforce, an architect should enforce mutual authentication between systems using SSL. Mutual authentication, also known as two-way SSL or client certificate authentication, is a process in which both parties in a communication exchange certificates to verify their identities7. This mechanism ensures that only authorized systems can access each other's resources and prevents unauthorized access or spoofing attacks8. To use mutual authentication with delegated authentication, you need to do the following steps9:
Generate a self-signed certificate in Salesforce and download it.
Import the certificate into your login service's truststore.
Configure your login service to require client certificates for incoming requests.
Generate a certificate for your login service and export it.
Import the certificate into Salesforce's certificate and key management tool.
Enable mutual authentication for your login service's endpoint URL in Salesforce.
References:
Mutual Authentication
Mutual Authentication Overview
Set Up Mutual Authentication


NEW QUESTION # 47
Under which scenario Web Server flow will be used?

  • A. Used for verifying Access protected resources.
  • B. Used for server-side components when page needs to be rendered.
  • C. Used for web applications when server-side code needs to interact with APIS.
  • D. Used for mobile applications and testing legacy Integrations.

Answer: C


NEW QUESTION # 48
Universal Containers allows employees to use a mobile device to access Salesforce for daily operations using a hybrid mobile app. This app uses Mobile software development kits (SDK), leverages refresh token to regenerate access token when required and is distributed as a private app.
The chief security officer is rolling out an org wide compliance policy to enforce re-verification of devices if an employee has not logged in from that device in the last week.
Which connected app setting should be leveraged to comply with this policy change?

  • A. Session Policy - Set timeout value of the connected app to 7 days.
  • B. Refresh Token Policy - Expire the refresh token if it has not been used for 7 days.
  • C. Scope - Deny refresh_token scope for this connected app.
  • D. Permitted User - Ask admins to maintain a list of users who are permitted based on last login date.

Answer: B

Explanation:
Explanation
Refresh Token Policy - Expire the refresh token if it has not been used for 7 days is the connected app setting that should be leveraged to comply with the policy change. This setting ensures that users have to re-verify their devices if they have not logged in from that device in the last week. The other settings are either not relevant or not effective for this scenario. References: Connected App Basics, OAuth 2.0 Refresh Token Flow


NEW QUESTION # 49
Universal Containers (UC) is looking to build a Canvas app and wants to use the corresponding Connected App to control where the app is visible. Which two options are correct in regards to where the app can be made visible under the Connected App setting for the Canvas app? Choose 2 answers

  • A. In the mobile navigation menu on Salesforce for Android.
  • B. Included in the Call Control Tool that's part of Open CTI.
  • C. As part of the body of a Salesforce Knowledge article.
  • D. The sidebar of a Salesforce Console as a console component.

Answer: C,D


NEW QUESTION # 50
Universal containers (UC) has implemented SAML SSO to enable seamless access across multiple applications. UC has regional salesforce orgs and wants it's users to be able to access them from their main Salesforce org seamless. Which action should an architect recommend?

  • A. Configure the regional salesforce orgs as Identity Providers.
  • B. Configure the main salesforce org as the Identity provider.
  • C. Configure the main salesforce org as an authentication provider.
  • D. Configure the main Salesforce org as a service provider.

Answer: B

Explanation:
Explanation
The action that an architect should recommend to UC is to configure the main Salesforce org as the identity provider. An identity provider is an application that authenticates users and provides information about them to service providers. A service provider is an application that provides a service to users and relies on an identity provider for authentication. SAML (Security Assertion Markup Language) is an XML-based standard that allows identity providers and service providers to exchange authentication and authorization data. SSO (Single Sign-On) is a feature that allows users to access multiple applications with one login. In this scenario, the main Salesforce org is the identity provider that authenticates users using SAML and provides information about them to the regional Salesforce orgs. The regional Salesforce orgs are the service providers that provide services to users and rely on the main Salesforce org for authentication. This way, users can access the regional Salesforce orgs from the main Salesforce org seamlessly using SSO.
References: [Identity Provider Overview], [SAML Single Sign-On Overview], [Single Sign-On Overview],
[Salesforce as an Identity Provider]


NEW QUESTION # 51
which three are features of federated Single Sign-on solutions? Choose 3 answers

  • A. It enables quick and easy provisioning and deactivating of users.
  • B. It federates credentials control to authorized applications.
  • C. It establishes trust between Identity store and service provider.
  • D. It improves affiliated applications adoption rates.
  • E. It solves all identity and access management problems.

Answer: B,C,D

Explanation:
Explanation
It federates credentials control to authorized applications. This means that users can access multiple applications across different domains or organizations using one set of credentials, without having to share their passwords with each application1. The applications rely on a trusted identity provider (IdP) to authenticate the users and grant them access.
It establishes trust between Identity store and service provider. This means that the IdP and the service provider (SP) have a mutual agreement to exchange identity information using standard protocols, such as SAML, OpenID Connect, or OAuth2. The IdP and the SP also share metadata and certificates to ensure secure communication and verification.
It improves affiliated applications adoption rates. This means that users are more likely to use applications that are connected to their existing identity provider, as they do not have to create or remember multiple passwords3. This also reduces the friction and frustration of logging in to different applications, and enhances the user experience.
The other options are not features of federated single sign-on solutions because:
It solves all identity and access management problems. This is false, as federated single sign-on solutions only address the authentication aspect of identity and access management, not the authorization, provisioning, governance, or auditing aspects. Federated single sign-on solutions also have some challenges, such as complexity, interoperability, and security risks.
It enables quick and easy provisioning and deactivating of users. This is not necessarily true, as federated single sign-on solutions do not automatically create or delete user accounts in the service provider applications. Users still need to be provisioned and deprovisioned manually or through other mechanisms, such as just-in-time provisioning or SCIM.
References: Federated Identity Management vs. Single Sign-On: What's the Difference?, What is single sign-on?, Single Sign-On (SSO) Solution, [Identity Management vs. Access Management: What's the Difference?], [Federated Identity Management Challenges], [Just-in-Time Provisioning for SAML], [SCIM User Provisioning]


NEW QUESTION # 52
Universal Containers (UC) plans to use a SAML-based third-party IdP serving both of the Salesforce Partner Community and the corporate portal. UC partners will log in 65* to the corporate portal to access protected resources, including links to Salesforce resources. What would be the recommended way to configure the IdP so that seamless access can be achieved in this scenario?

  • A. Configure SP-initiated SSO that passes the SAML token upon Salesforce resource access request.
  • B. Configure IdP-initiated SSO that passes the SAML token upon Salesforce resource access request.
  • C. Set up the corporate portal as a Connected App in Salesforce and use the Web server OAuth flow.
  • D. Set up the corporate portal as a Connected App in Salesforce and use the User Agent OAuth flow.

Answer: B


NEW QUESTION # 53
Universal Containers (UC) has implemented SAML-based Single Sign-On to provide seamless access to its Salesforce Orgs, financial system, and CPQ system. Below is the SSO implementation landscape.

What role combination is represented by the systems in this scenario''

  • A. Salesforce Org1 and Salesforce Org2 are the only Service Providers.
  • B. Financial System and CPQ System are the only Service Providers.
  • C. Salesforce Org1 and PingFederate are acting as Identity Providers.
  • D. Salesforce Org1 and Salesforce Org2 are acting as Identity Providers.

Answer: A

Explanation:
Explanation
In a SAML-based SSO scenario, the identity provider (IdP) is the system that performs authentication and passes the user's identity and authorization level to the service provider (SP), which trusts the IdP and authorizes the user to access the requested resource1. In this case, PingFederate is the IdP that authenticates users for UC and sends SAML assertions to the SPs. The SPs are the systems that rely on PingFederate for authentication and provide access to their services based on the SAML assertions. The SPs in this scenario are Salesforce Org1, Salesforce Org2, Financial System, and CPQ System2. Therefore, the correct answer is B.
References:
SAML web-based authentication guide
SAML-based single sign-on: Configuration and Limitations


NEW QUESTION # 54
Universal Containers is creating a web application that will be secured by Salesforce Identity using the OAuth
2.0 Web Server Flow uses the OAuth 2.0 authorization code grant type).
Which three OAuth concepts apply to this flow?
Choose 3 answers

  • A. Verification URL
  • B. Scopes
  • C. Client Secret
  • D. Access Token

Answer: B,C,D

Explanation:
Explanation
The OAuth 2.0 Web Server Flow requires the client secret to authenticate the web application to Salesforce.
The access token is used to access the Salesforce resources on behalf of the user. The scopes define the permissions and access levels for the web application. References: OAuth 2.0 Web Server Authentication Flow, Digging Deeper into OAuth 2.0 on Force.com


NEW QUESTION # 55
Northern Trail Outfitters (NTO) has an off-boarding process where a terminated employee is first disabled in the Lightweight Directory Act Protocol (LDAP) directory, then requests are sent to the various application support teams to finish user deactivations. A terminated employee recently was able to login to NTO's Salesforce instance 24 hours after termination, even though the user was disabled in the corporate LDAP directory.
What should an identity architect recommend to prevent this from happening in the future?

  • A. Configure an authentication provider to delegate authentication to the LDAP directory.
  • B. Setup an identity provider (IdP) to authenticate users using LDAP, set up single sign-on to Salesforce and disable Login Form authentication.
  • C. use a login flow to make a callout to the LDAP directory before authenticating the user to Salesforce.
  • D. Create a Just-in-Time provisioning registration handler to ensure users are deactivated in Salesforce as they are disabled in LDAP.

Answer: A


NEW QUESTION # 56
Containers (UC) uses a legacy Employee portal for their employees to collaborate. Employees access the portal from their company's internal website via SSO. It is set up to work with SiteMinder and Active Directory. The Employee portal has features to support posing ideas. UC decides to use Salesforce Ideas for voting and better tracking purposes. To avoid provisioning users on Salesforce, UC decides to integrate Employee portal ideas with Salesforce idea through the API. What is the role of Salesforce in the context of SSO, based on this scenario?

  • A. Identity Provider, because the API calls are authenticated by Salesforce.
  • B. An independent system, because Salesforce is not part of the SSO setup.
  • C. Service Provider, because Salesforce is the application for managing ideas.
  • D. Connected App, because Salesforce is connected with Employee portal via API.

Answer: B


NEW QUESTION # 57
How should an identity architect automate provisioning and deprovisioning of users into Salesforce from an external system?

  • A. Call SOAP API upsertQ on user object.
  • B. Call OpenID Connect (OIDC)-userinfo endpoint with a valid access token.
  • C. Use Security Assertion Markup Language Just-in-Time (SAML JIT) on incoming SAML assertions.
  • D. Run registration handler on incoming OAuth responses.

Answer: D

Explanation:
Explanation
To automate provisioning and deprovisioning of users into Salesforce from an external system, the identity architect should run a registration handler on incoming OAuth responses. A registration handler is a class that implements the Auth.RegistrationHandler interface and defines how to create or update users in Salesforce based on the information from an external identity provider. OAuth is a protocol that allows users to authorize an external application to access Salesforce resources on their behalf. By running a registration handler on incoming OAuth responses, the identity architect can automate user provisioning and deprovisioning based on the OAuth attributes. References: Registration Handler, Authorize Apps with OAuth


NEW QUESTION # 58
Northern Trail Outfitters (NTO) is planning to implement a community for its customers using Salesforce Experience Cloud. Customers are not able to self-register. NTO would like to have customers set their own passwords when provided access to the community.
Which two recommendations should an identity architect make to fulfill this requirement?
Choose 2 answers

  • A. Allow Password reset using the API to update Experience Cloud site membership.
  • B. Add customers as contacts and add them to Experience Cloud site.
  • C. Enable Welcome emails while configuring the Experience Cloud site.
  • D. Use Login Flows to allow users to reset password in Experience Cloud site.

Answer: A,D

Explanation:
Explanation
Allowing password reset using the API and using login flows are two possible ways to enable customers to set their own passwords in Experience Cloud. The other options are not relevant for this requirement, as they do not address the password issue. References: Allow Password Reset Using the API, Use Login Flows to Allow Users to Reset Passwords in Experience Cloud Sites


NEW QUESTION # 59
A technology enterprise is planning to implement single sign-on login for users. When users log in to the Salesforce User object custom field, data should be populated for new and existing users.
Which two steps should an identity architect recommend?
Choose 2 answers

  • A. Implement Auth.SamlJitHandler Interface.
  • B. Create and update methods.
  • C. Implement RegistrationHandler Interface.
  • D. Implement SesslonManagement Class.

Answer: A,B


NEW QUESTION # 60
Northern Trail Outfitters (NTO) is planning to roll out a partner portal for its distributors using Experience Cloud. NTO would like to use an external identity provider (idP) and for partners to register for access to the portal. Each partner should be allowed to register only once to avoid duplicate accounts with Salesforce.
What should a identity architect recommend to create partners?

  • A. On successful creation of Partners using Self Registration page in Experience Cloud, create identity in Ping.
  • B. Create a custom page m Experience Cloud to self register partner with Experience Cloud and Ping identity store.
  • C. Create a custom web page in the Portal and create users in the IdP and Experience Cloud using published APIs.
  • D. Allow partners to register through the IdP and create partner users in Salesforce through an API.

Answer: B


NEW QUESTION # 61
......

Achieve Success in Actual Identity-and-Access-Management-Architect Exam Identity-and-Access-Management-Architect Exam Dumps: https://www.test4engine.com/Identity-and-Access-Management-Architect_exam-latest-braindumps.html

Updated Salesforce Study Guide Identity-and-Access-Management-Architect Dumps Questions: https://drive.google.com/open?id=10QNTI26fGoZUk_7rrB52FdmwyC55db0m