Labour Day Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 2493360325

Good News !!! Identity-and-Access-Management-Architect Salesforce Certified Identity and Access Management Architect (SP24) is now Stable and With Pass Result

Identity-and-Access-Management-Architect Practice Exam Questions and Answers

Salesforce Certified Identity and Access Management Architect (SP24)

Last Update 1 day ago
Total Questions : 245

Identity-and-Access-Management-Architect is stable now with all latest exam questions are added 1 day ago. Just download our Full package and start your journey with Salesforce Certified Identity and Access Management Architect (SP24) certification. All these Salesforce Identity-and-Access-Management-Architect practice exam questions are real and verified by our Experts in the related industry fields.

Identity-and-Access-Management-Architect PDF

Identity-and-Access-Management-Architect PDF (Printable)
$48
$119.99

Identity-and-Access-Management-Architect Testing Engine

Identity-and-Access-Management-Architect PDF (Printable)
$56
$139.99

Identity-and-Access-Management-Architect PDF + Testing Engine

Identity-and-Access-Management-Architect PDF (Printable)
$70.8
$176.99
Question # 1

Universal Containers wants to allow its customers to log in to its Experience Cloud via a third party authentication provider that supports only the OAuth protocol.

What should an identity architect do to fulfill this requirement?

Options:

A.  

Contact Salesforce Support and enable delegate single sign-on.

B.  

Create a custom external authentication provider.

C.  

Use certificate-based authentication.

D.  

Configure OpenID Connect authentication provider.

Discussion 0
Question # 2

Universal Containers (UC) has a strict requirement to authenticate users to Salesforce using their mainframe credentials. The mainframe user store cannot be accessed from a SAML provider. UC would also like to have users in Salesforce created on the fly if they provide accurate mainframe credentials.

How can the Architect meet these requirements?

Options:

A.  

Use a Salesforce Login Flow to call out to a web service and create the user on the fly.

B.  

Use the SOAP API to create the user when created on the mainframe; implement Delegated Authentication.

C.  

Implement Just-In-Time Provisioning on the mainframe to create the user on the fly.

D.  

Implement OAuth User-Agent Flow on the mainframe; use a Registration Handler to create the user on the fly.

Discussion 0
Question # 3

Northern Trail Outfitters is implementing a busmess-to-business (B2B) collaboration site using Salesforce Experience Cloud. The partners will authenticate with an existing identity provider and the solution will utilize Security Assertion Markup Language (SAML) to provide single sign-on to Salesforce. Delegated administration will be used in the Expenence Cloud site to allow the partners to administer their users' access.

How should a partner identity be provisioned in Salesforce for this solution?

Options:

A.  

Create only a contact.

B.  

Create a contactless user.

C.  

Create a user and a related contact.

D.  

Create a person account.

Discussion 0
Question # 4

Universal containers (UC) has decided to use identity connect as it's identity provider. UC uses active directory(AD) and has a team that is very familiar and comfortable with managing ad groups. UC would like to use AD groups to help configure salesforce users. Which three actions can AD groups control through identity connect? Choose 3 answers

Options:

A.  

Public Group Assignment

B.  

Granting report folder access

C.  

Role Assignment

D.  

Custom permission assignment

E.  

Permission sets assignment

Discussion 0
Question # 5

A university is planning to set up an identity solution for its alumni. A third-party identity provider will be used for single sign-on Salesforce will be the system of records. Users are getting error messages when logging in.

Which Salesforce feature should be used to debug the issue?

Options:

A.  

Apex Exception Email

B.  

View Setup Audit Trail

C.  

Debug Logs

D.  

Login History

Discussion 0
Question # 6

Universal Containers is considering using Delegated Authentication as the sole means of Authenticating of Salesforce users. A Salesforce Architect has been brought in to assist with the implementation. What two risks Should the Architect point out? Choose 2 answers

Options:

A.  

Delegated Authentication is enabled or disabled for the entire Salesforce org.

B.  

UC will be required to develop and support a custom SOAP web service.

C.  

Salesforce users will be locked out of Salesforce if the web service goes down.

D.  

The web service must reside on a public cloud service, such as Heroku.

Discussion 0
Question # 7

Universal Containers (UC) is looking to purchase a third-party application as an Identity Provider. UC is looking to develop a business case for the purchase in general and has enlisted an Architect for advice. Which two capabilities of an Identity Provider should the Architect detail to help strengthen the business case? Choose 2 answers

Options:

A.  

The Identity Provider can authenticate multiple applications.

B.  

The Identity Provider can authenticate multiple social media accounts.

C.  

The Identity provider can store credentials for multiple applications.

D.  

The Identity Provider can centralize enterprise password policy.

Discussion 0
Question # 8

Northern Trail Outfitters (NTO) has a number of employees who do NOT need access Salesforce objects. Trie employees should sign in to a custom Benefits web app using their Salesforce credentials.

Which license should the identity architect recommend to fulfill this requirement?

Options:

A.  

Identity Only License

B.  

External Identity License

C.  

Identity Verification Credits Add-on License

D.  

Identity Connect License

Discussion 0
Question # 9

The executive sponsor for an organization has asked if Salesforce supports the ability to embed a login widget into its service providers in order to create a more seamless user experience.

What should be used and considered before recommending it as a solution on the Salesforce Platform?

Options:

A.  

OpenID Connect Web Server Flow. Determine if the service provider is secure enough to store the client secret on.

B.  

Embedded Login. Identify what level of UI customization will be required to make it match the service providers look and feel.

C.  

Salesforce REST apis. Ensure that Secure Sockets Layer (SSL) connection for the integration is used.

D.  

Embedded Login. Consider whether or not it relies on third party cookies which can cause browser compatibility issues.

Discussion 0
Question # 10

Universal Containers (UC) wants its users to access Salesforce and other SSO-enabled applications from a custom web page that UC magnets. UC wants its users to use the same set of credentials to access each of the applications. what SAML SSO flow should an Architect recommend for UC?

Options:

A.  

SP-Initiated with Deep Linking

B.  

SP-Initiated

C.  

IdP-Initiated

D.  

User-Agent

Discussion 0
Question # 11

How should an Architect force users to authenticate with Two-factor Authentication (2FA) for Salesforce only when not connected to an internal company network?

Options:

A.  

Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA if needed.

B.  

Add the list of company's network IP addresses to the Login Range list under 2FA Setup.

C.  

Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.

D.  

Apply the "Two-factor Authentication for User Interface Logins" permission and Login IP Ranges for all Profiles.

Discussion 0
Question # 12

Universal Containers (UC) has decided to use Salesforce as an Identity Provider for multiple external applications. UC wants to use the salesforce App Launcher to control the Apps that are available to individual users. Which three steps are required to make this happen?

Options:

A.  

Add each connected App to the App Launcher with a Start URL.

B.  

Set up an Auth Provider for each External Application.

C.  

Set up Salesforce as a SAML Idp with My Domain.

D.  

Set up Identity Connect to Synchronize user data.

E.  

Create a Connected App for each external application.

Discussion 0
Question # 13

Which tool should be used to track login data, such as the average number of logins, who logged in more than the average number of times and who logged in during non-business hours?

Options:

A.  

Login Inspector

B.  

Login History

C.  

Login Report

D.  

Login Forensics

Discussion 0
Question # 14

Universal Containers (UC) implemented SSO to a third-party system for their Salesforce users to access the App Launcher. UC enabled “User Provisioning” on the Connected App so that changes to user accounts can be synched between Salesforce and the third party system. However, UC quickly notices that changes to user roles in Salesforce are not getting synched to the third-party system. What is the most likely reason for this behaviour?

Options:

A.  

User Provisioning for Connected Apps does not support role sync.

B.  

Required operation(s) was not mapped in User Provisioning Settings.

C.  

The Approval queue for User Provisioning Requests is unmonitored.

D.  

Salesforce roles have more than three levels in the role hierarchy.

Discussion 0
Question # 15

Which two roles of the systems are involved in an environment where salesforce users are enabled to access Google Apps from within salesforce through App launcher and connected App set up? Choose 2 answers

Options:

A.  

Google is the identity provider

B.  

Salesforce is the identity provider

C.  

Google is the service provider

D.  

Salesforce is the service provider

Discussion 0
Question # 16

Universal containers wants to implement SAML SSO for their internal salesforce users using a third-party IDP. After some evaluation, UC decides not to set up my domain for their salesforce.org. How does that decision impact their SSO implementation?

Options:

A.  

Neithersp - nor IDP - initiated SSO will work

B.  

Either sp - or IDP - initiated SSO will work

C.  

IDP - initiated SSO will not work

D.  

Sp-Initiated SSO will not work

Discussion 0
Question # 17

Universal Containers (UC) rolling out a new Customer Identity and Access Management Solution will be built on top of their existing Salesforce instance.

Several service providers have been setup and integrated with Salesforce using OpenlD Connect to allow for a seamless single sign-on experience. UC has a requirement to limit user access to only a subset of service providers per customer type.

Which two steps should be done on the platform to satisfy the requirement?

Choose 2 answers

Options:

A.  

Manage which connected apps a user has access to by assigning authentication providers to the users profile.

B.  

Assign the connected app to the customer community, and enable the users profile in the Community settings.

C.  

Use Profiles and Permission Sets to assign user access to Admin Pre-Approved Connected Apps.

D.  

Set each of the Connected App access settings to Admin Pre-Approved.

Discussion 0
Question # 18

Universal containers(UC) has a customer Community that uses Facebook for authentication. UC would like to ensure that changes in the Facebook profile are reflected on the appropriate customer Community user. How can this requirement be met?

Options:

A.  

Use the updateuser() method on the registration handler class.

B.  

Use SAML just-in-time provisioning between Facebook and Salesforce

C.  

Use information in the signed request that is received from Facebook.

D.  

Develop a schedule job that calls out to Facebook on a nightly basis.

Discussion 0
Question # 19

How should an identity architect automate provisioning and deprovisioning of users into Salesforce from an external system?

Options:

A.  

Call SOAP API upsertQ on user object.

B.  

Use Security Assertion Markup Language Just-in-Time (SAML JIT) on incoming SAML assertions.

C.  

Run registration handler on incoming OAuth responses.

D.  

Call OpenID Connect (OIDC)-userinfo endpoint with a valid access token.

Discussion 0
Question # 20

Which two things should be done to ensure end users can only use single sign-on (SSO) to login in to Salesforce?

Choose 2 answers

Options:

A.  

Enable My Domain and select "Prevent login from https://login.salesforce.com ".

B.  

Request Salesforce Support to enable delegated authentication.

C.  

Once SSO is enabled, users are only able to login using Salesforce credentials.

D.  

Assign user "is Single Sign-on Enabled" permission via profile or permission set.

Discussion 0
Question # 21

Universal containers (UC) is concerned that having a self-registration page will provide a means for "bots" or unintended audiences to create user records, thereby consuming licences and adding dirty data. Which two actions should UC take to prevent unauthorised form submissions during the self-registration process? Choose 2 answers

Options:

A.  

Use open-ended security questions and complex password requirements

B.  

Primarily use lookup and picklist fields on the self registration page.

C.  

Require a captcha at the end of the self-registration process.

D.  

Use hidden fields populated via java script events in the self-registration page.

Discussion 0
Question # 22

Which two are valid choices for digital certificates when setting up two-way SSL between Salesforce and an external system. Choose 2 answers

Options:

A.  

Use a trusted CA-signed certificate for salesforce and a trusted CA-signed cert for the external system

B.  

Use a trusted CA-signed certificate for salesforce and a self-signed cert for the external system

C.  

Use a self-signed certificate for salesforce and a self-signed cert for the external system

D.  

Use a self-signed certificate for salesforce and a trusted CA-signed cert for the external system

Discussion 0
Question # 23

In a typical SSL setup involving a trusted party and trusting party, what consideration should an Architect take into account when using digital certificates?

Options:

A.  

Use of self-signed certificate leads to lower maintenance for trusted party because multiple self-signed certs need to be maintained.

B.  

Use of self-signed certificate leads to higher maintenance for trusted party because they have to act as the trusted CA

C.  

Use of self-signed certificate leads to lower maintenance for trusting party because there is no trusted CA cert to maintain.

D.  

Use of self-signed certificate leads to higher maintenance for trusting party because the cert needs to be added to their truststore.

Discussion 0
Question # 24

Northern Trail Outfitters recently acquired a company. Each company will retain its Identity Provider (IdP). Both companies rely extensively on Salesforce processes that send emails to users to take specific actions in Salesforce.

How should the combined companys' employees collaborate in a single Salesforce org, yet authenticate to the appropriate IdP?

Options:

A.  

Configure unique MyDomains for each company and have generated links use the appropriate MyDomam in the URL.

B.  

Have generated links append a querystnng parameter indicating the IdP. The login service will redirect to the appropriate IdP.

C.  

Have generated links be prefixed with the appropriate IdP URL to invoke an IdP-initiated Security Assertion Markup Language flow when clicked.

D.  

Enable each IdP as a login option in the MyDomain Authentication Service settings. Users will then click on the appropriate IdP button.

Discussion 0
Question # 25

A Salesforce customer is implementing Sales Cloud and a custom pricing application for its call center agents. An Enterprise single sign-on solution is used to authenticate and sign-in users to all applications. The customer has the following requirements:

1. The development team has decided to use a Canvas app to expose the pricing application to agents.

2. Agents should be able to access the Canvas app without needing to log in to the pricing application.

Which two options should the identity architect consider to provide support for the Canvas app to initiate login for users?

Choose 2 answers

Options:

A.  

Select "Enable as a Canvas Personal App" in the connected app settings.

B.  

Enable OAuth settings in the connected app with required OAuth scopes for the pricing application.

C.  

Configure the Canvas app as a connected app and set Admin-approved users as pre-authorized.

D.  

Enable SAML in the connected app and Security Assertion Markup Language (SAML) Initiation Method as Service Provider Initiated.

Discussion 0
Question # 26

Universal Containers (UC) is both a Salesforce and Google Apps customer. The UC IT team would like to manage the users for both systems in a single place to reduce administrative burden. Which two optimal ways can the IT team provision users and allow Single Sign-on between Salesforce and Google Apps ? Choose 2 answers

Options:

A.  

Build a custom app running on Heroku as the Identity Provider that can sync user information between Salesforce and Google Apps.

B.  

Use a third-party product as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.

C.  

Use Identity Connect as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.

D.  

Use Salesforce as the Identity Provider and Google Apps as a Service Provider and configure User Provisioning for Connected Apps.

Discussion 0
Question # 27

Northern Trail Outfitters (NTO) wants to improve its engagement with existing customers to boost customer loyalty. To get a better understanding of its customers, NTO establishes a single customer view including their buying behaviors, channel preferences and purchasing history. All of this information exists but is spread across different systems and formats.

NTO has decided to use Salesforce as the platform to build a 360 degree view. The company already uses Microsoft Active Directory (AD) to manage its users and company assets.

What should an Identity Architect do to provision, deprovision and authenticate users?

Options:

A.  

Salesforce Identity is not needed since NTO uses Microsoft A

D.  

B.  

Salesforce Identity can be included but NTO will be required to build a custom integration with Microsoft A

D.  

C.  

Salesforce Identity is included in the Salesforce licenses so it does not need to be considered separately.

D.  

A Salesforce Identity can be included but NTO will require Identity Connect.

Discussion 0
Question # 28

Universal Containers (UC) uses Global Shipping (GS) as one of their shipping vendors. Regional leads of GS need access to UC's Salesforce instance for reporting damage of goods using Cases. The regional leads also need access to dashboards to keep track of regional shipping KPIs. UC internally uses a third-party cloud analytics tool for capacity planning and UC decided to provide access to this tool to a subset of GS employees. In addition to regional leads, the GS capacity planning team would benefit from access to this tool. To access the analytics tool, UC IT has set up Salesforce as the Identity provider for Internal users and would like to follow the same approach for the GS users as well. What are the most appropriate license types for GS Tregional Leads and the GS Capacity Planners? Choose 2 Answers

Options:

A.  

Customer Community Plus license for GS Regional Leads and External Identity for GS Capacity Planners.

B.  

Customer Community Plus license for GS Regional Leads and Customer Community license for GS Capacity Planners.

C.  

Identity Licence for GS Regional Leads and External Identity license for GS capacity Planners.

D.  

Customer Community license for GS Regional Leads and Identity license for GS Capacity Planners.

Discussion 0
Question # 29

Northern Trail Outfitters wants to implement a partner community. Active community users will need to review and accept the community rules, and update key contact information for each community member before their annual partner event.

Which approach will meet this requirement?

Options:

A.  

Create tasks for users who need to update their data or accept the new community rules.

B.  

Create a custom landing page and email campaign asking all community members to login and verify their data.

C.  

Create a login flow that conditionally prompts users who have not accepted the new community rules and who have missing or outdated information.

D.  

Add a banner to the community Home page asking users to update their profile and accept the new community rules.

Discussion 0
Question # 30

Northern Trail Outfitters (NTO) is planning to implement a community for its customers using Salesforce Experience Cloud . Customers are not able to self-register. NTO would like to have customers set their own passwords when provided access to the community.

Which two recommendations should an identity architect make to fulfill this requirement?

Choose 2 answers

Options:

A.  

Add customers as contacts and add them to Experience Cloud site.

B.  

Enable Welcome emails while configuring the Experience Cloud site.

C.  

Allow Password reset using the API to update Experience Cloud site membership.

D.  

Use Login Flows to allow users to reset password in Experience Cloud site.

Discussion 0
Question # 31

A group of users try to access one of universal containers connected apps and receive the following error message : "Failed : Not approved for access". what is most likely to cause of the issue?

Options:

A.  

The use of high assurance sections are required for the connected App.

B.  

The users do not have the correct permission set assigned to them.

C.  

The connected App setting "All users may self-authorize" is enabled.

D.  

The salesforce administrators gave revoked the Oauth authorization.

Discussion 0
Question # 32

Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for NTO to give its customers the ability to login with their Amazon credentials.

What should an identity architect recommend to meet these requirements?

Options:

A.  

Configure a predefined authentication provider for Amazon.

B.  

Create a custom external authentication provider for Amazon.

C.  

Configure an OpenID Connect Authentication Provider for Amazon.

D.  

Configure Amazon as a connected app.

Discussion 0
Question # 33

Which three are features of federated Single sign-on solutions? Choose 3 Answers

Options:

A.  

It establishes trust between Identity Store and Service Provider.

B.  

It federates credentials control to authorized applications.

C.  

It solves all identity and access management problems.

D.  

It improves affiliated applications adoption rates.

E.  

It enables quick and easy provisioning and deactivating of users.

Discussion 0
Question # 34

Universal containers (UC) is setting up Delegated Authentication to allow employees to log in using their corporate credentials. UC's security team is concerned about the risk of exposing the corporate login service on the Internet and has asked that a reliable trust mechanism be put in place between the login service and salesforce. What mechanism should an architect put in place to enable a trusted connection between the login services and salesforce?

Options:

A.  

Include client ID and client secret in the login header callout.

B.  

Set up a proxy server for the login service in the DMZ.

C.  

Require the use of Salesforce security Tokens on password.

D.  

Enforce mutual Authentication between systems using SSL.

Discussion 0
Question # 35

An identity architect has been asked to recommend a solution that allows administrators to configure personalized alert messages to users before they land on the Experience Cloud site (formerly known as Community) homepage.

What is recommended to fulfill this requirement with the least amount of customization?

Options:

A.  

Customize the registration handler Apex class to create a routing logic navigating to different home pages based on the user profile.

B.  

Use Login Flows to add a screen that shows personalized alerts.

C.  

Build a Lightning web Component (LWC) for a homepage that shows custom alerts.

D.  

Create custom metadata that stores user alerts and use a LWC to display alerts.

Discussion 0
Question # 36

Universal Container's (UC) identity architect needs to recommend a license type for their new Experience Cloud site that will be used by external partners (delivery providers) for reviewing and updating their accounts, downloading files provided by UC and obtaining scheduled pickup dates from their calendar.

UC is using their Salesforce production org as the identity provider for these users and the expected number of individual users is 2.5 million with 13.5 million unique logins per month.

Which of the following license types should be used to meet the requirement?

Options:

A.  

External Apps License

B.  

Partner Community License

C.  

Partner Community Login License

D.  

Customer Community plus Login License

Discussion 0
Question # 37

Universal Containers (UC) has a classified information system that its call center team uses only when they are working on a case with a record type "Classified". They are only allowed to access the system when they own an open "Classified" case, and their access to the system is removed at all other times. They would like to implement SAML SSO eith Salesforce as the Idp, and automatically allow or deny the staff's access to the classified information system based on whether they currently own an open "Classified" case record when they try to access the system using SSO. What is the recommended solution for automatically allowing or denying the access to the classified information system based on the open "classified" case record criteria?

Options:

A.  

Use Salesforce reports to identify users that currently owns open "Classified" cases and should be granted access to the Classified information system.

B.  

Use Apex trigger on case to dynamically assign permission Sets that Grant access when an user is assigned with an open "Classified" case, and remove it when the case is closed.

C.  

Use Custom SAML JIT Provisioning to dynamically query the user's open "Classified" cases when attempting to access the classified information system.

D.  

Use a Common Connected App Handler using Apex to dynamically allow access to the system based on whether the staff owns any open "Classified" Cases.

Discussion 0
Get Identity-and-Access-Management-Architect dumps and pass your exam in 24 hours!

Free Exams Sample Questions