
Actual Identity-and-Access-Management-Designer Exam Recently Updated Questions with Free Demo
Free Salesforce Identity-and-Access-Management-Designer Exam Questions Self-Assess Preparation
The Salesforce Identity-and-Access-Management-Designer Certification Exam is designed to test the knowledge and skills of professionals who specialize in Identity and Access Management (IAM) solutions within the Salesforce ecosystem. This certification is intended for individuals who design and implement secure access solutions for Salesforce applications and data, and who can demonstrate a deep understanding of the Salesforce platform's security features and functionality.
Achieving the Salesforce Certified Identity-and-Access-Management-Designer certification can help you advance your career and open up new job opportunities. This certification demonstrates your expertise in designing and implementing identity and access management solutions using the Salesforce platform, which is highly valued by employers in industries such as finance, healthcare, and government.
NEW QUESTION # 103
Containers (UC) has implemented SAML-based single Sign-on for their Salesforce application and is planning to provide access to Salesforce on mobile devices using the Salesforce1 mobile app. UC wants to ensure that Single Sign-on is used for accessing the Salesforce1 mobile App. Which two recommendations should the Architect make? Choose 2 Answers
- A. Configure the Embedded Web Browser to use My Domain URL.
- B. Use the existing SAML SSO flow along with Web Server Flow.
- C. Use the existing SAML-SSO flow along with User Agent Flow.
- D. Configure the Salesforce1 App to use the MY Domain URL.
Answer: A,D
NEW QUESTION # 104
Northern Trail Outfitters (NTO) uses Salesforce for Sales Opportunity Management. Okta was recently brought in to Just-in-Time (JIT) provision and authenticate NTO users to applications. Salesforce users also use Okta to authorize a Forecasting web application to access Salesforce records on their behalf.
Which two roles are being performed by Salesforce?
Choose 2 answers
- A. OAuth Client
- B. OAuth Resource Server
- C. SAML Service Provider
- D. SAML Identity Provider
Answer: A,C
NEW QUESTION # 105
An Enterprise is using a Lightweight Directory Access Protocol (LDAP ) server as the only point for user authentication with a username/password. Salesforce delegated authentication is configured to integrate Salesforce under single sign-on (SSO).
Mow can end users change their password?
- A. Users can request the Salesforce Admin to reset their password.
- B. Users once logged In, can go to the Change Password screen in Salesforce.
- C. Users can change it on the enterprise LDAP authentication portal.
- D. Users can click on the "Forgot your Password" link on the Salesforce.com login page.
Answer: A
NEW QUESTION # 106
Which two security risks can be mitigated by enabling Two-Factor Authentication (2FA) in Salesforce?
Choose 2 answers
- A. Users accessing Salesforce from a public Wi-Fi access point.
- B. Users creating simple-to-guess password reset questions.
- C. Users choosing passwords that are the same as their Facebook password.
- D. Users leaving laptops unattended and not logging out of Salesforce.
Answer: A,C
NEW QUESTION # 107
Universal Containers (UC) uses Global Shipping (GS) as one of their shipping vendors. Regional leads of GS need access to UC's Salesforce instance for reporting damage of goods using Cases. The regional leads also need access to dashboards to keep track of regional shipping KPIs. UC internally uses a third-party cloud analytics tool for capacity planning and UC decided to provide access to this tool to a subset of GS employees. In addition to regional leads, the GS capacity planning team would benefit from access to this tool. To access the analytics tool, UC IT has set up Salesforce as the Identity provider for Internal users and would like to follow the same approach for the GS users as well. What are the most appropriate license types for GS Tregional Leads and the GS Capacity Planners? Choose 2 Answers
- A. Customer Community Plus license for GS Regional Leads and Customer Community license for GS Capacity Planners.
- B. Customer Community Plus license for GS Regional Leads and External Identity for GS Capacity Planners.
- C. Identity Licence for GS Regional Leads and External Identity license for GS capacity Planners.
- D. Customer Community license for GS Regional Leads and Identity license for GS Capacity Planners.
Answer: A,D
NEW QUESTION # 108
Which two considerations should be made when implementing Delegated Authentication?
Choose 2 answers
- A. Salesforce servers receive but do not validate a user's credentials.
- B. Just-in-time Provisioning can be configured for new users.
- C. It requires trusted IP ranges at the User Profile level.
- D. It can be used to authenticate API clients and mobile apps.
- E. The authentication web service can include custom attributes.
Answer: B,D
NEW QUESTION # 109
A multinational industrial products manufacturer is planning to implement Salesforce CRM to manage their business. They have the following requirements:
1. They plan to implement Partner communities to provide access to their partner network .
2. They have operations in multiple countries and are planning to implement multiple Salesforce orgs.
3. Some of their partners do business in multiple countries and will need information from multiple Salesforce communities.
4. They would like to provide a single login for their partners.
How should an Identity Architect solution this requirement with limited custom development?
- A. Consolidate Partner related information in a single org and provide access through Salesforce community.
- B. Register partners in one org and access information from other orgs using APIs.
- C. Create a partner login for the country of their operation and use SAML federation to provide access to other orgs.
- D. Allow partners to choose the Salesforce org they need information from and use login flows to authenticate access.
Answer: C
NEW QUESTION # 110
What information does the 'Relaystate' parameter contain in sp-Initiated Single Sign-on?
- A. Reference to the login address URL of the service provider.
- B. Reference to the login address URL of the identity Provider.
- C. Reference to a URL redirect parameter at the identity provider.
- D. Reference to a URL redirect parameter at the service provider.
Answer: C
NEW QUESTION # 111
Universal Containers (UC) has a classified information system that its call center team uses only when they are working on a case with a record type "Classified". They are only allowed to access the system when they own an open "Classified" case, and their access to the system is removed at all other times. They would like to implement SAML SSO eith Salesforce as the Idp, and automatically allow or deny the staff's access to the classified information system based on whether they currently own an open "Classified" case record when they try to access the system using SSO. What is the recommended solution for automatically allowing or denying the access to the classified information system based on the open "classified" case record criteria?
- A. Use a Common Connected App Handler using Apex to dynamically allow access to the system based on whether the staff owns any open "Classified" Cases.
- B. Use Apex trigger on case to dynamically assign permission Sets that Grant access when an user is assigned with an open "Classified" case, and remove it when the case is closed.
- C. Use Custom SAML JIT Provisioning to dynamically query the user's open "Classified" cases when attempting to access the classified information system.
- D. Use Salesforce reports to identify users that currently owns open "Classified" cases and should be granted access to the Classified information system.
Answer: A
NEW QUESTION # 112
Northern Trail Outfitters (NTO) utilizes a third-party cloud solution for an employee portal. NTO also owns Salesforce Service Cloud and would like employees to be able to login to Salesforce with their third-party portal credentials for a seamless expenence. The third-party employee portal only supports OAuth.
What should an identity architect recommend to enable single sign-on (SSO) between the portal and Salesforce?
- A. Configure Salesforce for Delegated Authentication.
- B. Create a custom external authentication provider.
- C. Configure SSO to use the third party portal as an identity provider.
- D. Add the third-party portal as a connected app.
Answer: C
NEW QUESTION # 113
Universal Containers (UC) would like to enable SAML-based SSO for a Salesforce Partner Community. UC has an existing LDAP identity store and a third-party portal. They would like to use the existing portal as the primary site these users access, but also want to allow seamless access to the Partner Community.
What SSO flow should an Architect recommend?
- A. User-Agent
- B. SP-Initiated
- C. IdP-Initiated
- D. Web Server
Answer: C
NEW QUESTION # 114
A farming enterprise offers smart farming technology to its farmer customers, which includes a variety of sensors for livestock tracking, pest monitoring, climate monitoring etc. They plan to store all the data in Salesforce. They would also like to ensure timely maintenance of the Installed sensors. They have engaged a salesforce Architect to propose an appropriate way to generate sensor Information In Salesforce.
Which OAuth flow should the architect recommend?
- A. OAuth 2.0 SAML Bearer Assertion Flow
- B. OAuth 2.0 JWT Bearer Token Flow
- C. OAuth 2.0 Asset Token Flow
- D. OAuth 2.0 Device Authentication Row
Answer: C
NEW QUESTION # 115
Universal Containers (UC) uses Active Directory (AD) as their identity store for employees and must continue to do so for network access. UC is undergoing a major transformation program and moving all of their enterprise applications to cloud platforms including Salesforct, Workday, and SAP HANA.
UC needs to implement an SSO solution for accessing all of the third-party cloud applications and the CIO is inclined to use Salesforce for all of their identity and access management needs.
Which two Salesforce license types does UC need for its employees'
Choose 2 answers
- A. Company Community and Identity licenses
- B. Chatter Only and Identity licenses
- C. Identity and Identity Connect licenses
- D. Salesforce and Identity Connect licenses
Answer: C,D
NEW QUESTION # 116
Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the OAuth 2.0 user-agent flow. Application users will authenticate using username and password. They should not be forced to approve API access in the mobile app or reauthenticate for 3 months.
Which two connected app options need to be configured to fulfill this use case?
Choose 2 answers
- A. Set the Refresh Token Policy to expire refresh token after 3 months.
- B. Set the Session Timeout value to 3 months.
- C. Set Permitted Users to "Admin approved users are pre-authorized".
- D. Set Permitted Users to "All users may self-authorize".
Answer: A,D
NEW QUESTION # 117
Universal Containers (UC) has a mobile application for its employees that uses data from Salesforce as well as uses Salesforce for authentication purposes. UC wants its mobile users to only enter their credentials the first time they run the app. The application has been live for a little over 6 months, and all of the users who were a part of the initial launch are complaining that they have to re-authenticate. UC has also recently changed the URI Scheme associated with the mobile app.
What should the Architect at UC first investigate?
- A. Validate that the users are checking the box to remember their passwords.
- B. Verify that the Callback URL is correctly pointing to the new URI Scheme.
- C. Check the Refresh Token Policy defined in the Salesforce Connected App.
- D. Confirm that the Access Token's Time-To-Live policy has been set appropriately.
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION # 118
Universal Containers (UC) has an existing Salesforce org configured for SP-Initiated SAML SSO with their Idp. A second Salesforce org is being introduced into the environment and the IT team would like to ensure they can use the same Idp for new org. What action should the IT team take while implementing the second org?
- A. Use a different Entity ID than the first org.
- B. Use the same request bindings as the first org.
- C. Use the same SAML Identity location as the first org.
- D. Use the Salesforce Username as the SAML Identity Type.
Answer: A
NEW QUESTION # 119
Universal Containers (UC) has an Experience Cloud site (Customer Community) where customers can authenticate and place orders, view the status of orders, etc. UC allows guest checkout.
Mow can a guest register using data previously collected during order placement?
- A. Enable Facebook as an authentication provider and use a registration handler to collect only order details to retrieve customer data.
- B. Use a Connected App Handler Apex Plugin class to collect only order details to retrieve customer data.
- C. Enable self-registration and customize a self-registration page to collect only order details to retrieve customer data.
- D. Enable Security Assertion Markup Language Sign-On and use a login flow to collect only order details to retrieve customer data.
Answer: C
NEW QUESTION # 120
In a typical SSL setup involving a trusted party and a trusting party, what consideration should an Architect take into account when using digital certificates?
- A. Use of self-signed certificate leads to higher maintenance for trusting party because the cert needs to be added to their truststore.
- B. Use of self-signed certificate leads to higher maintenance for trusted party because they have to act as the trusted CA.
- C. Use of self-signed certificate leads to lower maintenance for trusting party because there is no trusted CA cert to maintain.
- D. Use of self-signed certificate leads to lower maintenance for trusted party because multiple self-signed certs need to be maintained.
Answer: A
NEW QUESTION # 121
Which two statements are capable of Identity Connect? Choose 2 answers
- A. Automated user synchronization and de-activation.
- B. Support multiple orgs connecting to multiple Active Directory servers.
- C. Supports both Identity-Provider-Initiated and Service-Provider-Initiated SSO.
- D. Synchronization of Salesforce Permission Set Licence Assignments.
Answer: A,C
NEW QUESTION # 122
Universal Containers (UC) is planning to add Wi-Fi enabled GPS tracking devices to its shipping containers so that the GPS coordinates data can be sent from the tracking device to its Salesforce production org via a custom API. The GPS devices have no direct user input or output capabilities.
Which OAuth flow should the identity architect recommend to meet the requirement?
- A. OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration
- B. OAuth 2.0 Username-Password Flow for Special Scenarios
- C. OAuth 2.0 Asset Token Flow for Securing Connected Devices
- D. OAuth 2.0 Web Server Flow for Web App Integration
Answer: C
NEW QUESTION # 123
Universal containers (UC) uses an internal company portal for their employees to collaborate. UC decides to use salesforce ideas and provide the ability for employees to post ideas from the company portal. They use SAML-BASED SSO to get into the company portal and would like to leverage it to access salesforce. Most of the users don't exist in salesforce and they would like the user records created in salesforce communities the first time they try to access salesforce. What recommendation should an architect make to meet this requirement?
- A. Use Identity connect to sync users
- B. Use on-the-fly provisioning
- C. Use salesforce APIs to create users on the fly
- D. Use just-in-time provisioning
Answer: D
NEW QUESTION # 124
How should an Architect force users to authenticate with Two-factor Authentication (2FA) for Salesforce only when not connected to an internal company network?
- A. Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.
- B. Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA if needed.
- C. Add the list of company's network IP addresses to the Login Range list under 2FA Setup.
- D. Apply the "Two-factor Authentication for User Interface Logins" permission and Login IP Ranges for all Profiles.
Answer: B
NEW QUESTION # 125
A global fitness equipment manufacturer uses Salesforce to manage its sales cycle. The manufacturer has a custom order fulfillment app that needs to request order data from Salesforce. The order fulfillment app needs to integrate with the Salesforce API using OAuth 2.0 protocol.
What should an identity architect use to fulfill this requirement?
- A. Canvas App Integration
- B. OAuth Tokens
- C. Authentication Providers
- D. Connected App and OAuth scopes
Answer: D
NEW QUESTION # 126
......
Successful completion of the Salesforce Identity-and-Access-Management-Designer (Salesforce Certified Identity and Access Management Designer) Certification Exam is a great accomplishment for professionals looking to advance their careers in the field of IAM. It not only enhances their knowledge and skills in the field but also validates their expertise in designing and implementing IAM solutions on the Salesforce platform. The certification also demonstrates their commitment to continuous learning and professional development, which is highly valued by employers in the industry.
Identity-and-Access-Management-Designer Free Sample Questions to Practice One Year Update: https://www.latestcram.com/Identity-and-Access-Management-Designer-exam-cram-questions.html
Download Identity-and-Access-Management-Designer exam with Salesforce Identity-and-Access-Management-Designer Real Exam Questions: https://drive.google.com/open?id=1h5Fm84UdMHF7O3sfaHwJntnEXNDjXbOw
