Pass Your Next Identity-and-Access-Management-Architect Certification Exam Easily & Hassle Free [Q79-Q102]

Share

Pass Your Next Identity-and-Access-Management-Architect Certification Exam Easily & Hassle Free

Free Salesforce Identity-and-Access-Management-Architect Exam Question Practice Exams


Salesforce Identity-and-Access-Management-Architect Exam is a rigorous, multiple-choice exam that consists of 60 questions. Candidates have two hours to complete the exam, and they must achieve a passing score of 65% or higher to earn the certification. Identity-and-Access-Management-Architect exam can be taken either in person at a testing center or online, making it accessible to candidates around the world.


Salesforce Certified Identity and Access Management Architect exam covers a range of topics, including Salesforce identity and access management architecture, user authentication and authorization, identity federation, social sign-on, and single sign-on. Candidates are also expected to have a deep understanding of security standards and best practices, including OAuth, SAML, OpenID Connect, and multi-factor authentication. Identity-and-Access-Management-Architect exam consists of 60 multiple-choice questions, and candidates have 105 minutes to complete it. Passing the exam requires a score of 67% or higher, and the certification is valid for two years. With this certification, individuals can demonstrate their expertise in identity and access management solutions using Salesforce technologies, making them valuable assets to organizations looking to secure their Salesforce environments.

 

NEW QUESTION # 79
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers will utilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?

  • A. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML to allow SSO.
  • B. Use a nightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
  • C. Use SAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
  • D. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.

Answer: C


NEW QUESTION # 80
Universal Containers (UC) has an existing web application that it would like to access from Salesforce without requiring users to re-authenticate. The web application is owned UC and the UC team that is responsible for it is willing to add new javascript code and/or libraries to the application. What implementation should an Architect recommend to UC?

  • A. Rewrite the web application as a set of Visualforce pages and Apex code.
  • B. Configure the web application as an item in the Salesforce App Launcher.
  • C. Add the web application as a ConnectedApp using OAuth User-Agent flow.
  • D. Create a Canvas app and use Signed Requests to authenticate the users.

Answer: D


NEW QUESTION # 81
Northern Trail Outfitters (NTO) is planning to roll out a partner portal for its distributors using Experience Cloud. NTO would like to use an external identity provider (idP) and for partners to register for access to the portal. Each partner should be allowed to register only once to avoid duplicate accounts with Salesforce.
What should a identity architect recommend to create partners?

  • A. On successful creation of Partners using Self Registration page in Experience Cloud, create identity in Ping.
  • B. Create a custom page m Experience Cloud to self register partner with Experience Cloud and Ping identity store.
  • C. Create a custom web page in the Portal and create users in the IdP and Experience Cloud using published APIs.
  • D. Allow partners to register through the IdP and create partner users in Salesforce through an API.

Answer: B


NEW QUESTION # 82

A pharmaceutical company has an on-premise application (see illustration) that it wants to integrate with Salesforce.
The IT director wants to ensure that requests must include a certificate with a trusted certificate chain to access the company's on-premise application endpoint.
What should an Identity architect do to meet this requirement?

  • A. Use open SSL to generate a Self-signed Certificate and upload it to the on-premise app.
  • B. Generate a certificate authority-signed certificate in Salesforce and uploading it to the on-premise application Truststore.
  • C. Upload a third-party certificate from Salesforce into the on-premise server.
  • D. Configure the company firewall to allow traffic from Salesforce IP ranges.

Answer: D


NEW QUESTION # 83
Universal containers (UC) has implemented SAML -based single Sign-on for their salesforce application. UC is using pingfederate as the Identity provider. To access salesforce, Users usually navigate to a bookmarked link to my domain URL. What type of single Sign-on is this?

  • A. Web server flow.
  • B. Sp-Initiated
  • C. IDP-initiated
  • D. IDP-initiated with deep linking

Answer: B


NEW QUESTION # 84
An Architect has configured a SAML-based SSO integration between Salesforce and an external Identity provider and is ready to test it. When the Architect attempts to log in to Salesforce using SSO, the Architect receives a SAML error. Which two optimal actions should the Architect take to troubleshoot the issue?

  • A. Use the browser's Development tools to view the Salesforce page's markup.
  • B. Paste the SAML Assertion Validator in Salesforce.
  • C. Use a browser that has an add-on/extension that can inspect SAML.
  • D. Ensure the Callback URL is correctly set in the Connected Apps settings.

Answer: B,C


NEW QUESTION # 85
Universal Containers (UC) uses Salesforce as a CRM and identity provider (IdP) for their Sales Team to seamlessly login to intemaJ portals. The IT team at UC is now evaluating Salesforce to act as an IdP for its remaining employees.
Which Salesforce license is required to fulfill this requirement?

  • A. External Identity
  • B. Identity Connect
  • C. Identity Only
  • D. Identity Verification

Answer: C

Explanation:
Explanation
To use Salesforce as an IdP for its remaining employees, the IT team at UC should use the Identity Only license. The Identity Only license is a license type that enables users to access external applications that are integrated with Salesforce using single sign-on (SSO) or delegated authentication, but not access Salesforce objects or data. The other license types are not relevant for this scenario. References: Identity Only License, User Licenses


NEW QUESTION # 86
A company wants to provide its employees with a custom mobile app that accesses Salesforce. Users are required to download the internal native IOS mobile app from corporate intranet on their mobile device. The app allows flexibility to access other Non Salesforce internal applications once users authenticate with Salesforce. The apps self-authorize, and users are permitted to use the apps once they have logged into Salesforce.
How should an identity architect meet the above requirements with the privately distributed mobile app?

  • A. Use connected app with OAuth and Security Assertion Markup Language (SAML) to access other Non Salesforce internal apps.
  • B. Use Salesforce as an identity provider (IdP) to access the mobile app and use the external IdP for other non-Salesforce internal apps.
  • C. Configure Mobile App settings in connected app and Salesforce as identity provider for non-Salesforce internal apps.
  • D. Create a new hybrid mobile app and use the connected app with OAuth to authenticate users for Salesforce and non-Salesforce internal apps.

Answer: C


NEW QUESTION # 87
The executive sponsor for an organization has asked if Salesforce supports the ability to embed a login widget into its service providers in order to create a more seamless user experience.
What should be used and considered before recommending it as a solution on the Salesforce Platform?

  • A. OpenID Connect Web Server Flow. Determine if the service provider is secure enough to store the client secret on.
  • B. Embedded Login. Identify what level of UI customization will be required to make it match the service providers look and feel.
  • C. Embedded Login. Consider whether or not it relies on third party cookies which can cause browser compatibility issues.
  • D. Salesforce REST apis. Ensure that Secure Sockets Layer (SSL) connection for the integration is used.

Answer: C

Explanation:
Explanation
Embedded Login is a feature that allows Salesforce to embed a login widget into any web page, such as a service provider's site, to enable users to log in with their Salesforce credentials. However, Embedded Login relies on third-party cookies, which can cause browser compatibility issues and require users to adjust their browser settings. Therefore, this should be considered before recommending it as a solution on the Salesforce Platform. References: Embedded Login, Embedded Login Implementation Guide


NEW QUESTION # 88
An identity architect is implementing a mobile-first Consumer Identity Access Management (CIAM) for external users. User authentication is the only requirement. The users email or mobile phone number should be supported as a username.
Which two licenses are needed to meet this requirement?
Choose 2 answers

  • A. Identity Connect Licenses
  • B. Email Verification Credits
  • C. SMS verification Credits
  • D. External Identity Licenses

Answer: C,D


NEW QUESTION # 89

An organization has a central cloud-based Identity and Access Management (IAM) Service for authentication and user management, which must be utilized by all applications as follows:
1 - Change of a user status in the central IAM Service triggers provisioning or deprovisioning in the integrated cloud applications.
2 - Security Assertion Markup Language single sign-on (SSO) is used to facilitate access for users authenticated at identity provider (Central IAM Service).
Which approach should an IAM architect implement on Salesforce Sales Cloud to meet the requirements?

  • A. A Configure Salesforce as a SAML Service Provider, and enable SCIM (System for Cross-Domain Identity Management) for provisioning and deprovisioning of users.
  • B. Deploy Identity Connect component and set up automated provisioning and deprovisioning of users, as well as SAML-based SSO.
  • C. Configure central IAM Service as an authentication provider and extend registration handler to manage provisioning and deprovisioning of users.
  • D. Configure Salesforce as a SAML service provider, and enable Just-in Time (JIT) provisioning and deprovisioning of users.

Answer: A

Explanation:
Explanation
To meet the requirements of using a central cloud-based IAM service for authentication and user management, the IAM architect should implement Salesforce Sales Cloud as a SAML service provider and enable SCIM for provisioning and deprovisioning of users. SAML is a protocol that allows users to authenticate and authorize with an external identity provider and access Salesforce resources. By configuring Salesforce as a SAML service provider, the IAM architect can use the central IAM service as an identity provider and enable single sign-on for users. SCIM is a standard that defines how to manage user identities across different systems. By enabling SCIM in Salesforce, the IAM architect can synchronize user data between the central IAM service and Salesforce and automate user provisioning and deprovisioning based on the changes made in the central IAM service. References: SAML Single Sign-On Settings, SCIM User Provisioning for Connected Apps


NEW QUESTION # 90
An Identity and Access Management (IAM) architect is tasked with unifying multiple B2C Commerce sites and an Experience Cloud community with a single identity. The solution needs to support more than 1,000 logins per minute.
What should the IAM do to fulfill this requirement?

  • A. Confirm performance considerations with Salesforce Customer Support due to high peaks.
  • B. Configure community as a Security Assertion Markup Language (SAML) identity provider and enable Just-in-Time Provisioning to B2C Commerce.
  • C. Create a default account for capturing all ecommerce contacts registered on the community because person Account is not supported for this case.
  • D. Configure both the community and the commerce sites as OAuth2 RPs (relying party) with an external identity provider.

Answer: D

Explanation:
Explanation
According to the Salesforce documentation2, OAuth2 RPs (relying parties) are applications that use OAuth 2.0 for authentication and authorization with an external identity provider. This allows users to log in to multiple applications with a single identity provider account. The identity provider issues an access token to the relying party, which can be used to access protected resources on behalf of the user. This solution can support high volumes of logins per minute and unify multiple B2C Commerce sites and an Experience Cloud community with a single identity.


NEW QUESTION # 91
What item should an Architect consider when designing a Delegated Authentication implementation?

  • A. The web service should use the Salesforce Federation ID to identify the user.
  • B. The Web service should be able to accept one to four input method parameters.
  • C. The Web service should implement a custom password decryption method.
  • D. The Web service should be secured with TLS using Salesforce trusted certificates.

Answer: D

Explanation:
Explanation
The web service that is used for delegated authentication should be secured with TLS using Salesforce trusted certificates4. This ensures that the communication between Salesforce and the external authentication method is encrypted and authenticated. The other options are not relevant for designing a delegated authentication implementation. The web service does not need to accept one to four input method parameters, as it can accept any number of parameters as long as they are wrapped in a SOAP envelope5. The web service does not need to use the Salesforce Federation ID to identify the user, as it can use any identifier that is unique and consistent across systems6. The web service does not need to implement a custom password decryption method, as it can use any encryption or hashing algorithm that is supported by both systems7. References: Delegated Authentication, Enable 'Delegated Authentication', Delegated Authentication Flow in Salesforce, FAQs for Delegated Authentication


NEW QUESTION # 92
Universal Containers (UC) has implemented SAML-based SSO solution for use with their multi-org Salesforce implementation, utilizing one of the the orgs as the Identity Provider. One user is reporting that they can log in to the Identity Provider org but get a generic SAML error message when accessing the other orgs. Which two considerations should the architect review to troubleshoot the issue? Choose 2 answers

  • A. The Federation ID must is case sensitive
  • B. The Federation ID must be populated on the user record.
  • C. The Federation ID must be a valid Salesforce Username
  • D. The Federation ID must be in the form of an email address.

Answer: A,B


NEW QUESTION # 93
What are three capabilities of Delegated Authentication? Choose 3 answers

  • A. It can be assigned by Permission Sets.
  • B. It can connect to REST services.
  • C. It can be assigned by Custom Permissions.
  • D. It can connect to SOAP services.
  • E. It can be assigned by Profiles.

Answer: A,B,D


NEW QUESTION # 94
Northern Trail Outfitters manages application functional permissions centrally as Active Directory groups.
The CRM_Superllser and CRM_Reportmg_SuperUser groups should respectively give the user the SuperUser and Reportmg_SuperUser permission set in Salesforce. Salesforce is the service provider to a Security Assertion Markup Language (SAML) identity provider.
Mow should an identity architect ensure the Active Directory groups are reflected correctly when a user accesses Salesforce?

  • A. Use the Apex Just-in-Time handler to query standard SAML attributes and set permission sets.
  • B. Use a login flow to query standard SAML attributes and set permission sets.
  • C. Use the Apex Just-in-Time handler to query custom SAML attributes and set permission sets.
  • D. Use a login flow to query custom SAML attributes and set permission sets.

Answer: C

Explanation:
Explanation
Using the Apex Just-in-Time handler to query custom SAML attributes and set permission sets is the best way to ensure that the Active Directory groups are reflected correctly when a user accesses Salesforce. The Apex Just-in-Time handler is a custom class that can process the SAML response from the identity provider and assign permission sets based on the user's AD groups. The other options are either not feasible or not effective for this use case. References: Just-in-Time Provisioning for SAML, Apex Just-in-Time Handler


NEW QUESTION # 95
An administrator created a connected app for a custom wet) application in Salesforce which needs to be visible as a tile in App Launcher The tile for the custom web application is missing in the app launcher for all users in Salesforce. The administrator requested assistance from an identity architect to resolve the issue.
Which two reasons are the source of the issue?
Choose 2 answers

  • A. Session Policy is set as 'High Assurance Session required' for this connected app.
  • B. The connected app is not set in the App menu as 'Visible in App Launcher".
  • C. StartURL for the connected app is not set in Connected App settings.
  • D. OAuth scope does not include "openid".

Answer: B,C

Explanation:
Explanation
The StartURL for the connected app is required to specify the landing page for the app. The connected app must also be set as visible in the App Launcher to appear as a tile for users. References: Connected App Basics, Manage Connected Apps


NEW QUESTION # 96
Universal containers (UC) wants to integrate a Web application with salesforce. The UC team has implemented the Oauth web-server Authentication flow for authentication process. Which two considerations should an architect point out to UC? Choose 2 answers

  • A. The flow involves passing the user credentials back and forth.
  • B. The flow will not provide an Oauth refresh token back to the server.
  • C. The web server must be able to protect consumer privacy
  • D. The web application should be hosted on a secure server.

Answer: C,D


NEW QUESTION # 97
Universal Containers (UC) is building an authenticated Customer Community for its customers. UC does not want customer credentials stored in Salesforce and is confident its customers would be willing to use their social media credentials to authenticate to the community. Which two actions should an Architect recommend UC to take?

  • A. Create a Custom Apex Registration Handler to handle new and existing users.
  • B. Use Delegated Authentication to call the Twitter login API to authenticate users.
  • C. Configure an Authentication Provider for LinkedIn Social Media Accounts.
  • D. Configure SSO Settings For Facebook to serve as a SAML Identity Provider.

Answer: A,C


NEW QUESTION # 98
Which two roles of the systems are involved in an environment where salesforce users are enabled to access Google Apps from within salesforce through App launcher and connected App set up? Choose 2 answers

  • A. Salesforce is the identity provider
  • B. Google is the identity provider
  • C. Google is the service provider
  • D. Salesforce is the service provider

Answer: A,C

Explanation:
Explanation
In an environment where Salesforce users are enabled to access Google Apps from within Salesforce through App Launcher and Connected App setup, Google is the service provider and Salesforce is the identity provider. A service provider is an application that provides a service to users and relies on an identity provider for authentication3. A connected app is a service provider that integrates an application with Salesforce using APIs4. An identity provider is an application that authenticates users and provides information about them to service providers3. The App Launcher is a feature that allows users to access Salesforce, connected, and on-premises apps from one location5. In this scenario, Google Apps are connected apps that provide services to Salesforce users, such as Gmail, Google Drive, and Google Calendar. Salesforce is the identity provider that authenticates users and allows them to access Google Apps with their Salesforce credentials using single sign-on (SSO)6.
References: Identity Provider Overview, Connected Apps Overview, App Launcher, Single Sign-On for Desktop and Mobile Applications using SAML and OAuth


NEW QUESTION # 99
Universal Containers (UC) currently uses Salesforce Sales Cloud and an external billing application. Both Salesforce and the billing application are accessed several times a day to manage customers. UC would like to configure single sign-on and leverage Salesforce as the identity provider. Additionally, UC would like the billing application to be accessible from Salesforce. A redirect is acceptable.
Which two Salesforce tools should an identity architect recommend to satisfy the requirements?
Choose 2 answers

  • A. Identity Connect
  • B. salesforce Canvas
  • C. Connected Apps
  • D. App Launcher

Answer: B,D


NEW QUESTION # 100
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to SSO set up My Domain for their Salesforce org.
How does that decision impact their SSO implementation?

  • A. SP-initiated SSO will NOT work
  • B. Neither SP- nor IdP-initiated SSO will work.
  • C. Either SP- or IdP-initiated SSO will work.
  • D. IdP-initiated SSO will NOT work.

Answer: A

Explanation:
Explanation
This is because without My Domain, Salesforce will not know in advance what Identity Provider (IdP) to use for SSO, since it does not even know yet what Organization the user is trying to log in to1. SP-initiated SSO is the scenario where the user starts with a Salesforce link (login page, deep link, Outlook Sync URL, etc.) and then gets redirected to the IdP for authentication2. Without My Domain, SP-initiated SSO requires that the user do an IdP-initiated SSO at least once first so that Salesforce can set a cookie in their browser identifying the IdP1. The other options are not correct for this question because:
IdP-initiated SSO will work without My Domain, as long as the user starts SSO at the IdP and sends the identity information to Salesforce along with SAML protocol information that identifies the Organization and the IdP2.
Neither SP- nor IdP-initiated SSO will not work is false, as explained above.
Either SP- or IdP-initiated SSO will work is false, as explained above.
References: Considerations for setting up My Domain and SSO - Salesforce, SAML SSO with Salesforce as the Service Provider


NEW QUESTION # 101
Universal Containers (UC) uses Active Directory (AD) as their identity store for employees and must continue to do so for network access. UC is undergoing a major transformation program and moving all of their enterprise applications to cloud platforms including Salesforct, Workday, and SAP HANA. UC needs to implement an SSO solution for accessing all of the third-party cloud applications and the CIO is inclined to use Salesforce for all of their identity and access management needs.
Which two Salesforce license types does UC need for its employees'
Choose 2 answers

  • A. Chatter Only and Identity licenses
  • B. Identity and Identity Connect licenses
  • C. Company Community and Identity licenses
  • D. Salesforce and Identity Connect licenses

Answer: B,D


NEW QUESTION # 102
......


Salesforce Certified Identity and Access Management Architect certification exam covers a wide range of topics including identity and access management concepts, Salesforce security architecture, user management, authentication and authorization, external identity providers, and more. Identity-and-Access-Management-Architect exam is designed to test the candidate's knowledge and understanding of these topics and their ability to apply them in real-world scenarios.

 

Ace Identity-and-Access-Management-Architect Certification with 245 Actual Questions: https://www.actualpdf.com/Identity-and-Access-Management-Architect_exam-dumps.html

PASS Salesforce Identity-and-Access-Management-Architect EXAM WITH UPDATED DUMPS: https://drive.google.com/open?id=15Q2shiegXNt9v63xP2Ntek7dMuUjfLo8