Labour Day Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

Salesforce Certified Identity and Access Management Architect (SP23) Question and Answers

Salesforce Certified Identity and Access Management Architect (SP23)

Last Update Apr 24, 2024
Total Questions : 245

We are offering FREE Identity-and-Access-Management-Architect Salesforce exam questions. All you do is to just go and sign up. Give your details, prepare Identity-and-Access-Management-Architect free exam questions and then go for complete pool of Salesforce Certified Identity and Access Management Architect (SP23) test questions that will help you more.

Identity-and-Access-Management-Architect pdf

Identity-and-Access-Management-Architect PDF

$35  $99.99
Identity-and-Access-Management-Architect Engine

Identity-and-Access-Management-Architect Testing Engine

$42  $119.99
Identity-and-Access-Management-Architect PDF + Engine

Identity-and-Access-Management-Architect PDF + Testing Engine

$56  $159.99
Questions 1

Universal containers (UC) has multiple salesforce orgs and would like to use a single identity provider to access all of their orgs. How should UC'S architect enable this behavior?

Options:

A.  

Ensure that users have the same email value in their user records in all of UC's salesforce orgs.

B.  

Ensure the same username is allowed in multiple orgs by contacting salesforce support.

C.  

Ensure that users have the same Federation ID value in their user records in all of UC's salesforce orgs.

D.  

Ensure that users have the same alias value in their user records in all of UC's salesforce orgs.

Discussion 0
Questions 2

Universal containers (UC) is successfully using Delegated Authentication for their salesforce users. The service supporting Delegated Authentication is written in Java. UC has a new CIO that is requiring all company Web services be RESR-ful and written in . NET. Which two considerations should the UC Architect provide to the new CIO? Choose 2 answers

Options:

A.  

Delegated Authentication will not work with a.net service.

B.  

Delegated Authentication will continue to work with rest services.

C.  

Delegated Authentication will continue to work with a.net service.

D.  

Delegated Authentication will not work with rest services.

Discussion 0
Questions 3

Universal Containers (UC) wants to provide single sign-on (SSO) for a business-to-consumer (B2C) application using Salesforce Identity.

Which Salesforce license should UC utilize to implement this use case?

Options:

A.  

Identity Only

B.  

Salesforce Platform

C.  

External Identity

D.  

Partner Community

Discussion 0
Questions 4

Universal Container's (UC) is using Salesforce Experience Cloud site for its container wholesale business. The identity architect wants to an authentication provider for the new site.

Which two options should be utilized in creating an authentication provider?

Choose 2 answers

Options:

A.  

A custom registration handier can be set.

B.  

A custom error URL can be set.

C.  

The default login user can be set.

D.  

The default authentication provider certificate can be set.

Discussion 0
Questions 5

An Architect needs to advise the team that manages the Identity Provider how to differentiate Salesforce from other Service Providers. What SAML SSO setting in Salesforce provides this capability?

Options:

A.  

Identity Provider Login URL.

B.  

Issuer.

C.  

Entity Id

D.  

SAML Identity Location.

Discussion 0
Questions 6

Northern Trail Outfitters manages application functional permissions centrally as Active Directory groups. The CRM_Superllser and CRM_Reportmg_SuperUser groups should respectively give the user the SuperUser and Reportmg_SuperUser permission set in Salesforce. Salesforce is the service provider to a Security Assertion Markup Language (SAML) identity provider.

Mow should an identity architect ensure the Active Directory groups are reflected correctly when a user accesses Salesforce?

Options:

A.  

Use the Apex Just-in-Time handler to query standard SAML attributes and set permission sets.

B.  

Use the Apex Just-in-Time handler to query custom SAML attributes and set permission sets.

C.  

Use a login flow to query custom SAML attributes and set permission sets.

D.  

Use a login flow to query standard SAML attributes and set permission sets.

Discussion 0
Questions 7

Northern Trail Outfitters want to allow its consumer to self-register on it business-to-consumer (B2C) portal that is built on Experience Cloud. The identity architect has recommended to use Person Accounts.

Which three steps need to be configured to enable self-registration using person accounts?

Choose 3 answers

Options:

A.  

Enable access to person and business account record types under Public Access Settings.

B.  

Contact Salesforce Support to enable business accounts.

C.  

Under Login and Registration settings, ensure that the default account field is empty.

D.  

Contact Salesforce Support to enable person accounts.

E.  

Set organization-wide default sharing for Contact to Public Read Only.

Discussion 0
Questions 8

Universal containers (UC) has built a custom based Two-factor Authentication (2fa) system for their existing on-premise applications. Thru are now implementing salesforce and would like to enable a Two-factor login process for it, as well. What is the recommended solution an architect should consider?

Options:

A.  

Replace the custom 2fa system with salesforce 2fa for on-premise application and salesforce.

B.  

Use the custom 2fa system for on-premise applications and native 2fa for salesforce.

C.  

Replace the custom 2fa system with an app exchange app that supports on-premise applications and salesforce.

D.  

Use custom login flows to connect to the existing custom 2fa system for use in salesforce.

Discussion 0
Questions 9

Universal containers uses an Employee portal for their employees to collaborate. employees access the portal from their company's internal website via SSO. It is set up to work with Active Directory. What is the role of Active Directory in this scenario?

Options:

A.  

Identity store

B.  

Authentication store

C.  

Identity provider

D.  

Service provider

Discussion 0
Questions 10

Which two things should be done to ensure end users can only use single sign-on (SSO) to login in to Salesforce?

Choose 2 answers

Options:

A.  

Enable My Domain and select "Prevent login from https://login.salesforce.com ".

B.  

Request Salesforce Support to enable delegated authentication.

C.  

Once SSO is enabled, users are only able to login using Salesforce credentials.

D.  

Assign user "is Single Sign-on Enabled" permission via profile or permission set.

Discussion 0
Questions 11

A group of users try to access one of Universal Containers' Connected Apps and receive the following error message: " Failed: Not approved for access." What is the most likely cause of this issue?

Options:

A.  

The Connected App settings "All users may self-authorize" is enabled.

B.  

The Salesforce Administrators have revoked the OAuth authorization.

C.  

The Users do not have the correct permission set assigned to them.

D.  

The User of High Assurance sessions are required for the Connected App.

Discussion 0
Questions 12

A university is planning to set up an identity solution for its alumni. A third-party identity provider will be used for single sign-on Salesforce will be the system of records. Users are getting error messages when logging in.

Which Salesforce feature should be used to debug the issue?

Options:

A.  

Apex Exception Email

B.  

View Setup Audit Trail

C.  

Debug Logs

D.  

Login History

Discussion 0
Questions 13

Universal containers (UC) does my domain enable in the context of a SAML SSO configuration? Choose 2 answers

Options:

A.  

Resource deep linking

B.  

App launcher

C.  

SSO from salesforce1 mobile app.

D.  

Login forensics

Discussion 0
Questions 14

Universal containers (UC) would like to enable SSO between their existing Active Directory infrastructure and salesforce. The it team prefers to manage all users in Active Directory and would like to avoid doing any initial setup of users in salesforce directly, including the correct assignment of profiles, roles and groups. Which two optimal solutions should UC use to provision users in salesforce? Choose 2 answers

Options:

A.  

Use the salesforce REST API to sync users from active directory to salesforce

B.  

Use an app exchange product to sync users from Active Directory to salesforce.

C.  

Use Active Directory Federation Services to sync users from active directory to salesforce.

D.  

Use Identity connect to sync users from Active Directory to salesforce

Discussion 0
Questions 15

An identity architect's client has a homegrown identity provider (IdP). Salesforce is used as the service provider (SP). The head of IT is worried that during a SP initiated single sign-on (SSO), the Security Assertion Markup Language (SAML) request content will be altered.

What should the identity architect recommend to make sure that there is additional trust between the SP and the IdP?

Options:

A.  

Ensure that there is an HTTPS connection between IDP and SP.

B.  

Ensure that on the SSO settings page, the "Request Signing Certificate" field has a self-signed certificate.

C.  

Ensure that the Issuer and Assertion Consumer service (ACS) URL is property configured between SP and IDP.

D.  

Encrypt the SAML Request using certification authority (CA) signed certificate and decrypt on IdP.

Discussion 0
Questions 16

architect is troubleshooting some SAML-based SSO errors during testing. The Architect confirmed that all of the Salesforce SSO settings are correct. Which two issues outside of the Salesforce SSO settings are most likely contributing to the SSO errors the Architect is encountering? Choose 2 Answers

Options:

A.  

The Identity Provider is also used to SSO into five other applications.

B.  

The clock on the Identity Provider server is twenty minutes behind Salesforce.

C.  

The Issuer Certificate from the Identity Provider expired two weeks ago.

D.  

The default language for the Identity Provider and Salesforce are Different.

Discussion 0
Questions 17

Universal Containers (UC) has implemented SAML-based Single Sign-On to provide seamless access to its Salesforce Orgs, financial system, and CPQ system. Below is the SSO implementation landscape.

What role combination is represented by the systems in this scenario''

Options:

A.  

Financial System and CPQ System are the only Service Providers.

B.  

Salesforce Org1 and Salesforce Org2 are the only Service Providers.

C.  

Salesforce Org1 and Salesforce Org2 are acting as Identity Providers.

D.  

Salesforce Org1 and PingFederate are acting as Identity Providers.

Discussion 0
Questions 18

Universal containers (UC) has a mobile application that it wants to deploy to all of its salesforce users, including customer Community users. UC would like to minimize the administration overhead, which two items should an architect recommend? Choose 2 answers

Options:

A.  

Enable the "Refresh Tokens is valid until revoked " setting in the Connected App.

B.  

Enable the "Enforce Ip restrictions" settings in the connected App.

C.  

Enable the "All users may self-authorize" setting in the Connected App.

D.  

Enable the "High Assurance session required" setting in the Connected App.

Discussion 0
Questions 19

Universal Containers wants to allow its customers to log in to its Experience Cloud via a third party authentication provider that supports only the OAuth protocol.

What should an identity architect do to fulfill this requirement?

Options:

A.  

Contact Salesforce Support and enable delegate single sign-on.

B.  

Create a custom external authentication provider.

C.  

Use certificate-based authentication.

D.  

Configure OpenID Connect authentication provider.

Discussion 0
Questions 20

Universal Containers (UC) has five Salesforce orgs (UC1, UC2, UC3, UC4, UC5). of Every user that is in UC2, UC3, UC4, and UC5 is also in UC1, however not all users 65* have access to every org. Universal Containers would like to simplify the authentication process such that all Salesforce users need to remember one set of credentials. UC would like to achieve this with the least impact to cost and maintenance. What approach should an Architect recommend to UC?

Options:

A.  

Purchase a third-party Identity Provider for all five Salesforce orgs to use and set up JIT user provisioning on all other orgs.

B.  

Purchase a third-party Identity Provider for all five Salesforce orgs to use, but don't set up JIT user provisioning for other orgs.

C.  

Configure UC1 as the Identity Provider to the other four Salesforce orgs and set up JIT user provisioning on all other orgs.

D.  

Configure UC1 as the Identity Provider to the other four Salesforce orgs, but don't set up JIT user provisioning for other orgs.

Discussion 0
Questions 21

A multinational industrial products manufacturer is planning to implement Salesforce CRM to manage their business. They have the following requirements:

1. They plan to implement Partner communities to provide access to their partner network .

2. They have operations in multiple countries and are planning to implement multiple Salesforce orgs.

3. Some of their partners do business in multiple countries and will need information from multiple Salesforce communities.

4. They would like to provide a single login for their partners.

How should an Identity Architect solution this requirement with limited custom development?

Options:

A.  

Create a partner login for the country of their operation and use SAML federation to provide access to other orgs.

B.  

Consolidate Partner related information in a single org and provide access through Salesforce community.

C.  

Allow partners to choose the Salesforce org they need information from and use login flows to authenticate access.

D.  

Register partners in one org and access information from other orgs using APIs.

Discussion 0
Questions 22

Northern Trail Outfitters recently acquired a company. Each company will retain its Identity Provider (IdP). Both companies rely extensively on Salesforce processes that send emails to users to take specific actions in Salesforce.

How should the combined companys' employees collaborate in a single Salesforce org, yet authenticate to the appropriate IdP?

Options:

A.  

Configure unique MyDomains for each company and have generated links use the appropriate MyDomam in the URL.

B.  

Have generated links append a querystnng parameter indicating the IdP. The login service will redirect to the appropriate IdP.

C.  

Have generated links be prefixed with the appropriate IdP URL to invoke an IdP-initiated Security Assertion Markup Language flow when clicked.

D.  

Enable each IdP as a login option in the MyDomain Authentication Service settings. Users will then click on the appropriate IdP button.

Discussion 0
Questions 23

Universal Containers (UC) has Active Directory (AD) as their enterprise identity store and would like to use it for Salesforce user authentication. UC expects to synchronize user data between Salesforce and AD and Assign the appropriate Profile and Permission Sets based on AD group membership. What would be the optimal way to implement SSO?

Options:

A.  

Use Active Directory with Reverse Proxy as the Identity Provider.

B.  

Use Microsoft Access control Service as the Authentication provider.

C.  

Use Active Directory Federation Service (ADFS) as the Identity Provider.

D.  

Use Salesforce Identity Connect as the Identity Provider.

Discussion 0
Questions 24

Universal containers wants salesforce inbound Oauth-enabled integration clients to use SAML-BASED single Sign-on for authentication. What Oauth flow would be recommended in this scenario?

Options:

A.  

User-Agent Oauth flow

B.  

SAML assertion Oauth flow

C.  

User-Token Oauth flow

D.  

Web server Oauth flow

Discussion 0
Questions 25

Northern Trail Outfitters (NTO) is launching a new sportswear brand on its existing consumer portal built on Salesforce Experience Cloud. As part of the launch, emails with promotional links will be sent to existing customers to log in and claim a discount. The marketing manager would like the portal dynamically branded so that users will be directed to the brand link they clicked on; otherwise, users will view a recognizable NTO-branded page.

The campaign is launching quickly, so there is no time to procure any additional licenses. However, the development team is available to apply any required changes to the portal.

Which approach should the identity architect recommend?

Options:

A.  

Create a full sandbox to replicate the portal site and update the branding accordingly.

B.  

Implement Experience ID in the code and extend the URLs and endpomts, as required.

C.  

Use Heroku to build the new brand site and embedded login to reuse identities.

D.  

Configure an additional community site on the same org that is dedicated for the new brand.

Discussion 0
Questions 26

A financial services company uses Salesforce and has a compliance requirement to track information about devices from which users log in. Also, a Salesforce Security Administrator needs to have the ability to revoke the device from which users log in.

What should be used to fulfill this requirement?

Options:

A.  

Use multi-factor authentication (MFA) to meet the compliance requirement to track device information.

B.  

Use the Activations feature to meet the compliance requirement to track device information.

C.  

Use the Login History object to track information about devices from which users log in.

D.  

Use Login Flows to capture device from which users log in and store device and user information in a custom object.

Discussion 0
Questions 27

Universal Containers (UC) is building an authenticated Customer Community for its customers. UC does not want customer credentials stored in Salesforce and is confident its customers would be willing to use their social media credentials to authenticate to the community. Which two actions should an Architect recommend UC to take?

Options:

A.  

Use Delegated Authentication to call the Twitter login API to authenticate users.

B.  

Configure an Authentication Provider for LinkedIn Social Media Accounts.

C.  

Create a Custom Apex Registration Handler to handle new and existing users.

D.  

Configure SSO Settings For Facebook to serve as a SAML Identity Provider.

Discussion 0
Questions 28

Northern Trail Outfitters (NTO) has an off-boarding process where a terminated employee is first disabled in the Lightweight Directory Act Protocol (LDAP) directory, then requests are sent to the various application support teams to finish user deactivations. A terminated employee recently was able to login to NTO's Salesforce instance 24 hours after termination, even though the user was disabled in the corporate LDAP directory.

What should an identity architect recommend to prevent this from happening in the future?

Options:

A.  

Create a Just-in-Time provisioning registration handler to ensure users are deactivated in Salesforce as they are disabled in LDAP.

B.  

Configure an authentication provider to delegate authentication to the LDAP directory.

C.  

use a login flow to make a callout to the LDAP directory before authenticating the user to Salesforce.

D.  

Setup an identity provider (IdP) to authenticate users using LDAP, set up single sign-on to Salesforce and disable Login Form authentication.

Discussion 0
Questions 29

Universal Containers is creating a web application that will be secured by Salesforce Identity using the OAuth 2.0 Web Server Flow uses the OAuth 2.0 authorization code grant type).

Which three OAuth concepts apply to this flow?

Choose 3 answers

Options:

A.  

Verification URL

B.  

Client Secret

C.  

Access Token

D.  

Scopes

Discussion 0
Questions 30

Containers (UC) uses a legacy Employee portal for their employees to collaborate. Employees access the portal from their company’s internal website via SSO. It is set up to work with SiteMinder and Active Directory. The Employee portal has features to support posing ideas. UC decides to use Salesforce Ideas for voting and better tracking purposes. To avoid provisioning users on Salesforce, UC decides to integrate Employee portal ideas with Salesforce idea through the API. What is the role of Salesforce in the context of SSO, based on this scenario?

Options:

A.  

Service Provider, because Salesforce is the application for managing ideas.

B.  

Connected App, because Salesforce is connected with Employee portal via API.

C.  

Identity Provider, because the API calls are authenticated by Salesforce.

D.  

An independent system, because Salesforce is not part of the SSO setup.

Discussion 0
Questions 31

Universal Containers (UC) uses Global Shipping (GS) as one of their shipping vendors. Regional leads of GS need access to UC's Salesforce instance for reporting damage of goods using Cases. The regional leads also need access to dashboards to keep track of regional shipping KPIs. UC internally uses a third-party cloud analytics tool for capacity planning and UC decided to provide access to this tool to a subset of GS employees. In addition to regional leads, the GS capacity planning team would benefit from access to this tool. To access the analytics tool, UC IT has set up Salesforce as the Identity provider for Internal users and would like to follow the same approach for the GS users as well. What are the most appropriate license types for GS Tregional Leads and the GS Capacity Planners? Choose 2 Answers

Options:

A.  

Customer Community Plus license for GS Regional Leads and External Identity for GS Capacity Planners.

B.  

Customer Community Plus license for GS Regional Leads and Customer Community license for GS Capacity Planners.

C.  

Identity Licence for GS Regional Leads and External Identity license for GS capacity Planners.

D.  

Customer Community license for GS Regional Leads and Identity license for GS Capacity Planners.

Discussion 0
Questions 32

An architect has successfully configured SAML-BASED SSO for universal containers. SSO has been working for 3 months when Universal containers manually adds a batch of new users to salesforce. The new users receive an error from salesforce when trying to use SSO. Existing users are still able to successfully use SSO to access salesforce. What is the probable cause of this behaviour?

Options:

A.  

The administrator forgot to reset the new user's salesforce password.

B.  

The Federation ID field on the new user records is not correctly set

C.  

The my domain capability is not enabled on the new user's profile.

D.  

The new users do not have the SSO permission enabled on their profiles.

Discussion 0
Questions 33

Northern Trail Outfitters (NTO) leverages Microsoft Active Directory (AD) for management of employee usernames, passwords, permissions, and asset access. NTO also owns a third-party single sign-on (SSO) solution. The third-party party SSO solution is used for all corporate applications, including Salesforce.

NTO has asked an architect to explore Salesforce Identity Connect for automatic provisioning and deprovisiorung of users in Salesforce.

What role does identity Connect play in the outlined requirements?

Options:

A.  

Service Provider

B.  

Single Sign-On

C.  

Identity Provider

D.  

User Management

Discussion 0
Questions 34

Universal containers (UC) has a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a connected App in salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properly secure access to the app. Which two are recommendations to make the UC? Choose 2 answers

Options:

A.  

Disallow the use of single Sign-on for any users of the mobile app.

B.  

Require high assurance sessions in order to use the connected App

C.  

Use Google Authenticator as an additional part of the logical processes.

D.  

Set login IP ranges to the internal network for all of the app users profiles.

Discussion 0
Questions 35

IT security at Unversal Containers (UC) us concerned about recent phishing scams targeting its users and wants to add additional layers of login protection. What should an Architect recommend to address the issue?

Options:

A.  

Use the Salesforce Authenticator mobile app with two-step verification

B.  

Lock sessions to the IP address from which they originated.

C.  

Increase Password complexity requirements in Salesforce.

D.  

Implement Single Sign-on using a corporate Identity store.

Discussion 0
Questions 36

Universal containers(UC) has implemented SAML-BASED single Sign-on for their salesforce application and is planning to provide access to salesforce on mobile devices using the salesforce1 mobile app. UC wants to ensure that single Sign-on is used for accessing the salesforce1 mobile app. Which two recommendations should the architect make? Choose 2 answers

Options:

A.  

Use the existing SAML SSO flow along with user agent flow.

B.  

Configure the embedded Web browser to use my domain URL.

C.  

Use the existing SAML SSO flow along with Web server flow

D.  

Configure the salesforce1 app to use the my domain URL

Discussion 0
Questions 37

Universal Containers (UC) has a classified information system that its call center team uses only when they are working on a case with a record type "Classified". They are only allowed to access the system when they own an open "Classified" case, and their access to the system is removed at all other times. They would like to implement SAML SSO eith Salesforce as the Idp, and automatically allow or deny the staff's access to the classified information system based on whether they currently own an open "Classified" case record when they try to access the system using SSO. What is the recommended solution for automatically allowing or denying the access to the classified information system based on the open "classified" case record criteria?

Options:

A.  

Use Salesforce reports to identify users that currently owns open "Classified" cases and should be granted access to the Classified information system.

B.  

Use Apex trigger on case to dynamically assign permission Sets that Grant access when an user is assigned with an open "Classified" case, and remove it when the case is closed.

C.  

Use Custom SAML JIT Provisioning to dynamically query the user's open "Classified" cases when attempting to access the classified information system.

D.  

Use a Common Connected App Handler using Apex to dynamically allow access to the system based on whether the staff owns any open "Classified" Cases.

Discussion 0