IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER Exam Details

  • Exam Code
    :IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER
  • Exam Name
    :Salesforce Certified Platform Identity and Access Management Designer
  • Certification
    :Salesforce Certifications
  • Vendor
    :Salesforce
  • Total Questions
    :234 Q&As
  • Last Updated
    :Jan 07, 2025

Salesforce IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER Online Questions & Answers

  • Question 131:

    Universal Containers (UC) built an integration for their employees to post, view, and vote for ideas in Salesforce from an internal Company portal. When ideas are posted in Salesforce, links to the ideas are created in the company portal pages as part of the integration process. The Company portal connects to Salesforce using OAuth. Everything is working fine, except when users click on links to existing ideas, they are always taken to the Ideas home page rather than the specific idea, after authorization. Which OAuth URL parameter can be used to retain the original requested page so that a user can be redirected correctly after OAuth authorization?

    A. Redirect_uri
    B. State
    C. Scope
    D. Callback_uri

  • Question 132:

    Universal containers wants to implement SAML SSO for their internal salesforce users using a third-party IDP. After some evaluation, UC decides not to set up my domain for their salesforce.org. How does that decision impact their SSO implementation?

    A. Neithersp - nor IDP - initiated SSO will work
    B. Either sp - or IDP - initiated SSO will work
    C. IDP - initiated SSO will not work
    D. Sp-Initiated SSO will not work

  • Question 133:

    Universal Containers (UC) has an Experience Cloud site (Customer Community) where customers can authenticate and place orders, view the status of orders, etc. UC allows guest checkout.

    Mow can a guest register using data previously collected during order placement?

    A. Enable Security Assertion Markup Language Sign-On and use a login flow to collect only order details to retrieve customer data.
    B. Enable Facebook as an authentication provider and use a registration handler to collect only order details to retrieve customer data.
    C. Use a Connected App Handler Apex Plugin class to collect only order details to retrieve customer data.
    D. Enable self-registration and customize a self-registration page to collect only order details to retrieve customer data.

  • Question 134:

    What is one of the roles of an Identity Provider in a Single Sign-on setup using SAML?

    A. Validate token
    B. Create token
    C. Consume token
    D. Revoke token

  • Question 135:

    Which two roles of the systems are involved in an environment where salesforce users are enabled to access Google Apps from within salesforce through App launcher and connected App set up? Choose 2 answers

    A. Google is the identity provider
    B. Salesforce is the identity provider
    C. Google is the service provider
    D. Salesforce is the service provider

  • Question 136:

    A Salesforce customer is implementing Sales Cloud and a custom pricing application for its call center agents. An Enterprise single sign-on solution is used to authenticate and sign-in users to all applications. The customer has the following requirements:

    1.

    The development team has decided to use a Canvas app to expose the pricing application to agents.

    2.

    Agents should be able to access the Canvas app without needing to log in to the pricing application.

    Which two options should the identity architect consider to provide support for the Canvas app to initiate login for users?

    Choose 2 answers

    A. Select "Enable as a Canvas Personal App" in the connected app settings.
    B. Enable OAuth settings in the connected app with required OAuth scopes for the pricing application.
    C. Configure the Canvas app as a connected app and set Admin-approved users as pre- authorized.
    D. Enable SAML in the connected app and Security Assertion Markup Language (SAML) Initiation Method as Service Provider Initiated.

  • Question 137:

    Universal containers (UC) has implemented SAML -based single Sign-on for their salesforce application. UC is using pingfederate as the Identity provider. To access salesforce, Users usually navigate to a bookmarked link to my domain URL. What type of single Sign-on is this?

    A. Sp-Initiated
    B. IDP-initiated with deep linking
    C. IDP-initiated
    D. Web server flow.

  • Question 138:

    Northern Trail Outfitters (NTO) is planning to build a new customer service portal and wants to use passwordless login, allowing customers to login with a one-time passcode sent to them via email or SMS.

    How should the quantity of required Identity Verification Credits be estimated?

    A. Each community comes with 10,000 Identity Verification Credits per month and only customers with more than 10,000 logins a month should estimate additional SMS verifications needed.
    B. Identity Verification Credits are consumed with each SMS (text message) sent and should be estimated based on the number of login verification challenges for SMS verification users.
    C. Identity Verification Credits are consumed with each verification sent and should be estimated based on the number of logins that will incur a verification challenge.
    D. Identity Verification Credits are a direct add-on license based on the number of existing member-based or login-based Community licenses.

  • Question 139:

    How should an identity architect automate provisioning and deprovisioning of users into Salesforce from an external system?

    A. Call SOAP API upsertQ on user object.
    B. Use Security Assertion Markup Language Just-in-Time (SAML JIT) on incoming SAML assertions.
    C. Run registration handler on incoming OAuth responses.
    D. Call OpenID Connect (OIDC)-userinfo endpoint with a valid access token.

  • Question 140:

    Which three types of attacks would a 2-Factor Authentication solution help garden against?

    A. Key logging attacks
    B. Network perimeter attacks
    C. Phishing attacks
    D. Dictionary attacks
    E. Man-in-the-middle attacks

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Salesforce exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER exam preparations and Salesforce certification application, do not hesitate to visit our Vcedump.com to find your solutions here.