IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER Exam Details

  • Exam Code
    :IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER
  • Exam Name
    :Salesforce Certified Platform Identity and Access Management Designer
  • Certification
    :Salesforce Certifications
  • Vendor
    :Salesforce
  • Total Questions
    :234 Q&As
  • Last Updated
    :Jan 07, 2025

Salesforce IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER Online Questions & Answers

  • Question 161:

    Universal containers (UC) is building a mobile application that will make calls to the salesforce REST API. Additionally UC would like to provide the optimal experience for its mobile users. Which two OAuth scopes should UC configure in the connected App? Choose 2 answers

    A. Refresh token
    B. API
    C. full
    D. Web

  • Question 162:

    Which three are features of federated Single sign-on solutions? Choose 3 Answers

    A. It establishes trust between Identity Store and Service Provider.
    B. It federates credentials control to authorized applications.
    C. It solves all identity and access management problems.
    D. It improves affiliated applications adoption rates.
    E. It enables quick and easy provisioning and deactivating of users.

  • Question 163:

    An architect needs to advise the team that manages the identity provider how to differentiate salesforce from other service providers. What SAML SSO setting in salesforce provides this capability?

    A. Entity id
    B. Issuer
    C. Identity provider login URL
    D. SAML identity location

  • Question 164:

    Universal Containers (UC) is building an authenticated Customer Community for its customers. UC does not want customer credentials stored in Salesforce and is confident its customers would be willing to use their social media credentials to authenticate to the community. Which two actions should an Architect recommend UC to take?

    A. Use Delegated Authentication to call the Twitter login API to authenticate users.
    B. Configure an Authentication Provider for LinkedIn Social Media Accounts.
    C. Create a Custom Apex Registration Handler to handle new and existing users.
    D. Configure SSO Settings For Facebook to serve as a SAML Identity Provider.

  • Question 165:

    Universal Containers (UC) has a Customer Community that uses Facebook for Authentication. UC would like to ensure that Changes in the Facebook profile are reflected on the appropriate Customer Community user: How can this requirement be met?

    A. Use the updateUser method on the registration Handler Class.
    B. Develop a scheduled job that calls out to Facebook on a nightly basis.
    C. Use information in the signed Request that is received from facebook.
    D. Use SAML Just-In-Time Provisioning between Facebook and Salesforce.

  • Question 166:

    Universal Containers (UC) is using a custom application that will act as the Identity Provider and will generate SAML assertions used to log in to Salesforce. UC is considering including custom parameters in the SAML assertion. These attributes contain sensitive data and are needed to authenticate the users. The assertions are submitted to salesforce via a browser form post. The majority of the users will only be able to access Salesforce via UC's corporate network, but a subset of admins and executives would be allowed access from outside the corporate network on their mobile devices. Which two methods should an Architect consider to ensure that the sensitive data cannot be tampered with, nor accessible to anyone while in transit?

    A. Use the Identity Provider's certificate to digitally sign and Salesforce's Certificate to encrypt the payload.
    B. Use Salesforce's Certificate to digitally sign the SAML Assertion and a Mobile Device Management client on the users' mobile devices.
    C. Use the Identity provider's certificate to digitally Sign and the Identity provider's certificate to encrypt the payload.
    D. Use a custom login flow to retrieve sensitive data using an Apex callout without including the attributes in the assertion.

  • Question 167:

    Universal Containers (UC) has Active Directory (AD) as their enterprise identity store and would like to use it for Salesforce user authentication. UC expects to synchronize user data between Salesforce and AD and Assign the appropriate Profile and Permission Sets based on AD group membership. What would be the optimal way to implement SSO?

    A. Use Active Directory with Reverse Proxy as the Identity Provider.
    B. Use Microsoft Access control Service as the Authentication provider.
    C. Use Active Directory Federation Service (ADFS) as the Identity Provider.
    D. Use Salesforce Identity Connect as the Identity Provider.

  • Question 168:

    A global company has built an external application that uses data from its Salesforce org via an OAuth 2.0 authorization flow. Upon logout, the existing Salesforce OAuth token must be invalidated.

    Which action will accomplish this?

    A. Use a HTTP POST to request the refresh token for the current user.
    B. Use a HTTP POST to the System for Cross-domain Identity Management (SCIM) endpoint, including the current OAuth token.
    C. Use a HTTP POST to make a call to the revoke token endpoint.
    D. Enable Single Logout with a secure logout URL.

  • Question 169:

    Universal Containers (UC) is building a customer community and will allow customers to authenticate using Facebook credentials. The First time the user authenticating using facebook, UC would like a customer account created automatically in their Accounting system. The accounting system has a web service accessible to Salesforce for the creation of accounts. How can the Architect meet these requirements?

    A. Create a custom application on Heroku that manages the sign-on process from Facebook.
    B. Use JIT Provisioning to automatically create the account in the accounting system.
    C. Add an Apex callout in the registration handler of the authorization provider.
    D. Use OAuth JWT flow to pass the data from Salesforce to the Accounting System.

  • Question 170:

    Universal containers (UC) has a mobile application that calls the salesforce REST API. In order to prevent users from having to enter their credentials everytime they use the app, UC has enabled the use of refresh Tokens as part of the salesforce connected App and updated their mobile app to take advantage of the refresh token. Even after enabling the refresh token, Users are still complaining that they have to enter their credentials once a day. What is the most likely cause of the issue?

    A. The Oauth authorizations are being revoked by a nightly batch job.
    B. The refresh token expiration policy is set incorrectly in salesforce
    C. The app is requesting too many access Tokens in a 24-hour period
    D. The users forget to check the box to remember their credentials.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Salesforce exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER exam preparations and Salesforce certification application, do not hesitate to visit our Vcedump.com to find your solutions here.