An identity professional, responsible for ensuring secure access to the Salesforce platform, needs to audit and verify user activity during and after login. They want to monitor login attempts, track user authentication methods, and identify suspicious behavior or unauthorized access. Which tool or feature should they leverage to achieve this objective?
-
A
Customer Account Processes
-
B
-
C
-
D
Salesforce Lightning Flow
Reveal answer details
Close answer details
A company with 15,000 employees is using Salesforce and would like to take the necessary steps to highlight or curb fraudulent activity. Which tool should be used to track login data, such as the average number of logins, who logged in more than the average number of times and who logged in during non-business hours?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 3
Multiple choice
Universal Containers uses Salesforce as an identity provider and Concur as the Employee Expense management system. The HR director wants to ensure Concur accounts for employees are created only after the appropnate approval in the Salesforce org. Which three steps should the identity architect use to implement this requirement? Choose 3 answers
-
A
Create an approval process for a custom object associated with the provisioning flow.
-
B
Create a connected app for Concur in Salesforce.
-
C
Enable User Provisioning for the connected app.
-
D
Create an approval process for user object associated with the provisioning flow.
-
E
Create an approval process for UserProvisionlngRequest object associated with the provisioning flow.
Reveal answer details
Close answer details
Question 4
Multiple choice
Universal Containers (UC) has an e-commerce website where customers can buy products, make payments and manage their accounts. UC decides to build a Customer Community on Salesforce and wants to allow the customers to access the community from their accounts without logging in again. UC decides to implement an SP-initiated SSO using a SAML-compliant Idp. In this scenario where Salesforce is the Service Provider, which two activities must be performed in Salesforce to make SP-initiated SSO work? Choose 2 answers
-
A
Configure SAML SSO settings.
-
B
-
C
Configure Delegated Authentication.
-
D
Reveal answer details
Close answer details
Universal containers (UC) has a mobile application that calls the salesforce REST API. In order to prevent users from having to enter their credentials everytime they use the app, UC has enabled the use of refresh Tokens as part of the salesforce connected App and updated their mobile app to take advantage of the refresh token. Even after enabling the refresh token, Users are still complaining that they have to enter their credentials once a day. What is the most likely cause of the issue?
-
A
The Oauth authorizations are being revoked by a nightly batch job.
-
B
The refresh token expiration policy is set incorrectly in salesforce
-
C
The app is requesting too many access Tokens in a 24-hour period
-
D
The users forget to check the box to remember their credentials.
Reveal answer details
Close answer details
A farming enterprise offers smart farming technology to its farmer customers, which includes a variety of sensors for livestock tracking, pest monitoring, climate monitoring etc. They plan to store all the data in Salesforce. They would also like to ensure timely maintenance of the Installed sensors. They have engaged a salesforce Architect to propose an appropriate way to generate sensor Information In Salesforce. Which OAuth flow should the architect recommend?
-
A
OAuth 2.0 Asset Token Flow
-
B
OAuth 2.0 Device Authentication Row
-
C
OAuth 2.0 JWT Bearer Token Flow
-
D
OAuth 2.0 SAML Bearer Assertion Flow
Reveal answer details
Close answer details
Question 7
Multiple choice
Universal Containers is creating a web application that will be secured by Salesforce Identity using the OAuth 2.0 Web Server Flow (this flow uses the OAuth 2.0 authorization code grant type). Which three OAuth concepts apply to this flow? Choose 3 answers
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Universal Containers (UC) wants its closed Won opportunities to be synced to a Data warehouse in near real time. UC has implemented Outbound Message to enable near real-time data sync. UC wants to ensure that communication between Salesforce and Target System is secure. What certificate is sent along with the Outbound Message?
-
A
The Self-signed Certificates from the Certificate & Key Management menu.
-
B
The default client Certificate from the Develop--> API menu.
-
C
The default client Certificate or the Certificate and Key Management menu.
-
D
The CA-signed Certificate from the Certificate and Key Management Menu.
Reveal answer details
Close answer details
Question 9
Multiple choice
Universal Containers (UC) is considering a Customer 360 initiative to gain a single source of the truth for its customer data across disparate systems and services. UC wants to understand the primary benefits of Customer 360 Identity and how it contributes ato successful Customer 360 Truth project. What are two are key benefits of Customer 360 Identity as it relates to Customer 360? Choose 2 answers
-
A
Customer 360 Identity automatically integrates with Customer 360 Data Manager and Customer 360 Audiences to seamlessly populate all user data.
-
B
Customer 360 Identity enables an organization to build a single login for each of its customers, giving the organization an understanding of the user's login activity across all its digital properties and applications.
-
C
Customer 360 Identity supports multiple brands so you can deliver centralized identity services and correlation of user activity, even if it spans multiple corporate brands and user experiences.
-
D
Customer 360 Identity not only provides a unified sign up and sign in experience, but also tracks anonymous user activity prior to signing up so organizations can understand user activity before and after the users identify themselves.
Reveal answer details
Close answer details
Question 10
Single choice
Northern Trail Outfitters (NTO) believes a specific user account may have been compromised. NTO inactivated the user account and needs U perform a forensic analysis and identify signals that could Indicate a breach has occurred. What should NTO's first step be in gathering signals that could indicate account compromise?
-
A
Review the User record and evaluate the login and transaction history.
-
B
Download the Setup Audit Trail and review all recent activities performed by the user.
-
C
Download the Identity Provider Event Log and evaluate the details of activities performed by the user.
-
D
Download the Login History and evaluate the details of logins performed by the user.
Reveal answer details
Close answer details
Question 11
Single choice
Which tool should be used to track login data, such as the average number of logins, who logged in more than the average number of times and who logged in during non-business hours?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 12
Single choice
Universal containers (UC) has implemented a multi-org strategy and would like to centralize the management of their salesforce user profiles. What should the architect recommend to allow salesforce profiles to be managed from a central system of record?
-
A
Implement jit provisioning on the SAML IDP that will pass the profile id in each assertion.
-
B
Create an apex scheduled job in one org that will synchronize the other orgs profile.
-
C
Implement Delegated Authentication that will update the user profiles as necessary.
-
D
Implement an Oauthjwt flow to pass the profile credentials between systems.
Reveal answer details
Close answer details
Question 13
Single choice
Universal containers wants to implement single Sign-on for a salesforce org using an external identity provider and corporate identity store. What type of Authentication flow is required to support deep linking?
-
A
Web server Oauth SSO flow.
-
B
Identity-provider-initiated SSO
-
C
Service-provider-initiated SSO
-
D
Start URL on identity provider
Reveal answer details
Close answer details
Question 14
Multiple choice
An administrator created a connected app for a custom web application in Salesforce which needs to be visible as a tile in App Launcher. The tile for the custom web application is missing in the app launcher for all users in Salesforce. The administrator requested assistance from an identity architect to resolve the issue. Which two reasons are the source of the issue? Choose 2 answers
-
A
Session Policy is set as "High Assurance Session required" for this connected app.
-
B
The connected app is not set in the App menu as "Visible in App Launcher".
-
C
Statutes, for the connected app is not set in Connected App settings.
-
D
Obtain scope does not include "openid".
Reveal answer details
Close answer details
Question 15
Multiple choice
Which three types of attacks would a 2-Factor Authentication solution help garden against?
-
A
-
B
Network perimeter attacks
-
C
-
D
-
E
Man-in-the-middle attacks
Reveal answer details
Close answer details
Question 16
Single choice
Universal Containers (UC) is building a custom Innovation platform on their Salesforce instance. The Innovation platform will be written completely in Apex and Visualforce and will use custom objects to store the Data. UC would like all users to be able to access the system without having to log in with Salesforce credentials. UC will utilize a third-party idp using SAML SSO. What is the optimal Salesforce licence type for all of the UC employees?
-
A
-
B
-
C
External Identity Licence.
-
D
Salesforce Platform Licence.
Reveal answer details
Close answer details
Question 17
Single choice
Universal containers (UC) uses a home-grown employee portal for their employees to collaborate. UC decides to use salesforce ideas to allow the employees to post ideas from the employee portal. When clicking some links in the employee portal, the users should be redirected to salesforce, authenticated, and presented with relevant pages. What scope should be requested when using the Oauth token to meet this requirement?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 18
Multiple choice
A technology enterprise is planning to implement single sign-on login for users. When users log in to the Salesforce User object custom field, data should be populated for new and existing users. Which two steps should an identity architect recommend? Choose 2 answers
-
A
Implement Auth.SamlJitHandler Interface.
-
B
Create and update methods.
-
C
Implement RegistrationHandler Interface.
-
D
Implement SesslonManagement Class.
Reveal answer details
Close answer details
Question 19
Single choice
A multinational company using the Salesforce platform wants to implement robust user activity verification capabilities to detect unauthorized access and unusual login patterns. They need real-time monitoring and alerting functionalities to respond promptly to security incidents. Which Salesforce tool should be utilized to achieve these requirements?
-
A
Salesforce Event Monitoring and Event Log Files
-
B
-
C
Salesforce Platform Encryption
-
D
Reveal answer details
Close answer details
Question 20
Multiple choice
A client is planning to rollout multi-factor authentication (MFA) to its internal employees and wants to understand which authentication and verification methods meet the Salesforce criteria for secure authentication. Which three functions meet the Salesforce criteria for secure mfa? Choose 3 answers
-
A
username and password + SMS passcode
-
B
Username and password + secunty key
-
C
Third-party single sign-on with Mobile Authenticator app
-
D
Certificate-based Authentication
-
E
Reveal answer details
Close answer details
Question 21
Single choice
Universal Containers (UC) wants its users to access Salesforce and other SSO-enabled applications from a custom web page that UC magnets. UC wants its users to use the same set of credentials to access each of the applications. what SAML SSO flow should an Architect recommend for UC?
-
A
SP-Initiated with Deep Linking
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 22
Single choice
Universal Containers (UC) has built a custom time tracking app for its employee. UC wants to leverage Salesforce Identity to control access to the custom app. At a minimum, which Salesforce license is required to support this requirement?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 23
Multiple choice
Universal Containers (UC) is building an authenticated Customer Community for its customers. UC does not want customer credentials stored in Salesforce and is confident its customers would be willing to use their social media credentials to authenticate to the community. Which two actions should an Architect recommend UC to take?
-
A
Use Delegated Authentication to call the Twitter login API to authenticate users.
-
B
Configure an Authentication Provider for LinkedIn Social Media Accounts.
-
C
Create a Custom Apex Registration Handler to handle new and existing users.
-
D
Configure SSO Settings For Facebook to serve as a SAML Identity Provider.
Reveal answer details
Close answer details
Question 24
Multiple choice
Northern Trail Outfitters (NTO) has an existing custom business-to-consumer (B2C) website that does NOT support single sign-on standards, such as Security Assertion Markup Language (SAMi) or OAuth. NTO wants to use Salesforce Identity to register and authenticate new customers on the website. Which two Salesforce features should an identity architect use in order to provide username/password authentication for the website? Choose 2 answers
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Multiple choice
Universal Containers (UC) has implemented a multi-org architecture in their company. Many users have licences across multiple orgs, and they are complaining about remembering which org and credentials are tied to which business process. Which two recommendations should the Architect make to address the Complaints? Choose 2 answers
-
A
Activate My Domain to Brand each org to the specific business use case.
-
B
Implement SP-Initiated Single Sign-on flows to allow deep linking.
-
C
Implement IdP-Initiated Single Sign-on flows to allow deep linking.
-
D
Implement Delegated Authentication from each org to the LDAP provider.
Reveal answer details
Close answer details
Question 26
Multiple choice
Universal containers (UC) wants to implement a partner community. As part of their implementation, UC would like to modify both the Forgot password and change password experience with custom branding for their partner community users. Which 2 actions should an architect recommend to UC? Choose 2 answers
-
A
Build a community builder page for the change password experience and Custom Visualforce page for the Forgot password experience.
-
B
Build a custom visualforce page for both the change password and Forgot password experiences.
-
C
Build a custom visualforce page for the change password experience and a community builder page for the Forgot password experience.
-
D
Build a community builder page for both the change password and Forgot password experiences.
Reveal answer details
Close answer details
Question 27
Single choice
A third-party app provider would like to have users provisioned via a service endpoint before users access their app from Salesforce. What should an identity architect recommend to configure the requirement with limited changes to the third-party app?
-
A
Use a connected app with user provisioning flow.
-
B
Create Canvas app in Salesforce for third-party app to provision users.
-
C
Redirect users to the third-party app for registration.
-
D
Use Salesforce identity with Security Assertion Markup Language (SAML) for provisioning users.
Reveal answer details
Close answer details
Question 28
Multiple choice
A large consumer company is planning to create a community and will requ.re login through the customers social identity. The following requirements must be met: 1. The customer should be able to login with any of their social identities, however salesforce should only have one user per customer. 2. Once the customer has been identified with a social identity, they should not be required to authonze Salesforce. 3. The customers personal details from the social sign on need to be captured when the customer logs into Salesforce using their social Identity. 3. If the customer modifies their personal details in the social site, the changes should be updated in Salesforce . Which two options allow the Identity Architect to fulfill the requirements? Choose 2 answers
-
A
Use Login Flows to call an authentication registration handler to provision the user before logging the user into the community.
-
B
Use authentication providers for social sign-on and use the custom registration handler to insert or update personal details.
-
C
Redirect the user to a custom page that allows the user to select an existing social identity for login.
-
D
Use the custom registration handler to link social identities to Salesforce identities.
Reveal answer details
Close answer details
Question 29
Single choice
Universal containers (UC) is setting up their customer Community self-registration process. They are uncomfortable with the idea of assigning new users to a default account record. What will happen when customers self-register in the community?
-
A
The self-registration process will produce an error to the user.
-
B
The self-registration page will ask user to select an account.
-
C
The self-registration process will create a person Account record.
-
D
The self-registration page will create a new account record.
Reveal answer details
Close answer details
Question 30
Multiple choice
Universal containers (UC) has a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a connected App in salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properly secure access to the app. Which two are recommendations to make the UC? Choose 2 answers
-
A
Disallow the use of single Sign-on for any users of the mobile app.
-
B
Require high assurance sessions in order to use the connected App
-
C
Use Google Authenticator as an additional part of the logical processes.
-
D
Set login IP ranges to the internal network for all of the app users profiles.
Reveal answer details
Close answer details
Question 31
Single choice
Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for NTO to give its customers the ability to login with their Amazon credentials. What should an identity architect recommend to meet these requirements?
-
A
Configure a predefined authentication provider for Amazon.
-
B
Create a custom external authentication provider for Amazon.
-
C
Configure an OpenID Connect Authentication Provider for Amazon.
-
D
Configure Amazon as a connected app.
Reveal answer details
Close answer details
Question 32
Multiple choice
Universal containers (UC) wants to integrate a Web application with salesforce. The UC team has implemented the Oauth web-server Authentication flow for authentication process. Which two considerations should an architect point out to UC? Choose 2 answers
-
A
The web application should be hosted on a secure server.
-
B
The web server must be able to protect consumer privacy
-
C
The flow involves passing the user credentials back and forth.
-
D
The flow will not provide an Oauth refresh token back to the server.
Reveal answer details
Close answer details
Question 33
Multiple choice
Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for to give its customers the ability to login with their Facebook and Twitter credentials. Which two actions should an identity architect recommend to meet these requirements? Choose 2 answers
-
A
Create a custom external authentication provider for Facebook.
-
B
Configure a predefined authentication provider for Facebook.
-
C
Create a custom external authentication provider for Twitter.
-
D
Configure a predefined authentication provider for Twitter.
Reveal answer details
Close answer details
Question 34
Single choice
A pharmaceutical company has an on-premise application (see illustration) that it wants to integrate with Salesforce.  The IT director wants to ensure that requests must include a certificate with a trusted certificate chain to access the company's on-premise application endpoint. What should an Identity architect do to meet this requirement?
-
A
Use open SSL to generate a Self-signed Certificate and upload it to the on-premise app.
-
B
Configure the company firewall to allow traffic from Salesforce IP ranges.
-
C
Generate a certificate authority-signed certificate in Salesforce and uploading it to the on-premise application Truststore.
-
D
Upload a third-party certificate from Salesforce into the on-premise server.
Reveal answer details
Close answer details
Question 35
Multiple choice
A real estate company wants to provide its customers a digital space to design their interior decoration options. To simplify the registration to gain access to the community site (built in Experience Cloud), the CTO has requested that the IT/Development team provide the option for customers to use their existing social-media credentials to register and access. The IT lead has approached the Salesforce Identity and Access Management (IAM) architect for technical direction on implementing the social sign-on (for Facebook, Twitter, and a new provider that supports standard OpenID Connect (OIDC)). Which two recommendations should the Salesforce IAM architect make to the IT Lead? Choose 2 answers
-
A
Use declarative registration handler process builder/flow to create, update users and contacts.
-
B
Authentication provider configuration is required each social sign-on providers; and enable Authentication providers in community.
-
C
For supporting OIDC it is necessary to enable Security Assertion Markup Language (SAML) with Just-in- Time provisioning (JIT) and OAuth 2.0.
-
D
Apex coding skills are needed for registration handler to create and update users.
Reveal answer details
Close answer details
Question 36
Single choice
An organization has a central cloud-based Identity and Access Management (IAM) Service for authentication and user management, which must be utilized by all applications as follows: 1 - Change of a user status in the central IAM Service triggers provisioning or deprovisioining in the integrated cloud applications. 2 - Security Assertion Markup Language single sign-on (SSO) is used to facilitate access for users authenticated at identity provider (Central IAM Service).  Which approach should an IAM architect implement on Salesforce Sales Cloud to meet the requirements?
-
A
A Configure Salesforce as a SAML Service Provider, and enable SCIM (System for Cross-Domain Identity Management) for provisioning and deprovisioning of users.
-
B
Configure Salesforce as a SAML service provider, and enable Just-in Time (JIT) provisioning and deprovisioning of users.
-
C
Configure central IAM Service as an authentication provider and extend registration handler to manage provisioning and deprovisioning of users.
-
D
Deploy Identity Connect component and set up automated provisioning and deprovisioning of users, as well as SAML-based SSO.
Reveal answer details
Close answer details
Question 37
Multiple choice
Universal containers (UC) employees have salesforce access from restricted ip ranges only, to protect against unauthorised access. UC wants to rollout the salesforce1 mobile app and make it accessible from any location. Which two options should an architect recommend? Choose 2 answers
-
A
Relax the ip restriction in the connect app settings for the salesforce1 mobile app
-
B
Use login flow to bypass ip range restriction for the mobile app.
-
C
Relax the ip restriction with a second factor in the connect app settings for salesforce1 mobile app
-
D
Remove existing restrictions on ip ranges for all types of user access.
Reveal answer details
Close answer details
Question 38
Single choice
How should an Architect automatically redirect users to the login page of the external Identity provider when using an SP-Initiated SAML flow with Salesforce as a Service Provider?
-
A
Use visualforce as the landing page for My Domain to redirect users to the Identity Provider login Page.
-
B
Enable the Redirect to the Identity Provider setting under Authentication Services on the My domain Configuration.
-
C
Remove the Login page from the list of Authentication Services on the My Domain configuration.
-
D
Set the Identity Provider as default and enable the Redirect to the Identity Provider setting on the SAML Configuration.
Reveal answer details
Close answer details
Question 39
Multiple choice
Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the OAuth 2.0 user-agent flow (this flow uses the OAuth 2.0 implicit grant type). Which three OAuth concepts apply to this flow? Choose 3 answers
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 40
Multiple choice
Universal Containers (UC) is building an integration between Salesforce and a legacy web applications using the canvas framework. The security for UC has determined that a signed request from Salesforce is not an adequate authentication solution for the Third-Party app. Which two options should the Architect consider for authenticating the third-party app using the canvas framework? Choose 2 Answers
-
A
Utilize the SAML Single Sign-on flow to allow the third-party to authenticate itself against UC's IdP.
-
B
Utilize Authorization Providers to allow the third-party appliction to authenticate itself against Salesforce as the Idp.
-
C
Utilize Canvas OAuth flow to allow the third-party appliction to authenticate itself against Salesforce as the Idp.
-
D
Create a registration handler Apex class to allow the third-party appliction to authenticate itself against Salesforce as the Idp.
Reveal answer details
Close answer details
|