Salesforce Certified Identity and Access Management Designer - Certified Identity and Access Management Designer Exam
Page: 3 / 12
Total 60 questions
Question #11 (Topic: Exam A)
Universal Containers has implemented a multi-org strategy and would like to centralize the management of their Salesforce user profiles.
What should the Architect recommend to allow Salesforce profiles to be managed from a central system of record?
What should the Architect recommend to allow Salesforce profiles to be managed from a central system of record?
A. Implement JIT provisioning on the SAML IdP that will pass the ProfileID in each assertion.
B. Implement Delegated Authentication that will update the user profiles as necessary.
C. Create an Apex scheduled job in one org that will synchronize the other org's profiles.
D. Implement an OAuth JWT flow to pass the profile credentials between systems.
Answer: A
Question #12 (Topic: Exam A)
Universal Containers (UC) has implemented SAML-based Single Sign-on for their Salesforce application. UC is using PingFederate as the Identity Provider. To access Salesforce, users usually navigate to a bookmarked link to My Domain URL.
What type of Single Sign-on flow is this?
What type of Single Sign-on flow is this?
A. IdP-Initiated
B. IdP-Initiated with Deep Linking
C. SP-Initiated
D. Web Server Flow
Answer: C
Question #13 (Topic: Exam A)
What item should an Architect consider when designing a Delegated Authentication implementation?
A. The web service should be secured with TLS using Salesforce trusted certificates.
B. The web service should be able to accept one to four input method parameters.
C. The web service should use the Salesforce Federation ID to identify the user.
D. The web service should implement a custom password decryption method.
Answer: A
Question #14 (Topic: Exam A)
Universal Containers has built a custom token-based Two-Factor Authentication system for their existing on-premise applications. They are now implementing Salesforce and would like to enable a Two-Factor login process for it, as well.
What is the recommended solution an Architect should consider?
What is the recommended solution an Architect should consider?
A. Replace the custom 2FA system with an AppExchange App that supports on-premise applications and Salesforce.
B. Use the custom 2FA system for on-premise applications and native 2FA for Salesforce.
C. Replace the custom 2FA system with Salesforce 2FA for on-premise applications and Salesforce.
D. Use Custom Login Flows to connect to the existing custom 2FA system for use in Salesforce.
Answer: D
Question #15 (Topic: Exam A)
Universal Containers (UC) is looking to purchase a third-party application as an Identity Provider. UC is looking to develop a business case for the purchase in general and has enlisted an Architect for advice.
Which two capabilities of an Identity Provider should the Architect detail to help strengthen the business case? (Choose two.)
Which two capabilities of an Identity Provider should the Architect detail to help strengthen the business case? (Choose two.)
A. The Identity Provider can authenticate multiple applications.
B. The Identity Provider can authenticate multiple social media accounts.
C. The Identity Provider can store credentials for multiple applications.
D. The Identity Provider can centralize enterprise password policy.
Answer: CD