Salesforce Certified Platform Identity and Access Management Architect - Certified Platform Identity and Access Management Architect Exam

Question #11 (Topic: Topic 2, Accepting Third-Party Identity in Salesforce )
A university is planning to set up an identity solution for its alumni. A third-party identity provider will be used for single sign-on and Salesforce will be the system of records. Users are getting error messages when logging in.
Which Salesforce feature should be used to debug the issue?
A. Apex Exception Email B. Debug Logs C. Login History D. View Setup Audit Trail
Answer: C
Question #12 (Topic: Topic 2, Accepting Third-Party Identity in Salesforce )
A technology enterprise is planning to implement single sign-on login for users. When users log in to Salesforce, data should be populated in User object custom fields.
Which two steps should an identity architect recommend?
A. Implement SessionManagement Class. B. Create and update methods. C. Implement Auth.SamlJitHandler Interface. D. Implement RegistrationHandler Interface.
Answer: BC
Question #13 (Topic: Topic 2, Accepting Third-Party Identity in Salesforce )
A division of a Northern Trail Outfitters (NTO) purchased Salesforce. NTO uses a third party identity provider (IdP) to validate user credentials against its corporate Lightweight Directory Access Protocol (LDAP) directory. NTO wants to help employees remember as few passwords as possible.
What should an identity architect recommend?
A. Setup Salesforce as an Authentication Provider to the existing IdP. B. Use Salesforce connect to synchronize LDAP passwords to Salesforce. C. Setup Salesforce as a Service Provider to the existing IdP. D. Setup Salesforce as an IdP to authenticate against the LDAP directory.
Answer: C
Question #14 (Topic: Topic 2, Accepting Third-Party Identity in Salesforce )
Universal Containers wants to allow its customers to log in to its Experience Cloud via a third party authentication provider that supports only the OAuth protocol.
What should an identity architect do to fulfill this requirement?
A. Contact Salesforce Support and enable delegate single sign-on. B. Use certificate-based authentication. C. Create a custom external authentication provider. D. Configure OpenID Connect authentication provider.
Answer: C
Question #15 (Topic: Topic 2, Accepting Third-Party Identity in Salesforce )
Northern Trail Outfitters manages application functional permissions centrally as Active Directory groups. The CRM_SuperUser and CRM_Reporting_SuperUser groups should respectively give the user the SuperUser and Reporting_SuperUser permission set in Salesforce. Salesforce is the service provider to a Security Assertion Markup Language (SAML) identity provider.
How should an identity architect ensure the Active Directory groups are reflected correctly when a user accesses Salesforce?
A. Use the Apex Just-in-Time handler to query custom SAML attributes and set permission sets. B. Use a login flow to query custom SAML attributes and set permission sets. C. Use a login flow to query standard SAML attributes and set permission sets. D. Use the Apex Just-in-Time handler to query standard SAML attributes and set permission sets.
Answer: D
Download Exam
Page: 3 / 12
Total 58 questions