[Dec-2021] Identity-and-Access-Management-Designer Exam Dumps Pass with Updated 2021 Salesforce Certified Identity and Access Management Designer [Q95-Q112]

Share

[Dec-2021] Identity-and-Access-Management-Designer Exam Dumps Pass with Updated 2021 Salesforce Certified Identity and Access Management Designer

Free Identity-and-Access-Management-Designer Exam Dumps to Pass Exam Easily


What is the duration of the Identity-and-Access-Management-Designer Exam

  • Format: Multiple choices, multiple answers
  • Length of Examination: 120 minutes
  • Passing Score: 65%
  • Number of Questions: 60

Who should take the Identity-and-Access-Management-Designer exam

Salesforce Certified Identity and Access Management Designer (WI19) certification is an internationally-recognized validation that identifies persons who earn it as possessing skilled as a Salesforce Certified Identity and Access Management Designer (WI19). if a candidate wants significant improvement in career growth needs enhanced knowledge, skills, and talents. The Salesforce Identity-and-Access-Management-Designer Exam provides proof of this advanced knowledge and skill. If a candidate has knowledge of associated technologies and skills that are required to pass the Salesforce Identity-and-Access-Management-Designer Exam then he should take this exam.

 

NEW QUESTION 95
The security team at Universal Containers (UC) hasidentified exporting reports as a high-risk action and would like to require users to be logged into Salesforce with their Active Directory (AD) credentials when doing so.
For all other users of Salesforce, users should be allowed to use AD Credentials orSalesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with Salesforce credentials?

  • A. Use SAML Federated Authentication and block access to reports when accessed through a Standard Assurance session.
  • B. Use SAML federated Authentication, treat SAML Sessions as High Assurance, and raise the session level required for exporting reports.
  • C. Use SAML federated Authentication with a Login Flow to dynamically add or remove a Permission Set that grants the Export Reports Permission.
  • D. Use SAML Federated Authentication and Custom SAML JIT Provisioning to dynamically and or remove a permission set that grants the Export Reports Permission.

Answer: B

 

NEW QUESTION 96
Universal Containers (UC) has decided to build a new, highly sensitive application on the Force.com platform.
The security team at UC has decided that they want users to provide a fingerprint in addition to username/password to authenticate to this application. How can an Architect support fingerprints as a form of identification for Salesforce authentication?

  • A. Use delegated Authentication with callouts to a third-party fingerprint scanning application.
  • B. Use an AppExchange product that does fingerprint scanning with native Salesforce Identity Confirmation.
  • C. Use Salesforce Two-factor authentication with callouts to a third-party fingerprint scanning application.
  • D. Use custom login flows with callouts to a third-party fingerprint scanning application.

Answer: B

 

NEW QUESTION 97
Containers (UC) uses an internal system for recruiting and would like to have the candidates' info available in the Salesforce automatically when they are selected. UC decides to use OAuth to connect to Salesforce from the recruiting system and would like to do the authentication using digital certificates. Which two OAuth flows should be considered to meet the requirement? Choose 2 answers

  • A. SAML Bearer Assertion flow
  • B. Web Service flow
  • C. JWT Bearer Token flow
  • D. Refresh Token flow

Answer: A,C

 

NEW QUESTION 98
Universal containers (UC) has a mobile application that it wants to deploy to all of its salesforce users, including customer Community users. UC would like to minimize the administration overhead, which two items should an architect recommend? Choose 2 answers

  • A. Enable the "All users may self-authorize" setting in the Connected App.
  • B. Enable the "Refresh Tokens is valid until revoked " setting in the Connected App.
  • C. Enable the "High Assurance session required" setting in the Connected App.
  • D. Enable the "Enforce Ip restrictions" settings in the connected App.

Answer: A,B

 

NEW QUESTION 99
What are threecapabilitiesof Delegated Authentication? Choose 3 answers

  • A. It can be assigned by Permission Sets.
  • B. It can be assigned by Profiles.
  • C. It can be assigned by Custom Permissions.
  • D. It can connect to SOAP services.
  • E. It can connect to REST services.

Answer: A,D,E

 

NEW QUESTION 100
Universal Containers wants to allow its customers to log in to its Experience Cloud via a third party authentication provider that supports only the OAuth protocol.
What should an identity architect do to fulfill this requirement?

  • A. Use certificate-based authentication.
  • B. Contact Salesforce Support and enable delegate single sign-on.
  • C. Configure OpenID Connect authentication provider.
  • D. Create a custom external authentication provider.

Answer: D

 

NEW QUESTION 101
How should an Architect automatically redirect users to the login page of the external Identity provider when using an SP-Initiated SAML flow with Salesforce as a Service Provider?

  • A. Remove the Login page from the list of Authentication Services on the My Domain configuration.
  • B. Enable the Redirect to the Identity Provider setting under Authentication Services on the My domain Configuration.
  • C. Use visualforce as the landing page for My Domain to redirect users to the Identity Provider login Page.
  • D. Set the Identity Provider as default and enable the Redirect to the Identity Provider setting on the SAML Configuration.

Answer: A

 

NEW QUESTION 102
Which two statements are capable of Identity Connect? Choose 2 answers

  • A. Support multiple orgs connecting to multiple Active Directory servers.
  • B. Automated user synchronization and de-activation.
  • C. Synchronization of Salesforce Permission Set Licence Assignments.
  • D. Supports both Identity-Provider-Initiated and Service-Provider-Initiated SSO.

Answer: B,D

 

NEW QUESTION 103
The security team at Universal containers(UC) has identified exporting reports as a high-risk action and would like to require users to be logged into salesforce with their active directory (AD) credentials when doing so. For all other uses of Salesforce, Users should be allowed to use AD credentials or salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with salesforce credentials?

  • A. Use SAML Federated Authentication, treat SAML sessions as high assurance, and raise the session level required for exporting reports.
  • B. Use SAML Federated Authentication and block access to reports when accesses through a standard assurance session.
  • C. Use SAML Federated Authentication and Custom SAML jit provisioning to dynamically add or remove a permission set that grants the Export Reports permission.
  • D. Use SAML Federated Authentication with a login flow to dynamically add or remove a permission set that grants the export reports permission.

Answer: B

 

NEW QUESTION 104
Universal Containers (UC) uses Global Shipping (GS) as one of their shipping vendors. Regional leads of GS need access to UC's Salesforce instance for reporting damage of goods using Cases. The regional leads also need access to dashboards to keep track of regional shipping KPIs. UC internally uses a third-party cloud analytics tool for capacity planning and UC decided to provide access to this tool to a subset of GS employees.
In addition to regional leads, the GS capacity planning team would benefit from access to this tool. To access the analytics tool, UC IT has set up Salesforce as the Identity provider for Internal users and would like to follow the same approach for the GS users as well. What are the most appropriate license types for GS Tregional Leads and the GS Capacity Planners? Choose 2 Answers

  • A. Identity Licence for GS Regional Leads and External Identity license for GS capacity Planners.
  • B. Customer Community Plus license for GS Regional Leads and External Identity for GS Capacity Planners.
  • C. Customer Community license for GS Regional Leads and Identity license for GS Capacity Planners.
  • D. Customer Community Plus license for GS Regional Leads and Customer Community license for GS Capacity Planners.

Answer: C,D

 

NEW QUESTION 105
Universal containers (UC) employees have salesforce access from restricted ip ranges only, to protect against unauthorised access. UC wants to rollout the salesforce1 mobile app and make it accessible from any location.
Which two options should an architect recommend? Choose 2 answers

  • A. Remove existing restrictions on ip ranges for all types of user access.
  • B. Relax the ip restriction with a second factor in the connect app settings for salesforce1 mobile app
  • C. Use login flow to bypass ip range restriction for the mobile app.
  • D. Relax the ip restriction in the connect app settings for the salesforce1 mobile app

Answer: C,D

 

NEW QUESTION 106
architect is troubleshooting some SAML-based SSO errors during testing. The Architect confirmed that all of the Salesforce SSO settings are correct. Which two issues outside of the Salesforce SSO settings are most likely contributing to the SSO errors the Architect is encountering? Choose 2 Answers

  • A. The clock on the Identity Provider server is twenty minutes behind Salesforce.
  • B. The Issuer Certificate from the Identity Provider expired two weeks ago.
  • C. The default language for the Identity Provider and Salesforce are Different.
  • D. The Identity Provider is also used to SSO into five other applications.

Answer: A,B

 

NEW QUESTION 107
Universal Containers wants to implement Single Sign-on for a Salesforce org using an external Identity Provider and corporate identity store.
What type of authentication flow is required to support deep linking'

  • A. StartURL on Identity Provider
  • B. Service-Provider-Initiated SSO
  • C. Identity-Provider-initiated SSO
  • D. Web Server OAuth SSO flow

Answer: B

 

NEW QUESTION 108
Universal containers (UC) wants to implement Delegated Authentication for a certain subset of Salesforce users. Which three items should UC take into consideration while building the Web service to handle the Delegated Authentication request? Choose 3 answers

  • A. Delegated Authentication is enabled for the system administrator profile.
  • B. The return type of the Web service method should be a Boolean value
  • C. UC should whitelist all salesforce ip ranges on their corporate firewall.
  • D. The web service needs to include Source IP as a method parameter.
  • E. The web service can be written using either the soap or rest protocol.

Answer: B,C,D

 

NEW QUESTION 109
A technology enterprise is planning to implement single sign-on login for users. When users log in to the Salesforce User object custom field, data should be populated for new and existing users.
Which two steps should an identity architect recommend?
Choose 2 answers

  • A. Implement SesslonManagement Class.
  • B. Create and update methods.
  • C. Implement RegistrationHandler Interface.
  • D. Implement Auth.SamlJitHandler Interface.

Answer: B,D

 

NEW QUESTION 110
Universal Containers (UC) has implemented SAML-based SSO solution for use with their multi-org Salesforce implementation, utilizing one of the the orgs as the Identity Provider. One user is reporting that they can log in to the Identity Provider org but get a generic SAML error message when accessing the other orgs. Which two considerations should the architect review to troubleshoot the issue? Choose 2 answers

  • A. The Federation ID must be populated on the user record.
  • B. The Federation ID must is case sensitive
  • C. The Federation ID must be a valid Salesforce Username
  • D. The Federation ID must be in the form of an email address.

Answer: A,B

 

NEW QUESTION 111
Universal Containers is using OpenID Connect to enable a connection from their new mobile app to its production Salesforce org.
What should be done to enable the retrieval of the access token status for the OpenID Connect connection?

  • A. A Leverage OpenID Connect Token Introspection.
  • B. Create a custom OAuth scope.
  • C. Query using OpenID Connect discovery endpoint.
  • D. Enable cross-origin resource sharing (CORS) for the /services/oauth2/token endpoint.

Answer: A

 

NEW QUESTION 112
......

Identity-and-Access-Management-Designer Exam Dumps, Identity-and-Access-Management-Designer Practice Test Questions: https://www.prepawayete.com/Salesforce/Identity-and-Access-Management-Designer-practice-exam-dumps.html

Free Identity-and-Access-Management-Designer Study Guides Exam Questions & Answer: https://drive.google.com/open?id=1Pf-PWJY9lexAxULOcaHgT1op-uQClMaH

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 )
From Monday to Saturday

Support: Contact now