Salesforce Certified Identity and Access Management Designer Exam Practice Questions (P. 2)
- Full Access (60 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #6
Universal Containers (UC) has decided to use Identity Connect as its Identity Provider. UC uses Active Directory (AD) and has a team that is very familiar and comfortable with managing AD groups. UC would like to use AD Groups to help configure Salesforce users.
Which three actions can AD Groups control through Identity Connect? (Choose three.)
Which three actions can AD Groups control through Identity Connect? (Choose three.)
- APublic Group Assignment
- BRole Assignment
- CCustom Permissions Assignment
- DGranting Report Folder Access
- EPermission Sets Assignment
Correct Answer:
ABE
ABE
send
light_mode
delete
Question #7
The CIO of Universal Containers (UC) wants to start taking advantage of the refresh token capability for the UC applications that utilize OAuth 2.0. UC has enlisted an Architect to analyze all of the applications that use OAuth flows to see where refresh tokens can be applied.
Which two OAuth flows should the Architect consider in their evaluation? (Choose two.)
Which two OAuth flows should the Architect consider in their evaluation? (Choose two.)
- AJWT Bearer Token
- BWeb ServerMost Voted
- CUsername-Password
- DUser-AgentMost Voted
Correct Answer:
BD
BD
send
light_mode
delete
Question #8
An Architect needs to advise the team that manages the Identity Provider how to differentiate Salesforce from other Service Providers.
What SAML SSO setting in Salesforce provides this capability?
What SAML SSO setting in Salesforce provides this capability?
- ASAML Identity Location
- BIdentity Provider Login URL
- CEntity IdMost Voted
- DIssuer
Correct Answer:
C
C
send
light_mode
delete
Question #9
Universal Containers (UC) uses middleware to integrate multiple systems with Salesforce. UC has a strict, new requirement that usernames and passwords cannot be stored in any UC system.
How can UC's middleware authenticate to Salesforce while adhering to this requirement?
How can UC's middleware authenticate to Salesforce while adhering to this requirement?
- ACreate a Connected App that supports the Refresh Token OAuth Flow.
- BCreate a Connected App that supports the JWT Bearer Token OAuth Flow.Most Voted
- CCreate a Connected App that supports the User-Agent OAuth Flow.
- DCreate a Connected App that supports the Web Server OAuth Flow.
Correct Answer:
B
B
send
light_mode
delete
Question #10
Customer Service Representatives at Universal Containers (UC) are complaining that whenever they click on links to case records and are asked to log in with SAML SSO, they are being redirected to the Salesforce Home tab and not the specific case record.
What item should an Architect advise the identity team at UC to investigate first?
What item should an Architect advise the identity team at UC to investigate first?
- AMy Domain is configured and active within Salesforce.
- BThe users have the correct Federation ID within Salesforce.
- CThe Salesforce SSO settings are using HTTP POST.
- DThe Identity Provider is correctly preserving the RelayState.Most Voted
Correct Answer:
D
D
send
light_mode
delete
All Pages