更新された2023年11月テストエンジン練習Identity-and-Access-Management-Designer問題集と練習試験合格させます [Q16-Q37]

Share

更新された2023年11月テストエンジン練習Identity-and-Access-Management-Designer問題集と練習試験合格させます

問題集お試しセットIdentity-and-Access-Management-Designerテストエンジンで問題集トレーニングには245問あります

質問 # 16
Universal containers wants salesforce inbound Oauth-enabled integration clients to use SAML-BASED single Sign-on for authentication. What Oauth flow would be recommended in this scenario?

  • A. Web server Oauth flow
  • B. User-Token Oauth flow
  • C. SAML assertion Oauth flow
  • D. User-Agent Oauth flow

正解:C


質問 # 17
Universal Containers (UC) wants to integrate a third-party Reward Calculation system with Salesforce to calculate Rewards. Rewards will be calculated on a schedule basis and update back into Salesforce. The integration between Salesforce and the Reward Calculation System needs to be secure. Which are two recommended practices for using OAuth flow in this scenario. choose 2 answers

  • A. OAuth Username-Password Flow
  • B. OAuth SAML Bearer Assertion FLow
  • C. OAuth JWT Bearer Token FLow
  • D. OAuth Refresh Token FLow

正解:A、C


質問 # 18
Northern Trail Outfitters would like to automatically create new employee users in Salesforce with an appropriate profile that maps to its Active Directory Department.
How should an identity architect implement this requirement?

  • A. Use a login flow to collect Security Assertion Markup Language attributes and assign the appropriate profile during Just-In-Time (JIT) provisioning.
  • B. Use the createUser method in the Just-in-Time (JIT) provisioning registration handler to assign the appropriate profile.
  • C. Use the updateUser method in the Just-in-Time (JIT) provisioning registration handler to assign the appropriate profile.
  • D. Make a callout during the login flow to query department from Active Directory to assign the appropriate profile.

正解:C


質問 # 19
Universal containers (UC) uses a legacy Employee portal for their employees to collaborate and post their ideas. UC decides to use salesforce ideas for voting and better tracking purposes. To avoid provisioning users on Salesforce, UC decides to push ideas posted on the Employee portal to salesforce through API. UC decides to use an API user using Oauth Username - password flow for the connection. How can the connection to salesforce be restricted only to the employee portal server?

  • A. Use a digital certificate signed by the employee portal Server.
  • B. Add the employee portals IP address to the login IP range on the user profile.
  • C. Add the Employee portals IP address to the Trusted IP range for the connected App
  • D. Use a dedicated profile for the user the Employee portal uses.

正解:C


質問 # 20
Northern Trail Outfitters (NTO) wants its customers to use phone numbers to log in to their new digital portal, which was designed and built using Salesforce Experience Cloud. In order to access the portal, the user will need to do the following:
1. Enter a phone number and/or email address
2. Enter a verification code that is to be sent via email or text.
What is the recommended approach to fulfill this requirement?

  • A. Create an Authentication provider and implement a self-registration handler class.
  • B. Create a custom login page with an Apex controller. The controller has logic to send and verify the identity.
  • C. Create a Login Discovery page and provide a Login Discovery Handler Apex class.
  • D. Create a custom login flow that uses an Apex controller to verify the phone numbers with the company's verification service.

正解:C


質問 # 21
Universal containers (UC) has multiple salesforce orgs and would like to use a single identity provider to access all of their orgs. How should UC'S architect enable this behavior?

  • A. Ensure that users have the same email value in their user records in all of UC's salesforce orgs.
  • B. Ensure that users have the same Federation ID value in their user records in all of UC's salesforce orgs.
  • C. Ensure that users have the same alias value in their user records in all of UC's salesforce orgs.
  • D. Ensure the same username is allowed in multiple orgs by contacting salesforce support.

正解:B


質問 # 22
Universal Containers (UC) has implemented SAML-based SSO solution for use with their multi-org Salesforce implementation, utilizing one of the the orgs as the Identity Provider. One user is reporting that they can log in to the Identity Provider org but get a generic SAML error message when accessing the other orgs. Which two considerations should the architect review to troubleshoot the issue? Choose 2 answers

  • A. The Federation ID must is case sensitive
  • B. The Federation ID must be a valid Salesforce Username
  • C. The Federation ID must be in the form of an email address.
  • D. The Federation ID must be populated on the user record.

正解:A、D


質問 # 23
Universal Containers (UC) wants to integrate a web application with Salesforce. The UC team has implemented the OAuth Web-Server Authentication Flow for authentication purposes.
Which two considerations should an Architect point out to UC? (Choose two.)

  • A. The flow involves passing the user credentials back and forth.
  • B. The flow will NOT provide an OAuth Refresh Token back to the server.
  • C. The web server must be able to protect consumer secret.
  • D. The web application should be hosted on a secure server.

正解:C、D


質問 # 24
Universal Containers wants to allow its customers to log in to its Experience Cloud via a third party authentication provider that supports only the OAuth protocol.
What should an identity architect do to fulfill this requirement?

  • A. Use certificate-based authentication.
  • B. Contact Salesforce Support and enable delegate single sign-on.
  • C. Configure OpenID Connect authentication provider.
  • D. Create a custom external authentication provider.

正解:D


質問 # 25
A group of users try to access one of Universal Containers' Connected Apps and receive the following error message: " Failed: Not approved for access." What is the most likely cause of this issue?

  • A. The Connected App settings "All users may self-authorize" is enabled.
  • B. The Salesforce Administrators have revoked the OAuth authorization.
  • C. The User of High Assurance sessions are required for the Connected App.
  • D. The Users do not have the correct permission set assigned to them.

正解:D


質問 # 26
Which three are capabilities of SAML-based Federated authentication? Choose 3 answers

  • A. SAML tokens can be in XML or JSON format and can be used interchangeably.
  • B. Trust relationships between Identity Provider and Service Provider are required.
  • C. Web applications with no passwords are more secure and stronger against attacks.
  • D. Centralized federation provides single point of access, control and auditing.
  • E. Access tokens are used to access resources on the server once the user is authenticated.

正解:B、D、E


質問 # 27
Northern Trail Outfitters (NTO) uses Salesforce Experience Cloud sites (previously known as Customer Community) to provide a digital portal where customers can login using their Google account.
NTO would like to automatically create a case record for first time users logging into Salesforce Experience Cloud.
What should an Identity architect do to fulfill the requirement?

  • A. Configure an authentication provider for Social Login using Google and a custom registration handler.
  • B. Implement a Just-in-Time handler class that has logic to create cases upon first login.
  • C. Implement a login flow with a record create component for Case.
  • D. Create an authentication provider for Social Login using Google and leverage standard registration handler.

正解:C


質問 # 28
Containers (UC) uses a legacy Employee portal for their employees to collaborate. Employees access the portal from their company's internal website via SSO. It is set up to work with SiteMinder and Active Directory. The Employee portal has features to support posing ideas. UC decides to use Salesforce Ideas for voting and better tracking purposes. To avoid provisioning users on Salesforce, UC decides to integrate Employee portal ideas with Salesforce idea through the API. What is the role of Salesforce in the context of SSO, based on this scenario?

  • A. Service Provider, because Salesforce is the application for managing ideas.
  • B. Identity Provider, because the API calls are authenticated by Salesforce.
  • C. Connected App, because Salesforce is connected with Employee portal via API.
  • D. An independent system, because Salesforce is not part of the SSO setup.

正解:D


質問 # 29
which three are features of federated Single Sign-on solutions? Choose 3 answers

  • A. It solves all identity and access management problems.
  • B. It establishes trust between Identity store and service provider.
  • C. It federates credentials control to authorized applications.
  • D. It enables quick and easy provisioning and deactivating of users.
  • E. It improves affiliated applications adoption rates.

正解:A、B、D


質問 # 30
Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for to give its customers the ability to login with their Facebook and Twitter credentials.
Which two actions should an identity architect recommend to meet these requirements?
Choose 2 answers

  • A. Create a custom external authentication provider for Facebook.
  • B. Configure a predefined authentication provider for Twitter.
  • C. Configure a predefined authentication provider for Facebook.
  • D. Create a custom external authentication provider for Twitter.

正解:B、C


質問 # 31
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to SSO set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?

  • A. IdP-initiated SSO will NOT work.
  • B. Either SP- or IdP-initiated SSO will work.
  • C. SP-initiated SSO will NOT work
  • D. Neither SP- nor IdP-initiated SSO will work.

正解:D


質問 # 32
A farming enterprise offers smart farming technology to rts farmer customers, which includes a variety of sensors for livestock tracking, pest monitoring, climate monitoring etc. They plan to store all the data in Salesforce. They would also like to ensure timely maintenance of the Installed sensors. They have engaged a salesforce Architect to propose an appropnate way to generate sensor Information In Salesforce.
Which OAuth flow should the architect recommend?

  • A. OAuth 2.0 Device Authentication Row
  • B. OAuth 2.0 Asset Token Flow
  • C. OAuth 2.0 SAML Bearer Assertion Flow
  • D. OAuth 2.0 JWT Bearer Token Flow

正解:B


質問 # 33
Which three types of attacks would a 2-Factor Authentication solution help garden against?

  • A. Key logging attacks
  • B. Dictionary attacks
  • C. Phishing attacks
  • D. Man-in-the-middle attacks
  • E. Network perimeter attacks

正解:A、B、E


質問 # 34
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers willutilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?

  • A. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
  • B. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML toallow SSO.
  • C. Use anightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
  • D. UseSAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.

正解:D


質問 # 35
Universal Containers (UC) has implemented an SP-initiated SAML flow between an external IdP and Salesforce. A user at UC is attempting to log in to Salesforce mobile app for the first time and is being prompted for Salesforce credentials instead of being shown the IdP login page.
What is the likely cause of the issue?

  • A. The user has NOT configured the Salesforce mobile app to use My Domain for login.
  • B. The user has NOT been granted the "Enable Single Sign-on" permission.
  • C. The "Redirect to Identity Provider" option has NOT been selected in the My Domain configuration.
  • D. The "Redirect to Identity Provider" option has NOT been selected on the SAML configuration.

正解:A


質問 # 36
Universal Containers (UC) is concerned that having a self-registration page will provide a means for "bots" or unintended audiences to create user records, thereby consuming licenses and adding dirty data.
Which two actions should UC take to prevent unauthorized form submissions during the self-registration process? (Choose two.)

  • A. Use hidden fields populated via JavaScript events in the self-registration page.
  • B. Primarily use lookup and picklist fields on the self-registration page.
  • C. Use open-ended security questions and complex password requirements.
  • D. Require a CAPTCHA at the end of the self-registration process.

正解:C、D


質問 # 37
......

Salesforce Identity-and-Access-Management-Designer問題集カバー率リアル試験問題:https://jp.fast2test.com/Identity-and-Access-Management-Designer-premium-file.html

リアルIdentity-and-Access-Management-Designer問題集でSalesforce問題集PDF:https://drive.google.com/open?id=1GyhAUg2udg9dTwlP4iAw4i3qes4IhdDV


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어