最新の[2024年07月22日]Salesforce Identity-and-Access-Management-Architect日本語試験練習テスト最高成績で最速合格をゲットせよ!
これを使えば必ず合格させる問題集でSalesforce Identity-and-Access-Management-Architect日本語
質問 # 59
ユニバーサル コンテナー (UC) は、従業員がコラボレーションしてアイデアを投稿するために、従来の従業員ポータルを使用します。UC は、Salesforce のアイデアを投票と追跡の改善に使用することにしました。Salesforce でユーザーのプロビジョニングを回避するために、UC は従業員ポータルに投稿されたアイデアを API を介して Salesforce にプッシュすることにしました。UC は、接続に Oauth ユーザー名 - パスワード フローを使用して API ユーザーを使用することを決定します。Salesforce への接続を従業員ポータル サーバーのみに制限するにはどうすればよいですか?
- A. 従業員ポータルの IP アドレスをユーザー プロファイルのログイン IP 範囲に追加します。
- B. 従業員ポータルの IP アドレスを、接続されたアプリの信頼できる IP 範囲に追加します。
- C. 従業員ポータルが使用するユーザー専用のプロファイルを使用します。
- D. 従業員ポータル サーバーによって署名されたデジタル証明書を使用します。
正解:B
質問 # 60
Northern Trail Outfitters (NTO) には、セキュリティ アサーション マークアップ言語 (SAMi) や OAuth などのシングル サインオン標準をサポートしていない既存のカスタムの企業対消費者 (B2C) Web サイトがあります。NTO は、Salesforce Identity を使用して、Web サイトで新規顧客を登録および認証したいと考えています。
Web サイトのユーザー名/パスワード認証を提供するために、ID アーキテクトが使用する必要がある Salesforce の機能を 2 つ選択してください。
2つの答えを選択してください
- A. Identity Connect
- B. 埋め込みログイン
- C. 代理認証
- D. 接続されたアプリ
正解:B、C
解説:
Explanation
To register and authenticate new customers on the website using Salesforce Identity, the identity architect should use Delegated Authentication and Embedded Login. Delegated Authentication is a feature that allows Salesforce to delegate the authentication process to an external service, such as a custom website, instead of validating the username and password internally. Embedded Login is a feature that allows Salesforce to embed a login widget into any web page, such as a custom website, to enable users to log in with their Salesforce credentials. The other options are not relevant for this scenario. References: Delegated Authentication, Embedded Login
質問 # 61
アーキテクトは、ユニバーサル コンテナー用に SAML ベースの SSO を正常に構成しました。SSO は、ユニバーサル コンテナが新しいユーザーのバッチを手動で Salesforce に追加する 3 か月間機能しています。新しいユーザーが SSO を使用しようとすると、salesforce からエラーが表示されます。既存のユーザーは引き続き SSO を使用して Salesforce にアクセスできます。この動作の考えられる原因は何ですか?
- A. 新しいユーザーのプロファイルで SSO 権限が有効になっていません。
- B. 管理者が新しいユーザーの Salesforce パスワードをリセットするのを忘れました。
- C. 新しいユーザーのプロファイルでマイ ドメイン機能が有効になっていません。
- D. 新しいユーザー レコードのフェデレーション ID フィールドが正しく設定されていません
正解:D
質問 # 62
アイデンティティアーキテクトは、多国籍、マルチブランドの組織で働いています。組織と協力して顧客 ID およびアクセス管理の要件を理解するにつれて、アイデンティティ アーキテクトは、顧客のサブブランドごとにブランド エクスペリエンスが異なり、これらのブランド エクスペリエンスのそれぞれがログイン エクスペリエンスを通じて実行される必要があることを学びます。ユーザーがログインしているサブブランド。
組織に 150 を超えるサブブランドがある場合、スケーラビリティをサポートし、メンテナンス コストを削減するために、アーキテクトはどのソリューションを推奨する必要がありますか?
- A. Audiences を使用して各サブブランドのログイン エクスペリエンスをカスタマイズし、OAuth および Security Assertion Markup Language (SAML) フロー中にオーディエンス ID をコミュニティに渡します。
- B. サブブランドごとに個別の Salesforce 組織を作成して、各サブブランドがユーザーエクスペリエンスを完全に制御できるようにします。
- C. 各サブブランドに一意のエクスペリエンス ID を割り当て、エクスペリエンス ID を使用してログイン エクスペリエンスを動的にブランド化します。
- D. サブブランドごとにコミュニティ サブドメインを作成し、各コミュニティ サブドメインのログイン ページのルック アンド フィールをブランドに合わせてカスタマイズします。
正解:C
解説:
Explanation
To support scalability and reduce maintenance costs for a multinational, multi-brand organization, the architect should recommend assigning each sub-brand a unique Experience ID and using the Experience ID to dynamically brand the login experience. Experience ID is a parameter that can be used to identify different brands or experiences within a single Experience Cloud site (formerly known as Community). Dynamic branding is a feature that allows Experience Cloud sites to display different branding elements, such as logos, colors, or images, based on the Experience ID or other criteria. This solution can provide a consistent and personalized brand experience for each sub-brand without creating multiple subdomains or orgs. References:
Experience ID, Dynamic Branding for Experience Cloud Sites
質問 # 63
Universal Containers (UC) には、既存の e コマース プラットフォームがあり、新しい顧客コミュニティを実装しています。カスタマー エクスペリエンスに対する懸念から、顧客に両方のアプリケーションへの登録を強制することは望んでいません。e コマースの顧客の 25% がカスタマー コミュニティを利用すると予想されます。電子商取引プラットフォームは、SAML 応答を生成することができ、ユーザーを管理できる既存の REST-ful API を備えています。UC は、顧客コミュニティで e コマース ユーザーのアイデンティティをどのように作成する必要がありますか?
- A. 夜間のバッチ ETL ジョブを使用してカスタマー コミュニティと e コマース プラットフォームの間でユーザーを同期し、SAML を使用して SSO を許可します。
- B. 標準の Salesforce API を使用してコミュニティでユーザーを作成し、SAML を使用して SSO を許可します。
- C. ユーザーがカスタマー コミュニティに自己登録するときに e コマース REST API を使用してユーザーを作成し、SAML を使用して SSO を許可します。
- D. ユーザーが e コマース サイトからコミュニティにログインしようとしたときに、カスタマー コミュニティで SAML JIT を使用してユーザーを作成します。
正解:D
質問 # 64
Universal Containers (UC) は、クローズした商談をほぼリアルタイムでデータ ウェアハウスに同期したいと考えています。UC は、アウトバウンド メッセージを実装して、ほぼリアルタイムのデータ同期を可能にしました。UC は、Salesforce とターゲット システム間の通信が安全であることを確認したいと考えています。送信メッセージと一緒に送信される証明書は何ですか?
- A. デフォルトのクライアント証明書または [証明書と鍵の管理] メニューの証明書。
- B. [開発] --> [API] メニューのデフォルトのクライアント証明書。
- C. [証明書と鍵の管理] メニューの自己署名証明書。
- D. [証明書と鍵の管理] メニューの CA 署名付き証明書。
正解:B
質問 # 65
Northern Trail Outfitters (NTO) には、すべてのユーザー ログインに単一の多要素認証 (MFA) プロンプトが含まれるようにする必要があります。現在、ユーザーは、ユーザー名とパスワードを使用してログインするか、組み込みの MFA を含む NTO の企業 ID プロバイダーに対してシングル サインオンを介してログインするかを選択できます。
この要件を満たすのはどの構成ですか?
- A. すべての従業員プロファイルについて、[ログイン時に必要なセッション レベル] を [高保証] に設定し、企業 ID プロバイダーを組織のセッション セキュリティ レベルの [高保証] リストに追加します。
- B. 「ユーザー インターフェイス ログイン用の MFA」を含む権限セットを作成し、すべての従業員に割り当てます。
- C. [設定] -> [本人確認] から組織の「ユーザー インターフェイス ログインの MFA」を有効にします。
- D. MFA を適用するカスタム ログイン フローを作成し、権限セットに割り当てます。次に、権限セットをすべての従業員に割り当てます。
正解:C
質問 # 66
Unversal Containers (UC) の IT セキュリティ担当者は、ユーザーを標的とした最近のフィッシング詐欺を懸念しており、ログイン保護のレイヤーを追加したいと考えています。この問題に対処するためにアーキテクトは何を推奨すべきですか?
- A. Salesforce でパスワードの複雑さの要件を増やします。
- B. 2 段階認証で Salesforce Authenticator モバイルアプリを使用する
- C. 企業 ID ストアを使用してシングル サインオンを実装します。
- D. セッションを発信元の IP アドレスにロックします。
正解:B
解説:
Explanation
The Salesforce Authenticator mobile app adds an extra layer of security for online accounts with two-factor authentication. It allows users to respond to push notifications or use location services to verify their logins and other account activity1. This can help prevent phishing scams and unauthorized access.
References: Salesforce Authenticator, Salesforce Authenticator: Mobile App Security Features, Salesforce Authenticator
質問 # 67
Northern Trail Outfitters (NTO) は、Experience Cloud を使用してディストリビューター向けのパートナー ポータルを展開することを計画しています。NTO は、外部 ID プロバイダー (idP) を使用し、パートナーがポータルへのアクセスを登録できるようにしたいと考えています。Salesforce とのアカウントの重複を避けるために、各パートナーは 1 回だけ登録できるようにする必要があります。
アイデンティティ アーキテクトは、パートナーを作成するために何を推奨する必要がありますか?
- A. Experience Cloud でカスタム ページを作成して、パートナーを Experience Cloud および Ping ID ストアに自己登録します。
- B. Experience Cloud の自己登録ページを使用してパートナーを正常に作成したら、Ping で ID を作成します。
- C. ポータルでカスタム Web ページを作成し、公開された API を使用して IdP および Experience Cloud でユーザーを作成します。
- D. パートナーが IdP を介して登録し、API を介して Salesforce でパートナー ユーザーを作成できるようにします。
正解:A
質問 # 68
ユニバーサル コンテナ (UC) のアイデンティティ アーキテクトは、新しい Experience Cloud サイトのライセンス タイプを推奨する必要があります。このライセンス タイプは、外部パートナー (配信プロバイダー) がアカウントの確認と更新、UC から提供されたファイルのダウンロード、カレンダーからの集荷予定日の取得に使用されます。 .
UC は、Salesforce 本番組織をこれらのユーザーの ID プロバイダーとして使用しており、個々のユーザーの予想数は 250 万人で、1 か月あたり 1,350 万の一意のログインがあります。
要件を満たすために使用する必要があるライセンスの種類は次のうちどれですか?
- A. 外部アプリ ライセンス
- B. パートナー コミュニティ ログイン ライセンス
- C. パートナー コミュニティ ライセンス
- D. カスタマー コミュニティ プラス ログイン ライセンス
正解:D
質問 # 69
ある不動産会社は、顧客が室内装飾のオプションを設計できるデジタル スペースを提供したいと考えています。
コミュニティ サイト (Experience Cloud に組み込まれている) にアクセスするための登録を簡素化するために、CTO は、顧客が既存のソーシャル メディア資格情報を使用して登録およびアクセスするオプションを提供するよう IT/開発チームに要求しました。
IT リーダーは、ソーシャル サインオン (Facebook、Twitter、および標準の OpenID Connect (OIDC) をサポートする新しいプロバイダ) の実装に関する技術的な方向性について、Salesforce の ID およびアクセス管理 (IAM) アーキテクトにアプローチしました。
Salesforce IAM アーキテクトが IT リードに行うべき推奨事項を 2 つ選択してください。
2つの答えを選択してください
- A. OIDC をサポートするには、セキュリティ アサーション マークアップ言語 (SAML) とジャスト イン タイム プロビジョニング (JIT) および OAuth 2.0 を有効にする必要があります。
- B. 宣言型の登録ハンドラー プロセス ビルダー/フローを使用して、ユーザーと連絡先を作成、更新します。
- C. 登録ハンドラーがユーザーを作成および更新するには、Apex コーディングのスキルが必要です。
- D. ソーシャルサインオン プロバイダーごとに認証プロバイダーの構成が必要です。コミュニティで認証プロバイダーを有効にします。
正解:C、D
解説:
Explanation
Authentication provider configuration and Apex coding skills are two recommendations that the Salesforce IAM architect should make to the IT Lead. Authentication providers are used to configure social sign-on providers, such as Facebook, Twitter, and any OpenID Connect compliant provider. Apex coding skills are needed for registration handlers, which are custom classes that create and update users based on social sign-on data. References: Authentication Providers, Registration Handlers
質問 # 70
展示を参照してください。
Outfitters (NTO) は、Experience Cloud を Heroku 上のアプリケーションの ID として使用しています。Heroku 上のアプリケーションは、Northern Trail Shoes と Northern Trail Shirts の 2 つのブランドを処理できる必要があります。
ユーザーは、コミュニティにログインする前に、Heroku で 2 つのブランドのいずれかを選択する必要があります。その後、アプリは Salesforce Experience Cloud サイトで OAuth2.0 を使用して認証を実行します。
NTO は、承認前に Heroku で選択されたユーザーのブランド設定に基づいて、ログイン ページの画像を動的にレンダリングすることを確認したいと考えています。
上記の要件を満たすためにアイデンティティアーキテクトは何をすべきですか?
- A. ブランドごとに異なるコミュニティを作成し、Apex で記述されたカスタム ログイン コントローラを使用して、ユーザーを適切なコミュニティにリダイレクトします。
- B. Experience Builder を使用して複数のログイン画面を作成し、実行時にログイン フローを使用してさまざまなログイン画面にルーティングします。
- C. community-url/services/oauth2/authorize/cookie_value に承認要求を送信して、サードパーティ サービスを承認します。
- D. community-url/services/oauth2/authonze/expid_value に承認要求を送信して、サードパーティ サービスを承認します。
正解:D
解説:
Explanation
OAuth 2.0 is an open standard for authorization that allows a third-party application to obtain limited access to a protected resource on behalf of a user. To authorize a third-party service using OAuth 2.0 with the Salesforce Experience Cloud site, the identity architect should do the following steps:
Create a connected app for the third-party service in Salesforce. A connected app is an application that integrates with Salesforce using APIs and standard protocols, such as SAML, OAuth, and OpenID Connect. To create a connected app, you need to provide the basic information, such as the app name, logo URL, contact email, and API name. You also need to enable OAuth and configure the OAuth settings, such as the callback URL, the scopes, and the policies.
Authorize the third-party service by sending authorization requests to the community-url/services/oauth2/authorize/expid_value. This is a special endpoint that allows you to specify an experience ID (expid) as a query parameter in the authorization request. The experience ID is a unique identifier for each experience (community or site) in Salesforce. By using this endpoint, you can dynamically render the login page images based on the user's brand preference selected in the third-party service before authorization.
References:
OAuth 2.0
OAuth 2.0 Web Server Authentication Flow
Connected Apps
Create a Connected App
Experience ID
Authorize Apps with OAuth
質問 # 71
Northern Trail Outfitters (NTO) の従業員は、カスタムのオンプレミス ヘルプデスク アプリケーションを使用して、Salesforce を含むさまざまなオンプレミスおよびクラウド アプリケーションに付与されたアクセスを要求、承認、通知、および追跡します。
現在、Salesforce はユーザーの認証に使用されています。
Salesforce ユーザーがヘルプデスク アプリケーションで承認されたらすぐに、NTO は承認済みのプロファイルと権限セットを使用してどのようにプロビジョニングする必要がありますか?
- A. ログイン フローを使用してヘルプデスクに問い合わせ、ユーザー ステータスを検証します。
- B. ヘルプデスクに IdP 開始の Just-m-Time プロビジョニング セキュリティ アサーション マークアップ言語フローを開始してもらいます。
- C. Salesforce SOAP または REST API へのリモート コールインを実行する統合を構築します。
- D. Salesforce Connect を使用して、ヘルプデスク アプリケーションと統合します。
正解:A
質問 # 72
Salesforce の顧客は、Sales Cloud と、コール センター エージェント用のカスタム価格設定アプリケーションを実装しています。
エンタープライズ シングル サインオン ソリューションを使用して、ユーザーを認証し、すべてのアプリケーションにサインインします。お客様には次の要件があります。
1. 開発チームは、Canvas アプリを使用して価格設定アプリケーションをエージェントに公開することを決定しました。
2. エージェントは、価格設定アプリケーションにログインしなくても Canvas アプリにアクセスできる必要があります。
Canvas アプリがユーザーのログインを開始するためのサポートを提供するために、ID アーキテクトが検討すべきオプションはどれですか?
2つの答えを選択してください
- A. 接続アプリケーションで SAML を有効にし、Security Assertion Markup Language (SAML) Initiation Method を Service Provider Initiated として有効にします。
- B. 接続アプリの設定で「キャンバスの個人用アプリとして有効にする」を選択します。
- C. キャンバス アプリを接続アプリとして構成し、管理者が承認したユーザーを事前承認済みとして設定します。
- D. 価格設定アプリケーションに必要な OAuth スコープを使用して、接続アプリケーションで OAuth 設定を有効にします。
正解:A、C
解説:
Explanation
To allow agents to access the Canvas app without needing to log in to the pricing application, the identity architect should consider two options:
Configure the Canvas app as a connected app and set Admin-approved users as pre-authorized. A connected app is a framework that enables an external application to integrate with Salesforce using APIs and standard protocols. A Canvas app is a type of connected app that allows an external application to be embedded within Salesforce. By setting Admin-approved users as pre-authorized, the identity architect can control which users can access the Canvas app by assigning profiles or permission sets to the connected app.
Enable SAML in the connected app and Security Assertion Markup Language (SAML) Initiation Method as Service Provider Initiated. SAML is a protocol that allows users to authenticate and authorize with an external identity provider and access Salesforce resources. By enabling SAML in the connected app, the identity architect can use Salesforce as a service provider (SP) and the pricing application as an identity provider (IdP) for single sign-on (SSO). By setting SAML Initiation Method as Service Provider Initiated, the identity architect can initiate the SSO process from Salesforce and send a SAML request to the pricing application. References: Connected Apps, Canvas Apps, SAML Single Sign-On Settings
質問 # 73
ユニバーサル コンテナ (UC) には、salesforce REST API を呼び出すモバイル アプリケーションがあります。ユーザーがアプリを使用するたびに資格情報を入力する必要がないようにするために、UC は、Salesforce 接続アプリの一部として更新トークンの使用を有効にし、モバイル アプリを更新して更新トークンを利用できるようにしました。更新トークンを有効にした後でも、ユーザーは、資格情報を 1 日 1 回入力する必要があると不満を漏らしています。問題の最も可能性の高い原因は何ですか?
- A. Oauth 承認は、夜間のバッチ ジョブによって取り消されています。
- B. ユーザーは、自分の資格情報を記憶するためのチェック ボックスをオンにするのを忘れています。
- C. アプリが 24 時間に要求するアクセス トークンが多すぎます
- D. Salesforce で更新トークンの有効期限ポリシーが正しく設定されていない
正解:D
解説:
Explanation
The most likely cause of the issue is that the refresh token expiration policy is set incorrectly in Salesforce. A refresh token is a credential that allows a connected app to obtain a new access token when the previous one expires1. The refresh token expiration policy determines how long a refresh token is valid for2. If the policy is set to a short duration, such as 24 hours, the users have to enter their credentials once a day to get a new refresh token. To prevent this, the policy should be set to a longer duration, such as "Refresh token is valid until revoked" or "Refresh token expires after 90 days of inactivity"2.
References: OAuth 2.0 Refresh Token Flow, Manage OAuth Access Policies for a Connected App
質問 # 74
Identity Connect が可能な 2 つのステートメントはどれですか? 2つの答えを選択してください
- A. 自動化されたユーザー同期と無効化。
- B. ID プロバイダーが開始する SSO とサービス プロバイダーが開始する SSO の両方をサポートします。
- C. 複数の Active Directory サーバーに接続する複数の組織をサポートします。
- D. Salesforce 権限セットのライセンス割り当ての同期。
正解:A、B
質問 # 75
ID アーキテクトのクライアントには、独自の ID プロバイダー (IdP) があります。Salesforce は、サービス プロバイダー (SP) として使用されます。IT の責任者は、SP が開始するシングル サインオン (SSO) 中に Security Assertion Markup Language (SAML) 要求の内容が変更されるのではないかと心配しています。
SP と IdP の間に追加の信頼があることを確認するために、ID アーキテクトは何を推奨する必要がありますか?
- A. 認証局 (CA) の署名付き証明書を使用して SAML リクエストを暗号化し、IdP で復号化します。
- B. SSO 設定ページで、[署名証明書の要求] フィールドに自己署名証明書があることを確認します。
- C. IDP と SP の間に HTTPS 接続があることを確認します。
- D. 発行者とアサーション コンシューマ サービス (ACS) の URL が、SP と IDP の間で構成されたプロパティであることを確認します。
正解:A
解説:
Explanation
Encrypting the SAML Request using a CA signed certificate and decrypting it on the IdP ensures that the request content is not altered or tampered with during transit. This also adds an extra layer of security and trust between the SP and the IdP. References: SAML Single Sign-On Overview, SAML Assertion Encryption
質問 # 76
ユニバーサル コンテナー (UC) は委任認証を設定して、従業員が会社の資格情報を使用してログインできるようにします。UC のセキュリティ チームは、企業のログイン サービスがインターネット上に公開されるリスクを懸念しており、ログイン サービスとセールスフォースの間に信頼できる信頼メカニズムを配置するよう求めています。ログインサービスとセールスフォース間の信頼できる接続を可能にするために、アーキテクトはどのメカニズムを導入する必要がありますか?
- A. DMZ 内にログイン サービス用のプロキシ サーバーをセットアップします。
- B. パスワードに Salesforce セキュリティ トークンの使用を要求します。
- C. SSL を使用してシステム間の相互認証を強制します。
- D. ログイン ヘッダーのコールアウトにクライアント ID とクライアント シークレットを含めます。
正解:B
質問 # 77 
製薬会社には、Salesforce と統合したいオンプレミス アプリケーション (図を参照) があります。
IT 責任者は、会社のオンプレミス アプリケーション エンドポイントにアクセスするために、信頼できる証明書チェーンを持つ証明書を要求に含める必要があることを確認したいと考えています。
この要件を満たすために、アイデンティティ アーキテクトは何をすべきでしょうか?
- A. サードパーティの証明書を Salesforce からオンプレミス サーバーにアップロードします。
- B. オープン SSL を使用して自己署名証明書を生成し、オンプレミス アプリにアップロードします。
- C. Salesforce の IP 範囲からのトラフィックを許可するように会社のファイアウォールを構成します。
- D. Salesforce で認証局の署名付き証明書を生成し、オンプレミス アプリケーションの Truststore にアップロードします。
正解:C
質問 # 78
Universal Containers (UC) は、サードパーティの報酬計算システムを Salesforce と統合して報酬を計算したいと考えています。報酬はスケジュールに基づいて計算され、Salesforce に反映されます。Salesforce と報酬計算システムの統合は安全である必要があります。このシナリオで OAuth フローを使用するための 2 つの推奨される方法はどれですか。2つの答えを選ぶ
- A. OAuth JWT Bearer Token Flow
- B. OAuth ユーザー名パスワード フロー
- C. OAuth リフレッシュ トークン フロー
- D. OAuth SAML ベアラー アサーション フロー
正解:A、D
解説:
Explanation
OAuth is an open-standard protocol that allows a client app to access protected resources on a resource server, such as Salesforce API, by obtaining an access token from an authorization server. OAuth supports different types of flows, which are ways of obtaining an access token. For integrating a third-party Reward Calculation system with Salesforce securely, two recommended practices for using OAuth flow are:
OAuth SAML Bearer Assertion Flow, which allows the client app to use a SAML assertion issued by a trusted identity provider to request an access token from Salesforce. This flow does not require the client app to store any credentials or secrets, and leverages the existing SSO infrastructure between Salesforce and the identity provider.
OAuth JWT Bearer Token Flow, which allows the client app to use a JSON Web Token (JWT) signed by a private key to request an access token from Salesforce. This flow does not require any user interaction or consent, and uses a certificate to verify the identity of the client app.
Verified References: [OAuth 2.0 SAML Bearer Assertion Flow for Server-to-Server Integration], [OAuth 2.0 JWT Bearer Token Flow for Server-to-Server Integration]
質問 # 79
Universal Containers は、外部 ID プロバイダーと企業 ID ストアを使用して、Salesforce 組織にシングル サインオンを実装したいと考えています。
ディープリンクをサポートするには、どのタイプの認証フローが必要ですか?
- A. Web サーバー OAuth SSO フロー
- B. サービス プロバイダーが開始する SSO
- C. ID プロバイダーの StartURL
- D. ID プロバイダーが開始する SSO
正解:B
解説:
Explanation
Single sign-on (SSO) is an authentication method that enables users to access multiple applications with one login and one set of credentials4. There are two types of SSO flows that can be used with Salesforce as the service provider (SP) and an external identity provider (IdP)5:
Service-provider-initiated SSO: The user requests a resource from the SP, such as a Salesforce URL.
The SP redirects the user to the IdP for authentication. The IdP authenticates the user and sends a SAML response to the SP. The SP validates the SAML response and grants access to the user5. This type of SSO flow supports deep linking, which means that the user can access a specific page within Salesforce without logging in again6.
Identity-provider-initiated SSO: The user logs in to the IdP and selects an app from a list of available apps. The IdP sends a SAML response to the SP. The SP validates the SAML response and grants access to the user5. This type of SSO flow does not support deep linking, which means that the user can only access the default landing page of Salesforce6.
References:
Single Sign-On
SAML SSO Flows
Deep Linking
質問 # 80
Universal Containers (UC) は顧客コミュニティを構築しており、顧客は Facebook 資格情報を使用して認証できるようになります。ユーザーが facebook を使用して初めて認証するとき、UC は会計システムで自動的に作成された顧客アカウントを希望します。会計システムには、アカウントを作成するために Salesforce からアクセスできる Web サービスがあります。アーキテクトはこれらの要件をどのように満たすことができますか?
- A. Facebook からのサインオン プロセスを管理するカスタム アプリケーションを Heroku で作成します。
- B. 認証プロバイダの登録ハンドラに Apex コールアウトを追加します。
- C. JIT プロビジョニングを使用して、会計システムでアカウントを自動的に作成します。
- D. OAuth JWT フローを使用して、Salesforce から会計システムにデータを渡します。
正解:B
解説:
Explanation
The best option for UC to meet the requirements is to add an Apex callout in the registration handler of the authorization provider. An authorization provider is a configuration in Salesforce that allows users to log in with an external authentication provider, such as Facebook. A registration handler is an Apex class that implements the Auth.RegistrationHandler interface and defines the logic for creating or updating a user account when a user logs in with an external authentication provider. An Apex callout is a method that invokes an external web service from Apex code. By adding an Apex callout in the registration handler, UC can create a customer account in their accounting system by calling the web service that is accessible to Salesforce. This option enables UC to automate the account creation process and integrate with their existing accounting system. The other options are not optimal for this scenario. Creating a custom application on Heroku that manages the sign-on process from Facebook would require UC to develop and maintain a separate application and infrastructure, which could increase complexity and cost. Using JIT provisioning to automatically create the account in the accounting system would require UC to configure Facebook as a SAML identity provider, which is not supported by Facebook. Using OAuth JWT flow to pass the data from Salesforce to the accounting system would require UC to obtain an OAuth token from the accounting system and use it to make API calls, which could introduce security and performance issues. References: [Authorization Providers],
[Create a Registration Handler Class], [Auth.RegistrationHandler Interface], [Apex Callouts], [Facebook as SAML Identity Provider], [OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration]
質問 # 81
Universal Containers (UC) は、サードパーティの IdP を使用して内部の Salesforce ユーザーに SAML SSO を実装したいと考えています。いくつかの評価の後、UC は、Salesforce 組織の [私のドメイン] を SSO で設定しないことを決定しました。
その決定は、SSO の実装にどのような影響を与えますか?
- A. SP または IdP によって開始される SSO は機能しません。
- B. SP によって開始された SSO は機能しません
- C. IdP による SSO は機能しません。
- D. SP または IdP が開始する SSO のいずれかが機能します。
正解:A
質問 # 82
......
正真正銘のベスト問題集資料を使おうIdentity-and-Access-Management-Architect日本語オンライン練習試験:https://www.passtest.jp/Salesforce/Identity-and-Access-Management-Architect-JPN-shiken.html