
[2023年更新]合格できるIdentity-and-Access-Management-Designer試験にはリアルな問題解答
Identity-and-Access-Management-Designer試験問題ゲット最新[2023]と正解回答
Salesforce IdentityおよびAccess-Management-Designer認定は、Salesforce環境でのユーザー認証と承認の管理を担当する専門家向けに設計されています。この認定試験では、Salesforceアプリケーションとデータへの安全なアクセスの設計、実装、および維持における候補者の知識とスキルをテストします。
質問 # 30
universal container plans to develop a custom mobile app for the sales team that will use salesforce for authentication and access management. The mobile app access needs to be restricted to only the sales team.
What would be the recommended solution to grant mobile app access to sales users?
- A. Use the permission set license to assign the mobile app permission to sales users
- B. Use connected apps Oauth policies to restrict mobile app access to authorized users.
- C. Add a new identity provider to authenticate and authorize mobile users.
- D. Use a custom attribute on the user object to control access to the mobile app
正解:B
質問 # 31
Universal containers (UC) has decided to use identity connect as it's identity provider. UC uses active directory(AD) and has a team that is very familiar and comfortable with managing ad groups. UC would like to use AD groups to help configure salesforce users. Which three actions can AD groups control through identity connect? Choose 3 answers
- A. Custom permission assignment
- B. Permission sets assignment
- C. Granting report folder access
- D. Role Assignment
- E. Public Group Assignment
正解:B、D、E
質問 # 32
A real estate company wants to provide its customers a digital space to design their interior decoration options. To simplify the registration to gain access to the community site (built in Experience Cloud), the CTO has requested that the IT/Development team provide the option for customers to use their existing social-media credentials to register and access.
The IT lead has approached the Salesforce Identity and Access Management (IAM) architect for technical direction on implementing the social sign-on (for Facebook, Twitter, and a new provider that supports standard OpenID Connect (OIDC)).
Which two recommendations should the Salesforce IAM architect make to the IT Lead?
Choose 2 answers
- A. Use declarative registration handler process builder/flow to create, update users and contacts.
- B. Apex coding skills are needed for registration handler to create and update users.
- C. For supporting OIDC it is necessary to enable Security Assertion Markup Language (SAML) with Just-in-Time provisioning (JIT) and OAuth 2.0.
- D. Authentication provider configuration is required each social sign-on providers; and enable Authentication providers in community.
正解:B、D
質問 # 33
Northern Trail Outfitters is implementing a busmess-to-business (B2B) collaboration site using Salesforce Experience Cloud. The partners will authenticate with an existing identity provider and the solution will utilize Security Assertion Markup Language (SAML) to provide single sign-on to Salesforce. Delegated administration will be used in the Expenence Cloud site to allow the partners to administer their users' access.
How should a partner identity be provisioned in Salesforce for this solution?
- A. Create a person account.
- B. Create only a contact.
- C. Create a contactless user.
- D. Create a user and a related contact.
正解:D
質問 # 34
Universal Containers (UC) has a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a Connected App in Salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properly secure access to the app.
Which two solutions should be recommended? (Choose two.)
- A. Require High Assurance sessions in order to use the Connected App.
- B. Use Google Authenticator as an additional part of the login process.
- C. Disallow the use of Single Sign-on for any users of the mobile app.
- D. Set Login IP Ranges to the internal network for all of the app users' Profiles.
正解:A、B
質問 # 35
An Architect needs to set up a Facebook Authentication provider as a login option for a Salesforce Customer Community.
What portion of the authentication provider setup associates a Facebook user with a Salesforce user?
- A. Federation ID
- B. Consumer Key and Consumer Secret
- C. Apex Registration Handler
- D. User Info Endpoint URL
正解:C
質問 # 36
Universal Containers (UC) is successfully using Delegated Authentication for their Salesforce users. The service supporting Delegated Authentication is written in Java. UC has a new CIO that is requiring all company web services be REST-ful and written in .Net.
Which two considerations should the UC Architect provide to the new CIO? (Choose two.)
- A. Delegated Authentication will not work with REST services.
- B. Delegated Authentication will not work with a .Net service.
- C. Delegated Authentication will continue to work with REST services.
- D. Delegated Authentication will continue to work with a .Net service.
正解:A、D
質問 # 37
An identity architect is setting up an integration between Salesforce and a third-party system. The third-party system needs to authenticate to Salesforce and then make API calls against the REST API.
One of the requirements is that the solution needs to ensure the third party service providers connected app in Salesforce mini need for end user interaction and maximizes security.
Which OAuth flow should be used to fulfill the requirement?
- A. Web Server Flow
- B. Username-Password Flow
- C. User Agent Flow
- D. JWT Bearer Flow
正解:D
質問 # 38
Universal Containers (UC) wants to integrate a web application with Salesforce. The UC team has implemented the OAuth Web-Server Authentication Flow for authentication purposes.
Which two considerations should an Architect point out to UC? (Choose two.)
- A. The web server must be able to protect consumer secret.
- B. The web application should be hosted on a secure server.
- C. The flow will NOT provide an OAuth Refresh Token back to the server.
- D. The flow involves passing the user credentials back and forth.
正解:A、B
質問 # 39
Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers will utilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?
- A. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML to allow SSO.
- B. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
- C. Use SAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
- D. Use a nightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
正解:C
質問 # 40
Universal Containers (UC) uses Salesforce as a CRM and identity provider (IdP) for their Sales Team to seamlessly login to intemaJ portals. The IT team at UC is now evaluating Salesforce to act as an IdP for its remaining employees.
Which Salesforce license is required to fulfill this requirement?
- A. Identity Connect
- B. Identity Only
- C. Identity Verification
- D. External Identity
正解:B
質問 # 41
what item should an architect consider when designing a Delegated Authentication implementation?
- A. The web service should be able to accept one to four input method parameters.
- B. The web service should implement a custom password decryption method.
- C. The web service should be secured with TLS using Salesforce trusted certificates.
- D. The web service should use the salesforce Federation ID to identify the user.
正解:C
質問 # 42
Universal Containers (UC) is planning to add Wi-Fi enabled GPS tracking devices to its shipping containers so that the GPS coordinates data can be sent from the tracking device to its Salesforce production org via a custom API. The GPS devices have no direct user input or output capabilities.
Which OAuth flow should the identity architect recommend to meet the requirement?
- A. OAuth 2.0 Username-Password Flow for Special Scenarios
- B. OAuth 2.0 Asset Token Flow for Securing Connected Devices
- C. OAuth 2.0 Web Server Flow for Web App Integration
- D. OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration
正解:B
質問 # 43
Northern Trail Outfitters (NTO) is planning to implement a community for its customers using Salesforce Experience Cloud . Customers are not able to self-register. NTO would like to have customers set their own passwords when provided access to the community.
Which two recommendations should an identity architect make to fulfill this requirement?
Choose 2 answers
- A. Allow Password reset using the API to update Experience Cloud site membership.
- B. Add customers as contacts and add them to Experience Cloud site.
- C. Use Login Flows to allow users to reset password in Experience Cloud site.
- D. Enable Welcome emails while configuring the Experience Cloud site.
正解:A、C
質問 # 44
Universal Containers (UC) plans to use a SAML-based third-party IdP serving both of the Salesforce Partner Community and the corporate portal. UC partners will log in 65* to the corporate portal to access protected resources, including links to Salesforce resources. What would be the recommended way to configure the IdP so that seamless access can be achieved in this scenario?
- A. Set up the corporate portal as a Connected App in Salesforce and use the User Agent OAuth flow.
- B. Configure IdP-initiated SSO that passes the SAML token upon Salesforce resource access request.
- C. Set up the corporate portal as a Connected App in Salesforce and use the Web server OAuth flow.
- D. Configure SP-initiated SSO that passes the SAML token upon Salesforce resource access request.
正解:B
質問 # 45
Sales users at Universal containers use salesforce for Opportunity management. Marketing uses a third-party application called Nest for Lead nurturing that is accessed using username/password. The VP of sales wants to open up access to nest for all sales uses to provide them access to lead history and would like SSO for better adoption. Salesforce is already setup for SSO and uses Delegated Authentication. Nest can accept username/Password or SAML-based Authentication. IT teams have received multiple password-related issues for nest and have decided to set up SSO access for Nest for Marketing users as well. The CIO does not want to invest in a new IDP solution and is considering using Salesforce for this purpose. Which are appropriate license type choices for sales and marketing users, giving salesforce is using Delegated Authentication? Choose 2 answers
- A. Salesforce license for sales users and External Identity license for Marketing users
- B. Identity license for sales users and Identity connect license for Marketing users
- C. Salesforce license for sales users and Identity license for Marketing users
- D. Salesforce license for sales users and platform license for Marketing users.
正解:C、D
質問 # 46
Universal Containers is creating a web application that will be secured by Salesforce Identity using the OAuth 2.0 Web Server Flow uses the OAuth 2.0 authorization code grant type).
Which three OAuth concepts apply to this flow?
Choose 3 answers
- A. Verification URL
- B. Scopes
- C. Access Token
- D. Client Secret
正解:B、C、D
質問 # 47
Northern Trail Outfitters manages application functional permissions centrally as Active Directory groups. The CRM_Superllser and CRM_Reportmg_SuperUser groups should respectively give the user the SuperUser and Reportmg_SuperUser permission set in Salesforce. Salesforce is the service provider to a Security Assertion Markup Language (SAML) identity provider.
Mow should an identity architect ensure the Active Directory groups are reflected correctly when a user accesses Salesforce?
- A. Use the Apex Just-in-Time handler to query standard SAML attributes and set permission sets.
- B. Use a login flow to query custom SAML attributes and set permission sets.
- C. Use the Apex Just-in-Time handler to query custom SAML attributes and set permission sets.
- D. Use a login flow to query standard SAML attributes and set permission sets.
正解:C
質問 # 48
Universal Containers wants to secure its Salesforce APIs by using an existing Security Assertion Markup Language (SAML) configuration supports the company's single sign-on process to Salesforce, Which Salesforce OAuth authorization flow should be used?
- A. OAuth 2.0 User-Agent Flow
- B. OAuth 2.0 SAML Bearer Assertion Flow
- C. A SAML Assertion Row
- D. OAuth 2.0 JWT Bearer Flow
正解:C
質問 # 49
A company's external application is protected by Salesforce through OAuth. The identity architect for the project needs to limit the level of access to the data of the protected resource in a flexible way.
What should be done to improve security?
- A. Create custom scopes and assign to the connected app.
- B. Select "Admin approved users are pre-authonzed" and assign specific profiles.
- C. Leverage external objects and data classification policies.
- D. Define a permission set that grants access to the app and assign to authorized users.
正解:A
質問 # 50
Universal Containers (UC) has implemented SAML-based Single Sign-on for their Salesforce application and is planning to use the Salesforce mobile app. UC wants to ensure that Single Sign-on is used for accessing the Salesforce mobile app.
Which two recommendations should the Architect make? (Choose two.)
- A. Use the existing SAML SSO flow along with Web Server Flow.
- B. Configure the Salesforce App to use the My Domain URL.
- C. Configure the Embedded Web Browser to use My Domain URL.
- D. Use the existing SAML SSO flow along with User Agent Flow.
正解:B、D
質問 # 51
Universal Containers (UC) wants its closed Won opportunities to be synced to a Data Warehouse in near real time. UC has implemented Outbound Message to enable near real-time data sync. UC wants to ensure that communication between Salesforce and Target System is Secure. What Certificate is sent along with the Outbound Message?
- A. The default Client Certificate or a Certificate from Certificate and Key Management menu.
- B. The default Client Certificate from the Develop--> API Menu.
- C. The Self-Signed Certificates from the Certificate & Key Management menu.
- D. The CA-Signed Certificate from the Certificate and Key Management menu.
正解:A
質問 # 52
Universal Containers (UC) would like to enable self-registration for their Salesforce Partner Community Users. UC wants to capture some custom data elements from the partner user, and based on these data elements, wants to assign the appropriate Profile and Account values.
Which two actions should the Architect recommend to UC1
Choose 2 answers
- A. Configure Registration for Communities to use a custom Apex Controller.
- B. Modify the CommunitiesSelfRegController to assign the Profile and Account.
- C. Modify the SelfRegistration trigger to assign Profile and Account.
- D. Configure Registration for Communities to use a custom Visualforce Page.
正解:B、D
質問 # 53
Universal Containers (UC) has built a custom time tracking app for its employee. UC wants to leverage Salesforce Identity to control access to the custom app.
At a minimum, which Salesforce license is required to support this requirement?
- A. Identity Connect
- B. Identity Only
- C. Identity Verification
- D. External Identity
正解:B
質問 # 54
In a typical SSL setup involving a trusted party and a trusting party, what consideration should an Architect take into account when using digital certificates?
- A. Use of self-signed certificate leads to lower maintenance for trusting party because there is no trusted CA cert to maintain.
- B. Use of self-signed certificate leads to higher maintenance for trusted party because they have to act as the trusted CA.
- C. Use of self-signed certificate leads to lower maintenance for trusted party because multiple self-signed certs need to be maintained.
- D. Use of self-signed certificate leads to higher maintenance for trusting party because the cert needs to be added to their truststore.
正解:D
質問 # 55
......
この試験では、認証、承認、シングルサインオン(SSO)、アイデンティティフェデレーション、ユーザープロビジョニングなど、アイデンティティとアクセス管理に関連する広範なトピックをカバーしています。また、セキュリティのベストプラクティス、コンプライアンス要件、サードパーティシステムとの統合に関する質問も含まれます。
練習できるIdentity-and-Access-Management-Designer問題で認証試験問題集ガイド解答は練習専門PassTest:https://www.passtest.jp/Salesforce/Identity-and-Access-Management-Designer-shiken.html
無料Salesforce Identity-and-Access-Management-Designerテスト練習テスト問題試験問題集:https://drive.google.com/open?id=1E2g-O5sCj1ZBxHsv77eT1VAnbLITWX7i