2023年最新のSalesforce Identity-and-Access-Management-Architect問題集と試験テストエンジン [Q49-Q74]

Share

2023年最新のPassTest Salesforce Identity-and-Access-Management-Architect問題集と試験テストエンジン

Salesforce Identity-and-Access-Management-Architect問題集にはリアル試験問題解答


Salesforce IAM Architectsは、Salesforceを使用する組織向けの安全なアクセスおよびID管理ソリューションの設計と実装を担当しています。彼らは、Salesforceのセキュリティモデルと、クライアントの特定のニーズを満たすカスタムソリューションを設計する機能を深く理解することが期待されています。認定試験は、ID管理、ア​​クセス管理、シングルサインオン、セキュリティプロトコルなど、幅広いトピックに関する候補者をテストします。

 

質問 # 49
universal container plans to develop a custom mobile app for the sales team that will use salesforce for authentication and access management. The mobile app access needs to be restricted to only the sales team.
What would be the recommended solution to grant mobile app access to sales users?

  • A. Use connected apps Oauth policies to restrict mobile app access to authorized users.
  • B. Use a custom attribute on the user object to control access to the mobile app
  • C. Add a new identity provider to authenticate and authorize mobile users.
  • D. Use the permission set license to assign the mobile app permission to sales users

正解:A


質問 # 50
A global company's Salesforce Identity Architect is reviewing its Salesforce production org login history and is seeing some intermittent Security Assertion Markup Language (SAML SSO) 'Replay Detected and Assertion Invalid' login errors.
Which two issues would cause these errors?
Choose 2 answers

  • A. The certificate loaded into SSO configuration does not match the certificate used by the IdP.
  • B. The subject element is missing from the assertion sent to salesforce.
  • C. The current time setting of the company's identity provider (IdP) and Salesforce platform is out of sync by more than eight minutes.
  • D. The assertion sent to 5alesforce contains an assertion ID previously used.

正解:C、D

解説:
Explanation
A SAML SSO 'Replay Detected and Assertion Invalid' error occurs when Salesforce detects that the same assertion has been used more than once within the validity period. This can happen if the assertion ID is reused by the IdP or if the assertion is resent by the user. Another possible cause is that the time settings of the IdP and Salesforce are not synchronized, which can result in an assertion being valid for a shorter or longer period than expected. References: SAML Single Sign-On Settings, Troubleshoot SAML Single Sign-On


質問 # 51
Universal containers (UC) has an e-commerce website while customers can buy products, make payments, and manage their accounts. UC decides to build a customer Community on Salesforce and wants to allow the customers to access the community for their accounts without logging in again. UC decides to implement ansp-Initiated SSO using a SAML-BASED complaint IDP. In this scenario where salesforce is the service provider, which two activities must be performed in salesforce to make sp-Initiated SSO work? Choose 2 answers

  • A. Configure Delegated Authentication
  • B. Create a connected App
  • C. Configure SAML SSO settings.
  • D. Set up my domain

正解:C、D


質問 # 52
A global fitness equipment manufacturer is planning to sell fitness tracking devices and has the following requirements:
1) Customer purchases the device.
2) Customer registers the device using their mobile app.
3) A case should automatically be created in Salesforce and associated with the customers account in cases where the device registers issues with tracking.
Which OAuth flow should be used to meet these requirements?

  • A. OAuth 2.0 User-Agent Flow
  • B. OAuth 2.0 Username-Password Flow
  • C. OAuth 2.0 Asset Token Flow
  • D. OAuth 2.0 SAML Bearer Assertion Flow

正解:C


質問 # 53
which three are features of federated Single Sign-on solutions? Choose 3 answers

  • A. It establishes trust between Identity store and service provider.
  • B. It improves affiliated applications adoption rates.
  • C. It solves all identity and access management problems.
  • D. It federates credentials control to authorized applications.
  • E. It enables quick and easy provisioning and deactivating of users.

正解:A、C、E


質問 # 54
Northern Trail Outfitters (NTO) is planning to implement a community for its customers using Salesforce Experience Cloud . Customers are not able to self-register. NTO would like to have customers set their own passwords when provided access to the community.
Which two recommendations should an identity architect make to fulfill this requirement?
Choose 2 answers

  • A. Allow Password reset using the API to update Experience Cloud site membership.
  • B. Enable Welcome emails while configuring the Experience Cloud site.
  • C. Add customers as contacts and add them to Experience Cloud site.
  • D. Use Login Flows to allow users to reset password in Experience Cloud site.

正解:A、D


質問 # 55
What are three capabilities of Delegated Authentication? Choose 3 answers

  • A. It can connect to SOAP services.
  • B. It can connect to REST services.
  • C. It can be assigned by Custom Permissions.
  • D. It can be assigned by Permission Sets.
  • E. It can be assigned by Profiles.

正解:A、B、D


質問 # 56
Containers (UC) uses an internal system for recruiting and would like to have the candidates' info available in the Salesforce automatically when they are selected. UC decides to use OAuth to connect to Salesforce from the recruiting system and would like to do the authentication using digital certificates. Which two OAuth flows should be considered to meet the requirement? Choose 2 answers

  • A. SAML Bearer Assertion flow
  • B. JWT Bearer Token flow
  • C. Refresh Token flow
  • D. Web Service flow

正解:A、B


質問 # 57
Universal Containers (UC) implemented SSO to a third-party system for their Salesforce users to access the App Launcher. UC enabled "User Provisioning" on the Connected App so that changes to user accounts can be synched between Salesforce and the third party system. However, UC quickly notices that changes to user roles in Salesforce are not getting synched to the third-party system. What is the most likely reason for this behaviour?

  • A. Salesforce roles have more than three levels in the role hierarchy.
  • B. Required operation(s) was not mapped in User Provisioning Settings.
  • C. The Approval queue for User Provisioning Requests is unmonitored.
  • D. User Provisioning for Connected Apps does not support role sync.

正解:D


質問 # 58
Universal Containers (UC) is planning to add Wi-Fi enabled GPS tracking devices to its shipping containers so that the GPS coordinates data can be sent from the tracking device to its Salesforce production org via a custom API. The GPS devices have no direct user input or output capabilities.
Which OAuth flow should the identity architect recommend to meet the requirement?

  • A. OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration
  • B. OAuth 2.0 Asset Token Flow for Securing Connected Devices
  • C. OAuth 2.0 Web Server Flow for Web App Integration
  • D. OAuth 2.0 Username-Password Flow for Special Scenarios

正解:B

解説:
Explanation
OAuth 2.0 Asset Token Flow is the flow that allows connected devices to request an asset token from Salesforce. The device obtains an access token and an actor token, and uses them to create an asset token. This flow enables efficient token exchange and automatic linking of devices to Service Cloud Asset records.
References: OAuth 2.0 Asset Token Flow for Securing Connected Devices, OAuth Authorization Flows


質問 # 59
Universal Containers (UC) has a classified information system that its call center team uses only when they are working on a case with a record type "Classified". They are only allowed to access the system when they own an open "Classified" case, and their access to the system is removed at all other times. They would like to implement SAML SSO eith Salesforce as the Idp, and automatically allow or deny the staff's access to the classified information system based on whether they currently own an open "Classified" case record when they try to access the system using SSO. What is the recommended solution for automatically allowing or denying the access to the classified information system based on the open "classified" case record criteria?

  • A. Use Apex trigger on case to dynamically assign permission Sets that Grant access when an user is assigned with an open "Classified" case, and remove it when the case is closed.
  • B. Use a Common Connected App Handler using Apex to dynamically allow access to the system based on whether the staff owns any open "Classified" Cases.
  • C. Use Custom SAML JIT Provisioning to dynamically query the user's open "Classified" cases when attempting to access the classified information system.
  • D. Use Salesforce reports to identify users that currently owns open "Classified" cases and should be granted access to the Classified information system.

正解:B


質問 # 60
Refer to the exhibit.

Outfitters (NTO) is using Experience Cloud as an Identity for its application on Heroku. The application on Heroku should be able to handle two brands, Northern Trail Shoes and Northern Trail Shirts.
A user should select either of the two brands in Heroku before logging into the community. The app then performs Authorization using OAuth2.0 with the Salesforce Experience Cloud site.
NTO wants to make sure it renders login page images dynamically based on the user's brand preference selected in Heroku before Authorization.
what should an identity architect do to fulfill the above requirements?

  • A. Authorize third-party service by sending authorization requests to the community-url/services/oauth2/authonze/expid_value.
  • B. For each brand create different communities and redirect users to the appropriate community using a custom Login controller written in Apex.
  • C. Create multiple login screens using Experience Builder and use Login Flows at runtime to route to different login screens.
  • D. Authorize third-party service by sending authorization requests to the community-url/services/oauth2/authorize/cookie_value.

正解:A


質問 # 61
Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the OAuth 2.0 user-agent flow (this flow uses the OAuth 2.0 implicit grant type).
Which three OAuth concepts apply to this flow?
Choose 3 answers

  • A. Authorization Code
  • B. Client ID
  • C. Verification Code
  • D. Scopes
  • E. Refresh Token

正解:B、D、E


質問 # 62
A company with 15,000 employees is using Salesforce and would like to take the necessary steps to highlight or curb fraudulent activity.
Which tool should be used to track login data, such as the average number of logins, who logged in more than the average number of times and who logged in during non-business hours?

  • A. Login Inspector
  • B. Login History
  • C. Login Forensics
  • D. Login Report

正解:C


質問 # 63
Which two statements are capable of Identity Connect? Choose 2 answers

  • A. Automated user synchronization and de-activation.
  • B. Supports both Identity-Provider-Initiated and Service-Provider-Initiated SSO.
  • C. Synchronization of Salesforce Permission Set Licence Assignments.
  • D. Support multiple orgs connecting to multiple Active Directory servers.

正解:A、B


質問 # 64
Universal containers (UC) would like to enable SSO between their existing Active Directory infrastructure and salesforce. The it team prefers to manage all users in Active Directory and would like to avoid doing any initial setup of users in salesforce directly, including the correct assignment of profiles, roles and groups.
Which two optimal solutions should UC use to provision users in salesforce? Choose 2 answers

  • A. Use Identity connect to sync users from Active Directory to salesforce
  • B. Use the salesforce REST API to sync users from active directory to salesforce
  • C. Use Active Directory Federation Services to sync users from active directory to salesforce.
  • D. Use an app exchange product to sync users from Active Directory to salesforce.

正解:A、D

解説:
Explanation
To provision users in Salesforce from Active Directory without doing any initial setup of users in Salesforce, UC can use an app exchange product or Identity Connect. An app exchange product is a third-party application that can synchronize users and groups from Active Directory to Salesforce using a web-based interface1. Identity Connect is a desktop application that can synchronize users and groups from Active Directory to Salesforce using a graphical user interface2. Both solutions can also map Active Directory attributes to Salesforce fields and assign profiles, roles, and permission sets to users12.
References: Active Directory Integration with Salesforce, Identity Connect


質問 # 65
Northern Trail Outfitters (NTO) has a requirement to ensure all user logins include a single multi-factor authentication (MFA) prompt. Currently, users are allowed the choice to login with a username and password or via single sign-on against NTO's corporate Identity Provider, which includes built-in MFA.
Which configuration will meet this requirement?

  • A. Create a custom login flow that enforces MFA and assign it to a permission set. Then assign the permission set to all employees.
  • B. Create and assign a permission set to all employees that includes "MFA for User Interface Logins."
  • C. Enable "MFA for User Interface Logins" for your organization from Setup -> Identity Verification.
  • D. For all employee profiles, set the Session Level Required at Login to High Assurance and add the corporate identity provider to the High Assurance list for the org's Session Security Levels.

正解:C

解説:
Explanation
Enabling "MFA for User Interface Logins" for the organization is the simplest way to ensure that all user logins include a single MFA prompt. This setting applies to both direct logins and SSO logins, and overrides any other MFA settings at the profile or permission set level. References: Enable MFA for Direct User Logins, Everything You Need to Know About MFA Auto-Enablement and Enforcement


質問 # 66
Universal containers wants to build a custom mobile app connecting to salesforce using Oauth, and would like to restrict the types of resources mobile users can access. What Oauth feature of Salesforce should be used to achieve the goal?

  • A. Refresh Tokens
  • B. Mobile pins
  • C. Scopes
  • D. Access Tokens

正解:C


質問 # 67
Universal containers (UC) has implemented ansp-Initiated SAML flow between an external IDP and salesforce. A user at UC is attempting to login to salesforce1 for the first time and is being prompted for salesforce credentials instead of being shown the IDP login page. What is the likely cause of the issue?

  • A. The "Redirect to Identity Provider" option has been selected in the my domain configuration.
  • B. The "Redirect to identity provider" option has not been selected the SAML configuration.
  • C. The user has not configured the salesforce1 mobile app to use my domain for login
  • D. The user has not been granted the "Enable single Sign-on" permission

正解:C

解説:
Explanation
B is correct because the user has not configured the Salesforce1 mobile app to use My Domain for login, which is the likely cause of the issue. The My Domain URL is used to redirect the user to the identity provider's login page and initiate the SP-Initiated SAML flow. If the user does not configure the Salesforce1 mobile app to use My Domain for login, they will be prompted for Salesforce credentials instead of being shown the IDP login page. A is incorrect because the "Redirect to Identity Provider" option has been selected in the My Domain configuration, which is not the cause of the issue. The "Redirect to Identity Provider" option determines whether users are redirected to the identity provider's login page automatically or after clicking a button. C is incorrect because the "Redirect to Identity Provider" option has not been selected in the SAML configuration, which is not the cause of the issue. The "Redirect to Identity Provider" option determines whether users are redirected to the identity provider's login page automatically or after clicking a button. D is incorrect because the user has been granted the "Enable Single Sign-On" permission, which is not the cause of the issue. The "Enable Single Sign-On" permission allows users to use SSO with connected apps or external systems. Verified References: [My Domain URL], [SP-Initiated SAML Flow], [Redirect to Identity Provider Option], [Enable Single Sign-On Permission]


質問 # 68
Universal Containers (UC) wants to provide single sign-on (SSO) for a business-to-consumer (B2C) application using Salesforce Identity.
Which Salesforce license should UC utilize to implement this use case?

  • A. External Identity
  • B. Partner Community
  • C. Identity Only
  • D. Salesforce Platform

正解:A


質問 # 69
Which three types of attacks would a 2-Factor Authentication solution help garden against?

  • A. Man-in-the-middle attacks
  • B. Dictionary attacks
  • C. Phishing attacks
  • D. Network perimeter attacks
  • E. Key logging attacks

正解:B、D、E


質問 # 70
Universal containers (UC) wants users to authenticate into their salesforce org using credentials stored in a custom identity store. UC does not want to purchase or use a third-party Identity provider. Additionally, UC is extremely wary of social media and does not consider it to be trust worthy. Which two options should an architect recommend to UC? Choose 2 answers

  • A. Use a professional social media such as LinkedIn as an Authentication provider
  • B. Implement the Openid protocol and configure an Authentication provider
  • C. Build a custom Web service that is supported by Delegated Authentication.
  • D. Build a custom web page that uses the identity store and calls frontdoor.jsp

正解:B、C


質問 # 71
How should an identity architect automate provisioning and deprovisioning of users into Salesforce from an external system?

  • A. Run registration handler on incoming OAuth responses.
  • B. Use Security Assertion Markup Language Just-in-Time (SAML JIT) on incoming SAML assertions.
  • C. Call SOAP API upsertQ on user object.
  • D. Call OpenID Connect (OIDC)-userinfo endpoint with a valid access token.

正解:A

解説:
Explanation
To automate provisioning and deprovisioning of users into Salesforce from an external system, the identity architect should run a registration handler on incoming OAuth responses. A registration handler is a class that implements the Auth.RegistrationHandler interface and defines how to create or update users in Salesforce based on the information from an external identity provider. OAuth is a protocol that allows users to authorize an external application to access Salesforce resources on their behalf. By running a registration handler on incoming OAuth responses, the identity architect can automate user provisioning and deprovisioning based on the OAuth attributes. References: Registration Handler, Authorize Apps with OAuth


質問 # 72
customer service representatives at Universal containers (UC) are complaining that whenever they click on links to case records and are asked to login with SAML SSO, they are being redirected to the salesforce home tab and not the specific case record. What item should an architect advise the identity team at UC to investigate first?

  • A. The identity provider is correctly preserving the Relay state
  • B. The users have the correct Federation ID within salesforce.
  • C. The salesforce SSO settings are using http post
  • D. My domain is configured and active within salesforce.

正解:A


質問 # 73
Universal Containers (UC) is using Active Directory as its corporate identity provider and Salesforce as its CRM for customer care agents, who use SAML based sign sign-on to login to Salesforce. The default agent profile does not include the Manage User permission. UC wants to dynamically update the agent role and permission sets.
Which two mechanisms are used to provision agents with the appropriate permissions?
Choose 2 answers

  • A. Use Login Flow in System Context to update role and permission sets.
  • B. Use SAML Just-m-Time (JIT) Handler class run as current user to update role and permission sets.
  • C. Use SAML Just-in-Time (JIT) handler class run as an admin user to update role and permission sets.
  • D. Use Login Flow in User Context to update role and permission sets.

正解:A、C

解説:
Explanation
To dynamically update the agent role and permission sets using Active Directory as the corporate identity provider and Salesforce as the CRM for customer care agents, who use SAML based sign-on to login to Salesforce, the identity architect should use two mechanisms:
Use Login Flow in System Context to update role and permission sets. A Login Flow is a custom post-authentication process that can be used to add additional screens or logic after a user logs in to Salesforce. A System Context is a mode that allows a Login Flow to run as an administrator user with full access to Salesforce data and metadata. By using a Login Flow in System Context, the identity architect can update the agent role and permission sets based on the information from Active Directory or other criteria.
Use SAML Just-in-Time (JIT) handler class run as an admin user to update role and permission sets. A SAML JIT handler class is a class that implements the Auth.SamlJitHandler interface and defines how to handle SAML assertions for Just-in-Time (JIT) provisioning. JIT provisioning is a feature that allows Salesforce to create or update user records on the fly when users log in through an external identity provider. By using a SAML JIT handler class run as an admin user, the identity architect can update the agent role and permission sets based on the information from the SAML assertion. References: Login Flows, SAML Just-in-Time Provisioning, Auth.SamlJitHandler Interface


質問 # 74
......


Salesforce Identity-and-Access-Management-Architect 資格試験では、アイデンティティとアクセス管理に関連する広範なトピックがカバーされます。テストされる主要な分野には、アイデンティティとアクセス管理アーキテクチャ、アイデンティティガバナンス、認証と承認、シングルサインオン(SSO)、およびフェデレーションが含まれます。試験はまた、ユーザープロビジョニング、パスワード管理、およびアイデンティティライフサイクル管理などのトピックもカバーしています。

 

2023年最新のPassTest Identity-and-Access-Management-ArchitectのPDFで最近更新された問題です:https://www.passtest.jp/Salesforce/Identity-and-Access-Management-Architect-shiken.html

Identity-and-Access-Management-Architect試験には保証が付きます。更新されたのは245問があります:https://drive.google.com/open?id=18JQC_fs7MxxMNsJ7tHMoB4M28d8FFhFC