
Identity-and-Access-Management-Designer問題集を掴み取れ![最新2023]Salesforce試験合格させます
Identity-and-Access-Management-Designer試験問題集PDF正確率保証と更新された問題
Salesforce Identity-and-Access-Management-Designer試験は、105分以内に完了する必要がある60の質問で構成される、監督済みの複数選択試験です。この試験は、候補者の知識と、認証、承認、ユーザープロビジョニング、ID連合などのコアIAMの概念と原則に関する理解をテストするように設計されています。この試験では、マルチファクター認証、シングルサインオン、アイデンティティガバナンスなどの高度なトピックについてもカバーしています。
Salesforce Certified Identity-and-Access-Management-Designer認定は、Salesforceプラットフォームを使用してアイデンティティおよびアクセス管理ソリューションを設計および実装する専門家が自分の専門知識を証明するために設計されています。この認定は、ユーザー認証、認可、シングルサインオン、アイデンティティフェデレーション、およびアイデンティティ管理などの分野での知識とスキルを検証します。
質問 # 45
What information does the 'Relaystate' parameter contain in sp-Initiated Single Sign-on?
- A. Reference to the login address URL of the service provider.
- B. Reference to a URL redirect parameter at the identity provider.
- C. Reference to a URL redirect parameter at the service provider.
- D. Reference to the login address URL of the identity Provider.
正解:C
質問 # 46
Which two roles of the systems are involved in an environment where salesforce users are enabled to access Google Apps from within salesforce through App launcher and connected App set up? Choose 2 answers
- A. Salesforce is the service provider
- B. Google is the service provider
- C. Google is the identity provider
- D. Salesforce is the identity provider
正解:A
質問 # 47
Which three different attributes can be used to identify the user in a SAML 65> assertion when Salesforce is acting as a Service Provider? Choose 3 answers
- A. Salesforce User ID
- B. Federation ID
- C. User Full Name
- D. User Email Address
- E. Salesforce Username
正解:B、C、D
質問 # 48
Universal containers (UC) uses an internal company portal for their employees to collaborate. UC decides to use salesforce ideas and provide the ability for employees to post ideas from the company portal. They use SAML-BASED SSO to get into the company portal and would like to leverage it to access salesforce. Most of the users don't exist in salesforce and they would like the user records created in salesforce communities the first time they try to access salesforce. What recommendation should an architect make to meet this requirement?
- A. Use Identity connect to sync users
- B. Use salesforce APIs to create users on the fly
- C. Use on-the-fly provisioning
- D. Use just-in-time provisioning
正解:D
質問 # 49
Users logging into Salesforce are frequently prompted to verify their identity.
The identity architect is required to provide recommendations so that frequency of prompt verification can be reduced.
What should the identity architect recommend to meet the requirement?
- A. Set trusted IP ranges for the organization.
- B. Implement an single sign-on for Salesforce using an external identity provider.
- C. Implement 2FA authentication for the Salesforce org.
- D. Implement multi-factor authentication for the Salesforce org.
正解:A
質問 # 50
Northern Trail Outfitters (NTO) utilizes a third-party cloud solution for an employee portal. NTO also owns Salesforce Service Cloud and would like employees to be able to login to Salesforce with their third-party portal credentials for a seamless expenence. The third-party employee portal only supports OAuth.
What should an identity architect recommend to enable single sign-on (SSO) between the portal and Salesforce?
- A. Configure Salesforce for Delegated Authentication.
- B. Create a custom external authentication provider.
- C. Add the third-party portal as a connected app.
- D. Configure SSO to use the third party portal as an identity provider.
正解:D
質問 # 51
A technology enterprise is setting up an identity solution with an external vendors wellness application for its employees. The user attributes need to be returned to the wellness application in an ID token.
Which authentication mechanism should an identity architect recommend to meet the requirements?
- A. JWT Bearer Token Flow
- B. Web Server Flow
- C. OpenID Connect
- D. User Agent Flow
正解:B
質問 # 52
What are threecapabilitiesof Delegated Authentication? Choose 3 answers
- A. It can connect to SOAP services.
- B. It can be assigned by Custom Permissions.
- C. It can connect to REST services.
- D. It can be assigned by Permission Sets.
- E. It can be assigned by Profiles.
正解:A、C、D
質問 # 53
Universal Containers is considering using Delegated Authentication as the sole means of Authenticating of Salesforce users. A Salesforce Architect has been brought in to assist with the implementation. What two risks Should the Architect point out? Choose 2 answers
- A. Delegated Authentication is enabled or disabled for the entire Salesforce org.
- B. Salesforce users will be locked out of Salesforce if the web service goes down.
- C. The web service must reside on a public cloud service, such as Heroku.
- D. UC will be required to develop and support a custom SOAP web service.
正解:B、D
質問 # 54
Universal Containers (UC) uses Global Shipping (GS) as one of their shipping vendors. Regional leads of GS need access to UC's Salesforce instance for reporting damage of goods using Cases. The regional leads also need access to dashboards to keep track of regional shipping KPIs. UC internally uses a third-party cloud analytics tool for capacity planning and UC decided to provide access to this tool to a subset of GS employees. In addition to regional leads, the GS capacity planning team would benefit from access to this tool. To access the analytics tool, UC IT has set up Salesforce as the Identity provider for Internal users and would like to follow the same approach for the GS users as well. What are the most appropriate license types for GS Tregional Leads and the GS Capacity Planners? Choose 2 Answers
- A. Identity Licence for GS Regional Leads and External Identity license for GS capacity Planners.
- B. Customer Community Plus license for GS Regional Leads and Customer Community license for GS Capacity Planners.
- C. Customer Community license for GS Regional Leads and Identity license for GS Capacity Planners.
- D. Customer Community Plus license for GS Regional Leads and External Identity for GS Capacity Planners.
正解:B、C
質問 # 55
universal containers wants to build a custom mobile app connecting to salesforce using Oauth, and would like to restrict the types of resources mobile users can access. What Oauth feature of Salesforce should be used to achieve the goal?
- A. Mobile PINS
- B. Access Tokens
- C. Scopes
- D. Refresh Tokens
正解:B
質問 # 56
Universal containers (UC) has an e-commerce website while customers can buy products, make payments, and manage their accounts. UC decides to build a customer Community on Salesforce and wants to allow the customers to access the community for their accounts without logging in again. UC decides to implement ansp-Initiated SSO using a SAML-BASED complaint IDP. In this scenario where salesforce is the service provider, which two activities must be performed in salesforce to make sp-Initiated SSO work? Choose 2 answers
- A. Configure Delegated Authentication
- B. Create a connected App
- C. Set up my domain
- D. Configure SAML SSO settings.
正解:C、D
質問 # 57
Northern Trail Outfitters (NTO) is setting up Salesforce to authenticate users with an external identity provider. The NTO Salesforce Administrator is having trouble getting things setup.
What should an identity architect use to show which part of the login assertion is fading?
- A. Security Assertion Markup Language Validator
- B. SAML Metadata file importer
- C. Identity Provider Metadata download
- D. Connected App Manager
正解:A
質問 # 58
Northern Trail Outfitters (NTO) has an off-boarding process where a terminated employee is first disabled in the Lightweight Directory Act Protocol (LDAP) directory, then requests are sent to the various application support teams to finish user deactivations. A terminated employee recently was able to login to NTO's Salesforce instance 24 hours after termination, even though the user was disabled in the corporate LDAP directory.
What should an identity architect recommend to prevent this from happening in the future?
- A. Setup an identity provider (IdP) to authenticate users using LDAP, set up single sign-on to Salesforce and disable Login Form authentication.
- B. Create a Just-in-Time provisioning registration handler to ensure users are deactivated in Salesforce as they are disabled in LDAP.
- C. Configure an authentication provider to delegate authentication to the LDAP directory.
- D. use a login flow to make a callout to the LDAP directory before authenticating the user to Salesforce.
正解:C
質問 # 59
Universal Containers (UC) uses Salesforce to allow customers to keep track of the order status. The customers can log in to Salesforce using external authentication providers, such as Facebook and Google. UC is also leveraging the App Launcher to let customers access an of platform application for generating shipping labels.
The label generator application uses OAuth to provide users access. What license type should an Architect recommend for the customers?
- A. Customer Community license
- B. External Identity license
- C. Identity license
- D. Customer Community Plus license
正解:C
質問 # 60
A global company is using the Salesforce Platform as an Identity Provider and needs to integrate a third-party application with its Experience Cloud customer portal.
Which two features should be utilized to provide users with login and identity services for the third-party application?
Choose 2 answers
- A. Use the App Launcher with single sign-on (SSO).
- B. Use Delegated Authentication.
- C. External a Data source with Named Principal identity type.
- D. Use a connected app.
正解:A、D
質問 # 61
......
この試験では、ユーザー認証、承認、プロビジョニングなど、アイデンティティとアクセス管理に関連する幅広いトピックをカバーしています。また、SAMLやOAuthなどの外部IDプロバイダーとの統合に関連するトピックもカバーしています。さらに、この試験では、データを保護し、Salesforceでのユーザーアクセスを管理するためのベストプラクティスをカバーしています。
最新をゲットせよ!Identity-and-Access-Management-Designer認定練習テスト問題 試験問題集:https://www.passtest.jp/Salesforce/Identity-and-Access-Management-Designer-shiken.html
合格させるIdentity-and-Access-Management-Designer試験にはリアルテストエンジンPDFには245問題あります:https://drive.google.com/open?id=1l3saFczW58amM1lUebAAyv3CNlkVCh7D