Free Certified Identity and Access Management Architect Exam Braindumps (page: 26)

Page 25 of 62

Universal containers (UC) has decided to use identity connect as it's identity provider. UC uses active directory(AD) and has a team that is very familiar and comfortable with managing ad groups. UC would like to use AD groups to help configure salesforce users. Which three actions can AD groups control through identity connect? Choose 3 answers

  1. Public Group Assignment
  2. Granting report folder access
  3. Role Assignment
  4. Custom permission assignment
  5. Permission sets assignment

Answer(s): A,C,E



Universal containers wants to set up SSO for a selected group of users to access external applications from salesforce through App launcher. Which three steps must be completed in salesforce to accomplish the goal?

  1. Associate user profiles with the connected Apps.
  2. Complete my domain and Identity provider setup.
  3. Create connected apps for the external applications.
  4. Complete single Sign-on settings in security controls.
  5. Create named credentials for each external system.

Answer(s): A,B,C



Universal containers (UC) is concerned that having a self-registration page will provide a means for "bots" or unintended audiences to create user records, thereby consuming licences and adding dirty data. Which two actions should UC take to prevent unauthorised form submissions during the selfregistration process? Choose 2 answers

  1. Use open-ended security questions and complex password requirements
  2. Primarily use lookup and picklist fields on the self registration page.
  3. Require a captcha at the end of the self-registration process.
  4. Use hidden fields populated via java script events in the self-registration page.

Answer(s): C,D



Universal containers (UC) has implemented a multi-org strategy and would like to centralize the management of their salesforce user profiles. What should the architect recommend to allow salesforce profiles to be managed from a central system of record?

  1. Implement jit provisioning on the SAML IDP that will pass the profile id in each assertion.
  2. Create an apex scheduled job in one org that will synchronize the other orgs profile.
  3. Implement Delegated Authentication that will update the user profiles as necessary.
  4. Implement an Oauthjwt flow to pass the profile credentials between systems.

Answer(s): A






Post your Comments and Discuss Salesforce Certified Identity and Access Management Architect exam with other Community members:

Certified Identity and Access Management Architect Discussions & Posts