Free Certified Identity and Access Management Architect Exam Braindumps (page: 30)

Page 29 of 62

How should an Architect force users to authenticate with Two-factor Authentication (2FA) for Salesforce only when not connected to an internal company network?

  1. Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA if needed.
  2. Add the list of company's network IP addresses to the Login Range list under 2FA Setup.
  3. Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.
  4. Apply the "Two-factor Authentication for User Interface Logins" permission and Login IP Ranges for all Profiles.

Answer(s): A



What is one of the roles of an Identity Provider in a Single Sign-on setup using SAML?

  1. Validate token
  2. Create token
  3. Consume token
  4. Revoke token

Answer(s): B



Which two security risks can be mitigated by enabling Two-Factor Authentication (2FA) in Salesforce? Choose 2 answers

  1. Users leaving laptops unattended and not logging out of Salesforce.
  2. Users accessing Salesforce from a public Wi-Fi access point.
  3. Users choosing passwords that are the same as their Facebook password.
  4. Users creating simple-to-guess password reset questions.

Answer(s): B,C



Universal Containers (UC) implemented SSO to a third-party system for their Salesforce users to access the App Launcher. UC enabled ‘User Provisioning’ on the Connected App so that changes to user accounts can be synched between Salesforce and the third party system. However, UC quickly notices that changes to user roles in Salesforce are not getting synched to the third-party system. What is the most likely reason for this behaviour?

  1. User Provisioning for Connected Apps does not support role sync.
  2. Required operation(s) was not mapped in User Provisioning Settings.
  3. The Approval queue for User Provisioning Requests is unmonitored.
  4. Salesforce roles have more than three levels in the role hierarchy.

Answer(s): A






Post your Comments and Discuss Salesforce Certified Identity and Access Management Architect exam with other Community members:

Certified Identity and Access Management Architect Discussions & Posts