Free Certified Identity and Access Management Architect Exam Braindumps (page: 4)

Page 3 of 62

Universal Containers (UC) has a Customer Community that uses Facebook for of authentication. UC would like to ensure that changes in the Facebook profile are 65. reflected on the appropriate Customer Community user. How can this requirement be met?

  1. Use SAML Just-In-Time Provisioning between Facebook and Salesforce.
  2. Use information in the Signed Request that is received from Facebook.
  3. Develop a scheduled job that calls out to Facebook on a nightly basis.
  4. Use the updateUser() method on the Registration Handler class.

Answer(s): D



Universal Containers (UC) has five Salesforce orgs (UC1, UC2, UC3, UC4, UC5). of Every user that is in UC2, UC3, UC4, and UC5 is also in UC1, however not all users 65* have access to every org. Universal Containers would like to simplify the authentication process such that all Salesforce users need to remember one set of credentials. UC would like to achieve this with the least impact to cost and maintenance. What approach should an Architect recommend to UC?

  1. Purchase a third-party Identity Provider for all five Salesforce orgs to use and set up JIT user provisioning on all other orgs.
  2. Purchase a third-party Identity Provider for all five Salesforce orgs to use, but don't set up JIT user provisioning for other orgs.
  3. Configure UC1 as the Identity Provider to the other four Salesforce orgs and set up JIT user provisioning on all other orgs.
  4. Configure UC1 as the Identity Provider to the other four Salesforce orgs, but don't set up JIT user provisioning for other orgs.

Answer(s): B



Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to 65« set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?

  1. IdP-initiated SSO will NOT work.
  2. Neither SP- nor IdP-initiated SSO will work.
  3. Either SP- or IdP-initiated SSO will work.
  4. SP-initiated SSO will NOT work

Answer(s): B



Which two capabilities does My Domain enable in the context of a SAML SSO configuration? Choose 2 answers

  1. App Launcher
  2. Resource deep linking
  3. SSO from Salesforce Mobile App
  4. Login Forensics

Answer(s): B,C






Post your Comments and Discuss Salesforce Certified Identity and Access Management Architect exam with other Community members:

Certified Identity and Access Management Architect Discussions & Posts