Free IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER Exam Braindumps (page: 7)

Page 6 of 59

universal container plans to develop a custom mobile app for the sales team that will use salesforce for authentication and access management. The mobile app access needs to be restricted to only the sales team.
What would be the recommended solution to grant mobile app access to sales users?

  1. Usea custom attribute on the user object to control access to the mobile app
  2. Use connected apps Oauth policies to restrict mobile app access to authorized users.
  3. Use the permission set license to assign the mobile app permission to sales users
  4. Add anew identity provider to authenticate and authorize mobile users.

Answer(s): B



Universal Containers (UC) is setting up delegated authentication to allow employees to log in using their corporate credentials. UC's security team is concerned about the risks of exposing the corporate login service on the internet and has asked that a reliable trust mechanism be put in place between the login service and Salesforce.

What mechanism should an Architect put in place to enable a trusted connection between the login service and Salesforce?

  1. Require the use of Salesforce security tokens on passwords.
  2. Enforce mutual authentication between systems using SSL.
  3. Include Client Id and Client Secret in the login header callout.
  4. Set up a proxy service for the login service in the DMZ.

Answer(s): A



An architect has successfully configured SAML-BASED SSO for universal containers. SSO has been working for 3 months when Universal containers manually adds a batch of new users to salesforce. The new users receive an error from salesforce when trying to use SSO. Existing users are still able to successfully use SSO to access salesforce.
What is the probable cause of this behaviour?

  1. The administrator forgot to reset the new user's salesforce password.
  2. The Federation ID field on the new user records is not correctly set
  3. The my domain capability is not enabled on the new user's profile.
  4. The new users do not have the SSO permission enabled on their profiles.

Answer(s): B



Universal containers wants to build a custom mobile app connecting to salesforce using Oauth, and would like to restrict the types of resources mobile users can access.
What Oauth feature of Salesforceshould be used to achieve the goal?

  1. Access Tokens
  2. Mobile pins
  3. Refresh Tokens
  4. Scopes

Answer(s): D






Post your Comments and Discuss Salesforce IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER exam with other Community members:

IDENTITY-AND-ACCESS-MANAGEMENT-DESIGNER Discussions & Posts