Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Sure Pass Exam Identity-and-Access-Management-Architect PDF

Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Questions and Answers

Question 5

Universal Containers has multiple Salesforce instances where users receive emails from different instances. Users should be logged into the correct Salesforce instance authenticated by their IdP when clicking on an email link to a Salesforce record.

What should be enabled in Salesforce as a prerequisite?

Options:

A.

External Identity

B.

My Domain

C.

Multi-Factor Authentication

D.

Identity Provider

Question 6

A manufacturer wants to provide registration for an Internet of Things (IoT) device with limited display input or capabilities.

Which Salesforce OAuth authorization flow should be used?

Options:

A.

OAuth 2.0 User-Agent

B.

OAuth 2.0 Asset Token Flow

C.

OAuth 2.0 WiT Bearer Flow

D.

OAuth 2.0 Device Flow

Question 7

A service provider (SP) supports both Security Assertion Narkup Language (SAML) and OpenID Connect (OIDC).

When Salesforce is acting as Identity Provider for this SP, which use case is the determining factor when choosing OIDC or SAML?

Options:

A.

OIDC is more secure than SAML and therefore is the obvious choice.

B.

the SP needs to perform our calls back to Salesforce on behalf of the user after the user logs in to the service provider.

C.

They are equivalent protocols and there is no real reason to choose one over the other.

D.

If the user has a session on Salesforce, you do not want them to be promoted for a username and password when they login to the SP.

Question 8

Northern Trail Outfitters recently acquired a company. Each company will retain its Identity Provider (IdP). Both companies rely extensively on Salesforce processes that send emails to users to take specific actions in Salesforce.

How should the combined companys ' employees collaborate in a single Salesforce org, yet authenticate to the appropriate IdP?

Options:

A.

Configure unique MyDomains for each company and have generated links use the appropriate MyDomain in the URL.

B.

Have generated links append a quenystring parameter indicating the IdP. The login service will redirect to the appropriate IdP.

C.

Enable each IdP as a login option in the My Domain Authentication Service settings. Users will then click on the appropriate IdP button.

D.

Have generated links be prefixed with the appropriate IdP URL to invoke an idP-initiated Security Assertion Markup Language flow when clicked.