
[UPDATED 2026] Identity-and-Access-Management-Designer dumps Free Test Engine Verified By Certified Experts
Realistic Identity-and-Access-Management-Designer Accurate & Verified Answers As Experienced in the Actual Test!
Salesforce Identity-and-Access-Management-Designer certification is a prestigious certification that focuses on identity and access management in the Salesforce ecosystem. Salesforce Certified Identity and Access Management Designer certification is designed for professionals who are responsible for designing, implementing, and managing Salesforce security and access controls. It validates the skills and knowledge required to design and implement robust, secure, and scalable security solutions that protect valuable data and assets.
NEW QUESTION # 18
Which three are features of federated Single sign-on solutions? Choose 3 Answers
- A. It improves affiliated applications adoption rates.
- B. It solves all identity and access management problems.
- C. It establishes trust between Identity Store and Service Provider.
- D. It enables quick and easy provisioning and deactivating of users.
- E. It federates credentials control to authorized applications.
Answer: A,B,D
NEW QUESTION # 19
A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APAC. The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS . The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.
What is recommended to ensure these requirements are met ?
- A. Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.
- B. Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.
- C. Configure Each ADFS system under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce-
- D. Add a central identity system that federates between the ADFS systems and integrate with Salesforce for single sign-on.
Answer: B
NEW QUESTION # 20
A division of a Northern Trail Outfitters (NTO) purchased Salesforce. NTO uses a third party identity provider (IdP) to validate user credentials against Its corporate Lightweight Directory Access Protocol (LDAP) directory. NTO wants to help employees remember as passwords as possible.
What should an identity architect recommend?
- A. Use Salesforce connect to synchronize LDAP passwords to Salesforce.
- B. Setup Salesforce as an Authentication Provider to the existing IdP.
- C. Setup Salesforce as an IdP to authenticate against the LDAP directory.
- D. Setup Salesforce as a Service Provider to the existing IdP.
Answer: D
NEW QUESTION # 21
Universal containers (UC) is setting up their customer Community self-registration process. They are uncomfortable with the idea of assigning new users to a default account record. What will happen when customers self-register in the community?
- A. The self-registration process will produce an error to the user.
- B. The self-registration process will create a person Account record.
- C. The self-registration page will ask user to select an account.
- D. The self-registration page will create a new account record.
Answer: B
NEW QUESTION # 22
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to 65 set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?
- A. Neither SP- nor IdP-initiated SSO will work.
- B. IdP-initiated SSO will NOT work.
- C. SP-initiated SSO will NOT work
- D. Either SP- or IdP-initiated SSO will work.
Answer: A
NEW QUESTION # 23
Northern Trail Outfitters (NTO) uses Salesforce for Sales Opportunity Management. Okta was recently brought in to Just-in-Time (JIT) provision and authenticate NTO users to applications. Salesforce users also use Okta to authorize a Forecasting web application to access Salesforce records on their behalf.
Which two roles are being performed by Salesforce?
Choose 2 answers
- A. OAuth Client
- B. SAML Service Provider
- C. SAML Identity Provider
- D. OAuth Resource Server
Answer: A,B
NEW QUESTION # 24
Universal containers(UC) has implemented SAML-BASED single Sign-on for their salesforce application and is planning to provide access to salesforce on mobile devices using the salesforce1 mobile app. UC wants to ensure that single Sign-on is used for accessing the salesforce1 mobile app. Which two recommendations should the architect make? Choose 2 answers
- A. Configure the embedded Web browser to use my domain URL.
- B. Use the existing SAML SSO flow along with user agent flow.
- C. Use the existing SAML SSO flow along with Web server flow
- D. Configure the salesforce1 app to use the my domain URL
Answer: B,D
NEW QUESTION # 25
IT security at Unversal Containers (UC) us concerned about recent phishing scams targeting its users and wants to add additional layers of login protection. What should an Architect recommend to address the issue?
- A. Increase Password complexity requirements in Salesforce.
- B. Lock sessions to the IP address from which they originated.
- C. Implement Single Sign-on using a corporate Identity store.
- D. Use the Salesforce Authenticator mobile app with two-step verification
Answer: B
NEW QUESTION # 26
Northern Trail Outfitters (NTO) is launching a new sportswear brand on its existing consumer portal built on Salesforce Experience Cloud. As part of the launch, emails with promotional links will be sent to existing customers to log in and claim a discount. The marketing manager would like the portal dynamically branded so that users will be directed to the brand link they clicked on; otherwise, users will view a recognizable NTO-branded page.
The campaign is launching quickly, so there is no time to procure any additional licenses. However, the development team is available to apply any required changes to the portal.
Which approach should the identity architect recommend?
- A. Use Heroku to build the new brand site and embedded login to reuse identities.
- B. Create a full sandbox to replicate the portal site and update the branding accordingly.
- C. Configure an additional community site on the same org that is dedicated for the new brand.
- D. Implement Experience ID in the code and extend the URLs and endpomts, as required.
Answer: D
NEW QUESTION # 27
Universal Containers want users to be able to log in to the Salesforce mobile app with their Active Directory password. Employees are unable to use mobile VPN.
Which two options should an identity architect recommend to meet the requirement?
Choose 2 answers
- A. Salesforce Identity Connect
- B. Active Directory Password Sync Plugin
- C. Configure Cloud Provider Load Balancer
- D. Salesforce Trigger & Field on Contact Object
Answer: A,B
NEW QUESTION # 28
Universal containers (UC) has a mobile application that calls the salesforce REST API. In order to prevent users from having to enter their credentials everytime they use the app, UC has enabled the use of refresh Tokens as part of the salesforce connected App and updated their mobile app to take advantage of the refresh token. Even after enabling the refresh token, Users are still complaining that they have to enter their credentials once a day. What is the most likely cause of the issue?
- A. The refresh token expiration policy is set incorrectly in salesforce
- B. The users forget to check the box to remember their credentials.
- C. The Oauth authorizations are being revoked by a nightly batch job.
- D. The app is requesting too many access Tokens in a 24-hour period
Answer: A
NEW QUESTION # 29
Which two are valid choices for digital certificates when setting up two-way SSL between Salesforce and an external system. Choose 2 answers
- A. Use a trusted CA-signed certificate for salesforce and a self-signed cert for the external system
- B. Use a self-signed certificate for salesforce and a self-signed cert for the external system
- C. Use a trusted CA-signed certificate for salesforce and a trusted CA-signed cert for the external system
- D. Use a self-signed certificate for salesforce and a trusted CA-signed cert for the external system
Answer: B,D
NEW QUESTION # 30
Containers (UC) uses an internal system for recruiting and would like to have the candidates' info available in the Salesforce automatically when they are selected. UC decides to use OAuth to connect to Salesforce from the recruiting system and would like to do the authentication using digital certificates. Which two OAuth flows should be considered to meet the requirement? Choose 2 answers
- A. JWT Bearer Token flow
- B. Refresh Token flow
- C. Web Service flow
- D. SAML Bearer Assertion flow
Answer: A,D
NEW QUESTION # 31
In a typical SSL setup involving a trusted party and trusting party, what consideration should an Architect take into account when using digital certificates?
- A. Use of self-signed certificate leads to higher maintenance for trusted party because they have to act as the trusted CA
- B. Use of self-signed certificate leads to lower maintenance for trusted party because multiple self-signed certs need to be maintained.
- C. Use of self-signed certificate leads to lower maintenance for trusting party because there is no trusted CA cert to maintain.
- D. Use of self-signed certificate leads to higher maintenance for trusting party because the cert needs to be added to their truststore.
Answer: C
NEW QUESTION # 32
What information does the 'Relaystate' parameter contain in sp-Initiated Single Sign-on?
- A. Reference to the login address URL of the identity Provider.
- B. Reference to the login address URL of the service provider.
- C. Reference to a URL redirect parameter at the service provider.
- D. Reference to a URL redirect parameter at the identity provider.
Answer: D
NEW QUESTION # 33
Universal Containers has built a custom token-based Two-Factor Authentication system for their existing on-premise applications. They are now implementing Salesforce and would like to enable a Two-Factor login process for it, as well.
What is the recommended solution an Architect should consider?
- A. Use Custom Login Flows to connect to the existing custom 2FA system for use in Salesforce.
- B. Replace the custom 2FA system with an AppExchange App that supports on-premise applications and Salesforce.
- C. Use the custom 2FA system for on-premise applications and native 2FA for Salesforce.
- D. Replace the custom 2FA system with Salesforce 2FA for on-premise applications and Salesforce.
Answer: A
NEW QUESTION # 34
The executive sponsor for an organization has asked if Salesforce supports the ability to embed a login widget into its service providers in order to create a more seamless user experience.
What should be used and considered before recommending it as a solution on the Salesforce Platform?
- A. OpenID Connect Web Server Flow. Determine if the service provider is secure enough to store the client secret on.
- B. Embedded Login. Consider whether or not it relies on third party cookies which can cause browser compatibility issues.
- C. Salesforce REST apis. Ensure that Secure Sockets Layer (SSL) connection for the integration is used.
- D. Embedded Login. Identify what level of UI customization will be required to make it match the service providers look and feel.
Answer: B
NEW QUESTION # 35
universal container plans to develop a custom mobile app for the sales team that will use salesforce for authentication and access management. The mobile app access needs to be restricted to only the sales team.
What would be the recommended solution to grant mobile app access to sales users?
- A. Add a new identity provider to authenticate and authorize mobile users.
- B. Use connected apps Oauth policies to restrict mobile app access to authorized users.
- C. Use a custom attribute on the user object to control access to the mobile app
- D. Use the permission set license to assign the mobile app permission to sales users
Answer: A
NEW QUESTION # 36
......
Earning the Salesforce Certified Identity and Access Management Designer credential can help you stand out in a crowded job market. Salesforce Certified Identity and Access Management Designer certification is recognized globally and is highly valued by employers who require expertise in identity and access management. With this certification, you can demonstrate your commitment to professional development and your ability to create secure and efficient solutions that meet the unique needs of your organization or clients.
Latest Salesforce Identity-and-Access-Management-Designer Practice Test Questions: https://pass4sure.actual4cert.com/Identity-and-Access-Management-Designer-pass4sure-vce.html