Identity-and-Access-Management-Architect: Salesforce Certified Identity and Access Management Architect (SU23) Login Practice Questions
The free Identity-and-Access-Management-Architect: Salesforce Certified Identity and Access Management Architect (SU23) questions that deal with login, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #3
Universal containers (UC) is setting up Delegated Authentication to allow employees to log in using their corporate credentials. UC's security team is concerned about the risk of exposing the corporate login service on the Internet and has asked that a reliable trust mechanism be put in place between the login service and salesforce. What mechanism should an architect put in place to enable a trusted connection between the login services and salesforce?
Correct answer: D
Explanation
To enable a trusted connection between the login services and Salesforce, UC should enforce mutual authentication between systems using SSL. Mutual authentication is a process in which both parties in a communication verify each other’s identity using certificates7. SSL (Secure Sockets Layer) is a protocol that provides secure communication over the Internet using encryption and certificates8. By using mutual authentication with SSL, UC can ensure that only authorized login services can access Salesforce and vice versa. This can prevent unauthorized access, impersonation, or phishing attacks. References: Mutual Authentication, SSL (Secure Sockets Layer)
Question #8
A large consumer company is planning to create a community and will requ.re login through the customers social identity. The following requirements must be met: * 1. The customer should be able to login with any of their social identities, however salesforce should only have one user per customer. * 2. Once the customer has been identified with a social identity, they should not be required to authonze Salesforce. * 3. The customers personal details from the social sign on need to be captured when the customer logs into Salesforce using their social Identity. * 3. If the customer modifies their personal details in the social site, the changes should be updated in Salesforce. Which two options allow the Identity Architect to fulfill the requirements? Choose 2 answers
Select 2 answers.
Correct answer: B, D
Explanation
To allow customers to log in to the community with any of their social identities, such as Facebook, Google, or Twitter, the identity architect needs to use authentication providers for social sign-on. Authentication providers are configurations that enable users to authenticate with an external identity provider and access Salesforce resources. To ensure that Salesforce has only one user per customer, regardless of how many social identities they have, the identity architect needs to use the custom registration handler to link social identities to Salesforce identities. The custom registration handler is a class that implements the Auth.RegistrationHandler interface and defines how to create or update users in Salesforce based on the information from the external identity provider. The custom registration handler can also be used to insert or update personal details of the customers when they log in to Salesforce using their social identity. References: Authentication Providers, Social Sign-On with Authentication Providers, Create a Custom Registration Handler
Question #9
A global company's Salesforce Identity Architect is reviewing its Salesforce production org login history and is seeing some intermittent Security Assertion Markup Language (SAML SSO) 'Replay Detected and Assertion Invalid' login errors. Which two issues would cause these errors? Choose 2 answers
Select 2 answers.
Correct answer: C, D
Explanation
A SAML SSO ‘Replay Detected and Assertion Invalid’ error occurs when Salesforce detects that the same assertion has been used more than once within the validity period. This can happen if the assertion ID is reused by the IdP or if the assertion is resent by the user. Another possible cause is that the time settings of the IdP and Salesforce are not synchronized, which can result in an assertion being valid for a shorter or longer period than expected. References: SAML Single Sign-On Settings, Troubleshoot SAML Single Sign-On
Continue with Identity-and-Access-Management-Architect: Salesforce Certified Identity and Access Management Architect (SU23)
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in Identity-and-Access-Management-Architect: Salesforce Certified Identity and Access Management Architect (SU23), the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
