Aug-2026 Free Salesforce Identity-and-Access-Management-Designer Exam Question Practice Exams [Q129-Q148]

Rate this post

Aug-2026 Free Salesforce Identity-and-Access-Management-Designer Exam Question Practice Exams

Ace Identity-and-Access-Management-Designer Certification with 245 Actual Questions

Salesforce Identity-and-Access-Management-Designer Exam Syllabus Topics:

Section Weight Objectives
Topic 1: Accepting Third-Party Identity in Salesforce 21% – Authentication mechanisms with external identity providers
– Salesforce as service provider identity solutions
Topic 2: Access Management Best Practices 15% – Session security and high-assurance sessions
– Two-Factor Authentication (2FA) risk mitigation
Topic 3: Community (Partner and Customer) 18% – External identity solutions for Experience Cloud
– Community self-registration and authentication
Topic 4: Salesforce Identity 12% – License type considerations for identity requirements
– Identity Connect role in IAM solutions
Topic 5: Salesforce as an Identity Provider 17% – Connected Apps usage for identity provisioning
– OAuth flow types and implementation concepts
Topic 6: Identity Management Concepts 17% – Authentication, authorization, and accountability fundamentals
– Trust establishment between systems

 

NEW QUESTION 129
Universal containers (UC) is planning to deploy a custom mobile app that will allow users to get e-signatures from its customers on their mobile devices. The mobile app connects to salesforce to upload the e-signatures as a file attachment and uses Oauth protocol for both Authentication and authorization. What is the most recommended and secure Oauth scope setting that an architect should recommend?

 
 
 
 

NEW QUESTION 130
Northern Trail Outfitters wants to implement a partner community. Active community users will need to review and accept the community rules, and update key contact information for each community member before their annual partner event.
Which approach will meet this requirement?

 
 
 
 

NEW QUESTION 131
Northern Trail Outfitters (NTO) is setting up Salesforce to authenticate users with an external identity provider. The NTO Salesforce Administrator is having trouble getting things setup.
What should an identity architect use to show which part of the login assertion is fading?

 
 
 
 

NEW QUESTION 132
Which three types of attacks would a 2-Factor Authentication solution help garden against?

 
 
 
 
 

NEW QUESTION 133
Universal Containers (UC) uses middleware to integrate multiple systems with Salesforce. UC has a strict, new requirement that usernames and passwords cannot be stored in any UC system.
How can UC’s middleware authenticate to Salesforce while adhering to this requirement?

 
 
 
 

NEW QUESTION 134
Universal Containers is considering using Delegated Authentication as the sole means of Authenticating of Salesforce users. A Salesforce Architect has been brought in to assist with the implementation. What two risks Should the Architect point out? Choose 2 answers

 
 
 
 

NEW QUESTION 135
Universal Containers (UC) wants its closed Won opportunities to be synced to a Data Warehouse in near real time. UC has implemented Outbound Message to enable near real-time data sync. UC wants to ensure that communication between Salesforce and Target System is Secure. What Certificate is sent along with the Outbound Message?

 
 
 
 

NEW QUESTION 136
Universal Containers has implemented a multi-org strategy and would like to centralize the management of their Salesforce user profiles.
What should the Architect recommend to allow Salesforce profiles to be managed from a central system of record?

 
 
 
 

NEW QUESTION 137
Which tool should be used to track login data, such as the average number of logins, who logged in more than the average number of times and who logged in during non-business hours?

 
 
 
 

NEW QUESTION 138
Universal Containers (UC) has implemented SAML-based SSO solution for use with their multi-org Salesforce implementation, utilizing one of the the orgs as the Identity Provider. One user is reporting that they can log in to the Identity Provider org but get a generic SAML error message when accessing the other orgs. Which two considerations should the architect review to troubleshoot the issue? Choose 2 answers

 
 
 
 

NEW QUESTION 139
A university is planning to set up an identity solution for its alumni. A third-party identity provider will be used for single sign-on Salesforce will be the system of records. Users are getting error messages when logging in.
Which Salesforce feature should be used to debug the issue?

 
 
 
 

NEW QUESTION 140
Which three are features of federated Single sign-on solutions? Choose 3 Answers

 
 
 
 
 

NEW QUESTION 141
What are three capabilities of Delegated Authentication? Choose 3 answers

 
 
 
 
 

NEW QUESTION 142
Universal Containers (UC) has a classified information system that its call center team uses only when they are working on a case with a record type “Classified”. They are only allowed to access the system when they own an open “Classified” case, and their access to the system is removed at all other times. They would like to implement SAML SSO eith Salesforce as the Idp, and automatically allow or deny the staff’s access to the classified information system based on whether they currently own an open “Classified” case record when they try to access the system using SSO. What is the recommended solution for automatically allowing or denying the access to the classified information system based on the open “classified” case record criteria?

 
 
 
 

NEW QUESTION 143
Universal containers (UC) has multiple salesforce orgs and would like to use a single identity provider to access all of their orgs. How should UC’S architect enable this behavior?

 
 
 
 

NEW QUESTION 144
Universal Containers (UC) uses an internal system for recruiting and would like to have the candidates’ info available in Salesforce automatically when they are selected. UC decides to use OAuth to connect to Salesforce from the recruiting system and would like to do the authentication using digital certificates.
Which two OAuth flows should be considered to meet the requirement? (Choose two.)

 
 
 
 

NEW QUESTION 145
Universal Containers wants to secure its Salesforce APIs by using an existing Security Assertion Markup Language (SAML) configuration supports the company’s single sign-on process to Salesforce, Which Salesforce OAuth authorization flow should be used?

 
 
 
 

NEW QUESTION 146
An Architect needs to advise the team that manages the Identity Provider how to differentiate Salesforce from other Service Providers. What SAML SSO setting in Salesforce provides this capability?

 
 
 
 

NEW QUESTION 147
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to 65« set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?

 
 
 
 

NEW QUESTION 148
Which three capabilities does SAML-based Federated authentication provide? (Choose three.)

 
 
 
 
 

Identity-and-Access-Management-Designer Questions PDF [2026] Use Valid New dump to Clear Exam: https://www.premiumvcedump.com/Salesforce/valid-Identity-and-Access-Management-Designer-premium-vce-exam-dumps.html

Related Links: www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw