
2026 Valid Identity-and-Access-Management-Architect FREE EXAM DUMPS QUESTIONS & ANSWERS
Free Identity-and-Access-Management-Architect Exam Braindumps Salesforce Pratice Exam
Salesforce Identity-and-Access-Management-Architect (IAM) Certification Exam is a highly advanced certification that validates the expertise of an individual in designing, implementing and managing Salesforce Identity and Access Management solutions. Salesforce Certified Identity and Access Management Architect certification is designed for professionals who have deep knowledge and experience in managing the security and access control of Salesforce applications. Identity-and-Access-Management-Architect exam focuses on various aspects of Identity and Access Management such as authentication, authorization, single sign-on, multi-factor authentication, and user provisioning. Salesforce Certified Identity and Access Management Architect certification exam is intended for experienced professionals who have a thorough understanding of the Salesforce platform and its security features.
To qualify for the Salesforce Certified IAM Architect certification, candidates must have a deep understanding of the Salesforce platform, as well as experience in designing and implementing complex identity and access management solutions. Candidates must also have a strong understanding of industry best practices, standards, and regulations related to identity and access management. Identity-and-Access-Management-Architect exam consists of multiple-choice questions that evaluate the candidate's knowledge and understanding of core concepts and practices related to IAM. Passing Identity-and-Access-Management-Architect exam demonstrates that the candidate has the expertise required to design and implement secure and scalable IAM solutions on the Salesforce platform, thus providing a valuable credential for professionals seeking to advance their careers in this field.
NEW QUESTION # 13
Universal containers (UC) wants to implement Delegated Authentication for a certain subset of Salesforce users. Which three items should UC take into consideration while building the Web service to handle the Delegated Authentication request? Choose 3 answers
- A. The web service needs to include Source IP as a method parameter.
- B. The web service can be written using either the soap or rest protocol.
- C. The return type of the Web service method should be a Boolean value
- D. UC should whitelist all salesforce ip ranges on their corporate firewall.
- E. Delegated Authentication is enabled for the system administrator profile.
Answer: A,C,D
NEW QUESTION # 14
An insurance company has a connected app in its Salesforce environment that is used to integrate with a Google Workspace (formerly knot as G Suite).
An identity and access management (IAM) architect has been asked to implement automation to enable users, freeze/suspend users, disable users, and reactivate existing users in Google Workspace upon similar actions in Salesforce.
Which solution is recommended to meet this requirement?
- A. Update the Security Assertion Markup Language Just-in-Time (SAML JIt; handler in Salesforce for user provisioning and de-provisioning.
- B. Build an Apex trigger on the useriogin object to make asynchronous callouts to Google APIs.
- C. Configure user Provisioning for Connected Apps.
- D. Build a custom REST endpoint in Salesforce that Google Workspace can poll against.
Answer: C
NEW QUESTION # 15
Universal containers (UC) employees have salesforce access from restricted ip ranges only, to protect against unauthorised access. UC wants to rollout the salesforce1 mobile app and make it accessible from any location.
Which two options should an architect recommend? Choose 2 answers
- A. Remove existing restrictions on ip ranges for all types of user access.
- B. Relax the ip restriction with a second factor in the connect app settings for salesforce1 mobile app
- C. Use login flow to bypass ip range restriction for the mobile app.
- D. Relax the ip restriction in the connect app settings for the salesforce1 mobile app
Answer: C,D
NEW QUESTION # 16
A leading fitness tracker company is getting ready to launch a customer community. The company wants its customers to login to the community and connect their fitness device to their profile. Customers should be able to obtain exercise details and fitness recommendation in the community.
Which should be used to satisfy this requirement?
- A. Login Flows
- B. OAuth Device Flow
- C. Single Sign-On Settings
- D. Named Credentials
Answer: B
Explanation:
Explanation
OAuth Device Flow is a protocol that allows users to authenticate their devices, such as fitness trackers, smart TVs, or printers, with an external identity provider and access Salesforce resources. The device flow involves displaying a verification code and a URL on the device, which the user can use to log in and authorize the device from another device, such as a smartphone or a computer. References: OAuth Device Flow, OAuth 2.0 Device Flow
NEW QUESTION # 17
Universal Containers (UC) plans to use a SAML-based third-party IdP serving both of the Salesforce Partner Community and the corporate portal. UC partners will log in 65* to the corporate portal to access protected resources, including links to Salesforce resources. What would be the recommended way to configure the IdP so that seamless access can be achieved in this scenario?
- A. Configure SP-initiated SSO that passes the SAML token upon Salesforce resource access request.
- B. Set up the corporate portal as a Connected App in Salesforce and use the User Agent OAuth flow.
- C. Set up the corporate portal as a Connected App in Salesforce and use the Web server OAuth flow.
- D. Configure IdP-initiated SSO that passes the SAML token upon Salesforce resource access request.
Answer: D
NEW QUESTION # 18
Universal containers (UC) would like to enable SAML-BASED SSO for a salesforce partner community. UC has an existing ldap identity store and a third-party portal. They would like to use the existing portal as the primary site these users' access, but also want to allow seamless access to the partner community. What SSO flow should an architect recommend?
- A. IDP-initiated
- B. Web server
- C. User-Agent
- D. Sp-Initiated
Answer: A
Explanation:
Explanation
IDP-initiated SSO flow is when the user starts at the identity provider (IDP) site and then is redirected to the service provider (SP) site with a SAML assertion. This flow is suitable for UC's scenario because they want to use their existing portal as the primary site and also enable seamless access to the partner community. The IDP-initiated flow does not require the user to log in again at the SP site, which is Salesforce in this case.
References: SAML SSO Flows, Single Sign-On, Salesforce Community Single Sign-on (SSO)
NEW QUESTION # 19
An identity architect is setting up an integration between Salesforce and a third-party system. The third-party system needs to authenticate to Salesforce and then make API calls against the REST API.
One of the requirements is that the solution needs to ensure the third party service providers connected app in Salesforce mini need for end user interaction and maximizes security.
Which OAuth flow should be used to fulfill the requirement?
- A. Username-Password Flow
- B. JWT Bearer Flow
- C. Web Server Flow
- D. User Agent Flow
Answer: B
Explanation:
JWTBearer Flow allows the third-party system to authenticate to Salesforce using a digital certificate and a JSON Web Token (JWT) without any user interaction. It also provides a high level of security as it does not require sharing credentials or storing tokens. References: OAuth 2.0 JWT Bearer Token Flow
NEW QUESTION # 20
Universal Containers (UC) is both a Salesforce and Google Apps customer. The UC IT team would like to manage the users for both systems in a single place to reduce administrative burden. Which two optimal ways can the IT team provision users and allow Single Sign-on between Salesforce and Google Apps ? Choose 2 answers
- A. Use Salesforce as the Identity Provider and Google Apps as a Service Provider and configure User Provisioning for Connected Apps.
- B. Use a third-party product as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
- C. Build a custom app running on Heroku as the Identity Provider that can sync user information between Salesforce and Google Apps.
- D. Use Identity Connect as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
Answer: A,B
NEW QUESTION # 21
Universal Containers (UC) wants to provide single sign-on (SSO) for a business-to-consumer (B2C) application using Salesforce Identity.
Which Salesforce license should UC utilize to implement this use case?
- A. Identity Only
- B. Partner Community
- C. External Identity
- D. Salesforce Platform
Answer: C
Explanation:
External Identity is the license that enables SSO for B2C applications using Salesforce Identity. It also provides self-registration, social sign-on, and user profile management features. References: Certification - Identity and Access Management Architect - Trailhead
NEW QUESTION # 22
After a recent audit, universal containers was advised to implement Two-factor Authentication for all of their critical systems, including salesforce. Which two actions should UC consider to meet this requirement?
Choose 2 answers
- A. Require users to supply their email and phone number, which gets validated.
- B. Require users to enter a second password after the first Authentication
- C. Require users to provide their RSA token along with their credentials.
- D. Require users to use a biometric reader as well as their password
Answer: C,D
Explanation:
A is correct because requiring users to provide their RSA token along with their credentials is a form of two- factor authentication. An RSA token is a hardware device thatgenerates a one-time password (OTP) that changes every few seconds. The user needs to enter both their password and the OTP to log in to Salesforce.
D is correct because requiring users to use a biometric reader as well as their password is another form oftwo- factor authentication. A biometric reader is a device that scans a user's fingerprint, face, iris, or other physical characteristics to verify their identity. The user needs to provide both their password and their biometric data to log in to Salesforce.
B is incorrect because requiring users to supply their email and phone number, which gets validated, is not a form of two-factor authentication. This is a form of identity verification, which is used to confirm that the user owns the email and phone number they provided. However, this does not add an extra layer of protection beyond their password when they log in to Salesforce.
C is incorrect because requiring users to enter a second password after the first authentication is not a form of two-factor authentication. This is a form of single-factor authentication, which only relies on something the user knows (their passwords). This does not increase security against unauthorized account access.
References: 4: Multi-Factor Authentication - Salesforce 5: Salesforce Multi-Factor Authentication 6: Two Factor Authentication - Salesforce India 7: Customer 360 | IncreaseProductivity - Salesforce UK 8: Secure Salesforce Login Using Two-Factor Authentication and Salesforce ...
NEW QUESTION # 23
Containers (UC) has decided to implement a federated single Sign-on solution using a third-party Idp.In reviewing the third-party products, they would like to ensure the product supports the automated provisioning and deprovisioning of users. What are the underlining mechanisms that the UC Architect must ensure are part of the product?
- A. Just-in-Time (JIT) for both Provisioning and Deprovisioning.
- B. SOAP API for provisioning; Just-in-Time (JIT) for Deprovisioning.
- C. Provisioning API for both Provisioning and Deprovisioning.
- D. Just-In-time (JIT) for Provisioning; SOAP API for Deprovisioning.
Answer: A
Explanation:
Just-in-Time (JIT) provisioning and deprovisioning can be used to create, update, or deactivate users in Salesforce based on the information in the SAML assertion sent by the IdP. This way, the user lifecycle can be managed automatically without the need for a separate provisioning API. Reference: [Salesforce Help: Just- in-Time Provisioning for SAML]
NEW QUESTION # 24
Which three types of attacks would a 2-Factor Authentication solution help garden against?
- A. Network perimeter attacks
- B. Key logging attacks
- C. Man-in-the-middle attacks
- D. Dictionary attacks
- E. Phishing attacks
Answer: A,B,D
NEW QUESTION # 25
Universal Containers (UC) has implemented SAML-based Single Sign-On to provide seamless access to its Salesforce Orgs, financial system, and CPQ system. Below is the SSO implementationlandscape.
What role combination is represented by the systems in this scenario''
- A. Salesforce Org1 and Salesforce Org2 are the only Service Providers.
- B. Financial System and CPQ System are the only Service Providers.
- C. Salesforce Org1 and PingFederate are acting as Identity Providers.
- D. Salesforce Org1 and Salesforce Org2 are acting as Identity Providers.
Answer: A
Explanation:
In a SAML-based SSO scenario, the identity provider (IdP) is the system that performs authentication and passes the user's identity and authorization level to the service provider (SP), which trusts the IdP and authorizes the user to access the requested resource1. In this case, PingFederate is the IdP that authenticates users for UC and sends SAML assertions to the SPs. The SPs are the systems that rely on PingFederate for authentication and provide access to their services based on the SAML assertions. The SPs in this scenario are Salesforce Org1, Salesforce Org2, Financial System, and CPQ System2. Therefore, the correct answer is B.
References:
SAML web-based authentication guide
SAML-based single sign-on: Configuration and Limitations
NEW QUESTION # 26
Universal containers (UC) does my domain enable in the context of a SAML SSO configuration? Choose 2 answers
- A. Resource deep linking
- B. SSO from salesforce1 mobile app.
- C. App launcher
- D. Login forensics
Answer: A,B
Explanation:
Explanation
Enabling My Domain in the context of a SAML SSO configuration enables resource deep linking and SSO from Salesforce1 mobile app. Resource deep linking allows users to access specific records or pages after logging in with SSO5. SSO from Salesforce1 mobile app requires using the My Domain URL as the login server4. Enabling My Domain does not affect the app launcher or login forensics features. Therefore, option A and C are the correct answers. References: Salesforce Mobile Application Single Sign-On overview, SAML SSO with Salesforce as the Service Provider, Single Sign-On, Considerations for setting up My Domain and SSO
NEW QUESTION # 27
A division of a Northern Trail Outfitters (NTO) purchased Salesforce. NTO uses a third party identity provider (IdP) to validate user credentials against Its corporate Lightweight Directory Access Protocol (LDAP) directory. NTO wants to help employees remember as passwords as possible.
What should an identity architect recommend?
- A. Setup Salesforce as a Service Provider to the existing IdP.
- B. Setup Salesforce as an Authentication Provider to the existing IdP.
- C. Use Salesforce connect to synchronize LDAP passwords to Salesforce.
- D. Setup Salesforce as an IdP to authenticate against the LDAP directory.
Answer: A
NEW QUESTION # 28
Universal Containers wants to secure its Salesforce APIs by using an existing Security Assertion Markup Language (SAML) configuration supports the company's single sign-on process to Salesforce, Which Salesforce OAuth authorization flow should be used?
- A. OAuth 2.0 JWT Bearer Flow
- B. OAuth 2.0 SAML Bearer Assertion Flow
- C. OAuth 2.0 User-Agent Flow
- D. A SAML Assertion Row
Answer: B
Explanation:
Explanation
OAuth 2.0 SAML Bearer Assertion Flow allows a client application to use a SAML assertion to request an access token from Salesforce. This flow can leverage the existing SAML configuration for single sign-on and secure the Salesforce APIs. References: OAuth 2.0 SAML Bearer Assertion Flow
NEW QUESTION # 29
Universal containers(UC) has implemented SAML-BASED single Sign-on for their salesforce application and is planning to provide access to salesforce on mobile devices using the salesforce1 mobile app. UC wants to ensure that single Sign-on is used for accessing the salesforce1 mobile app. Which two recommendations should the architect make? Choose 2 answers
- A. Configure the embedded Web browser to use my domain URL.
- B. Use the existing SAML SSO flow along withWeb server flow
- C. Use the existing SAML SSO flow along with user agent flow.
- D. Configure the salesforce1 app to use the my domain URL
Answer: A,D
Explanation:
To use SAML SSO for accessing the Salesforce1 mobile app, the architect should recommend configuring the embedded web browser to use the My Domain URL and configuring the Salesforce1 app to use the My Domain URL4. Using the My Domain URL allows Salesforce to identify the identityprovider and initiate the SSO process5. Using the existing SAML SSO flow along with user agent flow or web server flow is not necessary because SalesforceMobile Applications only work with service provider initiated setups46.
Therefore, option B and D are the correct answers.
References: Salesforce Mobile Application Single Sign-On overview, SAML SSO with Salesforce as the Service Provider, Single Sign-On
NEW QUESTION # 30
Universal Container's (UC) identity architect needs to recommend a license type for their new Experience Cloud site that will be used by external partners (delivery providers) for reviewing and updating their accounts, downloading files provided by UC and obtaining scheduled pickup dates from their calendar.
UC is using their Salesforce production org as the identity provider for these users and the expected number of individual users is 2.5 million with 13.5 million unique logins per month.
Which of the following license types should be used to meet the requirement?
- A. External Apps License
- B. Partner Community Login License
- C. Partner Community License
- D. Customer Community plus Login License
Answer: D
NEW QUESTION # 31
Universal Containers is budding a web application that will connect with the Salesforce API using JWT OAuth Flow.
Which two settings need to be configured in the connect app to support this requirement?
Choose 2 answers
- A. The Use Digital Signature option in the connected app.
- B. The "edair_api" OAuth scope m the connected app.
- C. The "api" OAuth scope in the connected app.
- D. The "web" OAuth scope in the connected app,
Answer: A,C
Explanation:
Explanation
JWT OAuth Flow is a protocol that allows a client app to obtain an access token from Salesforce by using a JSON Web Token (JWT) instead of an authorization code. The JWT contains information about the client app and the user who wants to access Salesforce. To use this flow, the client app needs to have a connected app configured in Salesforce. The connected app is a framework that enables an external application to integrate with Salesforce using APIs and standard protocols. To support JWT OAuth Flow, two settings need to be configured in the connected app:
The Use Digital Signature option, which enables the connected app to verify the signature of the JWT using a certificate.
The "api" OAuth scope, which allows the connected app to access Salesforce APIs on behalf of the user.
References: JWT OAuth Flow, Connected Apps, OAuth Scopes
NEW QUESTION # 32
Universal Containers (UC) is building a custom Innovation platform on their Salesforce instance. The Innovation platform will be written completely in Apex and Visualforce and will use custom objects to store the Data. UC would like all users to be able to access the system without having to log in with Salesforce credentials. UC will utilize a third-party idp using SAML SSO. What is the optimal Salesforce licence type for all of the UC employees?
- A. Salesforce Platform Licence.
- B. Identity Licence.
- C. External Identity Licence.
- D. Salesforce Licence.
Answer: A
Explanation:
Explanation
The optimal Salesforce license type for all of the UC employees who will access the custom Innovation platform without logging in with Salesforce credentials is the Salesforce Platform license. The Salesforce Platform license allows users to access custom applications built on the Lightning Platform, such as Apex and Visualforce, and use standard objects such as accounts, contacts, reports, dashboards, and custom tabs. It also supports SSO with a third-party identity provider using SAML. Option A is not a good choice because the Identity license is designed for users who need to access Salesforce Identity features, such as identity provider, social sign-on, and user provisioning, but not for users who need to access custom applications. Option B is not a good choice because the Salesforce license is designed for users who need full access to standard CRM and Lightning Platform features, such as leads, opportunities, campaigns, forecasts, and contracts, but it may be unnecessary or expensive for users who only need to access custom applications. Option C is not a good choice because the External Identity license is designed for users who are external to the organization, such as customers or partners, but not for users who are internal employees.
References: Salesforce Help: User License Types, [Salesforce Help: Single Sign-On for Desktop and Mobile Applications using SAML and OAuth]
NEW QUESTION # 33
Which two are valid choices for digital certificates when setting up two-way SSL between Salesforce and an external system. Choose 2 answers
- A. Use a self-signed certificate for salesforce and a trusted CA-signed cert for the external system
- B. Use a trusted CA-signed certificate for salesforce and a self-signed cert for the external system
- C. Use a trusted CA-signed certificate for salesforce and a trusted CA-signed cert for the external system
- D. Use a self-signed certificate for salesforce and a self-signed cert for the external system
Answer: A,D
NEW QUESTION # 34
......
Salesforce Certified Identity and Access Management Architect certification is an excellent choice for professionals who want to build their expertise in identity and access management, and help organizations build secure and scalable systems. With the right preparation and dedication, candidates can pass Identity-and-Access-Management-Architect exam and earn this valuable certification.
Prepare For Realistic Identity-and-Access-Management-Architect Dumps PDF - 100% Passing Guarantee: https://www.pass4leader.com/Salesforce/Identity-and-Access-Management-Architect-exam.html
Practice Test for Identity-and-Access-Management-Architect Certification Real 2026 Mock Exam: https://drive.google.com/open?id=15rpU17YdfG5ke0pzRiQNNqsxBjMzGLk3