Salesforce Identity-and-Access-Management-Architect Daily Practice Exam New 2026 Updated 112 Questions [Q22-Q44]

Share

Salesforce Identity-and-Access-Management-Architect Daily Practice Exam New 2026 Updated 112 Questions

Use Valid Identity-and-Access-Management-Architect Exam - Actual Exam Question & Answer

NEW QUESTION # 22
Universal Containers (UC) is building an integration between Salesforce and a legacy web application using the canvas framework. The security for UC has determined that asigned request from Salesforce is not an adequate authentication solution for the Third-Party app. Which two options should the Architect consider for authenticating the third-party app using the canvas framework? Choose 2 Answers

  • A. Create a registration handler Apex class to allow the third-party application to authenticate itself against Salesforce as the Idp.
  • B. Utilize Canvas OAuth flow to allow the third-party application to authenticate itself against Salesforce as the Idp.
  • C. Utilize the SAML Single Sign-on flow to allow the third-party to authenticate itself against UC's IdP.
  • D. Utilize Authorization Providers to allow the third-party application to authenticate itself against Salesforce as the Idp.

Answer: B,C

Explanation:
The Canvas framework supports OAuth 2.0 for authorization1. There are two OAuth flows that can be used to authenticate the third-party app using the canvas framework: User-Agent OAuth Flow and Web Server OAuth Flow2. The User-Agent OAuth Flow uses the Canvas JavaScript SDK to obtain an OAuth token by using the login function in the SDK2. The Web Server OAuth Flow redirects the user to the Salesforce OAuthauthorization endpoint and then obtains an OAuth access token by making a POST request to the Salesforce OAuth token endpoint2. Both of these flows allow the third-party app to authenticate itself against Salesforce as the IdP. The SAML Single Sign-on flow can also be used to allow the third-party app to authenticate itself against UC's IdP, which is another option for authentication3.
References: OAuth Authorization, Mastering Salesforce Canvas Apps, Integrate third-party applications via Canvas App


NEW QUESTION # 23
Northern Trail Outfitters (NTO) has a requirement to ensure all user logins include a single multi-factor authentication (MFA) prompt. Currently, users are allowed the choice to login with a username and password or via single sign-on against NTO's corporate Identity Provider, which includes built-in MFA.
Which configuration will meet this requirement?

  • A. For all employee profiles, set the Session Level Required at Login to High Assurance and add the corporate identity provider to the High Assurance list for the org's Session Security Levels.
  • B. Create and assign a permission set to all employees that includes "MFA for User Interface Logins."
  • C. Enable "MFA for User Interface Logins" for your organization from Setup -> Identity Verification.
  • D. Create a custom login flow that enforces MFA and assign it to a permission set. Then assign the permission set to all employees.

Answer: C


NEW QUESTION # 24
An Identity and Access Management (IAM) architect is tasked with unifying multiple B2C Commerce sites and an Experience Cloud community with a single identity. The solution needs to support more than 1,000 logins per minute.
What should the IAM Architect do to fulfill this requirement?

  • A. Confirm performance considerations with Salesforce Customer Support due to high peaks.
  • B. Configure community as a Security Assertion Markup Language (SAML) identity provider and enable Just-In-Time Provisioning to B2C Commerce.
  • C. Create a default account for capturing all ecommerce contacts registered on the community because personAccount is not supported for this case.
  • D. Configure both the community and the commerce sites as OAuth2 RPs (relying party) with an external identity provider.

Answer: A

Explanation:
When a single identity design must support very high external login volumes, performance becomes part of the architecture, not just feature selection. Salesforce Experience Cloud and identity features can support large-scale CIAM scenarios, but official guidance encourages validating expected login peaks and performance assumptions with Salesforce for unusually high throughput requirements. That is especially important when the solution spans communities and commerce experiences and expects more than a thousand logins per minute. The question is not just whether the platform supports federation, Person Accounts, or an external identity provider; it is whether the design has been reviewed for operational scale. Confirming performance considerations with Salesforce is therefore the prudent architectural step before finalizing the rollout model. This is why option B is the best answer in Salesforce terms.


NEW QUESTION # 25
An Enterprise is using a Lightweight Directory Access Protocol (LDAP ) server as the only point for user authentication with a username/password. Salesforce delegated authentication is configured to integrate Salesforce under single sign-on (SSO).
Mow can end users change their password?

  • A. Users can request the Salesforce Admin to reset their password.
  • B. Users can change it on the enterprise LDAP authentication portal.
  • C. Users can click on the "Forgot your Password" link on the Salesforce.com login page.
  • D. Users once logged In, can go to the Change Password screen in Salesforce.

Answer: A

Explanation:
Explanation
Users can request the Salesforce Admin to reset their password if they are using delegated authentication with LDAP. The other options are not applicable for this scenario, as the password is managed by the LDAP server, not by Salesforce. References: Delegated Authentication, FAQs for Delegated Authentication


NEW QUESTION # 26
Universal containers (UC) wants users to authenticate into their salesforce org using credentials stored in a custom identity store. UC does not want to purchase or use a third-party Identity provider. Additionally, UC is extremely wary of social media and does not consider it to be trust worthy. Which two options should an architect recommend to UC? Choose 2 answers

  • A. Use a professional social media such as LinkedIn as an Authentication provider
  • B. Implement the Openid protocol and configure an authentication provider
  • C. Build a custom web page that uses the identity store and calls frontdoor.jsp
  • D. Build a custom Web service that is supported by Delegated Authentication.

Answer: B,D

Explanation:
Explanation
The two options that an architect should recommend to UC are to build a custom web service that is supported by delegated authentication and to implement the OpenID protocol and configure an authentication provider. Delegated authentication is a feature that allows Salesforce to delegate user authentication to an external service instead of using Salesforce credentials3. A custom web service can be built to use the credentials stored in the custom identity store and validate them against Salesforce using SOAP or REST API3. OpenID is an open standard protocol that allows users to authenticate with various web services using an existing account4. An authentication provider can be configured in Salesforce to use OpenID and connect with the custom identity store5.
References: Delegated Authentication, OpenID, Authentication Providers


NEW QUESTION # 27
Northern Trail Outfitters (NTO) uses Salesforce for Sales Opportunity Management. Okta was recently brought in to Just-in-Time (JIT) provision and authenticate NTO users to applications. Salesforce users also use Okta to authorize a Forecasting web application to access Salesforce records on their behalf.
Which two roles are being performed by Salesforce?
Choose 2 answers

  • A. OAuth Resource Server
  • B. SAML Identity Provider
  • C. OAuth Client
  • D. SAML Service Provider

Answer: C,D


NEW QUESTION # 28

A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APAC. The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS . The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.
What is recommended to ensure these requirements are met ?

  • A. Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.
  • B. Add a central identity system that federates between the ADFS systems and integrate with Salesforce for single sign-on.
  • C. Configure Each ADFS system under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce-
  • D. Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.

Answer: D


NEW QUESTION # 29
After a recent audit, universal containers was advised to implement Two-factor Authentication for all of their critical systems, including salesforce. Which two actions should UC consider to meet this requirement?
Choose 2 answers

  • A. Require users to enter a second password after the first Authentication
  • B. Require users to supply their email and phone number, which gets validated.
  • C. Require users to provide their RSA token along with their credentials.
  • D. Require users to use a biometric reader as well as their password

Answer: C,D

Explanation:
A is correct because requiring users to provide their RSA token along with their credentials is a form of two- factor authentication. An RSA token is a hardware device thatgenerates a one-time password (OTP) that changes every few seconds. The user needs to enter both their password and the OTP to log in to Salesforce.
D is correct because requiring users to use a biometric reader as well as their password is another form oftwo- factor authentication. A biometric reader is a device that scans a user's fingerprint, face, iris, or other physical characteristics to verify their identity. The user needs to provide both their password and their biometric data to log in to Salesforce.
B is incorrect because requiring users to supply their email and phone number, which gets validated, is not a form of two-factor authentication. This is a form of identity verification, which is used to confirm that the user owns the email and phone number they provided. However, this does not add an extra layer of protection beyond their password when they log in to Salesforce.
C is incorrect because requiring users to enter a second password after the first authentication is not a form of two-factor authentication. This is a form of single-factor authentication, which only relies on something the user knows (their passwords). This does not increase security against unauthorized account access.
References: 4: Multi-Factor Authentication - Salesforce 5: Salesforce Multi-Factor Authentication 6: Two Factor Authentication - Salesforce India 7: Customer 360 | IncreaseProductivity - Salesforce UK 8: Secure Salesforce Login Using Two-Factor Authentication and Salesforce ...


NEW QUESTION # 30
Universal Containers (UC) wants to build a mobile application that twill be making calls to the Salesforce REST API. UC's Salesforce implementation relies heavily on custom objects and custom Apex code. UC does not want its users to have to enter credentials every time they use the app. Which two scope values should an Architect recommend to UC? Choose 2 answers.

  • A. Custom_permissions
  • B. Refresh_token
  • C. Full
  • D. Api

Answer: B,D

Explanation:
The two scope values that an architect should recommend to UC are api and refresh_token. The api scope allows the app to access the Salesforce REST API and use custom objects and custom Apex code.
Therefresh_token scope allows the app to obtain a refresh token that can be used to get new access tokens without requiring the user to re-enter credentials. Option A is not a good choice because the custom_permissions scope allows the app to access custom permissions in Salesforce, but it does not affect how the app can access the REST API or avoid user re-authentication. Option D is not a good choice because the full scope allows the app to access all data accessible by the user, including the web UI and theAPI, but it may be unnecessary or insecure for UC's requirement. References: OAuth 2.0 Web Server Authentication Flow, Digging Deeper into OAuth 2.0 on Force.com


NEW QUESTION # 31
Which two security risks can be mitigated by enabling Two-Factor Authentication (2FA) in Salesforce?
Choose 2 answers

  • A. Users creating simple-to-guess password reset questions.
  • B. Users accessing Salesforce from a public Wi-Fi access point.
  • C. Users leaving laptops unattended and not logging out of Salesforce.
  • D. Users choosing passwords that are the same as their Facebook password.

Answer: B,D

Explanation:
Explanation
Enabling Two-Factor Authentication (2FA) in Salesforce can mitigate the security risks of users accessing Salesforce from a public Wi-Fi access point or choosing passwords that are the same as their Facebook password. 2FA is an additional layer of protection beyond your password that requires users to verify their identity with another factor, such as a mobile app, a security key, or a verification code. This can prevent unauthorized access even if the user's password is compromised or guessed by a malicious actor. The other options are not directly related to 2FA, but rather to user behavior or password policies.


NEW QUESTION # 32
Universal containers (UC) wants to integrate a Web application with salesforce. The UC team hasimplemented the Oauth web-server Authentication flow for authentication process. Which two considerations should an architect point out to UC? Choose 2 answers

  • A. The web server must be able to protect consumer privacy
  • B. The web application should be hosted on a secure server.
  • C. The flow will not provide an Oauth refresh token back to the server.
  • D. The flow involves passing the user credentials back and forth.

Answer: A,B

Explanation:
The web application should be hosted on a secure server and the web server must be able to protect consumer privacy are two considerations that an architect should point out to UC. To integrate an external web app with the Salesforce API, UC can use the OAuth 2.0 web server flow, which implements the OAuth 2.0 authorization code grant type4. With this flow, the server hosting the web app must be able to protect the connected app's identity, defined by the client ID and client secret4. The web application should be hosted on a secure server to ensure that the communication between the web app and Salesforce is encrypted and protected from unauthorized access or tampering6. The web server must be able to protect consumer privacy to comply with data protection laws and regulations, such as GDPR or CCPA . The web server should implement best practices for storing and handling user data, such as encryption, hashing, salting, and anonymization. The flow involves passing the user credentials back and forth is not a correct consideration, as the web server flow does not require the user credentials to be passed between the web app and Salesforce. Instead,it uses an authorization code that is exchanged for an access token and a refresh token4. The flow will not provide an OAuth refreshtoken back to the server is also not a correct consideration, as the web server flow does provide a refresh token that can be usedto obtain new access tokens without user interaction4. References: OAuth 2.0 Web Server Flow for Web App Integration, Secure Your Web Application, [General Data Protection Regulation (GDPR)], [California Consumer Privacy Act (CCPA)],
[Data Protection Best Practices]


NEW QUESTION # 33
A leading fitness tracker company is getting ready to launch a customer community. The company wants its customers to login to the community and connect their fitness device to their profile. Customers should be able to obtain exercise details and fitness recommendation in the community.
Which should be used to satisfy this requirement?

  • A. OAuth Device Flow
  • B. Named Credentials
  • C. Login Flows
  • D. OAuth Asset Token flow

Answer: D

Explanation:
The OAuth 2.0 Asset Token Flow is Salesforce's purpose-built answer for connected devices and IoT-style integrations. It is designed for assets that need to act on behalf of a physical device or asset record rather than a human user. That makes it the correct fit for sensors, GPS trackers, or smart devices that must securely post telemetry or create service actions in Salesforce. User-agent, web-server, or username-password flows are built around user identity or generic application access, not around a registered device/asset relationship. The architectural advantage of the asset token model is that it ties the authorization context back to the asset, which is exactly what you want when the platform must know which device generated the event or maintenance alert. This is why option D is the best answer in Salesforce terms.


NEW QUESTION # 34
Containers (UC) uses an internal system for recruiting and would like to have thecandidates' info available in the Salesforce automatically when they are selected. UC decides to use OAuth to connect to Salesforce from the recruiting system and would like to do the authentication using digital certificates. Which two OAuth flows shouldbe considered to meet the requirement? Choose 2 answers

  • A. JWT Bearer Token flow
  • B. Refresh Token flow
  • C. Web Service flow
  • D. SAML Bearer Assertion flow

Answer: A,D

Explanation:
JWT Bearer Token flow and SAML Bearer Assertion flow are two OAuth flows that can be usedto authenticate to Salesforce using digital certificates. JWT Bearer Token flow allows a connected app to request an access token from Salesforce by using a JSON Web Token (JWT) that is signed with a digital certificate.
SAML Bearer Assertion flow allowsa connected app to request an access token from Salesforce by using a SAML assertion that is signed with a digital certificate. These two flows can meet therequirement of UC to use OAuth and digital certificates to connect to Salesforce from the recruiting system.


NEW QUESTION # 35
Containers (UC) has implemented SAML-based single Sign-on for their Salesforce application and is planning to provide access to Salesforce on mobile devices using the Salesforce1 mobile app. UC wants to ensure that Single Sign-on is used for accessing the Salesforce1 mobile App. Which two recommendations should the Architect make? Choose 2 Answers

  • A. Use the existing SAML-SSO flow along with User Agent Flow.
  • B. Configure the Salesforce1 App to use the MY Domain URL.
  • C. Configure the Embedded Web Browser to use My Domain URL.
  • D. Use the existing SAML SSO flow along with Web Server Flow.

Answer: A,B

Explanation:
Explanation
To ensure that SSO is used for accessing the Salesforce1 mobile app, UC should configure the Salesforce1 app to use the My Domain URL instead of the default login.salesforce.com URL. My Domain is a feature that allows UC to create a custom domain name for their Salesforce org that supports SSO with their identity provider. UC should also use the existing SAML-SSO flow along with User Agent Flow, which is an OAuth
2.0 flow that allows users to authenticate with their identity provider through an embedded browser within the mobile app. Verified References: [Configure SSO with Salesforce as a SAML Service Provider], [User-Agent Flow]


NEW QUESTION # 36
Universal Containers (UC) has built a custom time tracking app for its employee. UC wants to leverage Salesforce Identity to control access to the custom app.
At a minimum, which Salesforce license is required to support this requirement?

  • A. Identity Verification
  • B. Identity Connect
  • C. External Identity
  • D. Identity Only

Answer: D


NEW QUESTION # 37
Universal Containers (UC) is using its production org as the identity provider for a new Experience Cloud site and the identity architect is deciding which login experience to use for the site.
Which two page types are valid login page types for the site?
Choose 2 answers

  • A. Experience Builder Page
  • B. Login Discovery Page
  • C. Embedded Login Page
  • D. lightning Experience Page

Answer: B,C


NEW QUESTION # 38
Users logging into Salesforce are frequently prompted to verify their identity.
The identity architect is required to provide recommendations so that frequency of prompt verification can be reduced.
What should the identity architect recommend to meet the requirement?

  • A. Implement 2FA authentication for the Salesforce org.
  • B. Set trusted IP ranges for the organization.
  • C. Implement a single sign-on for Salesforce using an externalidentity provider.
  • D. Implement multi-factor authentication for the Salesforce org.

Answer: B

Explanation:
To reduce the frequency of prompt verification for users logging into Salesforce, the identity architect should recommend setting trusted IP ranges for the organization. Trusted IP ranges are IP addresses that are considered safe for logging in without any additional verification. Users who log in from trusted IP ranges do not need to activate their computer or use a verification code. Trusted IP ranges can improve user convenience and security. References: Trusted IP Ranges, Set Trusted IP Ranges for Your Organization


NEW QUESTION # 39
A financial enterprise is planning to set up a user authentication mechanism to login to the Salesforce system.
Due to regulatory requirements, the CIO of the company wants user administration, including passwords and authentication requests, to be managed by an external system that is only accessible via a SOAP webservice.
Which authentication mechanism should an identity architect recommend to meet the requirements?

  • A. Delegated Authentication
  • B. Security Assertion Markup Language (SANL) Single Sign On
  • C. OAuth Web-Server Flow
  • D. Just-in-Time Provisioning

Answer: A

Explanation:
Delegated Authentication is the Salesforce mechanism intended for organizations that must keep password validation and authentication processing in an external system reachable through a web service. In this model, Salesforce sends the authentication request outward and relies on the external service to decide whether the credentials are valid. That is a strong fit when regulations or internal policy require the external system to remain authoritative for passwords and authentication logic. JIT provisioning and SAML SSO solve adjacent problems, but they do not match the stated SOAP-based password-validation requirement. The important architecture cue is the external SOAP web service: that points directly to delegated authentication rather than to token-based federation or user-provisioning features. This is why option B is the best answer in Salesforce terms.


NEW QUESTION # 40
A service provider (SP) supports both Security Assertion Narkup Language (SAML) and OpenID Connect (OIDC).
When Salesforce is acting as Identity Provider for this SP, which use case is the determining factor when choosing OIDC or SAML?

  • A. the SP needs to perform our calls back to Salesforce on behalf of the user after the user logs in to the service provider.
  • B. OIDC is more secure than SAML and therefore is the obvious choice.
  • C. They are equivalent protocols and there is no real reason to choose one over the other.
  • D. If the user has a session on Salesforce, you do not want them to be promoted for a username and password when they login to the SP.

Answer: A

Explanation:
When a service provider needs to continue making calls back to Salesforce on behalf of the user after login, OpenID Connect is usually the more natural choice because it sits in the OAuth family and aligns well with token-based delegated access. SAML is excellent for browser-based federation, but it is not as naturally suited to modern API token usage after the interactive sign-in event. The question is not simply "which protocol is more secure." It is about post-login application behavior. If the downstream application needs identity plus a token-friendly pattern for additional calls, that use case pushes the architect toward OIDC. In other words, the deciding factor is what the service provider must do after the initial authentication succeeds. This is why option B is the best answer in Salesforce terms.


NEW QUESTION # 41
An Identity and Access Management (IAM) Architect is recommending Identity Connect to integrate Microsoft Active Directory (AD) with Salesforce for user provisioning, deprovisioning and single sign-on (SSO).
Which feature of Identity Connect is applicable for this scenario?

  • A. If the number of provisioned users exceeds Salesforce license allowances, identity Connect will start disabling the existingSalesforce users in First-in, First-out (FIFO) fashion.
  • B. When configured, Identity Connect acts as an identity provider to both Active Directory and Salesforce, thus providing SSO as a default feature.
  • C. When Identity Connect is in place, if a user is deprovisioned in an on-premise AD, the user's Salesforce session Is revoked Immediately.
  • D. Identity Connect can be deployed as amanaged package on salesforce org, leveraging High Availability of Salesforce Platform out-of-the-box.

Answer: C

Explanation:
Identity Connect is a tool that synchronizes user data between Microsoft Active Directory and Salesforce. It allows user provisioning, deprovisioning, and single sign-on (SSO) between multiple Active Directory domains and a single Salesforce org. Oneof the features of Identity Connect is that it can revoke the user's Salesforce session immediately when the user is deprovisioned in an on-premise Active Directory. This can enhance security and compliance by preventing unauthorized access to Salesforceresources. References:
Identity Connect Implementation Guide, Identity Connect Overview


NEW QUESTION # 42
Universal Containers (UC) currently uses Salesforce Sales Cloud and an external billing application. Both Salesforce andthe billing application are accessed several times a day to manage customers. UC would like to configure single sign-on and leverageSalesforce as the identity provider. Additionally, UC would like the billing application to be accessible from Salesforce.A redirect is acceptable.
Which two Salesforce tools should an identity architect recommend to satisfy the requirements?
Choose 2 answers

  • A. Connected Apps
  • B. App Launcher
  • C. salesforce Canvas
  • D. Identity Connect

Answer: B,C

Explanation:
Salesforce Canvas is a tool that allows external applications to be embedded into Salesforce as iframes, which can provide a seamless user experience. App Launcher is a feature that allows users to access connected apps from a single location in Salesforce. To enable single sign-on anduse Salesforce as the identity provider, the external billing application needs to be configured as a connected app and use an OAuth 2.0 or SAML protocol. Identity Connect is not relevant for this scenario, as it is a tool for synchronizing user data between Salesforce and Active Directory. References: Salesforce Canvas Developer Guide, App Launcher, Connected Apps


NEW QUESTION # 43
Northern Trail Outfitters (NTO) leverages Microsoft Active Directory (AD) for management of employee usernames, passwords, permissions, and asset access. NTO also owns a third-party single sign-on (SSO) solution. The third-party party SSO solution is used for all corporate applications, including Salesforce.
NTO has asked an architect to explore Salesforce Identity Connect for automatic provisioning and deprovisioning of users in Salesforce.
What role does identity Connect play in the outlined requirements?

  • A. Service Provider
  • B. User Management
  • C. Identity Provider
  • D. Single Sign-On

Answer: B

Explanation:
Explanation
Salesforce Identity Connect is a tool that synchronizes user data between Microsoft Active Directory and Salesforce. It allows automatic provisioning and deprovisioning of users in Salesforce based on the changes made in Active Directory. Therefore, Identity Connect plays the role of user management in the outlined requirements. References: Identity Connect Implementation Guide, Identity Connect Overview


NEW QUESTION # 44
......


Salesforce is a company that provides Customer Relationship Management (CRM) solutions to businesses of all sizes. One of the key features of Salesforce is its Identity and Access Management (IAM) system, which allows businesses to control who has access to their data and applications. To ensure that their IAM system is properly implemented, Salesforce has developed the Identity and Access Management Architect certification. Salesforce Certified Identity and Access Management Architect certification is designed for experienced architects who are responsible for designing and implementing IAM solutions that meet the needs of their organizations.

 

Test Engine to Practice Identity-and-Access-Management-Architect Test Questions: https://actualtests.troytecdumps.com/Identity-and-Access-Management-Architect-troytec-exam-dumps.html