|
via Udemy |
Go to Course: https://www.udemy.com/course/salesforce-identity-access-management-architect-questions/
Salesforce Certified Identity and Access Management Architect CredentialThe Salesforce Certified Identity and Access Management Architect credential is for professionals aiming to validate their ability to assess identity architectures, design secure and efficient access management solutions on the Customer 360 platform, and communicate technical solutions to both business and technical stakeholders.Skills Required to Pass the ExamTo successfully pass the exam, candidates should be able to:Design identity architectures that integrate multiple platforms and support authentication across systems.Explain system design considerations, benefits, and provide recommendations for identity architecture.Implement best practices in identity and access management within Salesforce environments.Target Audience: Salesforce Certified Identity and Access Management ArchitectThis credential is ideal for individuals who evaluate environments and requirements to create secure, scalable identity management solutions on the Customer 360 platform. Professionals in this role have experience designing and implementing complex identity and access management strategies and can effectively communicate solution trade-offs to both business and technical stakeholders.Required BackgroundExperience:At least 1 year designing and implementing Identity and Access Management solutions within the Salesforce Customer 360 platform.Over 2 years in identity and/or security technologies.Typical Job Roles:Enterprise ArchitectTechnical ArchitectSecurity ArchitectIntegration ArchitectIdentity ArchitectSolution ArchitectKey CompetenciesCandidates should demonstrate the ability to:Differentiate between federated and delegated single sign-on (SSO).Gather requirements and configure delegated authentication and SAML in Salesforce.Understand the distinctions between Identity Provider (IdP) Initiated SAML and Service Provider (SP) Initiated SAML, and determine their appropriate use cases.Establish trust between IdPs and SPs.Assess identity federation capabilities for specific projects.Comprehend high-level concepts and flows of OAuth, SAML, and OpenID Connect.Implement social sign-on and authentication mechanisms for Communities in Salesforce.Troubleshoot common SSO failures in Salesforce.Develop effective SSO strategies to enhance enterprise security.Implement two-factor authentication (2FA) strategies in Salesforce.Utilize login flows effectively.Identify suitable use cases for Identity Connect.Apply appropriate user lifecycle management techniques, including automated and just-in-time provisioning.Areas Where Candidates May Need SupportWriting Apex codeNetworking and domain management related to IdentityConfiguring Salesforce for automated user lifecycle management through user provisioning and Connected AppsSetting up Salesforce to support social sign-on and registrationKnowledge Not RequiredSpecific IdP technology capabilities outside of SalesforceObtaining signed certificatesExam DetailsFormat: 60 multiple-choice/multiple-select questions, plus up to five non-scored questionsDuration: 120 minutesPassing Score: 67%Registration Fee: US$400, plus applicable taxesRetake Fee: US$200, plus applicable taxesDelivery Options: Proctored exam administered at a testing center or online with proctoringMaterials: No reference materials allowed during the examPrerequisites: NoneExam OutlineThe Salesforce Identity and Access Management Architect Exam measures a candidate's knowledge and skills related to the following objectives.Identity Management Concepts: 17%Describe common authentication patterns and understand the differences between each one.Describe the building blocks that are part of an identity solution (authentication, authorization, and accountability) and how you enable those building blocks using Salesforce features.Describe how trust is established between two systems.Given a scenario, recommend the appropriate method for provisioning users in Salesforce.Given a scenario, troubleshoot common points of failure that may be encountered in a single sign-on (SSO) solution (SAML, OAuth, etc.).Accepting Third-Party Identity in Salesforce: 21%Given a use case, describe when Salesforce is used as a Service Provider (SP).Given a scenario, recommend the most appropriate way to provision users from identity stores in business-to-employer (B2E) and business-to-consumer (B2C) scenarios.Given a scenario, recommend the appropriate authentication mechanism when Salesforce needs to accept third-party Identity (Enterprise Directory, Social, Community, etc.).Given a scenario, identify the ways to provision users in Salesforce to enable SSO and apply access rights.Given a scenario, identify the auditing and monitoring approaches available on the platform, and describe the tools available to diagnose Identity Provider (IdP) issues.Salesforce as an Identity Provider: 17%Given a scenario, identify the most appropriate OAuth flow (Web-based, JWT, User agent, Device auth flow).Given a scenario, recommend appropriate Scope and Configuration of the Connected App for Authorization.Describe the various implementation concepts of OAuth (scopes, secrets, tokens, refresh tokens, token expiration, token revocation, etc.).Given a scenario, recommend the Salesforce technologies that should be used to provide identity to the third-party system (Canvas, Connected Apps, App Launcher, etc.).Access Management Best Practices: 15%Given a set of requirements, determine the most appropriate methods of multi-factor authentication (MFA) to use, and the right type of session they should yield.Given a scenario, determine how to best assign roles, profiles, and permission sets to a user during the SSO process, how to keep these assignments up to date.Given a scenario, describe which tools you can apply to audit and verify the activity/user during and after login.Given a scenario, identify the configuration settings for a Connected App.Salesforce Identity: 12%Given a set of requirements, identify the role Identity Connect plays in a Salesforce Identity implementation.Given a scenario, identify if Salesforce Customer 360 Identity fits into a fully-developed Customer 360 solution.Give a set of requirements, recommend the most appropriate Salesforce license type(s).Community (Partner and Customer): 18%Describe the capabilities for customizing the user experience for Experience Cloud (Branding options, authentication options, identity verification self-registration, communications, password reset, etc.).Given a set of requirements, determine the best way to support external IdPs in communities and leverage the right user/contact model to support community user experience.Given a requirement, understand the advantages and limitations of External Identity solutions and associated licenses.Given a scenario, determine when to use embedded login.