The security team at Universal Containers has identified exporting reports as a high-risk action and would like to require users to be logged into Salesforce with their Active Directory (AD) credentials when doing so. For all other uses of Salesforce, users should be allowed to use AD credentials or Salesforce credentials.
What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with Salesforce credentials?
Answer : B
Which three capabilities does SAML-based Federated authentication provide? (Choose three.)
Answer : ABD
Universal Containers is setting up their Customer Community self-registration process. They are uncomfortable with the idea of assigning new users to a default Account record.
What will happen when customers self-register in the Community?
Answer : A
After a recent audit, Universal Containers (UC) was advised to implement Two-Factor Authentication for all of their critical systems, including Salesforce.
Which two actions should UC consider to meet this requirement? (Choose two.)
Answer : AD
Universal Containers (UC) has a mobile application for its employees that uses data from Salesforce as well as uses Salesforce for authentication purposes. UC wants its mobile users to only enter their credentials the first time they run the app. The application has been live for a little over 6 months, and all of the users who were a part of the initial launch are complaining that they have to re-authenticate. UC has also recently changed the URI Scheme associated with the mobile app.
What should the Architect at UC first investigate?
Answer : A
Universal Containers (UC) would like to enable self-registration for their Salesforce Partner Community Users. UC wants to capture some custom data elements from the partner user, and based on these data elements, wants to assign the appropriate Profile and Account values.
Which two actions should the Architect recommend to UC? (Choose two.)
Answer : AC
Universal Containers (UC) wants to build a mobile application that will be making calls to the Salesforce REST API. UC's Salesforce implementation relies heavily on custom objects and custom Apex code. UC does not want its users to have to enter credentials every time they use the app.
Which two scope values should an Architect recommend to UC? (Choose two.)
Answer : AC
Universal Containers (UC) built a Customer Community for customers to buy products, review orders, and manage their accounts. UC has provided three different options for customers to log in to the Customer Community: Salesforce, Google, and Facebook.
Which two role combinations are represented by the systems in this scenario? (Choose two.)
Answer : CD
Universal Containers (UC) has Active Directory (AD) as their enterprise identity store and would like to use it for Salesforce user authentication. UC expects to synchronize user data between Salesforce and AD and assign the appropriate Profile and Permission Sets based on AD group membership.
What would be the recommended way to implement SSO?
Answer : A
Universal Containers (UC) has decided to use Salesforce as an Identity Provider for multiple external applications. UC wants to use the Salesforce App Launcher to control the apps that are available to individual users.
Which three steps are required to make this happen? (Choose three.)
Answer : ACE
Universal Containers (UC) has implemented an SP-initiated SAML flow between an external IdP and Salesforce. A user at UC is attempting to log in to Salesforce mobile app for the first time and is being prompted for Salesforce credentials instead of being shown the IdP login page.
What is the likely cause of the issue?
Answer : D
Which two security risks can be mitigated by enabling Two-Factor Authentication in Salesforce? (Choose two.)
Answer : AD
Universal Containers (UC) would like to enable SAML-based SSO for a Salesforce Partner Community. UC has an existing LDAP identity store and a third-party portal. They would like to use the existing portal as the primary site these users access, but also want to allow seamless access to the Partner Community.
What SSO flow should an Architect recommend?
Answer : A
An Architect needs to set up a Facebook Authentication provider as a login option for a Salesforce Customer Community.
What portion of the authentication provider setup associates a Facebook user with a Salesforce user?
Answer : A
Universal Containers (UC) employees have Salesforce access from restricted IP ranges only, to protect against unauthorized access. UC wants to roll out the Salesforce mobile app and make it accessible from any location.
Which two options should an Architect recommend? (Choose two.)
Answer : BC
Have any questions or issues ? Please dont hesitate to contact us