Identity-and-Access-Management-Architect Exam Question 6

The security team at Universal Containers (UC) has identified exporting reports as a high-risk action and would like to require users to be logged into Salesforce with their Active Directory (AD) credentials when doing so. For all other users of Salesforce, users should be allowed to use AD Credentials or Salesforce credentials. What solution should be recommended to prevent exporting reports except when logged in using AD credentials while maintaining the ability to view reports when logged in with Salesforce credentials?
  • Identity-and-Access-Management-Architect Exam Question 7

    Universal Containers (UC) uses a home-grown Employee portal for their employees to collaborate. UC decides to use Salesforce Ideas to allow employees to post Ideas from the Employee portal. When users click on some of the links in the Employee portal, the users should be redirected to Salesforce, authenticated, and presented with the relevant pages. What OAuth flow is best suited for this scenario?
  • Identity-and-Access-Management-Architect Exam Question 8

    A service provider (SP) supports both Security Assertion Markup Language (SAML) and OpenID Connect (OIDC).
    When integrating this SP with Salesforce, which use case is the determining factor when choosing OIDC or SAML?
  • Identity-and-Access-Management-Architect Exam Question 9

    How should an identity architect automate provisioning and deprovisioning of users into Salesforce from an external system?
  • Identity-and-Access-Management-Architect Exam Question 10

    An architect needs to set up a Facebook Authentication provider as login option for a salesforce customer Community. What portion of the authentication provider setup associates a Facebook user with a salesforce user?