Salesforce Certified Identity and Access Management Designer Free Sample Questions

4 free sample questions34 in the full practice test

Try simulator

Identity and Access Management Designer Sample Questions

  1. Question 1

    Case Study: Global Finance Inc. Identity Modernization

    Company Background:
    Global Finance Inc. (GFI) is a multinational financial services company. Their primary Salesforce org serves as the central hub for customer relationship management. They are developing a new suite of applications to be used by internal employees, external financial partners, and retail customers. The primary Salesforce org must act as the central Identity Provider (IdP) for this new ecosystem.

    Application Ecosystem:

    1. Internal Analytics Dashboard: A confidential web application hosted on-premise that requires server-to-server API access to pull Salesforce data. The app must act on behalf of the logged-in user to respect sharing rules.
    2. Partner Portal: A separate Salesforce Experience Cloud org for financial partners. Partners should log in to the primary GFI org and then access the Partner Portal seamlessly.
    3. Mobile Client App: A native iOS/Android application for retail customers that will use the primary GFI org for authentication and API access. The app must securely handle sessions on the mobile device.

    Requirements & Constraints:

    • The primary GFI org must be the single source of truth for identity.
    • Server-to-server communication must not involve storing user passwords.
    • Partner access must be seamless after initial login (SSO).
    • The mobile app must provide a secure and long-lived session without requiring frequent logins.

    Which combination of identity protocols and flows represents the most secure and appropriate architectural solution for this ecosystem?

    graph TD subgraph Primary_Org [Primary Salesforce Org (IdP)] direction LR Users((Users)) end subgraph Applications A[Internal Analytics Dashboard] B[Partner Portal (Experience Cloud)] C[Mobile Client App] end Users --> Primary_Org Primary_Org --> A Primary_Org --> B Primary_Org --> C

    Answer and explanation

    Correct answer: C

    This solution correctly maps each requirement to the appropriate protocol: 1) The JWT Bearer Flow is ideal for secure, non-interactive server-to-server authentication. 2) SAML SSO is the standard for providing seamless access between Salesforce orgs where one acts as an IdP. 3) The User-Agent flow is designed for native mobile apps, and using a refresh token allows the app to maintain a long-lived session securely without storing user credentials.

  2. Question 2

    Universal Containers (UC) has decided to build a new, highly sensitive application on the Lightning platform. The security team at UC has decided that they want users to provide a fingerprint in addition to username/password to authenticate to this application.How can an Architect support fingerprints as a form of identification for Salesforce authentication?

    Answer and explanation

    Correct answer: D

Register free to unlock 2 more sample questions

Lifetime One

Own this practice test forever.

$46.31
$43.99
one-time
  • Full access to 34 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon