Skip to content

Salesforce Certified Identity and Access Management Designer Practice Questions

Prepare for Identity and Access Management Designer with more than an answer.

34 questions in the full set4 sample questionsUpdated Oct 25, 2025
Exam fee
$400 USD
Level
Architect
Valid for
3 years
Domains covered on the exam 6
  1. Identity Management Concepts17%
  2. Accepting 3rd Party Identity in Salesforce23%
  3. Salesforce as an Identity Provider17%
  4. Access Management Best Practices11%
  5. Salesforce Identity15%
  6. Community (Partner and Customer)17%
  1. 1

    How should an Architect force users to authenticate with Two-factor Authentication (2FA) for Salesforce only when NOT connected to an internal company network? A.Apply the “Two-factor Authentication for User Interface Logins” permission and Login IP Ranges for all Profiles.B.Add the company's list of network IP addresses to the Login Range list under 2FA Setup.C.Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA if needed.D.Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.

    Show answer details

    Correct answer: C

  2. 2

    Case Study: Global Finance Inc. Identity Modernization

    Company Background:
    Global Finance Inc. (GFI) is a multinational financial services company. Their primary Salesforce org serves as the central hub for customer relationship management. They are developing a new suite of applications to be used by internal employees, external financial partners, and retail customers. The primary Salesforce org must act as the central Identity Provider (IdP) for this new ecosystem.

    Application Ecosystem:

    1. Internal Analytics Dashboard: A confidential web application hosted on-premise that requires server-to-server API access to pull Salesforce data. The app must act on behalf of the logged-in user to respect sharing rules.
    2. Partner Portal: A separate Salesforce Experience Cloud org for financial partners. Partners should log in to the primary GFI org and then access the Partner Portal seamlessly.
    3. Mobile Client App: A native iOS/Android application for retail customers that will use the primary GFI org for authentication and API access. The app must securely handle sessions on the mobile device.

    Requirements & Constraints:

    • The primary GFI org must be the single source of truth for identity.
    • Server-to-server communication must not involve storing user passwords.
    • Partner access must be seamless after initial login (SSO).
    • The mobile app must provide a secure and long-lived session without requiring frequent logins.

    Which combination of identity protocols and flows represents the most secure and appropriate architectural solution for this ecosystem?

    graph TD subgraph Primary_Org [Primary Salesforce Org (IdP)] direction LR Users((Users)) end subgraph Applications A[Internal Analytics Dashboard] B[Partner Portal (Experience Cloud)] C[Mobile Client App] end Users --> Primary_Org Primary_Org --> A Primary_Org --> B Primary_Org --> C

    Show answer details

    Correct answer: C

    This solution correctly maps each requirement to the appropriate protocol: 1) The JWT Bearer Flow is ideal for secure, non-interactive server-to-server authentication. 2) SAML SSO is the standard for providing seamless access between Salesforce orgs where one acts as an IdP. 3) The User-Agent flow is designed for native mobile apps, and using a refresh token allows the app to maintain a long-lived session securely without storing user credentials.

Create an account to continue.