フリー問題

Salesforce Certified Platform Identity and Access Management Architect のフリー問題 9 / 20 問目

問題文

A mobile application installed on employees' phones needs authorized access to Salesforce data. The executable sits on the device, so any secret compiled into it can be extracted. Which flow is designed for this situation?

選択肢

  1. The Client Credentials flow, and the application can present its own consumer key and consumer secret to the token endpoint and receive a token issued on behalf of a designated integration user, which avoids showing a login page on the small screen.
  2. The SAML Bearer flow, where the mobile application signs its own assertion with the secret compiled into it and exchanges that assertion for a token.
  3. The Device flow, because the application runs on a device, and the phone can show the short code that the employee then types on a computer.
  4. The User-Agent flow, which does not use the client secret and returns the token through an external or embedded browser.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。