フリー問題

Salesforce Certified Platform Identity and Access Management Architect のフリー問題 13 / 20 問目

問題文

An org provisions users with Just-in-Time provisioning during SAML single sign-on. The identity provider knows which department each employee belongs to. How should profiles and permission sets be applied?

選択肢

  1. Have administrators assign the profile and the permission sets by hand after the first login, and run a monthly report that lists users whose assignments do not match their department so that the differences can be corrected before the next audit cycle.
  2. Give every user the same profile.
  3. Pass the values needed to determine access in the assertion and let the provisioning handler set the profile and assign permission sets when it creates or updates the user.
  4. Store the permission set assignments in the identity provider and let it enforce them at each login, which keeps one list of who may do what and saves the administrators a second place to maintain.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。