Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Exam - Topic 3 Question 79 Discussion

Northern Trail Outfitters (NTO) has an off-boarding process where a terminated employee is first disabled in the Lightweight Directory Act Protocol (LDAP) directory, then requests are sent to the various application support teams to finish user deactivations. A terminated employee recently was able to login to NTO's Salesforce instance 24 hours after termination, even though the user was disabled in the corporate LDAP directory.What should an identity architect recommend to prevent this from happening in the future?
B) Configure an authentication provider to delegate authentication to the LDAP directory.
A) Create a Just-in-Time provisioning registration handler to ensure users are deactivated in Salesforce as they are disabled in LDAP.
C) use a login flow to make a callout to the LDAP directory before authenticating the user to Salesforce.
D) Setup an identity provider (IdP) to authenticate users using LDAP, set up single sign-on to Salesforce and disable Login Form authentication.

Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Exam - Topic 3 Question 79 Discussion

Actual exam question for Salesforce's Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) exam
Question #: 79
Topic #: 3
[All Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Questions]

Northern Trail Outfitters (NTO) has an off-boarding process where a terminated employee is first disabled in the Lightweight Directory Act Protocol (LDAP) directory, then requests are sent to the various application support teams to finish user deactivations. A terminated employee recently was able to login to NTO's Salesforce instance 24 hours after termination, even though the user was disabled in the corporate LDAP directory.

What should an identity architect recommend to prevent this from happening in the future?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Sheron
13 days ago
Option D sounds solid too. SSO could streamline the process.
upvoted 0 times
...
Eden
18 days ago
I prefer option C. Checking LDAP before login is smart.
upvoted 0 times
...
Tequila
23 days ago
I think option A is the best. It ensures real-time deactivation.
upvoted 0 times
...
Graciela
29 days ago
Not sure if any of these will really solve the problem long-term.
upvoted 0 times
...
Marilynn
1 month ago
I disagree, option D seems too complicated for this issue.
upvoted 0 times
...
Rodolfo
1 month ago
Wait, how did they even log in after being terminated?
upvoted 0 times
...
Colette
1 month ago
I think option C is the best way to go!
upvoted 0 times
...
Andree
2 months ago
Sounds like a classic case of sync issues between systems.
upvoted 0 times
...
Asuncion
2 months ago
I feel like option C could work, but I wonder if it might slow down the login process too much.
upvoted 0 times
...
Devora
2 months ago
I'm a bit confused about the difference between options B and D. Both seem to involve LDAP, but I can't recall which one is more effective for this scenario.
upvoted 0 times
...
Antonio
2 months ago
I think option A sounds familiar; it might be similar to a practice question we did about user provisioning.
upvoted 0 times
...
Vicky
2 months ago
I remember we discussed the importance of real-time deactivation in our last class, but I'm not sure which option would best achieve that.
upvoted 0 times
...

Save Cancel