IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT Exam Details

  • Exam Code
    :IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT
  • Exam Name
    :Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
  • Certification
    :Salesforce Certifications
  • Vendor
    :Salesforce
  • Total Questions
    :247 Q&As
  • Last Updated
    :May 27, 2026

Salesforce IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT Online Questions & Answers

  • Question 141:

    A company wants to provide its employees with a custom mobile app that accesses Salesforce. Users are required to download the internal native IOS mobile app from corporate intranet on their mobile device. The app allows flexibility to access other Non Salesforce internal applications once users authenticate with Salesforce. The apps self- authorize, and users are permitted to use the apps once they have logged into Salesforce.

    How should an identity architect meet the above requirements with the privately distributed mobile app?

    A. Use connected app with OAuth and Security Assertion Markup Language (SAML) to access other Non Salesforce internal apps.
    B. Configure Mobile App settings in connected app and Salesforce as identity provider for non-Salesforce internal apps.
    C. Use Salesforce as an identity provider (IdP) to access the mobile app and use the external IdP for other non-Salesforce internal apps.
    D. Create a new hybrid mobile app and use the connected app with OAuth to authenticate users for Salesforce and non-Salesforce internal apps.

  • Question 142:

    An Enterprise is using a Lightweight Directory Access Protocol (LDAP ) server as the only point for user authentication with a username/password. Salesforce delegated authentication is configured to integrate Salesforce under single sign-on (SSO).

    Mow can end users change their password?

    A. Users once logged In, can go to the Change Password screen in Salesforce.
    B. Users can click on the "Forgot your Password" link on the Salesforce.com login page.
    C. Users can request the Salesforce Admin to reset their password.
    D. Users can change it on the enterprise LDAP authentication portal.

  • Question 143:

    Universal Containers (UC) would like its community users to be able to register and log in with Linkedin or Facebook Credentials. UC wants users to clearly see Facebook andLinkedin Icons when they register and login. What are the two recommended actions UC can take to achieve this Functionality? Choose 2 answers

    A. Enable Facebook and Linkedin as Login options in the login section of the Community configuration.
    B. Create custom Registration Handlers to link Linkedin and facebook accounts to user records.
    C. Store the Linkedin or Facebook user IDs in the Federation ID field on the Salesforce User record.
    D. Create custom buttons for Facebook and inkedin using JAVAscript/CSS on a custom Visualforce page.

  • Question 144:

    Northern Trail Outfitters (NTO) is setting up Salesforce to authenticate users with an external identity provider. The NTO Salesforce Administrator is having trouble getting things setup.

    What should an identity architect use to show which part of the login assertion is fading?

    A. SAML Metadata file importer
    B. Identity Provider Metadata download
    C. Connected App Manager
    D. Security Assertion Markup Language Validator

  • Question 145:

    A real estate company wants to provide its customers a digital space to design their interior decoration options. To simplify the registration to gain access to the community site (built in Experience Cloud), the CTO has requested that the IT/ Development team provide the option for customers to use their existing social-media credentials to register and access.

    The IT lead has approached the Salesforce Identity and Access Management (IAM) architect for technical direction on implementing the social sign-on (for Facebook, Twitter, and a new provider that supports standard OpenID Connect (OIDC)).

    Which two recommendations should the Salesforce IAM architect make to the IT Lead?

    Choose 2 answers

    A. Use declarative registration handler process builder/flow to create, update users and contacts.
    B. Authentication provider configuration is required each social sign-on providers; and enable Authentication providers in community.
    C. For supporting OIDC it is necessary to enable Security Assertion Markup Language (SAML) with Just-in-Time provisioning (JIT) and OAuth 2.0.
    D. Apex coding skills are needed for registration handler to create and update users.

  • Question 146:

    Universal Containers wants to implement SAML SSO for their internal Salesforce users using a third-party IdP. After some evaluation, UC decides not to set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?

    A. SP-initiated SSO will not work.
    B. Neither SP- nor IdP-initiated SSO will work.
    C. Either SP- or IdP-initiated SSO will work.
    D. IdP-initiated SSO will not work.

  • Question 147:

    Universal containers wants to set up SSO for a selected group of users to access external applications from salesforce through App launcher. Which three steps must be completed in salesforce to accomplish the goal?

    A. Associate user profiles with the connected Apps.
    B. Complete my domain and Identity provider setup.
    C. Create connected apps for the external applications.
    D. Complete single Sign-on settings in security controls.
    E. Create named credentials for each external system.

  • Question 148:

    Universal Containers built a custom mobile app for their field reps to create orders in Salesforce. OAuth is used for authenticating mobile users. The app is built in such a way that when a user session expires after Initial login, a new access token is obtained automatically without forcing the user to log in again. While that improved the field reps' productivity, UC realized that they need a "logout" feature.

    What should the logout function perform in this scenario, where user sessions are refreshed automatically?

    A. Invoke the revocation URL and pass the refresh token.
    B. Clear out the client Id to stop auto session refresh.
    C. Invoke the revocation URL and pass the access token.
    D. Clear out all the tokens to stop auto session refresh.

  • Question 149:

    Northern Trail Outfitters (NTO) wants to improve its engagement with existing customers to boost customer loyalty. To get a better understanding of its customers, NTO establishes a single customer view including their buying behaviors,

    channel preferences and purchasing history. All of this information exists but is spread across different systems and formats.

    NTO has decided to use Salesforce as the platform to build a 360 degree view. The company already uses Microsoft Active Directory (AD) to manage its users and company assets.

    What should an Identity Architect do to provision, deprovision and authenticate users?

    A. Salesforce Identity is not needed since NTO uses Microsoft AD.
    B. Salesforce Identity can be included but NTO will be required to build a custom integration with Microsoft AD.
    C. Salesforce Identity is included in the Salesforce licenses so it does not need to be considered separately.
    D. A Salesforce Identity can be included but NTO will require Identity Connect.

  • Question 150:

    What are three capabilities of Delegated Authentication? Choose 3 answers

    A. It can be assigned by Custom Permissions.
    B. It can connect to SOAP services.
    C. It can be assigned by Permission Sets.
    D. It can be assigned by Profiles.
    E. It can connect to REST services.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Salesforce exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT exam preparations and Salesforce certification application, do not hesitate to visit our Vcedump.com to find your solutions here.