IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT Exam Details

  • Exam Code
    :IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT
  • Exam Name
    :Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
  • Certification
    :Salesforce Certifications
  • Vendor
    :Salesforce
  • Total Questions
    :247 Q&As
  • Last Updated
    :May 27, 2026

Salesforce IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT Online Questions & Answers

  • Question 171:

    A technology enterprise is setting up an identity solution with an external vendors wellness application for its employees. The user attributes need to be returned to the wellness application in an ID token.

    Which authentication mechanism should an identity architect recommend to meet the requirements?

    A. OpenID Connect
    B. User Agent Flow
    C. JWT Bearer Token Flow
    D. Web Server Flow

  • Question 172:

    Which two statements are capable of Identity Connect? Choose 2 answers

    A. Synchronization of Salesforce Permission Set Licence Assignments.
    B. Supports both Identity-Provider-Initiated and Service-Provider-Initiated SSO.
    C. Support multiple orgs connecting to multiple Active Directory servers.
    D. Automated user synchronization and de-activation.

  • Question 173:

    Universal containers (UC) has a custom, internal-only, mobile billing application for users who are commonly out of the office. The app is configured as a connected App in salesforce. Due to the nature of this app, UC would like to take the appropriate measures to properly secure access to the app. Which two are recommendations to make the UC? Choose 2 answers

    A. Disallow the use of single Sign-on for any users of the mobile app.
    B. Require high assurance sessions in order to use the connected App
    C. Use Google Authenticator as an additional part of the logical processes.
    D. Set login IP ranges to the internal network for all of the app users profiles.

  • Question 174:

    An architect needs to set up a Facebook Authentication provider as login option for a salesforce customer Community. What portion of the authentication provider setup associates a Facebook user with a salesforce user?

    A. Consumer key and consumer secret
    B. Federation ID
    C. User info endpoint URL
    D. Apex registration handler

  • Question 175:

    Northern Trail Outfitters (NTO) has an existing custom business-to-consumer (B2C) website that does NOT support single sign-on standards, such as Security Assertion Markup Language (SAMi) or OAuth. NTO wants to use Salesforce

    Identity to register and authenticate new customers on the website.

    Which two Salesforce features should an identity architect use in order to provide username/password authentication for the website?

    Choose 2 answers

    A. Identity Connect
    B. Delegated Authentication
    C. Connected Apps
    D. Embedded Login

  • Question 176:

    Universal Containers (UC) employees have Salesforce access from restricted IP ranges only, to protect against unauthorised access. UC wants to roll out the Salesforce1 mobile app and make it accessible from any location. Which two options should an Architect recommend? Choose 2 answers

    A. Relax the IP restriction with a second factor in the Connect App settings for Salesforce1 mobile app.
    B. Remove existing restrictions on IP ranges for all types of user access.
    C. Relax the IP restrictions in the Connect App settings for the Salesforce1 mobile app.
    D. Use Login Flow to bypass IP range restriction for the mobile app.

  • Question 177:

    Universal Containers (UC) is building a custom Innovation platform on their Salesforce instance. The Innovation platform will be written completely in Apex and Visualforce and will use custom objects to store the Data. UC would like all users to be able to access the system without having to log in with Salesforce credentials. UC will utilize a third-party idp using SAML SSO. What is the optimal Salesforce licence type for all of the UC employees?

    A. Identity Licence.
    B. Salesforce Licence.
    C. External Identity Licence.
    D. Salesforce Platform Licence.

  • Question 178:

    Universal Containers (UC) is using a custom application that will act as the Identity Provider and will generate SAML assertions used to log in to Salesforce. UC is considering including custom parameters in the SAML assertion. These attributes contain sensitive data and are needed to authenticate the users. The assertions are submitted to salesforce via a browser form post. The majority of the users will only be able to access Salesforce via UC's corporate network, but a subset of admins and executives would be allowed access from outside the corporate network on their mobile devices. Which two methods should an Architect consider to ensure that the sensitive data cannot be tampered with, nor accessible to anyone while in transit?

    A. Use the Identity Provider's certificate to digitally sign and Salesforce's Certificate to encrypt the payload.
    B. Use Salesforce's Certificate to digitally sign the SAML Assertion and a Mobile Device Management client on the users' mobile devices.
    C. Use the Identity provider's certificate to digitally Sign and the Identity provider's certificate to encrypt the payload.
    D. Use a custom login flow to retrieve sensitive data using an Apex callout without including the attributes in the assertion.

  • Question 179:

    Northern Trail Outfitters manages application functional permissions centrally as Active Directory groups. The CRM_Superllser and CRM_Reportmg_SuperUser groups should respectively give the user the SuperUser and Reportmg_SuperUser permission set in Salesforce. Salesforce is the service provider to a Security Assertion Markup Language (SAML) identity provider.

    Mow should an identity architect ensure the Active Directory groups are reflected correctly when a user accesses Salesforce?

    A. Use the Apex Just-in-Time handler to query standard SAML attributes and set permission sets.
    B. Use the Apex Just-in-Time handler to query custom SAML attributes and set permission sets.
    C. Use a login flow to query custom SAML attributes and set permission sets.
    D. Use a login flow to query standard SAML attributes and set permission sets.

  • Question 180:

    Universal Containers (UC) has Active Directory (AD) as their enterprise identity store and would like to use it for Salesforce user authentication. UC expects to synchronize user data between Salesforce and AD and Assign the appropriate Profile and Permission Sets based on AD group membership. What would be the optimal way to implement SSO?

    A. Use Active Directory with Reverse Proxy as the Identity Provider.
    B. Use Microsoft Access control Service as the Authentication provider.
    C. Use Active Directory Federation Service (ADFS) as the Identity Provider.
    D. Use Salesforce Identity Connect as the Identity Provider.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Salesforce exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT exam preparations and Salesforce certification application, do not hesitate to visit our Vcedump.com to find your solutions here.