IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT Exam Details

  • Exam Code
    :IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT
  • Exam Name
    :Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
  • Certification
    :Salesforce Certifications
  • Vendor
    :Salesforce
  • Total Questions
    :247 Q&As
  • Last Updated
    :May 27, 2026

Salesforce IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT Online Questions & Answers

  • Question 181:

    Universal Containers (UC) is using its production org as the identity provider for a new Experience Cloud site and the identity architect is deciding which login experience to use for the site.

    Which two page types are valid login page types for the site?

    Choose 2 answers

    A. Experience Builder Page
    B. lightning Experience Page
    C. Login Discovery Page
    D. Embedded Login Page

  • Question 182:

    Universal Containers (UC) currently uses Salesforce Sales Cloud and an external billing application. Both Salesforce and the billing application are accessed several times a day to manage customers. UC would like to configure single sign-on and leverage Salesforce as the identity provider. Additionally, UC would like the billing application to be accessible from Salesforce. A redirect is acceptable.

    Which two Salesforce tools should an identity architect recommend to satisfy the requirements?

    Choose 2 answers

    A. salesforce Canvas
    B. Identity Connect
    C. Connected Apps
    D. App Launcher

  • Question 183:

    Universal Containers (UC) is building an authenticated Customer Community for its customers. UC does not want customer credentials stored in Salesforce and is confident its customers would be willing to use their social media credentials to authenticate to the community. Which two actions should an Architect recommend UC to take?

    A. Use Delegated Authentication to call the Twitter login API to authenticate users.
    B. Configure an Authentication Provider for LinkedIn Social Media Accounts.
    C. Create a Custom Apex Registration Handler to handle new and existing users.
    D. Configure SSO Settings For Facebook to serve as a SAML Identity Provider.

  • Question 184:

    Universal containers wants to build a custom mobile app connecting to salesforce using Oauth, and would like to restrict the types of resources mobile users can access. What Oauth feature of Salesforce should be used to achieve the goal?

    A. Access Tokens
    B. Mobile pins
    C. Refresh Tokens
    D. Scopes

  • Question 185:

    A global fitness equipment manufacturer uses Salesforce to manage its sales cycle. The manufacturer has a custom order fulfillment app that needs to request order data from Salesforce. The order fulfillment app needs to integrate with the

    Salesforce API using OAuth 2.0 protocol.

    What should an identity architect use to fulfill this requirement?

    A. Canvas App Integration
    B. OAuth Tokens
    C. Authentication Providers
    D. Connected App and OAuth scopes

  • Question 186:

    A financial enterprise is planning to set up a user authentication mechanism to login to the Salesforce system. Due to regulatory requirements, the CIO of the company wants user administration, including passwords and authentication requests, to be managed by an external system that is only accessible via a SOAP webservice.

    Which authentication mechanism should an identity architect recommend to meet the requirements?

    A. OAuth Web-Server Flow
    B. Identity Connect
    C. Delegated Authentication
    D. Just-in-Time Provisioning

  • Question 187:

    A public sector agency is setting up an identity solution for its citizens using a Community built on Experience Cloud and requires the new user registration functionality to capture first name, last name, and phone number. The phone number will be used for identity verification.

    Which feature should an identity architect recommend to meet the requirements?

    A. Integrate with social websites (Facebook, Linkedin. Twitter)
    B. Use an external Identity Provider
    C. Create a custom Lightning Web Component
    D. Use Login Discovery

  • Question 188:

    Containers (UC) has implemented SAML-based single Sign-on for their Salesforce application and is planning to provide access to Salesforce on mobile devices using the Salesforce1 mobile app. UC wants to ensure that Single Sign-on is used for accessing the Salesforce1 mobile App. Which two recommendations should the Architect make? Choose 2 Answers

    A. Configure the Embedded Web Browser to use My Domain URL.
    B. Configure the Salesforce1 App to use the MY Domain URL.
    C. Use the existing SAML-SSO flow along with User Agent Flow.
    D. Use the existing SAML SSO flow along with Web Server Flow.

  • Question 189:

    Universal containers (UC) employees have salesforce access from restricted ip ranges only, to protect against unauthorised access. UC wants to rollout the salesforce1 mobile app and make it accessible from any location. Which two options should an architect recommend? Choose 2 answers

    A. Relax the ip restriction in the connect app settings for the salesforce1 mobile app
    B. Use login flow to bypass ip range restriction for the mobile app.
    C. Relax the ip restriction with a second factor in the connect app settings for salesforce1 mobile app
    D. Remove existing restrictions on ip ranges for all types of user access.

  • Question 190:

    A technology enterprise is planning to implement single sign-on login for users. When users log in to the Salesforce User object custom field, data should be populated for new and existing users.

    Which two steps should an identity architect recommend?

    Choose 2 answers

    A. Implement Auth.SamlJitHandler Interface.
    B. Create and update methods.
    C. Implement RegistrationHandler Interface.
    D. Implement SesslonManagement Class.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Salesforce exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your IDENTITY-AND-ACCESS-MANAGEMENT-ARCHITECT exam preparations and Salesforce certification application, do not hesitate to visit our Vcedump.com to find your solutions here.