Spring Special Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: spcl70

Practice Free Identity-and-Access-Management-Architect Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Exam Questions Answers With Explanation

We at Crack4sure are committed to giving students who are preparing for the Salesforce Identity-and-Access-Management-Architect Exam the most current and reliable questions . To help people study, we've made some of our Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) exam materials available for free to everyone. You can take the Free Identity-and-Access-Management-Architect Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.

Question # 6

Universal Containers (UC) uses Salesforce as a CRM and identity provider (IdP) for their Sales Team to seamlessly login to internal portals.

The IT team at UC is now evaluating Salesforce to act as an IdP for its remaining employees.

Which Salesforce license is required to full fill this requirement?

A.

Identify Verification

B.

Identify Connect

C.

Identify Only

D.

External Identity

Question # 7

A client is planning to rollout multi-factor authentication (MFA) to its internal employees and wants to understand which authentication and verification methods meet the Salesforce criteria for secure authentication.

Which three functions meet the Salesforce criteria for secure MFA?

Choose 3 answers

A.

Username and password = security key

B.

Lightning Login

C.

Username and password = SMS passwords

D.

Third-party single sign-on with Mobile Authenticator app

E.

Username & password = Email Verification Code

Question # 8

Universal Containers uses Salesforce as an identity provider and Concur as the Employee Expense management system. The HR director wants to ensure Concur accounts for employees are created only after the appropriate approval in the Salesforce org.

Which three steps should the identity architect use to implement this requirement.

Choose 3 answers

A.

Create an approval process for a custom object associated with the provisioning flow.

B.

Create an approval process for UserProvisioningReguest object associated with the provisioning flow.

C.

Create a connected app for Concur in Salesforce.

D.

Enable User Provisioning for the connected app.

E.

Create an approval process for User object associated with the provisioning flow.

Question # 9

Universal Containers (UC) is using its production org as the identity provider for a new Experience Cloud site and the identity architect is deciding which login experience to use for the site.

Which two page types are valid login page types for the site?

Choose 2 answers

A.

Login Discovery Page

B.

Experience Builder Page

C.

Embedded Login Page

D.

Lightning Experience Page

Question # 10

Universal Containers is implementing Salesforce Identity to broker authentication from its enterprise single sign-on (550) solution through Salesforce to third party applications using SAML.

What role does Salesforce Identity play in its relationship with the enterprise S50 system?

A.

Service Provider {SP)

B.

Identity Provider [IdP)

C.

Resource Server

D.

Client Application

Question # 11

When designing a multi-branded Customer Identity and Access Management solution on the Salesforce Platform, how should an identity architect ensure a specific brand experience in Salesforce is presented?

A.

The Experience ID, which can be included in OAuth/Open ID flows and Security Assertion

Markup Language (SAML) flows as a URL parameter.

B.

The Audience ID, which can be set in a shared cookie.

C.

Add a custom parameter to the service provider’s OAuth/SAML call and implement logic on its login page to apply branding based on the parameters value.

D.

Provide a brand picker that the end user can use to select its sub-brand when they arrive on Salesforce.

Question # 12

Northern Trail Outfitters (NTO) believes a specific user account may have been compromised. NTO inactivated the user account and needs to perform a forensic analysis and identify signals that could indicate a breach has occurred.

What should NTO’s first step be in gathering signals that could indicate account compromise?

A.

download the identity provider Event log and contact the details of activities performed by the user.

B.

download the Login history and evaluate the details of topics performed by the user.

C.

download the Setup Audit Trail and review all recent activities performed by the user.

D.

Review the User record and evaluate the login and transaction history.

Question # 13

A global company has built an external application that uses data from its Salesforce org via an OAuth 2.0 authorization flow. Upon logout, the existing Salesforce OAuth token must be invalidated.

Which action will accomplish this?

A.

Use a HTTP POST to make a call as the reverse token endpoint.

B.

Use a HTTP POST to request any refresh token for this current user.

C.

Enable Single Logout with a secure logout URL.

D.

Use a HTTP POST to file System for Cross-domain Identity Management (SCIPI) endpoint, including the current OAuth token.

Question # 14

A multinational company using the Salesforce platform wants to implement robust user activity verification capabilities to detect unauthorized access and unusual login patterns.

They need real-time monitoring and alerting functionalities to respond promptly to security incidents.

Which Salesforce tool should be utilized to achieve these requirements?

A.

Salesforce Event Monitoring and Event Log Files

B.

Salesforce Profiles

C.

Salesforce Platform Encryption

D.

Salesforce Data Loader

Question # 15

Northern Trail Outfitters is implementing a business-to-business (B2B) collaboration site using Salesforce Experience Cloud. The partners will authenticate with an existing identity provider and the solution will utilize Security Assertion Markup Language (SAML) to provide single sign-on to Salesforce. Delegated administration will be used in the Experience Cloud site to allow the partners to administer their users ' access.

How should a partner identity be provisioned in Salesforce for this solution?

A.

Create a user and a related contact.

B.

Create only a contact.

C.

Create a contactless user.

D.

Create a person account.

Question # 16

A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APAC. The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS. The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.

What is recommended to ensure these requirements are met?

A.

Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.

B.

Configure Each ADFS system under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce.

C.

Add a central identity system that facilitates between the ADFS systems and integrate with Salesforce for single sign-on.

D.

Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.

Question # 17

Northern Trail Outfitters (NTO) recently purchased Salesforce Identity Connect to streamline user provisioning across Microsoft Active Directory (AD) and Salesforce Sales Cloud.

NTO has asked an identity architect to identify which Salesforce security configurations can map to AD permissions.

Which three Salesforce permissions are available to map to AD permissions?

Choose 3 answers

A.

Sharing Rules

B.

Public Groups

C.

Permission Set License

D.

Roles

E.

Profiles and Permission Sets

Question # 18

The CMO of an advertising company has invited an Identity and Access Management (IAM) specialist to discuss Salesforce out-of-box capabilities for configuring the company ' s login and registration experience on Salesforce Experience Cloud.

The CMO is looking to brand the login page with the company ' s logo, background color, login button color, and dynamic right-frame from an external URL.

Which two solutions should the IAM specialist recommend?

Choose 2 answers:

A.

Login & Registration pages can be branded in the Community Administration settings.

B.

Build custom site pages for reset and forget password features.

C.

Build custom pages for handling requirements as Experienced Cloud.

D.

Use Experience Builder to build branded Reset and Forget Password pages.

Question # 19

An administrator created a connected app for a custom web application in Salesforce which needs to be visible as a tile in App Launcher. The tile for the custom web application is missing in the app launcher for all users in Salesforce. The administrator requested assistance from an identity architect to resolve the issue.

Which two reasons are the source of the issue?

Choose 2 answers

A.

Session Policy is set as “High Assurance Session required” for this connected app.

B.

The connected app is not set in the App menu as “Visible in App Launcher”.

C.

Statutes, for the connected app is not set in Connected App settings.

D.

Obtain scope does not include “openid”.

Question # 20

Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for NTO to give its customers the ability to login with their Facebook and Twitter credentials.

What should an identity architect recommend to meet these requirements?

A.

create a custom external authentication provider for Facebook.

B.

obtain login icon for Facebook and Twitter.

C.

configure a predefined authentication provider for Facebook and Twitter.

D.

create a custom external authentication provider for Twitter.

Question # 21

An organization has a central cloud-based Identity and Access Management (IAM) Service

for authentication and user management, which must be utilized by all applications as follows:

1 - Change of a user status in the central IAM Service triggers provisioning or deprovisioning

in the integrated cloud applications.

2 - Security Assertion Markup Language single sign-on (SSO) is used to facilitate access for

users authenticated at identity provider (Central IAM Service).

Which approach should an IAM architect implement on Salesforce Sales Cloud to meet the

requirements?

A.

Configure Salesforce as a SAML service provider, and enable Just-In Time (JIT) provisioning and deprovisioning of users.

B.

Configure central IAM Service as an authentication provider and extend registration handler to manage provisioning and deprovisioning of users.

C.

Configure Salesforce as a SAML Service Provider, and enable SCIM (System for CrossDomain Identity Management) for provisioning and deprovisioning of users.

D.

Deploy Identity Connect component and set up automated provisioning and deprovisioning of users, as well as SAML-based SSO.

Question # 22

Northern Trail Outfitters (NTO) uses the Customer 360 Platform implemented on Salesforce Experience Cloud. The development team in charge has learned of a contact lessuser feature, which can reduce the overhead of managing customers and partners by creating users without contact information.

What is the potential impact to the architecture if NTO decides to implement this feature?

A.

Custom registration handler is needed to correctly assign External Identity or Community license for the newly registered contactless user.

B.

If contactless user is upgraded to Community license, the contact record is automatically created and linked to the user record, but not associated with an Account.

C.

Contactless user feature is available only with the External Identity license, which can restrict the Experience Cloud functionality available to the user.

D.

Passivordless authentication can not be supported because the mobile phone receiving one-time password (OTP) needs to match the number on the contact record.

Question # 23

An identity professional, responsible for ensuring secure access to the Salesforce platform, needs to audit and verify user activity during and after login. They want to monitor login attempts, track user authentication methods, and identify suspicious behavior or unauthorized access.

Which tool or feature should they leverage to achieve this objective?

A.

Customer Account Processes

B.

Salesforce Login History

C.

Salesforce Skield

D.

Salesforce Lightning Flow

Question # 24

Which two things should be done to ensure end users can only use single sign-on (SSO) to login in to Salesforce?

Choose 2 answers

A.

Enable My Domain and select " Prevent login from https://login.salesforce.com " .

B.

Request Salesforce Support to enable delegated authentication.

C.

Once SSO is enabled, users are only able to login using Salesforce credentials.

D.

Assign user " Is Single Sign-On Enabled " permission via profile or permission set.

Question # 25

A global company is using the Salesforce Platform as an Identity Provider and needs to integrate a third-party application with its Experience Cloud customer portal.

Which two features should be utilized to provide users with login and identity services for the third-party application?

Choose 2 answers

A.

Use the App Launcher with single sign-on (SSO).

B.

Use Delegated Authentication.

C.

Use a connected app.

D.

External a Data source with Named Principal identity type.

Question # 26

A global fitness equipment manufacturer uses Salesforce to manage its sales cycle. The manufacturer has a custom order fulfillment app that needs to request order data from

Salesforce. The order fulfillment app needs to integrate with the Salesforce API using OAuth 2.0 protocol.

What should an identity architect use to fulfill this requirement?

A.

OAuth Token

B.

Genre Age Integration

C.

Authentication Providers

D.

Connected App and OAuth Scopes

Question # 27

A leading fitness tracker company is getting ready to launch a customer community. The company wants its customers to login to the community and connect their fitness device to their profile. Customers should be able to obtain exercise details and fitness recommendation in the community.

Which should be used to satisfy this requirement?

A.

Named Credentials

B.

Login Flows

C.

OAuth Device Flow

D.

OAuth Asset Token flow

Question # 28

Universal Containers has multiple Salesforce instances where users receive emails from different instances. Users should be logged into the correct Salesforce instance authenticated by their IdP when clicking on an email link to a Salesforce record.

What should be enabled in Salesforce as a prerequisite?

A.

External Identity

B.

My Domain

C.

Multi-Factor Authentication

D.

Identity Provider

Question # 29

A university is planning to set up an identity solution for its alumni. A third-party identity provider will be used for single sign-on and Salesforce will be the system of records. Users are getting error messages when logging in.

Which Salesforce feature should be used to debug the issue?

A.

News Legs

B.

Web Apps Audit Trail

C.

Login History

D.

About Exception Email

Question # 30

Universal Containers uses Salesforce as an identity provider and Concur as the Employee Expense management system. The HR director wants to ensure Concur accounts for employees are created only after the appropriate approval in the Salesforce org.

Which three steps should the identity architect use to implement this requirement?

Choose 3 answers

A.

Create an approval process for User object associated with the provisioning flow.

B.

Create an approval process for a custom object associated with the provisioning flow.

C.

Create an approval process for UserProviderRequests object associated with the provisioning flow.

D.

Enable User Provisioning for the connected app.

E.

Create a connected app for Concur in Salesforce.

Question # 31

A technology enterprise is setting up an identity solution with an external vendors wellness application for its employees. The user attributes need to be returned to the wellness application in an ID token.

Which authentication mechanism should an identity architect recommend to meet the

requirements?

A.

User Agent Flow

B.

OpenID Connect

C.

JWT Bearer Token Flow

D.

Web Server Flow

Question # 32

A Salesforce Administrator is tasked with setting up Just-in-Time (JIT) provisioning for SAML to enable Single Sign-On (SSO) for your organization. They have already configured the SAML settings for SSO in Salesforce.

What should be their next steps to enable JIT provisioning?

A.

Enable Just-in-Time User Provisioning in the SAML Single Sign-On Setting, configure the User Provisioning Type, and provide the SAML JIT Handler.

B.

Create a new permission set with JIT provisioning enabled, configure the necessary permissions, and assign the permission set to relevant users.

C.

Create a new Apex class to handle JIT provisioning, implement the required methods, and assign the class to the appropriate user profiles.

D.

Modify the organization-wide sharing settings to allow JIT provisioning, update the sharing rules for the user object.

Identity-and-Access-Management-Architect PDF

$33

$109.99

3 Months Free Update

  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions

Identity-and-Access-Management-Architect PDF + Testing Engine

$52.8

$175.99

3 Months Free Update

  • Exam Name: Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
  • Last Update: Apr 8, 2026
  • Questions and Answers: 109
  • Free Real Questions Demo
  • Recommended by Industry Experts
  • Best Economical Package
  • Immediate Access

Identity-and-Access-Management-Architect Engine

$39.6

$131.99

3 Months Free Update

  • Best Testing Engine
  • One Click installation
  • Recommended by Teachers
  • Easy to use
  • 3 Modes of Learning
  • State of Art Technology
  • 100% Real Questions included