Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
Update Date
29 Aug, 2026
Total Questions
109 Questions Answers With Explanation
$45
$55
$65
Prepare Smarter for the Identity-and-Access-Management-Architect with Pass4itexam
At Pass4itexam, we believe in smart preparation. That’s why we’ve built a complete guide to help you succeed in the Salesforce Identity-and-Access-Management-Architect exam. Whether you’re a first-time test taker or revisiting certification, our expert-curated PDF dumps for Identity-and-Access-Management-Architect are your shortcut to confidence and clarity.
This isn’t just a question bank—it’s a full prep system. Our materials reflect real exam objectives, with relevant scenarios and actual exam-style questions. You’ll get to know the format, practice effectively, and reduce test-day anxiety.
What to Expect from Our Identity-and-Access-Management-Architect Preparation
1. Straightforward Study Material
Exam-Aligned Content: Every topic we cover is mapped to Salesforce's objectives, so no wasted time.
Easy to Understand: No fluff, no filler—just simplified concepts that actually stick.
2. Real Practice for Real Exams
True-to-Exam Questions: Practice on material that mirrors the real Identity-and-Access-Management-Architect exam format.
Instant Feedback: Learn from your mistakes and understand the “why” behind the answers.
3. Smart Strategies That Work
Master time management to reduce pressure during the exam.
Use our proven techniques to handle tricky or unexpected questions.
Learn patterns and question logic to boost your confidence.
4. Always Updated, Always Relevant
90 Days Free Updates: We keep your dumps current, so you’re never studying outdated content.
Based on Real Feedback: We monitor exam changes and adjust quickly.
Your Success Is Our Promise
If you use our Identity-and-Access-Management-Architect prep materials and still don’t pass, we’ll refund you—simple as that. No hidden terms. No stress.
We stand behind our products with a full 100% Money-Back Guarantee, because we know our materials deliver results.
Final Thoughts
If you’re serious about passing the Salesforce Identity-and-Access-Management-Architect certification, you’re in the right place. Our resources are designed to help you save time, study smarter, and get certified faster.
0 Review for Salesforce Identity-and-Access-Management-Architect Exam Dumps
Add Your Review About Salesforce Identity-and-Access-Management-Architect Exam Dumps
Question # 1
An identity architect's client has a homegrown identity provider (IdP). Salesforce is used as
the service provider (SP). The head of IT is worried that during a SP initiated single sign-on
(SSO), the Security Assertion Markup Language (SAML) request content will be altered.
What should the identity architect recommend to make sure that there is additional trust
between the SP and the IdP?
A. Ensure that there is an HTTPS connection between IDP and SP. B. Ensure that on the SSO settings page, the "Request Signing Certificate" field has a selfsigned certificate. C. Ensure that the Issuer and Assertion Consumer service (ACS) URL is property configured between SP and IDP. D. Encrypt the SAML Request using certification authority (CA) signed certificate and decrypt on IdP.
Answer: D
Question # 2
Northern Trail Outfitters (NTO) is planning to roll out a partner portal for its distributors
using Experience Cloud. NTO would like to use an external identity provider (idP) and for
partners to register for access to the portal. Each partner should be allowed to register only
once to avoid duplicate accounts with Salesforce.
What should a identity architect recommend to create partners?
A. On successful creation of Partners using Self Registration page in Experience Cloud, create identity in Ping. B. Create a custom page m Experience Cloud to self register partner with Experience Cloud and Ping identity store. C. Create a custom web page in the Portal and create users in the IdP and Experience Cloud using published APIs. D. Allow partners to register through the IdP and create partner users in Salesforce through an API.
Answer: B
Question # 3
A consumer products company uses Salesforce to maintain consumer information,
including orders. The company implemented a portal solution using Salesforce Experience
Cloud for its consumers where the consumers can log in using their credentials. The
company is considering allowing users to login with their Facebook or Linkedln credentials.
Once enabled, what role will Salesforce play?
A. Facebook and Linkedln will be the SPs. B. Salesforce will be the service provider (SP). C. Salesforce will be the identity provider (IdP). D. Facebook and Linkedln will act as the IdPs and SPs.
Answer: B
Question # 4
Which tool should be used to track login data, such as the average number of logins, who
logged in more than the average number of times and who logged in during non-business
hours?
A. Login Inspector B. Login History C. Login Report D. Login Forensics
Answer: D
Question # 5
Universal containers (UC) has an e-commerce website while customers can buy products,
make payments, and manage their accounts. UC decides to build a customer Community
on Salesforce and wants to allow the customers to access the community for their accounts
without logging in again. UC decides to implement ansp-Initiated SSO using a SAMLBASED complaint IDP. In this scenario where salesforce is the service provider, which two
activities must be performed in salesforce to make sp-Initiated SSO work? Choose 2
answers
A. Configure SAML SSO settings. B. Configure Delegated Authentication C. Create a connected App D. Set up my domain
Answer: A,D
Question # 6
An identity architect is setting up an integration between Salesforce and a third-party
system. The third-party system needs to authenticate to Salesforce and then make API
calls against the REST API.
One of the requirements is that the solution needs to ensure the third party service
providers connected app in Salesforce mini need for end user interaction and maximizes
security.
Which OAuth flow should be used to fulfill the requirement?
A. JWT Bearer Flow B. Web Server Flow C. User Agent Flow D. Username-Password Flow
Answer: A
Question # 7
Universal Containers (UC) has a Customer Community that uses Facebook for of
authentication. UC would like to ensure that changes in the Facebook profile are 65.
reflected on the appropriate Customer Community user. How can this requirement be met?
A. Use SAML Just-In-Time Provisioning between Facebook and Salesforce. B. Use information in the Signed Request that is received from Facebook. C. Develop a scheduled job that calls out to Facebook on a nightly basis. D. Use the updateUser() method on the Registration Handler class.
Answer: D
Question # 8
Universal containers (UC) is successfully using Delegated Authentication for their
salesforce users. The service supporting Delegated Authentication is written in Java. UC
has a new CIO that is requiring all company Web services be RESR-ful and written in .
NET. Which two considerations should the UC Architect provide to the new CIO? Choose 2
answers
A. Delegated Authentication will not work with a.net service. B. Delegated Authentication will continue to work with rest services. C. Delegated Authentication will continue to work with a.net service. D. Delegated Authentication will not work with rest services.
Answer: C,D
Question # 9
Universal containers (UC) has a mobile application that calls the salesforce REST API. In
order to prevent users from having to enter their credentials everytime they use the app,
UC has enabled the use of refresh Tokens as part of the salesforce connected App and updated their mobile app to take advantage of the refresh token. Even after enabling the
refresh token, Users are still complaining that they have to enter their credentials once a
day. What is the most likely cause of the issue?
A. The Oauth authorizations are being revoked by a nightly batch job. B. The refresh token expiration policy is set incorrectly in salesforce C. The app is requesting too many access Tokens in a 24-hour period D. The users forget to check the box to remember their credentials.
Answer: B
Question # 10
Universal Containers (UC) has an existing e-commerce platform and is implementing a
new customer community. They do not want to force customers to register on both
applications due to concern over the customers experience. It is expected that 25% of the
e-commerce customers will utilize the customer community . The e-commerce platform is
capable of generating SAML responses and has an existing REST-ful API capable of
managing users. How should UC create the identities of its e-commerce users with the
customer community?
A. Use SAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site. B. Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO. C. Use a nightly batch ETL job to sync users between the Customer Community and the ecommerce platform and use SAML to allow SSO. D. Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML to allow SSO.
Answer: A
Question # 11
Universal containers (UC) has a custom, internal-only, mobile billing application for users
who are commonly out of the office. The app is configured as a connected App in
salesforce. Due to the nature of this app, UC would like to take the appropriate measures
to properly secure access to the app. Which two are recommendations to make the UC?
Choose 2 answers
A. Disallow the use of single Sign-on for any users of the mobile app. B. Require high assurance sessions in order to use the connected App C. Use Google Authenticator as an additional part of the logical processes. D. Set login IP ranges to the internal network for all of the app users profiles.
Answer: B,C
Question # 12
Universal Containers (UC) uses Salesforce to allow customers to keep track of the order
status. The customers can log in to Salesforce using external authentication providers,
such as Facebook and Google. UC is also leveraging the App Launcher to let customers
access an of platform application for generating shipping labels. The label generator
application uses OAuth to provide users access. What license type should an Architect
recommend for the customers?
A. Customer Community license B. Identity license C. Customer Community Plus license D. External Identity license
Answer: B
Question # 13
Which two security risks can be mitigated by enabling Two-Factor Authentication (2FA) in
Salesforce? Choose 2 answers
A. Users leaving laptops unattended and not logging out of Salesforce. B. Users accessing Salesforce from a public Wi-Fi access point. C. Users choosing passwords that are the same as their Facebook password. D. Users creating simple-to-guess password reset questions.
Answer: B,C
Question # 14
Universal Containers allows employees to use a mobile device to access Salesforce for
daily operations using a hybrid mobile app. This app uses Mobile software development
kits (SDK), leverages refresh token to regenerate access token when required and is
distributed as a private app.
The chief security officer is rolling out an org wide compliance policy to enforce re venfication of devices if an employee has not logged in from that device in the last week.
Which connected app setting should be leveraged to comply with this policy change?
A. Scope - Deny refresh_token scope for this connected app. B. Refresh Token Policy - Expire the refresh token if it has not been used for 7 days. C. Session Policy - Set timeout value of the connected app to 7 days. D. Permitted User - Ask admins to maintain a list of users who are permitted based on last login date.
Answer: B
Question # 15
Universal Containers (UC) has implemented SAML-based SSO solution for use with their
multi-org Salesforce implementation, utilizing one of the the orgs as the Identity Provider.
One user is reporting that they can log in to the Identity Provider org but get a generic
SAML error message when accessing the other orgs. Which two considerations should the
architect review to troubleshoot the issue? Choose 2 answers
A. The Federation ID must be a valid Salesforce Username B. The Federation ID must is case sensitive C. The Federation ID must be in the form of an email address. D. The Federation ID must be populated on the user record.
Answer: B,D
Question # 16
Universal Containers (UC) has a mobile application for its employees that uses data from
Salesforce as well as uses Salesforce for Authentication purposes. UC wants its mobile users to only enter their credentials the first time they run the app. The application has
been live for a little over 6 months, and all of the users who were part of the initial launch
are complaining that they have to re-authenticate. UC has also recently changed the URI
Scheme associated with the mobile app. What should the Architect at UC first
investigate?Universal Containers (UC) has a mobile application for its employees that uses
data from Salesforce as well as uses Salesforce for Authentication purposes. UC wants its
mobile users to only enter their credentials the first time they run the app. The application
has been live for a little over 6 months, and all of the users who were part of the initial
launch are complaining that they have to re-authenticate. UC has also recently changed
the URI Scheme associated with the mobile app. What should the Architect at UC first
investigate?
A. Check the Refresh Token policy defined in the Salesforce Connected App. B. Validate that the users are checking the box to remember their passwords. C. Verify that the Callback URL is correctly pointing to the new URI Scheme. D. Confirm that the access Token's Time-To-Live policy has been set appropriately.
Answer: A
Question # 17
Northern Trail Outfitters (NTO) uses Salesforce Experience Cloud sites (previously known
as Customer Community) to provide a digital portal where customers can login using their
Google account.
NTO would like to automatically create a case record for first time users logging into
Salesforce Experience Cloud.
What should an Identity architect do to fulfill the requirement?
A. Configure an authentication provider for Social Login using Google and a custom registration handler. B. Implement a Just-in-Time handler class that has logic to create cases upon first login. C. Create an authentication provider for Social Login using Google and leverage standard registration handler. D. Implement a login flow with a record create component for Case.
Answer: D
Question # 18
Northern Trail Outfitters (NTO) has an off-boarding process where a terminated employee
is first disabled in the Lightweight Directory Act Protocol (LDAP) directory, then requests
are sent to the various application support teams to finish user deactivations. A terminated
employee recently was able to login to NTO's Salesforce instance 24 hours after
termination, even though the user was disabled in the corporate LDAP directory.
What should an identity architect recommend to prevent this from happening in the future?
A. Create a Just-in-Time provisioning registration handler to ensure users are deactivated in Salesforce as they are disabled in LDAP. B. Configure an authentication provider to delegate authentication to the LDAP directory. C. use a login flow to make a callout to the LDAP directory before authenticating the user to Salesforce. D. Setup an identity provider (IdP) to authenticate users using LDAP, set up single sign-on to Salesforce and disable Login Form authentication.
Answer: B
Question # 19
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce
users using a third-party IdP. After some evaluation, UC decides NOT to 65« set up My
Domain for their Salesforce org. How does that decision impact their SSO implementation?
A. IdP-initiated SSO will NOT work. B. Neither SP- nor IdP-initiated SSO will work. C. Either SP- or IdP-initiated SSO will work. D. SP-initiated SSO will NOT work
Answer: B
Question # 20
A financial services company uses Salesforce and has a compliance requirement to track
information about devices from which users log in. Also, a Salesforce Security
Administrator needs to have the ability to revoke the device from which users log in.
What should be used to fulfill this requirement?
A. Use multi-factor authentication (MFA) to meet the compliance requirement to track device information. B. Use the Activations feature to meet the compliance requirement to track device information. C. Use the Login History object to track information about devices from which users log in. D. Use Login Flows to capture device from which users log in and store device and user information in a custom object.
0 Review for Salesforce Identity-and-Access-Management-Architect Exam Dumps