Salesforce Plat-Arch-203 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| API and Integration Security | - Token management and refresh mechanisms - Secure integration patterns - OAuth scopes and API authentication flows |
| Access Management and Security Controls | - Profiles, permission sets, and role hierarchy - Multi-factor authentication (MFA) enforcement - Session management and security policies |
| Authentication and Single Sign-On (SSO) | - SSO troubleshooting and configuration - OpenID Connect and OAuth 2.0 flows - SAML 2.0 implementation in Salesforce |
| Salesforce Identity Services | - My Domain and identity configuration - Connected Apps and OAuth policies - Identity Connect and external identity providers |
| Identity and Access Management Fundamentals | - Authentication vs authorization principles - Identity lifecycle management concepts - Enterprise identity architecture basics |
| Experience Cloud and External Identity | - Community login and identity providers - External user authentication and authorization - B2B and B2C identity considerations |
Salesforce Certified Platform Identity and Access Management Architect Sample Questions:
1. An Identity architect works for a multinational, multi-brand organization. As they work with the organization to understand their Customer Identity and Access Management requirements, the identity architect learns that the brand experience is different for each of the customer's sub-brands and each of these branded experiences must be carried through the login experience depending on which sub-brand the user is logging into.
Which solution should the architect recommend to support scalability and reduce maintenance costs, if the organization has more than 150 sub-brands?
A) Assign each sub-brand a unique Experience ID and use the Experience ID to dynamically brand the login experience.
B) Create a community subdomain for each sub-brand and customize the look and feel of the Login page for each community subdomain to match the brand.
C) Use Audiences to customize the login experience for each sub-brand and pass an audience ID to the community during the OAuth and Security Assertion Markup Language (SAML) flows.
D) Create a separate Salesforce org for each sub-brand so that each sub-brand has complete control over the user experience.
2. Universal containers (UC) has decided to use identity connect as it's identity provider. UC uses active directory(AD) and has a team that is very familiar and comfortable with managing ad groups. UC would like to use AD groups to help configure salesforce users. Which three actions can AD groups control through identity connect? Choose 3 answers
A) Role Assignment
B) Public Group Assignment
C) Permission sets assignment
D) Custom permission assignment
E) Granting report folder access
3. A technology enterprise is planning to implement single sign-on login for users. When users log in to the Salesforce User object custom field, data should be populated for new and existing users.
Which two steps should an identity architect recommend?
Choose 2 answers
A) Implement SesslonManagement Class.
B) Implement Auth.SamlJitHandler Interface.
C) Implement RegistrationHandler Interface.
D) Create and update methods.
4. Containers (UC) has decided to implement a federated single Sign-on solution using a third-party Idp. In reviewing the third-party products, they would like to ensure the product supports the automated provisioning and deprovisioning of users. What are the underlining mechanisms that the UC Architect must ensure are part of the product?
A) Just-In-time (JIT) for Provisioning; SOAP API for Deprovisioning.
B) Provisioning API for both Provisioning and Deprovisioning.
C) SOAP API for provisioning; Just-in-Time (JIT) for Deprovisioning.
D) Just-in-Time (JIT) for both Provisioning and Deprovisioning.
5. A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APAC. The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS . The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.
What is recommended to ensure these requirements are met ?
A) Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.
B) Add a central identity system that federates between the ADFS systems and integrate with Salesforce for single sign-on.
C) Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.
D) Configure Each ADFS system under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce-
Solutions:
| Question # 1 Answer: A | Question # 2 Answer: A,B,C | Question # 3 Answer: B,D | Question # 4 Answer: D | Question # 5 Answer: C |














1300 Customer Reviews
Quality and ValueITCertKing Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITCertKing testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITCertKing offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.
