Salesforce Plat-Arch-203 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Access Management and Security Controls | - Multi-factor authentication (MFA) enforcement - Profiles, permission sets, and role hierarchy - Session management and security policies |
| Identity and Access Management Fundamentals | - Identity lifecycle management concepts - Enterprise identity architecture basics - Authentication vs authorization principles |
| API and Integration Security | - Secure integration patterns - OAuth scopes and API authentication flows - Token management and refresh mechanisms |
| Salesforce Identity Services | - Identity Connect and external identity providers - Connected Apps and OAuth policies - My Domain and identity configuration |
| Experience Cloud and External Identity | - B2B and B2C identity considerations - Community login and identity providers - External user authentication and authorization |
| Authentication and Single Sign-On (SSO) | - SSO troubleshooting and configuration - SAML 2.0 implementation in Salesforce - OpenID Connect and OAuth 2.0 flows |
Salesforce Certified Platform Identity and Access Management Architect Sample Questions:
1. Universal Containers (UC) wants to integrate a third-party Reward Calculation system with Salesforce to calculate Rewards. Rewards will be calculated on a schedule basis and update back into Salesforce. The integration between Salesforce and the Reward Calculation System needs to be secure. Which are two recommended practices for using OAuth flow in this scenario. choose 2 answers
A) OAuth SAML Bearer Assertion FLow
B) OAuth JWT Bearer Token FLow
C) OAuth Refresh Token FLow
D) OAuth Username-Password Flow
2. Universal Containers (UC) has an existing e-commerce platform and is implementing a new customer community. They do not want to force customers to register on both applications due to concern over the customers experience. It is expected that 25% of the e-commerce customers will utilize the customer community . The e-commerce platform is capable of generating SAML responses and has an existing REST-ful API capable of managing users. How should UC create the identities of its e-commerce users with the customer community?
A) Use the standard Salesforce API to create users in the Community When a User is Created in the e-Commerce platform and use SAML to allow SSO.
B) Use SAML JIT in the Customer Community to create users when a user tries to login to the community from the e-commerce site.
C) Use a nightly batch ETL job to sync users between the Customer Community and the e-commerce platform and use SAML to allow SSO.
D) Use the e-commerce REST API to create users when a user self-register on the customer community and use SAML to allow SSO.
3. Universal Containers (UC) wants its closed Won opportunities to be synced to a Data Warehouse in near real time. UC has implemented Outbound Message to enable near real-time data sync. UC wants to ensure that communication between Salesforce and Target System is Secure. What Certificate is sent along with the Outbound Message?
A) The default Client Certificate from the Develop--> API Menu.
B) The CA-Signed Certificate from the Certificate and Key Management menu.
C) The default Client Certificate or a Certificate from Certificate and Key Management menu.
D) The Self-Signed Certificates from the Certificate & Key Management menu.
4. customer service representatives at Universal containers (UC) are complaining that whenever they click on links to case records and are asked to login with SAML SSO, they are being redirected to the salesforce home tab and not the specific case record. What item should an architect advise the identity team at UC to investigate first?
A) My domain is configured and active within salesforce.
B) The identity provider is correctly preserving the Relay state
C) The users have the correct Federation ID within salesforce.
D) The salesforce SSO settings are using http post
5. How should an Architect automatically redirect users to the login page of the external Identity provider when using an SP-Initiated SAML flow with Salesforce as a Service Provider?
A) Set the Identity Provider as default and enable the Redirect to the Identity Provider setting on the SAML Configuration.
B) Enable the Redirect to the Identity Provider setting under Authentication Services on the My domain Configuration.
C) Remove the Login page from the list of Authentication Services on the My Domain configuration.
D) Use visualforce as the landing page for My Domain to redirect users to the Identity Provider login Page.
Solutions:
| Question # 1 Answer: A,B | Question # 2 Answer: B | Question # 3 Answer: A | Question # 4 Answer: B | Question # 5 Answer: C |














1041 Customer Reviews
Quality and ValueITCertKing Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITCertKing testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITCertKing offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.
