Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

Identity-and-Access-Management-Architect Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) Free Practice Exam Questions (2026 Updated)

Prepare effectively for your Salesforce Identity-and-Access-Management-Architect Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Universal Containers is designing an identity architecture that involves integrating Salesforce with an external directory service. The external directory service will act as the central repository for user authentication and authorization across multiple systems within the organization.

Which approach should be evaluated to establish trust between Salesforce and the external directory service?

A.

Utilizing email-based verification for user authentication across the systems.

B.

Using a shared database table to synchronize user credentials between the two systems.

C.

Enforcing IP-based access restrictions for Salesforce and the external directory service.

D.

Implementing a federated identity solution based on SANL (Security Assertion Markup Language).

Northern Trail Outfitters (NTO) would like to use a portal built on Salesforce Experience Cloud for customer self-service. Guests of the portal should be able to self-register, but be unable to automatically be assigned to a contact record until verified. External Identity licenses have been purchased for the project.

After registered guests complete an onboarding process, a flow will create the appropriate account and contact records for the user.

Which three steps should an identity architect follow to implement the outlined requirements?

Choose 3 answers

A.

Customize the self-registration Apps handler to create only the user record.

B.

Select the “Configurable Self-Reg Page” option under Login & Registration.

C.

Set up an external login page and call Salesforce APIs for user creation.

D.

Select new customers and partners to self-register.

E.

Customize the self-registration Apps handler to temporarily associate the user to a shared single contact record.

Universal Containers (UC) is rolling out its new Customer Identity and Access Management Solution built on top of its existing Salesforce instance. UC wants to allow customers to login using Facebook, Google, and other social sign-on providers.

How should this functionality be enabled for UC, assuming all social sign-on providers support OpenID Connect?

A.

configure a single sign-on setting and a JTT handler for each social sign-on provider.

B.

configure an authentication provider and a Auto-Time Unit handler for each social sign-on provider.

C.

configure an authentication provider and a registration handler for each social sign-on provider.

D.

configure a single sign-on setting and a registration handler for each social sign-on provider.

Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for NTO to give its customers the ability to login with their Facebook and Twitter credentials.

What should an identity architect recommend to meet these requirements?

A.

create a custom external authentication provider for Facebook.

B.

obtain login icon for Facebook and Twitter.

C.

configure a predefined authentication provider for Facebook and Twitter.

D.

create a custom external authentication provider for Twitter.

A financial services company uses Salesforce and has a compliance requirement to track information about devices from which users log in. Also, a Salesforce Security Administrator

needs to have the ability to revoke the device from which users log in.

What should be used to fulfill this requirement?

A.

Use multi-factor authentication (MFA) to meet the compliance requirement to track device information.

B.

Use the Login History object to track information about devices from which users log in.

C.

Use Login Flows to capture device from which users log in and store device and user information in a custom object.

D.

Use the Activations feature to meet the compliance requirement to track device information.

A real estate company wants to provide its customers a digital space to design their interior decoration options. To simplify the registration to gain access to the community site (built in Experience Cloud), the CTO has requested that the IT/Development team provide the option for customers to use their existing social-media credentials to register and access.

The IT lead has approached the Salesforce Identity and Access Management (IAM) architect

for technical direction on implementing the social sign-on (for Facebook, Twitter, and a new

provider that supports standard OpenID Connect (OIDC)).

Which two recommendations should the Salesforce IAM architect make to the IT Lead?

Choose 2 answers

A.

For supporting OIDC it is necessary to enable Security Assertion Markup Language (SAML) with Just-In-Time provisioning (JIT) and OAuth 2.0.

B.

Authentication provider configuration is required each social sign-on providers; and enable Authentication providers in community.

C.

Apex coding skills are needed for registration handler to create and update users.

D.

Use declarative registration handler process builder/flow to create, update users and contacts.

Northern Trail Outfitters (NTO) uses Salesforce for Sales Opportunity Management. Okta was recently brought in to Just-in-Time (JIT) provision and authenticate NTO users to applications. Salesforce users also use Okta to authorize a Forecasting web application to access Salesforce records on their behalf.

Which two roles are being performed by Salesforce?

Choose 2 answers

A.

OAuth Resource Server

B.

SAML Service Provider

C.

OAuth Client

D.

SAML Identity Provider

Northern Trail Outfitters (NTO) uses a Security Assertion Markup Language (SANL)-based Identity Provider (IdP) to authenticate employees to all systems. The IdP authenticates users

against a Lightweight Directory Access Protocol (LDAP) directory and has access to user information. NTO wants to minimize Salesforce license usage since only a small percentage

of users need Salesforce.

What is recommended to ensure new employees have immediate access to Salesforce using their current IdP?

A.

Build an Integration that exorcits LDAP periodically and creates new active users in Salesforce.

B.

configure Auto-in-Time provisioning using SANL attributes to create new Salesforce users as necessary when a new user attempts to login to Salesforce.

C.

Define a process where administrators manually create new users in Salesforce.

D.

Build an Integration that exorcist LDAP and creates new inactive users in Salesforce and use a login flow to activate the user at first login.

A financial enterprise is planning to set up a user authentication mechanism to login to the Salesforce system. Due to regulatory requirements, the CIO of the company wants user administration, including passwords and authentication requests, to be managed by an external system that is only accessible via a SOAP webservice.

Which authentication mechanism should an identity architect recommend to meet the requirements?

A.

Just-in-Time Provisioning

B.

Delegated Authentication

C.

Security Assertion Markup Language (SANL) Single Sign On

D.

OAuth Web-Server Flow

A leading fitness tracker company is getting ready to launch a customer community. The company wants its customers to login to the community and connect their fitness device to their profile. Customers should be able to obtain exercise details and fitness recommendation in the community.

Which should be used to satisfy this requirement?

A.

Named Credentials

B.

Login Flows

C.

OAuth Device Flow

D.

OAuth Asset Token flow

Northern Trail Outfitters (NTO) is planning to implement a community for its customers

using Salesforce Experience Cloud. Customers are not able to self-register. NTO would like to have customers set their own passwords when provided access to the community.

Which two recommendations should an identity architect make to fulfill this requirement?

Choose 2 answers

A.

Enable Welcome emails while configuring the Experience Cloud site.

B.

Use Login Flows to allow users to reset password in Experience Cloud site.

C.

Allow Password reset using the API to update Experience Cloud site membership.

D.

Add customers as contacts and add them to Experience Cloud site.

A multinational industrial products manufacturer is planning to implement Salesforce CRM to manage their business. They have the following requirements:

1. They plan to implement Partner communities to provide access to their partner network.

2. They have operations in multiple countries and are planning to implement multiple Salesforce orgs.

3. Some of their partners do business in multiple countries and will need information from multiple Salesforce communities.

4. They would like to provide a single login for their partners.

How should an Identity Architect solution this requirement with limited custom development?

A.

Create a partner login for the country of their operation and use SAML federation to provide access to other orgs.

B.

Register partners in one org and access information from other orgs using APIs.

C.

Allow partners to choose the Salesforce org they need information from and use login flows to authenticate access.

D.

Consolidate Partner related information in a single org and provide access through Salesforce community.

Copyright © 2014-2026 Solution2Pass. All Rights Reserved