Exam Code: Identity-and-Access-Management-Architect
Exam Questions: 258
Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
Updated: 24 May, 2026
Viewing Page : 1 - 26
Practicing : 1 - 5 of 258 Questions
Question 1

Northern Trail Outfitters is implementing a busmess-to-business (B2B) collaboration site using Salesforce
Experience Cloud. The partners will authenticate with an existing identity provider and the solution will utilize
Security Assertion Markup Language (SAML) to provide single sign-on to Salesforce. Delegated
administration will be used in the Expenence Cloud site to allow the partners to administer their users' access.
How should a partner identity be provisioned in Salesforce for this solution?

Options :
Answer: C

Question 2

Universal containers wants to build a custom mobile app connecting to salesforce using Oauth, and would like
to restrict the types of resources mobile users can access. What Oauth feature of Salesforce should be used to
achieve the goal?

Options :
Answer: D

Question 3

Universal containers (UC) is building a mobile application that will make calls to the salesforce REST API.
Additionally UC would like to provide the optimal experience for its mobile users. Which two OAuth scopes
should UC configure in the connected App? Choose 2 answers

Options :
Answer: A,B

Question 4

A large consumer company is planning to create a community and will requ.re login through the customers
social identity. The following requirements must be met:
1. The customer should be able to login with any of their social identities, however salesforce should only
have one user per customer.
2. Once the customer has been identified with a social identity, they should not be required to authonze
Salesforce.
3. The customers personal details from the social sign on need to be captured when the customer logs into
Salesforce using their social Identity.
3. If the customer modifies their personal details in the social site, the changes should be updated in Salesforce
.
Which two options allow the Identity Architect to fulfill the requirements?
Choose 2 answers

Options :
Answer: B,D

Question 5

Northern Trail Outfitters (NTO) has an off-boarding process where a terminated employee is first disabled in
the Lightweight Directory Act Protocol (LDAP) directory, then requests are sent to the various application
support teams to finish user deactivations. A terminated employee recently was able to login to NTO's
Salesforce instance 24 hours after termination, even though the user was disabled in the corporate LDAP
directory.
What should an identity architect recommend to prevent this from happening in the future?

Options :
Answer: B

Viewing Page : 1 - 26
Practicing : 1 - 5 of 258 Questions

© Copyrights FreePDFQuestions 2026. All Rights Reserved

We use cookies to ensure that we give you the best experience on our website (FreePDFQuestions). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreePDFQuestions.