Pre-Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Identity-and-Access-Management-Architect Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) is now Stable and With Pass Result | Test Your Knowledge for Free

Exams4sure Dumps

Identity-and-Access-Management-Architect Practice Questions

Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)

Last Update 1 day ago
Total Questions : 109

Dive into our fully updated and stable Identity-and-Access-Management-Architect practice test platform, featuring all the latest Identity and Access Management Designer exam questions added this week. Our preparation tool is more than just a Salesforce study aid; it's a strategic advantage.

Our free Identity and Access Management Designer practice questions crafted to reflect the domains and difficulty of the actual exam. The detailed rationales explain the 'why' behind each answer, reinforcing key concepts about Identity-and-Access-Management-Architect. Use this test to pinpoint which areas you need to focus your study on.

Identity-and-Access-Management-Architect PDF

Identity-and-Access-Management-Architect PDF (Printable)
$43.75
$124.99

Identity-and-Access-Management-Architect Testing Engine

Identity-and-Access-Management-Architect PDF (Printable)
$50.75
$144.99

Identity-and-Access-Management-Architect PDF + Testing Engine

Identity-and-Access-Management-Architect PDF (Printable)
$63.7
$181.99
Question # 21

Northern Trail Outfitters manages application functional permissions centrally as Active Directory groups. The CRM_SuperUser and CRM_Reporting_SuperUser groups should respectively give the user the SuperUser and Reporting_SuperUser permission set in Salesforce. Salesforce is the service provider to a Security Assertion Markup Language (SAML) identity provider.

How should an identity architect ensure the Active Directory groups are reflected correctly

when a user accesses Salesforce?

Options:

A.  

Use the Apex Just-in-Time handler to query custom SAML attributes and set permission sets.

B.  

Use a login flow to query standard SAML attributes and set permission sets.

C.  

Use a login flow to query custom SAML attributes and set permission sets.

D.  

Use the Apex Just-in-Time handler to query standard SAML attributes and set permission sets.

Discussion 0
Question # 22

Northern Trail Outfitters is implementing a business-to-business (B2B) collaboration site using Salesforce Experience Cloud. The partners will authenticate with an existing identity provider and the solution will utilize Security Assertion Markup Language (SAML) to provide single sign-on to Salesforce. Delegated administration will be used in the Experience Cloud site to allow the partners to administer their users ' access.

How should a partner identity be provisioned in Salesforce for this solution?

Options:

A.  

Create a user and a related contact.

B.  

Create only a contact.

C.  

Create a contactless user.

D.  

Create a person account.

Discussion 0
Question # 23

A consumer products company uses Salesforce to maintain consumer information, including orders. The company implemented a portal solution using Salesforce Experience Cloud for its consumers where the consumers can log in using their credentials. The company is considering allowing users to login with their Facebook or LinkedIn credentials.

Once enabled, what role will Salesforce play?

Options:

A.  

Facebook and LinkedIn will be this SPs.

B.  

Facebook and LinkedIn will act as the LIPS and SPs.

C.  

Salesforce will be the service provider (SP).

D.  

Salesforce will be the identity provider (LIP).

Discussion 0
Question # 24

Universal Containers want users to be able to log in to the Salesforce mobile app with their Active Directory password. Employees are unable to use mobile VPN.

Which two options should an identity architect recommend to meet the requirement?

Choose 2 answers

Options:

A.  

Active Directory Password Since Plugin

B.  

Salesforce Identity Connect

C.  

Salesforce Trigger & Field on Contact Object

D.  

Configure Cloud Provider Load Balancer

Discussion 0
Question # 25

Northern Trail Outfitters (NTO) recently purchased Salesforce Identity Connect to streamline user provisioning across Microsoft Active Directory (AD) and Salesforce Sales Cloud.

NTO has asked an identity architect to identify which Salesforce security configurations can map to AD permissions.

Which three Salesforce permissions are available to map to AD permissions?

Choose 3 answers

Options:

A.  

Sharing Rules

B.  

Public Groups

C.  

Permission Set License

D.  

Roles

E.  

Profiles and Permission Sets

Discussion 0
Question # 26

A third-party app provider would like to have users provisioned via a service endpoint before users access their app from Salesforce.

What should an identity architect recommend to configure the requirement with limited changes to the third-party app?

Options:

A.  

Use a connected app with user provisioning flow.

B.  

Redirect users to the third-party app for registration.

C.  

Create Canvas app in Salesforce for third-party app to provision users.

D.  

Use Salesforce Identity with Security Assertion Markup Language (SAML) for provisioning users.

Discussion 0
Question # 27

An identity architect is setting up an integration between Salesforce and a third-party system. The third-party system needs to be able to authenticate to Salesforce and then make API calls against the REST API.

One of the requirements is that the solution needs to ensure the third party service providers connected app in Salesforce minimizes the need for end user interaction and maximizes security.

Which OAuth flow should be used to fulfill the requirement?

Options:

A.  

JWT Bearer Flow

B.  

Web Server Flow

C.  

Username-Razoned Flow

D.  

User Agent Flow

Discussion 0
Question # 28

A financial services company uses Salesforce and has a compliance requirement to track information about devices from which users log in. Also, a Salesforce Security Administrator

needs to have the ability to revoke the device from which users log in.

What should be used to fulfill this requirement?

Options:

A.  

Use multi-factor authentication (MFA) to meet the compliance requirement to track device information.

B.  

Use the Login History object to track information about devices from which users log in.

C.  

Use Login Flows to capture device from which users log in and store device and user information in a custom object.

D.  

Use the Activations feature to meet the compliance requirement to track device information.

Discussion 0
Question # 29

Northern Trail Outfitters (NTO) is planning to roll out a partner portal for its distributors using Experience Cloud. NTO would like to use an external identity provider (IdP) and for partners to register for access to the portal. Each partner should be allowed to register only once to avoid duplicate accounts with Salesforce.

What should a identity architect recomend to create partners?

Options:

A.  

Create a custom page in Experience Cloud to self register partner with Experience Cloud and Ping Identity store.

B.  

On successful creation of Partners using Self Registration page in Experience Cloud, create Identity in Ping.

C.  

Create a custom web page in the Portal and create users in the IdP and Experience Cloud

using published APIs.

D.  

Allow partners to register through the IdP and create partner users in Salesforce through an API.

Discussion 0
Question # 30

Universal Containers (UC) has an Experience Cloud site (Customer Community) where customers can authenticate and place orders, view the status of orders, etc. UC allows guest checkout.

How can a guest register using data previously collected during order placement?

Options:

A.  

Enable self-registration and customize a self-registration page to collect only order details to retrieve customer data.

B.  

Enable Security Assertion Markup Language (SAML) Sign-On and use a login flow to collect only order details to retrieve customer data.

C.  

Enable Facebook as an authentication provider and use a registration handler to collect only order details to retrieve customer data.

D.  

Use a Connected App Handler. Apex Plugin class to collect only order details to retrieve customer data.

Discussion 0
Get Identity-and-Access-Management-Architect dumps and pass your exam in 24 hours!

Free Exams Sample Questions