Pre-Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

Identity-and-Access-Management-Architect Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203) is now Stable and With Pass Result | Test Your Knowledge for Free

Exams4sure Dumps

Identity-and-Access-Management-Architect Practice Questions

Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)

Last Update 1 day ago
Total Questions : 109

Dive into our fully updated and stable Identity-and-Access-Management-Architect practice test platform, featuring all the latest Identity and Access Management Designer exam questions added this week. Our preparation tool is more than just a Salesforce study aid; it's a strategic advantage.

Our free Identity and Access Management Designer practice questions crafted to reflect the domains and difficulty of the actual exam. The detailed rationales explain the 'why' behind each answer, reinforcing key concepts about Identity-and-Access-Management-Architect. Use this test to pinpoint which areas you need to focus your study on.

Identity-and-Access-Management-Architect PDF

Identity-and-Access-Management-Architect PDF (Printable)
$43.75
$124.99

Identity-and-Access-Management-Architect Testing Engine

Identity-and-Access-Management-Architect PDF (Printable)
$50.75
$144.99

Identity-and-Access-Management-Architect PDF + Testing Engine

Identity-and-Access-Management-Architect PDF (Printable)
$63.7
$181.99
Question # 1

Northern Trail Outfitters recently acquired a company. Each company will retain its Identity Provider (IdP). Both companies rely extensively on Salesforce processes that send emails to users to take specific actions in Salesforce.

How should the combined companys ' employees collaborate in a single Salesforce org, yet authenticate to the appropriate IdP?

Options:

A.  

Configure unique MyDomains for each company and have generated links use the appropriate MyDomain in the URL.

B.  

Have generated links append a quenystring parameter indicating the IdP. The login service will redirect to the appropriate IdP.

C.  

Enable each IdP as a login option in the My Domain Authentication Service settings. Users will then click on the appropriate IdP button.

D.  

Have generated links be prefixed with the appropriate IdP URL to invoke an idP-initiated Security Assertion Markup Language flow when clicked.

Discussion 0
Question # 2

Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the QAuth 2.0 user-agent flow (this flow uses the QAuth 2.0 implicit grant type).

Which three QAuth concepts apply to this flow?

Choose 3 answers

Options:

A.  

Refresh Token

B.  

Client ID

C.  

Verification Code

D.  

Authorization Code

E.  

Scopus

Discussion 0
Question # 3

Northern Trail Outfitters (NTO) is planning to build a new customer service portal and wants to use passwordless login, allowing customers to login with a one-time passcode sent to them via email or SMS.

How should the quantity of required Identity Verification Credits be estimated?

Options:

A.  

Identity Verification Credits are consumed with each verification sent and should be estimated based on the number of logins that will incur a verification challenge.

B.  

Each community comes with 10,000 Identity Verification Credits per month and only customers with more than 10,000 logins a month should estimate additional SMS verifications needed.

C.  

Identity Verification Credits are consumed with each SMS (best message) sent and should be estimated based on the number of login verification challenges for SMS verification users.

D.  

Identity Verification Credits are a direct add-on license based on the number of existing member-based or login-based Community licenses.

Discussion 0
Question # 4

An identity architect ' s client has a homegrown identity provider (IdP). Salesforce is used as the service provider (SP). The head of IT is worried that during a SP initiated single sign-on (SSO), the Security Assertion Markup Language (SAML) request content will be altered.

What should the identity architect recommend to make sure that there is additional trust between the SP and the IdP?

Options:

A.  

Ensure that there is an HTTPS connection between IDP and SP.

B.  

Encrypt the SAML Request using certification authority (CA) signed certificate and decrypt on IdP.

C.  

Ensure that the Issuer and Assertion Consumer Service (ACS) URL is properly configured between SP and IDP.

D.  

Ensure that on the SSO settings page, the " Request Signing Certificate " field has a selfsigned certificate.

Discussion 0
Question # 5

A global fitness equipment manufacturer is planning to sell fitness tracking devices and has the following requirements:

1) Customer purchases the device.

2) Customer registers the device using their mobile app.

3) A case should automatically be created in Salesforce and associated with the customers

account in cases where the device registers issues with tracking.

Which OAuth flow should be used to meet these requirements?

Options:

A.  

OAuth 2.0 User-Agent Flow

B.  

OAuth 2.0 Asset Token Flow

C.  

OAuth 2.0 Device Flow

D.  

OAuth 2.0 SAVL Server Assertion Flow

Discussion 0
Question # 6

Universal Containers (UC) is rolling out its new Customer Identity and Access Management Solution built on top of its existing Salesforce instance. UC wants to allow customers to login using Facebook, Google, and other social sign-on providers.

How should this functionality be enabled for UC, assuming all social sign-on providers support OpenID Connect?

Options:

A.  

configure a single sign-on setting and a JTT handler for each social sign-on provider.

B.  

configure an authentication provider and a Auto-Time Unit handler for each social sign-on provider.

C.  

configure an authentication provider and a registration handler for each social sign-on provider.

D.  

configure a single sign-on setting and a registration handler for each social sign-on provider.

Discussion 0
Question # 7

Universal Containers (UC) is planning to add Wi-Fi enabled GPS tracking devices to its shipping containers so that the GPS coordinates data can be sent from the tracking device to its Salesforce production org via a custom API. The GPS devices have no direct user input or output capabilities.

Which OAuth flow should the identity architect recommend to meet the requirement?

Options:

A.  

OAuth 2.0 Asset Token Flow for Securing Connected Devices

B.  

OAuth 2.0 Web Server Flow for Web App Integration

C.  

OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration

D.  

OAuth 2.0 Username-Password Flow for Special Scenarios

Discussion 0
Question # 8

A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APA

C.  

The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS. The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.

What is recommended to ensure these requirements are met?

Options:

A.  

Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.

B.  

Configure Each ADFS system under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce.

C.  

Add a central identity system that facilitates between the ADFS systems and integrate with Salesforce for single sign-on.

D.  

Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.

Discussion 0
Question # 9

Northern Trail Outfitters (NTO) is planning to implement a community for its customers

using Salesforce Experience Cloud. Customers are not able to self-register. NTO would like to have customers set their own passwords when provided access to the community.

Which two recommendations should an identity architect make to fulfill this requirement?

Choose 2 answers

Options:

A.  

Enable Welcome emails while configuring the Experience Cloud site.

B.  

Use Login Flows to allow users to reset password in Experience Cloud site.

C.  

Allow Password reset using the API to update Experience Cloud site membership.

D.  

Add customers as contacts and add them to Experience Cloud site.

Discussion 0
Question # 10

A technology enterprise is planning to implement single sign-on login for users. When users log in to Salesforce, data should be populated in User object custom fields.

Which two steps should an identity architect recommend?

Choose 2 answers

Options:

A.  

Implement Registration/Handle Interface.

B.  

Implement SessionManagement Class.

C.  

Implement Auth.SumIDHandler Interface.

D.  

Create and update methods.

Discussion 0
Get Identity-and-Access-Management-Architect dumps and pass your exam in 24 hours!

Free Exams Sample Questions