Salesforce Plat-Arch-203 Exam Overview:
| Certification Vendor: | Salesforce |
|---|---|
| Exam Name: | Salesforce Certified Platform Identity and Access Management Architect |
| Exam Number: | Plat-Arch-203 |
| Exam Price: | USD 400 |
| Exam Format: | Multiple-choice, Multiple-select |
| Available Languages: | English |
| Related Certifications: | Salesforce Certified Application Architect Salesforce Certified System Architect Salesforce Certified Technical Architect |
| Real Exam Qty: | 60 (+ up to 5 unscored) |
| Exam Duration: | 120 minutes |
| Passing Score: | 68% |
| Sample Questions: | Salesforce Plat-Arch-203 Sample Questions |
| Exam Way: | Online (proctored) or at a Kryterion testing center |
| Pre Condition: | Salesforce recommends completing Salesforce Certified System Architect and/or Application Architect prior to attempting this exam. Practical experience with Salesforce identity, SSO, and security is expected. |
| Official Syllabus URL: | https://trailhead.salesforce.com/credentials/identityandaccessmanagementarchitect |
Salesforce Plat-Arch-203 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Integration | 15% | - Identity Integration Concepts
|
| Topic 2: Identity and Single Sign-On | 30% | - Identity Management Concepts
|
| Topic 3: Security and Compliance | 25% | - Access Management Best Practices
|
| Topic 4: Access Management | 30% | - Salesforce Identity
|
Salesforce Certified Platform Identity and Access Management Architect Sample Questions:
Question 1
Universal Containers (UC) is both a Salesforce and Google Apps customer. The UC IT team would like to manage the users for both systems in a single place to reduce administrative burden. Which two optimal ways can the IT team provision users and allow Single Sign-on between Salesforce and Google Apps ? Choose 2 answers
A. Use Identity Connect as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
B. Use Salesforce as the Identity Provider and Google Apps as a Service Provider and configure User Provisioning for Connected Apps.
C. Build a custom app running on Heroku as the Identity Provider that can sync user information between Salesforce and Google Apps.
D. Use a third-party product as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
Question 2
The executive sponsor for an organization has asked if Salesforce supports the ability to embed a login widget into its service providers in order to create a more seamless user experience.
What should be used and considered before recommending it as a solution on the Salesforce Platform?
A. OpenID Connect Web Server Flow. Determine if the service provider is secure enough to store the client secret on.
B. Embedded Login. Consider whether or not it relies on third party cookies which can cause browser compatibility issues.
C. Salesforce REST apis. Ensure that Secure Sockets Layer (SSL) connection for the integration is used.
D. Embedded Login. Identify what level of UI customization will be required to make it match the service providers look and feel.
Question 3
Universal Containers (UC) wants to build a custom mobile app for their field reps to create orders in salesforce. After the first time the users log in, they must be able to access salesforce upon opening the mobile app without being prompted to log in again. What Oauth flows should be considered to support this requirement?
A. SAML Assertion flow with a Bearer Token.
B. User Agent flow with a Refresh Token.
C. Mobile Agent flow with a Bearer Token.
D. Web Server flow with a Refresh Token.
Question 4
Universal Containers (UC) is planning to deploy a custom mobile app that will allow users to get e-signatures from its customers on their mobile devices. The mobile app connects to Salesforce to upload the e-signature as a file attachment and uses OAuth protocol for both authentication and authorization. What is the most recommended and secure OAuth scope setting that an Architect should recommend?
A. Custom_permissions
B. Web
C. Api
D. Id
Question 5
Sales users at Universal containers use salesforce for Opportunity management. Marketing uses a third-party application called Nest for Lead nurturing that is accessed using username/password. The VP of sales wants to open up access to nest for all sales uses to provide them access to lead history and would like SSO for better adoption. Salesforce is already setup for SSO and uses Delegated Authentication. Nest can accept username/Password or SAML-based Authentication. IT teams have received multiple password-related issues for nest and have decided to set up SSO access for Nest for Marketing users as well. The CIO does not want to invest in a new IDP solution and is considering using Salesforce for this purpose. Which are appropriate license type choices for sales and marketing users, giving salesforce is using Delegated Authentication? Choose 2 answers
A. Salesforce license for sales users and Identity license for Marketing users
B. Salesforce license for sales users and platform license for Marketing users.
C. Salesforce license for sales users and External Identity license for Marketing users
D. Identity license for sales users and Identity connect license for Marketing users
Solutions:
| Question 1 Answer: B,D | Question 2 Answer: B | Question 3 Answer: B | Question 4 Answer: A | Question 5 Answer: A,B |
We're so confident of our products that we provide no hassle product exchange.


By Tammy

