Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Salesforce Identity-and-Access-Management-Architect Practice Exam with Questions & Answers

Questions 1

A client is planning to rollout multi-factor authentication (MFA) to its internal employees and wants to understand which authentication and verification methods meet the Salesforce criteria for secure authentication.

Which three functions meet the Salesforce criteria for secure MFA?

Choose 3 answers

Options:
A.

Username and password = security key

B.

Lightning Login

C.

Username and password = SMS passwords

D.

Third-party single sign-on with Mobile Authenticator app

E.

Username & password = Email Verification Code

Salesforce Identity-and-Access-Management-Architect Premium Access
Questions 2

A Salesforce Administrator is tasked with setting up Just-in-Time (JIT) provisioning for SAML to enable Single Sign-On (SSO) for your organization. They have already configured the SAML settings for SSO in Salesforce.

What should be their next steps to enable JIT provisioning?

Options:
A.

Enable Just-in-Time User Provisioning in the SAML Single Sign-On Setting, configure the User Provisioning Type, and provide the SAML JIT Handler.

B.

Create a new permission set with JIT provisioning enabled, configure the necessary permissions, and assign the permission set to relevant users.

C.

Create a new Apex class to handle JIT provisioning, implement the required methods, and assign the class to the appropriate user profiles.

D.

Modify the organization-wide sharing settings to allow JIT provisioning, update the sharing rules for the user object.

Questions 3

An Identity architect works for a multinational, multi-brand organization. As they work with the organization to understand their Customer Identity and Access Management requirements, the identity architect learns that the brand experience is different for each of the customer’s sub-brands and each of these branded experiences must be carried through the login experience depending on which sub-brand the user is logging into.

Which solution should the architect recommend to support scalability and reduce maintenance costs, if the organization has more than 150 sub-brands?

Options:
A.

Create a community subdomain for each sub-brand and customize the look and feel of the Login page for each community subdomain to match the brand.

B.

Assign each sub-brand a unique Experience ID and use the Experience ID to dynamically brand the login experience.

C.

Create a separate Salesforce org for each sub-brand so that each sub-brand has complete control over the user experience.

D.

Use Audiences to customize the login experience for each sub-brand and pass an audience ID to the community during the DAuth and Security Assertion Markup Language (SANL) flows.

Questions 4

An identity architect is setting up an integration between Salesforce and a third-party system. The third-party system needs to be able to authenticate to Salesforce and then make API calls against the REST API.

One of the requirements is that the solution needs to ensure the third party service providers connected app in Salesforce minimizes the need for end user interaction and maximizes security.

Which OAuth flow should be used to fulfill the requirement?

Options:
A.

JWT Bearer Flow

B.

Web Server Flow

C.

Username-Razoned Flow

D.

User Agent Flow

Questions 5

A manufacturer wants to provide registration for an Internet of Things (IoT) device with limited display input or capabilities.

Which Salesforce OAuth authorization flow should be used?

Options:
A.

OAuth 2.0 User-Agent

B.

OAuth 2.0 Asset Token Flow

C.

OAuth 2.0 WiT Bearer Flow

D.

OAuth 2.0 Device Flow

Questions 6

Universal Containers (UC) rolling out a new Customer Identity and Access Management Solution will be built on top of their existing Salesforce instance. Several service providers have been setup and integrated with Salesforce using OpenID Connect to allow for a seamless single sign-on experience. UC has a requirement to limit users to sign on directly from the Salesforce org to the external Service provider app that accepts OpenID Connect.

Which two steps should be done on the platform to satisfy the requirement?

Choose 2 answers

Options:
A.

Manage which connected apps a user has access to by assigning authentication providers to the users profile.

B.

Assign the connected app to the customer community, and enable the users profile in the Community settings.

C.

Set each of the Connected App access settings to Admin Pre-Approved.

D.

Use Profiles and Permission Sets to assign user access to Admin Pre-Approved Connected Apps.

Questions 7

Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the OAuth 2.0 user-agent flow (this flow uses the OAuth 2.0 implicit grant type). Which three OAuth concepts apply to this flow?

Choose 3 answers

Options:
A.

Scopes

B.

Client ID

C.

Authorization Code

D.

Verification Code

E.

Refresh Token

Questions 8

An identity architect has built a native mobile application and plans to integrate it with a Salesforce Identity solution. The following are the requirements for the solution:

1. Users should not have to login every time they use the app.

2. The app should be able to make calls to the Salesforce REST API.

3. End users should NOT see the OAuth approval page.

How should the identity architect configure the Salesforce connected app to meet the requirements?

Options:
A.

Enable the API Scope and Offline Access Scope on the connected app, and then set the Connected App access settings to " User may self authorize " .

B.

Enable the Full Access Scope and then set the connected app access settings to " Admin Pre-Approved " .

C.

Enable the API Scope and Offline Access Scope on the connected app, and then set the connected app to access settings to " Admin Pre-Approved " .

D.

Enable the API Scope and Offline Access Scope, upload a certificate so JWT Bearer Flow can be used and then set the connected app access settings to " Admin Pre-Approved " .

Questions 9

Northern Trail Outfitters wants to implement a partner community. Active community users will need to review and accept the community rules, and update key contact information for each community member before performing any further operation on the portal.

Which approach will meet this requirement?

Options:
A.

Create a custom landing page and email campaign asking all community members to login and verify their data.

B.

Add a banner to the community Home page asking users to update their profile and accept the new community rules.

C.

Create tasks for users who need to update their data or accept the new community rules.

D.

Create a login flow that conditionally prompts users who have not accepted the new community rules and who have missing or outdated information.

Questions 10

Universal Containers wants to allow its customers to log in to its Experience Cloud via a third party authentication provider that supports only the OAuth protocol.

What should an identity architect do to fulfill this requirement?

Options:
A.

Contact Salesforce Support and enable delegate single sign-on.

B.

Configure OpenID Connect authentication provider.

C.

Create a custom external authentication provider.

D.

Use certificate-based authentication.

Certification Provider: Salesforce
Exam Name: Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
Last Update: Apr 14, 2026
Questions: 109