Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Salesforce Identity-and-Access-Management-Architect Practice Exam with Questions & Answers | Set: 3

Questions 21

Northern Trail Outfitters (NTO) wants its customers to use phone numbers to log in to their new digital portal, which was designed and built using Salesforce Experience Cloud. In order to access the portal, the user will need to do the following:

1. Enter a phone number and/or email address

2. Enter a verification code that is to be sent via email or text.

What is the recommended approach to fulfill this requirement?

Options:
A.

create an authentication provider and implement a self-registration handler class.

B.

Create a custom login page with an Apex controller. The controller has tips to send and verify the identity.

C.

create a Login Discoverer page and provide a Login Discovery Handler Apex class.

D.

Create a custom login flow that uses an Apex controller to verify the phone numbers with the company’s verification service.

Salesforce Identity-and-Access-Management-Architect Premium Access
Questions 22

Northern Trail Outfitters want to allow its consumer to self-register on it business-to consumer (B2C) portal that is built on Experience Cloud. The identity architect has recommended to use Person Accounts.

Which three steps need to be configured to enable self-registration using person accounts?

Choose 3 answers

Options:
A.

Enable business accounts in the Setup page.

B.

Enable person accounts in the Setup page.

C.

Under Login and Registration settings, ensure that the default account field is empty.

D.

Enable access to person and business account record types under Public Access Settings.

E.

Set organization-wide default sharing for Contact to Public Read Only.

Questions 23

Northern Trail Outfitters (NTO) has an existing business-to-consumer (B2C) website that does NOT support single sign-on standards, such as Security Assertion Markup Language (SAML) or OAuth. NTO wants to use Salesforce Identity to register and authenticate new customers on the website.

Which three Salesforce features should an Identity architect use in order to provide social sign-in capabilities for the website?

Choose 3 answers

Options:
A.

Connected Apps

B.

Authentication Providers

C.

Delegated Authentication

D.

Embedded Login

E.

Identity Connect

Questions 24

The executive sponsor for an organization has asked if Salesforce supports the ability to embed a login widget into its service providers in order to create a more seamless user experience.

What should be used and considered before recommending it as a solution on the Salesforce Platform?

Options:
A.

Embedded Login. Identify what level of UI customization will be required to make it match the service providers look and feel.

B.

Salesforce REST APIs. Ensure that Secure Sockets Layer (SSL) connection for the integration is used.

C.

OpenID Connect Web Server Flow. Determine if the service provider is secure enough to store the client secret on.

D.

Embedded Login. Consider whether or not it relies on third party cookies which can cause browser compatibility issues.

Questions 25

A multinational company using the Salesforce platform wants to implement robust user activity verification capabilities to detect unauthorized access and unusual login patterns.

They need real-time monitoring and alerting functionalities to respond promptly to security incidents.

Which Salesforce tool should be utilized to achieve these requirements?

Options:
A.

Salesforce Event Monitoring and Event Log Files

B.

Salesforce Profiles

C.

Salesforce Platform Encryption

D.

Salesforce Data Loader

Questions 26

A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APAC. The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS. The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.

What is recommended to ensure these requirements are met?

Options:
A.

Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.

B.

Configure Each ADFS system under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce.

C.

Add a central identity system that facilitates between the ADFS systems and integrate with Salesforce for single sign-on.

D.

Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.

Questions 27

An Enterprise is using a Lightweight Directory Access Protocol (LDAP) server as the only point for user authentication with a username/password. Salesforce leverages delegated authentication to integrate with the LDAP.

How can end users change their password?

Options:
A.

Users can change it on the enterprise LDAP authentication portal.

B.

Users can click on the " Forgot your Password " link on the Salesforce.com login page.

C.

Users can request the Salesforce Admin to reset their password.

D.

Users once logged in, can go to the Change Password screen in Salesforce.

Questions 28

A consumer products company uses Salesforce to maintain consumer information, including orders. The company implemented a portal solution using Salesforce Experience Cloud for its consumers where the consumers can log in using their credentials. The company is considering allowing users to login with their Facebook or LinkedIn credentials.

Once enabled, what role will Salesforce play?

Options:
A.

Facebook and LinkedIn will be this SPs.

B.

Facebook and LinkedIn will act as the LIPS and SPs.

C.

Salesforce will be the service provider (SP).

D.

Salesforce will be the identity provider (LIP).

Questions 29

Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for NTO to give its customers the ability to login with their Amazon credentials.

What should an identity architect recommend to meet these requirements?

Options:
A.

Create a custom external authentication provider for Amazon.

B.

Configure Amazon as & connected app.

C.

Configure an OpenlD Connect Authentication Provider for Amazon.

D.

Configure a predefined authentication provider for Amazon.

Questions 30

A division of a Northern Trail Outfitters (NTO) purchased Salesforce. NTO uses a third party identity provider (IdP) to validate user credentials against its corporate Lightweight.

Directory Access Protocol (LDAP) directory. NTO wants to help employees remember as few passwords as possible.

What should an identity architect recommend?

Options:
A.

Use Salesforce connect to synchronize LDAP passwords to Salesforce.

B.

Setup Salesforce as an Authentication Provider to the existing IdR.

C.

Setup Salesforce as an IdP to authenticate against the LDAP directory.

D.

Setup Salesforce as a Service Provider to the existing IdP.

Certification Provider: Salesforce
Exam Name: Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
Last Update: Apr 7, 2026
Questions: 109