Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

Identity-and-Access-Management-Architect Exam Dumps - Salesforce Identity and Access Management Designer Questions and Answers

Question # 14

Universal Containers uses Salesforce as an identity provider and Concur as the Employee Expense management system. The HR director wants to ensure Concur accounts for employees are created only after the appropriate approval in the Salesforce org.

Which three steps should the identity architect use to implement this requirement.

Choose 3 answers

Options:

A.

Create an approval process for a custom object associated with the provisioning flow.

B.

Create an approval process for UserProvisioningReguest object associated with the provisioning flow.

C.

Create a connected app for Concur in Salesforce.

D.

Enable User Provisioning for the connected app.

E.

Create an approval process for User object associated with the provisioning flow.

Buy Now
Question # 15

A company with 15,000 employees is using Salesforce and would like to take the necessary steps to highlight or curb fraudulent activity.

Which tool should be used to track login data, such as the average number of logins, who logged in more than the average number of times and who logged in during non-business hours?

Options:

A.

Login Inspector

B.

Login Forensics

C.

Login Report

D.

Login History

Buy Now
Question # 16

Northern Trail Outfitters (NTO) is planning to implement a community for its customers

using Salesforce Experience Cloud. Customers are not able to self-register. NTO would like to have customers set their own passwords when provided access to the community.

Which two recommendations should an identity architect make to fulfill this requirement?

Choose 2 answers

Options:

A.

Enable Welcome emails while configuring the Experience Cloud site.

B.

Use Login Flows to allow users to reset password in Experience Cloud site.

C.

Allow Password reset using the API to update Experience Cloud site membership.

D.

Add customers as contacts and add them to Experience Cloud site.

Buy Now
Question # 17

A global fitness equipment manufacturer uses Salesforce to manage its sales cycle. The manufacturer has a custom order fulfillment app that needs to request order data from

Salesforce. The order fulfillment app needs to integrate with the Salesforce API using OAuth 2.0 protocol.

What should an identity architect use to fulfill this requirement?

Options:

A.

OAuth Token

B.

Genre Age Integration

C.

Authentication Providers

D.

Connected App and OAuth Scopes

Buy Now
Question # 18

An insurance company has a connected app in its Salesforce environment that is used to integrate with a Google Workspace (formerly known as G Suite).

An identity and access management (ZAM) architect has been asked to implement automation to enable users, freeze/suspend users, disable users, and reactivate existing users in Google Workspace upon similar actions in Salesforce.

Which solution is recommended to meet this requirement?

Options:

A.

Build a custom REST endpoint in Salesforce that Google Workspace can pull against.

B.

Build an Asset Trigger on the UserLogin object to make asynchronous callouts to Google APIs.

C.

configure Users Provisioning for Connected Apps.

D.

Update the Security Attention Hadoop Language Just-In-Time (SJAR, LTT) handler in Salesforce for user provisioning and de-provisioning.

Buy Now
Question # 19

Northern Trail Outfitters (NTO) is launching a new sportswear brand on its existing consumer portal built on Salesforce Experience Cloud. As part of the launch, emails with promotional links will be sent to existing customers to log in and claim a discount. The marketing manager would like the portal dynamically branded so that users will be directed to the brand link they clicked on; otherwise, users will view a recognizable NTO-branded page.

The campaign is launching quickly, so there is no time to procure any additional licenses.

However, the development team is available to apply any required changes to the portal.

Which approach should the identity architect recommend?

Options:

A.

Create a full audience to replicate the portal and set up these the branding accordingly.

B.

Use tutorials to build the new brand site and embedded login for some identities.

C.

Configure an additional community site on the same way that is dedicated for the new brand.

D.

Implement Experiences ID in the code and extend the URLs and endpoints, as required.

Buy Now
Question # 20

Universal Containers is creating a mobile application that will be secured by Salesforce Identity using the QAuth 2.0 user-agent flow (this flow uses the QAuth 2.0 implicit grant type).

Which three QAuth concepts apply to this flow?

Choose 3 answers

Options:

A.

Refresh Token

B.

Client ID

C.

Verification Code

D.

Authorization Code

E.

Scopus

Buy Now
Question # 21

A farming enterprise offers smart farming technology to its farmer customers, which includes a variety of sensors for livestock tracking, pest monitoring, climate monitoring etc.

They plan to store all the data in Salesforce. They would also like to ensure timely maintenance of the installed sensors. They have engaged a Salesforce Architect to propose an appropriate way to send an alert when something goes wrong.

Which OAuth flow should the architect recommend?

Options:

A.

OAuth 2.0 SAML Bearer Assertion Flow

B.

OAuth 2.0 Device Authentication Flow

C.

OAuth 2.0 Asset Token Flow

D.

OAuth 2.0 JWT Bearer Token Flow

Buy Now
Question # 22

Northern Trail Outfitters (NTO) recently purchased Salesforce Identity Connect to streamline user provisioning across Microsoft Active Directory (AD) and Salesforce Sales Cloud.

NTO has asked an identity architect to identify which Salesforce security configurations can map to AD permissions.

Which three Salesforce permissions are available to map to AD permissions?

Choose 3 answers

Options:

A.

Sharing Rules

B.

Public Groups

C.

Permission Set License

D.

Roles

E.

Profiles and Permission Sets

Buy Now
Question # 23

A global company ' s Salesforce Identity Architect is reviewing its Salesforce production org login history and is seeing some intermittent Security Assertion Markup Language (SAML SSO) " Replay Detected " and " Assertion Invalid " login errors.

Which two issues would cause these errors?

Choose 2 answers

Options:

A.

The certificate loaded into SSO configuration does not match the certificate used by the IdP.

B.

The subject element is missing from the assertion sent to Salesforce.

C.

The current time setting of the company ' s identity provider (IdP) and Salesforce platform

is out of sync by more than eight minutes.

D.

The assertion sent to Salesforce contains an assertion ID previously used.

Buy Now
Exam Name: Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
Last Update: May 22, 2026
Questions: 109
Identity-and-Access-Management-Architect pdf

Identity-and-Access-Management-Architect PDF

$25.5  $84.99
Identity-and-Access-Management-Architect Engine

Identity-and-Access-Management-Architect Testing Engine

$28.5  $94.99
Identity-and-Access-Management-Architect PDF + Engine

Identity-and-Access-Management-Architect PDF + Testing Engine

$40.5  $134.99