Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

Identity-and-Access-Management-Architect Exam Dumps - Salesforce Identity and Access Management Designer Questions and Answers

Question # 4

Universal Container’s (UC) is using Salesforce Experience Cloud site for its container wholesale business. The identity architect wants to use an authentication provider for the new site.

Which two options should be utilized in creating an authentication provider?

Choose 2 answers

Options:

A.

The default login user can be set.

B.

A custom error URL can be set.

C.

The default authentication provider certificate can be set.

D.

A custom registration handler can be set.

Buy Now
Question # 5

Northern Trail Outfitters (NTO) has an existing business-to-consumer (B2C) website that does NOT support single sign-on standards, such as Security Assertion Markup Language (SAML) or OAuth. NTO wants to use Salesforce Identity to register and authenticate new customers on the website.

Which three Salesforce features should an Identity architect use in order to provide social sign-in capabilities for the website?

Choose 3 answers

Options:

A.

Connected Apps

B.

Authentication Providers

C.

Delegated Authentication

D.

Embedded Login

E.

Identity Connect

Buy Now
Question # 6

Northern Trail Outfitters (NTO) has a number of employees who do NOT need access Salesforce objects. The employees should sign in to a custom Benefits web app using their Salesforce credentials.

Which license should the identity architect recommend to fulfill this requirement?

Options:

A.

Identify Only License

B.

Identify Verification Credits Add-On License

C.

External Identity License

D.

Identify Connect License

Buy Now
Question # 7

Universal Containers (UC) uses Salesforce as a CRM and identity provider (IdP) for their Sales Team to seamlessly login to internal portals.

The IT team at UC is now evaluating Salesforce to act as an IdP for its remaining employees.

Which Salesforce license is required to full fill this requirement?

Options:

A.

Identify Verification

B.

Identify Connect

C.

Identify Only

D.

External Identity

Buy Now
Question # 8

Universal Containers has multiple Salesforce instances where users receive emails from different instances. Users should be logged into the correct Salesforce instance authenticated by their IdP when clicking on an email link to a Salesforce record.

What should be enabled in Salesforce as a prerequisite?

Options:

A.

External Identity

B.

My Domain

C.

Multi-Factor Authentication

D.

Identity Provider

Buy Now
Question # 9

Universal Containers (UC) has an Experience Cloud site (Customer Community) where customers can authenticate and place orders, view the status of orders, etc. UC allows guest checkout.

How can a guest register using data previously collected during order placement?

Options:

A.

Enable self-registration and customize a self-registration page to collect only order details to retrieve customer data.

B.

Enable Security Assertion Markup Language (SAML) Sign-On and use a login flow to collect only order details to retrieve customer data.

C.

Enable Facebook as an authentication provider and use a registration handler to collect only order details to retrieve customer data.

D.

Use a Connected App Handler. Apex Plugin class to collect only order details to retrieve customer data.

Buy Now
Question # 10

An administrator created a connected app for a custom web application in Salesforce which needs to be visible as a tile in App Launcher. The tile for the custom web application is missing in the app launcher for all users in Salesforce. The administrator requested assistance from an identity architect to resolve the issue.

Which two reasons are the source of the issue?

Choose 2 answers

Options:

A.

Session Policy is set as “High Assurance Session required” for this connected app.

B.

The connected app is not set in the App menu as “Visible in App Launcher”.

C.

Statutes, for the connected app is not set in Connected App settings.

D.

Obtain scope does not include “openid”.

Buy Now
Question # 11

An Enterprise is using a Lightweight Directory Access Protocol (LDAP) server as the only point for user authentication with a username/password. Salesforce leverages delegated authentication to integrate with the LDAP.

How can end users change their password?

Options:

A.

Users can change it on the enterprise LDAP authentication portal.

B.

Users can click on the " Forgot your Password " link on the Salesforce.com login page.

C.

Users can request the Salesforce Admin to reset their password.

D.

Users once logged in, can go to the Change Password screen in Salesforce.

Buy Now
Question # 12

Universal Containers is creating a web application that will be secured by Salesforce Identity using the OAuth 2.0 Web Server Flow (this flow uses the OAuth 2.0 authorization code grant type).

Which three OAuth concepts apply to this flow?

Choose 3 answers

Options:

A.

Verification URL

B.

Authentication Token

C.

Scopes

D.

Access Token

E.

Client Secret

Buy Now
Question # 13

Which two things should be done to ensure end users can only use single sign-on (SSO) to login in to Salesforce?

Choose 2 answers

Options:

A.

Enable My Domain and select " Prevent login from https://login.salesforce.com " .

B.

Request Salesforce Support to enable delegated authentication.

C.

Once SSO is enabled, users are only able to login using Salesforce credentials.

D.

Assign user " Is Single Sign-On Enabled " permission via profile or permission set.

Buy Now
Exam Name: Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
Last Update: May 22, 2026
Questions: 109
Identity-and-Access-Management-Architect pdf

Identity-and-Access-Management-Architect PDF

$25.5  $84.99
Identity-and-Access-Management-Architect Engine

Identity-and-Access-Management-Architect Testing Engine

$28.5  $94.99
Identity-and-Access-Management-Architect PDF + Engine

Identity-and-Access-Management-Architect PDF + Testing Engine

$40.5  $134.99