Pre-Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: get65

Salesforce Updated Identity-and-Access-Management-Architect Exam Questions and Answers by mikey

Page: 2 / 7

Salesforce Identity-and-Access-Management-Architect Exam Overview :

Exam Name: Salesforce Certified Platform Identity and Access Management Architect (Plat-Arch-203)
Exam Code: Identity-and-Access-Management-Architect Dumps
Vendor: Salesforce Certification: Identity and Access Management Designer
Questions: 109 Q&A's Shared By: mikey
Question 8

Northern Trail Outfitters (NTO) utilizes a third-party cloud solution for an employee portal. NTO also owns Salesforce Service Cloud and would like employees to be able to login to Salesforce with their third-party portal credentials for a seamless experience. The third-party employee portal only supports OAuth.

What should an Identity architect recommend to enable single sign-on (SSO) between the portal and Salesforce?

Options:

A.

Add the third-party portal as a connected app.

B.

Configure Salesforce for Delegated Authentication.

C.

Create a custom external authentication provider.

D.

Configure SSO with OpenlD Connect and leverage the third party portal as an identity provider.

Discussion
Question 9

Universal Containers allows employees to use a mobile device to access Salesforce for daily operations using a hybrid mobile app. This app uses Mobile software development kits (SDK), leverages refresh token to regenerate access token when required and is distributed as a private app.

The chief security officer is rolling out an org wide compliance policy to enforce re verification of devices if an employee has not logged in from that device in the last week.

Which connected app setting should be leveraged to comply with this policy change?

Options:

A.

Scope - Deny refresh_token scope for this connected app.

B.

Permitted User - Ask admins to maintain a list of users who are permitted based on last login date.

C.

Session Policy - Set timeout value of the connected app to 7 days.

D.

Refresh Token Policy - Expire the refresh token if it has not been used for 7 days.

Discussion
Ivan
I tried these dumps for my recent certification exam and I found it pretty helpful.
Elis Mar 14, 2026
Agree!!! The questions in the dumps were quite similar to what came up in the actual exam. It gave me a good idea of the types of questions to expect and helped me revise efficiently.
Marley
Hey, I heard the good news. I passed the certification exam!
Jaxson Mar 25, 2026
Yes, I passed too! And I have to say, I couldn't have done it without Cramkey Dumps.
Atlas
What are these Dumps? Would anybody please explain it to me.
Reign Mar 21, 2026
These are exam dumps for a variety of IT certifications. They have a vast collection of updated questions and answers, which are very helpful in preparing for the exams.
Syeda
I passed, Thank you Cramkey for your precious Dumps.
Stella Mar 17, 2026
That's great. I think I'll give Cramkey Dumps a try.
Robin
Cramkey is highly recommended.
Jonah Mar 22, 2026
Definitely. If you're looking for a reliable and effective study resource, look no further than Cramkey Dumps. They're simply wonderful!
Question 10

A financial enterprise is planning to set up a user authentication mechanism to login to the Salesforce system. Due to regulatory requirements, the CIO of the company wants user administration, including passwords and authentication requests, to be managed by an external system that is only accessible via a SOAP webservice.

Which authentication mechanism should an identity architect recommend to meet the requirements?

Options:

A.

Just-in-Time Provisioning

B.

Delegated Authentication

C.

Security Assertion Markup Language (SANL) Single Sign On

D.

OAuth Web-Server Flow

Discussion
Question 11

Users logging into Salesforce are frequently prompted to verify their identity.

The identity architect is required to provide recommendations so that frequency of prompt verification can be reduced.

What should the identity architect recommend to meet the requirement?

Options:

A.

Implement an single sign-on for Salesforce using an external identity provider.

B.

Set trusted IP ranges for the organization.

C.

Implement 2FA authentication for the Salesforce org.

D.

Implement multi-factor authentication for the Salesforce org.

Discussion
Page: 2 / 7

Identity-and-Access-Management-Architect
PDF

$36.75  $104.99

Identity-and-Access-Management-Architect Testing Engine

$43.75  $124.99

Identity-and-Access-Management-Architect PDF + Testing Engine

$57.75  $164.99