Salesforce Plat-Arch-203 Exam Overview:
| Certification Vendor: | Salesforce |
| Exam Name: | Salesforce Certified Platform Identity and Access Management Architect Exam |
| Exam Number: | Plat-Arch-203 |
| Exam Price: | USD 200 |
| Related Certifications: | Salesforce Certified Identity and Access Management Designer Salesforce Certified Application Architect Salesforce Certified System Architect |
| Passing Score: | Approximately 65% (subject to change by Salesforce) |
| Real Exam Qty: | 60-65 |
| Exam Duration: | 120 minutes |
| Certificate Validity Period: | Maintenance required; typically requires periodic certification maintenance via Salesforce release exams (no fixed expiration if maintained) |
| Available Languages: | English |
| Exam Format: | Multiple Choice, Multiple Select |
| Recommended Training: | Trailhead Identity Basics Modules Identity and Access Management Architect Trailmix |
| Exam Registration: | Salesforce Certification Registration Salesforce Credential Exam Guide |
| Sample Questions: | Salesforce Plat-Arch-203 Sample Questions |
| Exam Way: | Online proctored or authorized test center |
| Pre Condition: | Recommended: Salesforce Certified Identity and Access Management Designer plus architect-level Salesforce experience |
| Official Syllabus URL: | https://trailhead.salesforce.com/credentials/architect |
Salesforce Plat-Arch-203 Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Salesforce Identity Services | - My Domain and identity configuration - Connected Apps and OAuth policies - Identity Connect and external identity providers |
| Topic 2: Access Management and Security Controls | - Profiles, permission sets, and role hierarchy - Multi-factor authentication (MFA) enforcement - Session management and security policies |
| Topic 3: Experience Cloud and External Identity | - B2B and B2C identity considerations - External user authentication and authorization - Community login and identity providers |
| Topic 4: Authentication and Single Sign-On (SSO) | - OpenID Connect and OAuth 2.0 flows - SSO troubleshooting and configuration - SAML 2.0 implementation in Salesforce |
| Topic 5: API and Integration Security | - Secure integration patterns - OAuth scopes and API authentication flows - Token management and refresh mechanisms |
| Topic 6: Identity and Access Management Fundamentals | - Enterprise identity architecture basics - Identity lifecycle management concepts - Authentication vs authorization principles |
Salesforce Certified Platform Identity and Access Management Architect Sample Questions:
1. Universal Containers (UC) wants to integrate a third-party Reward Calculation system with Salesforce to calculate Rewards. Rewards will be calculated on a schedule basis and update back into Salesforce. The integration between Salesforce and the Reward Calculation System needs to be secure. Which are two recommended practices for using OAuth flow in this scenario. choose 2 answers
A) OAuth Refresh Token FLow
B) OAuth SAML Bearer Assertion FLow
C) OAuth JWT Bearer Token FLow
D) OAuth Username-Password Flow
2. A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APAC. The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS . The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.
What is recommended to ensure these requirements are met ?
A) Configure Each ADFS system under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce-
B) Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.
C) Add a central identity system that federates between the ADFS systems and integrate with Salesforce for single sign-on.
D) Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.
3. Which three different attributes can be used to identify the user in a SAML 65> assertion when Salesforce is acting as a Service Provider? Choose 3 answers
A) Federation ID
B) User Email Address
C) User Full Name
D) Salesforce Username
E) Salesforce User ID
4. Universal Containers (UC) uses Active Directory (AD) as their identity store for employees and must continue to do so for network access. UC is undergoing a major transformation program and moving all of their enterprise applications to cloud platforms including Salesforct, Workday, and SAP HANA. UC needs to implement an SSO solution for accessing all of the third-party cloud applications and the CIO is inclined to use Salesforce for all of their identity and access management needs.
A) Identity and Identity Connect licenses
B) Company Community and Identity licenses
C) Chatter Only and Identity licenses
D) Salesforce and Identity Connect licenses
5. How should an Architect force users to authenticate with Two-factor Authentication (2FA) for Salesforce only when not connected to an internal company network?
A) Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA if needed.
B) Add the list of company's network IP addresses to the Login Range list under 2FA Setup.
C) Apply the "Two-factor Authentication for User Interface Logins" permission and Login IP Ranges for all Profiles.
D) Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.
Solutions:
| Question # 1 Answer: B,C | Question # 2 Answer: D | Question # 3 Answer: A,B,C | Question # 4 Answer: A,D | Question # 5 Answer: A |


PDF Version Demo






We are confident about the products and aim to help you pass with ease. In case of failure, we will provide a no hassle full money back guarantee for the purchasing fee.
1172 Customer Reviews
Quality and ValueITbraindumps Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITbraindumps testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITbraindumps offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.