ExamDumpster

Free Plat-Arch-203 sample questions

Real questions from the Salesforce Certified Platform Identity and Access Management Architect practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 6 of 12 free sample questions.

Question 1Choose one

A multinational financial services firm uses Active Directory Federation Services (ADFS) as their Identity Provider (IdP) and Salesforce as a Service Provider (SP). Users in the 'APAC' region are reporting intermittent login failures when accessing Salesforce via SSO. The Identity Architect reviews the SAML assertions and notices the `NotBefore` and `NotOnOrAfter` timestamps are causing validation errors due to a slight time drift between the ADFS server in Singapore and the Salesforce servers. Which configuration change in Salesforce should the Architect recommend to resolve this issue without compromising security?

Question 2Choose one

An architect is designing a server-to-server integration where an external middleware system needs to update Salesforce records nightly without user interaction. The security team requires that no shared secrets (passwords) be transmitted during the authentication handshake and that the session should be valid for only a short duration. Which OAuth flow is the optimal choice for this scenario?

Question 3Choose one

A global manufacturing company uses Identity Connect to provision users from Microsoft Active Directory (AD) to Salesforce. They have a requirement to assign users to specific Permission Set Groups in Salesforce based on their AD 'Department' attribute. The AD team has created three groups: 'Sales', 'Service', and 'Marketing'. How should the Identity Architect configure Identity Connect to meet this requirement?

Question 4Choose 2

Which TWO statements accurately describe the behavior of the 'High Assurance' session security level in Salesforce? (Select TWO)

Question 5Choose one

A developer is building a custom mobile application for a partner community. The app needs to authenticate users via Salesforce using OpenID Connect. The partner users should be able to log in using their LinkedIn credentials, which are already configured as an Auth Provider in Salesforce. Which specific parameter must be included in the authorization request to the Salesforce OAuth 2.0 endpoint to direct the user specifically to the LinkedIn login page, bypassing the standard Salesforce username/password screen?

Question 6Choose one

True or False: When configuring a Connected App for an external web application to use Salesforce as an Identity Provider, enabling 'High Assurance' in the Connected App's Session Policies will automatically force the user to complete Multi-Factor Authentication every time they access the external application, regardless of their current Salesforce session state.

6 more free samples are waiting

Create a free account to unlock the whole Plat-Arch-203 sample bank, or get full access to all 160 practice questions in the simulator.

Create account