Salesforce Plat-Arch-203 Exam Overview:
| Certification Vendor: | Salesforce |
| Exam Name: | Salesforce Certified Platform Identity and Access Management Architect |
| Exam Number: | Plat-Arch-203 |
| Certificate Validity Period: | 2 years |
| Exam Duration: | 105 - 120 |
| Related Certifications: | Salesforce Certified System Architect Salesforce Certified Application Architect |
| Exam Format: | Multiple-choice, Multiple-select, Scenario-based |
| Available Languages: | English, Japanese |
| Passing Score: | 67% |
| Exam Price: | $400 USD (initial), $200 USD (retake) |
| Real Exam Qty: | 60 - 65 |
| Recommended Training: | Architect Journey: Identity and Access Management |
| Exam Registration: | Salesforce Certification Registration |
| Sample Questions: | Salesforce Plat-Arch-203 Sample Questions |
| Exam Way: | Online proctored or onsite at Kryterion/Pearson VUE test centers |
| Pre Condition: | No mandatory prerequisites; recommended: 2–3 years of IAM experience on Salesforce, familiarity with SAML/OAuth/OIDC, and prior architect certifications |
| Official Syllabus URL: | https://trailhead.salesforce.com/credentials/identityandaccessmanagementarchitect |
Salesforce Plat-Arch-203 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Accepting Third-Party Identity in Salesforce | 26% | - SAML SSO configuration and troubleshooting
- Authentication providers and social login |
| Salesforce Identity | 12% | - License type selection for identity use cases - Identity Connect implementation - Customer 360 Identity integration |
| Access Management Best Practices | 15% | - Field-level and object-level security - Role hierarchy and sharing rules - Multi-factor authentication and session management - Profiles, permission sets and groups |
| Identity Management Concepts | 17% | - Authentication patterns and selection
|
| Salesforce as an Identity Provider | 19% | - SCIM and user provisioning to external systems - Connected Apps and OAuth flows
|
| Community (Partner and Customer) Identity | 18% | - External identity provider integration for communities - Experience Cloud authentication and verification - Self-registration and password reset |
Salesforce Certified Platform Identity and Access Management Architect Sample Questions:
1. A multinational company is looking to rollout Salesforce globally. The company has a Microsoft Active Directory Federation Services (ADFS) implementation for the Americas, Europe and APAC. The company plans to have a single org and they would like to have all of its users access Salesforce using the ADFS . The company would like to limit its investments and prefer not to procure additional applications to satisfy the requirements.
What is recommended to ensure these requirements are met ?
A) Use connected apps for each ADFS implementation and implement Salesforce site to authenticate users across the ADFS system applicable to their geo.
B) Implement Identity Connect to provide single sign-on to Salesforce and federated across multiple ADFS systems.
C) Add a central identity system that federates between the ADFS systems and integrate with Salesforce for single sign-on.
D) Configure Each ADFS system under single sign-on settings and allow users to choose the system to authenticate during sign on to Salesforce-
2. Universal containers(UC) wants to integrate a third-party reward calculation system with salesforce to calculate rewards. Rewards will be calculated on a schedule basis and update back into salesforce. The integration between Salesforce and the reward calculation system needs to be secure. Which are the recommended best practices for using Oauth flows in this scenario? Choose 2 answers
A) Oauth refresh token flow
B) Oauth Username-password flow
C) Oauthjwt bearer token flow
D) Oauth SAML bearer assertion flow
3. Universal Containers (UC) is both a Salesforce and Google Apps customer. The UC IT team would like to manage the users for both systems in a single place to reduce administrative burden. Which two optimal ways can the IT team provision users and allow Single Sign-on between Salesforce and Google Apps ? Choose 2 answers
A) Use Identity Connect as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
B) Use a third-party product as the Identity Provider for both Salesforce and Google Apps and manage the provisioning from there.
C) Build a custom app running on Heroku as the Identity Provider that can sync user information between Salesforce and Google Apps.
D) Use Salesforce as the Identity Provider and Google Apps as a Service Provider and configure User Provisioning for Connected Apps.
4. Universal Containers (UC) implemented SSO to a third-party system for their Salesforce users to access the App Launcher. UC enabled "User Provisioning" on the Connected App so that changes to user accounts can be synched between Salesforce and the third party system. However, UC quickly notices that changes to user roles in Salesforce are not getting synched to the third-party system. What is the most likely reason for this behaviour?
A) The Approval queue for User Provisioning Requests is unmonitored.
B) Required operation(s) was not mapped in User Provisioning Settings.
C) User Provisioning for Connected Apps does not support role sync.
D) Salesforce roles have more than three levels in the role hierarchy.
5. universal container plans to develop a custom mobile app for the sales team that will use salesforce for authentication and access management. The mobile app access needs to be restricted to only the sales team. What would be the recommended solution to grant mobile app access to sales users?
A) Add a new identity provider to authenticate and authorize mobile users.
B) Use a custom attribute on the user object to control access to the mobile app
C) Use the permission set license to assign the mobile app permission to sales users
D) Use connected apps Oauth policies to restrict mobile app access to authorized users.
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: C,D | Question # 3 Answer: B,D | Question # 4 Answer: C | Question # 5 Answer: D |

We're so confident of our products that we provide no hassle product exchange.


By Tammy


