
Updated Jul-2026 Exam Engine for Plat-Arch-203 Exam Free Demo & 365 Day Updates
Exam Passing Guarantee Plat-Arch-203 Exam with Accurate Quastions!
NEW QUESTION # 130
Universal Containers (UC) has decided to use Salesforce as an Identity Provider for multiple external applications. UC wants to use the salesforce App Launcher to control the Apps that are available to individual users. Which three steps are required to make this happen?
- A. Set up Salesforce as a SAML Idp with My Domain.
- B. Set up Identity Connect to Synchronize user data.
- C. Add each connected App to the App Launcher with a Start URL.
- D. Create a Connected App for each external application.
- E. Set up an Auth Provider for each External Application.
Answer: A,C,D
NEW QUESTION # 131
Containers (UC) has implemented SAML-based single Sign-on for their Salesforce application and is planning to provide access to Salesforce on mobile devices using the Salesforce1 mobile app. UC wants to ensure that Single Sign-on is used for accessing the Salesforce1 mobile App. Which two recommendations should the Architect make? Choose 2 Answers
- A. Use the existing SAML-SSO flow along with User Agent Flow.
- B. Configure the Salesforce1 App to use the MY Domain URL.
- C. Configure the Embedded Web Browser to use My Domain URL.
- D. Use the existing SAML SSO flow along with Web Server Flow.
Answer: A,B
NEW QUESTION # 132
Northern Trail Outfitters (NTO) has an existing custom business-to-consumer (B2C) website that does NOT support single sign-on standards, such as Security Assertion Markup Language (SAMi) or OAuth. NTO wants to use Salesforce Identity to register and authenticate new customers on the website.
Which two Salesforce features should an identity architect use in order to provide username/password authentication for the website?
Choose 2 answers
- A. Identity Connect
- B. Delegated Authentication
- C. Connected Apps
- D. Embedded Login
Answer: B,D
NEW QUESTION # 133
Universal Containers (UC) uses Active Directory (AD) as their identity store for employees and must continue to do so for network access. UC is undergoing a major transformation program and moving all of their enterprise applications to cloud platforms including Salesforct, Workday, and SAP HANA. UC needs to implement an SSO solution for accessing all of the third-party cloud applications and the CIO is inclined to use Salesforce for all of their identity and access management needs.
- A. Identity and Identity Connect licenses
- B. Salesforce and Identity Connect licenses
- C. Chatter Only and Identity licenses
- D. Company Community and Identity licenses
Answer: A,B
NEW QUESTION # 134
Universal Containers (UC) is looking to purchase a third-party application as an Identity Provider. UC is looking to develop a business case for the purchase in general and has enlisted an Architect for advice. Which two capabilities of an Identity Provider should the Architect detail to help strengthen the business case? Choose 2 answers
- A. The Identity Provider can authenticate multiple social media accounts.
- B. The Identity provider can store credentials for multiple applications.
- C. The Identity Provider can centralize enterprise password policy.
- D. The Identity Provider can authenticate multiple applications.
Answer: C,D
NEW QUESTION # 135
Universal Containers (UC) has an Experience Cloud site (Customer Community) where customers can authenticate and place orders, view the status of orders, etc. UC allows guest checkout.
Mow can a guest register using data previously collected during order placement?
- A. Use a Connected App Handler Apex Plugin class to collect only order details to retrieve customer data.
- B. Enable self-registration and customize a self-registration page to collect only order details to retrieve customer data.
- C. Enable Facebook as an authentication provider and use a registration handler to collect only order details to retrieve customer data.
- D. Enable Security Assertion Markup Language Sign-On and use a login flow to collect only order details to retrieve customer data.
Answer: B
NEW QUESTION # 136
Universal containers (UC) has implemented a multi-org strategy and would like to centralize the management of their salesforce user profiles. What should the architect recommend to allow salesforce profiles to be managed from a central system of record?
- A. Implement Delegated Authentication that will update the user profiles as necessary.
- B. Create an apex scheduled job in one org that will synchronize the other orgs profile.
- C. Implement an Oauthjwt flow to pass the profile credentials between systems.
- D. Implement jit provisioning on the SAML IDP that will pass the profile id in each assertion.
Answer: D
NEW QUESTION # 137
Universal Containers (UC) is planning to add Wi-Fi enabled GPS tracking devices to its shipping containers so that the GPS coordinates data can be sent from the tracking device to its Salesforce production org via a custom API. The GPS devices have no direct user input or output capabilities.
Which OAuth flow should the identity architect recommend to meet the requirement?
- A. OAuth 2.0 Asset Token Flow for Securing Connected Devices
- B. OAuth 2.0 Web Server Flow for Web App Integration
- C. OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration
- D. OAuth 2.0 Username-Password Flow for Special Scenarios
Answer: A
NEW QUESTION # 138
In an SP-Initiated SAML SSO setup where the user tries to access a resource on the Service Provider, What HTTP param should be used when submitting a SAML Request to the Idp to ensure the user is returned to the intended resourse after authentication?
- A. DisplayState
- B. RelayState
- C. StartURL
- D. RedirectURL
Answer: B
NEW QUESTION # 139
A web service is developed that allows secure access to customer order status on the Salesforce Platform. The service connects to Salesforce through a connected app with the web server flow. The following are the required actions for the authorization flow:
1. User Authenticates and Authorizes Access
2. Request an Access Token
3. Salesforce Grants an Access Token
4. Request an Authorization Code
5. Salesforce Grants Authorization Code
What is the correct sequence for the authorization flow?
- A. 2, 1, 3, 4, 5
- B. 4, 1, 5, 2, 3
- C. 4,5,2, 3, 1
- D. 1, 4, 5, 2, 3
Answer: C
NEW QUESTION # 140
Northern Trail Outfitters (NTO) uses the Customer 360 Platform implemented on Salesforce Experience Cloud. The development team in charge has learned of a contactless user feature, which can reduce the overhead of managing customers and partners by creating users without contact information.
What is the potential impact to the architecture if NTO decides to implement this feature?
- A. Contactless user feature is available only with the External Identity license, which can restrict the Experience Cloud functionality available to the user.
- B. Passwordless authentication can not be supported because the mobile phone receiving one-time password (OTP) needs to match the number on the contact record.
- C. Custom registration handler is needed to correctly assign External Identity or Community license for the newly registered contactless user.
- D. If contactless user is upgraded to Community license, the contact record is automatically created and linked to the user record, but not associated with an Account.
Answer: A
NEW QUESTION # 141
Universal Containers (UC) would like its community users to be able to register and log in with Linkedin or Facebook Credentials. UC wants users to clearly see Facebook &Linkedin Icons when they register and login. What are the two recommended actions UC can take to achieve this Functionality? Choose 2 answers
- A. Enable Facebook and Linkedin as Login options in the login section of the Community configuration.
- B. Store the Linkedin or Facebook user IDs in the Federation ID field on the Salesforce User record.
- C. Create custom buttons for Facebook and inkedin using JAVAscript/CSS on a custom Visualforce page.
- D. Create custom Registration Handlers to link Linkedin and facebook accounts to user records.
Answer: A,D
NEW QUESTION # 142
Northern Trail Outfitters (NTO) wants to give customers the ability to submit and manage issues with their purchases. It is important for to give its customers the ability to login with their Facebook and Twitter credentials.
Which two actions should an identity architect recommend to meet these requirements?
Choose 2 answers
- A. Configure a predefined authentication provider for Twitter.
- B. Create a custom external authentication provider for Facebook.
- C. Configure a predefined authentication provider for Facebook.
- D. Create a custom external authentication provider for Twitter.
Answer: A,C
NEW QUESTION # 143
Universal Containers (UC) built an integration for their employees to post, view, and vote for ideas in Salesforce from an internal Company portal. When ideas are posted in Salesforce, links to the ideas are created in the company portal pages as part of the integration process. The Company portal connects to Salesforce using OAuth. Everything is working fine, except when users click on links to existing ideas, they are always taken to the Ideas home page rather than the specific idea, after authorization. Which OAuth URL parameter can be used to retain the original requested page so that a user can be redirected correctly after OAuth authorization?
- A. State
- B. Redirect_uri
- C. Callback_uri
- D. Scope
Answer: B
NEW QUESTION # 144
An insurance company has a connected app in its Salesforce environment that is used to integrate with a Google Workspace (formerly knot as G Suite).
An identity and access management (IAM) architect has been asked to implement automation to enable users, freeze/suspend users, disable users, and reactivate existing users in Google Workspace upon similar actions in Salesforce.
Which solution is recommended to meet this requirement?
- A. Configure user Provisioning for Connected Apps.
- B. Build an Apex trigger on the userlogin object to make asynchronous callouts to Google APIs.
- C. Build a custom REST endpoint in Salesforce that Google Workspace can poll against.
- D. Update the Security Assertion Markup Language Just-in-Time (SAML JIT) handler in Salesforce for user provisioning and de-provisioning.
Answer: A
NEW QUESTION # 145
Universal containers (UC) does my domain enable in the context of a SAML SSO configuration? Choose 2 answers
- A. App launcher
- B. Login forensics
- C. Resource deep linking
- D. SSO from salesforce1 mobile app.
Answer: C,D
NEW QUESTION # 146
Universal Containers is implementing Salesforce Identity to broker authentication from its enterprise single sign-on (SSO) solution through Salesforce to third party applications using SAML.
What rote does Salesforce Identity play in its relationship with the enterprise SSO system?
- A. Service Provider (SP)
- B. Client Application
- C. Identity Provider (IdP)
- D. Resource Server
Answer: A
NEW QUESTION # 147
An Identity and Access Management (IAM) Architect is recommending Identity Connect to integrate Microsoft Active Directory (AD) with Salesforce for user provisioning, deprovisioning and single sign-on (SSO).
Which feature of Identity Connect is applicable for this scenano?
- A. When Identity Connect is in place, if a user is deprovisioned in an on-premise AD, the user's Salesforce session Is revoked Immediately.
- B. Identity Connect can be deployed as a managed package on salesforce org, leveraging High Availability of Salesforce Platform out-of-the-box.
- C. If the number of provisioned users exceeds Salesforce licence allowances, identity Connect will start disabling the existing
- D. When configured, Identity Connect acts as an identity provider to both Active Directory and Salesforce, thus providing SSO as a default feature.
Answer: A
NEW QUESTION # 148
A real estate company wants to provide its customers a digital space to design their interior decoration options. To simplify the registration to gain access to the community site (built in Experience Cloud), the CTO has requested that the IT/Development team provide the option for customers to use their existing social-media credentials to register and access.
The IT lead has approached the Salesforce Identity and Access Management (IAM) architect for technical direction on implementing the social sign-on (for Facebook, Twitter, and a new provider that supports standard OpenID Connect (OIDC)).
Which two recommendations should the Salesforce IAM architect make to the IT Lead?
Choose 2 answers
- A. For supporting OIDC it is necessary to enable Security Assertion Markup Language (SAML) with Just-in-Time provisioning (JIT) and OAuth 2.0.
- B. Apex coding skills are needed for registration handler to create and update users.
- C. Authentication provider configuration is required each social sign-on providers; and enable Authentication providers in
- D. Use declarative registration handler process builder/flow to create, update users and contacts.
Answer: B,C
NEW QUESTION # 149
Universal Containers (UC) has decided to replace the homegrown customer portal with Salesforce Experience Cloud. UC will continue to use its third-party single sign-on (SSO) solution that stores all of its customer and partner credentials.
The first time a customer logs in to the Experience Cloud site through SSO, a user record needs to be created automatically.
Which solution should an identity architect recommend in order to automatically provision users in Salesforce upon login?
- A. Third-party AppExchange solution
- B. Just-in-Time (JIT) provisioning
- C. Custom middleware and web services
- D. Custom login flow and Apex handler
Answer: B
NEW QUESTION # 150
customer service representatives at Universal containers (UC) are complaining that whenever they click on links to case records and are asked to login with SAML SSO, they are being redirected to the salesforce home tab and not the specific case record. What item should an architect advise the identity team at UC to investigate first?
- A. The salesforce SSO settings are using http post
- B. The users have the correct Federation ID within salesforce.
- C. The identity provider is correctly preserving the Relay state
- D. My domain is configured and active within salesforce.
Answer: C
NEW QUESTION # 151
Universal Containers (UC) is rolling out its new Customer Identity and Access Management Solution built on top of its existing Salesforce instance. UC wants to allow customers to login using Facebook, Google, and other social sign-on providers.
How should this functionality be enabled for UC, assuming ail social sign-on providers support OpenID Connect?
- A. Configure an authentication provider and a registration handler for each social sign-on provider.
- B. Configure an authentication provider and a Just-In-Time (JIT) handler for each social sign-on provider.
- C. Configure a single sign-on setting and a registration handler for each social sign-on provider.
- D. Configure a single sign-on setting and a JIT handler for each social sign-on provider.
Answer: A
NEW QUESTION # 152
......
Exam Questions for Plat-Arch-203 Updated Versions With Test Engine: https://www.actualtestsquiz.com/Plat-Arch-203-test-torrent.html
Test Engine to Practice Test for Plat-Arch-203 Valid and Updated Dumps: https://drive.google.com/open?id=1tW71gQ0FCiNHRfjgSCiqRSFDuGJurA8e

