Salesforce Plat-Arch-203 Exam Overview:
| Certification Vendor: | Salesforce |
| Exam Name: | Salesforce Certified Platform Identity and Access Management Architect |
| Exam Number: | Plat-Arch-203 |
| Exam Price: | $400 USD (initial), $200 USD (retake) |
| Available Languages: | English, Japanese |
| Certificate Validity Period: | 2 years |
| Exam Format: | Multiple-choice, Multiple-select, Scenario-based |
| Passing Score: | 67% |
| Related Certifications: | Salesforce Certified System Architect Salesforce Certified Application Architect |
| Real Exam Qty: | 60 - 65 |
| Exam Duration: | 105 - 120 |
| Recommended Training: | Architect Journey: Identity and Access Management |
| Exam Registration: | Salesforce Certification Registration |
| Sample Questions: | Salesforce Plat-Arch-203 Sample Questions |
| Exam Way: | Online proctored or onsite at Kryterion/Pearson VUE test centers |
| Pre Condition: | No mandatory prerequisites; recommended: 2–3 years of IAM experience on Salesforce, familiarity with SAML/OAuth/OIDC, and prior architect certifications |
| Official Syllabus URL: | https://trailhead.salesforce.com/credentials/identityandaccessmanagementarchitect |
Salesforce Plat-Arch-203 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Accepting Third-Party Identity in Salesforce | 26% | - Just-in-Time (JIT) provisioning - Authentication providers and social login - SAML SSO configuration and troubleshooting
|
| Topic 2: Salesforce as an Identity Provider | 19% | - Connected Apps and OAuth flows
- SCIM and user provisioning to external systems |
| Topic 3: Community (Partner and Customer) Identity | 18% | - Experience Cloud authentication and verification - Self-registration and password reset - External identity provider integration for communities |
| Topic 4: Identity Management Concepts | 17% | - Authentication patterns and selection
|
| Topic 5: Salesforce Identity | 12% | - Identity Connect implementation - Customer 360 Identity integration - License type selection for identity use cases |
| Topic 6: Access Management Best Practices | 15% | - Field-level and object-level security - Role hierarchy and sharing rules - Profiles, permission sets and groups - Multi-factor authentication and session management |
Salesforce Certified Platform Identity and Access Management Architect Sample Questions:
1. Which three different attributes can be used to identify the user in a SAML 65> assertion when Salesforce is acting as a Service Provider? Choose 3 answers
A) User Full Name
B) Salesforce Username
C) Federation ID
D) Salesforce User ID
E) User Email Address
2. Universal Containers (UC) is building a customer community and will allow customers to authenticate using Facebook credentials. The First time the user authenticating using facebook, UC would like a customer account created automatically in their Accounting system. The accounting system has a web service accessible to Salesforce for the creation of accounts. How can the Architect meet these requirements?
A) Create a custom application on Heroku that manages the sign-on process from Facebook.
B) Use OAuth JWT flow to pass the data from Salesforce to the Accounting System.
C) Add an Apex callout in the registration handler of the authorization provider.
D) Use JIT Provisioning to automatically create the account in the accounting system.
3. Universal containers(UC) has implemented SAML-BASED single Sign-on for their salesforce application and is planning to provide access to salesforce on mobile devices using the salesforce1 mobile app. UC wants to ensure that single Sign-on is used for accessing the salesforce1 mobile app. Which two recommendations should the architect make? Choose 2 answers
A) Use the existing SAML SSO flow along with user agent flow.
B) Configure the salesforce1 app to use the my domain URL
C) Configure the embedded Web browser to use my domain URL.
D) Use the existing SAML SSO flow along with Web server flow
4. A global company has built an external application that uses data from its Salesforce org via an OAuth 2.0 authorization flow. Upon logout, the existing Salesforce OAuth token must be invalidated.
Which action will accomplish this?
A) Use a HTTP POST to request the refresh token for the current user.
B) Use a HTTP POST to the System for Cross-domain Identity Management (SCIM) endpoint, including the current OAuth token.
C) Use a HTTP POST to make a call to the revoke token endpoint.
D) Enable Single Logout with a secure logout URL.
5. Universal Containers (UC) has a desktop application to collect leads for marketing campaigns. UC wants to extend this application to integrate with Salesforce to create leads. Integration between the desktop application and Salesforce should be seamless. What Authorization flow should the Architect recommend?
A) Web Server Authentication Flow
B) Username and Password Flow
C) User Agent Flow
D) JWT Bearer Token Flow
Solutions:
| Question # 1 Answer: A,C,E | Question # 2 Answer: C | Question # 3 Answer: A,B | Question # 4 Answer: C | Question # 5 Answer: C |

We're so confident of our products that we provide no hassle product exchange.


By Truda


