Skip to content

Plat-Arch-203 Salesforce Certified Platform Identity and Access Management Architect Practice Questions

Prepare for Plat-Arch-203 with more than an answer.

160 questions in the full set12 sample questionsUpdated Mar 12, 2026
Exam fee
$400 USD
Level
Architect
Valid for
Annual maintenance (Trailhead maintenance modules)
Domains covered on the exam 6
  1. Identity Management Concepts17%
  2. Accepting Third-Party Identity in Salesforce21%
  3. Salesforce as an Identity Provider17%
  4. Access Management Best Practices15%
  5. Salesforce Identity12%
  6. Community (Partner and Customer)18%
  1. 1

    A developer is configuring a Connected App to allow an external inventory system to access Salesforce data. The external system runs a nightly batch job and cannot support browser-based user interaction. The developer has generated a self-signed certificate. What is the correct sequence of steps to configure the OAuth 2.0 JWT Bearer Flow?

    Show answer details

    Correct answer: C

    This is the correct flow. 1) The certificate (public key) is uploaded to the Connected App in Salesforce. 2) The user profile must be pre-authorized ('Admin approved users are pre-authorized') to skip the consent screen. 3) The external system signs the JWT with its private key. 4) The signed JWT is exchanged for an access token at the /services/oauth2/token endpoint.

  2. 2

    The security team at Universal Containers has noticed that a specific user account is frequently locked out due to invalid password attempts. They suspect a script is attempting to brute-force the login. Which tool should the Identity Architect use to definitively identify the IP address and the specific login type (e.g., API vs UI) of these failed attempts?

    Show answer details

    Correct answer: B

    Login History provides a detailed log of all login attempts, including status (success/failure), IP address, login type (Application, Browser, etc.), and the specific application used. Setup Audit Trail tracks metadata changes, not user login attempts.

  3. 3

    A Salesforce Architect is reviewing the Single Sign-On implementation documentation for a client. The client uses a SAML-based IdP. The documentation mentions that Salesforce is sending a SAMLRequest to the IdP to start the login process. Which type of SAML flow is being described?

    Show answer details

    Correct answer: A

    In SP-Initiated SSO, the user attempts to access the Service Provider (Salesforce) first. Salesforce generates a SAMLRequest and redirects the user to the IdP. In IdP-Initiated SSO, the flow starts at the IdP, and no SAMLRequest is sent from Salesforce.

  4. 4

    A multinational financial services firm uses Active Directory Federation Services (ADFS) as their Identity Provider (IdP) and Salesforce as a Service Provider (SP). Users in the 'APAC' region are reporting intermittent login failures when accessing Salesforce via SSO. The Identity Architect reviews the SAML assertions and notices the NotBefore and NotOnOrAfter timestamps are causing validation errors due to a slight time drift between the ADFS server in Singapore and the Salesforce servers. Which configuration change in Salesforce should the Architect recommend to resolve this issue without compromising security?

    Show answer details

    Correct answer: A

  5. 5

    An architect is designing a server-to-server integration where an external middleware system needs to update Salesforce records nightly without user interaction. The security team requires that no shared secrets (passwords) be transmitted during the authentication handshake and that the session should be valid for only a short duration. Which OAuth flow is the optimal choice for this scenario?

    Show answer details

    Correct answer: A

    The JWT Bearer Flow is designed for server-to-server integration. It uses a certificate to sign the JWT request, eliminating the need to transmit a password or client secret over the wire during the handshake, fulfilling the security requirement. The Web Server flow requires user interaction, and the Username-Password flow transmits credentials.

  6. 6

    A global manufacturing company uses Identity Connect to provision users from Microsoft Active Directory (AD) to Salesforce. They have a requirement to assign users to specific Permission Set Groups in Salesforce based on their AD 'Department' attribute. The AD team has created three groups: 'Sales', 'Service', and 'Marketing'. How should the Identity Architect configure Identity Connect to meet this requirement?

    Show answer details

    Correct answer: B

    Identity Connect maps AD Groups to Salesforce Permissions Sets, Public Groups, or Roles. It does not map directly to Permission Set Groups. The correct approach is to map the AD Groups to the specific Permission Sets that make up the required access. While the question asks about Permission Set Groups, Identity Connect's direct mapping capability targets Permission Sets. (Note: In newer versions, direct mapping to Permission Set Groups may be supported via advanced configuration or indirect mapping, but the standard architectural pattern is mapping AD Groups to Permission Sets).

Create an account to continue.