
2026 Realistic Verified Free Salesforce Plat-Arch-203 Exam Questions
Plat-Arch-203 Real Exam Questions and Answers FREE
NEW QUESTION # 28
Northern Trail Outfitters wants to implement a partner community. Active community users will need to review and accept the community rules, and update key contact information for each community member before their annual partner event.
Which approach will meet this requirement?
- A. Create a custom landing page and email campaign asking all community members to login and verify their data.
- B. Create a login flow that conditionally prompts users who have not accepted the new community rules and who have missing or outdated information.
- C. Create tasks for users who need to update their data or accept the new community rules.
- D. Add a banner to the community Home page asking users to update their profile and accept the new community rules.
Answer: B
NEW QUESTION # 29
Uwversal Containers (UC) is building a custom employee hut) application on Amazon Web Services (AWS) and would like to store their users' credentials there. Users will also need access to Salesforce for internal operations. UC has tasked an identity architect with evaluating Afferent solutions for authentication and authorization between AWS and Salesforce.
How should an identity architect configure AWS to authenticate and authorize Salesforce users?
- A. Create a custom external authentication provider.
- B. Configure the custom employee app as a connected app.
- C. Develop a custom Auth server in AWS.
- D. Configure AWS as an OpenID Connect Provider.
Answer: D
NEW QUESTION # 30
Universal Containers (UC) plans to use a SAML-based third-party IdP serving both of the Salesforce Partner Community and the corporate portal. UC partners will log in 65* to the corporate portal to access protected resources, including links to Salesforce resources. What would be the recommended way to configure the IdP so that seamless access can be achieved in this scenario?
- A. Set up the corporate portal as a Connected App in Salesforce and use the User Agent OAuth flow.
- B. Configure SP-initiated SSO that passes the SAML token upon Salesforce resource access request.
- C. Set up the corporate portal as a Connected App in Salesforce and use the Web server OAuth flow.
- D. Configure IdP-initiated SSO that passes the SAML token upon Salesforce resource access request.
Answer: D
NEW QUESTION # 31
The CIO of universal containers(UC) wants to start taking advantage of the refresh token capability for the UC applications that utilize Oauth 2.0. UC has listed an architect to analyze all of the applications that use Oauth flows to. See where refresh Tokens can be applied. Which two OAuth flows should the architect consider in their evaluation? Choose 2 answers
- A. Username-password
- B. Jwt bearer token
- C. User-Agent
- D. Web server
Answer: C,D
NEW QUESTION # 32
Universal Containers is using OpenID Connect to enable a connection from their new mobile app to its production Salesforce org.
What should be done to enable the retrieval of the access token status for the OpenID Connect connection?
- A. Create a custom OAuth scope.
- B. Query using OpenID Connect discovery endpoint.
- C. Enable cross-origin resource sharing (CORS) for the /services/oauth2/token endpoint.
- D. A Leverage OpenID Connect Token Introspection.
Answer: D
NEW QUESTION # 33
Northern Trail Outfitters (NTO) has an off-boarding process where a terminated employee is first disabled in the Lightweight Directory Act Protocol (LDAP) directory, then requests are sent to the various application support teams to finish user deactivations. A terminated employee recently was able to login to NTO's Salesforce instance 24 hours after termination, even though the user was disabled in the corporate LDAP directory.
What should an identity architect recommend to prevent this from happening in the future?
- A. use a login flow to make a callout to the LDAP directory before authenticating the user to Salesforce.
- B. Create a Just-in-Time provisioning registration handler to ensure users are deactivated in Salesforce as they are disabled in LDAP.
- C. Configure an authentication provider to delegate authentication to the LDAP directory.
- D. Setup an identity provider (IdP) to authenticate users using LDAP, set up single sign-on to Salesforce and disable Login Form authentication.
Answer: C
NEW QUESTION # 34
An identity architect is setting up an integration between Salesforce and a third-party system. The third-party system needs to authenticate to Salesforce and then make API calls against the REST API.
One of the requirements is that the solution needs to ensure the third party service providers connected app in Salesforce mini need for end user interaction and maximizes security.
Which OAuth flow should be used to fulfill the requirement?
- A. Username-Password Flow
- B. Web Server Flow
- C. JWT Bearer Flow
- D. User Agent Flow
Answer: C
NEW QUESTION # 35
Universal containers (UC) is successfully using Delegated Authentication for their salesforce users. The service supporting Delegated Authentication is written in Jav a. UC has a new CIO that is requiring all company Web services be RESR-ful and written in . NET. Which two considerations should the UC Architect provide to the new CIO? Choose 2 answers
- A. Delegated Authentication will continue to work with a.net service.
- B. Delegated Authentication will not work with a.net service.
- C. Delegated Authentication will continue to work with rest services.
- D. Delegated Authentication will not work with rest services.
Answer: A,D
NEW QUESTION # 36
Universal Containers (UC) wants to provide single sign-on (SSO) for a business-to-consumer (B2C) application using Salesforce Identity.
Which Salesforce license should UC utilize to implement this use case?
- A. Salesforce Platform
- B. Identity Only
- C. Partner Community
- D. External Identity
Answer: D
NEW QUESTION # 37
A company's external application is protected by Salesforce through OAuth. The identity architect for the project needs to limit the level of access to the data of the protected resource in a flexible way.
What should be done to improve security?
- A. Select "Admin approved users are pre-authorized" and assign specific profiles.
- B. Leverage external objects and data classification policies.
- C. Create custom scopes and assign to the connected app.
- D. Define a permission set that grants access to the app and assign to authorized users.
Answer: C
NEW QUESTION # 38
Northern Trail Outfitters want to allow its consumer to self-register on it business-to-consumer (B2C) portal that is built on Experience Cloud. The identity architect has recommended to use Person Accounts.
Which three steps need to be configured to enable self-registration using person accounts?
Choose 3 answers
- A. Under Login and Registration settings, ensure that the default account field is empty.
- B. Contact Salesforce Support to enable business accounts.
- C. Contact Salesforce Support to enable person accounts.
- D. Enable access to person and business account record types under Public Access Settings.
- E. Set organization-wide default sharing for Contact to Public Read Only.
Answer: A,C,D
NEW QUESTION # 39
What are three capabilities of Delegated Authentication? Choose 3 answers
- A. It can be assigned by Custom Permissions.
- B. It can be assigned by Profiles.
- C. It can be assigned by Permission Sets.
- D. It can connect to REST services.
- E. It can connect to SOAP services.
Answer: C,D,E
NEW QUESTION # 40
Universal Container's (UC) identity architect needs to recommend a license type for their new Experience Cloud site that will be used by external partners (delivery providers) for reviewing and updating their accounts, downloading files provided by UC and obtaining scheduled pickup dates from their calendar.
UC is using their Salesforce production org as the identity provider for these users and the expected number of individual users is 2.5 million with 13.5 million unique logins per month.
Which of the following license types should be used to meet the requirement?
- A. Partner Community Login License
- B. Partner Community License
- C. External Apps License
- D. Customer Community plus Login License
Answer: D
NEW QUESTION # 41
How should an Architect force users to authenticate with Two-factor Authentication (2FA) for Salesforce only when not connected to an internal company network?
- A. Apply the "Two-factor Authentication for User Interface Logins" permission and Login IP Ranges for all Profiles.
- B. Add the list of company's network IP addresses to the Login Range list under 2FA Setup.
- C. Use Custom Login Flows with Apex to detect the user's IP address and prompt for 2FA if needed.
- D. Use an Apex Trigger on the UserLogin object to detect the user's IP address and prompt for 2FA if needed.
Answer: C
NEW QUESTION # 42
Universal Containers (UC) built an integration for their employees to post, view, and vote for ideas in Salesforce from an internal Company portal. When ideas are posted in Salesforce, links to the ideas are created in the company portal pages as part of the integration process. The Company portal connects to Salesforce using OAuth. Everything is working fine, except when users click on links to existing ideas, they are always taken to the Ideas home page rather than the specific idea, after authorization. Which OAuth URL parameter can be used to retain the original requested page so that a user can be redirected correctly after OAuth authorization?
- A. Callback_uri
- B. State
- C. Redirect_uri
- D. Scope
Answer: C
NEW QUESTION # 43
Universal Containers (UC) is planning to add Wi-Fi enabled GPS tracking devices to its shipping containers so that the GPS coordinates data can be sent from the tracking device to its Salesforce production org via a custom API. The GPS devices have no direct user input or output capabilities.
Which OAuth flow should the identity architect recommend to meet the requirement?
- A. OAuth 2.0 Username-Password Flow for Special Scenarios
- B. OAuth 2.0 Asset Token Flow for Securing Connected Devices
- C. OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration
- D. OAuth 2.0 Web Server Flow for Web App Integration
Answer: B
NEW QUESTION # 44
Universal Containers (UC) wants to integrate a third-party Reward Calculation system with Salesforce to calculate Rewards. Rewards will be calculated on a schedule basis and update back into Salesforce. The integration between Salesforce and the Reward Calculation System needs to be secure. Which are two recommended practices for using OAuth flow in this scenario. choose 2 answers
- A. OAuth JWT Bearer Token FLow
- B. OAuth Refresh Token FLow
- C. OAuth Username-Password Flow
- D. OAuth SAML Bearer Assertion FLow
Answer: A,D
NEW QUESTION # 45
Universal Containers (UC) is using its production org as the identity provider for a new Experience Cloud site and the identity architect is deciding which login experience to use for the site.
Which two page types are valid login page types for the site?
Choose 2 answers
- A. Embedded Login Page
- B. lightning Experience Page
- C. Experience Builder Page
- D. Login Discovery Page
Answer: A,D
NEW QUESTION # 46
Universal containers wants to implement single Sign-on for a salesforce org using an external identity provider and corporate identity store. What type of Authentication flow is required to support deep linking?
- A. Web server Oauth SSO flow.
- B. Identity-provider-initiated SSO
- C. Start URL on identity provider
- D. Service-provider-initiated SSO
Answer: D
NEW QUESTION # 47
......
Exam Dumps Plat-Arch-203 Practice Free Latest Salesforce Practice Tests: https://www.prepawayete.com/Salesforce/Plat-Arch-203-practice-exam-dumps.html