Aug 27, 2026 Detailed New Plat-Arch-203 Exam Questions for Concept Clearance
Plat-Arch-203 Exam Preparation Material with New Plat-Arch-203 Dumps Questions.
NEW QUESTION # 80
Which two things should be done to ensure end users can only use single sign-on (SSO) to login in to Salesforce?
Choose 2 answers
- A. Assign user "is Single Sign-on Enabled" permission via profile or permission set.
- B. Once SSO is enabled, users are only able to login using Salesforce credentials.
- C. Request Salesforce Support to enable delegated authentication.
- D. Enable My Domain and select "Prevent login from https://login.salesforce.com".
Answer: A,D
NEW QUESTION # 81
Universal containers (UC) has a mobile application that it wants to deploy to all of its salesforce users, including customer Community users. UC would like to minimize the administration overhead, which two items should an architect recommend? Choose 2 answers
- A. Enable the "Refresh Tokens is valid until revoked " setting in the Connected App.
- B. Enable the "All users may self-authorize" setting in the Connected App.
- C. Enable the "High Assurance session required" setting in the Connected App.
- D. Enable the "Enforce Ip restrictions" settings in the connected App.
Answer: A,B
NEW QUESTION # 82
Northern Trail Outfitters manages application functional permissions centrally as Active Directory groups. The CRM_Superllser and CRM_Reportmg_SuperUser groups should respectively give the user the SuperUser and Reportmg_SuperUser permission set in Salesforce. Salesforce is the service provider to a Security Assertion Markup Language (SAML) identity provider.
Mow should an identity architect ensure the Active Directory groups are reflected correctly when a user accesses Salesforce?
- A. Use the Apex Just-in-Time handler to query custom SAML attributes and set permission sets.
- B. Use a login flow to query standard SAML attributes and set permission sets.
- C. Use a login flow to query custom SAML attributes and set permission sets.
- D. Use the Apex Just-in-Time handler to query standard SAML attributes and set permission sets.
Answer: A
NEW QUESTION # 83
Universal containers (UC) wants to integrate a Web application with salesforce. The UC team has implemented the Oauth web-server Authentication flow for authentication process. Which two considerations should an architect point out to UC? Choose 2 answers
- A. The flow will not provide an Oauth refresh token back to the server.
- B. The flow involves passing the user credentials back and forth.
- C. The web application should be hosted on a secure server.
- D. The web server must be able to protect consumer privacy
Answer: C,D
NEW QUESTION # 84
Northern Trail Outfitters recently acquired a company. Each company will retain its Identity Provider (IdP). Both companies rely extensively on Salesforce processes that send emails to users to take specific actions in Salesforce.
How should the combined companys' employees collaborate in a single Salesforce org, yet authenticate to the appropriate IdP?
- A. Configure unique MyDomains for each company and have generated links use the appropriate MyDomam in the URL.
- B. Have generated links append a querystnng parameter indicating the IdP. The login service will redirect to the appropriate IdP.
- C. Enable each IdP as a login option in the MyDomain Authentication Service settings. Users will then click on the appropriate IdP button.
- D. Have generated links be prefixed with the appropriate IdP URL to invoke an IdP-initiated Security Assertion Markup Language flow when clicked.
Answer: C
NEW QUESTION # 85
A consumer products company uses Salesforce to maintain consumer information, including orders. The company implemented a portal solution using Salesforce Experience Cloud for its consumers where the consumers can log in using their credentials. The company is considering allowing users to login with their Facebook or Linkedln credentials.
Once enabled, what role will Salesforce play?
- A. Facebook and Linkedln will act as the IdPs and SPs.
- B. Salesforce will be the service provider (SP).
- C. Facebook and Linkedln will be the SPs.
- D. Salesforce will be the identity provider (IdP).
Answer: B
NEW QUESTION # 86
Universal Containers (UC) is looking to build a Canvas app and wants to use the corresponding Connected App to control where the app is visible. Which two options are correct in regards to where the app can be made visible under the Connected App setting for the Canvas app? Choose 2 answers
- A. Included in the Call Control Tool that's part of Open CTI.
- B. In the mobile navigation menu on Salesforce for Android.
- C. The sidebar of a Salesforce Console as a console component.
- D. As part of the body of a Salesforce Knowledge article.
Answer: C,D
NEW QUESTION # 87
Uwversal Containers (UC) is building a custom employee hut) application on Amazon Web Services (AWS) and would like to store their users' credentials there. Users will also need access to Salesforce for internal operations. UC has tasked an identity architect with evaluating Afferent solutions for authentication and authorization between AWS and Salesforce.
How should an identity architect configure AWS to authenticate and authorize Salesforce users?
- A. Develop a custom Auth server in AWS.
- B. Create a custom external authentication provider.
- C. Configure AWS as an OpenID Connect Provider.
- D. Configure the custom employee app as a connected app.
Answer: C
NEW QUESTION # 88
universal container plans to develop a custom mobile app for the sales team that will use salesforce for authentication and access management. The mobile app access needs to be restricted to only the sales team. What would be the recommended solution to grant mobile app access to sales users?
- A. Use a custom attribute on the user object to control access to the mobile app
- B. Use connected apps Oauth policies to restrict mobile app access to authorized users.
- C. Add a new identity provider to authenticate and authorize mobile users.
- D. Use the permission set license to assign the mobile app permission to sales users
Answer: B
NEW QUESTION # 89
Universal Containers (UC) has implemented SAML-based Single Sign-On to provide seamless access to its Salesforce Orgs, financial system, and CPQ system. Below is the SSO implementation landscape.
What role combination is represented by the systems in this scenario''
- A. Financial System and CPQ System are the only Service Providers.
- B. Salesforce Org1 and PingFederate are acting as Identity Providers.
- C. Salesforce Org1 and Salesforce Org2 are the only Service Providers.
- D. Salesforce Org1 and Salesforce Org2 are acting as Identity Providers.
Answer: B
NEW QUESTION # 90
Universal containers (UC) is successfully using Delegated Authentication for their salesforce users. The service supporting Delegated Authentication is written in Jav a. UC has a new CIO that is requiring all company Web services be RESR-ful and written in . NET. Which two considerations should the UC Architect provide to the new CIO? Choose 2 answers
- A. Delegated Authentication will not work with a.net service.
- B. Delegated Authentication will continue to work with a.net service.
- C. Delegated Authentication will continue to work with rest services.
- D. Delegated Authentication will not work with rest services.
Answer: B,D
NEW QUESTION # 91
A global company's Salesforce Identity Architect is reviewing its Salesforce production org login history and is seeing some intermittent Security Assertion Markup Language (SAML SSO) 'Replay Detected and Assertion Invalid' login errors.
Which two issues would cause these errors?
Choose 2 answers
- A. The certificate loaded into SSO configuration does not match the certificate used by the IdP.
- B. The assertion sent to 5alesforce contains an assertion ID previously used.
- C. The current time setting of the company's identity provider (IdP) and Salesforce platform is out of sync by more than eight minutes.
- D. The subject element is missing from the assertion sent to salesforce.
Answer: B,D
NEW QUESTION # 92
A global company is using the Salesforce Platform as an Identity Provider and needs to integrate a third-party application with its Experience Cloud customer portal.
Which two features should be utilized to provide users with login and identity services for the third-party application?
Choose 2 answers
- A. Use the App Launcher with single sign-on (SSO).
- B. Use a connected app.
- C. Use Delegated Authentication.
- D. External a Data source with Named Principal identity type.
Answer: A,B
NEW QUESTION # 93
Universal Containers (UC) has five Salesforce orgs (UC1, UC2, UC3, UC4, UC5). of Every user that is in UC2, UC3, UC4, and UC5 is also in UC1, however not all users 65* have access to every org. Universal Containers would like to simplify the authentication process such that all Salesforce users need to remember one set of credentials. UC would like to achieve this with the least impact to cost and maintenance. What approach should an Architect recommend to UC?
- A. Configure UC1 as the Identity Provider to the other four Salesforce orgs, but don't set up JIT user provisioning for other orgs.
- B. Configure UC1 as the Identity Provider to the other four Salesforce orgs and set up JIT user provisioning on all other orgs.
- C. Purchase a third-party Identity Provider for all five Salesforce orgs to use, but don't set up JIT user provisioning for other orgs.
- D. Purchase a third-party Identity Provider for all five Salesforce orgs to use and set up JIT user provisioning on all other orgs.
Answer: C
NEW QUESTION # 94
A service provider (SP) supports both Security Assertion Markup Language (SAML) and OpenID Connect (OIDC).
When integrating this SP with Salesforce, which use case is the determining factor when choosing OIDC or SAML?
- A. They are equivalent protocols and there is no real reason to choose one over the other.
- B. The SP needs to perform API calls back to Salesforce on behalf of the user after the user logs in to the service provider.
- C. OIDC is more secure than SAML and therefore is the obvious choice.
- D. If the user has a session on Salesforce, you do not want them to be prompted for a username and password when they login to the SP.
Answer: B
NEW QUESTION # 95
Containers (UC) uses a legacy Employee portal for their employees to collaborate. Employees access the portal from their company's internal website via SSO. It is set up to work with SiteMinder and Active Directory. The Employee portal has features to support posing ideas. UC decides to use Salesforce Ideas for voting and better tracking purposes. To avoid provisioning users on Salesforce, UC decides to integrate Employee portal ideas with Salesforce idea through the API. What is the role of Salesforce in the context of SSO, based on this scenario?
- A. Connected App, because Salesforce is connected with Employee portal via API.
- B. Service Provider, because Salesforce is the application for managing ideas.
- C. An independent system, because Salesforce is not part of the SSO setup.
- D. Identity Provider, because the API calls are authenticated by Salesforce.
Answer: C
NEW QUESTION # 96
Universal Containers wants to implement Single Sign-on for a Salesforce org using an external Identity Provider and corporate identity store.
What type of authentication flow is required to support deep linking'
- A. Identity-Provider-initiated SSO
- B. Service-Provider-Initiated SSO
- C. StartURL on Identity Provider
- D. Web Server OAuth SSO flow
Answer: B
NEW QUESTION # 97
Containers (UC) has an existing Customer Community. UC wants to expand the self-registration capabilities such that customers receive a different community experience based on the data they provide during the registration process. What is the recommended approach an Architect Should recommend to UC?
- A. Modify the existing Communities registration controller to assign different profiles.
- B. Modify the Community pages to utilize specific fields on the User and Contact records.
- C. Create separate login flows corresponding to the different community user personas.
- D. Create an After Insert Apex trigger on the user object to assign specific custom permissions.
Answer: B
NEW QUESTION # 98
Universal Containers (UC) wants to build a custom mobile app for their field reps to create orders in salesforce. After the first time the users log in, they must be able to access salesforce upon opening the mobile app without being prompted to log in again. What Oauth flows should be considered to support this requirement?
- A. Mobile Agent flow with a Bearer Token.
- B. User Agent flow with a Refresh Token.
- C. SAML Assertion flow with a Bearer Token.
- D. Web Server flow with a Refresh Token.
Answer: B
NEW QUESTION # 99
Universal containers (UC) is concerned that having a self-registration page will provide a means for "bots" or unintended audiences to create user records, thereby consuming licences and adding dirty dat a. Which two actions should UC take to prevent unauthorised form submissions during the self-registration process? Choose 2 answers
- A. Use hidden fields populated via java script events in the self-registration page.
- B. Use open-ended security questions and complex password requirements
- C. Require a captcha at the end of the self-registration process.
- D. Primarily use lookup and picklist fields on the self registration page.
Answer: A,C
NEW QUESTION # 100
Universal Containers (UC) wants to implement SAML SSO for their internal of Salesforce users using a third-party IdP. After some evaluation, UC decides NOT to set up My Domain for their Salesforce org. How does that decision impact their SSO implementation?
- A. SP-initiated SSO will NOT work
- B. Neither SP- nor IdP-initiated SSO will work.
- C. IdP-initiated SSO will NOT work.
- D. Either SP- or IdP-initiated SSO will work.
Answer: B
NEW QUESTION # 101
......
Plat-Arch-203 2026 Training With 246 QA's: https://prepaway.updatedumps.com/Salesforce/Plat-Arch-203-updated-exam-dumps.html