
Plat-Arch-203 Actual Questions - Instant Download Tests Free Updated Today!
Get instant access of 100% real Salesforce Plat-Arch-203 exam questions with verified answers
NEW QUESTION # 38
The CMO of an advertising company has invited an Identity and Access Management (IAM) specialist to discuss Salesforce out-of-box capabilities for configuring the company*s login and registration experience on Salesforce Experience Cloud.
The CMO is looking to brand the login page with the company's logo, background color, login button color, and dynamic right-frame from an external URL.
Which two solutions should the IAM specialist recommend?
Choose 2 answers
- A. Login & Registration pages can be branded in the Community Administration settings.
- B. Build custom pages for branding requirements in Experience Cloud.
- C. Build custom site pages for reset and forgot password features.
- D. Use Experience Builder to build branded Reset and Forgot Password pages.
Answer: A,D
NEW QUESTION # 39
Universal containers (UC) is setting up their customer Community self-registration process. They are uncomfortable with the idea of assigning new users to a default account record. What will happen when customers self-register in the community?
- A. The self-registration process will produce an error to the user.
- B. The self-registration page will create a new account record.
- C. The self-registration page will ask user to select an account.
- D. The self-registration process will create a person Account record.
Answer: A
NEW QUESTION # 40
Northern Trail Outfitters (NTO) uses a Security Assertion Markup Language (SAML)-based Identity Provider (idP) to authenticate employees to all systems. The IdP authenticates users against a Lightweight Directory Access Protocol (LDAP) directory and has access to user information. NTO wants to minimize Salesforce license usage since only a small percentage of users need Salesforce.
What is recommended to ensure new employees have immediate access to Salesforce using their current IdP?
- A. Configure Just-in-Time provisioning using SAML attributes to create new Salesforce users as necessary when a new user attempts to login to Salesforce.
- B. Build an integration that queries LDAP and creates new inactive users in Salesforce and use a login flow to activate the user at first login.
- C. Install Salesforce Identity Connect to automatically provision new users in Salesforce the first time they attempt to login.
- D. Build an integration that queries LDAP periodically and creates new active users in Salesforce.
Answer: A
NEW QUESTION # 41
Universal Containers (UC) uses Salesforce for its customer service agents. UC has a proprietary system for order tracking which supports Security Assertion Markup Language (SAML) based single sign-on. The VP of customer service wants to ensure only active Salesforce users should be able to access the order tracking system which is only visible within Salesforce.
What should be done to fulfill the requirement?
Choose 2 answers
- A. Setup Salesforce as an identity provider (IdP) for order Tracking.
- B. Setup Order Tracking as a Canvas app in Salesforce to POST IdP initiated SAML assertion.
- C. Customize Order Tracking to initiate a REST call to validate users in Salesforce after login.
- D. Set up the Corporate Identity store as an identity provider (IdP) for Order Tracking,
Answer: A,D
NEW QUESTION # 42
Which two considerations should be made when implementing Delegated Authentication?
Choose 2 answers
- A. The authentication web service can include custom attributes.
- B. Just-in-time Provisioning can be configured for new users.
- C. It can be used to authenticate API clients and mobile apps.
- D. Salesforce servers receive but do not validate a user's credentials.
- E. It requires trusted IP ranges at the User Profile level.
Answer: B,C
NEW QUESTION # 43
Northern Trail Outfitters (NTO) leverages Microsoft Active Directory (AD) for management of employee usernames, passwords, permissions, and asset access. NTO also owns a third-party single sign-on (SSO) solution. The third-party party SSO solution is used for all corporate applications, including Salesforce.
NTO has asked an architect to explore Salesforce Identity Connect for automatic provisioning and deprovisiorung of users in Salesforce.
What role does identity Connect play in the outlined requirements?
- A. Identity Provider
- B. Single Sign-On
- C. User Management
- D. Service Provider
Answer: C
NEW QUESTION # 44
Universal Containers (UC) has decided to use Salesforce as an Identity Provider for multiple external applications. UC wants to use the salesforce App Launcher to control the Apps that are available to individual users. Which three steps are required to make this happen?
- A. Create a Connected App for each external application.
- B. Set up an Auth Provider for each External Application.
- C. Set up Identity Connect to Synchronize user data.
- D. Add each connected App to the App Launcher with a Start URL.
- E. Set up Salesforce as a SAML Idp with My Domain.
Answer: A,D,E
NEW QUESTION # 45
Universal Containers (UC) wants its users to access Salesforce and other SSO-enabled applications from a custom web page that UC magnets. UC wants its users to use the same set of credentials to access each of the applications. what SAML SSO flow should an Architect recommend for UC?
- A. User-Agent
- B. IdP-Initiated
- C. SP-Initiated
- D. SP-Initiated with Deep Linking
Answer: B
NEW QUESTION # 46
Which two statements are capable of Identity Connect? Choose 2 answers
- A. Automated user synchronization and de-activation.
- B. Support multiple orgs connecting to multiple Active Directory servers.
- C. Synchronization of Salesforce Permission Set Licence Assignments.
- D. Supports both Identity-Provider-Initiated and Service-Provider-Initiated SSO.
Answer: A,D
NEW QUESTION # 47
Northern Trail Outfitters (NTO) is planning to implement a community for its customers using Salesforce Experience Cloud . Customers are not able to self-register. NTO would like to have customers set their own passwords when provided access to the community.
Which two recommendations should an identity architect make to fulfill this requirement?
Choose 2 answers
- A. Add customers as contacts and add them to Experience Cloud site.
- B. Enable Welcome emails while configuring the Experience Cloud site.
- C. Use Login Flows to allow users to reset password in Experience Cloud site.
- D. Allow Password reset using the API to update Experience Cloud site membership.
Answer: C,D
NEW QUESTION # 48
Universal Containers (UC) is looking to build a Canvas app and wants to use the corresponding Connected App to control where the app is visible. Which two options are correct in regards to where the app can be made visible under the Connected App setting for the Canvas app? Choose 2 answers
- A. The sidebar of a Salesforce Console as a console component.
- B. In the mobile navigation menu on Salesforce for Android.
- C. Included in the Call Control Tool that's part of Open CTI.
- D. As part of the body of a Salesforce Knowledge article.
Answer: A,D
NEW QUESTION # 49
Universal containers (UC) has a classified information system that it's call centre team uses only when they are working on a case with a record type of "classified". They are only allowed to access the system when they own an open "classified" case, and their access to the system is removed at all other times. They would like to implement SAML SSO with salesforce as the IDP, and automatically allow or deny the staff's access to the classified information system based on whether they currently own an open "classified" case record when they try to access the system using SSO. What is the recommended solution for automatically allowing or denying access to the classified information system based on the open "classified" case record criteria?
- A. Use salesforce reports to identify users that currently owns open "classified" cases and should be granted access to the classified information system.
- B. Use custom SAML jit provisioning to dynamically query the user's open "classified" cases when attempting to access the classified information system
- C. Use apex trigger on case to dynamically assign permission sets that grant access when a user is assigned with an open "classified" case, and remove it when the case is closed.
- D. Use a custom connected App handler using apex to dynamically allow access to the system based on whether the staff owns any open "classified" cases.
Answer: D
NEW QUESTION # 50
Northern Trail Outfitters (NTO) employees use a custom on-premise helpdesk application to request, approve, notify, and track access granted to various on-premises and cloud applications, including Salesforce. Salesforce is currently used to authenticate users.
How should NTO provision Salesforce users as soon as they are approved in the helpdesk application with the approved profiles and permission sets?
- A. Have the helpdesk initiate an IdP-initiated Just-m-Time provisioning Security Assertion Markup Language flow.
- B. Use Salesforce Connect to integrate with the helpdesk application.
- C. Use a login flow to query the helpdesk to validate user status.
- D. Build an integration that performs a remote call-in to the Salesforce SOAP or REST API.
Answer: C
NEW QUESTION # 51
Northern Trail Outfitters (NTO) uses the Customer 360 Platform implemented on Salesforce Experience Cloud. The development team in charge has learned of a contactless user feature, which can reduce the overhead of managing customers and partners by creating users without contact information.
What is the potential impact to the architecture if NTO decides to implement this feature?
- A. Contactless user feature is available only with the External Identity license, which can restrict the Experience Cloud functionality available to the user.
- B. Passwordless authentication can not be supported because the mobile phone receiving one-time password (OTP) needs to match the number on the contact record.
- C. Custom registration handler is needed to correctly assign External Identity or Community license for the newly registered contactless user.
- D. If contactless user is upgraded to Community license, the contact record is automatically created and linked to the user record, but not associated with an Account.
Answer: A
NEW QUESTION # 52
Universal containers(UC) has decided to build a new, highly sensitive application on Force.com platform. The security team at UC has decided that they want users to provide a fingerprint in addition to username/Password to authenticate to this application. How can an architect support fingerprints as a form of identification for salesforce Authentication?
- A. Use an appexchange product that does fingerprint scanning with native salesforce identity confirmation.
- B. Use salesforce Two-factor Authentication with callouts to a third-party fingerprint scanning application.
- C. Use Delegated Authentication with callouts to a third-party fingerprint scanning application.
- D. Use custom login flows with callouts to a third-party fingerprint scanning application.
Answer: D
NEW QUESTION # 53
Universal Containers uses Salesforce as an identity provider and Concur as the Employee Expense management system. The HR director wants to ensure Concur accounts for employees are created only after the appropnate approval in the Salesforce org.
Which three steps should the identity architect use to implement this requirement?
Choose 3 answers
- A. Create a connected app for Concur in Salesforce.
- B. Enable User Provisioning for the connected app.
- C. Create an approval process for user object associated with the provisioning flow.
- D. Create an approval process for a custom object associated with the provisioning flow.
- E. Create an approval process for UserProvisionlngRequest object associated with the provisioning flow.
Answer: A,B,E
NEW QUESTION # 54
Universal Containers (UC) is implementing Salesforce and would like to establish SAML SSO for its users to log in. UC stores its corporate user identities in a Custom Database. The UC IT Manager has heard good things about Salesforce Identity Connect as an Idp, and would like to understand what limitations they may face if they decided to use Identity Connect in their current environment. What limitation Should an Architect inform the IT Manager about?
- A. Identity Connect will only support SP-initiated SAML flows in UC's current environment.
- B. Identity Connect will not support user provisioning in UC's current environment.
- C. Identity connect is not compatible with UC's current identity environment.
- D. Identity Connect will only support Idp-initiated SAML flows in UC's current environment.
Answer: B
NEW QUESTION # 55
Universal containers (UC) built a customer Community for customers to buy products, review orders, and manage their accounts. UC has provided three different options for customers to log in to the customer Community: salesforce, Google, and Facebook. Which two role combinations are represented by the systems in the scenario? Choose 2 answers
- A. Google is the service provider and Facebook is the identity provider
- B. Facebook is the service provider and salesforce is the identity provider
- C. Salesforce is the service provider and Google is the identity provider
- D. Salesforce is the service provider and Facebook is the identity provider
Answer: C,D
NEW QUESTION # 56
Universal Containers (UC) wants to use Salesforce for sales orders and a legacy of system for order fulfillment. The legacy system must update the status of orders in 65* Salesforce in real time as they are fulfilled. UC decides to use OAuth for connecting the legacy system to Salesforce. What OAuth flow should be considered that doesn't require storing credentials, client secret or refresh tokens?
- A. Username-Password flow
- B. JWT Bearer Token flow
- C. Web Server flow
- D. User Agent flow
Answer: B
NEW QUESTION # 57
A technology enterprise is setting up an identity solution with an external vendors wellness application for its employees. The user attributes need to be returned to the wellness application in an ID token.
Which authentication mechanism should an identity architect recommend to meet the requirements?
- A. JWT Bearer Token Flow
- B. User Agent Flow
- C. OpenID Connect
- D. Web Server Flow
Answer: D
NEW QUESTION # 58
Northern Trail Outfitters recently acquired a company. Each company will retain its Identity Provider (IdP). Both companies rely extensively on Salesforce processes that send emails to users to take specific actions in Salesforce.
How should the combined companys' employees collaborate in a single Salesforce org, yet authenticate to the appropriate IdP?
- A. Configure unique MyDomains for each company and have generated links use the appropriate MyDomam in the URL.
- B. Enable each IdP as a login option in the MyDomain Authentication Service settings. Users will then click on the appropriate IdP button.
- C. Have generated links be prefixed with the appropriate IdP URL to invoke an IdP-initiated Security Assertion Markup Language flow when clicked.
- D. Have generated links append a querystnng parameter indicating the IdP. The login service will redirect to the appropriate IdP.
Answer: B
NEW QUESTION # 59
......
Download Latest & Valid Questions For Salesforce Plat-Arch-203 exam: https://www.prep4sureexam.com/Plat-Arch-203-dumps-torrent.html
Exam Dumps for the Preparation of Latest Plat-Arch-203 Exam Questions: https://drive.google.com/open?id=1LRyHMvISPCJbm_vUa1mVi_Rzm73QRv8i