Demo Preview

ARCH-203 Safe Question Preview

This public preview shows limited demo-safe questions only. Correct answers, full explanations, paid-only media, private IDs, and attempt data are not included.

Accepting Third-Party Identity in SalesforceCommunity (Partner and Customer)Salesforce IdentityMultiple ChoiceMulti Select

Preview Questions

Multiple ChoiceAccepting Third-Party Identity in Salesforce
Question 1. Universal Containers wants to secure its Salesforce APIs by using an existing Security Assertion Markup Language (SAML) configuration supports the company's single sign-on process to Salesforce, Which Salesforce OAuth authorization flow should be used?
A. OAuth 2.0 SAML Bearer Assertion Flow
B. A SAML Assertion Row
C. OAuth 2.0 User-Agent Flow
D. OAuth 2.0 JWT Bearer Flow
Multi SelectAccepting Third-Party Identity in Salesforce
Question 2. Containers (UC) has implemented SAML-based single Sign-on for their Salesforce application and is planning to provide access to Salesforce on mobile devices using the Salesforce1 mobile app. UC wants to ensure that Single Sign-on is used for accessing the Salesforce1 mobile App. Which two recommendations should the Architect make? Choose 2 Answers
A. Configure the Embedded Web Browser to use My Domain URL.
B. Configure the Salesforce1 App to use the MY Domain URL.
C. Use the existing SAML-SSO flow along with User Agent Flow.
D. Use the existing SAML SSO flow along with Web Server Flow.
Multi SelectCommunity (Partner and Customer)
Question 3. Northern Trail Outfitters want to allow its consumer to self-register on it business-to-consumer (B2C) portal that is built on Experience Cloud. The identity architect has recommended to use Person Accounts. Which three steps need to be configured to enable self-registration using person accounts? Choose 3 answers
A. Enable access to person and business account record types under Public Access Settings.
B. Contact Salesforce Support to enable business accounts.
C. Under Login and Registration settings, ensure that the default account field is empty.
D. Enable Person Accounts in Setup after satisfying the Person Account prerequisites
E. Configure organization-wide sharing so Contact is Controlled by Parent, or set both Account and Contact to Private
Multiple ChoiceSalesforce Identity
Question 4. Universal Containers (UC) is planning to add Wi-Fi enabled GPS tracking devices to its shipping containers so that the GPS coordinates data can be sent from the tracking device to its Salesforce production org via a custom API. The GPS devices have no direct user input or output capabilities. Which OAuth flow should the identity architect recommend to meet the requirement?
A. OAuth 2.0 Asset Token Flow for Securing Connected Devices
B. OAuth 2.0 Username-Password Flow for Special Scenarios
C. OAuth 2.0 Web Server Flow for Web App Integration
D. OAuth 2.0 JWT Bearer Flow for Server-to-Server Integration
Multi SelectAccepting Third-Party Identity in Salesforce
Question 5. Universal Containers (UC) has implemented SAML-based SSO solution for use with their multi-org Salesforce implementation, utilizing one of the the orgs as the Identity Provider. One user is reporting that they can log in to the Identity Provider org but get a generic SAML error message when accessing the other orgs. Which two considerations should the architect review to troubleshoot the issue? Choose 2 answers
A. The Federation ID must be a valid Salesforce Username
B. The Federation ID must is case sensitive
C. The Federation ID must be in the form of an email address.
D. The Federation ID must be populated on the user record.